Skip to content

Validation evidence

Temporary planning record. It lists what was checked while producing this package, how, and the limits. No runtime tests were run, because the package is documentation-only and the planning work was read-only. Sections 1–7 record the first round (early morning of 3 October 2026); section 8 records the second review round and the writes Chris later authorised.

1. Session and authority

  • Model and effort: Claude Code on Opus 5.5 (claude-opus-5-5) at maximum effort, as Chris requested; no other model was used for the main session.
  • Interruptions: the session was interrupted once to enable Remote Control and resumed in the same conversation; it was later continued from a context summary. Both times the authorised task (claude-planning-launch-2026-10-03/prompt.txt) remained the governing instruction.
  • Authority: planning only. Chris's 3 October notification scope addition was incorporated as an additive, read-only planning update. No notification was sent and no notification PR was touched.

2. Workspace safety checks (read-only)

Check Command / method Result
PR3617 worktree state at start git status --short --branch Branch feat/research-screening-as-specialised-annotation-gxgahs, 0 ahead / 0 behind upstream, HEAD 0f4c764b2; pre-existing dirty research: 2 modified + 16 untracked planning documents, none edited
Other writer in the worktree Scan of /proc/*/cwd; newest planning-document mtime Only this session's shell had its cwd there; the last prior write was 03:13, the check ran at 03:22. No clash.
Effective wt configuration main/.worktreerc + main/.worktreerc.local worktreeParent=/home/chris/workspace/syrf/pr, pattern pr{number}.{slug}, branch prefix codex; no worktree was created, moved or deleted
Handoff package vs worktree copies cmp and diff Identical except link-path rewrites in six documents and in COMPARISON ↔ syrf-v10-design-comparison.md
Main baseline git rev-parse HEAD, origin/main; git ls-remote origin refs/heads/main First 78c6d097d. Later the main checkout was found at 2949ca3a7 and then c59d9d0f1, each equal to the remote and clean; it was advanced outside this session. This session never fetched, pulled or modified it.
Code changes since the baseline git log and git diff --stat from 78c6d097d to 2949ca3a7 and c59d9d0f1, over src/libs, the API, the web app and env-mapping.yaml Only FEAT-024 work (fold slice 6, including a reservation claim-stage refactor that keeps claims keyed by stage and investigator, and #3955's question-answer staleness fix), an identity registration fix, auth-migration documents and the generated API client
Writes made git status and file modification times at the end Still the same 2 modified + 16 untracked pre-existing documents (last modified 03:00–03:08 BST, before this session's first write), plus only the new folder docs/planning/integrated-review-plan-2026-10/; no existing file changed

3. Live GitHub reads (read-only gh)

  • About 03:30–03:50 BST: gh pr list --state open --limit 250 (131 open PRs), merged PRs since 15 September (--limit 300), and gh pr view for 47 in-scope PRs and the 8 notification PRs.
  • About 04:52 BST (03:52 UTC), after the reviews: gh pr view for 41 in-scope PRs (state, draft, mergeability, author, head, base, updated time), repeated once so GitHub recomputed mergeability against the new main.
  • About 05:48 BST (04:48 UTC), after verification: gh pr view for 21 in-scope PRs and a list of PRs opened since 03:50 UTC (#3958 and #3959, both outside this plan's areas); #3955 had merged.
  • In round 1, no PR, issue, label, comment or review was created or changed. The writes made later at Chris's request are listed in section 8.

4. Sub-agents (all instructed to be strictly read-only)

Agent Purpose Type / model
Theme A inventory Question, annotation, forms, outcomes, classification, setup documents and code Explore / Opus
Theme B inventory Review workflow, operations, governance documents and code Explore / Opus
Prototype asset locator Older QM v2, newer question-interface and reviewer prototypes; found / not found Explore / Opus
Backend verification Domain and API implementation state on main Explore / Opus
Frontend verification Angular implementation state on main Explore / Opus
Notification stack inspection #3932–#3947, main email/SignalR baseline, provenance transcript excerpts Explore / Opus
Adversarial reviewers A, B, C Independent critique of the draft package (reports) Plan / Opus
Resolution verifier Fresh-context check that the resolutions landed and the restructure is consistent Plan / Opus

5. Direct re-verification of load-bearing claims

Before the reviews:

  • ChangeOwner unenforced: ResourceSecurity.json, ProjectController.cs:365-390, Project.cs:855-883, ProjectUpdateDto.cs:17.
  • Optional never read on the server: AnnotationQuestion.cs:55, 227.
  • The reconciliation response maps all study sessions: ReviewController.cs:1586-1628, StudyDto.cs:53-58.
  • Question deletion cascade and #3088 gap: ProjectManagementService.cs:201-222.
  • The redesign-prototype folder contents on main.

