FEATURE COVERAGE MATRIX v1.0

Date: 2026-08-25 (§10 + Gap Register G-25–G-28 + two CODE-VS-CANON rows added 2026-08-26, xdomain-r14 sweep) Author: AGENT B (CLAUDE-B), Product Launch v5.3 Phase 2B Canon sources: SIGNAL_SHOPIFY_MASTER v4.0 · GROWTH_CONTROL r2.0 + amendment r3.5.2 · WHITEPAPER r3.5.1 · MARKETING_AUTOMATION_WHITEPAPER r1.2 + amendments r1.3, r1.4 · OFFERING_MAP v2.3 · SIGNAL_OVERVIEW v5.3 · CELL_REGISTRY v1.1 · service-registry.yaml v2 Status vocabulary: LIVE (deployed and measured) · PARTIAL (shipped, incomplete surface) · IN BUILD (active development, flags off) · PROPOSED (designed, not approved) · DARK (built, flag-off by design, activation gated) Claim discipline: [Validated] / [Illustrative] / [Roadmap] per TRUTH.md. Canon guardrail: "anticipatory intent with proof of causal lift" — mind-reading / prediction framing BANNED.


1. ANTICIPATORY INTENT PIPELINE

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
1.1 Cell 33 — micro-signal ingestion src/cells/cell33/ → intent-signal-ingest (Cloud Run, IAM-locked) PARTIAL Consent gate blocks a disallowed signal type in real time Signal Factory demo, Command Center Shadow/observe-only; no real merchant traffic yet (register item 6: first real store webhook pending)
1.2 Consent gate (fail-closed) src/cells/cell33/ — consent check runs before persistence; DISALLOWED_KEYSTROKE_DYNAMICS tag LIVE Red gate block in Signal Factory — signal rejected with named tag Signal Factory demo, /signal page —
1.3 O-1 prohibited signals (audio/keystroke/gaze) Schema-level rejection in Cell 33 collector + ingestion; test-asserted both directions LIVE Show rejection of a keystroke event, dual assertion (permitted lifecycle validates, rejected class fails) Trust features section, compliance docs —
1.4 Cell 34 — intent scoring API src/cells/cell34/ → intent-scoring-api (Cloud Run, IAM-locked) PARTIAL Sub-100ms score with explanation path Intent Scores Grid (Command Center) Model quality gate open: fv2 AUC 0.6967 mean / Brier 0.1845 over 8 seeds; fixture ORACLE ceiling 0.7277 — 0.72 autonomy line unreachable on synthetic data. Blocked on real forward labels (register item 17 / 6c / 23)
1.5 I-01 PassiveAttentionSequence Cell 33 micro-signal capture — viewport deceleration, dwell, scroll velocity, swipe vectors, partial-watch depth, tab blur/return PARTIAL Session replay of ordered micro-behavior stream Intent API docs Retention: ephemeral (session-end purge). Content-free by construction. Web Pixel extension path exists but flag-off
1.6 I-02 SessionOutcomeForecast Cell 34 session sequence model — compact causal transformer (4 layers, 128 dims, 4 heads); three output heads (stage transition, next-interest, hesitation). UNTRAINED — ships with deterministic seeded weights (model_version: "sst-v1-untrained"), shadow-only (intent_scores_shadow). IN BUILD Predicted stage-transition probability with drift metadata Predicted Journey Timeline Behind LII_REALTIME flag (default OFF); shadow writes only, never served; attention summaries join explanation payload when served
1.7 I-03 CreativeSemanticProfile Multimodal encoders → unified.creative_vectors; decayed aesthetic-affinity vectors; RESONATED_WITH edges in intent graph IN BUILD Creative element → session context alignment score Creative Intelligence panel Ranking behind its own flag with automatic revert to default rotation
1.8 I-04 IntentHypothesis Cell 35 intent-graph — temporary bridge nodes with support, confidence, 30-day TTL, provenance; hypothesis is the only writable status IN BUILD Show a latent bridge between disconnected behaviors with deny-list screening Growth Decision Graph visualization Promotion to targetable requires owner approval; deny-list screening at creation (sensitive composites rejected at write time, test-proven)
1.9 I-05 ValidationPassport contracts/mizoki_contracts/ passport module; 18 SPEC_FIELDS + per-tenant chain block; chain-walk verify route on service-audit-replay PARTIAL Full evidence packet for any decision: signals used, model versions, refutation results, confidence, consent basis Audit ledger, pilot report Passport-chain v1 landed (skill v3.6); pilot-report generator is a skeleton until first real pilot
1.10 Cell 35 — intent graph (Firestore-backed) src/cells/cell35/ → intent-graph (Cloud Run, IAM-locked); Firestore own-collection + boot rebuild + DSAR/erasure leg PARTIAL Interest edges with decay, sequence edges with lift/support/confidence Knowledge Graph viewer (Command Center) DSAR live-verified 2026-08-10; Neo4j retired 2026-08-09; durable-store phase 1 (321 tests)
1.11 Cell 36 — causal credit src/cells/cell36/ → intent-causal (Cloud Run, IAM-locked); caused-vs-anticipated classification, refutation battery LIVE Conversion classified caused vs. anticipated with confidence interval Incrementality Panel (Command Center) Live-verified 2026-08-11 (rev 00012-j27); refutation_engine=arm_level_permutation
1.12 Explanation payload Intent scores never served as bare numbers; attention summaries + reasoning path accompany every score IN BUILD Score + graph-backed reasoning path shown together Intent API, Command Center scores grid Full explanation payload depends on I-02 transformer being active
1.13 Agent-originated conversions (origin dimension) src/shared/virtuoso_models/origin_classifier.py + origin_strata.py (schema fields origin_class / origin_protocol / origin_evidence, names-only; rule classifier; read-side credit strata), services/service-canonical-ingestion/origin_shadow.py (shadow table unified.origin_classification_shadow, AGENT_SHARE_THRESHOLD) IN BUILD (dark, ORIGIN_CLASSIFIER=false) Flag ON in a hermetic run: an event with a declared agent-protocol header lands ONE shadow row keyed sha256(event_id); the event row is unchanged; credit output byte-identical with and without strata none — site line HELD (OPEN_ITEMS S2-D5) docs/specs/GOVERNED_DECISION_FEED_v0.1.md (PROPOSED); image lacks src/shared (S2-D2); header-name reconciliation (S2-D4); strata route wiring BUILD_DEBT S2-BD-1/2

