AUDIT.md — MIZ OKI 3.5 Integrated Bundle

Full-session audit record · 2026-07-25

Scope: every artifact produced in this build session, re-reviewed from the top with fresh eyes and re-tested with the real toolchain. Proof of health: python selfcheck.py → 20/20 checks pass (exit 0).


A. Issues found in THIS audit pass (all fixed, all regression-tested)

# Severity Where Bug Fix
1 Critical (test infra) every prior test run pip install jsonschema ran without --break-system-packages, failing silently on Ubuntu 24 — so all earlier "validation PASS" results used the weak fallback validator, never real JSON Schema validation jsonschema installed correctly; selfcheck _t5 requires the real validator; MIGRATION documents the flag
2 Critical virtuoso_models/schemas/journey-event.json schema (additionalProperties:false) had no top-level source_payload_hash, but every mapper emits it → with real jsonschema, every mapped event failed validation; ingestion would be dead on arrival in production. Masked by #1 property added to schema; all 4 mappers re-validated with real jsonschema; schema_hash auto-updated
3 High mizoki_media/mdes.py _action_rank 4 of 5 declared high-blast-radius actions (channel_launch, channel_kill, audience_strategy_change, bid_strategy_migration) ranked as "never allowed" → the operator-gate path for them was unreachable at any band high-blast actions rank at expansion level: reachable only at the expand band, always behind the hard gate; unknown actions still never authorizable
4 High mizoki_media/contracts.py MediaEvent event_id hashed only kind+channel+timestamp → distinct payloads in the same second collide, breaking ingest idempotency payload sha256 folded into the id; collision regression test added
5 Medium (correctness) mizoki_cre/simulation.py break-even occupancy formula double-counted occupancy (ads·occ²/NOI instead of ads·occ/NOI) → understated break-even formula corrected; sanity band asserted in selfcheck
6 Medium (honesty) mizoki_cre/simulation.py with zero history rows the gate still named historical_bootstrap primary while simulate() silently ran Gaussian → the passport misrepresented its own method zero-history → Gaussian primary with history_status:"none_gaussian_proxy"; proxy-substituted baselines carry an explicit "proxy" label; source-of-truth rule text synced
7 Low (toothless control) mizoki_finance/contracts EvidenceBundle explanation_ready checked contradicting_sources is not None, but the field defaulted to [] — the "contradiction search must have run" control could never fail default is now None (= search never ran → not ready); the retrieval pipeline always sets a real list; regression test added
8 Hygiene prior turns no permanent test suite existed — MIGRATION.md told operators to "run the pytest suites" that were never shipped; all prior tests were inline throwaways selfcheck.py shipped at bundle root: 20 permanent checks incl. regression tests for #2–#7; MIGRATION step 2 now runs it

B. Issues found and fixed in EARLIER passes (for the complete record)

C. What was checked and found SOUND this pass

Role lock + reversible 3.5-Pro flip; cross-vendor failover incl. fallback=False re-raise; legacy-string guard; ingest idempotency (insert→duplicate→updated); finance look-ahead guard, no-bypass ValidationLab (weak signal FAILs: PBO 0.83/DSR 0.0), end-to-end pipeline chain integrity; media consent envelope (EEA TCF-native, IP-matching refusal, erasure propagation), incrementality-gated expansion, score-alone-never-unlocks, OPE clipping + divergence warning; CRE NOI chain, SR 11-7 validator independence, sequential phase locks, multi-year Phase B, weight-calibration guards; three-domain conformance.

D. Standing limits — unchanged and stated plainly

  1. 0% deployed. Nothing here has been pushed to GitHub, built into an image, or served on Cloud Run. No live API call to any model vendor has ever been made from this environment; the failover test stubs the dispatch layer.
  2. Verified in isolation. Deterministic stubs stand in for trained models (regime engines, TGNN, uplift), real market/ad/deal data, Neo4j/BigQuery sessions, and a real CMP. The interfaces are production-final; the internals behind hooks are Phase-3 prototypes by design.
  3. Internal repo claims remain unverified (Chrome extension six-tool registration) — verify via CLAUDE_CODE_PROMPT.md against the actual repo.
  4. gemini-3.5-pro flip target is provisional until GA; flip is env-gated and reversible. Claude Fable 5 remains uncallable via API (suspended) — routing correctly avoids it.
  5. Path to live: PUSH.md → CLAUDE_CODE_PROMPT.md in Claude Code → staging with live-key proofs → production behind observe/recommend autonomy (MIGRATION.md).
← All docsView source on GitHub →