Skip to content

Fresh-context verifier V2 — acceptance criteria, PRISMA amendments and domain model (verbatim report)

Temporary planning review record. The report below is reproduced verbatim as returned by the independent read-only verifier (Plan agent, Opus model, launched 3 October 2026 about 14:05 BST) that checked the three documents added after round 1: acceptance-criteria.md, prisma-amendments.md and domain-model.md. Only this front matter and note were added. Line numbers refer to the package as it stood when the verifier read it. Resolutions are in the round-2 resolution matrix.

Verdict: The package isn't ready to mark as verified. There are no blockers. All five required invariants hold in all three documents, and every release, gate and Q/E/U/A/AC reference exists in the plan and open questions. The claims about FEAT-011 and FEAT-012 check out against the specs: the brief says R subprocess while the Approved spec says native C#, scenario 1's table says "delete" while its steps keep the study as Duplicate, and the box 3 derivation and the H, I, J and K line references are correct. Amendment G's line range is off by one. Nine major problems need fixing first: a FEAT-011 conflict that no amendment covers, dedup-merge and Publication boundaries that clash with the new keys and with privacy, gaps in amendment K, missing labels and missing criteria in the acceptance criteria, fixture assignments that can't be met, one contradiction with the contracts, and a staging-seed rule with no mechanism behind it.

Abbreviations used in the table (absolute paths): - AC = /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/acceptance-criteria.md - PA = .../integrated-review-plan-2026-10/prisma-amendments.md (same folder as AC) - DM = .../integrated-review-plan-2026-10/domain-model.md - Plan = .../integrated-review-plan-2026-10/integrated-plan.md - Contracts = .../integrated-review-plan-2026-10/contracts.md - 3LM = /home/chris/workspace/syrf/main/docs/features/prisma-specification/three-level-data-model.md - Map = /home/chris/workspace/syrf/main/docs/features/prisma-specification/prisma-flow-diagram-mapping.md - Dedup = /home/chris/workspace/syrf/main/docs/features/deduplication/service-specification.md

ID Sev File / section Finding Evidence Recommended fix
V2-01 Major PA (summary; "single register"); DM §3.5, §8 P1 writes immutable Citations before any Publication exists (Publication only arrives in P2). FEAT-011 makes Citation.publicationId required and forbids changing a Citation after it is created, so P2 would have to change P1's Citations to link them. No amendment from A to L covers this. 3LM:147 (publicationId "Nullable: No"), :167 (a Citation is never modified); DM §3.5 (Publication in P2), §8 (P1 changes Study (citations)); migration §7 ("P1 (Citations), P2 (Publications)") Add an amendment. Either create Publications at P1 import (FEAT-012 Stage 1, DOI/PMID only), or hold the Citation-to-Publication link in a separate record that can be added later. Add a P2 criterion that linking never rewrites a Citation.
V2-02 Major PA D, L.4; DM §5 (merge/split row), §7 The reviewed-duplicate merge is described as moving ("remapping") sessions and gold onto the canonical Study, which the new keys don't allow. The C2 answer key includes studyId and revisions never change. FormSession is unique per study, form and reviewer, so L.4's own case (one reviewer reviewed both duplicates) collides. StudyGold is one per study, and ScreeningOutcome one per study and profile. L.4 also keeps FEAT-012's split into "same stage" and "different stages". Under SF1 sessions belong to forms, not stages, so a duplicate reviewed with the same form through two stages lands in scenario 4: kept as two Studies, both counted in PRISMA. Dedup:435–436, 462–484; DM:219–222; Contracts C1 "Merge and split", C2 key Define the merge as a link: the secondary study's sessions join as extra candidates and are not re-keyed. Add explicit rules for one reviewer's two sessions (admin choice, counted once), two gold histories and two outcome histories. Restate scenarios 3 and 4 by form and profile instead of stage. Record this under E33 and in L.4.
V2-03 Major DM principle 5, §3.5; PA L.6; AC P2 criteria and §7 fixture 8 Publication is not "bibliographic data only". FEAT-011 gives it linkedProjectIds[] and per-field provenance holding sourceProjectId and sourceCitationId, and FEAT-012 enriches it automatically across projects. L.6 only rules out review data, not exposing which other (possibly private) projects imported a paper. Cross-project enrichment also changes what another project displays without any event in that project's commit sequence (needed for C11 as-of exports), and it isn't listed as a writer. Publication ships in P2, but the cross-project part of fixture 8 is first required in R5b, and P2 has no privacy criterion. 3LM:97–109; Dedup:417–423; main/docs/architecture/mongodb-reference.md:112 ("privacy and cross-project authorisation remain design gates") Extend L.6 and the DM invariant: reading a Publication never exposes project or citation IDs from projects the caller can't access. Decide how enrichment reaches Study metadata and how as-of exports cover it. Add an AC-P2 privacy criterion and move fixture 8's cross-project part to P2.