2. CAUSAL PROOF

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
2.1 Qualified holdouts Cell 36 holdout registry — randomized, ghost-bid, matched-geo types; deterministic arm assignment; holdout registration mandatory before activation PARTIAL Register a holdout, show deterministic arm assignment Measurement panel, API No real registered holdout exists yet (register item 23)
2.2 Geo holdouts services/service-media-incrementality/ + F4 growth-scheduler geo-reservation engine PARTIAL Matched-market design with owner-configured geographies Geo experiments panel F4 LIVE-ARMED for mycocoons (US-CA/NY/FL/TX, $2,500/cycle, ±30%); L2-approval-gated
2.3 Intention-to-treat (ITT) Measurement on assignment, not delivery — Cell 36 intent-causal service PARTIAL Show measurement on assigned cohort regardless of delivery outcome Measurement methodology docs Serving but observe-only
2.4 CATE meta-learners (S/T/X/DR-Learner) Cell 26 cell26-causal-uplift (X-Learner live); Cell 27 (DR-Learner/DoWhy refutation) PARTIAL Heterogeneous treatment effects showing WHERE lift concentrates Uplift-quadrant targeting X-Learner live-verified 2026-08-11; DR-Learner serving via Cell 27; uplift → DCP activation gated
2.5 Automated DoWhy refutation Cell 27 + Cell 36 refutation battery — placebo-treatment collapse, random-confounder invariance, subset stability PARTIAL Estimate survives/fails refutation with named test results Refutation status in Incrementality Panel An estimate that fails refutation is flagged, never shipped
2.6 Causal Credit Ledger unified.causal_credit_ledger (immutable); caused vs. anticipated per conversion with confidence intervals PARTIAL Single conversion traced through classification with CI whiskers Console /latent/overcharge — Overcharge Statement (catalogue L2), IN BUILD (Wave 2 WS-6, 2026-09-02; not deployed) (route + view mounted; no BFF read of unified.causal_credit_ledger exists and no holdout is registered, so the view renders "no data" under its ILLUSTRATIVE watermark). Audit surface: this row Ledger architecture live; population requires real holdout data
2.7 Ghost bids services/measurement-rails/ghost_bid.py (shadow execution + auction logger, built) + GHOST_BID_HOLDOUT_IMPLEMENTATION_PLAN.md (design) PARTIAL (DARK) Show a withheld-bid auction row carrying the same shape a real bid would have Story 2 (Paying For Your Own Name) preview Gap: built shadow-only; MEASUREMENT_RAIL_GHOST_BID flag off by design; no live run against real ad spend yet. Not claimed on any customer-facing surface. Register: BUILD_DEBT GB-1 (operator: live run against real ad spend)
2.8 Federated measurement (design-pilot) docs/product/FEDERATED_MEASUREMENT_DESIGN_PILOT.md (plan only; no code, no flag, no store) PROPOSED None — designed, never in use; in-tenant measurement unchanged, only DP-aggregated structure labeled as priors would ever leave a tenant; sequenced after the core pilot (Day-90 readout + counsel memo W3-13a — design doc §4 P-1/P-2); owner-declared DP/consent proposal 2026-09-15 under counsel review [PROPOSED] None (absent from customer docs until the OFFERING_MAP D.3 privacy/legal memo clears) Gap: Phase 0 privacy/legal memo BLOCKED-ON-OWNER; owner decision 5 (consent default) declared opt-in 2026-09-15 as the proposal counsel reviews — not yet ruled; D-14 OPEN ⇒ no EU tenant; fleet-integrity family A (tests/governance/test_fleet_integrity.py) must be re-proven with an aggregate present (plan §5 E-1…E-7)
2.9 MMM export adapters (Robyn / Meridian) src/shared/growth_control/mmm_export/ — causal credit ledger + spend series → Robyn robyn_inputs() frame (ROBYN_INPUT_VERSION = "3.12.1") and Meridian InputData-shaped dict (MERIDIAN_SCHEMA_VERSION = "1.8.0"); caused split → calibration_input / CalibrationBuilder sidecar; PII denylist; idempotent; MMM_EXPORT OFF (source-pinned) IN BUILD (dark) Same ledger rows → byte-identical Robyn CSV and Meridian arrays; dark flag → not_configured Measurement interop docs (docs/product/MEASUREMENT_INTEROP.md) Gap: spend series, channel map, population, calibration interval are owner-open (W3-S8-1..4); no model has run
2.10 Batch MMM (Meridian / Robyn) none — "labeled follow-on" (f4_calibration/priors.py); miz_oki_source_of_truth.py media-domain open proof obligation; F4 prior bridge MMM_PRIOR_WRITEBACK dark per tenant PROPOSED — — armed-awaiting-data: ≥ 2 closed quarters per mmm_export.readiness() (data_insufficient below the bar); vendor guidance is stricter (two years weekly) and is quoted, not adopted

