Validation evidence¶
Temporary planning record. It lists what was checked while producing this package, how, and the limits. No runtime tests were run, because the package is documentation-only and the planning work was read-only. Sections 1–7 record the first round (early morning of 3 October 2026); section 8 records the second review round and the writes Chris later authorised.
1. Session and authority¶
- Model and effort: Claude Code on Opus 5.5 (
claude-opus-5-5) at maximum effort, as Chris requested; no other model was used for the main session. - Interruptions: the session was interrupted once to enable Remote Control and resumed in the
same conversation; it was later continued from a context summary. Both times the authorised task
(
claude-planning-launch-2026-10-03/prompt.txt) remained the governing instruction. - Authority: planning only. Chris's 3 October notification scope addition was incorporated as an additive, read-only planning update. No notification was sent and no notification PR was touched.
2. Workspace safety checks (read-only)¶
| Check | Command / method | Result |
|---|---|---|
| PR3617 worktree state at start | git status --short --branch |
Branch feat/research-screening-as-specialised-annotation-gxgahs, 0 ahead / 0 behind upstream, HEAD 0f4c764b2; pre-existing dirty research: 2 modified + 16 untracked planning documents, none edited |
| Other writer in the worktree | Scan of /proc/*/cwd; newest planning-document mtime |
Only this session's shell had its cwd there; the last prior write was 03:13, the check ran at 03:22. No clash. |
Effective wt configuration |
main/.worktreerc + main/.worktreerc.local |
worktreeParent=/home/chris/workspace/syrf/pr, pattern pr{number}.{slug}, branch prefix codex; no worktree was created, moved or deleted |
| Handoff package vs worktree copies | cmp and diff |
Identical except link-path rewrites in six documents and in COMPARISON ↔ syrf-v10-design-comparison.md |
| Main baseline | git rev-parse HEAD, origin/main; git ls-remote origin refs/heads/main |
First 78c6d097d. Later the main checkout was found at 2949ca3a7 and then c59d9d0f1, each equal to the remote and clean; it was advanced outside this session. This session never fetched, pulled or modified it. |
| Code changes since the baseline | git log and git diff --stat from 78c6d097d to 2949ca3a7 and c59d9d0f1, over src/libs, the API, the web app and env-mapping.yaml |
Only FEAT-024 work (fold slice 6, including a reservation claim-stage refactor that keeps claims keyed by stage and investigator, and #3955's question-answer staleness fix), an identity registration fix, auth-migration documents and the generated API client |
| Writes made | git status and file modification times at the end |
Still the same 2 modified + 16 untracked pre-existing documents (last modified 03:00–03:08 BST, before this session's first write), plus only the new folder docs/planning/integrated-review-plan-2026-10/; no existing file changed |
3. Live GitHub reads (read-only gh)¶
- About 03:30–03:50 BST:
gh pr list --state open --limit 250(131 open PRs), merged PRs since 15 September (--limit 300), andgh pr viewfor 47 in-scope PRs and the 8 notification PRs. - About 04:52 BST (03:52 UTC), after the reviews:
gh pr viewfor 41 in-scope PRs (state, draft, mergeability, author, head, base, updated time), repeated once so GitHub recomputed mergeability against the newmain. - About 05:48 BST (04:48 UTC), after verification:
gh pr viewfor 21 in-scope PRs and a list of PRs opened since 03:50 UTC (#3958 and #3959, both outside this plan's areas); #3955 had merged. - In round 1, no PR, issue, label, comment or review was created or changed. The writes made later at Chris's request are listed in section 8.
