CX-1_CODEX.txt

You are working in the MIZOKI-3-5/MIZOKICloudRun repository (MIZ OKI 3.5, a governed
decision-intelligence platform: 39 Cloud Run cells, BigQuery, Firestore, Next.js command-center UI).
Read in this order before touching code: CLAUDE.md, CONSTITUTION.md (Article VI governs governance
surfaces), docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md, docs/audits/wo/<your WO files>, and
docs/audits/AUDIT_2026-09-06_RECONCILIATION.md if it exists (CX-1 writes it).

Ground rules
- Audit findings are HYPOTHESES pinned at commit fc8b03f9. main has moved. Step 0 of every WO is:
  reproduce the counterexample on current main with a failing test. If it does not reproduce,
  record "not reproduced on <sha>" in your report and move on — do not fix what is not broken.
- Fail closed. Every fix must make a refusal path explicit and tested. Never widen access to make a test pass.
- No new architecture. Reuse the existing modules named in the WO. If a WO says "reuse X", reuse X.
- Tests are the deliverable. Each WO lists acceptance tests; write them first, watch them fail, then fix.
  Name them test_wo<nn>_<what>. Keep the audit's synthetic counterexample numbers ($40 refund → $80,
  $70+$70 vs $100 cap, DEL 91.7, etc.) as fixtures so the regression is recognizable.
- Branch: audit/<PROMPT-ID>-<slug>. NEVER use a claude/* branch (they auto-merge to main in seconds).
  Commit per WO with message "WO-nn: <title>". Open ONE PR for the prompt when done. Do not merge.
- Protected paths (.github/**, deployment/terraform/**, deployment/cloudbuild*, CODEOWNERS): review PR only.
- Never write a typed gate token in full anywhere (docs, commits, PR bodies, reports): the gate-leak
  ratchet (tests/test_gate_leak_scan.py) turns main red. Refer to it only as APPROVED: [MERGE].
- Do not deploy, do not change Cloud Run config, do not touch secrets, do not run anything against
  production BigQuery/Firestore, do not spend money on any provider. Local + test fixtures only.
- Coordination: before starting, run
    python scripts/claude_memory.py record --title "<PROMPT-ID> claim" --summary "<WOs> on branch <name>" --tags coordination
  if the script exists; if not, add a line to docs/audits/COORDINATION.md.
- Stop and report (do not guess) if: a fix needs a new secret, a provider account, an IAM change,
  a schema migration on a live dataset, or a change to a file owned by another prompt (see the
  ownership table in docs/audits/AUDIT_EXECUTION_PROMPTS_2026-09-08.md).

Final report — write docs/audits/reports/<PROMPT-ID>_REPORT_<date>.md with, per WO:
  status (fixed | not reproduced | blocked), repro test name + first failing run, fix summary,
  files changed, acceptance tests + pass evidence, anything deferred and why. End with the PR URL,
  the exact test command(s) that prove the pack, and the commit SHA the PR is based on.

PROMPT-ID: CX-1. Branch: audit/cx-1-current-truth. RUN THIS FIRST — every other pack reads your output.
Work orders: WO-00 (P0), WO-30 (P2), WO-31 (P2). Lane: ENG + OWNER.
You own: docs/audits/** (new files only; do not edit AUDIT_WORK_ORDERS_2026-09-08.md or wo/*),
OPEN_ITEMS.md, docs/BUILD_DEBT.md, miz-oki-command-center-ui/app/api/bff/lanes/** and the
onboarding page's readiness display only.

WO-00 Pin the audit commit and diff to current main
  1. git fetch; record main SHA. Confirm fc8b03f9da963f79d010df05fdb9e16c467e0d8f is an ancestor.
  2. For each of the 44 WOs in docs/audits/wo/manifest.json (WO-00..43 plus WO-44..49 from the v1.1 review), take the "Files" line, and produce
     git diff --stat fc8b03f9..main -- <those paths>. Classify each WO: unchanged | moved (give new
     path) | already fixed (cite the commit and the test that proves it) | file missing.
  3. Write docs/audits/AUDIT_2026-09-06_RECONCILIATION.md: a table with one row per WO-nn and per
     R0..R33: path at fc8b03f9, path at main, classification, evidence, owning prompt (from the
     ownership table in docs/audits/AUDIT_EXECUTION_PROMPTS_2026-09-08.md). Also record: main SHA,
     date, and the list of files that exist at main but not at fc8b03f9 in the owned paths.
  4. Specifically resolve these unknown locations and write them into the table: the shared tenant
     resolver (grep "def resolve_tenant", "TenantRegistry", "strict_mode"); cell 26 and cell 27
     modules (config/actual_urls.py, cell registry, src/cells/, srpaldl-cells/); the site pilot
     request code for WO-33 (not found under repo root — check the website repos referenced in
     docs/ and CLAUDE.md, and record the repo+path or "not in this repo").
  5. Do not create tickets; do not fix code.
  Accept: all 44 WO rows and all 34 R rows filled; no "TBD". Also record the GitHub issue number for each WO from docs/audits/wo/issue_map.json.

WO-30 Lane-readiness evidence join
  Files: miz-oki-command-center-ui/app/api/bff/lanes/status/route.ts (+ route.test.ts), onboarding page readiness display.
  Step 0: Vitest: a tenant with no economics record; assert the lane currently reports "ready"
          (or whatever the default is). If it already reports not_ready, record "not reproduced".
  Fix: every readiness flag must be derived from a present, non-default evidence record with a
       timestamp; missing/default → not_ready with a reason string shown in the UI.
  Accept: no-economics tenant → not_ready; stale evidence (older than the lane's freshness window) →
          not_ready:stale; full evidence → ready.

WO-31 Reconcile the open register
  Files: OPEN_ITEMS.md, docs/BUILD_DEBT.md.
  Fix: add one line per WO-nn under a new "Audit 2026-09-06 remediation" section linking to
       docs/audits/wo/WO-nn.md and (once they exist) the GitHub issue numbers from
       docs/audits/wo/issue_map.json; close/strike any register item superseded by the Sep 2 state
       (e.g., #804 closed via #809/#810, F4 global params, supply-veto v2) with the superseding
       reference. Do not create a second status document.
  Accept: one register; every WO linked; no duplicate of an already-closed item; git diff shows only
          additions and strike-throughs, no deletions of open items.

Gates: npx vitest run app/api/bff/lanes; markdown lint if configured.
PR title: "Audit pack A — reconciliation table, lane readiness, register (WO-00, 30, 31)".
← All docsView source on GitHub →