3. PROFIT (NET YIELD)

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
3.1 Net Contribution Margin (NCM-v1) Order economics: R − COGS − pick/pack − shipping − fees − E[return cost] − AdSpend(C) under causal credit IN BUILD Show an order's true net contribution vs. platform-reported revenue Profit Truth Audit report template Metric contract versioned (NCM-v1). Missing costs flag a row incomplete.
3.2 Per-tenant order economics config/net_yield_costs.yaml per-tenant cost config; commerce data ingestion from Shopify orders/refunds IN BUILD Side-by-side: platform ROAS vs. net contribution Console /latent/profit-leak — Profit-Leak Report (catalogue L1), IN BUILD (Wave 2 WS-6, 2026-09-02; not deployed) (route + view mounted; the net-yield ledger has no governed BFF read — per-key reads only, dispatch-only — so the view renders "no data" under its ILLUSTRATIVE watermark); pilot report. Audit surface: this row Gap: net_yield_costs has 5 NULLs (register item 21 — operator: real cost values needed)
3.3 Continuous dosage estimator services/lift-engine/ — cross-fitted R-learner convention (built in GC Activation v2.1) IN BUILD Optimal spend-per-channel recommendation based on marginal iNCM Budget Intelligence panel Built flag-off; pilot configuration gates activation
3.4 LTV regimes (F2) Dynamic treatment regimes; ledger outcome-horizon dimension; findings gated on ≥2 observed quarters IN BUILD Multi-quarter retention vs. immediate conversion trade-off F2 LTV panel (DARK) Gap: F2 data-gate — requires ≥2 observed quarters per cohort. F2_ORDER_ECONOMICS_BQ_TABLE unset.
3.5 Both writebacks OFF MEASUREMENT_WRITEBACK=false, NET_YIELD_WRITEBACK=false; tests fail if flipped without approval LIVE (safety posture) Show the flag-off assertion and the test that guards it Trust features, governance docs Each requires its own verified pilot and separate approval. Source-literal defaults test-asserted.

4. CHANNEL RAILS

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
4.1 Meta CAPI Two implementations: (1) service-action-runner adapters MetaCapiConversionUploadAdapter + MetaCapiValueRestatementAdapter (execution path); (2) services/measurement-rails/meta_capi.py (governed rail, shared event_id dedup). Both triple-gated (rail flag + dry_run + transport). PARTIAL Server-side conversion event transmitted to Meta with dedup proof Measurement rails docs Both execution and rail OFF; tenant allowlist empty
4.2 Enhanced Conversions (Google) services/measurement-rails/google_enhanced_conversions.py — Google Ads API v22 uploadConversionAdjustments, SHA-256 normalized identifiers. No standalone action-runner adapter — exists only in measurement-rails and boss agentic code. PARTIAL Google Ads value signal: margin, not revenue Measurement rails docs Rail OFF; no action-runner execution adapter (boss agentic module only)
4.3 GA4 Measurement Protocol GA4 MP server-side events; intent-ga4-extender service PARTIAL GA4 event enrichment with intent-derived signals Connector status page Gap: GA4 extender needs BQ link + dataViewer grant + env var (register item 6 — operator, 3 steps)
4.4 Google Ads adapter service-action-runner — google_ads campaign budget+status, ad-group bid, keyword bid+status PARTIAL Budget reallocation recommendation with clipped-ReLU authorization Budget Intelligence panel 13 adapters installed, all switches false; recommend-only posture
4.5 Meta Ads adapter service-action-runner — meta_ads campaign budget+status, adset bid+audience PARTIAL Audience exclusion recommendation Audience Intelligence panel Same off posture
4.6 Klaviyo integration services/service-marketing-connectors/klaviyo_connector.py — aggregate campaign reporting only; structurally refuses person-capable endpoints (_assert_aggregate_endpoint). No action-runner execution adapter. PARTIAL Aggregate campaign metrics; suppress Klaviyo-converting audiences from paid spend Lifecycle coordination docs Gap: Klaviyo puller aggregate-only (no per-person data by design); secret VERSION needed (register item 6 — operator); webhook half BUILT flag-off 2026-08-27 (klaviyo_webhook.py, KLAVIYO_WEBHOOK_ENABLED dark — W7)
4.7 Observe-only default Every adapter defaults to observe-only; execution authority is a separate explicit grant LIVE (safety posture) Adapter dashboard showing all switches OFF Trust features section —
4.8 Klaviyo email/SMS value feed (W5) services/measurement-rails/klaviyo_feed.py + ncm_feed_wiring.build_klaviyo_value_events/send_klaviyo_value_events — mirrors the Meta CAPI / Google EC rail pattern; E[NCM]-shaped events only (margin, never raw revenue), gated by KLAVIYO_FEED (default OFF, same as every other rail). health() reports not_configured until KLAVIYO_PRIVATE_API_KEY is set. Distinct from row 4.6's aggregate-reporting PULL connector (KLV-1) — this is the per-conversion value PUSH half. DARK Order-margin event delivered to a Klaviyo flow trigger, never raw revenue Measurement rails docs Skeleton only: no tenant credential wiring, no GATE 2. Site/product copy labels this [Roadmap] until GATE 2 + real credentials exist — no LIVE claim.
4.9 Amazon Ads — measurement interop connector: services/service-marketing-connectors/direct_connectors.py amazon_ads fail-closed direct-pull adapter (catalog available: False, "Wave 3 — adapter not live-verified yet"); interop (spend → MMM channel, console-attributed sales → reported) unbuilt ROADMAP (connector PARTIAL) — — Marketplace-reported attribution is reported evidence, never incrementality; no live verification
4.10 Walmart Connect none — no provider, catalog row, adapter, registry entry or env var in the tree (grep -rni "walmart connect\|walmart_connect" → 0 code hits) ROADMAP — — Same interop shape as 4.9 once a connector exists; retail-media console ROAS is dashboard ROAS by construction (MEASUREMENT_INTEROP.md §1, §5); catalog row = OPEN_ITEMS W3-S8-8

