MIZ OKI 3.5 — Remediation-Layer Reconciliation Prompt
SUPERSEDED (2026-07-27, MIZ-REC-2026-003). This prompt was superseded by the July 27 integration directive; its Phase 0 obligation is discharged by
docs/INTEGRATION_PLAN.md, which also records which of this file's mandates were carried forward. Do not execute this prompt. Retained as historical record.
Ref: MIZ-REC-2026-002 · companion to MIZ-REM-2026-001 (remediation drop) and MIZ-GA-2026-001 (gap analysis) How to use: paste this entire file as the opening prompt of a Claude Code session started at the MIZOKICloudRun repository root. Do not excerpt it — the prohibitions at the end are load-bearing.
You are integrating the MIZ OKI 3.5 remediation layer (mizoki-remediation/) with the platform code that already exists in this repository. This is a reconciliation task, not a construction task. Several prior sessions (July 13–17, 2026) already landed overlapping artifacts — src/shared/miz_oki_source_of_truth.py, src/shared/mizoki_core|counsel|estate|risk, src/shared/virtuoso_models/, the miz_oki_3.5_integrated/ bundle and its MIGRATION.md — and an earlier integration prompt may have produced additional unpushed work in this checkout. Landing the remediation layer blindly on top of that would create two parallel contract definitions that agree today and drift next month. Your job is to make paper and platform the same thing.
Ground rules (read before touching anything)
- Verify actual checkout state before believing any session summary. Run
git status,git log --oneline -10, andgit log --oneline -5 -- src/shared/miz_oki_source_of_truth.py miz_oki_3.5_integrated/ mizoki-remediation/first. Prior-session notes (including this prompt's own framing) may describe files as "unpushed" that are already onmain, or vice versa. The repository is the authority; summaries are hints. mizoki-remediation/contracts/mizoki_contracts/wins any definitional conflict. Where the same concept exists in two places — the canonical event envelope, the eight decision objects, auth, the store, validators — themizoki_contractsdefinition is canonical and the other copy is either deleted, converted to a re-export, or explicitly recorded as a mirror with a parity check. No third option.- The defect inventory is your work order, not background reading. Read
docs/REVIEW.mdfirst if it exists in this checkout. If it does not, the defect inventory lives in two files that do exist onmain:docs/MIZ_OKI_PRODUCTION_CONVERGENCE_PLAN.md(10 line-cited P0 gaps, Appendix A) andmizoki-remediation/docs/README.md(the 12-row gap → resolution matrix). Treat the union as the defect list. Every change you make must cite which defect or gap it closes. - This repo auto-merges. A push to any
claude/*orcursor/*branch lands onmainwithin seconds via the Auto-Merge bot, and the Deploy Router will dispatch matching deploy workflows for the merge. There is no "draft PR" safety net. Do not push until the phase you are in is complete and its verification gate is green.
Invariants — defects that get reintroduced during integration
These are the specific defect classes that a well-meaning integration session recreates. Check your diff against every one of these before each commit:
- Locked ingress is intentional.
virtuoso-models-service,rewoo,cell_3, and the MIZ-REM-hardened services useinternal-and-cloud-load-balancingingress. A public 404/403 from them is the expected posture, not an outage. Do not "fix" a failing public curl by opening ingress — that reverses the MIZ-REM-2026-001 auth lockdown. Onlysecurity/harden_auth.shand the API gateway define the public surface. Health is verified viagcloud run services describeReady conditions, never public HTTP. - Do not sever inter-cell calls while tidying auth. Cells call each other with ID tokens via
mizoki_contracts.auth.outbound_headers(). Any change to service IAM, ingress, or the auth module must be validated by exercising at least one real cell→service call path (or its test double), not by eyeballing the config. - Stage 3 recommend-only is a ceiling, not a placeholder. The Decision Control Plane issues STAGE_3 for everything today, and
service-action-runnerdefaults to Stage 3. That is deliberate. Do not promote any scope to Stage 4, do not delete the dead Stage-4 branch as "cleanup" in a way that makes Stage 4 reachable, and do not hardcode the ceiling in a second place — the ceiling lives in policy (service-policy-engine/ DCP), and code must read it from there. - Advisory-only stays advisory-only. Finance and CRE are held at Stage 3 by
advisory_onlypolicy gates until their proof obligations close. Counsel legal conclusions, estate fiduciary/disposition actions, risk committee decisions, and CRE binding commitments areFORBIDDEN_AUTONOMY(mizoki_core.control_plane) and raisePermissionErrorat grant time. Nothing in this integration lifts any of these. - Passports fail by construction. A
ValidationPassportmissing any required check is a FAIL. The convergence plan's P0-6 (caller-selected check subsets) is fixed by removing the caller's ability to narrow checks — do not preserve an "optionalchecksparameter" for backward compatibility. - The dev signing key is a defect, not a default.