V2-04 Major PA K (K.1, K.2, K.5); AC-R5b-03, AC-R5b-07 K lets users report title/abstract screening, full-text retrieval and assessment, and "studies from a previous review version" done outside SyRF, but only says how totals add up. FEAT-011's later boxes depend on SyRF's own outcomes: box 6 needs the title/abstract profile outcome to be Included, and boxes 10 and 16 count lifecycle Included. A review that screened titles and abstracts outside SyRF therefore gets box 6 = 0 and an overstated box 10. Previous-review counts fill box 1 and change box 16, contradicting the plan's "box 1 stays deferred". AC-R5b-07's "all 34 fields derivable" is ambiguous on this. Map:80–81, 126, 178, 185; Plan R5b (lines 679–680); PA:189–214 Add an "entry phase" rule per search or import: records imported after an outside step count as having passed that step. Add per-box rules for combining reported and computed counts. Either drop the previous-review step type or explicitly bring box 1 back with the updated-review template. Reword AC-R5b-07. Put these questions under Q-37.
V2-05 Major AC §1 (lines 26–27) and criteria; DM §3.1, §3.3, §3.4 AC §1 says everything not marked PROPOSAL comes from confirmed decisions or the plan. Yet several criteria state open-question recommendations as settled: AC-R1d-02 (non-recursive delegation, a recommendation under PM2/Q-03), AC-R2d-08 (Q-20), AC-R3a-07 (Q-24 and assumption A-16), AC-R3c-02 (the exact LC1 flow, Q-02), AC-R4a-02 (re-pairing history, PROPOSAL in the plan), AC-R4a-08 (most-restrictive blinding, Q-28), AC-R4a-09 (target-1 forms create no task, Q-29), AC-P1-05 and AC-R5b-03/-04 (amendment K rules, Q-37), and UI-8's preview acceptance (assumption A-24). The domain model does the same: target-1 and no-self-reconciliation stated without Q-29 or Q-36, "Design capability (Q-19)" for project rules, and Q-02's flow attributed to LC1. Ship gates pass only on these criteria, so an unlabelled recommendation becomes a decision by default. Ledger PM2 (lines 865–870); open questions Q-02, Q-20, Q-24, Q-28, Q-29, Q-36, Q-37 and A-24 Mark each as PROPOSAL or "as Q-x decides", reword §1, and add the Q-36 caveat on self-reconciliation.
V2-06 Major AC §4: R2a, R3a, R4a, R5b, P2 The acceptance criteria decide the ship gates but leave out items in the plan's MVP boundaries, so these would ship unchecked. R2a: system-question snapshots (E24), automatic inclusion of ancestor questions, refusal of a second stage binding (A-21), the per-project commit sequence (R5a depends on it), server-minted IDs (E27), maximum form size (E28), presentation state never affecting qualification, and the #3732 target override becoming legacy-only. R3a: the default profile reproduces the project threshold; the capture log is consumed; Skip records nothing (amendment A); Complete-and-Include is atomic; VS1/BL1 settings carry provisional Q-30 defaults; pool entry for batched and early-stopped reviews (required by amendment A's fixtures). R4a: changed inputs never retract gold; three-state exposure recording (R5c depends on it); NT1, RE1, UA1; assignment never overrides reconciler eligibility; non-qualifying assessments don't inflate sufficiency. R5b: amendments B and E once Q-06b decides; Q-33's presentation of withdrawn searches; box 1 stays deferred. P2: Publication creation with unique sparse DOI/PMID indexes; citations[] backfill or "derived" labelling; full-text status; retroactive deduplication; the merge wizard. Plan §5.4 (lines 382–418), §5.5 (499–524), §5.6 (582–604), §5.7 (675–680), §5.8 P2 (690) Add a numbered criterion for each item.
