FEATURE COVERAGE MATRIX v1.0
Date: 2026-08-25 (§10 + Gap Register G-25–G-28 + two CODE-VS-CANON rows added 2026-08-26, xdomain-r14 sweep) Author: AGENT B (CLAUDE-B), Product Launch v5.3 Phase 2B Canon sources: SIGNAL_SHOPIFY_MASTER v4.0 · GROWTH_CONTROL r2.0 + amendment r3.5.2 · WHITEPAPER r3.5.1 · MARKETING_AUTOMATION_WHITEPAPER r1.2 + amendments r1.3, r1.4 · OFFERING_MAP v2.3 · SIGNAL_OVERVIEW v5.3 · CELL_REGISTRY v1.1 · service-registry.yaml v2 Status vocabulary: LIVE (deployed and measured) · PARTIAL (shipped, incomplete surface) · IN BUILD (active development, flags off) · PROPOSED (designed, not approved) · DARK (built, flag-off by design, activation gated) Claim discipline: [Validated] / [Illustrative] / [Roadmap] per TRUTH.md. Canon guardrail: "anticipatory intent with proof of causal lift" — mind-reading / prediction framing BANNED.
1. ANTICIPATORY INTENT PIPELINE
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 1.1 | Cell 33 — micro-signal ingestion | src/cells/cell33/ → intent-signal-ingest (Cloud Run, IAM-locked) |
PARTIAL | Consent gate blocks a disallowed signal type in real time | Signal Factory demo, Command Center | Shadow/observe-only; no real merchant traffic yet (register item 6: first real store webhook pending) |
| 1.2 | Consent gate (fail-closed) | src/cells/cell33/ — consent check runs before persistence; DISALLOWED_KEYSTROKE_DYNAMICS tag |
LIVE | Red gate block in Signal Factory — signal rejected with named tag | Signal Factory demo, /signal page | — |
| 1.3 | O-1 prohibited signals (audio/keystroke/gaze) | Schema-level rejection in Cell 33 collector + ingestion; test-asserted both directions | LIVE | Show rejection of a keystroke event, dual assertion (permitted lifecycle validates, rejected class fails) | Trust features section, compliance docs | — |
| 1.4 | Cell 34 — intent scoring API | src/cells/cell34/ → intent-scoring-api (Cloud Run, IAM-locked) |
PARTIAL | Sub-100ms score with explanation path | Intent Scores Grid (Command Center) | Model quality gate open: fv2 AUC 0.6967 mean / Brier 0.1845 over 8 seeds; fixture ORACLE ceiling 0.7277 — 0.72 autonomy line unreachable on synthetic data. Blocked on real forward labels (register item 17 / 6c / 23) |
| 1.5 | I-01 PassiveAttentionSequence | Cell 33 micro-signal capture — viewport deceleration, dwell, scroll velocity, swipe vectors, partial-watch depth, tab blur/return | PARTIAL | Session replay of ordered micro-behavior stream | Intent API docs | Retention: ephemeral (session-end purge). Content-free by construction. Web Pixel extension path exists but flag-off |
| 1.6 | I-02 SessionOutcomeForecast | Cell 34 session sequence model — compact causal transformer (4 layers, 128 dims, 4 heads); three output heads (stage transition, next-interest, hesitation). UNTRAINED — ships with deterministic seeded weights (model_version: "sst-v1-untrained"), shadow-only (intent_scores_shadow). |
IN BUILD | Predicted stage-transition probability with drift metadata | Predicted Journey Timeline | Behind LII_REALTIME flag (default OFF); shadow writes only, never served; attention summaries join explanation payload when served |
| 1.7 | I-03 CreativeSemanticProfile | Multimodal encoders → unified.creative_vectors; decayed aesthetic-affinity vectors; RESONATED_WITH edges in intent graph |
IN BUILD | Creative element → session context alignment score | Creative Intelligence panel | Ranking behind its own flag with automatic revert to default rotation |
| 1.8 | I-04 IntentHypothesis | Cell 35 intent-graph — temporary bridge nodes with support, confidence, 30-day TTL, provenance; hypothesis is the only writable status |
IN BUILD | Show a latent bridge between disconnected behaviors with deny-list screening | Growth Decision Graph visualization | Promotion to targetable requires owner approval; deny-list screening at creation (sensitive composites rejected at write time, test-proven) |
| 1.9 | I-05 ValidationPassport | contracts/mizoki_contracts/ passport module; 18 SPEC_FIELDS + per-tenant chain block; chain-walk verify route on service-audit-replay |
PARTIAL | Full evidence packet for any decision: signals used, model versions, refutation results, confidence, consent basis | Audit ledger, pilot report | Passport-chain v1 landed (skill v3.6); pilot-report generator is a skeleton until first real pilot |
| 1.10 | Cell 35 — intent graph (Firestore-backed) | src/cells/cell35/ → intent-graph (Cloud Run, IAM-locked); Firestore own-collection + boot rebuild + DSAR/erasure leg |
PARTIAL | Interest edges with decay, sequence edges with lift/support/confidence | Knowledge Graph viewer (Command Center) | DSAR live-verified 2026-08-10; Neo4j retired 2026-08-09; durable-store phase 1 (321 tests) |
| 1.11 | Cell 36 — causal credit | src/cells/cell36/ → intent-causal (Cloud Run, IAM-locked); caused-vs-anticipated classification, refutation battery |
LIVE | Conversion classified caused vs. anticipated with confidence interval | Incrementality Panel (Command Center) | Live-verified 2026-08-11 (rev 00012-j27); refutation_engine=arm_level_permutation |
| 1.12 | Explanation payload | Intent scores never served as bare numbers; attention summaries + reasoning path accompany every score | IN BUILD | Score + graph-backed reasoning path shown together | Intent API, Command Center scores grid | Full explanation payload depends on I-02 transformer being active |
| 1.13 | Agent-originated conversions (origin dimension) | src/shared/virtuoso_models/origin_classifier.py + origin_strata.py (schema fields origin_class / origin_protocol / origin_evidence, names-only; rule classifier; read-side credit strata), services/service-canonical-ingestion/origin_shadow.py (shadow table unified.origin_classification_shadow, AGENT_SHARE_THRESHOLD) |
IN BUILD (dark, ORIGIN_CLASSIFIER=false) |
