# Connections — what actually runs real `packages/*` code (honest status)

> The harness's whole value is running the REAL cores, not stubs. This is the honest ledger of what's
> connected, verified adversarially (09-verify-python-bridge). The rule (SKILL/HARNESS.md): import the
> real code, prove it with an eval, and **never call a partial connection "done."**

For a one-page orientation, see [How it all works](HOW-IT-ALL-WORKS.md).

## Status

**Campaign Improvement current support:** the checked-in local application has
a caller-reachable Campaign Data Workspace for one trusted operator. It
retains one or more content-addressed CSV partitions, maps one or more logical
media relations from each partition, and freezes explicit source namespace,
grain, observed window, completeness, availability, lateness, and outcome-
maturity contracts. The optional model classifier receives bounded schema and
profile metadata only and proposes roles, fields, grains, and candidate
connections; invalid, unavailable, or unsafe output falls back to the canonical
deterministic classifier. Model-origin mappings require human ratification.
Connections measure the full ordered composite key over exact retained rows and
bind directional semantics, namespaces, observed cardinality, time alignment,
result grain, and measure preservation before they enter a revision. The local
adapter refuses cross-namespace equality without a supported ratified crosswalk.
Analysis-specific assessment and compare-and-set publication retain immutable
synchronized versions with explicit evidence limits. A release-bound descriptive
executor reads the exact retained sources, keeps physical and logical row bases
separate, persists the canonical content-addressed v4 result, and reopens
retained verified v2, v3, or v4 results without another upload. Browser, HTTP, typed
SDK, CLI, and eleven reference-only MCP tools use the same workspace identities;
MCP has no create/upload surface and accepts no rows, bytes, paths, cloud
locations, credentials, caller tenancy, vendor upload metadata, or ratifier
identity. Ask
Precise binds the exact current revision and latest exact-release result, sends
an allowlisted aggregate grounding, streams Markdown and tables, and returns
plain stale, budget, rate, timeout, incomplete, configuration, grounding, and
provider errors. The same composition
runs the non-synthetic single-campaign Board and the real campaign-book
historical evaluator with verified retained history. It does not materialize an
arbitrary workspace release into that evaluator. Hosted R2/S3/GCS onboarding,
a caller-reachable crosswalk workflow, an MMM executor, and a hosted backtest
worker remain open typed seams. The 0.2.1 image observed on 2026-09-02 does not
contain the local workspace, analyst, Python historical court, current neutral
`math` child, or default continuation workflows.

**Latest staging observation (2026-09-02):** private revision
`app_rev_4ac0c1d7` was healthy on OCI digest `sha256:97aac51b…f79c07` with 20
transitions and 17 input schemas. `report` and `band_basis` were served, the
by-name read returned `workspace-not-bound`, and event booking was armed on the
existing GCS application-state custody. No real producer outcome was observed,
self-heal was absent, and this revision predates the current neutral `math`
child and default continuation workflows.

**Historical staging observation (2026-08-24):** the private Cloud Run service
observed that day was Precise Gateway 0.2.1 with hosted GCS Product state, the
synthetic Campaign Improvement source, and the Product-owned
`trust-validation` child. It grades preregistered known answers and locked
rolling-origin historical holdouts produced by
`trace-calibration.walk_forward`, binds exact dataset/result digests, rejects
look-ahead and unsupported producers, and states the exact predictive and
causal evidence limits. An optional descriptor-declared data handle can project
one already-admitted, credential-free bucket/prefix/URI binding for connected-
bucket intake; it does not provide a managed upload service. Caller payloads can
choose neither a bucket nor a tenant, and a frozen snapshot remains mandatory
before execution. The three Trust command identities and deterministic Product
result refs were observed in the payload-free Boombox operation ledger. That
deployed revision contained no customer data binding, local CSV or snapshot-
analysis route, Ask Precise analyst route, direct managed upload, end-user
identity adapter, backtest worker, or Boombox neutral receipt binding.

**2026-08-21 standing Decision Learning Gateway bundle:**
This is the optional Campaign Improvement reference-app standing composition
(B), not the generic Gateway.
The tenant-bound Precise Gateway now mounts the Campaign Improvement BFF as one
standing Product composition. A recommendation derives its coalition game from
the named campaign read, opens the Call, and retains the exact pre-action close
context including the consumed learned-state ref and digest. Resolution ingests
the mature outcome through the same adapter used for every source class, applies
the real Mondrian default and exact descriptive finite attribution, authorizes
and records the update, re-verifies closure/v2, and projects the Board/history.
The next recommendation resolves and applies those exact learned bytes; a
different valid learned state changes the declared confidence range, while a
no-op update preserves decision fields. Restart, exact retry, race-safe state
pinning, and learned-state refusals pass.

`npm run build:gateway-bundle` now emits a deterministic unsigned
`application/vnd.boombox.app-bundle.v1+tar+gzip` archive and matching
ConnectorBundle. A black-box test extracts that archive, checks `/health` and
`/harness`, runs recommend → resolve → history through the real process, restarts
it, and reattaches byte-equal Product state. The published Boombox 0.13.2
descriptor validator accepts the effect-free harness-only descriptor after the
platform returns signed manifest and attestation references. This is packaged,
not live: the connector is unsigned by design, and no platform Deployment,
revision record, app-operation, consumer-authenticated door, metering, or host
Run is claimed. The published runtime and app-operation client are wired and
black-box tested against a fake lifecycle host; an app-operation never
substitutes for a Product judgment or `run_ref`. The joined evaluation is sealed
locally and verifiable offline; Precise does not deliver it to Boombox.

**2026-08-21 Call context signature:** `precise.call-opening/v2` now accepts an
optional, strictly validated `precise.call-context-signature/v1` containing only
caller-declared measurement context. When present it joins the opening hash,
replay, conflict, opened/closed Call, and episode projections; when absent it is
omitted from the canonical body so pre-instrumentation bytes and hashes remain
unchanged. Invalid supplied context refuses with
`call-context-signature-invalid` before persistence. The signature computes no
metric, grants no authority, and is not copied into closure authority.

**2026-08-21 Product custody adapter seam:** the optional Campaign Improvement
composition can now select one injected GCS Bucket host for Call opening,
optional Call Attestation, closure/v1/v2, Decision Learning primaries, and the
released public Boombox binding-receipt port. Both environment values—the named
bucket and safe Product prefix—are required together; the production composition
constructs the official provider Bucket with ambient ADC/workload identity and
accepts no credential input. Faithful fake-Bucket tests prove generation-zero
create-only writes, exact retry and conflict, cross-scope absence, tamper and
oversize refusal, lost-write-acknowledgement recovery, ref-index repair, and
fresh-composition reattachment of the complete synthetic closed episode. The
dedicated `gs://precise-product-call-custody` bucket and bucket-scoped runtime
IAM are live, and the first live create-only smoke against the real bucket passed on
2026-09-01 UTC under `scratch/live-custody-conformance`. The standing Gateway
has not been repointed to this bucket.

**Gateway capability and workflows (current repository):**
`precise.gateway-capability/v2` is a neutral catalog of mounted methods, paths,
input shapes, mutation flags, and opaque floor and eval references. It has no
rungs, claim ceilings, or Product-policy state machine. Reader access serves
`capability` and `status`; full authenticated access can invoke
`math methods/run/result/status/cancel` and
`workflow workflows/start/focus/outcome/result`. The four Precise continuing
workflows are `understand-the-book`, `find-the-next-move`, `design-the-test`,
and `measure-and-learn`. This code is connected in the default tree and
standing composition. It has not been deployed.

**Historical staging observation (2026-08-31):** revision
`app_rev_210390f` deployed an older capability build and answered through Cloud
Run IAM and the Gateway's peer lane. The observation proved the deploy pipeline
and rejection of an invalid assertion; it did not include a valid peer call.
That revision predates the current v2 catalog, `math` child, and four continuing
workflows, so it is not deployment evidence for them.

**2026-08-30 carrier + tenant rulings (platform lane, source-verified):** `x-boombox-peer-assertion` is THE canonical carrier — `BOOMBOX_PEER_ASSERTION_HEADER` staged platform-side (2045cb3d5), rides a cut after 0.14.8; our bearer read is compatibility-only until the constant is importable, and different tokens on the two carriers now refuse closed (tested). The peer verifier stays same-tenant on purpose; cross-tenant ships as a distinct platform-minted binding assertion (`binding_id` + consuming tenant as verified claims) with the binding store — consuming-tenant reads should prefer a verified binding claim and fall back to transport `tenant_id`.

**2026-08-30 admission shape ruling (Adam, via the platform lane):** admission is ACCOUNT-BOUND, not app-bound — the grant names the consuming account (covers every app it deploys and every successor credential; account revocation revokes all), collapsing same-tenant and cross-tenant into one admission grammar (grantee account → capability, access tier / admitted transitions, terms, lifecycle). Per-deployment scope survives only as transport anti-replay (assertion audience = deployment id). Our `tenant.callers` peer entries stay the working enforcement seam today but are provisional projections; the derive step keys on verified account identity, never the app sub, when the platform record ships.

**2026-08-30 pin 0.14.8 + §8 rulings + end-user compose:** exact `@konstantdotcloud/boombox@0.14.8` (integrity `sha512-jW95qZT1/kqcoSXpqWRRoyIKOKB5GhS1YmUnUMY5dEnmiHQlQYTv45HBi3dfxVMWKl8R/GmaiFI6Y7HtGcAZTQ==`, shasum `a7f27294be64965facdf00137c78bc1c88b8a1d8`, registry-verified; 0.14.7/0.14.8 were age-suppressed from plain `npm view` — the launcher's exemption applies); doctor converged (manifest, lock, installed, BOOMBOX_VERSION agree; skill mirrors regenerated, `boombox_skills` ok). The end-user assertion surface is BYTE-IDENTICAL 0.14.6→0.14.8, which was the adjudication the hold-gate stood in for — Adam dissolved the gate same day, and the compose landed: `createBoomboxPlatformEndUserAuthenticator` (kit verifier as an injected port; refusals map closed; kit `platform_verified` → seam `platform-verified`; dev-signer assurance preserved) + `armBoomboxPlatformEndUserAuthenticatorFromEnvironment` (null without injected keys), proven in `test/boombox-end-user-auth.test.ts`. `requireEndUserAuthenticator` still fails closed; NO deployment has login sequenced. Adam also ruled DECISION-SHAPES §8: all 19 defaults confirmed, Q10 amended (self-district GCS arming first; Polymarket road-B = first external estate) — recorded in that doc's §8 header; the Q3/Q4/Q5 vocabulary propagation is an authorized work order not yet landed.

**2026-08-24 package pin (evening):** exact `@konstantdotcloud/boombox@0.14.6` (integrity `sha512-+YP/PsKnpvYvJFP3Z/OFcKvicqE0Z+fnmJ9MHOV9i993dg6B/TyHJ/NDwuKymP5jEOpoC4HeXVTZYTJ6qJn2GA==`, shasum `b12b38da1318120e5a4e454790a3f5c976a64556`, registry-verified). 0.14.4 exists but predates the wave (a parallel-lane publish collision, resolved platform-side by a notes split and a semantic bump) and is not the pin. 0.14.6 carries the events kit surface (`verifyBoomboxApplicationEvent`, `boomboxPeerAuthorityVerificationEnvironment` — importable, verified), `boombox app refresh`, `boombox app orphans`, `boombox app dev-token`, and the typed `subject_kind` verifier return (verified in the installed d.ts). Platform-lane proofs attributed to that lane; doctor converged (sdk + skills agree on 0.14.6).