V2-07 Major AC-R2c-09, AC-R3b-08, AC-R3a-05; §7 table Fixture 4 includes LC1 readiness and confirmation plus "old PRISMA snapshot unchanged". R2c and R3b ship before R3c (windows W3/W4) and long before R5b snapshots, so "fixture 4 passes" can't be met there. R3c appears only as a re-run, and AC-R3c has no fixture 4 criterion. Fixture 3 needs pending exclusion reasons and a preliminary report, neither of which exists at R3a. PRISMA review fixtures 3–4 (review-prisma-integration-2026-10-03.md:149–154); Plan §7 windows W3–W6; AC:197, 220, 238, 471–472 Split fixtures 3 and 4 into named parts, each with the release where it first applies (fixture 4's LC1 part first in R3c, snapshot parts in R5b). Reference them from AC-R3c and AC-R4p.
V2-08 Major AC-R3a-09 The criterion says "Who is offered what" never reveals personal votes. C10 says the opposite: the Monitor view needs a capability precisely because it "can reveal personal votes". OD5 only covers warnings shown to reviewers. The plan's wording matches the criterion, so plan and contract disagree too. Contracts:429–430; Plan:517–518; decision register OD5 Decide which rule holds (likely: capability holders see votes, reviewer-facing warnings never do) and align the criterion, the plan and C10.
V2-09 Major AC §6 rules and seed table No mechanism exists for "Staging receives new seeds only through the existing seed reconciliation, without altering existing data". DatabaseSeeder skips any database that already has data. The reconciliation only reassigns ownership of the five fixed seed projects. New fixtures are "not retrofitted into shared staging", and a staging reseed is a destructive operator procedure. Two smaller problems: the "Versioned forms" seed is bound to two stages, so it can't serve R2a (one stage per form), and seed users aren't accounts human testers can log in as. main/src/services/project-management/SyRF.ProjectManagement.Endpoint/Seeding/DatabaseSeeder.cs:124–128; main/docs/platform/enhanced-database-seeding.md:106–131, 143–156; main/docs/how-to/seed-pdf-fixtures.md:27–31, 192–196 Add an engineering item for an additive staging seeder limited to known IDs, or say new seeds are preview-only plus an authorised staging reset. Split the versioned-forms seed. Name real tester accounts for owner and non-owner tests.
V2-10 Minor PA G G cites "lines 279–281" for MIG-11/12, but line 281 is MIG-13. G also leaves out the other Phase 16 platform-wide migrations this programme replaces: MIG-13 (the sourceType backfill, which migration §7 moves to per-project R6) and MIG-14 (stage settings). .../prisma-specification/prisma-constraint-annotations.md:279–282; migration §7 Cite lines 279–280, and either extend G to MIG-13/MIG-14 or state that they stand.
V2-11 Minor PA H H cites only the taxonomy's placeholder. FEAT-011 has a second, different placeholder (finalOutcome, decidedAt, source including Admin), and the Release 3 checklist pins the taxonomy's shape. The "Admin authority" H mentions exists only in that second placeholder. 3LM:221–234; prisma-constraint-annotations.md:331 Amend all three places in one change.
V2-12 Minor PA L.1, L.2, L.5; AC-P2-01, -04, -06 L.1 says P2 implements FEAT-012 "as specified", but approved amendment D changes scenario 2 (auto-confirm when one study is reviewed) to admin review, which also changes §8.1's queue. L.5 and AC-P2-06 exclude only four statuses from pools; FEAT-012 §12 also requires excluding RemovedByAutomation and RemovedOther, and FEAT-011 admits only Active studies to screening pools. AC-P2-04 says secondary studies become "Duplicate" (scenario 3 makes them Merged) and doesn't require moved Citations to move back on reversal. AC-P2-01 drops L.2's parity check on the seeded pilot data. Dedup:452–460, 506–509, 646–651; taxonomy §4 rule 1 List D's scenario 2 change in L, extend the excluded-status list, and fix AC-P2-04 and AC-P2-01.
V2-13 Minor PA K; AC-P2-07 K.2 says each field is "computed plus reported", but K.3 replaces the identification count with the identified-at-source count. Derived fields #31–34 shouldn't accept reported values. K changes FEAT-012 §11.1's box 3 formula, but its "Amends" column lists only FEAT-011. Once box 3 includes reported duplicates, AC-P2-07's count-consistency equation is ambiguous, since §11.2 only balances Citations held in SyRF. No release builds data entry for step types other than identification and deduplication. Records tied to withdrawn searches (J, Q-33) aren't addressed. PA:202–214, 223–224; Dedup:611–632 Make K.2 and K.3 agree, restrict the allowed fields, add FEAT-012 §11 to "Amends", state that §11.2 holds over SyRF-held Citations, assign entry of the other step types to a release, and define what happens for withdrawn searches.