5. DECISIONING

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
5.1 Decision Jobs J-01 through J-06 config/decision_jobs.yaml + registry module + GET /api/v1/jobs on service-audit-replay IN BUILD Decision job catalog: each job with input telemetry, eligible decisions, constraints, evidence, outcome Decision Jobs catalog (Command Center) Registry exists; internal routes serving; customer-facing SLA packaging at Phase 8
5.2 DEL Score + authorization service-decision-control-plane — DEL score computed by Policy Engine as linear weighted average: 100 * (0.5*passport_pass_rate + 0.3*evidence_completeness + 0.2*verification_weight). CODE-VS-CANON NOTE: canon doc (DEL_AUTHORIZATION_FUNCTION.md) describes clipped-ReLU authority_c = min(cap_c, max(0, DEL_score − threshold_c)); code implements linear formula + HMAC-signed authorization. The concept (threshold-gated authority) is present; the activation function shape differs. PARTIAL Show a proposed action below threshold → blocked; above threshold → authorized with signed proof Signal Factory demo (5 guardrails), DEL authorization panel Platform floor thresholds raisable by customer, never lowerable. Gap G-18: code formula ≠ canon formula.
5.3 Blocking verdicts DCP produces a documented decision NOT to act. CODE-VS-CANON NOTE: no formal WITHHOLD verdict in Eligibility enum; actual values are eligible, approval-required, experiment-required, advisory-only, blocked. The concept (documented non-action with reasoning) exists as blocked + advisory-only. PARTIAL Show a blocked or advisory-only eligibility with full reasoning path Decision Queue (Command Center) —
5.4 Autonomy stages service-policy-engine declarative policy.yaml, hash-versioned; per-domain DEL thresholds. CODE-VS-CANON NOTE: code implements two-stage model: STAGE_3_RECOMMEND_ONLY and STAGE_4_BOUNDED_AUTONOMY. Canon describes L0–L5 six-level ladder. Five policy domains defined: default, media, calibration, finance (advisory-only), cre (advisory-only). PARTIAL Show autonomy stage per domain; one-tap kill switch Autonomy panel, pilot report Gap G-19: shipped 2-stage model vs canon 6-level ladder. Promotion from Stage 3→4 is a manual human POST, not automated.
5.5 Autonomy promotion gates Brier ≤ 0.20, AUC ≥ 0.72, stable lift ≥ 2 purchase cycles — described in metric_contracts.py as threshold definitions. Evaluator machinery BUILT 2026-08-27 (src/shared/l5_certification/ — observe-only Brier/AUC/stability evaluation with never-auto-upgrade policy; W5). CertificationCheck fingerprint primitive integrated. Promotion remains a manual POST /api/v1/actuators/stage and is unwired to the evaluator by design. IN BUILD Show metric thresholds that a model must meet (threshold display, not automated evaluation) Governance docs, pilot report Gap G-20 (narrowed 2026-08-27): the evaluator now exists observe-only (W5); promotion stays manual/human by law. Real evaluations remain blocked on real forward labels (register 17/6c/23), and L5-CERT-1's program document + first pack stay owner-held.
5.6 Signing authority DCP holds DCP_SIGNING_KEY; KMS asymmetric passport signing + verify + tamper tests (GC Activation workstream C) PARTIAL Signed decision proof with tamper detection Audit ledger Gap: KMS key + verify PEM is GATE 2 owner work
5.7 Decisions-governed meter (usage counter, observe-only) services/service-decision-control-plane/decision_meter.py → STORE collection decisions_governed_meter; DDL bigquery/schemas/decisions_governed_meter.sql IN BUILD (dark, DECISION_METER=false) Arm the flag in a hermetic run: one eligible proposal ⇒ one row; the same proposal again ⇒ no second row; a treasury-vetoed proposal ⇒ nothing none (internal; no invoice surface) Billing not wired; BigQuery landing not wired (BUILD_DEBT MTR-1); pricing basis is owner decision S-3
5.8 DEL / ValidationPassport open specification spec/del-validation-passport/v0.1/ — JSON Schema, DEL_SCORE definition, 9 conformance vectors, validator, AP2 interop mapping (PROPOSED) IN BUILD Run tests/spec: vectors verdict as expected; MIZ OKI's own passport output does NOT yet conform (13 deltas recorded, never hidden) none (third-party emit/verify is the audience once published) CONFORMANCE_RESULTS_2026-09-02.md deltas → BUILD_DEBT PASS-1…PASS-6; license/publication OPEN S6-1
5.9 Pacing veto (third hard-constraint class) services/service-policy-engine/pacing_veto.py (pure function; per-decision / daily / cycle caps, velocity, holdout-at-L2+, autonomy ceiling L3) wired into evaluate() behind PACING_VETO (owner ruling W3-12a, 2026-09-15); tests/governance/test_pacing_veto.py IN BUILD (dark: PACING_VETO default off, absent from the deploy env; flag-off output byte-identical, test-pinned) Flag-on hermetic run: a proposal over the daily cap is BLOCKED with a named constraint; flag-off run is byte-identical none until armed; treasury/supply vetoes precede it docs/design/AD_CONTROL_PLANE_BANDIT_CAUSAL_BIDDING_DESIGN.md §4; BUILD_DEBT PACE-1 (closed 2026-09-25, row deleted per that file's convention; the Closed note carries the cite); register docs/governance/DARK_FLIP_EVIDENCE_GATES.md row PACING_VETO
5.10 Ad Control Plane — bandit arms + causal bidding docs/design/AD_CONTROL_PLANE_BANDIT_CAUSAL_BIDDING_DESIGN.md (design only; no governed bandit code; causal bidding refused by name while the dosage estimator is advisory) PROPOSED — (design; nothing runs) none exploration budget field landed (W3-12b) but nothing reads it at runtime; envelope cap not bound to it; DCP does not forward bid_multiplier_source (design doc gaps)