**2026-08-24 package pin:** canonical `harness/` now pins exact
`@konstantdotcloud/boombox@0.14.4` (devDependency and peerDependency) with
registry integrity
`sha512-pJrfEf06ufLRkHq3UBs20ScK0s2sL1L7vaTFPT7I3NE420gr7yMIRX515QBKdnDwaxHJV5/+Kl2BewsAu5KgmQ==`
(shasum `9feefe4f39ad25d9b0c8efd50ea7859d367435e6`, registry `latest`). The
platform lane reports this cut ships `secret_refs` v1 (version-pinned secret
files under `/var/run/boombox/secrets`, the app env name carrying the PATH),
`availability: "on_demand"` scale-to-zero for standing targets, and declared
developer access (`peer_ingress.developer_invokers` + a developer-authority
route minting host-key assertions with `subject_kind: developer`) with the
installed client validating and transmitting that declaration — all proved
live on the staging district by that lane, not re-verified here. Skill mirrors
regenerated from the installed package; `npm run doctor` reports `boombox_sdk`
and `boombox_skills` converged.

**2026-08-23 package pin:** canonical `harness/` now pins exact
`@konstantdotcloud/boombox@0.14.2` (devDependency and peerDependency) with
registry integrity
`sha512-pA+MvW9E5kxlZgo5n10eD2sXSW/TkIC32I6J8nVcfD0Jd7Ie3Q6Fvoj8RNbgzjmW9AlfWLwcvgEhG2TAWrsM8A==`
(shasum `a33020674516df8a4a8eb7e86e42bf6ac997a6e2`). The npm registry and the
live developer contract both report `0.14.2`; the platform lane reported the
0.14 cohort as released truth after public-surface equivalence, and this
repository relies on the registry integrity rather than re-verifying that
equivalence. `PRECISE_BOOMBOX_SDK_INTEGRITY` binds that registry artifact, the
package-owned skill mirrors are regenerated from the installed package, and
`npm run doctor` verifies `boombox_sdk` and `boombox_skills` convergence. Dated
0.13.2 statements below remain the record of what was proved at that release.

**2026-08-21 public receipt seam:** canonical `harness/` now pins exact
`@konstantdotcloud/boombox@0.13.2` with registry integrity
`sha512-ev8Mt2HWQihvLgUi2O8i9K/B8Pulb+rsOKYxFrM4ubcnxIxEhFZlFC7EcPyStqCeK5A8G+9FDk11Ax9HowDnZw==`.
The optional Campaign Improvement publication path consumes the released
`@konstantdotcloud/boombox/receipts` port through a Precise-owned Product mapper
and a conformant create-only file adapter. Package conformance, structured
tenant/sub-scope mapping, exact retry, changed-content conflict, tamper refusal,
cross-scope absence, same-process race, fresh-process reattachment, and
direct/Harness/authenticated HTTP/BFF/MCP parity pass. This advances the public
contract seam, not live hosting: the file adapter is local Precise custody,
hosted Boombox receipt custody and live Product-account tenant binding remain
open, and application/workload `run_id` plus lifecycle Receipts are separate.

**2026-08-21 Jordan/Decision Learning acceptance:** one deterministic
Product-build session at `git:180c27b3…` now binds the real optional Campaign
Improvement success eval, fired refusal eval, three actionable caller refusals,
five-field Call, closure/v2 episode, Board projection, canonical local
`boombox.evaluation.v1`, and verified Project attachment revision 3. A fresh
0.13.1 builder process recovered the Project, delivered payload-free evaluation
fact `bbevf_83668049ae37b23e36a9536f`, and listed/reopened answered Project Need
`bbneed_e3599616c03d2abee49c58b3`; the platform response names that Need thread
the canonical resumable help surface and declines a duplicate chat contract.
Cloud Build `82204b4a-796d-4ad1-9fe1-d3062b61ebac` published OCI digest
`sha256:f2b2b7e7…a81df85e` only after bundled page/MCP, Call/evaluation closure, first
container removal, and fresh-container exact reattachment passed. The
provider-free plan `app_plan_ea93f209b777092339ea5dcf` remains local and
non-authoritative. That dated 0.13.1 acceptance stopped there:
`public_lifecycle_client:unavailable`; it issued no application Deployment, Run,
customer session, hosted durable custody, or owner-gateway/WorkOS application
proof. The dated 2026-08-23 package-pin entry above is the current package
status; the dated 2026-08-21 sections are the record of what was proved at 0.13.2.
Exact receipts and owner-specific gaps are in [Campaign Improvement
→ Boombox black-box acceptance](CAMPAIGN-IMPROVEMENT-BOOMBOX-BLACKBOX-2026-08-20.md).

Every deployed or live statement below is a dated observation, not a claim that
the current repository is deployed. In particular, the current `math` child and
default continuing `workflow` child are absent from the recorded staging
revisions.

The intended Campaign Improvement path connects sources, retains one accepted
field map, takes the measured goal, automatically selects and composes fitting
workflows, and refreshes the answer as data changes while keeping the last
complete answer visible. Its real artifact projector must return the finest
supported controllable inputs—such as creative × channel × audience × placement
where the data supports them—with measured contribution, uncertainty,
interactions, current size, and marginal value ready for a proposed move.
Unsupported dimensions remain missing, and measured decomposition is not a
causal claim. Workflow identifiers and method comparisons are drill-down;
Calls, actions, and outcomes stay in Product state. That Campaign compiler and
projector are not built yet.