V2-14 Minor PA preamble The page says each amendment goes through the change policy "in the PR that implements it". The plan opens amendment documentation PRs first (§12 step 3), Q-06a wants amendment PRs before the P1 build and the F3 freeze, and H is "frozen at F3". The page also never cites Q-37, where the K and L rules get confirmed. Plan:1094–1095; Q-06a; Q-37 Align the wording with the freeze-gate timing and cite Q-37.
V2-15 Minor DM header, §2 Errors in the "today" table. The aggregate class is StudyPdfCorrection, so by the naming rule its collection is pmStudyPdfCorrection (the reference doc's pmStudyCorrection is itself out of date). SystematicSearch holds NumberOfStudies, computed from reference files, not a citation count. Aggregates are not one per folder: ReviewerPresence and ReviewSessionConnection sit at the Model root, and three BulkPdfUpload* roots sit inside ProjectAggregate. Roots and stores that write Study and belong in R0's legacy-writer inventory are missing: bulk PDF upload, ADR-020 bulk update and the M5b risk-of-bias run stores (these use explicit collection names). main/src/libs/project-management/SyRF.ProjectManagement.Core/Model/StudyCorrectionAggregate/StudyPdfCorrection.cs:9; .../SystematicSearchAggregate/SystematicSearch.cs:42; mongodb-reference.md:88, 103–111 Correct the table and add the missing rows.
V2-16 Minor DM principle 5; §3.1 DefinitionTemplate; §8 R1a "Only Publication is system-wide" conflicts with system-supplied templates (SET1, TC1), outcome schemas ("Project, or system-supplied") and entity-type templates. Template copies "record their source template and version". In R1a that means a new field on the question list embedded in Project, yet §8 lists no R1a change and R1a ships before R0's N-1 compatibility floor. DM:43–45, 80, 120, 230 Allow system-scoped definitions with their own authorization. Either drop copy provenance for R1a or list the Project change with its compatibility step.
V2-17 Minor DM §3.1, §3.2, §3.5, §4 Name and ownership overlaps. The new ScreeningOutcome aggregate shares its name with FEAT-011's embedded ScreeningOutcome value. Study gets both a summary projection with "current per-profile screening outcomes" and screeningOutcomes[]; it's unclear whether that is one array or two. Both StageSettings versions and StageLifecycle hold the lifecycle mode. pmDedupAuditEntry differs from FEAT-012 §10.2's pmDedupAuditLog (or embedded) option, and FEAT-012's pmDedupBatch staging collection is missing. DM:81–82, 92, 130, 159; Dedup:256, 597 Rename the projected value and state there is one array, give lifecycle mode a single owner, reconcile the dedup collection names, and list pmDedupBatch.
V2-18 Minor DM §3.2, §3.3, §7 FormSession's unique key (study, form, reviewer) lacks the authority scope that C2's key includes, and the domain model doesn't say whether the reconciler's session is a FormSession. The key collides if Q-36 allows self-reconciliation, or if one form has tasks in two compatibility classes. ProfileAdjudication has a single record per study and profile with no versions, against principle 3, even though DP2 corrections and R4b re-run adjudication. "One draft per session" conflicts with AC-R2a-06's "both drafts are kept". Screening-only steps have no session or draft container, yet the screening-submit transaction cites "the FormSession version" and AC-R3a-04 implies screening autosave. DM:90–91, 104, 108, 176, 219–222; Contracts C2, C5 Add authority scope to the key (or a separate reconciliation session type), version ProfileAdjudication, say where the losing tab's draft lives, and define the screening submission and draft container (at F3/F5).
V2-19 Minor DM §5 The transaction table doesn't match C1, C11 or FEAT-024. Only Save/Complete includes the receipt, commit sequence, Study version bump and FEAT-024 pending entries. Screening submit (FEAT-024's main screening family), gold publication, merge/split and stage-change approval leave them out, though C11 allocates the sequence "inside each canonical transaction". Missing operations: clearing or rebasing the SessionDraft on Save/Complete; publishing StageSettings while the stage is Completed (RX2 freezes bindings); capturing legacy screening writes; pool-entry events written by anything other than screening submit (batch release, imports into active stages, stage or filter changes, dedup reversal, return from retrieval); committing the approved underlying change together with the stage status on approval. Contracts:118–121, 444; main/.claude/rules/materialized-stats.md:110–117 Add the missing columns and rows.