6. FRONTIERS (F1–F5)

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
6.1 F1 — Creative component unbundling DR-Learner + multimodal vision-language embeddings on CreativeSemanticProfile lane IN BUILD (DARK) Element-level causal effect: promo framing vs. layout vs. imagery Creative Intelligence panel Estimates labeled provisional until pilot creative volume; generated-creative deployment retains human approval
6.2 F2 — Multi-quarter LTV treatment regimes Dynamic treatment regimes; ledger outcome-horizon dimension; F2_ORDER_ECONOMICS_BQ_TABLE IN BUILD (DARK) Balance immediate conversion against discounted multi-quarter retention LTV regime panel Gap: findings gated on ≥ 2 observed quarters per cohort (code guard). BQ table unset.
6.3 F3 — Supply-chain / inventory yield sync Inventory telemetry joins Growth Decision Graph; bids throttle on stockouts, accelerate on overstock IN BUILD Show a bid pause triggered by stockout detection Inventory sync panel Observe-only by owner ruling. No-dispatch invariant enforced by test.
6.4 F4 — Continuous Bayesian geo calibration services/growth-scheduler — geo-reservation engine, synthetic-control estimator, Bayesian MMM prior updater LIVE (ARMED) Automated geo reservation with spend perturbation and realized-lift estimation F4 calibration panel F4 LIVE-ARMED for mycocoons (US-CA/NY/FL/TX, $2,500/cycle, ±30%; L0); reservations recommend-only (L2 approval queue + deliberately unregistered actuator). LTV/MMM/EDGE/supply-veto DARK.
6.5 F5 — Treasury-gated spend governance service-policy-engine F5 treasury gate — liquidity floors, covenant limits as hard constraints in VALIDATE/DECIDE; veto + human routing on breach PARTIAL (DARK) Treasury floor breach → automatic spend cap tightening with named veto Console /latent/restraint-ledger — Restraint Ledger (catalogue L5), IN BUILD (Wave 2 WS-6, 2026-09-02; not deployed) (route + view mounted over /api/bff/decisions, /api/bff/actions/outcomes, /api/bff/passports; avoided waste illustrative until measured). Audit surface: this row v1 config-declared floors (config/treasury_constraints.yaml); fails closed absent config. Gap: real treasury config values needed (owner).