Flag ON in a hermetic run: an event with a declared agent-protocol header lands ONE shadow row keyed sha256(event_id); the event row is unchanged; credit output byte-identical with and without strata | none — site line HELD (OPEN_ITEMS S2-D5) | docs/specs/GOVERNED_DECISION_FEED_v0.1.md (PROPOSED); image lacks src/shared (S2-D2); header-name reconciliation (S2-D4); strata route wiring BUILD_DEBT S2-BD-1/2 |
2. CAUSAL PROOF
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 2.1 | Qualified holdouts | Cell 36 holdout registry — randomized, ghost-bid, matched-geo types; deterministic arm assignment; holdout registration mandatory before activation | PARTIAL | Register a holdout, show deterministic arm assignment | Measurement panel, API | No real registered holdout exists yet (register item 23) |
| 2.2 | Geo holdouts | services/service-media-incrementality/ + F4 growth-scheduler geo-reservation engine |
PARTIAL | Matched-market design with owner-configured geographies | Geo experiments panel | F4 LIVE-ARMED for mycocoons (US-CA/NY/FL/TX, $2,500/cycle, ±30%); L2-approval-gated |
| 2.3 | Intention-to-treat (ITT) | Measurement on assignment, not delivery — Cell 36 intent-causal service | PARTIAL | Show measurement on assigned cohort regardless of delivery outcome | Measurement methodology docs | Serving but observe-only |
| 2.4 | CATE meta-learners (S/T/X/DR-Learner) | Cell 26 cell26-causal-uplift (X-Learner live); Cell 27 (DR-Learner/DoWhy refutation) |
PARTIAL | Heterogeneous treatment effects showing WHERE lift concentrates | Uplift-quadrant targeting | X-Learner live-verified 2026-08-11; DR-Learner serving via Cell 27; uplift → DCP activation gated |
| 2.5 | Automated DoWhy refutation | Cell 27 + Cell 36 refutation battery — placebo-treatment collapse, random-confounder invariance, subset stability | PARTIAL | Estimate survives/fails refutation with named test results | Refutation status in Incrementality Panel | An estimate that fails refutation is flagged, never shipped |
| 2.6 | Causal Credit Ledger | unified.causal_credit_ledger (immutable); caused vs. anticipated per conversion with confidence intervals |
PARTIAL | Single conversion traced through classification with CI whiskers | Console /latent/overcharge — Overcharge Statement (catalogue L2), IN BUILD (Wave 2 WS-6, 2026-09-02; not deployed) (route + view mounted; no BFF read of unified.causal_credit_ledger exists and no holdout is registered, so the view renders "no data" under its ILLUSTRATIVE watermark). Audit surface: this row |
Ledger architecture live; population requires real holdout data |
| 2.7 | Ghost bids | services/measurement-rails/ghost_bid.py (shadow execution + auction logger, built) + GHOST_BID_HOLDOUT_IMPLEMENTATION_PLAN.md (design) |
PARTIAL (DARK) | Show a withheld-bid auction row carrying the same shape a real bid would have | Story 2 (Paying For Your Own Name) preview | Gap: built shadow-only; MEASUREMENT_RAIL_GHOST_BID flag off by design; no live run against real ad spend yet. Not claimed on any customer-facing surface. Register: BUILD_DEBT GB-1 (operator: live run against real ad spend) |
| 2.8 | Federated measurement (design-pilot) | docs/product/FEDERATED_MEASUREMENT_DESIGN_PILOT.md (plan only; no code, no flag, no store) |
PROPOSED | None — designed, never in use; in-tenant measurement unchanged, only DP-aggregated structure labeled as priors would ever leave a tenant; sequenced after the core pilot (Day-90 readout + counsel memo W3-13a — design doc §4 P-1/P-2); owner-declared DP/consent proposal 2026-09-15 under counsel review [PROPOSED] | None (absent from customer docs until the OFFERING_MAP D.3 privacy/legal memo clears) | Gap: Phase 0 privacy/legal memo BLOCKED-ON-OWNER; owner decision 5 (consent default) declared opt-in 2026-09-15 as the proposal counsel reviews — not yet ruled; D-14 OPEN ⇒ no EU tenant; fleet-integrity family A (tests/governance/test_fleet_integrity.py) must be re-proven with an aggregate present (plan §5 E-1…E-7) |
| 2.9 | MMM export adapters (Robyn / Meridian) | src/shared/growth_control/mmm_export/ — causal credit ledger + spend series → Robyn robyn_inputs() frame (ROBYN_INPUT_VERSION = "3.12.1") and Meridian InputData-shaped dict (MERIDIAN_SCHEMA_VERSION = "1.8.0"); caused split → calibration_input / CalibrationBuilder sidecar; PII denylist; idempotent; MMM_EXPORT OFF (source-pinned) |
IN BUILD (dark) | Same ledger rows → byte-identical Robyn CSV and Meridian arrays; dark flag → not_configured |
Measurement interop docs (docs/product/MEASUREMENT_INTEROP.md) |
Gap: spend series, channel map, population, calibration interval are owner-open (W3-S8-1..4); no model has run |
| 2.10 | Batch MMM (Meridian / Robyn) | none — "labeled follow-on" (f4_calibration/priors.py); miz_oki_source_of_truth.py media-domain open proof obligation; F4 prior bridge MMM_PRIOR_WRITEBACK dark per tenant |
PROPOSED | — | — | armed-awaiting-data: ≥ 2 closed quarters per mmm_export.readiness() (data_insufficient below the bar); vendor guidance is stricter (two years weekly) and is quoted, not adopted |
3. PROFIT (NET YIELD)
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 3.1 | Net Contribution Margin (NCM-v1) | Order economics: R − COGS − pick/pack − shipping − fees − E[return cost] − AdSpend(C) under causal credit | IN BUILD | Show an order's true net contribution vs. platform-reported revenue | Profit Truth Audit report template | Metric contract versioned (NCM-v1). Missing costs flag a row incomplete. |
| 3.2 | Per-tenant order economics | config/net_yield_costs.yaml per-tenant cost config; commerce data ingestion from Shopify orders/refunds |
IN BUILD | Side-by-side: platform ROAS vs. net contribution | Console /latent/profit-leak — Profit-Leak Report (catalogue L1), IN BUILD (Wave 2 WS-6, 2026-09-02; not deployed) (route + view mounted; the net-yield ledger has no governed BFF read — per-key reads only, dispatch-only — so the view renders "no data" under its ILLUSTRATIVE watermark); pilot report. Audit surface: this row |
Gap: net_yield_costs has 5 NULLs (register item 21 — operator: real cost values needed) |