V2-20 Minor DM §4, §8 §8 has no rows for R2d (outdated-flag state, FV4 policy-revision records), R3d (setup drafts, listed in migration §5), R4c (outcome-series gold), R5a (export manifest and DataExportJob changes, which §3.6 and §4 assign to R5a) or O2/R6 (manifests, staged copies). §8's R2a row omits the Project change that §4 lists. §4's ProjectStatistics row omits R3b's profile-version usage (C8 at F5). Migration §5 (R3d, O2, R6 rows); Contracts C8 Add the missing rows and entries.
V2-21 Minor AC §2, AC-R0-01 AC-ALL-04 (image rollback with canonical data present) can't apply to R1a–R1d, which write no canonical data and have no recorded minimum image, and AC-ALL-11 (pilot exit) can't apply to R0, which has no pilot. At R0's own ship gate, AC-R0-01's "previous production image" means the image from before R0, which by design can't tolerate the new fields. Migration §5 (R1a–R1d rows); Plan §5.2 Scope AC-ALL-04 and AC-ALL-11 to releases they apply to. Make AC-R0-01's subject the R0 image (the recorded minimum) reading fields added by later releases.
V2-22 Minor AC §3 UI-6's width list omits the plan's v10 925 px check. The reading of UI1 (new screens render through the Material 2 bridge in production until FEAT-023's single cutover) isn't flagged for Chris, though production users won't see Material 3 components until then. UI-8's preview acceptance rests on assumption A-24 but doesn't cite it. Plan:826–828; main/docs/features/material-3-migration/README.md:166–168; A-24 Add 925 px. Put the UI1 reading to Chris, or make the FEAT-023 cutover a production prerequisite. Cite A-24.
V2-23 Minor AC §1, §4, §5 Several criteria break the document's own rules. PE-01 to PE-05 have no verification method, and PE-02 asks to prove a negative. Several criteria bundle many outcomes, against §1's one-outcome rule: AC-R4a-03 has about seven; AC-R2a-09, AC-R4a-07, AC-O2-04 and AC-R6-05 also bundle. Some aren't observable outcomes: AC-R3b-04 ("follow the DP5 setting"), AC-R4c-03 (an entry condition), AC-C1-03/-04 (design statements), and AC-R4a-13's undefined "reference laptop profile". AC:234, 278, 307, 363–364, 403–409 Add verification methods, and split or rewrite these criteria.
V2-24 Minor AC §4 Smaller omissions against the plan's acceptance text. R3d drops setup-proposal fixtures: an empty project creates no PRISMA records; extraction-off adds no mandatory types (TC1); the old entry point creates no duplicate project; Living Search/ML stay disabled. R3c lacks approval across all affected stages for shared work. R4b lacks QY5 (rejection explanation optional) and the query-review permission. R4p lacks RX1's "an extra vote doesn't resolve supporting-answer conflicts". R5c lacks CSV export. C1 lacks TC1 templates, export and the move from category tabs to entity types. M0 lacks the compatibility-floor and AF2 drafts designs, and weakens "Q-08 harvest executed" to "list complete". R6 lacks notification items in manifests and "no automatic promotion at adoption". R1c lacks invariant 10 (holding a grant doesn't let you assign it). R2d lacks SF5's warning when a shared answer changes. .../docs/planning/review-guided-setup-template-plan-2026-10-03.md:128–134; lifecycle proposal; Plan §5.1, §5.3, §5.9 Add the missing criteria.
V2-25 Minor AC §5 user-testing table No user-testing tasks for user-facing R2d (Fix, U4), R3c (approval dialog, U10), R4b (U21), R4p, R5c (U29), P2 (dedup queue, merge wizard) or C2, though plan §9.8 requires user testing for every release. For these releases PE-05 checks nothing. Plan §9 item 8; open questions §3 Add tasks or state why none apply.
V2-26 Note DM §6, §9 The ER diagram's cardinalities ignore legacy projects: STUDY to STUDY_GOLD and STUDY_POPULATION, PROJECT to PROJECT_ADMISSION, and STAGE to STAGE_SETTINGS and STAGE_LIFECYCLE should be zero-or-one. ExternalStepRecord's relation to Project is missing. §9 leaves out decisions taken at F3, F5, F-P, F-C, F-O and F6a. DM:187–213, 248–258 Correct the diagram and complete §9.

Critical Files for Implementation

  • /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/acceptance-criteria.md
  • /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/prisma-amendments.md
  • /home/chris/workspace/syrf/pr/pr3617.research-screening-as-specialised-annotation-gxgahs/docs/planning/integrated-review-plan-2026-10/domain-model.md
  • /home/chris/workspace/syrf/main/docs/features/prisma-specification/three-level-data-model.md
  • /home/chris/workspace/syrf/main/docs/features/deduplication/service-specification.md