dev-only-key-rotate-in-kmsmust not survive as a fallback in any deployed path. Absent a mounted secret, services must refuse to sign, not sign with the dev key. forbidden_legacymodel strings stay accurate. Superseded-but-callable models (gemini-3.5-flash,claude-opus-4-8,gpt-5.5,grok-4.3) must not be added to the forbidden list; genuinely retired strings must not be resurrected. Any model-pin change updatesmiz_oki_source_of_truth.MODEL_ROLESin the same commit orcheck_conformance()trips fleet-wide at startup.
Phase 0 — Reconciliation plan (BLOCKING: no other phase starts until this file exists)
Produce docs/RECONCILIATION_PLAN.md and commit it alone before any code change. It must contain:
- Checkout-state table. For each artifact family, what is actually present and at what version:
mizoki-remediation/(dropbdbf0a88),src/shared/mizoki_core|counsel|estate|risk,src/shared/miz_oki_source_of_truth.py(expect v3.5.2),src/shared/virtuoso_models/+ its vendored copy inservices/virtuoso-models-service/,miz_oki_3.5_integrated/bundle, and any uncommitted work from earlier prompts. - Superseded-vs-merged disposition. One row per overlap, with the decision and the rule applied:
-
mizoki_contracts.envelopevsmizoki_core.envelope— contracts wins the definition; record what happens tomizoki_core.envelope(delete / re-export / stdlib mirror + parity test). Note the constraint honestly:mizoki_coreis deliberately stdlib-only and ships inside the boss image; if pydantic cannot be imposed on its consumers, the recorded outcome is a mirror with a CI parity check (field names, types, bitemporal ordering ruleavailable_to_model_at >= observed_at), not silent coexistence. -mizoki_contracts.decision_objects(pydantic, eight objects + ClaimLabel + RollbackContract) vsmizoki_core.objects(dataclasses, eight objects) — same rule, same honesty about the stdlib constraint. -mizoki_contracts.auth/store/validatorsvs any per-cell equivalents you find. -miz_oki_3.5_integrated/bundle copies — already established as deliberately stale (June-26 vintage); confirm the plan states they are a tracked work-product record and are never synced oversrc/shared/. - The defect inventory you are working from —
docs/REVIEW.mdif present, otherwise the Convergence Plan P0 list ∪ the remediation gap matrix — enumerated with IDs you will cite in later commits. - Sequencing — which convergence-plan tickets this session touches (start at PROD-001/OPS-001 ordering; do not jump the 20-ticket merge sequence).
Do not begin Phase 1 until docs/RECONCILIATION_PLAN.md is committed. If you find a genuine contradiction between the remediation layer and main that the "contracts wins" rule cannot resolve mechanically (e.g., the Vertex-aware call_claude vs a contracts-side assumption), record it in the plan with your proposed resolution and proceed only on the documented choice — never on an undocumented one.
Phase 1 — Defect closure
Work the defect inventory in convergence-plan priority order. For each defect:
- Cite the defect ID (P0-n / gap-n / REVIEW-n) in the commit message.
- Fix it in the canonical home per the Phase 0 plan — not in whichever file you happened to open first.
- Re-check the diff against every invariant above; the invariants section exists because P0-3 (tenant from request body), P0-4 (silent memory fallback), P0-5 (non-transactional audit chain), P0-6 (caller-weakened validation), P0-7 (Stage-4 dead branch), and P0-8 (dev signing key) are exactly the defects that "tidying" reintroduces.
- Known specifics you must not regress:
store.py's Firestore-failure → in-memory fallback becomes a hard readiness failure, not a warning; the audit chain's_last_chain_hash()/_next_seq()read-then-write becomes transactional;tenant_idderives from verified identity, never the request body;/pendingapprovals filter by tenant.