| 3.3 | Continuous dosage estimator | services/lift-engine/ — cross-fitted R-learner convention (built in GC Activation v2.1) |
IN BUILD | Optimal spend-per-channel recommendation based on marginal iNCM | Budget Intelligence panel | Built flag-off; pilot configuration gates activation |
| 3.4 | LTV regimes (F2) | Dynamic treatment regimes; ledger outcome-horizon dimension; findings gated on ≥2 observed quarters | IN BUILD | Multi-quarter retention vs. immediate conversion trade-off | F2 LTV panel (DARK) | Gap: F2 data-gate — requires ≥2 observed quarters per cohort. F2_ORDER_ECONOMICS_BQ_TABLE unset. |
| 3.5 | Both writebacks OFF | MEASUREMENT_WRITEBACK=false, NET_YIELD_WRITEBACK=false; tests fail if flipped without approval |
LIVE (safety posture) | Show the flag-off assertion and the test that guards it | Trust features, governance docs | Each requires its own verified pilot and separate approval. Source-literal defaults test-asserted. |
4. CHANNEL RAILS
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 4.1 | Meta CAPI | Two implementations: (1) service-action-runner adapters MetaCapiConversionUploadAdapter + MetaCapiValueRestatementAdapter (execution path); (2) services/measurement-rails/meta_capi.py (governed rail, shared event_id dedup). Both triple-gated (rail flag + dry_run + transport). |
PARTIAL | Server-side conversion event transmitted to Meta with dedup proof | Measurement rails docs | Both execution and rail OFF; tenant allowlist empty |
| 4.2 | Enhanced Conversions (Google) | services/measurement-rails/google_enhanced_conversions.py — Google Ads API v22 uploadConversionAdjustments, SHA-256 normalized identifiers. No standalone action-runner adapter — exists only in measurement-rails and boss agentic code. |
PARTIAL | Google Ads value signal: margin, not revenue | Measurement rails docs | Rail OFF; no action-runner execution adapter (boss agentic module only) |
| 4.3 | GA4 Measurement Protocol | GA4 MP server-side events; intent-ga4-extender service |
PARTIAL | GA4 event enrichment with intent-derived signals | Connector status page | Gap: GA4 extender needs BQ link + dataViewer grant + env var (register item 6 — operator, 3 steps) |
| 4.4 | Google Ads adapter | service-action-runner — google_ads campaign budget+status, ad-group bid, keyword bid+status |
PARTIAL | Budget reallocation recommendation with clipped-ReLU authorization | Budget Intelligence panel | 13 adapters installed, all switches false; recommend-only posture |
| 4.5 | Meta Ads adapter | service-action-runner — meta_ads campaign budget+status, adset bid+audience |
PARTIAL | Audience exclusion recommendation | Audience Intelligence panel | Same off posture |
| 4.6 | Klaviyo integration | services/service-marketing-connectors/klaviyo_connector.py — aggregate campaign reporting only; structurally refuses person-capable endpoints (_assert_aggregate_endpoint). No action-runner execution adapter. |
PARTIAL | Aggregate campaign metrics; suppress Klaviyo-converting audiences from paid spend | Lifecycle coordination docs | Gap: Klaviyo puller aggregate-only (no per-person data by design); secret VERSION needed (register item 6 — operator); webhook half BUILT flag-off 2026-08-27 (klaviyo_webhook.py, KLAVIYO_WEBHOOK_ENABLED dark — W7) |
| 4.7 | Observe-only default | Every adapter defaults to observe-only; execution authority is a separate explicit grant | LIVE (safety posture) | Adapter dashboard showing all switches OFF | Trust features section | — |
| 4.8 | Klaviyo email/SMS value feed (W5) | services/measurement-rails/klaviyo_feed.py + ncm_feed_wiring.build_klaviyo_value_events/send_klaviyo_value_events — mirrors the Meta CAPI / Google EC rail pattern; E[NCM]-shaped events only (margin, never raw revenue), gated by KLAVIYO_FEED (default OFF, same as every other rail). health() reports not_configured until KLAVIYO_PRIVATE_API_KEY is set. Distinct from row 4.6's aggregate-reporting PULL connector (KLV-1) — this is the per-conversion value PUSH half. |
DARK | Order-margin event delivered to a Klaviyo flow trigger, never raw revenue | Measurement rails docs | Skeleton only: no tenant credential wiring, no GATE 2. Site/product copy labels this [Roadmap] until GATE 2 + real credentials exist — no LIVE claim. |
| 4.9 | Amazon Ads — measurement interop | connector: services/service-marketing-connectors/direct_connectors.py amazon_ads fail-closed direct-pull adapter (catalog available: False, "Wave 3 — adapter not live-verified yet"); interop (spend → MMM channel, console-attributed sales → reported) unbuilt |
ROADMAP (connector PARTIAL) | — | — | Marketplace-reported attribution is reported evidence, never incrementality; no live verification |
| 4.10 | Walmart Connect | none — no provider, catalog row, adapter, registry entry or env var in the tree (grep -rni "walmart connect\|walmart_connect" → 0 code hits) |
ROADMAP | — | — | Same interop shape as 4.9 once a connector exists; retail-media console ROAS is dashboard ROAS by construction (MEASUREMENT_INTEROP.md §1, §5); catalog row = OPEN_ITEMS W3-S8-8 |
5. DECISIONING
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 5.1 | Decision Jobs J-01 through J-06 | config/decision_jobs.yaml + registry module + GET /api/v1/jobs on service-audit-replay |
IN BUILD | Decision job catalog: each job with input telemetry, eligible decisions, constraints, evidence, outcome | Decision Jobs catalog (Command Center) | Registry exists; internal routes serving; customer-facing SLA packaging at Phase 8 |
| 5.2 | DEL Score + authorization | service-decision-control-plane — DEL score computed by Policy Engine as linear weighted average: 100 * (0.5*passport_pass_rate + 0.3*evidence_completeness + 0.2*verification_weight). CODE-VS-CANON NOTE: canon doc (DEL_AUTHORIZATION_FUNCTION.md) describes clipped-ReLU authority_c = min(cap_c, max(0, DEL_score − threshold_c)); code implements linear formula + HMAC-signed authorization. The concept (threshold-gated authority) is present; the activation function shape differs. |