After the reviews, before adopting their claims (all held):

  • Strict class maps: StudyRepository.cs:3176, 3209, 3220 register ScreeningInfo, ExtractionInfo and SessionTally with no SetIgnoreExtraElements anywhere in the file; only Entity.cs:21 carries [BsonExtraElements].
  • Deletion fails closed: SearchController.cs:122, 134 and ProjectController.cs:410 throw DeletionLifecycleUnavailableException; StudyRepository.cs:1129-1130 says search deletion is disabled today; the deletionLifecycle flag entry in env-mapping.yaml.
  • "Reconciliation reserves nothing" (StageReviewService.cs:153) and "Migrate legacy reservations before enabling review eligibility" (Study.cs:346).
  • SystemQuestionVersion changes system-question structure (AnnotationQuestion.cs:561-578).
  • GreaterIsWorse is a bool (OutcomeData.cs:39); client defaults SD, mean, false (annotation-form-outcome-topology.ts:40-43).
  • The AF2 reconcile host is read-only and stage-review/preview hard-fail on reconciliation (src/services/web/CLAUDE.md AF2 section, lines 353–356).
  • AF2 eligibility must read the generated selector (annotation-form-v2-eligibility.ts:59).
  • Dockview layouts: per-reviewer capability slots and API validation (docs/architecture/dockview-layout-migration.md).
  • Impersonation edit mode admits side-effecting actions (SupportImpersonationAttributes.cs).
  • The studyAttention flag admits conversations, study reports and authorised decisions (#3947's env-mapping.yaml); #3945 and #3947 are stacked on #3944 (gh pr view base branches).
  • The authorization plan's G-D, WP9, WP11, WP-M1/M2 and D10 (handover/2026-09-08-authorization-3335/PLAN.md).
  • All seven #2621 prototypes exist; the local classification site build exists; v10's default navigation mode is "steps" with the numbered Setup section (prototype navigation code).
  • The PRISMA amendment and fixture definitions, the FEAT-011 release checklists, the outcome-measure clarification and the ledger's OC2/ODIR1 and QY4 wording were read in source.

6. Documentation validation

./docs/scripts/validate-docs.sh --verbose --skip-indexes, run in the PR3617 worktree. --skip-indexes is required because the index check runs generate-indexes.sh, which rewrites existing index.md files; this package must not modify existing files. The validator checks front matter and that linked files exist; it doesn't check #anchors, so a separate read-only anchor check was added.

Run When Result for this package Whole-repository result
1 Before every file existed Files then present passed front-matter checks; 8 broken-link errors, all pointing at package files not yet written 8 errors, 63 pre-existing warnings
2 Before the review files existed 5 broken-link errors, all pointing at reviews/ files not yet written 5 errors, 63 pre-existing warnings
3 After the resolutions All 14 package files pass front-matter checks; no broken links Exit 0; 0 errors; 63 pre-existing warnings, none from this package
4 After the verifier's fixes, 06:00 BST All 14 package files pass front-matter checks; no broken links Exit 0; 0 errors; 63 pre-existing warnings, none from this package
5 After Chris's 3 October decisions (new acceptance-criteria and PRISMA-amendment documents), about 07:30 BST All 16 package files pass front-matter checks; no broken links Exit 0; 0 errors; 63 pre-existing warnings, none from this package
6 After adding the domain-model document, about 08:50 BST All 17 package files pass front-matter checks; no broken links; 59 anchored links resolve under both slug rules Exit 0; 0 errors; 63 pre-existing warnings, none from this package

Anchor check (scratchpad script, both GitHub and MkDocs slug rules): after run 3, 42 anchored links all resolved, one only under GitHub's rule, so it was rewritten without the anchor. After run 4, 42 anchored links resolved under both rules. After run 5, 58 anchored links resolve under both rules (the amendment headings were changed from em dashes to "X." so their anchors match in both renderers).

Consistency sweep after the verifier's fixes: no stale release, gate or ID names remain outside the matrix rows that describe them; every question ID referenced in the package is defined in the open-questions document.

Not checked: the Mermaid dependency graph wasn't rendered by a Mermaid tool; its syntax follows the earlier version of the same graph.

The same results are summarised in the resolution matrix.

7. Limits

  • No runtime, browser, database or deployment checks were made. Flag states in environments come from cluster-gitops values.yaml; runtime overrides were not read.
  • The notification provenance transcript was read in targeted excerpts only; claims were checked against code.
  • The Figma file, the remote classification site and Review Prototype v3/v5 were not available; the local classification build was found but not reviewed. Three #2621 prototypes (PRISMA workflows, study state, dashboard) were inventoried by review C and by heading, not read in full.
  • Some reviewer claims were adopted with their evidence but not traced end to end (marked "per review B/C" in the inventory).
  • PR states are snapshots from 3 October 2026, about 03:30–03:50 and 04:52 BST.

8. Round 2 (afternoon and evening of 3 October 2026)

Times are BST. Chris asked for the round-2 review at about 14:30 and added the in-flight programmes at about 14:55; at about 19:00 he asked for plan progress to be committed and pushed on the PR #3617 branch.

8.1 Sub-agents

All reviewers and verifiers were instructed to be strictly read-only; drafters wrote only to the session scratchpad, and patch appliers edited only this package.