7. SHOPIFY APP

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
7.1 Multi-merchant OAuth install service-marketing-connectors — OAuth authorization-code grant; MIZ OKI Commerce Link (client ID 039cb627...); docs/architecture/SHOPIFY_OAUTH_INSTALL_DESIGN.md IN BUILD One-click OAuth install from direct link Shopify app install flow Gap: OAuth is OFF — source literal is False; shopify-app-client-secret holds no enabled secret version. Distribution: direct/unlisted P1–P3; App Store at P4. (Decision D1, 2026-08-12)
7.2 Web Pixel extension Shopify Web Pixel → Cell 33 through consent gate; extended (never duplicated by second collector); PIXEL_COLLECT_ENABLED flag-off IN BUILD Micro-signal capture from a Shopify storefront session Signal capture docs Flag-off: PIXEL_COLLECT_ENABLED unset ⇒ 404; HMAC body token from install_id. Gap: activation is GATE-2 owner step.
7.3 Commerce truth (order economics) Shopify webhooks: orders/*, refunds/*, inventory_levels/*, fulfillments/*; Pub/Sub delivery provisioned (topic + DLQ + push sub all exist) PARTIAL Shopify order → canonical envelope → BigQuery unified Commerce integration panel Pub/Sub delivery NOT yet live (no shop installed); becomes live at first acked message
7.4 COGS worksheet Guided worksheet for ERP-less merchants: per-variant landed COGS (bundle-decomposed), 3PL pick/pack + dimensional surcharges, gateway fees, return-processing costs IN BUILD Merchant enters costs → net contribution computed per order Onboarding UI COGS section Gap: net_yield_costs 5 NULLs (register item 21)
7.5 App listing copy Naming: MIZOKI Signal for Shopify (commercial); direct/unlisted distribution P1–P3 PROPOSED (P4) N/A until P4 Shopify App Store listing Gap: App Store listing + Built-for-Shopify review + embedded/token-exchange swap-in all at P4
7.6 Install → Day-1 Observe path 90-Day Growth Control Pilot, Days 1–30 Observe: connect stack, establish baseline, define target Decision Jobs. Zero changes to live execution. ADOPTED Walk through Observe phase: connection → baseline → first dashboard Pilot playbook, onboarding UI Gap: no real pilot tenant exists yet; pilot-report generator is a skeleton. Per canon: the pilot that closes a customer is the machine that produces verified numbers.
7.7 Merchant-owned ad accounts Decision D2 (2026-08-12): merchant-granted credentials, per-tenant Secret Manager custody, merchant-revocable ADOPTED (design) Show Connectors page with tenant-owned credentials Onboarding UI connectors section Gap: operator credentials per provider needed (register item 6/18/22)

8. REPORTING FORMAT

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
8.1 Pilot-report generator GET /api/v1/pilot/{tenant}/report on service-audit-replay; contracts/mizoki_contracts/pilot.py per-tenant state machine IN BUILD Week-N and Day-90 reports per docs/product/PILOT_REPORT_SPEC_v1.md (every spec section; "no data" rendered as no data; watermark by the tenant's ledger evidence_class; Day-90 emits a PROPOSED ledger row + readout file, never a ledger write) — contracts/mizoki_contracts/pilot_report.py, test-pinned tests/governance/test_pilot_report.py (Wave 2 WS-8, 2026-09-02); true of the branch, not of the fleet, until the owner-typed DEPLOY gate (service-audit-replay is dispatch-only) Pilot report deliverable (GET /api/v1/pilot/{tenant}/report/{kind}, kind = week-n day-90, ?format=markdown; the skeleton route …/report is unchanged) + console /latent views
8.2 ValidationPassport views GET/POST /api/v1/passport/{decision_id}(/assemble) on service-audit-replay; 18 SPEC_FIELDS + chain block PARTIAL Full decision trace: signals, model versions, refutation, confidence, consent Audit ledger (Command Center) Passport-chain v1 with passport-chain-v1 block and append-only passport_chain_links mirror
8.3 Command Center surfacing miz-oki-command-center-ui — Decision Queue, Audit Ledger, Intent Scores Grid, Incrementality Panel, Signal Factory demo LIVE Complete Command Center walkthrough: graph → queue → decision → audit trail Command Center at the deployed URL UI is deployed-ci, public auth; /approvals and /audit consume governance services
8.4 Weekly pilot cadence 90-Day Pilot structure: Observe (Days 1–30) → Validate (31–60) → Recommend (61–90); checklists enforced in code per phase ADOPTED Timeline visualization with gate checkpoints Pilot playbook docs Phase advance refused (409) unless day window reached AND checklist complete
8.5 Signal Factory demo (Gate 1) Live public demo at mizoki3.com/demo/signal — raw events → canonical → gate → all 7 SRPVDAL stages with one deliberate guardrail block LIVE Full SRPVDAL proof in a browser, no signup mizoki3.com/demo/signal —
8.6 Signal public surface mizoki3.com/signal — capability dossiers, field-note scenarios (10 composites, Story Bank v1.2), Preview labels LIVE The /signal page with preview framing and the truth-delta headline mizoki3.com/signal Preview labels remain until verified pilot numbers enter the claim ledger