PARTIAL | Show a proposed action below threshold → blocked; above threshold → authorized with signed proof | Signal Factory demo (5 guardrails), DEL authorization panel | Platform floor thresholds raisable by customer, never lowerable. Gap G-18: code formula ≠ canon formula. |
| 5.3 | Blocking verdicts | DCP produces a documented decision NOT to act. CODE-VS-CANON NOTE: no formal WITHHOLD verdict in Eligibility enum; actual values are eligible, approval-required, experiment-required, advisory-only, blocked. The concept (documented non-action with reasoning) exists as blocked + advisory-only. |
PARTIAL | Show a blocked or advisory-only eligibility with full reasoning path |
Decision Queue (Command Center) | — |
| 5.4 | Autonomy stages | service-policy-engine declarative policy.yaml, hash-versioned; per-domain DEL thresholds. CODE-VS-CANON NOTE: code implements two-stage model: STAGE_3_RECOMMEND_ONLY and STAGE_4_BOUNDED_AUTONOMY. Canon describes L0–L5 six-level ladder. Five policy domains defined: default, media, calibration, finance (advisory-only), cre (advisory-only). |
PARTIAL | Show autonomy stage per domain; one-tap kill switch | Autonomy panel, pilot report | Gap G-19: shipped 2-stage model vs canon 6-level ladder. Promotion from Stage 3→4 is a manual human POST, not automated. |
| 5.5 | Autonomy promotion gates | Brier ≤ 0.20, AUC ≥ 0.72, stable lift ≥ 2 purchase cycles — described in metric_contracts.py as threshold definitions. Evaluator machinery BUILT 2026-08-27 (src/shared/l5_certification/ — observe-only Brier/AUC/stability evaluation with never-auto-upgrade policy; W5). CertificationCheck fingerprint primitive integrated. Promotion remains a manual POST /api/v1/actuators/stage and is unwired to the evaluator by design. |
IN BUILD | Show metric thresholds that a model must meet (threshold display, not automated evaluation) | Governance docs, pilot report | Gap G-20 (narrowed 2026-08-27): the evaluator now exists observe-only (W5); promotion stays manual/human by law. Real evaluations remain blocked on real forward labels (register 17/6c/23), and L5-CERT-1's program document + first pack stay owner-held. |
| 5.6 | Signing authority | DCP holds DCP_SIGNING_KEY; KMS asymmetric passport signing + verify + tamper tests (GC Activation workstream C) |
PARTIAL | Signed decision proof with tamper detection | Audit ledger | Gap: KMS key + verify PEM is GATE 2 owner work |
| 5.7 | Decisions-governed meter (usage counter, observe-only) | services/service-decision-control-plane/decision_meter.py → STORE collection decisions_governed_meter; DDL bigquery/schemas/decisions_governed_meter.sql |
IN BUILD (dark, DECISION_METER=false) |
Arm the flag in a hermetic run: one eligible proposal ⇒ one row; the same proposal again ⇒ no second row; a treasury-vetoed proposal ⇒ nothing | none (internal; no invoice surface) | Billing not wired; BigQuery landing not wired (BUILD_DEBT MTR-1); pricing basis is owner decision S-3 |
| 5.8 | DEL / ValidationPassport open specification | spec/del-validation-passport/v0.1/ — JSON Schema, DEL_SCORE definition, 9 conformance vectors, validator, AP2 interop mapping (PROPOSED) |
IN BUILD | Run tests/spec: vectors verdict as expected; MIZ OKI's own passport output does NOT yet conform (13 deltas recorded, never hidden) |
none (third-party emit/verify is the audience once published) | CONFORMANCE_RESULTS_2026-09-02.md deltas → BUILD_DEBT PASS-1…PASS-6; license/publication OPEN S6-1 |
| 5.9 | Pacing veto (third hard-constraint class) | services/service-policy-engine/pacing_veto.py (pure function; per-decision / daily / cycle caps, velocity, holdout-at-L2+, autonomy ceiling L3) wired into evaluate() behind PACING_VETO (owner ruling W3-12a, 2026-09-15); tests/governance/test_pacing_veto.py |
IN BUILD (dark: PACING_VETO default off, absent from the deploy env; flag-off output byte-identical, test-pinned) |
Flag-on hermetic run: a proposal over the daily cap is BLOCKED with a named constraint; flag-off run is byte-identical | none until armed; treasury/supply vetoes precede it | docs/design/AD_CONTROL_PLANE_BANDIT_CAUSAL_BIDDING_DESIGN.md §4; BUILD_DEBT PACE-1 (closed 2026-09-25, row deleted per that file's convention; the Closed note carries the cite); register docs/governance/DARK_FLIP_EVIDENCE_GATES.md row PACING_VETO |
| 5.10 | Ad Control Plane — bandit arms + causal bidding | docs/design/AD_CONTROL_PLANE_BANDIT_CAUSAL_BIDDING_DESIGN.md (design only; no governed bandit code; causal bidding refused by name while the dosage estimator is advisory) |
PROPOSED | — (design; nothing runs) | none | exploration budget field landed (W3-12b) but nothing reads it at runtime; envelope cap not bound to it; DCP does not forward bid_multiplier_source (design doc gaps) |
6. FRONTIERS (F1–F5)
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 6.1 | F1 — Creative component unbundling | DR-Learner + multimodal vision-language embeddings on CreativeSemanticProfile lane | IN BUILD (DARK) | Element-level causal effect: promo framing vs. layout vs. imagery | Creative Intelligence panel | Estimates labeled provisional until pilot creative volume; generated-creative deployment retains human approval |
| 6.2 | F2 — Multi-quarter LTV treatment regimes | Dynamic treatment regimes; ledger outcome-horizon dimension; F2_ORDER_ECONOMICS_BQ_TABLE |
IN BUILD (DARK) | Balance immediate conversion against discounted multi-quarter retention | LTV regime panel | Gap: findings gated on ≥ 2 observed quarters per cohort (code guard). BQ table unset. |
| 6.3 | F3 — Supply-chain / inventory yield sync | Inventory telemetry joins Growth Decision Graph; bids throttle on stockouts, accelerate on overstock | IN BUILD | Show a bid pause triggered by stockout detection | Inventory sync panel | Observe-only by owner ruling. No-dispatch invariant enforced by test. |