Agent Purpose Type / model
Verifier V2 The three documents added after round 1 (report) Plan / Opus
Reviewers VA, DD, UX, SR, AP, MS Versioning concept, domain design, whole-application UI and UX, methodology, allocation and pools, materialised statistics Plan / Fable
Reviewers VB, DC, AC, PH, DS, RT, NS Versioning implementation, data consistency, acceptance criteria, past-year planning, delivery, active reviewer tracking, notifications Plan / Opus
Drafters (4) Versioning model, UX strategy, methodology coverage, domain-model revision general-purpose / Fable
Drafters (4) Consistency model, delivery operating model, programme integration, acceptance-criteria revision general-purpose / Opus
Patch appliers (5) Merged the drafters' patch files into the existing documents; this session reviewed each diff sdd-worker / Sonnet (1), Opus (4)
Verifier V3 Fresh-context whole-package check after integration (report; fixes in matrix §7) general-purpose / Opus
V3 fix workers (6) Applied verifier V3's fixes from one shared brief, each owning a separate set of files; this session read every report, spot-checked the diffs and re-ran the scans sdd-worker / Opus (4), Sonnet (2)

The thirteen reviews and V2 were saved verbatim in reviews/round-2/. The fix PRs (#3964, #3965) had their own implementers and fresh-context diff verifiers under Chris's separate authorisation; they are not part of this package.

8.2 Live reads (read-only)

  • GitOps. The cluster-gitops repository, read at the remote head, has materializedProjectStatisticsFold: true for staging's API and project management services (Chris's 1 October pilot decision). This corrected review MS, which had read a stale checkout.
  • Production and staging databases. A read-only count found no project storing a grant of ChangeOwner, AssignPermissions or Delete. A read-only count of legacy reconciled sessions in production timed out on an unindexed field and was not retried; it is recorded as an off-peak task before F4.
  • GitHub. gh pr view and gh pr list for the in-flight programme PRs; the refresh time is in programme integration §1.

8.3 Writes made (all authorised)

  • Commits and pushes on the PR #3617 branch only, from about 19:00 (Chris's request), including one merge of origin/main whose only conflict, docs/planning/index.md, was regenerated with docs/scripts/generate-indexes.sh. The PR #3617 description gained a section on this package. mkdocs.yml was regenerated with docs/scripts/generate-mkdocs-nav.py because PR CI's navigation check failed on the new planning documents; the generator only added their entries.
  • Follow-up issues #3997, #3998, #3999 and #4000, filed from this session.
  • #3964: Chris authorised the fix and its shipping on a passing review and green checks, and chose it over #3969 (D1-01). It merged at 20:27 BST (merge commit 85e6facf7) after an approving review on its head and green checks; its description gained links to the follow-up issues, its worktree and branches were removed, and #3969 received a comment pointing to #3964.
  • #3617, step 0 (D1-05, approved by Chris on 3 October): the title and description were refreshed and /claude-review was requested on head 1c8b1e84c. The review gave a "comment only" verdict with nothing blocking; it said it had not read the full prose. Its two non-blocking suggestions were answered on the PR: the navigation is left to the generator, and the lifetime trigger is added in the follow-up. After the review settled and the checks were green (docs validation passed on that head), it merged at 22:42 BST (merge commit f5318074d). Its worktree and branches were then removed.
  • #4002, opened with wt new: records step 0 as merged and adds the package's lifetime (PROPOSAL) to the README.
  • No notification was sent, and no runtime code, migration, deployment or flag change was made by the planning work.

8.4 Documentation validation

./docs/scripts/validate-docs.sh --skip-indexes --skip-links, plus the anchor script. The link check was skipped in these runs because it is slow across the whole repository; the anchor script checks every relative link with an anchor in this package, and the validator run in PR CI checks links.

Run When Result for this package Whole-repository result
7 After integrating the round-2 documents, about 20:00 All package files pass front-matter checks; 205 anchored links resolve Exit 0; 0 errors; 64 warnings, none from this package (the 64th came from main in the merge)
8 After the acceptance-criteria cross-file patches and fixture-name fixes, about 20:20 As run 7; every AC, FX and contract test ID cited in the package is defined, apart from labelled round-1 review IDs Exit 0; 0 errors; 64 warnings, none from this package
9 After verifier V3's 33 fixes, about 21:10 All package files, including the saved V3 report and resolution brief, pass front-matter checks; 236 anchored links resolve under both slug rules (one renderer-specific anchor removed) Exit 0; 0 errors; 64 warnings, none from this package
10 After recording Chris's Batch D1 answers, about 22:34 All package files pass front-matter checks; 260 anchored links resolve under both slug rules; no pending-D1-… status remains Exit 0; 0 errors; 64 warnings, none from this package

8.5 Limits of round 2

  • No runtime, browser, database-write or deployment checks were made.
  • Reviewers' code citations were adopted where the resolving writer re-read them; the matrix marks where a claim was corrected instead.
  • Live PR and programme states are snapshots from 3 October 2026 and must be rechecked before any implementation decision.