9. GOVERNANCE AS FEATURES

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
9.1 Consent gate Cell 33 hard gate — no consent, no persistence; analytics-only consent rejects behavioral signal; test matrix LIVE Signal rejected pre-persistence with named tag Trust features section, compliance docs —
9.2 Erasure cascade mizoki_contracts/erasure.py — REDACTION (not deletion): Firestore leg nullifies payload while preserving event_id/hashes/time axes as tombstones; mizoki_contracts/erasure_bigquery.py — BQ DML-based redaction with streaming-buffer-honest receipt. POST /api/v1/subjects/erase + merge_receipts() worst-wins fold. Subject references are salted HMACs. PARTIAL Erasure request → cascaded redaction across Firestore + BQ with count-redact-recount receipt Compliance docs, /signal trust section Gateway canonical_eraser leg wired behind CANONICAL_ERASER_URL (prod env unset); compliance jobs stay open until operator arms it (register item 27 closed for build)
9.3 O-1 refusals (deny-list) Sensitive-category deny-list: health, sexuality, religion, financial distress, minors — never predicted, stored, surfaced, or composed; screening at ingest AND at hypothesis creation LIVE Show a sensitive composite rejected at write time (not filtered at read time) Trust features, regulatory docs Tests prove both directions: permitted classes validate, every rejected class fails with explicit tag
9.4 Shadow mode Predictions write to shadow tables, never served; bridges write as hypotheses, never targeted; creative ranks log, never apply; byte-identical serving asserted by test LIVE (safety posture) Show shadow predictions alongside production (no impact on live traffic) Engineering docs, Signal Factory —
9.5 Three-level rollback (1) Flag revert without deploy, (2) Cloud Run revision pin with recorded pre-deploy revision IDs, (3) additive-only schema — old events still validate LIVE Show rollback sequence: flag → revision → schema compatibility Engineering docs, pilot safety section —
9.6 One-tap kill switch Per action class, per level; immutable journal; weekly plain-language digest IN BUILD Emergency stop on one action class → immediate demotion, journaled Autonomy panel (Command Center) Kill switch is part of the L0–L5 machinery; weekly digest is a reporting feature
9.7 Deterministic identity for causal math Probabilistic household matches excluded from all causal measurement; deterministic-first identity resolution LIVE Show causal math using only deterministic links; probabilistic for recall only Measurement methodology docs —
9.8 Claim discipline machinery Automated content QA gates public copy in CI — banned strings, unlabeled numbers, missing preview framing, unbacked machinery claims fail the build LIVE CI build failure on an unlabeled performance number Engineering docs, content QA content_qa suite passing; scripts/mizoki_canon.py RATIFIED_VOCABULARY
9.9 Security packet v1 (customer-facing) docs/product/SECURITY_PACKET_v1.md — IAM posture per registry, O-1 tests, consent, erasure legs, D6-3 runbooks, secrets, fleet integrity, sub-processors, "not yet" list IN BUILD none (document) pilot due-diligence hand-off §9 items 1–12 (OPEN_ITEMS V4-19)
9.10 Boss Agent Chrome extension chrome-boss-agent-extension/ 6.48.1 (MV3) — reviewed 2026-09-02, re-review §9 PASS 2026-09-15, install readiness §10 2026-09-25 PARTIAL — review PASS; install permitted for 6.48.1 only (owner-delegated decision D3); 6.47.0 artifacts withdrawn; onboarding-pack step HELD — operator tooling, not a merchant surface C1–C3 CLOSED (OPEN_ITEMS V4-18); R2/R3 open non-gating; onboarding-pack step HELD (OPEN_ITEMS V4-22); no chrome-extension-v6.48.1 GitHub release yet — publish + 6.47.0 asset withdrawal = owner UI actions; retired install binaries still portal-served (OPEN_ITEMS V4-23)
9.11 Agent-readable governance evidence (MCP, read-only) services/mcp_server/ — six get_* tools over DCP / audit-replay / policy-engine / Cell 36 / net-yield reads; OAuth 2.1; unified.mcp_audit (no bodies); flag MCP_SERVER OFF; 69 tests; no deploy workflow IN BUILD (dark) Flag ON in a hermetic run: tools/list shows six read-only tools; tenant A cannot read tenant B by id none — no tenant has read through it (OPEN_ITEMS S3-1) get_net_contribution_by_sku is PROPOSED (BUILD_DEBT MCP-1); deploy is an owner-typed gate
9.12 Design-partner pipeline (stages, consent-gated outreach, milestones, digest) src/shared/design_partner_pipeline/ (on wave4/partner-onboarding, Lane 6 S1) — Firestore partners/{id} + BigQuery unified.design_partner_pipeline behind DESIGN_PARTNER_PIPELINE; digest behind PIPELINE_DIGEST IN BUILD (dark; both flags OFF) tests/gtm/ (54): a stage may only advance one legal step; intake from the pilot form is idempotent; milestone events fire once at 3 and 10 PILOT_SIGNED none — no partner selected (OPEN_ITEMS L6-1) readiness docs/pilot/PILOT_READINESS_DESIGN_PARTNER_UNSELECTED_2026-09-02.md; L6-5 wiring; L6-7 sending; BUILD_DEBT L6-6

10. CROSS-DOMAIN PLATFORM (r1.4)

Rows added 2026-08-26 for whitepaper amendment r1.4 §14 ("The Platform Under The Marketing Product"). Verified by five independent read-only code sweeps against the draft's original claims; see docs/marketing/MIZOKI_MARKETING_AUTOMATION_WHITEPAPER_r2.0_SEP2026.md §14 for the corrected prose (originally amendment r1.4, now folded into r2.0; archived under docs/marketing/history/) and docs/product/CONNECTOR_GAPS.md for the full connector table.