| 6.4 | F4 — Continuous Bayesian geo calibration | services/growth-scheduler — geo-reservation engine, synthetic-control estimator, Bayesian MMM prior updater |
LIVE (ARMED) | Automated geo reservation with spend perturbation and realized-lift estimation | F4 calibration panel | F4 LIVE-ARMED for mycocoons (US-CA/NY/FL/TX, $2,500/cycle, ±30%; L0); reservations recommend-only (L2 approval queue + deliberately unregistered actuator). LTV/MMM/EDGE/supply-veto DARK. |
| 6.5 | F5 — Treasury-gated spend governance | service-policy-engine F5 treasury gate — liquidity floors, covenant limits as hard constraints in VALIDATE/DECIDE; veto + human routing on breach |
PARTIAL (DARK) | Treasury floor breach → automatic spend cap tightening with named veto | Console /latent/restraint-ledger — Restraint Ledger (catalogue L5), IN BUILD (Wave 2 WS-6, 2026-09-02; not deployed) (route + view mounted over /api/bff/decisions, /api/bff/actions/outcomes, /api/bff/passports; avoided waste illustrative until measured). Audit surface: this row |
v1 config-declared floors (config/treasury_constraints.yaml); fails closed absent config. Gap: real treasury config values needed (owner). |
7. SHOPIFY APP
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 7.1 | Multi-merchant OAuth install | service-marketing-connectors — OAuth authorization-code grant; MIZ OKI Commerce Link (client ID 039cb627...); docs/architecture/SHOPIFY_OAUTH_INSTALL_DESIGN.md |
IN BUILD | One-click OAuth install from direct link | Shopify app install flow | Gap: OAuth is OFF — source literal is False; shopify-app-client-secret holds no enabled secret version. Distribution: direct/unlisted P1–P3; App Store at P4. (Decision D1, 2026-08-12) |
| 7.2 | Web Pixel extension | Shopify Web Pixel → Cell 33 through consent gate; extended (never duplicated by second collector); PIXEL_COLLECT_ENABLED flag-off | IN BUILD | Micro-signal capture from a Shopify storefront session | Signal capture docs | Flag-off: PIXEL_COLLECT_ENABLED unset ⇒ 404; HMAC body token from install_id. Gap: activation is GATE-2 owner step. |
| 7.3 | Commerce truth (order economics) | Shopify webhooks: orders/*, refunds/*, inventory_levels/*, fulfillments/*; Pub/Sub delivery provisioned (topic + DLQ + push sub all exist) |
PARTIAL | Shopify order → canonical envelope → BigQuery unified | Commerce integration panel | Pub/Sub delivery NOT yet live (no shop installed); becomes live at first acked message |
| 7.4 | COGS worksheet | Guided worksheet for ERP-less merchants: per-variant landed COGS (bundle-decomposed), 3PL pick/pack + dimensional surcharges, gateway fees, return-processing costs | IN BUILD | Merchant enters costs → net contribution computed per order | Onboarding UI COGS section | Gap: net_yield_costs 5 NULLs (register item 21) |
| 7.5 | App listing copy | Naming: MIZOKI Signal for Shopify (commercial); direct/unlisted distribution P1–P3 | PROPOSED (P4) | N/A until P4 | Shopify App Store listing | Gap: App Store listing + Built-for-Shopify review + embedded/token-exchange swap-in all at P4 |
| 7.6 | Install → Day-1 Observe path | 90-Day Growth Control Pilot, Days 1–30 Observe: connect stack, establish baseline, define target Decision Jobs. Zero changes to live execution. | ADOPTED | Walk through Observe phase: connection → baseline → first dashboard | Pilot playbook, onboarding UI | Gap: no real pilot tenant exists yet; pilot-report generator is a skeleton. Per canon: the pilot that closes a customer is the machine that produces verified numbers. |
| 7.7 | Merchant-owned ad accounts | Decision D2 (2026-08-12): merchant-granted credentials, per-tenant Secret Manager custody, merchant-revocable | ADOPTED (design) | Show Connectors page with tenant-owned credentials | Onboarding UI connectors section | Gap: operator credentials per provider needed (register item 6/18/22) |
8. REPORTING FORMAT
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 8.1 | Pilot-report generator | GET /api/v1/pilot/{tenant}/report on service-audit-replay; contracts/mizoki_contracts/pilot.py per-tenant state machine |
IN BUILD | Week-N and Day-90 reports per docs/product/PILOT_REPORT_SPEC_v1.md (every spec section; "no data" rendered as no data; watermark by the tenant's ledger evidence_class; Day-90 emits a PROPOSED ledger row + readout file, never a ledger write) — contracts/mizoki_contracts/pilot_report.py, test-pinned tests/governance/test_pilot_report.py (Wave 2 WS-8, 2026-09-02); true of the branch, not of the fleet, until the owner-typed DEPLOY gate (service-audit-replay is dispatch-only) |
Pilot report deliverable (GET /api/v1/pilot/{tenant}/report/{kind}, kind = week-n |
day-90, ?format=markdown; the skeleton route …/report is unchanged) + console /latent views |
| 8.2 | ValidationPassport views | GET/POST /api/v1/passport/{decision_id}(/assemble) on service-audit-replay; 18 SPEC_FIELDS + chain block |
PARTIAL | Full decision trace: signals, model versions, refutation, confidence, consent | Audit ledger (Command Center) | Passport-chain v1 with passport-chain-v1 block and append-only passport_chain_links mirror |
| 8.3 | Command Center surfacing | miz-oki-command-center-ui — Decision Queue, Audit Ledger, Intent Scores Grid, Incrementality Panel, Signal Factory demo |
LIVE | Complete Command Center walkthrough: graph → queue → decision → audit trail | Command Center at the deployed URL | UI is deployed-ci, public auth; /approvals and /audit consume governance services |
| 8.4 | Weekly pilot cadence | 90-Day Pilot structure: Observe (Days 1–30) → Validate (31–60) → Recommend (61–90); checklists enforced in code per phase | ADOPTED | Timeline visualization with gate checkpoints | Pilot playbook docs | Phase advance refused (409) unless day window reached AND checklist complete |
| 8.5 | Signal Factory demo (Gate 1) | Live public demo at mizoki3.com/demo/signal — raw events → canonical → gate → all 7 SRPVDAL stages with one deliberate guardrail block | LIVE | Full SRPVDAL proof in a browser, no signup | mizoki3.com/demo/signal | — |