4. Sub-agents (all instructed to be strictly read-only)¶
| Agent | Purpose | Type / model |
|---|---|---|
| Theme A inventory | Question, annotation, forms, outcomes, classification, setup documents and code | Explore / Opus |
| Theme B inventory | Review workflow, operations, governance documents and code | Explore / Opus |
| Prototype asset locator | Older QM v2, newer question-interface and reviewer prototypes; found / not found | Explore / Opus |
| Backend verification | Domain and API implementation state on main |
Explore / Opus |
| Frontend verification | Angular implementation state on main |
Explore / Opus |
| Notification stack inspection | #3932–#3947, main email/SignalR baseline, provenance transcript excerpts |
Explore / Opus |
| Adversarial reviewers A, B, C | Independent critique of the draft package (reports) | Plan / Opus |
| Resolution verifier | Fresh-context check that the resolutions landed and the restructure is consistent | Plan / Opus |
5. Direct re-verification of load-bearing claims¶
Before the reviews:
ChangeOwnerunenforced:ResourceSecurity.json,ProjectController.cs:365-390,Project.cs:855-883,ProjectUpdateDto.cs:17.Optionalnever read on the server:AnnotationQuestion.cs:55, 227.- The reconciliation response maps all study sessions:
ReviewController.cs:1586-1628,StudyDto.cs:53-58. - Question deletion cascade and #3088 gap:
ProjectManagementService.cs:201-222. - The redesign-prototype folder contents on
main.
After the reviews, before adopting their claims (all held):
- Strict class maps:
StudyRepository.cs:3176, 3209, 3220registerScreeningInfo,ExtractionInfoandSessionTallywith noSetIgnoreExtraElementsanywhere in the file; onlyEntity.cs:21carries[BsonExtraElements]. - Deletion fails closed:
SearchController.cs:122, 134andProjectController.cs:410throwDeletionLifecycleUnavailableException;StudyRepository.cs:1129-1130says search deletion is disabled today; thedeletionLifecycleflag entry inenv-mapping.yaml. - "Reconciliation reserves nothing" (
StageReviewService.cs:153) and "Migrate legacy reservations before enabling review eligibility" (Study.cs:346). SystemQuestionVersionchanges system-question structure (AnnotationQuestion.cs:561-578).GreaterIsWorseis abool(OutcomeData.cs:39); client defaultsSD,mean,false(annotation-form-outcome-topology.ts:40-43).- The AF2 reconcile host is read-only and stage-review/preview hard-fail on reconciliation
(
src/services/web/CLAUDE.mdAF2 section, lines 353–356). - AF2 eligibility must read the generated selector (
annotation-form-v2-eligibility.ts:59). - Dockview layouts: per-reviewer capability slots and API validation
(
docs/architecture/dockview-layout-migration.md). - Impersonation edit mode admits side-effecting actions (
SupportImpersonationAttributes.cs). - The
studyAttentionflag admits conversations, study reports and authorised decisions (#3947'senv-mapping.yaml); #3945 and #3947 are stacked on #3944 (gh pr viewbase branches). - The authorization plan's G-D, WP9, WP11, WP-M1/M2 and D10
(
handover/2026-09-08-authorization-3335/PLAN.md). - All seven #2621 prototypes exist; the local classification site build exists; v10's default navigation mode is "steps" with the numbered Setup section (prototype navigation code).
- The PRISMA amendment and fixture definitions, the FEAT-011 release checklists, the outcome-measure clarification and the ledger's OC2/ODIR1 and QY4 wording were read in source.
6. Documentation validation¶
./docs/scripts/validate-docs.sh --verbose --skip-indexes, run in the PR3617 worktree.
--skip-indexes is required because the index check runs generate-indexes.sh, which rewrites
existing index.md files; this package must not modify existing files. The validator checks
front matter and that linked files exist; it doesn't check #anchors, so a separate read-only
anchor check was added.
