CC-1b_CLAUDE_CODE.txt

You are working in the MIZOKI-3-5/MIZOKICloudRun repository (MIZ OKI 3.5, a governed
decision-intelligence platform: 39 Cloud Run cells, BigQuery, Firestore, Next.js command-center UI).
Read in this order before touching code: CLAUDE.md, CONSTITUTION.md (Article VI governs governance
surfaces), docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md, docs/audits/wo/<your WO files>, and
docs/audits/AUDIT_2026-09-06_RECONCILIATION.md if it exists (CX-1 writes it).

Ground rules
- Audit findings are HYPOTHESES pinned at commit fc8b03f9. main has moved. Step 0 of every WO is:
  reproduce the counterexample on current main with a failing test. If it does not reproduce,
  record "not reproduced on <sha>" in your report and move on — do not fix what is not broken.
- Fail closed. Every fix must make a refusal path explicit and tested. Never widen access to make a test pass.
- No new architecture. Reuse the existing modules named in the WO. If a WO says "reuse X", reuse X.
- Tests are the deliverable. Each WO lists acceptance tests; write them first, watch them fail, then fix.
  Name them test_wo<nn>_<what>. Keep the audit's synthetic counterexample numbers ($40 refund → $80,
  $70+$70 vs $100 cap, DEL 91.7, etc.) as fixtures so the regression is recognizable.
- Branch: audit/<PROMPT-ID>-<slug>. NEVER use a claude/* branch (they auto-merge to main in seconds).
  Commit per WO with message "WO-nn: <title>". Open ONE PR for the prompt when done. Do not merge.
- Protected paths (.github/**, deployment/terraform/**, deployment/cloudbuild*, CODEOWNERS): review PR only.
- Never write a typed gate token in full anywhere (docs, commits, PR bodies, reports): the gate-leak
  ratchet (tests/test_gate_leak_scan.py) turns main red. Refer to it only as APPROVED: [MERGE].
- Do not deploy, do not change Cloud Run config, do not touch secrets, do not run anything against
  production BigQuery/Firestore, do not spend money on any provider. Local + test fixtures only.
- Coordination: before starting, run
    python scripts/claude_memory.py record --title "<PROMPT-ID> claim" --summary "<WOs> on branch <name>" --tags coordination
  if the script exists; if not, add a line to docs/audits/COORDINATION.md.
- Stop and report (do not guess) if: a fix needs a new secret, a provider account, an IAM change,
  a schema migration on a live dataset, or a change to a file owned by another prompt (see the
  ownership table in docs/audits/AUDIT_EXECUTION_PROMPTS_2026-09-08.md).

Final report — write docs/audits/reports/<PROMPT-ID>_REPORT_<date>.md with, per WO:
  status (fixed | not reproduced | blocked), repro test name + first failing run, fix summary,
  files changed, acceptance tests + pass evidence, anything deferred and why. End with the PR URL,
  the exact test command(s) that prove the pack, and the commit SHA the PR is based on.

PROMPT-ID: CC-1b. Branch: audit/cc-1b-f4-calibration-exploration (base on the head of PR #1016, or on main after it merges).
Purpose: CC-1 (PR #1016, report docs/audits/reports/CC-1_REPORT_2026-09-09.md §WO-01 "Owner decision surfaced") pinned that the live F4
geo-calibration passport is BLOCKED by WO-01's hard checks (consent_coverage 0/0, incremental_profit −cap, incrementality_evidence,
causal_refutation). Owner ruling: resolve via option (ii) — a DECLARED, bounded, test-pinned exploration eligibility on the calibration
domain, implemented as WO-02's exploration class, never as an exemption from HARD checks that can be reached silently. Lane: ENG. P0.
You own: services/service-policy-engine/**, services/service-decision-control-plane/**, services/growth-scheduler/main.py (_seal_passport only),
tests/governance/test_wo01_02_hard_gates.py (add tests; do not weaken existing ones).

Fix:
  1. growth-scheduler _seal_passport: seal the F4 passport with eligibility_class=exploration, envelope_id=<the F4 pilot's approved
     envelope record id, read from tenant config — never hardcoded>, cap = the tenant's F4 per-cycle cap (the live pilot's is $2,500/cycle),
     and the logged assignment probability the geo split already produces. Also seal consent_coverage from the geo panel (it is measurable)
     so that HARD check passes honestly instead of being waived.
  2. policy-engine: exploration candidates are still subject to consent, integrity and policy HARD checks; the ONLY check an exploration
     candidate may carry as 'exploration-deferred' is incremental_profit / incrementality_evidence / causal_refutation, and only when
     envelope_id resolves, spend ≤ cap, and the envelope's domain equals the passport's domain (calibration). Emit reason code
     EXPLORATION_ENVELOPE_APPLIED on the decision record so it is visible in review.
  3. Rename nothing; keep test_wo01_f4_shaped_calibration_passport_is_now_blocked_by_hard_checks passing for a passport WITHOUT an envelope
     (that is still the correct outcome) and add test_wo01b_f4_calibration_passport_with_envelope_is_exploration_eligible plus
     test_wo01b_exploration_over_cap_is_blocked and test_wo01b_exploration_with_consent_gap_is_blocked.
Acceptance: all CC-1 tests still pass; the three new tests pass; deploy_router dry run lists only the governance + growth-scheduler workflows.
Gates: same as CC-1 (pytest tests/governance -c tests/governance/pytest.ini; content_gates.sh; gate_leak_scan --check; skill_sync.py --audit).
PR title: "Audit pack B follow-up — F4 calibration as declared exploration (WO-01/02)".
← All docsView source on GitHub →