| Core | State | What's real | What's NOT (the honest gap) |
|-|-|-|-|
| **Jordan Product-build session + Decision Learning evaluation return** (`harness/src/testing/campaign-improvement-developer-session.ts` + `harness/src/decision-learning-evaluation.ts`) | **REAL LOCAL PRODUCT/EVALUATION CONTINUITY + LIVE PROJECT NEED/FACT RETURN · OPTIONAL WORKED APP** | One deterministic public script runs without login or a machine-local attachment and binds exact committed source, a passed useful eval, an actually fired refusal eval, three actionable caller refusals, one five-field Call and closure/v2 episode, its Board projection, and one canonical Project-local `boombox.evaluation.v1`. It constructs a fresh composition over the same stores and requires exact episode/projection/evaluation reuse; the retained receipt is create-once. A connected caller may additionally supply a verified Project attachment, and optional service-fact delivery (first live-proved at package 0.13.1) is live-proved accepted/unchanged with an empty outbox. The evaluation adapter re-verifies Product custody, refuses invented judgment/Run/deployment/Crossfade/Arranger lineage and raw payload-shaped fields, and cannot block Product work on capture failure. A hosted composition may instead supply one exact, strictly shaped application-revision `record_ref`; direct, Harness, and HTTP callers then seal a distinct create-once deployment-linked evaluation and reattach it unchanged after restart while `run_ref` remains absent. The package-pinned published runtime adapter sources that binding from the active host injection, and its extracted-bundle test proves the joined evaluation stays local. | The local Product-build receipt and rich evaluation are Precise custody, not hosted runtime state or promotion authority. In the current package-pinned scope, the joined evaluation is sealed locally and verifiable offline; Precise does not deliver it to Boombox. The later host evaluation-delivery route is a Boombox contract, not a hidden developer credential or Precise-side workaround. Campaign Improvement remains an optional cloneable example, not the generic Product shape. |
| **Generic manifest-driven app road** (`harness/src/app-manifest.ts` + `harness/src/app-gateway.ts` + `harness/src/app-auth.ts` + `harness/src/app-gateway-client.ts` + `scripts/precise-app-new.mjs`) | **REAL LOCAL GENERIC APP ROAD · PACKAGED STATIC-BEARER CALLER AUTH** | A blank `precise.app/v1` manifest loads and serves. The app Harness proves the useful path plus three firing floors: `app-node-unknown`, `app-caller-not-allowed`, and `app-tenant-header-refused`. The typed client reports secret-hygienic `APP_GATEWAY_UNREACHABLE`. Campaign Improvement remains an optional clone; its optional `evaluation_capture: "local"` journal records `run_ref` as absent:not_applicable, loads lazily, and reuses byte-stably across fresh processes. `npm run precise:app:bundle -- --slug <slug>` is locally proved to emit a deterministic unsigned app-bundle and ConnectorBundle; it is not a hosted connection. Gateway caller authentication accepts an exact injected `tenant.callers` identity independently of the app-facing `auth.mode`; missing credentials, unallowed callers, and caller-supplied tenant headers refuse. | The packaged local caller-auth helper is the static bearer. `auth.mode` describes end-user/app-facing authentication and is not a selector for that caller authenticator; generated blank and cloned apps declare `none`. The repository now has `createBoomboxPlatformEndUserAuthenticator` plus environment arming over the pinned kit's end-user assertion verifier, and `requireEndUserAuthenticator` still fails closed when required verification keys are absent. No direct customer-identity-provider adapter, deployed WorkOS front door, production end-user session, or hosted subject-runtime proof exists. |
| **Gateway math and Precise outcome workflows** (`harness/src/gateway-default-math.ts` + `harness/src/precise-workflow-service.ts` + `harness/src/workflow-continuation.ts`) | **REAL DEFAULT-TREE AND STANDING COMPOSITION · NOT DEPLOYED** | `precise.gateway-capability/v2` describes the mounted neutral method catalog without rungs or Product policy. `math methods/run/result/status/cancel` exposes 17 dependency-light methods and seven release-bound worker methods in the full development composition, with method-specific schemas, tenant-bound immutable terminal results, exact retry, direct/HTTP parity, item/sample/time controls, and no global 16-item cap. `workflow workflows/start/focus/outcome/result` exposes `understand-the-book`, `find-the-next-move`, `design-the-test`, and `measure-and-learn` plus focused graphs; it resolves exact mounted method versions, runs independent DAG steps concurrently, retains raw Gateway refs, compares adversarial variants, and appends duplicate-safe cycles through authenticated outcomes or the signed subject-head path. Local-file and generation-checked GCS stores cover runs, workflows, and outcome bytes. | `math run` is synchronous: queued/running state is process-local and an active method call does not resume after restart. Standing without worker URLs exposes only the 17 dependency-light methods; remote workers require immutable release digests. The signed path expects an authorized Product/host producer to land outcome bytes before the pointer event; there is no unauthenticated write route. No recorded staging revision contains this current math and continuation build. See `GATEWAY-PRIMITIVES-AND-MATH.md` and `GATEWAY-WORKFLOW-BUILD.md`. |
| **Trust Portal workflow reader** (`packages/campaign-improvement/src/lib/server/trust-workflow.ts` + `TrustJourney.svelte`) | **REAL LOCAL READ-ONLY PRODUCT PROJECTION · NOT DEPLOYED** | The `/trust` route is now becoming an operating modeled-example decision view backed by the read-only workflow projection. Its adapter reads the workflow catalog and a retained result while preserving workflow version and implementation identity, workflow-owned findings, comparisons, diagnostics, run references, and outcome references. | This is not a workflow execution caller. It does not call `start`, `focus`, or `outcome`, compile Campaign Improvement records into method inputs, or project raw workflow output into a real Campaign Board, Ask answer, Decision, Goal update, Report, Decision Learning record, or decomposed controllable inputs ready for a move. The existing direct Shapley, holdout, and Next-Dollar paths remain canonical until that Campaign caller and projector exist. |
| **seal** (`precise-gateway/chained-seal-reference`) | **REAL LOCAL REFERENCE** | imports public `canonicalJson`/`sealOver`/`verifyChainedSeals`/`GENESIS_PREV_SEAL`; canonical JSON is re-exported from the real `@precise/research-core/hash` core; the captured pre-split bytes and Harness chain parity pass | Durable ledger custody and Merkle/AliceNet anchoring remain outside this pure local reference; `anchored:false` until an owned production port is connected |
| **contribution and finite attribution** (`trace_exact` + `trace_approximate` + `compute._make_value_function`) | **VERIFIED-PARTIAL** | `shapley_harness.py` runs the **real production value function** (`_make_value_function`) + the real exact/CC estimators. The default `precise attribution` node separately accepts a complete domain-neutral coalition game and runs canonical exact Shapley/interactions/Owen through 16 players or sampled CC through 20. Both use the TS-controlled fail-closed bridge, stdin for large payloads, and a pinned Python hash seed; 2 MiB transport and exact-16/sampled-17 boundaries are regression-tested. The portable SDK exposes an injected long-lived-worker core. | Exact remains settlement authority; sampled CC remains research-only and cannot invent missing coverage/df/CIs. Attribution explains a measured game; it is not information value or a strategy generator. Production-value routing is **exact/CC only** — parallel/cc_fast/additive_exact need a picklable value-spec; only the **`cac`** KPI family is driven; no media scanner consumes the finite-game result yet. |
| **advocate loop** (`advocate.harness.ts`) | **PARTIAL (the spine RUNS)** | Wrap→Propose→Gate→Act→Receipt→Sharpen composed from real cores: exact φ + par gap + the 4-predicate Move-Card gate + the real gateway seal + the reward-join; runs end-to-end + sealed, tested | Propose uses exact φ + a **caller-supplied** move (the ∇v̂ frontier is next); **Act is hand-off** (no real dispatcher); Sharpen null until real data |
| **runtime** (`precise <child> <cmd>`) | **REAL** | `dispatchTree`/`resolveNode` — every documented command now routes down the tree (was a 404); tested | auto-discovery still hand-registered (`backlog.ts` `harness-autodiscovery`) |
| **Product-build continuity** (`@precise/harness/product-build`) | **REAL GENERIC LOCAL LEDGER · BINDING-ONLY PROOF MATURITY** | The default tree exposes `session-open`, `attempt-record`, `attempt-prove`, and `session-inspect` over create-only memory and file stores. One record binds a named user and desired outcome to the current repository, ordered developer attempts, opaque identities from their owning issuers, and one passed-useful-eval plus actually-fired-refusal pair. Exact retries preserve the original timestamps across later clocks; changed semantic content conflicts. A ref cannot change from deployment to run or another identity kind across attempts, while same-kind retry reuse is allowed. Inspection follows the latest attempt so new unproved work stays visible. Unit tests, Harness evals, CLI-shaped input, file reattachment, SDK export, estate coverage, and the real refusal floors pass. | This ledger mints only Product-build session and developer-attempt IDs. It is not a runtime Product session, Boombox deployment, logical run, run attempt, or approval gate. `attempt-prove` currently binds caller-supplied content addresses but does not dereference the evidence bytes; the record is honest local continuity, not external verification or promotion authority. Hosted custody, Project/thread binding receipts, runtime operation joins, and evidence dereferencing remain separate typed seams. |
| **Decision Learning Call and verified Product closure** (`@precise/research-core/call` + `outcome-map` + `decision-brief-route` + `decision-learning-episode` + `product-learning-authority` + `@precise/harness/decision-learning`) | **REAL CALL-BOUND CLOSURE/V1 + ADDITIVE CLOSURE/V2 LEARNING VERTICAL** | The existing `episode-close`, `episode-inspect`, and `verify-episode` surface remains the strict closure/v1 path. Explicit `episode-close-v2`, `episode-inspect-v2`, and `verify-episode-v2` commands add exact Outcome Map, Outcome Window, mature baseline observation, Decision Brief, Decision Route, and optional independent Call Attestation primaries without rewriting v1. Both schema writers share one serialized closure-family authority and create-only custody, so the same Call cannot acquire both closure schemas. Closure/v2 binds the frozen Forecast, actual Action Exposure, mature Outcome Observation, derived Forecast Score, one exact-additive descriptive post-action outcome decomposition, explicit `not_identified` records for the other analysis kinds, and one Learning Decision `update`; Claim Judgment remains explicit null. The update re-verifies one retained `precise.product-learning-authority/v1` rights label through the existing primary resolver and refuses an ungranted target class. Closure/v1 remains byte-compatible and accepts only Learning Decision `none`. The closure copies no primary payload. Baseline and Product-learning authority verification run before semantic issuance or persistence. Retained verification rechecks optional Attestation, Action Exposure, both Outcome Observations, the rights label, and closure Receipt without semantic reissuance. Exact retry is byte-identical and performs no resolver, evidence verifier, or issuer work; changed content conflicts. Direct core tests, typed Product client, runtime JSON codecs, HTTP, portable SDK, success eval, tenant and learning-authority floor evals, local closure-family custody, and injected generation-zero GCS custody against a faithful Bucket fake pass. The dedicated `gs://precise-product-call-custody` bucket and bucket-scoped runtime IAM are live, and the first live create-only smoke against the real bucket passed on 2026-09-01 UTC (five checks: create-once ifGenerationMatch:0, exact-retry same-generation, changed-bytes 412 refusal, fresh-client read-back, prefix isolation); the full recovery/repair/episode battery remains proven against the faithful fake only. | This is not all of Decision Learning. The other three identified analysis kinds, independent non-null Claim Judgment, non-weight default targets, no-Call identity, successor/restatement lineage, training materialization, and correction semantics remain unbuilt. Local files and the injected GCS implementation are Product-owned custody adapters; the standing Gateway has not been repointed to the dedicated bucket, and no production semantic verifier has proved the hosted composition. The Call and closure do not grant learning authority; the separately retained rights label does. |
| **Decision Learning outcome ingestion** (`@precise/harness/decision-learning-outcome-ingestion`) | **REAL PRODUCT NAMED-READ PORT + INJECTED BIGQUERY READER / LIVE CONNECTION OPEN** | One Product-owned adapter resolves exact tenant, decision, Product, workflow, outcome, horizon, units, direction, aggregation, evidence design, and custody before reading. It accepts synthetic and customer source classes through the same path, validates one mature row, binds source and job evidence, enforces freshness, timeout and `maximum_bytes_billed`, refuses multi-row or missing results, and has no live-to-fixture fallback. The BigQuery adapter takes an injected query client and one named table; deterministic tests prove the useful path and the scan-budget floor without adding an SDK dependency. | No live customer table, production source attestation, provider credential composition, Upload, Author, API-landed snapshot, or hosted connector grant is claimed. This is the Product meaning/read seam; credential custody and generic ingress remain Boombox or infrastructure responsibilities. |
| **Campaign Improvement reference-app standing Gateway (optional)** (`@precise/harness/always-on-precise-gateway` + standing app-bundle) | **REPOSITORY-CONNECTED PRODUCT SERVICE · HISTORICAL STAGING OBSERVATION (2026-09-02)** | The public client exposes `status`, `learn({decision_id})`, `history`, `exportCampaign(...)`, and `campaignTrackRecord(...)`. The repository composition adds the Campaign Improvement BFF, report and track-record custody, signed-event intake, restart-safe Call and learned-state records, named workspace result reads, and `precise.result-envelope/v1` responses. It can close a mature Call, learn, open the next Call, and seal the graded and next Boards. On 2026-09-02, `app_rev_4ac0c1d7` was observed on private staging with twenty transitions, seventeen input schemas, `report`, one real recommendation response, a by-name `workspace-not-bound` response, and the event door armed. The earlier `app_rev_fb9de789` observation was on 2026-09-01. These are dated deployment facts. Neither revision contains the current neutral `math` child or the default `workflow workflows/start/focus/outcome/result` service. | The observed 0.2.1 source is synthetic. No real signed producer outcome has arrived. The observed revision has no customer dataset binding, local CSV or snapshot-analysis route, Ask Precise route, managed upload, hosted model, end-user login, production source, neutral Trust receipt publication, current Gateway math catalog, or four Precise continuing workflows. The ten campaign-book slice reads and other later repository additions also need a new admitted artifact and deployment. The BigQuery producer that materializes campaign-window outcomes is not built. Campaign Improvement remains one optional Product composition, not the generic Gateway shape. |