| Run | When | Result for this package | Whole-repository result |
|---|---|---|---|
| 1 | Before every file existed | Files then present passed front-matter checks; 8 broken-link errors, all pointing at package files not yet written | 8 errors, 63 pre-existing warnings |
| 2 | Before the review files existed | 5 broken-link errors, all pointing at reviews/ files not yet written |
5 errors, 63 pre-existing warnings |
| 3 | After the resolutions | All 14 package files pass front-matter checks; no broken links | Exit 0; 0 errors; 63 pre-existing warnings, none from this package |
| 4 | After the verifier's fixes, 06:00 BST | All 14 package files pass front-matter checks; no broken links | Exit 0; 0 errors; 63 pre-existing warnings, none from this package |
| 5 | After Chris's 3 October decisions (new acceptance-criteria and PRISMA-amendment documents), about 07:30 BST | All 16 package files pass front-matter checks; no broken links | Exit 0; 0 errors; 63 pre-existing warnings, none from this package |
| 6 | After adding the domain-model document, about 08:50 BST | All 17 package files pass front-matter checks; no broken links; 59 anchored links resolve under both slug rules | Exit 0; 0 errors; 63 pre-existing warnings, none from this package |
Anchor check (scratchpad script, both GitHub and MkDocs slug rules): after run 3, 42 anchored links all resolved, one only under GitHub's rule, so it was rewritten without the anchor. After run 4, 42 anchored links resolved under both rules. After run 5, 58 anchored links resolve under both rules (the amendment headings were changed from em dashes to "X." so their anchors match in both renderers).
Consistency sweep after the verifier's fixes: no stale release, gate or ID names remain outside the matrix rows that describe them; every question ID referenced in the package is defined in the open-questions document.
Not checked: the Mermaid dependency graph wasn't rendered by a Mermaid tool; its syntax follows the earlier version of the same graph.
The same results are summarised in the resolution matrix.
7. Limits¶
- No runtime, browser, database or deployment checks were made. Flag states in environments come
from cluster-gitops
values.yaml; runtime overrides were not read. - The notification provenance transcript was read in targeted excerpts only; claims were checked against code.
- The Figma file, the remote classification site and Review Prototype v3/v5 were not available; the local classification build was found but not reviewed. Three #2621 prototypes (PRISMA workflows, study state, dashboard) were inventoried by review C and by heading, not read in full.
- Some reviewer claims were adopted with their evidence but not traced end to end (marked "per review B/C" in the inventory).
- PR states are snapshots from 3 October 2026, about 03:30–03:50 and 04:52 BST.
8. Round 2 (afternoon and evening of 3 October 2026)¶
Times are BST. Chris asked for the round-2 review at about 14:30 and added the in-flight programmes at about 14:55; at about 19:00 he asked for plan progress to be committed and pushed on the PR #3617 branch.
8.1 Sub-agents¶
All reviewers and verifiers were instructed to be strictly read-only; drafters wrote only to the session scratchpad, and patch appliers edited only this package.
| Agent | Purpose | Type / model |
|---|---|---|
| Verifier V2 | The three documents added after round 1 (report) | Plan / Opus |
| Reviewers VA, DD, UX, SR, AP, MS | Versioning concept, domain design, whole-application UI and UX, methodology, allocation and pools, materialised statistics | Plan / Fable |
| Reviewers VB, DC, AC, PH, DS, RT, NS | Versioning implementation, data consistency, acceptance criteria, past-year planning, delivery, active reviewer tracking, notifications | Plan / Opus |
| Drafters (4) | Versioning model, UX strategy, methodology coverage, domain-model revision | general-purpose / Fable |
| Drafters (4) | Consistency model, delivery operating model, programme integration, acceptance-criteria revision | general-purpose / Opus |
| Patch appliers (5) | Merged the drafters' patch files into the existing documents; this session reviewed each diff | sdd-worker / Sonnet (1), Opus (4) |
| Verifier V3 | Fresh-context whole-package check after integration (report; fixes in matrix §7) | general-purpose / Opus |
| V3 fix workers (6) | Applied verifier V3's fixes from one shared brief, each owning a separate set of files; this session read every report, spot-checked the diffs and re-ran the scans | sdd-worker / Opus (4), Sonnet (2) |
The thirteen reviews and V2 were saved verbatim in reviews/round-2/. The fix PRs (#3964, #3965)
had their own implementers and fresh-context diff verifiers under Chris's separate authorisation;
they are not part of this package.