Phase 2 — Wiring the cells into the layer
Follow the integration map in mizoki-remediation/docs/README.md exactly (SENSE cells → canonical-ingestion; REASON cells → mizoki_contracts + point-in-time evidence reads; DECIDE cells → DCP /api/v1/propose; ACT cells → action-runner with rollback contracts; LEARN cells → Outcome/LearningRecords; virtuoso_models → model registry with named baselines). Rules:
- The minimal-diff adoption pattern in that README is the template — cells are wired into the layer, never rewritten.
- Every actuator registration requires a rollback contract; no exceptions for "read-only-ish" actuators.
virtuoso_modelshas two homes (src/shared/and the vendored copy inservices/virtuoso-models-service/) that must stay byte-identical — edit once,cp,diff -qverify.- Any deploy-workflow or path-filter change must keep
workflow_dispatchinputs optional (a required-no-default input breaks the Deploy Router) and must be pushed via the SSH remote (HTTPS pushes touching.github/workflows/**are rejected).
Phase 3 — The canonical data file is the deliverable
src/shared/miz_oki_source_of_truth.py is what makes paper and platform the same thing. After this phase:
- It imports the eight decision objects,
ClaimLabel,AutonomyStage, and the envelope frommizoki_contracts(or from the single re-export point Phase 0 chose) rather than restating them. If it currently duplicates any of them — as prose constants, shadow enums, or copied class definitions — the duplicates get deleted in this phase, not deprecated. MODEL_ROLES,NON_BYPASSABLE,STAGE_ROUTING, and the six-domain rules remain here — this file is the registry of values;mizoki_contractsis the registry of shapes.check_conformance()is extended to assert the reconciliation itself: it must fail ifmizoki_core's mirror (if the Phase 0 plan kept one) drifts frommizoki_contractson any field, if a service still references the dev signing key default, or if anyadvisory_only/FORBIDDEN_AUTONOMYscope has been narrowed since v3.5.2.- Bump
VERSIONandLAST_VALIDATED, runcheck_conformance()live (PYTHONPATH=src/shared), and record zero violations in the commit message.
Phase 4 — Verification gates (all must be green before the final push)
python3 -m unittest tests.test_six_domain_blueprint— 29/29.pytest tests/shared/test_virtuoso_models.py— 34/34 (in-package suites run separately, 25/25 each; running both files in one invocation collides on the module name — that is not a real failure).mizoki-remediation/tests/test_end_to_end.py— 8/8 in-memory.python3 mizoki-remediation/tools/claims_lint.pyover changed files — clean.check_conformance()— zero violations, including the new reconciliation assertions.diff -qacross the twovirtuoso_modelshomes and (if kept) themizoki_coremirror parity test.
Prohibitions (absolute — a blocked gate is a finding, not an obstacle)
- Do not lift advisory-only on finance or CRE, and do not touch
FORBIDDEN_AUTONOMYscopes, for any reason including "the test needs it." - Do not promote any scope to Stage 4 or make the Stage-4 execution path reachable.
- Do not weaken a gate to get past it — no skipping tests, no loosening
claims_lint.pyvocabulary, no relaxingcheck_conformance(), no wideningadditionalProperties, no--no-verify. If a gate blocks you at the end of the session, commit the passing subset, write the blocker intodocs/RECONCILIATION_PLAN.mdunder "Open items," and stop. An honest partial landing beats a forced green one. - Do not open ingress, disable auth, or bypass the API gateway to make a probe pass.
- Do not sync
miz_oki_3.5_integrated/bundle contents oversrc/shared/— the bundle is a historical record. - Do not upgrade claim labels. Everything remains
built, pre-benchmarkuntil Stage 2 domain benchmarks exist; no "verified"/"benchmark"/"pilot" language enters any doc or docstring from this session. - Do not run manual deploy sweeps after your branch auto-merges — check the Deploy Router run for the merge instead.
Deliverables checklist
- [ ]
docs/RECONCILIATION_PLAN.md(Phase 0, committed first, updated at session end with open items) - [ ] Defect-closure commits, each citing a defect ID (Phase 1)
- [ ] Cell wiring per the integration map (Phase 2)
- [ ]
miz_oki_source_of_truth.pyimporting shapes frommizoki_contracts, duplicates deleted,check_conformance()extended and passing (Phase 3) - [ ] All six verification gates green, results quoted in the final commit message (Phase 4)
- [ ] CLAUDE.md session record appended (this repo's convention: the tree is the record; PRs against auto-merged branches are impossible)