| **Media Next-Dollar Decision Learning Product caller** (`packages/surfaces/core/src/options/next-dollar.ts` + `harness/src/media-next-dollar-decision-learning.ts`) | **REAL RECOMMEND-ONLY PRODUCT VERTICAL · OPTIONAL WORKED APP** | The explicitly selected Campaign Improvement attachment imports the canonical `nextDollarCurve` and `priceMove` core through a narrow injected port; the generic tree imports neither this core nor this media Product adapter. A strict runtime codec freezes the exact modeled intervention and ordered uncertainty band into a content-addressed recommendation, Decision Brief, Decision Route, Forecast, and one create-only Call. The selected path retains exact Map, Window, baseline, explicit analysis dispositions, Brief, Route, and Forecast in shared Decision Learning primary custody; verified actual exposure and a mature outcome then close and re-inspect through closure/v2. Direct core, Product preparation, in-process Harness, authenticated HTTP, Precise publication, thin-BFF, MCP, exact retry, portable SDK, deterministic optional-attachment eval, estate coverage, and the no-positive-route and cross-tenant floors pass while preserving the exact Product result. The no-cloud eval uses the generated historical `olv16` snapshot and is not live customer evidence. | This caller recommends only and has no activation, execution, Product-learning, network-learning, commercial, or promotion authority. It is one cloneable worked Product choice, not a generic Harness primitive or assignment. A negative modeled move refuses before primary or Call writes. Identified post-action analyses, TimeWalk, live customer source/authority, and production custody/verifiers remain unbuilt. |
| **Media Next-Dollar publication + public Boombox binding receipt** (`harness/src/media-next-dollar-publication.ts` + `harness/src/binding-receipt-reference-file-store.ts` + `harness/src/boombox-binding-receipt-gcs-store.ts`) | **REAL PRECISE PRODUCT ADAPTER + PUBLIC PACKAGE-PINNED CONTRACT / CONFORMANT FILE AND INJECTED-GCS CUSTODY · OPTIONAL WORKED APP** | The Precise-owned adapter preserves the exact recommendation or refusal and maps its Product records into canonically ordered opaque `{name,ref,digest}` bindings. The exact package-pinned `@konstantdotcloud/boombox` supplies `boombox.binding-receipt.v1`, deterministic receipt identity, offline verification, and `runBoomboxBindingReceiptConformance`; both Precise custody adapters pass it. Precise tenant paths map deterministically to one platform tenant plus ordered sub-scope. The file adapter proves atomic local reattachment. The injected GCS adapter adds generation-zero create-only by-key and by-ref objects, bounded gzip, lost-write-acknowledgement recovery, ref-index repair, race serialization, cross-scope absence, tamper refusal, and fresh-composition reattachment against a faithful Bucket fake. Product-refusal preservation, SDK export, real success/refusal evals, and direct/Harness/authenticated HTTP/BFF/MCP parity pass. The composition loads only with Campaign Improvement; the generic tree remains media-free. The dedicated Product bucket and shared content-store adapter passed their first live create-only conformance run on 2026-09-01 UTC. | The binding-receipt-specific adapter has not yet run live, and no deployed Boombox host uses the dedicated bucket. Binding receipts are run-less and grant no effect authority; application/workload `run_id`, admission, and lifecycle Receipts remain separate. Live tenant identity, effect admission, hosted reattachment, and deployment remain open. The older `precise.local-binding-receipt-reference/v2` implementation and policy-to-price-to-verdict/OPE demo remain quarantined legacy context, not the canonical primitive path. |
| **Named campaign decision-context read** (`harness/src/media-campaign-decision-context.ts` + `harness/src/campaign-dataset-analysis.ts`) | **REAL PRODUCT-LOCAL NON-SYNTHETIC READ + VERIFIED PORTABLE CONTRACT · CONNECTED SOURCE OPEN** | A strict tenant- and acting-for-bound command returns one content-addressed campaign context with source time, freshness, scan budget, timeout, materialization policy, job/bytes/cache facts, current outcome, segments, and evidence refs. Product-local mode derives the read from one tenant-scoped create-once CSV source and immutable snapshot, reconstructs and verifies the retained source/snapshot/analysis on every read, and reattaches the same Board after restart. Ambiguous match keys require explicit confirmation; unmatched rows, collisions, and raw-row containment are tested. Explicit fixture mode remains available for synthetic closure tests. The portable contract also has authenticated HTTP parity, a parameterized injected BigQuery reader, and total absent/stale/over-budget/signed-out/expired/unmandated/wrong-tenant refusals. There is no live-to-fixture fallback. | No connected customer reader, direct managed bucket upload, BigQuery SDK composition, production authority adapter, Boombox Product-account bind, or deployment exists. Product-local CSV support is callable repository software, not evidence that a customer bucket or hosted source is connected. |
| **Campaign Improvement Workspace, descriptive result, BFF, Board, Backtest Brief, MCP, and analyst** (`harness/src/campaign-data-workspace.ts` + `harness/src/campaign-data-workspace-result.ts` + `harness/src/campaign-improvement-bff.ts` + `harness/src/campaign-book-backtest.ts` + `harness/src/campaign-improvement-mcp.ts` + `packages/campaign-improvement`) | **REAL LOCAL ONE-OR-MANY-SOURCE CUSTOMER DATA + V4 CAMPAIGN DECISION BOOK + FILE OR POSTGRES CUSTODY + STANDING HTTP RESULT PATH · STREAMED ANALYST** | Product-local mode accepts bounded CSV bytes into create-once file or Postgres custody. The workspace keeps one or more physical partitions, one or several logical relations per file, source namespaces, time contracts, measured connections, and immutable saved versions. The public result run accepts only workspace, release, and exact revision identities, derives its request identity inside the Product, reads the sources already bound to that release, persists `precise.descriptive-workspace-summary/v4`, and reopens verified retained v2, v3, or v4 results by `result_ref`. The v4 result supplies the server-built campaign decision book, exact attribution-model output or a typed absence, and an **Over plan** queue chip when a declared limit is exceeded. Campaign Data Workspace Result child 0.4.0 exposes run, list, and inspect. Its Northstar v4 book eval and its arithmetic, collided-edge, zero-denominator, single-row, and unavailable-calculation refusal evals pass. The standing Result transport sends the same real payloads over local HTTP, preserves refusals, rejects malformed responses, and fails closed when the service is unavailable. The SvelteKit UI, HTTP, typed SDK, CLI, and eleven reference-only MCP tools resolve the same workspace and result identities; MCP has no create or upload tool. Ask Precise uses the latest exact-release result, validates every completed answer, and states whether the answer came from the provider, the Product's fixed answer, or saved session state. The single-campaign path reconstructs the non-synthetic Board from retained bytes, and the campaign-book path runs its delayed-outcome historical comparison through the real `trace_calibration.eval.walk_forward` process with verified retained history. | The descriptive result is observational and does not materialize an arbitrary workspace release into the historical runner, causal analysis, or MMM. Direct managed upload and connected R2/S3/GCS onboarding remain an open Boombox capability. The local Product has no caller-reachable cross-namespace crosswalk workflow or MMM executor. The Boombox application builder has no database-URL handle for the results composition, so hosted Postgres apply is blocked. The Python court is a local subprocess, and the live private 0.2.1 revision contains neither it nor the workspace/analyst additions. Hosted data custody, backtesting, model routing, end-user identity, Product-account MCP admission, deployment, and customer release require their admitted ports. No activation or external effect is performed. |
| **Grounded chat capability** (`harness/src/grounded-chat` → `@precise/harness/grounded-chat`) | **REAL DEFAULT-TREE LOCAL CAPABILITY / TWO PRODUCT CALLERS** | The dependency-light node is mounted at `precise app grounded-chat`. Its four registered, network-free evals prove wrong-number withholding, stale-resume 409 before provider use, a Product-authored answer with zero provider calls and usage, and subject-isolated thread storage. Both Campaign Improvement analysts delegate grounding, decoding, deterministic answers, auxiliary events, and final answer checks to the canonical core. The SDK also retains deterministic fake-transport coverage for request bounds, storage restart, rolling compaction, budget checks, aborts, and once-only metering. A local Doppler-backed smoke completed a real Cloudflare AI Gateway model call. Run `npm run precise -- app grounded-chat eval` or `npx tsx examples/grounded-chat-robustness.ts`; see `BUILDING-A-GROUNDED-CHAT.md`. | The mounted node qualifies the reusable mechanism; every Product still supplies and proves its own allowlist `ground()` and consistency `floor()`. No hosted chat service, production store, production secret delivery, or customer-session proof exists. |
| **Portfolio Select** (`harness/src/portfolio-select` → `@precise/harness/portfolio-select`) | **BUILT LIBRARY / FLOORS FIRING / NO PRODUCT CALLER / SHADOW RACE UNSETTLED** | The lazy `select` harness wraps a pure, independently re-derived public-math core: candidates carry spine-settled expected net return per dollar and visible shrink weights; the content-addressed overlap kernel admits only provenance-bound, PSD-verified features; the output is a realized-pending sealed test-book call with water-filled allocation and itemized redundancy. Three deterministic evals fire the quality, measurement, and soft-diversity floors, and `select-shadow-plan-vs-incumbent-holdout` freezes both plans, requires disjoint support, settles held-out net return per dollar, and books a thin-window loss as provisional. Venue-neutral parity fixtures pin `desk@9c56c9d`; no desk or Konstant implementation source is carried here. | First wedge: test-book selection. Deployment remains unavailable until the desk-parity `0.8/0.2` kernel mix and shrink schedule are re-fit on Precise settle history and one real disjoint-support race settles. The command has proposal authority only; it cannot spend, deploy, or act. |
| **Saved workflow definitions** (`harness/src/saved-workflows.ts`, hidden lazy registration `workflow`, alias `saved-workflows`) | **DEFINITIONS + SYNCHRONOUS RUNNER / NAMING COLLISION / NO DEPLOYED MOUNT** | Selecting `precise init workflow` loads the separate lazy harness. Its `save/list/show/run/run-result` commands retain canonical `precise.workflow/v1` definitions, resolve a name head or pinned hash, claim deterministic runs, invoke tenant-scoped Harness commands, and seal `precise.workflow-run/v1`. GCS uses create-only content plus generation-CAS definition and run heads; exact sealed retry does not execute again. This harness also reports its name as `workflow`, which collides with the default outcome-continuation child even though their commands and record families differ. | This is not the default `workflow workflows/start/focus/outcome/result` service. The saved-definition runner is synchronous and in-process, emits no usage atoms, and has no deployed mount. Mutating steps, event triggers, track-record projection, and user filtering remain absent. The two surfaces need distinct public names before both can be presented together without ambiguity. |
| **Gateway self-heal** (`harness/src/gateway-self-heal*`, lazy + standing optional child) | **STANDING MOUNT IN CODE / ABSENT FROM THE OBSERVED STAGING REVISION** | Behind the existing complete signed-event environment gate, the standing entrypoint mounts `gateway-self-heal` and subscribes the fixture-pinned `boombox.deployment-uptime-notice/v1` kind on the ordinary `/boombox/events` verifier and ledger road. `uptime/notice-received`, `uptime/remediate`, and `uptime/remediation-result` read the required notice facts without rejecting extensions, deduplicate by `notice_id`, refuse a stale failure run, select rollback then pinned redeploy then page, and seal `precise.remediation/v1`. The Product GCS custody packet keeps create-only notices and records plus generation-CAS notice and target heads under `remediation`; a fresh fake-bucket composition reopens the result. Lazy/local use remains process memory and says so in served state. Rollback and pinned-redeploy take artifact, manifest, target, actor, and Boombox config refs only from the deploy-road environment or the explicit composition binding feeding the checked-in assembler; any incomplete set leaves the child absent with `remediation-target-unbound`. No apply ran here. | The 2026-09-02 staging revision `app_rev_4ac0c1d7` did not mount this child. The platform slice-1 ping still owes the real kind string and signed notice sample; the intake test is pinned to the ledger's §14.1.1 fixture until then. Paging stays a stub until an admitted tenant-scoped pager returns a durable delivery receipt. No timer, service probe, pager binding, apply, or deployment of this child is claimed. |
| **Measured capture tape** (`harness/src/capture-tape` → `@precise/harness/capture-tape`) | **REAL LIBRARY / NO PRODUCT CALLER** | Size-cutoff reference math, injected in-band weighting, self mass, and zero-floored external mass reproduce four venue-neutral desk vectors pinned to `desk@e09d1fc772005fab7739caad989d8b004ff9a5c2`. One shared rule object binds tape and netting. The new append-only recorder owns raw-reference fallback and retains source, window, netting declaration, retrieval time, payload hash, tape ref, and recorder identity in memory or local JSONL. Seven lazy-lane evals prove the differential, fixture provenance, tamper detection, neutralization, and both firing floors. | No Precise product calls it; no hosted recorder, tenant custody, cadence, or telemetry is connected. The library measures and records only—it cannot allocate, activate, execute, or convert model-implied mass into measured evidence. |
| **Campaign Improvement decisions surfaces** (`packages/campaign-improvement` Decisions + Seats + Goals + Reports + Ask + Rules + Playground) | **REAL LOCAL PRODUCT SURFACES / HOSTED SUPPORT UNCHANGED** | The SvelteKit application has five linked areas. Decisions starts and reopens analysis, shows the goal track record, and renders a configured simulated AdCP pending-buy queue. Seats projects the money map, source aliases, file-upload connection, connection surfaces, and named future rows from the real media-seat registry. Goals creates flight or compounding goals with a complete measure identity and links calls to them. Reports mounts standing questions, a two-release demo history, the over-time correction record, tracked one-page exports, matching JSON and Markdown companions, and checked Monday-note and client-email drafts. Ask is object-based and the anchored assistant can return a validator-checked draft call. Rules names structural and declarable limits. Playground completes the synthetic allocation, call, outcome, and score loop. | This is local trusted-operator support. Vendor connection machinery is not built. Standing questions run on data arrival; calendar scheduling still needs durable jobs. AdCP pricing remains simulated and no live seller relationship is claimed. A local approval records tenant and surface, not a verified person. The assistant drafts but does not send. These repository additions are not present in the observed hosted 0.2.1 image. |
| **Precise seat overlay** (`@precise/seat-overlay`) | **VERIFIED LOCAL BROWSER PACKAGE / MANUAL CHROME REGISTRATION** | The Manifest V3 package builds a content script with no background process. Fixture tests cover the Playground and one The Trade Desk campaign-list layout, reject a similar table on an unrelated host, price the visible rows through the shared core, create a local draft link without sending, send a snapshot only after the explicit action, and refuse non-loopback destinations. | Chrome registration is verified manually after build. The package claims no other vendor layout, vendor API access, hidden-row access, analytics, telemetry, background service, vendor write, hosted distribution, or live browser deployment. |