| 8.6 | Signal public surface | mizoki3.com/signal — capability dossiers, field-note scenarios (10 composites, Story Bank v1.2), Preview labels | LIVE | The /signal page with preview framing and the truth-delta headline | mizoki3.com/signal | Preview labels remain until verified pilot numbers enter the claim ledger |
9. GOVERNANCE AS FEATURES
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 9.1 | Consent gate | Cell 33 hard gate — no consent, no persistence; analytics-only consent rejects behavioral signal; test matrix | LIVE | Signal rejected pre-persistence with named tag | Trust features section, compliance docs | — |
| 9.2 | Erasure cascade | mizoki_contracts/erasure.py — REDACTION (not deletion): Firestore leg nullifies payload while preserving event_id/hashes/time axes as tombstones; mizoki_contracts/erasure_bigquery.py — BQ DML-based redaction with streaming-buffer-honest receipt. POST /api/v1/subjects/erase + merge_receipts() worst-wins fold. Subject references are salted HMACs. |
PARTIAL | Erasure request → cascaded redaction across Firestore + BQ with count-redact-recount receipt | Compliance docs, /signal trust section | Gateway canonical_eraser leg wired behind CANONICAL_ERASER_URL (prod env unset); compliance jobs stay open until operator arms it (register item 27 closed for build) |
| 9.3 | O-1 refusals (deny-list) | Sensitive-category deny-list: health, sexuality, religion, financial distress, minors — never predicted, stored, surfaced, or composed; screening at ingest AND at hypothesis creation | LIVE | Show a sensitive composite rejected at write time (not filtered at read time) | Trust features, regulatory docs | Tests prove both directions: permitted classes validate, every rejected class fails with explicit tag |
| 9.4 | Shadow mode | Predictions write to shadow tables, never served; bridges write as hypotheses, never targeted; creative ranks log, never apply; byte-identical serving asserted by test | LIVE (safety posture) | Show shadow predictions alongside production (no impact on live traffic) | Engineering docs, Signal Factory | — |
| 9.5 | Three-level rollback | (1) Flag revert without deploy, (2) Cloud Run revision pin with recorded pre-deploy revision IDs, (3) additive-only schema — old events still validate | LIVE | Show rollback sequence: flag → revision → schema compatibility | Engineering docs, pilot safety section | — |
| 9.6 | One-tap kill switch | Per action class, per level; immutable journal; weekly plain-language digest | IN BUILD | Emergency stop on one action class → immediate demotion, journaled | Autonomy panel (Command Center) | Kill switch is part of the L0–L5 machinery; weekly digest is a reporting feature |
| 9.7 | Deterministic identity for causal math | Probabilistic household matches excluded from all causal measurement; deterministic-first identity resolution | LIVE | Show causal math using only deterministic links; probabilistic for recall only | Measurement methodology docs | — |
| 9.8 | Claim discipline machinery | Automated content QA gates public copy in CI — banned strings, unlabeled numbers, missing preview framing, unbacked machinery claims fail the build | LIVE | CI build failure on an unlabeled performance number | Engineering docs, content QA | content_qa suite passing; scripts/mizoki_canon.py RATIFIED_VOCABULARY |
| 9.9 | Security packet v1 (customer-facing) | docs/product/SECURITY_PACKET_v1.md — IAM posture per registry, O-1 tests, consent, erasure legs, D6-3 runbooks, secrets, fleet integrity, sub-processors, "not yet" list |
IN BUILD | none (document) | pilot due-diligence hand-off | §9 items 1–12 (OPEN_ITEMS V4-19) |
| 9.10 | Boss Agent Chrome extension | chrome-boss-agent-extension/ 6.48.1 (MV3) — reviewed 2026-09-02, re-review §9 PASS 2026-09-15, install readiness §10 2026-09-25 |
PARTIAL — review PASS; install permitted for 6.48.1 only (owner-delegated decision D3); 6.47.0 artifacts withdrawn; onboarding-pack step HELD | — | operator tooling, not a merchant surface | C1–C3 CLOSED (OPEN_ITEMS V4-18); R2/R3 open non-gating; onboarding-pack step HELD (OPEN_ITEMS V4-22); no chrome-extension-v6.48.1 GitHub release yet — publish + 6.47.0 asset withdrawal = owner UI actions; retired install binaries still portal-served (OPEN_ITEMS V4-23) |
| 9.11 | Agent-readable governance evidence (MCP, read-only) | services/mcp_server/ — six get_* tools over DCP / audit-replay / policy-engine / Cell 36 / net-yield reads; OAuth 2.1; unified.mcp_audit (no bodies); flag MCP_SERVER OFF; 69 tests; no deploy workflow |
IN BUILD (dark) | Flag ON in a hermetic run: tools/list shows six read-only tools; tenant A cannot read tenant B by id |
none — no tenant has read through it (OPEN_ITEMS S3-1) | get_net_contribution_by_sku is PROPOSED (BUILD_DEBT MCP-1); deploy is an owner-typed gate |
| 9.12 | Design-partner pipeline (stages, consent-gated outreach, milestones, digest) | src/shared/design_partner_pipeline/ (on wave4/partner-onboarding, Lane 6 S1) — Firestore partners/{id} + BigQuery unified.design_partner_pipeline behind DESIGN_PARTNER_PIPELINE; digest behind PIPELINE_DIGEST |
IN BUILD (dark; both flags OFF) | tests/gtm/ (54): a stage may only advance one legal step; intake from the pilot form is idempotent; milestone events fire once at 3 and 10 PILOT_SIGNED |
none — no partner selected (OPEN_ITEMS L6-1) | readiness docs/pilot/PILOT_READINESS_DESIGN_PARTNER_UNSELECTED_2026-09-02.md; L6-5 wiring; L6-7 sending; BUILD_DEBT L6-6 |
10. CROSS-DOMAIN PLATFORM (r1.4)
Rows added 2026-08-26 for whitepaper amendment r1.4 §14 ("The Platform Under The Marketing Product"). Verified by five independent read-only code sweeps against the draft's original claims; see docs/marketing/MIZOKI_MARKETING_AUTOMATION_WHITEPAPER_r2.0_SEP2026.md §14 for the corrected prose (originally amendment r1.4, now folded into r2.0; archived under docs/marketing/history/) and docs/product/CONNECTOR_GAPS.md for the full connector table.