8.2 Live reads (read-only)¶
- GitOps. The cluster-gitops repository, read at the remote head, has
materializedProjectStatisticsFold: truefor staging's API and project management services (Chris's 1 October pilot decision). This corrected review MS, which had read a stale checkout. - Production and staging databases. A read-only count found no project storing a grant of ChangeOwner, AssignPermissions or Delete. A read-only count of legacy reconciled sessions in production timed out on an unindexed field and was not retried; it is recorded as an off-peak task before F4.
- GitHub.
gh pr viewandgh pr listfor the in-flight programme PRs; the refresh time is in programme integration §1.
8.3 Writes made (all authorised)¶
- Commits and pushes on the PR #3617 branch only, from about 19:00 (Chris's request), including one
merge of
origin/mainwhose only conflict,docs/planning/index.md, was regenerated withdocs/scripts/generate-indexes.sh. The PR #3617 description gained a section on this package.mkdocs.ymlwas regenerated withdocs/scripts/generate-mkdocs-nav.pybecause PR CI's navigation check failed on the new planning documents; the generator only added their entries. - Follow-up issues #3997, #3998, #3999 and #4000, filed from this session.
- #3964: Chris authorised the fix and its shipping on
a passing review and green checks, and chose it over #3969 (D1-01). It merged at
20:27 BST (merge commit
85e6facf7) after an approving review on its head and green checks; its description gained links to the follow-up issues, its worktree and branches were removed, and #3969 received a comment pointing to #3964. - #3617, step 0 (D1-05, approved by Chris on
3 October): the title and description were refreshed and
/claude-reviewwas requested on head1c8b1e84c. The review gave a "comment only" verdict with nothing blocking; it said it had not read the full prose. Its two non-blocking suggestions were answered on the PR: the navigation is left to the generator, and the lifetime trigger is added in the follow-up. After the review settled and the checks were green (docs validation passed on that head), it merged at 22:42 BST (merge commitf5318074d). Its worktree and branches were then removed. - #4002, opened with
wt new: records step 0 as merged and adds the package's lifetime (PROPOSAL) to the README. - No notification was sent, and no runtime code, migration, deployment or flag change was made by the planning work.
8.4 Documentation validation¶
./docs/scripts/validate-docs.sh --skip-indexes --skip-links, plus the anchor script. The link
check was skipped in these runs because it is slow across the whole repository; the anchor script
checks every relative link with an anchor in this package, and the
validator run in PR CI checks links.
| Run | When | Result for this package | Whole-repository result |
|---|---|---|---|
| 7 | After integrating the round-2 documents, about 20:00 | All package files pass front-matter checks; 205 anchored links resolve | Exit 0; 0 errors; 64 warnings, none from this package (the 64th came from main in the merge) |
| 8 | After the acceptance-criteria cross-file patches and fixture-name fixes, about 20:20 | As run 7; every AC, FX and contract test ID cited in the package is defined, apart from labelled round-1 review IDs | Exit 0; 0 errors; 64 warnings, none from this package |
| 9 | After verifier V3's 33 fixes, about 21:10 | All package files, including the saved V3 report and resolution brief, pass front-matter checks; 236 anchored links resolve under both slug rules (one renderer-specific anchor removed) | Exit 0; 0 errors; 64 warnings, none from this package |
| 10 | After recording Chris's Batch D1 answers, about 22:34 | All package files pass front-matter checks; 260 anchored links resolve under both slug rules; no pending-D1-… status remains |
Exit 0; 0 errors; 64 warnings, none from this package |
8.5 Limits of round 2¶
- No runtime, browser, database-write or deployment checks were made.
- Reviewers' code citations were adopted where the resolving writer re-read them; the matrix marks where a claim was corrected instead.
- Live PR and programme states are snapshots from 3 October 2026 and must be rechecked before any implementation decision.