| **Decision Learning Call Attestation** (`@precise/research-core/call-attestation` + `harness/src/call-attestation-file-store.ts` + `harness/src/call-attestation-reference-verifier.ts`) | **REAL PORT + NON-CRYPTOGRAPHIC LOCAL REFERENCE ADAPTER** | `call-attest` and `verify-call-attestation` preserve one `precise.call-attestation/v1` through direct core, Harness, typed client, authenticated HTTP, SDK, eval, and fresh-process file reattachment. The record binds the exact retained opening hash to tenant, principal, acting-for mandate, Product, capability, release, signer, signature content bindings. Deterministic verifier issuance, concurrent/retry conformance, side-effect-free retained checks, changed-content conflict, contextual substitution refusal, byte ceiling, and tenant floor are exercised. Closure/v2 may bind the exact Attestation primary and rechecks its retained verification on inspect; closure/v1 remains unchanged. | The default tree verifier is deliberately labeled non-cryptographic reference assurance; it proves the verifier port but does not validate signature bytes or establish production identity. Production must inject an approved verifier. Attestation remains an independent primary; inclusion in closure/v2 does not grant action, learning, or identity authority to the closure. |
| **v̂ model** (`vhat.ts`) | **POC** | glass-box amortizer recovers exact Shapley on-form, bounded gap off-form; flows through `runContinuous` | the **∇v̂ gradient** (the decision) unbuilt — additive can't curve; real training gated on a corpus |
| calibration (`calibrator.ts` + `calibration-harness.ts` + tree node) | **REAL AND MOUNTED** | The default `calibration` node imports the real Mondrian split-conformal core. Its strict `band` command consumes held-out absolute residuals, returns a `projection-error-only` interval, uses the group band when supported, falls back to the pooled global band for thin groups, and returns an infinite interval when evidence is insufficient. The useful eval proves a non-echo Mondrian band and the floor eval fires on an empty corpus. The always-on Product composition uses this same core for its mounted default. | This proves the implementation and its refusal behavior, not empirical live-customer coverage or causal uncertainty. A displayed coverage claim still requires compatible retained cases; the calibrator cannot turn missing evidence into a finite band. |
| **decision** (`surfaces/core` next-dollar) | **REAL (imported)** | `decision.harness.ts` imports `nextDollarCurve`/`priceMove` (not a copy); the advocate's Propose now uses the real priced frontier (Δ + honest band), not a caller-supplied move | the **measured** frontier + heuristic band — the learned **∇v̂** gradient is `gradient-vhat` (build-now) |
| **PMXT v2 historical evidence** (`pmxt-v2-book-state` + `pmxt-v2-research-tape` + `pmxt-v2-edge-feature-tape`) | **VERIFIED-PARTIAL, RESEARCH-ONLY** | `polymarket-pmxt-evidence.ts` calls the real reconstruction, tape, feature-game, and canonical Precise attribution cores; powered fixtures prove the route can settle a complete game and underpowered fixtures refuse | The first GCS range manifest is honestly incomplete at 2,199/2,202 hours. Parent-artifact replay binding, execution-batch replay, resolution authority, prefix-invariant features, mirrored outcome arms, and typed fee scenarios remain hardening gates. PMXT is third-party **L2**, not L3; no fill, queue, signer, order, or empirical-edge claim is available |
| **Polymarket maker lanes + exact settle + event-time court** (`lane-container` + `lane-settle` + `event-time-court` + maker evidence lake) | **VERIFIED-PARTIAL / NO-ORDER LAZY ATTACHMENT** | `npm run precise -- init polymarket-lanes describe` loads the small `polymarket-lanes` registration (`poly-lanes` alias) only on request. Its eleven commands retain the real lane/callsheet/frozen-config reads, add `lanes.event-court.run` and `.status`, verify A4 written governance criteria, back-score the old and corrected Lane T replicas on one fixed population, plan no-order liquidation under the aggregate-book refusal, execute the deterministic overlay-net quote/no-make gate, and expose exact settlement plus its latest immutable read. P1 is now the first real default lane-container tenant: the registry boots it in shadow with exact $960/$300/$100 caps, a namespaced sealed journal, doctrine-8 re-center-before-suppress-before-complement ordering, and no-send place/cancel/merge recording. The event court extracts cancel-burst/spread-move episodes, freezes cancel acceleration, spread velocity, and point-in-time TWAP fair divergence, walks displayed bids for the paired FLOOR-7 immediate-exit versus 60-second-hold estimand, dollar-weights the result, and block-bootstraps underlying × resolution-date clusters. Run seals a verdict only after 1,000 episodes over 14 regime-diverse complete days; status and the named floor retain the countdown without outcome authority. Fourteen evals prove the original reads, P1 shadow registration, real settle route, supported overlay and event-court paths, fixed-population replica comparison, and every declared support/freeze/governance/liquidation/incomplete/ratio refusal. The maker config remains pinned at `sha256:efd99ce3…7617`, and no order command, signer, authenticated trading client, automatic sizing, or capital authority enters the harness. | Read-only inventory on 2026-08-21 found 16 EU archive hours (04–19 UTC) but no complete daily manifest, so the event court is correctly at 0/1,000 admitted episodes and 0/14 days; no real outcome or verdict was read. The corrected a8b33efd Lane T replica admits 0/152 eligible CS38 observations, so corrected EV/CI/win rate are unestimable and the old +$9.82 edge does not survive. The CS22 overlay estimate still has only two settle days, allocated rather than venue-native per-market overlay, and 316 right-censored placements. P1's amended prereg remains unsigned, its shipped registry remains `shadow`, and its separate network-denied Mumbai unit is fixture-verified but undeployed; live still requires Adam's signature plus an exact signed registry hash. The weekly settle units and state-ledger mirror are code only and unapplied, and no deployed P1, event-court, settle, or back-score runtime telemetry is claimed. |
| **Polymarket feature lab** (`feature-lab` table/model core + `polymarket-feature-lab` lazy harness) | **VERIFIED-PARTIAL / LOCAL RETROSPECTIVE RECEIPT** | `npm run precise -- init polymarket-feature-lab describe` loads a separate heavy registration only on request. The real runner freezes physical-plan, policy-semantics, workload, denominator, release, and source identities; assembles one row per fully contained 5m/15m window; runs prior-only P(up), observed-entry fill, and 30-second quote-staleness courts; binds canonical conformal calibration, exact feature-game/ratio attribution, and advisory partial pooling; and publishes create-only JSONL/Parquet/model artifacts behind a terminal-last receipt. The verifier recomputes every content hash, row denominator, model/contract authority, and manifest identity. Two evals prove the real calibrated model path and named corrupt-artifact floor. The authoritative local Aug 21 01:05–Aug 23 00:00 UTC attempt contains 3,750/3,750 rows and 434,441 quote spells under `order_authority:none`. | Only 573 windows have retrieved completed Chainlink outcomes, 2,294 have compact top-of-book observations, three match the selected ignition corpus, and none overlaps the later three-way replica capture or an attributable counterparty join. The P(up) surface has one interval-exceeding row; that is discovery, not promotion. The sealed overlapping entry corpus has one intent and zero terminal labels, so fill probability correctly refuses. The daily job JSON is deployable specification only: no host unit, schedule, remote publication, signer, trade, or capital authority is deployed. |
| **Polymarket longitudinal task body and campaign hosts** (`longitudinal-workload-task` + generic workload adapter; compatible `longitudinal-campaign`) | **REAL LOCAL / DEPLOYED-PAUSED EU REFERENCE HOST / GENERIC BOOMBOX HOST LIVE ELSEWHERE** | The live local supervisor remains the campaign authority while its immutable graph is staged. New campaigns map all twelve epochs one-for-one onto the generic Precise workload protocol: generic claims/checkpoints/renewals/retries/completion are the sole task authority, while immutable registry, selection, retained-stream, and capture artifacts remain domain-owned. The compatible legacy Cloud Run Job is Ready in `europe-west1`, digest-pinned, keyless, and has zero executions; its five-minute Scheduler is deliberately PAUSED. | The 48h pilot is incomplete. A generic Boombox Cloud Run/GCS host is live-proven in a separate US Precise research-eval trace; this EU job has not been migrated to it and remains the compatible legacy campaign composition. Its target content is being staged behind zero published pointers; source drain/fence, final readback-bound migration, a rebuilt digest containing the latest fixes, assignment-bound admission, and scheduler activation remain required. Neither path has signer, order, wallet, or capital authority. |
| **Polymarket operator Control composition and publication** (`polymarket-operator-control-source` + generic `control-reference-registry` + domain publication + exact-generation GCS adapter/sidecar) | **REAL LOCAL COMPOSITOR + VERIFIED DURABLE-REFERENCE CORE / DEPLOYED SEALED SNAPSHOT** | The evidence-host adapter calls canonical artifact verifiers before the global-operations `operator-control` command produces one sealed no-order projection. A Precise-owned generic Control registry now wraps the domain publication reference: receipts and predecessor-bound reference records are content-addressed/create-only, while versioned `current.json` advances only on a strictly newer `published_at` and exact observed-generation CAS. The reader binds the observed pointer generation to the exact record generation and exact receipt generation. Loose generations, stale writers, rollback/equal time, caller paths/URIs, correctly resealed identity changes, noncanonical shapes, secrets, signers, authenticated requests, and orders refuse. The official ADC/workload-identity adapter and argument-free HTTP sidecar are tested; the UI composition injects a structurally read-only adapter with no create/CAS methods. The optional `europe-west1` Terraform plan declares a private versioned bucket, prefix-scoped create/get publisher, exact-`current.json` delete condition, and get-only UI reader. Cloud Run revision `precise-polymarket-observatory-ui-00005-7dw` still serves the sealed no-order snapshot and read-only drilldowns. | No real Control receipt/reference/current object, registry bucket, publisher runtime/image, scheduler, or deployed exact-chain sidecar exists. The Terraform switch defaults false and has not been applied. The public UI remains an operator-built immutable snapshot and does not refresh itself. The GCS implementation is a Precise reference adapter, not a live Boombox capability. January 2025 currently has source-boundary and deep raw-landing evidence; later custody stages remain unavailable. See `packages/polymarket-observatory/infra/gcp/observatory-ui/README.md`. |
| **portable application: private preview + release qualification** (`boombox-private-preview.harness.ts` + `boombox-private-preview-server.ts` + `qualification.ts` + `application-qualification-verifier.ts` + `private-preview.demo.ts`) | **LIVE-PROVEN HISTORICAL PRIVATE CANARY + REAL LOCAL QUALIFICATION AND PLATFORM-BINDING CONFORMANCE** | The Plan059 disposable canary (built from Precise `312479c4`, image `sha256:5c978fc1…`) ran the same-origin frontend + authenticated harness in `precise-pipeline-prod` through the full Boombox application lifecycle: plan, pre-provider regional refusal, apply, duplicate-apply adoption, replacement-controller adoption, private authenticated invocation, wrong-tenant/principal/unauthenticated/cross-tenant refusals, healthy→retired payload-free fleet projection with `charge_authority:false`, verified apply/retire receipts, and independent provider-absence proof. Locally, `precise.release-qualification/v1` seals Precise evidence meaning content-addressed with strict-schema verification, promotion floors, an explicit composition-root clock, and an exact source-closure pair. The canonical harness pins the exact public `@konstantdotcloud/boombox` release declared in `harness/package.json` and its lock; `@precise/harness/boombox-application-qualification` exports the public Precise qualification/handoff/verifier seam; `precise.release-handoff/v2` puts the exact `{qualification_ref, qualification_digest}` pair on the application descriptor; and the verifier passes the public accepted, refused, expired, verifier-release-mismatched, and placement-mismatched conformance cases. Acceptance is returned only after the injected immutable qualification loader resolves the exact Precise record and the create-only publisher persists the exact target-bound verification receipt. `application qualify`/`release` remain the discoverable commands and `npm run demo:preview` remains the one-command local path with a tenant-safe fixture boundary. | The canary is retired historical proof, not a live deployment; nothing currently serves. The demo refuses a promotable handoff for the historical artifact (`release-source-closure-unbound`) because its build predates build-closure capture. The next proof requires a rebuilt image recording a path-sorted `{path, byte_digest}` source-input closure plus production loader/publisher composition, then the same qualified two-revision apply/promote/rollback lifecycle first in Precise-owned GCP and next through a separate admission into customer-owned infrastructure. Local closure proves source-to-artifact byte binding only; provider admission and lifecycle receipts must prove the target-specific binding. Estate-schema note: the catalog cannot mark "retired disposable proof" as a first-class state; the descriptor uses lifecycle `deployable` with the proof recorded in its harness note and no fabricated observation. |
| **generic research workload observations** (`research-workload-observation` + create-only Control object-store port) | **REAL CORE + HARNESS / HOST WIRING VERIFIED-PARTIAL** | A dependency-light core seals allowlisted progress and terminal observations against exact plan, workload, source-release, invocation, sequence, checkpoint, and evidence identities. The host injects the existing ADC/workload-identity create-only object-store port. Every object is canonical, content-addressed, append-only, and constrained to operational phase/counter facts; raw events, wallet/token identifiers, paths, credentials, signers, authenticated requests, and orders cannot enter the receipt. The Polygon actor-evidence CLI now emits start, selected unit/checkpoint progress, success, and sanitized failure observations when the complete frozen observation environment is supplied. Direct-core parity, immutable publication, CLI failure-path publication, and the no-order floor are tested. The EU Terraform declares a dedicated private versioned bucket, prefix-confined create/exact-read actor role, and prefix-confined get/list durable-operator role. Terraform 1.15.8 with Google provider 6.50.0 passes format and validation; the real remote-state target plan is exactly five adds, zero changes, and zero destroys, with an unchanged state generation. | No live January observation has been published because the first EU source release predated this seam and its unit retained an exact read-only source-verifier-scratch failure. Corrected source release `sha256:07eaf215…12afb21` and outer control `sha256:750e8de4…75a1be` are deeply verified locally, but the observation bucket/IAM has not been applied and the release has not been installed. The durable operator can read state but cannot create its lock object or act as the default Cloud Build service account. Append-only discovery is real; a durable current pointer, deployed aggregator, and UI projection remain unbuilt. This is operational evidence, never experiment completion or promotion authority. |