| # | Feature | Implementing artifact | Status | Demo moment | Launch surface | Gap / register item |
|---|---|---|---|---|---|---|
| 10.1 | Connector ingestion paths | Two parallel mechanisms: service-canonical-ingestion (envelope v3.5.1) and MAPPERS[source] → ingest_gate (src/shared/virtuoso_models/transforms/mappers.py:434-440, journey-event.json shape) |
PARTIAL | Show a Google Ads or Meta Ads event normalize through MAPPERS into the journey envelope |
§14.1 amendment, connector status page | No single "gateway" exists; full per-connector table in docs/product/CONNECTOR_GAPS.md. G-27 |
| 10.2 | Per-connector coverage (15 named sources) | 3 LIVE / 4 PARTIAL / 1 IN BUILD / 7 not-a-source (4 Boss outbound tools, 3 destinations) | PARTIAL | — | §14.1 amendment | docs/product/CONNECTOR_GAPS.md full table. G-25–G-28 |
| 10.3 | Canonical Event Envelope schema | Three coexisting schemas: v1.0.0 (contracts/canonical-event-envelope/, superseded 2026-07-27), v3.5.1 (contracts/mizoki_contracts/envelope.py, live/authoritative), journey-event.json (MAPPERS path) |
IN BUILD | — | §14.2 amendment | Convergence tracked at docs/INTEGRATION_PLAN.md DATA-001, no date committed. G-26 |
| 10.4 | Decision authorization path (DEL score + policy-engine checks) | Single linear DEL formula (services/service-policy-engine/main.py:116-120) HMAC-signed at DCP (services/service-decision-control-plane/main.py:94-96); ~9 sequential veto/threshold checks in evaluate() (services/service-policy-engine/main.py:110-222) |
PARTIAL | Show a proposal blocked below threshold, authorized with signed proof above it | §14.3 amendment, DEL authorization panel | Same mechanism as row 5.2; not organized as "four gates." G-18 (existing) |
| 10.5 | Autonomy tier enforcement | Two-stage enum (contracts/mizoki_contracts/decision_objects.py:55-57); manual promotion (services/service-action-runner/main.py:226-241); three-part actuation check (DCP ceiling + action-runner recheck + adapter presence) |
PARTIAL | Show Stage-3→Stage-4 manual promotion with the three-part check | §14.4 amendment, autonomy panel | No L0–L5 enum exists anywhere in code, wired or not. G-19, G-20 (existing) |
| 10.6 | Domain desk demo engines | demo_counsel.py, demo_capital.py, demo_estate.py, demo_risk.py, demo_nexus.py — deterministic, stdlib-only, fixture-data marketing-site engines under /demo/* |
PARTIAL (Counsel) / PROPOSED (Capital, Estate, Risk, Nexus per production-cell status) | Nexus Run: five division engines chained under one trace id | §14.5 amendment, marketing-site demo | Per docs/OFFERING_MAP.md row 5: Capital/Risk/Estate cells do not exist in the fleet. ACT-991 correctly labeled illustrative in TRUTH.md/GOVERNANCE.md/AGENTS.md. "spec-per-r3.5.1" attribution in the original r1.4 draft was false and has been removed. |
| 10.7 | Growth Decision Graph — cross-domain scope | Single writer: F3 supply-chain sync (src/cells/cell37/market_cell/f3_inventory.py:530), observe-only |
PARTIAL — marketing-scoped only | — | §14.6 amendment | No treasury/legal/estate writer exists; F5 reaches marketing decisions via a direct policy-engine config check (contracts/mizoki_contracts/treasury.py:223), not a graph edge. README.md:68 confirms "observe-only / shadow." |
GAP REGISTER (items requiring resolution before launch)
Cross-referenced against: engineering register (51 items, 0 OPEN — RESIDUAL_REGISTER_FINAL_2026-08-24.md), Codex launch register (L-01 through L-21 — LAUNCH_RESIDUAL_REGISTER_CODEX_2026-08-25.md), and Agent A reconciliation (LAUNCH_RECONCILIATION_CLAUDE-A_2026-08-25.md).
| Gap # | Category | Description | Class | Blocking | Cross-ref |
|---|---|---|---|---|---|
| G-01 | Intent pipeline | No real forward labels — model quality gate unreachable on synthetic data (AUC 0.72 line inside fixture oracle ceiling CI) | operator + build | Autonomy promotion; full Intent Engine v2 activation | R-17 owner-held |
| G-02 | Causal proof | No real registered holdout exists (register item 23); writeback flags hard-false until one does | operator | Any LII/intent activation; causal credit population | R-23 closed (build); operator activation pending |
| G-03 | Causal proof | Ghost bids built shadow-only (ghost_bid.py); MEASUREMENT_RAIL_GHOST_BID flag off by design, no live run against real ad spend yet |
operator | T2+ merchant tier measurement claims | BUILD_DEBT GB-1 |
| G-04 | Net yield | net_yield_costs 5 NULLs — real cost values needed per tenant (register item 21) |
operator | NCM computation; pilot Profit Truth Audit | R-21 owner-held; L-20 |
| G-05 | Channel rails | GA4 extender needs BQ link + dataViewer grant + env var (register item 6 — 3 operator steps) | operator | GA4 measurement rail | R-06 owner-held |
| G-06 | Channel rails | Klaviyo puller secret VERSION needed (register item 6) | operator | Klaviyo lifecycle suppression | R-06 owner-held |
| G-07 | Shopify app | ~~OAuth is OFF — source literal False; no enabled secret version~~ OAuth ARMED 2026-08-21 (PR #768, deploy env list; source literal stays False) and secrets populated + mounted 2026-08-25; the gap is now the first real install — none has ever completed (corrected 2026-09-30) | operator + owner | Any merchant install; entire Shopify commercial offering | R-06 owner-held; L-07 |
| G-08 | Shopify app | Web Pixel flag-off — PIXEL_COLLECT_ENABLED unset | operator (GATE-2) | Session-level micro-signal capture from Shopify stores | L-07 |
| G-09 | Shopify app | No real pilot tenant; pilot-report generator per spec renders "no data" (WS-8) | operator + owner | First verified pilot numbers; Preview→Verified label flip | L-05 BLOCKED-ON-REAL-PILOT; L-07 |
| G-10 | Decisioning | KMS key + verify PEM = GATE 2 owner work | operator | Cryptographic passport signing in production | R-02 owner-executed; R-50 owner-executed |
| G-11 | Frontiers | F2 BQ table unset; F2 findings require ≥2 observed quarters | operator + time | LTV regime activation | L-13 BLOCKED-ON-OWNER |
| G-12 | Frontiers | F5 real treasury config values needed | owner | Treasury-gated spend governance beyond fail-closed | L-13 BLOCKED-ON-OWNER |
| G-13 | Governance | Erasure gateway leg (CANONICAL_ERASER_URL) prod env unset |
operator | Full erasure cascade for canonical store | R-27 closed (build) |
| G-14 | Reporting | Pilot-report generator implemented per spec (WS-8, 2026-09-02) but every data section renders "no data" — no verified numbers exist | time (pilot) | Launch claim that pilot reports contain real data | L-05 BLOCKED-ON-REAL-PILOT |
| G-15 | Fleet | 78 of 107 services run as default compute SA (register item 14) | build + operator | Least-privilege posture for full fleet | R-14 owner-held |
| G-16 | Measurement | Measurement secrets VALUES + BQ DDL confirms needed (register item 22) | operator | CAPI/Enhanced Conversions with real credentials | R-22 closed (build); operator values pending |
| G-17 | Channel rails | All 13 action-runner adapter execution switches OFF; tenant allowlist empty | operator (by design) | Any spend-affecting action — intentionally gated on pilot | L-13; L-07 |