| **generic research program** (`harness/src/experiments`) | **REAL / PRODUCTION COMPOSITION GAP** | Shared v2 canonical hashing, frozen run context and complete recipes, one bound verified-evidence handle, source-to-contribution receipt DAGs, provider/release/recipe/predecessor hashes, executable floors, controls, independent courts, contextual semantic verification, and ledger-bound stored reuse are tested. Missingness is a typed estimand contract: hard-zero preserves every eligible case, withhold stops before evaluation, and an identified subpopulation requires a sealed eligibility rule. The default `research` node mounts the planning-only `decision-program` child; lazy Polymarket adapters run real staged providers. A separate single-task bridge joins an exact assignment to the real `run_once`/stored-`verify` path only after an injected verifier accepts an already-issued host admission receipt. A first lazy media client now proves the v2 map/planner structure over canonical historical snapshots. | Durable result/ledger providers still have to be selected at the production composition root. The bridge issues no admission or dispatch and does not yet support typed multi-stage assignments. No activation command exists. A real immutable customer-evidence media adapter and controlled causal run remain open. |
| **v1 generic discovery planner benchmark** (`@precise/research-core/experiment-map` + `harness/src/research-experiment-map.ts`) | **REAL / SEMANTICS FROZEN AS BASELINE** | The core freezes one declared comparison-cell map with common-support identity, typed failure policy, complete baseline/challenger/negative-control bundles, stable definition/instance identity, explicit blockers, and no execution authority. Its bounded heuristic emits one `run|audit|hold|refuse` row per candidate and contextually replays the exact map. | Priority remains caller-declared, seed precommit remains unverified, and audit changes the primary candidate pool. It is not EVSI or the v2 audit design. Preserve it unchanged for benchmark comparison; confirmation still refuses without contextual nomination. |
| **v2 DecisionResearchProgram** (`@precise/research-core` decision map/round/audit/intent/assignment/planner/episode/nomination/confirmation/proposal + `harness/src/research-decision-program.ts`) | **REAL CONTROL KERNEL + GENERIC HOST / ASSIGNMENT + COUPLED-PLANNING GAP** | `DecisionEvidenceMap/v2` retains atomic predicates, explicit decision reach, and separate definition/instance/offer hashes. A vector-budget primary plan excludes audit; independent commit/reveal samples the frozen hold frame with exact probabilities. Experiment intent joins map/spec/policy semantics. `ResearchRoundAssignment/v1` binds one primary run or sampled audit to release, desired placement, physical plan, workload, and complete evidence identity. The exact cold coverage reference returns sealed `OPTIMAL|INFEASIBLE|UNKNOWN`; unknown and infeasible rounds schedule nothing. Assignment-rooted episodes retain the full denominator, predictions, terminal/courts, complete predicate effects, actual resources, audit-weighted misses, private-reference regret when precommitted, and target-specific training eligibility. Contextual nomination reconciles primary plus sampled-audit outcomes and requires exact selector-withheld fresh support. `ContextualConfirmationRound/v1` projects only nominated definitions onto that support, retains the discovery denominator, and schedules all runnable nominations or refuses. Confirmation assignment requires the outer receipt and binds the discovery, nomination, support/scope, confirmation map/expected plan, and definition into physical evidence refs. `DecisionProposalSet/v1` accounts for every declared independent target and supports optional exact tenant/policy/evidence/time/denominator verification. Current package, harness, eval, and SDK gates pass. | The exact branch-and-bound engine is a small-case reference, not production CP-SAT. Weights are declared criticality, not EVSI. External entropy/precommit timing, typed expert/source-request assignment, learned adaptive selection, coupled portfolio optimization, an Arranger `DecisionPlan` adapter, live customer media evidence, durable episode storage, and the exact assignment-bound live traversal through the proved generic Boombox host remain open. The public authenticated control client exists; it has not yet carried this exact Precise assignment envelope through a Precise-owned immutable worker image. Referenced terminal/court/fresh-support and qualification artifacts must be independently verified from pinned source bytes at production composition. The 40-command child has no run, admit, dispatch, execute, persist, promote, activate, signer, or order verb. |
| **media decision-research historical client** (`harness/src/media-decision-research.ts` + canonical `surfaces-core` campaign/frontier cores) | **VERIFIED-PARTIAL HISTORICAL CONFORMANCE / NOT CUSTOMER EVIDENCE** | The optional `media-decision-research` attachment imports the canonical four-campaign roster, `nextDollarSeed`, and `nextDollarCurve` rather than copying allocation logic. It projects the complete declared historical denominator into `DecisionEvidenceMap/v2`: three campaigns have structural frontiers and `ezc` remains blocked for missing canonical frontier evidence. Every priority is zero, no modeled outcome ranks the candidates, and exact cold planning requires caller-supplied causal contract hashes plus complete resource, latency, risk, audit, budget, and coverage inputs. Focused tests, two evals, typecheck, SDK smoke, and the full harness pass. | This proves that the generic spine is not Poly-shaped. It is not a live customer manifest, causal experiment, operational-eligibility receipt, identified move value, assignment, host run, or activation surface. The next media slice must bind immutable customer evidence, a controlled outcome contract, and the exact assignment/workload/host receipts; Boombox supplies host authority, not media meaning. |
| **generic physical research plan** (`@precise/research-core/physical-plan` + `harness/src/research-physical-plan.ts`) | **REAL CONTRACT + EXACT HOST WRITE-AUTHORITY BINDING** | `precise.research-physical-plan/v1` content-addresses the materialized stage DAG, immutable release and evidence refs, non-nested host- or provider-managed scratch, a sealed engine-resource config plus host memory/scratch/billing/time ceilings, create-only atomic publication, uncapped denominator, one common opportunity key across variants, rank-before-economics, and information/execution separation. A host stage may additionally bind every file URI it must mutate in `host_writable_resources`; `verifyResearchHostWritePathBinding()` requires the service's exact `ReadWritePaths` set, refusing both an omitted nested-verifier scratch and undeclared extra write authority. The default `precise research` node freezes and verifies the plan; `verify-physical-workload-binding` also proves tenant, logical run, implementation, and exact `plan_hash` parity before dispatch. Success, host/provider resource, nested-release-scratch, exact host-write authority, and workload-binding tests pass. The uncapped PMXT build that motivated the contract materialized 151,975,578,891 raw events into 1,517,352,428 causal states with zero post-cut rows; its equally sized causal spine has also passed exact key, missingness, causality, and authority audits. | The contract does not provision or launch compute. Generic Boombox Cloud Run/GCS provider conformance is live-proven, but this corrected GCE actor plan has not entered a generic host. The remaining join must enforce all declared resources, checkpoint each stage, and bind terminal receipts back to the assignment and plan. |
| **generic policy-semantics seal** (`@precise/research-core/policy-semantics` + `harness/src/research-policy-semantics.ts`) | **REAL CONTRACT / DOMAIN AUDIT BINDING** | `precise.research-policy-semantics/v1` freezes the opportunity unit/key, whether target choice is fixed before or occurs inside the policy, and every variant's score/action start offset, horizon, and payoff. Direct calibration requires exact target equality; an intentional mismatch is research-only `exploratory-proxy`. `verify-physical-policy-binding` requires tenant/run/implementation parity, the same opportunity key, and the exact `semantics_hash` in physical-plan evidence. The default `precise research` node exposes the freeze/verifiers and an eval exercises the time-anchor refusal. | Domain SQL or model adapters must still project and audit these fields against their computed branches; the seal prevents a semantic substitution across contracts but does not inspect opaque provider code by itself. |
| **Markov transition evidence map** (`@precise/research-core/markov-transition-map` + `harness/src/markov-transition-map.ts` + `polymarket-global-markov-context`) | **REAL GENERIC CORE / REAL RETROSPECTIVE POLY COURT** | The generic core freezes an exact state space, source receipts, transition denominator, point-in-time availability, and purged train/validation/holdout contract under a canonical binary Merkle root. It produces independently verifiable row-inclusion proofs, fits a train-only first-order categorical Markov model, and fits sparse contextual models with Dirichlet shrinkage and exact unseen-context backoff. The optional Poly court projects the sealed January–October 2024 case artifact into one common map per 5m/1h/6h/24h horizon, scores all 32 public-flow/wallet coalitions on identical rows, applies equal condition-cluster value, and publishes immutable court `sha256:d782c054…a0d4`. Public flow improves the retrospective holdout proper score at all four horizons. Current wallet context adds `-0.00055`, `-0.02585`, `-0.03542`, and `-0.10404` over public flow. Canonical exact Shapley/Owen ran on each positive complete game; separate wallet-over-public-flow attribution withheld at every horizon. | This is retrospective information value, not execution, P&L, capacity, promotion, or alpha. The source has only 136–175 retained transitions per horizon. The state/context grid, prior strength, and binning remain a first projection. Role-specific context, support/missingness, market age, event family, semi-Markov duration, stronger non-Markov controls, strict cold-condition evaluation, and a newer prospective tape remain open. Merkle proves custody rather than value; optional Valence/AliceNet anchoring remains unconnected. |
| **Polymarket signal refinery** (`edge-lab/signal-experiment-registry` + `polymarket-signal-refinery`) | **REAL LAZY V1 + V2 PLANNING CLIENT / VERIFIED HISTORICAL COURT INVENTORY** | The optional tree exposes eight sealed scientific families as nine accountable claim lanes spanning microstructure, logical payoff geometry, market birth/attention, wallet/cohort/graph transfer, maker/mechanics regimes, resolution semantics, semantic news, and weather/calendar anchors. A read-only local operator executes the exact 16-capability source denominator, preserves partial and unavailable probes, publishes one ignored content-addressed artifact plus receipt, and binds that exact artifact through `bind_runtime_inventory`; the latest verified receipt derives five discovery-ready families, three blocked families, and zero confirmation-ready families. A separate exact nine-lane court inventory invokes each existing source-ready verifier and retains every blocked lane. Its current receipt binds five terminal historical lanes, three fully verified lanes, one source-recomputed lane, two verified-partial lanes, four blocked lanes, one Shapley-called lane, and zero running lanes to the exact runtime artifact and registry. The harness `bind_court_inventory` command independently refuses any runtime artifact, receipt, registry, or ready-lane mismatch. The v1 map/planner remains available. `decision_map_v2` and `plan_decision_coverage_v2` project the same runtime-inventory-bound nine-lane denominator into the generic `DecisionEvidenceMap/v2` and exact cold coverage planner. Assignment-ready mode derives every eligible lane's definition, instance, offer, predicate, and evidence identities through the canonical generic `ResearchExperimentIntent/v1` core; legacy Poly hashes remain explicitly planning-only. `project-discovery-assignment` contextually replays the source map, v2 map and plan, canonical family projection, intent, release, policy semantics, placement, physical plan, workload, and task denominator before emitting the generic basis and assignment for one selected primary run. Held, blocked, legacy-incompatible, and substituted-map inputs refuse. The attached resolution-semantics child now uses the physical source unit: it checkpoints every exact Gamma keyset page, derives the complete active registry and one rule/resolver/source projection per eligible row from those identical bytes, then fetches each unique mapped official-source URL once and projects the result across all referring markets. Deep replay reproduces pages, registry, exclusions, rules, deduplication, clocks, and the complete market denominator. A generic worker retry is fixture-proved across a forced mid-census failure. A sealed UTC cadence now expands to 120 explicit all-market cuts over 30 days; its source closure, runtime config, two-stage physical plan, workload, and program reproduce locally. The ADC-only EU provider and narrow image remain no-order, and a reviewed bootstrap plan isolates 19 creates with zero updates or destroys from five unrelated live-stack updates. The legacy N+1 adapter is excluded from the production image. The official-calendar child and local provider now separately prove DNS-validated exact-source BLS retrieval, reviewed Eastern-time interpretation, complete market and source-row denominators, quarantine, and deep replay. The first live v1 pass retained three quarantined rows and withheld all 10 dependent markets; a separately versioned v2 receipt decoded all 15 rows and admitted all 10 markets. The calendar core also binds explicit repeated cuts into the generic workload, checkpointing deeply verifiable receipts and completing idempotently. A source-release-bound 12-cut local program has completed and deeply verified its first task over the same 10-market, 15-row denominator; 11 tasks remain pending. The runtime verifier reports that source partial without opening the scheduled-event lane. | Historical terminal math is not continuous execution, freshness, or evidence of an edge. Operational vectors and strata are caller evidence; fixtures prove the seam but not their live truth. Priority remains the legacy bounded registry-order heuristic and is explicitly not EVSI. Independent v2 audit assignments, fresh source recomputation for each ready lane, durable scheduling, terminal/court/episode closure, fresh-support nomination and confirmation inputs, and an assignment-bound signed receipt through the real generic Boombox host remain open. None of the nine lanes is currently running and none is confirmation-ready. Resolution semantics and news remain blocked on live point-in-time source evidence; weather and calendar are verified-partial but still below their discovery support floors. Calendar capture still needs its generic workload composed onto the durable EU store and provider schedule, followed by repeated cuts and broader event-family coverage. The resolution host remains unapplied and still needs state-lock authority, exact-generation publication of the staged program and provider config, a digest-pinned image, one manual live run, and repeated durable terminal tapes. Actor/PMXT confirmation joins, exact fills/queues, and lane-specific live provider receipts remain incomplete. See `packages/polymarket-observatory/docs/signal-refinery.md`, `packages/polymarket-observatory/docs/official-calendar-vintage-capture.md`, and `packages/polymarket-observatory/docs/resolution-source-vintage-capture.md`. |