| G-18 | Decisioning | DEL authorization formula in code (linear weighted average) differs from canon doc (clipped-ReLU). Concept correct, math differs. | build | Canon-code alignment for DEL authorization surface | L-09 canon consistency |
| G-19 | Decisioning | Code implements 2-stage autonomy (Stage 3 recommend-only / Stage 4 bounded) vs canon 6-level L0–L5 ladder. Promotion is manual POST, not automated. | build | Launch claim accuracy for autonomy ladder; customer-facing autonomy presentation | L-09 canon consistency |
| G-20 | Decisioning | Autonomy promotion gate evaluation (Brier/AUC/cycles) exists only as metric-contract descriptions, not as executing code. L5-CERT-1 program explicitly "still open debt." | build | Automated promotion gate decisions; L5 certification path | L-09 canon consistency |
| G-21 | Channel rails | Enhanced Conversions has no standalone action-runner adapter — exists only in measurement-rails and boss agentic code | build | Execution-path parity with Meta CAPI (which has action-runner adapters) | — |
| G-22 | Reporting | LearningRecord pydantic model exists but has no writer — learning_update_ref always absent from passport packages |
build | Complete passport assembly; learning-loop closure | — |
| G-23 | F4 | F4 rollback drill not executed — cannot be claimed from unit tests | operator | Operational readiness evidence | L-06D OPEN |
| G-24 | F4 | F4 cap-approach proactive alert does not exist — hard-cap refusal exists but no early warning | build | Operational safety | L-06E OPEN |
| G-25 | Cross-domain (r1.4) | ~~content_qa does not scope repo-root docs/marketing/ or docs/product/~~ CLOSED 2026-08-26: content-truth-gate (ci.yaml) now also runs scripts/check_canon_docs.py (ratchet gate over docs/marketing/*.md + docs/product/*.md, baseline scripts/canon_docs_baseline.json, self-tests on seeded violations before scanning) |
build | Automated claim-discipline enforcement for repo-root docs | Closed 2026-08-26; was found when this PR reported the old gate green without being scanned |
| G-26 | Cross-domain (r1.4) | Three coexisting Canonical Event Envelope schemas (v1.0.0 superseded, v3.5.1 live, journey-event.json via MAPPERS) with no committed convergence date beyond DATA-001 tracking | build | Schema clarity for any new connector work | New 2026-08-26 |
| G-27 | Cross-domain (r1.4) | No single "Unified Connector Gateway" exists — service-canonical-ingestion and MAPPERS[source]→ingest_gate are parallel, non-unified paths with different envelope shapes |
build | Marketing claims about "one gateway" | New 2026-08-26; docs/product/CONNECTOR_GAPS.md |
| G-28 | Cross-domain (r1.4) | OpenRTB has no HTTP adapter and is unreachable via service-canonical-ingestion — journey-lane mapper only |
build | OpenRTB connector claims | New 2026-08-26 |
CODE-VS-CANON DISCREPANCIES
The following features exist in canon documents with one description but are implemented differently in code. Neither side is "wrong" — the canon describes the design intent, the code describes the shipped reality. This matrix reports shipped reality with the discrepancy noted.
| Feature | Canon description | Code reality | Severity |
|---|---|---|---|
| DEL authorization | Clipped-ReLU: authority_c = min(cap_c, max(0, DEL_score − threshold_c)) |
Linear weighted average: 100 * (0.5*passport_pass_rate + 0.3*evidence_completeness + 0.2*verification_weight) + HMAC-signed proof |
Medium — concept (threshold-gated authority) is correct; activation function shape differs |
| WITHHOLD verdict | Named verdict for documented non-action | No formal WITHHOLD in Eligibility enum; closest are blocked + advisory-only |
Low — semantics equivalent, vocabulary differs |
| L0–L5 autonomy ladder | Six-level ladder per (account × action class) | Two-stage model: STAGE_3_RECOMMEND_ONLY, STAGE_4_BOUNDED_AUTONOMY |
High — customer-facing claims reference L0–L5; code cannot express levels 0, 1, 2, or 5 |
| Promotion gates | Automated evaluation: Brier ≤ 0.20, AUC ≥ 0.72, ≥ 2 cycles | Thresholds described in metric_contracts.py docs only; no evaluator code; promotion via manual POST |
High — no automated gate exists; all promotions are human-performed |
| Enhanced Conversions adapter | Action-runner execution adapter | Measurement-rails rail only; no action-runner adapter | Low — rail-only posture is correct for current observe-only mode |
| "Unified Connector Gateway" (r1.4 draft) | One named gateway component normalizing 15 sources | No component named "gateway" in code; two parallel mechanisms (service-canonical-ingestion, MAPPERS→ingest_gate) with different envelope shapes; 7 of 15 named "sources" are not ingestion sources at all |
Medium — real connectors exist and are governed, but the "one gateway" framing is inaccurate; corrected in r1.4 §14.1 |
| "Domain Desks" (r1.4 draft) | Counsel/Capital/Estate/Risk/Nexus run "the same loop and gates" as marketing, spec'd in r3.5.1 | Deterministic fixture-only demo engines on the marketing site; Capital/Risk/Estate do not exist as production cells (OFFERING_MAP.md row 5); r3.5.1 does not mention any of these terms |
High — original draft attributed a false citation and implied production parity; corrected in r1.4 §14.5 |
LAUNCH PACK STATUS
LAUNCH_DEVELOPMENT_PACK_v1.0.md: NOT FOUND in repo or Drive prompt board. Searched:
- Repo: find across all paths — no match
- Drive: MIZ/ tree — no match (Drive search timed out on deep traversal; prompt-board folder contents enumerated — no LAUNCH_DEVELOPMENT_PACK present)
Per task instructions: the pack is unreachable. This matrix was derived directly from the four canon documents + OFFERING_MAP + SIGNAL_OVERVIEW + service registry + Cell Registry + live code verification. Parts B–D (LAUNCH_KIT_v1, PILOT_REPORT_SPEC_v1, SHOPIFY_INSTALL_ACCEPTANCE_v1) were not found and are not reconstructed.
VERIFICATION METHOD
Each row's status was derived from:
1. Canon documents — the four named sources plus OFFERING_MAP v2.3 §6 deployment state table and amendment r3.5.2
2. Service registry (production/service-registry.yaml v2) — deployed revision, auth posture, adapter inventory
3. Cell Registry (docs/architecture/CELL_REGISTRY.md v1.1) — cell function, deploy status, live-verified dates
4. Code verification — three independent subagent sweeps (intent pipeline, DCP/governance, Shopify/commerce/channels) reading actual source files in src/cells/, services/, contracts/, config/ to confirm implementing artifacts exist and match canon claims. Test counts: Cell 33 (246 tests / 9 files), Cell 34 (307 / 14), Cell 35 (341 / 14), Cell 36 (111 / 6), lift-engine (81 / 8).
5. Register items — cross-referenced against .claude/memory/active/current-priorities.md open work register
Status labels follow the canon vocabulary: LIVE / PARTIAL / IN BUILD / PROPOSED. Where a capability is built but flag-off by design, DARK is appended. Every gap becomes a register item in the Gap Register above.
Claim discipline note: Five code-vs-canon discrepancies were found and documented in the CODE-VS-CANON DISCREPANCIES section above. Two are HIGH severity (L0-L5 ladder and promotion gates), affecting customer-facing claims. This matrix reports code reality, not canon aspiration, per TRUTH.md 4.5.