| **Polymarket microstructure response court** (`microstructure-response-court` + `polymarket-microstructure-response`) | **REAL / VERIFIED-PARTIAL INFORMATION COURT** | The v2 optional child reads immutable longitudinal selection/checkpoint/capture roots, retains one eligible denominator with horizon-specific hard-zero attrition, rederives the full action cube from sealed decisions, independently recomputes group/time isolation, fits only on grouped discovery, and settles an untouched event-purged epoch. Exact independent-group sign tests, an eight-group floor, Holm correction, direction-flip and target-permutation gates, caller-resealed-decision rejection, and per-horizon exact source replay are tested. The current three-epoch receipt (`sha256:25efce8…448785`) found material held-out later-bid information at 1h and 6h and invoked canonical exact Shapley only on those complete information games; every finite discovery entry threshold lost, so the frozen policy abstained and promotion remained closed. | This is evidence of quote-response information, not profit. The earlier two-epoch receipt is superseded as decision evidence. Exact fills, post-decision latency, adverse selection, fees sufficient for exact utility, and capacity remain unidentified. The next preregistered lane must learn side and entry timing on earlier epochs and settle on later untouched epochs. Generated courts stay under ignored `data/`; only code, tests, harness contracts, and pointers are committed. |
| **Polymarket direct entry-timing policy court** (`entry-timing-policy-court` + `polymarket-entry-timing-policy`) | **REAL CORE + IMMUTABLE PROGRAM / CONTRACT-EVIDENCE ONLY** | A sealed preregistration (`sha256:bcc29f…e6f0`) fixes epochs 0–2 as discovery and later epochs as confirmation, then jointly learns abstention, ordinal side, enter-now versus wait-120s, and 1h/6h exits at fixed $5 taker size. The package core imports the audited v2 action-integrity, point-in-time feature, ridge, grouped sign/bootstrap, and Holm primitives; preserves incomplete action cases as hard-zero; gates against immediate-only plus four direction/target/timing controls; exact-source-replays before file output; and calls canonical exact Shapley only on a positive complete identical-support held-out game. `research:entry-timing-policy:program` now seals the exact `120,3600,3720,21600,21720` offsets, split, policy hash, and no-order authority into a program accepted by the restartable longitudinal supervisor. The optional signal-refinery child has real success and leakage-floor evals. | No real result or timing-campaign receipt exists. The legacy campaign omitted `+3720s` and `+21720s`, so it cannot identify exits 1h/6h after waiting 120s; it cannot be repaired retroactively or spliced with a later program. The new program and public-data supervisor have not been run. Even a positive diagnostic leaves exact execution and capacity unidentified. See `packages/polymarket-observatory/docs/entry-timing-policy-court.md`. |
| **resonance compatibility kernel** (`@precise/research-core/resonance`) | **REAL BORROWED BENCHMARK / LICENSED PROVIDER UNBUILT** | The dependency-free compatibility copy adapts Konstant vFAST channels and registered weights plus a local orphan-pressure proxy. It rejects absent/non-finite inputs, exposes every component, and is regression-tested; the Polymarket graph adapter maps strictly prior wallet/community/topology evidence into it instead of owning another copy. This is not a Precise ownership claim. | Do not extend the local copy. Replace it with a licensed Konstant library or service through the planned `konstant.selection-signal-envelope/v1` seam after provenance, missingness, range, and parity conformance. The kernel does not declare actors, communities, graph edges, activity, causal value, EVSI, or economic utility; Precise still owns the evidence semantics, ablations, courts, decision economics, and contribution math that evaluate its outputs. |
| **generic research workload host** (`@precise/research-core/workload` + `harness/src/research-workload.ts` + `harness/src/research-assignment-workload.ts` + `harness/src/boombox-research-workload.ts`) | **REAL PRECISE WORKER + PACKAGE-PINNED PLAN + LIVE GENERIC BOOMBOX HOST / ASSIGNMENT-LIVE GAP** | Content-addressed programs and state, exact schedules, CAS claims, leases, fencing, bounded retries, compressed local persistence, generation-CAS GCS persistence through injected workload identity, checkpoints, idempotent terminal commit, reattachment, payload-free failure receipts, and no-order authority are implemented and tested. The worker freezes the full due universe but claims long work in explicit concurrency-sized waves. A separate injected create-only episode ledger proves exact opening/closing reuse and conflict refusal. The first assignment bridge contextually verifies an exact one-task experiment assignment, physical plan, workload, desired placement, task, and no-order research adapter; it exposes the real `run_once`/stored-`verify` handler only after an injected verifier accepts an already-issued host admission receipt. A second adapter pins `@konstantdotcloud/boombox` and binds the exact Precise program to the public descriptor, target, and non-authoritative plan. Plan057 separately live-proves Boombox apply/invoke/read, durable control state, controller replacement, customer-owned Cloud Run/GCS, and terminal custody for one Precise research eval. | Precise owns and proves research, worker, episode, and assignment semantics; Boombox owns and proves generic host/runtime semantics. The exact public `@konstantdotcloud/boombox` release declared in `harness/package.json` and its lock exposes both provider-free planning and the authenticated workload-control client. The remaining join is signed full assignment-envelope admission, a Precise-owned immutable worker image, and one exact assignment traversing the live host. The bridge still refuses multi-task assignments. The deployed EU legacy-compatible job is not that migration. |
| **PMXT bounded materialization** (`pmxt-v2-materializer` + `pmxt-v2-gcs-reader` + `pmxt-v2-gcs-materialization`) | **VERIFIED-PARTIAL, RESEARCH-ONLY** | A real non-test CLI reads one content-addressed manifest through the official ADC/workload-identity adapter, binds the raw manifest hash and GCS generation, verifies every selected Parquet generation/byte count/SHA before DuckDB yields rows, runs and replays the checkpoint core, then atomically publishes content-addressed cut/receipt/checkpoint/evidence artifacts behind a local current pointer. Complete manifest gaps stay in the denominator; explicit resource bounds refuse rather than truncate. | The earlier 2026-07-15 rehearsal stopped at an expired reauthentication token before Parquet or publication. ADC has since been restored for read-only control-plane and GCS access, but no replacement PMXT materialization receipt proves this full path yet. Durable scheduled/recoverable hosting remains unproved; PMXT stays third-party L2, never exact fill or queue evidence. |
| **PMXT prospective forward collector** (`polymarket-pmxt-prospective-forward` + `pmxt-prospective-forward-job`) | **REAL DEPLOYED COLLECT-ONLY / SCORING AND PAPER BLOCKED** | The optional harness, package CLI, exact-generation config, and digest-pinned `europe-west3` job freeze a one-stage collect-only physical/workload plan. The hourly `pmxt-delta` workload now mirrors bytes and publishes their exact manifest at minute 18; the forward scheduler consumes it at minute 25, retains source and materialization failures as twelve chained five-minute cuts, writes application-create-only content, and advances one prefix-scoped generation-CAS pointer. Manual publish/reuse and the first autonomous paired cycle closed through `2026-07-16T04`; every run hard-abstained with no BigQuery, scorer, signer, order, or capital IAM/authority. Current receipts are on [Research Control](../research-control/index.html). | The cloud instance was created through equivalent reviewed `gcloud` operations and is not reconciled into Terraform state yet. Every current cut is `unavailable-materialization`: no qualified SQL/table/denominator-bound frontier materializer, prospective scorer/promotion verifier, causal action-time snapshot, or stateful portfolio/exit runtime exists. `sealed-query` is refused and the policy gate remains blocked. See `packages/polymarket-observatory/docs/pmxt-prospective-forward-runbook.md`. |
| **Polygon actor-history bootstrap and production graph** (`polygon-calendar-block-boundary` + Storage Read/packed-custody/actor-evidence cores + `polymarket-actor-history-production`) | **VERIFIED-PARTIAL, RESEARCH-ONLY** | January 2025 has sealed calendar boundaries and a keyless US landing that deep-verifies 14,074,651 rows and 10,875,471,576 raw Arrow bytes. Its EU raw actor materialization is terminal and independently replayed over 12,846,179 OrderFilled logs. Packed custody is fixture-proved. The monthly decoder/archive/coverage path is bounded, streamed, fenced, checkpointed, deterministically resumable, and complete-month-or-refuse. The first outer attachment retained an exact execution-placement failure before child work because systemd omitted the source verifier's sealed scratch; the corrected outer runner admits that path against the source run config, and the physical plan binds the exact three-path write-authority set. The full January 2025–June 2026 denominator is frozen into five physical plans and five bound generic workloads: 90 exact month/lane tasks, null scientific caps, retained failures, US/EU placement, same-month upstream completion gates, immutable result bodies, generation-CAS current pointers, and no order authority. | January is not yet a terminal actor-evidence receipt or a completion in the new workload. Corrected release `sha256:07eaf215…12afb21`, plan `sha256:8ea9829f…8a8c56`, workload `sha256:8186c7d2…cc6253`, and control `sha256:750e8de4…75a1be` are sealed locally but not installed. The EU observation plan is HCL-valid and clean at five adds, zero changes, and zero destroys; apply still needs a state-lock writer with resource authority. The US control-bucket Terraform, automatic dispatch/task executor, broad-disk capacity decision, and exact-acceptance cleanup authority also remain open. The multi-month compositor still withholds its actor-evidence handle until raw/quarantine/unavailable identity ledgers close across months. Shapley/Owen remains forbidden until at least two independent months close and held-out transfer is positive. See `packages/polymarket-observatory/docs/polygon-actor-history-production.md`. |
| **Global prospective research observer** (`polymarket-global-operations advance-prospective`) | **REAL LOCAL / DEPLOYMENT READY / NOT LIVE** | A separate no-authority observer reads the current sealed EU actor hook without collecting the chain again, deep-verifies its exact lineage and safe head, and runs the point-in-time feature, paper/shadow forecast, public-book execution, executable-return, shared-bankroll portfolio, and eligible contribution chain exactly once per actor run. The dedicated harness CLI, hardened oneshot service and non-overlapping timer, content-addressed installer, immutable recipe/experiment inputs, no-order boundary, and estate entry are test-proved. A real local smoke exposed and then fixed a missing `safe_head` field in the public actor hook; the repaired smoke now refuses honestly as `catching-up` against the older local mirror. | The observer is not installed on `precise-pm-global-eu-1`, so the continuously current EU actor hook still stops before these courts. One user-authorized GCP installation and one deeply verified live observer receipt remain before the timer can be enabled. No contribution attribution is called unless the held-out game has complete identical support and positive grand-coalition value; no signer, wallet, authenticated trading request, order, or live capital authority exists. See `packages/polymarket-observatory/docs/global-operational-supervisor.md`. |
| **Polygon actor signal court** (`polygon-actor-signal-court-runner` + `polygon-actor-signal-court` + `polymarket-polygon-actor-signal-court`) | **VERIFIED-PARTIAL, DISCOVERY-ONLY** | The source adapter deep-verifies one immutable monthly actor-evidence manifest, scans every canonical maker-owner action at its exact confirmation-block clock, retains unavailable clock/economic/markout cases with denominator closure, and sends the resulting point-in-time rows through the existing wallet identity, behavior fingerprint, clone-collapsed cohort, graph-resonance, adapted vFAST, multi-model, grouped-transfer, permutation, placebo, and negative-control courts. Direct core-to-harness parity, source no-cap closure, point-in-time success, a resealed clock-floor failure, immutable result binding, no-order authority, and one-month Shapley refusal are tested. | No real month has run this court. January is upstream-blocked by the actor-evidence streaming/checkpoint launch refusal. A later matched print is an information proxy, not identified execution or capacity. One month cannot establish independent calendar transport or call canonical Shapley/Owen; even a positive discovery proxy remains `winner:null`, $0, and unpromotable. See `packages/polymarket-observatory/docs/polygon-actor-signal-court.md`. |
| **PMXT wallet foundry** (`pmxt-wallet-foundry` + PMXT feature/model/transfer/execution cores + Strategy Foundry portfolio/contribution + generic ResearchProgramHarness) | **VERIFIED-PARTIAL, RESEARCH-ONLY** | One exact PMXT L2 manifest and one complete ActorCoverageManifest now freeze a pre-label wallet-triggered population, retain missing/unmapped cells, run the real wallet/cohort/graph/vFAST/control ablations, separate exact execution from the zero-fee visible-depth upper bound, replay shared capital, and call canonical Precise attribution only on a complete identical-support game. The lazy main-tree surface accepts a content-addressed foundry file, uses a verified-evidence handle, executes ten real floors (including exact confirmation-block availability), and stores generic stage receipts/result/ledger bindings. | No full actor corpus or intended PMXT span has run. PMXT is L2, so fees, fills, queue position, and executable utility remain unidentified; executable Shapley and promotion are withheld. A durable generic Boombox host now exists, but this foundry's process-local composition has not been bound, admitted, or migrated to it. See `packages/polymarket-observatory/docs/pmxt-wallet-foundry.md`. |
| **HF V1 maker/taker role court** (`hf-v1-wallet-role-court` + `hf-v1-wallet-role-diagnostic`) | **REAL RETROSPECTIVE DISCOVERY COURT / SEALED NULL** | Version four admits exact two-player role-group Shapley only when the held-out combined-exposure grand coalition is positive and maker, taker, and combined coverage are all nonzero. A public-interface regression proves the negative game is withheld, and the current court plus multi-window diagnostic tests pass 6/6. Six unchanged fixed-lookback windows were rebuilt from verified source receipts into a sealed 118-case, seven-event-family diagnostic (`sha256:b4963cd…643a5`; manifest `sha256:b327797…309bd`). Combined role context improved case-weighted log loss by 0.00689 and maker-only by 0.00740, but both clustered 95% intervals cross zero; taker-only is slightly negative. Three windows admit attribution, while one negative-value and two zero-role-support windows withhold it. | This is a retrospective third-party analytical archive with approximate `DOUBLE` economics. The 200-case floor is unmet, clustered support is fragile, and no prospective, execution, queue, capacity, or promotion authority exists. The next regime/maker court must use the current sealed actor frontier joined to point-in-time books and mechanics versions, with router exclusion and held-out maker-cluster transfer. |
| par / ledger / advocate | **missing / floor-only** | the floors exist | no engine (see the audit, 07-*) |

**2026-09-01 reward-join entrypoint landing:** the standing production entrypoint began mounting `/boombox/events` only when `BOOMBOX_PEER_AUTHORITY_PUBLIC_KEY`, the complete `PRECISE_GATEWAY_GCS_BUCKET` + `PRECISE_GATEWAY_GCS_PREFIX` custody pair, the durable event ledger, the durable open-decision store, and `PRECISE_OUTCOME_SOURCE_CLASS=customer` are all composed. It uses the ES256 verifier and the wire-order-1 maturity scan; the open appointments persist under Product GCS custody. Any absent piece leaves the door unmounted and is named plainly in startup state. At landing time no deployed revision had that environment. The later 2026-09-02 observation of `app_rev_4ac0c1d7` found event booking armed on the existing GCS application-state custody, with no real producer outcome observed.

## The remaining work to make `contribution` a REAL product connection

The production value function, exact/CC estimators, long-lived worker, and Python CI
are connected. The remaining gaps are narrower:

1. **Bridge the complete production router.** Add parallel/cc_fast/additive-exact
   through a picklable value specification and prove the routing cutoffs.
2. **Cover the full outcome contract.** The connected path currently drives only the
   `cac` family; extend it through the shared `Outcome` descriptor and cross-language
   golden vectors.
3. **Repoint a real product caller.** The real `{segments}` score and ablation paths
   run, but the in-tree default remains legacy equal-split and no scanner/product
   caller consumes the real result yet.
4. **Finish deterministic cross-language sealing.** Pin canonical bytes, runtime
   versions, and worker configuration so two deployments reproduce the same result.
5. **Carry tenant and egress authority through the real caller.** A correct score is
   not a production connection until identity, path scope, evidence, and sealed
   crossing are enforced at the composition root.

## The honest one-liner

`seal` is a **real** connection. `contribution` is **verified-partial**: the real
production value function and exact/CC estimators run cross-language, ablate, and
have a long-lived worker plus CI, but the router/KPI coverage is incomplete and no
real product or scanner path consumes the result yet.

**2026-09-01 package pin:** exact `@konstantdotcloud/boombox@0.14.9` (integrity `sha512-rgh6oPgj5aKHSFJrfVZC/vTO/5maw1a7+fLhHKJDo2ocO6hH6UAbBY/KsNC6rXz1xJ4/VGT8UocgseNgIuUh2w==`, shasum `b97fabc3d89a838fc85cf284e0bc5f8f5e0e8268`, registry-verified); doctor converged (manifest, lock, installed, BOOMBOX_VERSION agree; skill mirrors regenerated, boombox_skills ok). This cut was the consumer kit (platform-lane ping, kai-wt-sr-int-12): `@konstantdotcloud/boombox/testing` createMockBoomboxAppRuntime, the consumer-app-full-loop worked example, poll fallback, and platform-side input-schema validation. At that cut, the deployed Gateway had neither the injected open-decision store nor an armed event subscription, and the campaign-improvement example remained on 0.14.6. The example moved to 0.14.9 later that day, and the 2026-09-02 `app_rev_4ac0c1d7` observation found event booking armed.

**2026-09-01 amendment to the 0.14.9 pin entry:** the example-package lag is resolved — `packages/campaign-improvement` pins exact `0.14.9` (@47323490c; battery 114 files / 820 tests green; offline `--from` clone proof green). The bump's battery also caught and fixed a type defect from the analyst fold (@4b1490752); the harness suite now counts 950.

**Current package pin (landed 2026-09-01):** exact `@konstantdotcloud/boombox@0.14.10` (integrity `sha512-DjKGuPK8bepsLImewLE1MayOxTG9YOtlLH5vv2y6XsKKCxgI8BsFIRCIcwHllgm69b3qt8IS3qBxDAK/db44kQ==`, shasum `80f03afe511973c97d6309f08d173fad2a9d977a`, registry-verified); doctor converged and the campaign-improvement example uses the same pin. This cut accepts the additive operation-record fields `usage_atoms`, `run_id`, and `invocation_id` plus typed 409 `APPLICATION_APPLY_OPERATION_STALE`. The standing Gateway adapter now emits one `verb_call` atom for each of its eleven mapped default commands and for the three optional workspace-result commands. Current `math/*` and continuation `workflow/*` paths are not mapped, and the hidden saved-definition runner emits no per-step operation records, so those paths have no operation atoms yet.