# Feature Implementing artifact Status Demo moment Launch surface Gap / register item
10.1 Connector ingestion paths Two parallel mechanisms: service-canonical-ingestion (envelope v3.5.1) and MAPPERS[source] → ingest_gate (src/shared/virtuoso_models/transforms/mappers.py:434-440, journey-event.json shape) PARTIAL Show a Google Ads or Meta Ads event normalize through MAPPERS into the journey envelope §14.1 amendment, connector status page No single "gateway" exists; full per-connector table in docs/product/CONNECTOR_GAPS.md. G-27
10.2 Per-connector coverage (15 named sources) 3 LIVE / 4 PARTIAL / 1 IN BUILD / 7 not-a-source (4 Boss outbound tools, 3 destinations) PARTIAL — §14.1 amendment docs/product/CONNECTOR_GAPS.md full table. G-25–G-28
10.3 Canonical Event Envelope schema Three coexisting schemas: v1.0.0 (contracts/canonical-event-envelope/, superseded 2026-07-27), v3.5.1 (contracts/mizoki_contracts/envelope.py, live/authoritative), journey-event.json (MAPPERS path) IN BUILD — §14.2 amendment Convergence tracked at docs/INTEGRATION_PLAN.md DATA-001, no date committed. G-26
10.4 Decision authorization path (DEL score + policy-engine checks) Single linear DEL formula (services/service-policy-engine/main.py:116-120) HMAC-signed at DCP (services/service-decision-control-plane/main.py:94-96); ~9 sequential veto/threshold checks in evaluate() (services/service-policy-engine/main.py:110-222) PARTIAL Show a proposal blocked below threshold, authorized with signed proof above it §14.3 amendment, DEL authorization panel Same mechanism as row 5.2; not organized as "four gates." G-18 (existing)
10.5 Autonomy tier enforcement Two-stage enum (contracts/mizoki_contracts/decision_objects.py:55-57); manual promotion (services/service-action-runner/main.py:226-241); three-part actuation check (DCP ceiling + action-runner recheck + adapter presence) PARTIAL Show Stage-3→Stage-4 manual promotion with the three-part check §14.4 amendment, autonomy panel No L0–L5 enum exists anywhere in code, wired or not. G-19, G-20 (existing)
10.6 Domain desk demo engines demo_counsel.py, demo_capital.py, demo_estate.py, demo_risk.py, demo_nexus.py — deterministic, stdlib-only, fixture-data marketing-site engines under /demo/* PARTIAL (Counsel) / PROPOSED (Capital, Estate, Risk, Nexus per production-cell status) Nexus Run: five division engines chained under one trace id §14.5 amendment, marketing-site demo Per docs/OFFERING_MAP.md row 5: Capital/Risk/Estate cells do not exist in the fleet. ACT-991 correctly labeled illustrative in TRUTH.md/GOVERNANCE.md/AGENTS.md. "spec-per-r3.5.1" attribution in the original r1.4 draft was false and has been removed.
10.7 Growth Decision Graph — cross-domain scope Single writer: F3 supply-chain sync (src/cells/cell37/market_cell/f3_inventory.py:530), observe-only PARTIAL — marketing-scoped only — §14.6 amendment No treasury/legal/estate writer exists; F5 reaches marketing decisions via a direct policy-engine config check (contracts/mizoki_contracts/treasury.py:223), not a graph edge. README.md:68 confirms "observe-only / shadow."

GAP REGISTER (items requiring resolution before launch)

Cross-referenced against: engineering register (51 items, 0 OPEN — RESIDUAL_REGISTER_FINAL_2026-08-24.md), Codex launch register (L-01 through L-21 — LAUNCH_RESIDUAL_REGISTER_CODEX_2026-08-25.md), and Agent A reconciliation (LAUNCH_RECONCILIATION_CLAUDE-A_2026-08-25.md).

Gap # Category Description Class Blocking Cross-ref
G-01 Intent pipeline No real forward labels — model quality gate unreachable on synthetic data (AUC 0.72 line inside fixture oracle ceiling CI) operator + build Autonomy promotion; full Intent Engine v2 activation R-17 owner-held
G-02 Causal proof No real registered holdout exists (register item 23); writeback flags hard-false until one does operator Any LII/intent activation; causal credit population R-23 closed (build); operator activation pending
G-03 Causal proof Ghost bids built shadow-only (ghost_bid.py); MEASUREMENT_RAIL_GHOST_BID flag off by design, no live run against real ad spend yet operator T2+ merchant tier measurement claims BUILD_DEBT GB-1
G-04 Net yield net_yield_costs 5 NULLs — real cost values needed per tenant (register item 21) operator NCM computation; pilot Profit Truth Audit R-21 owner-held; L-20
G-05 Channel rails GA4 extender needs BQ link + dataViewer grant + env var (register item 6 — 3 operator steps) operator GA4 measurement rail R-06 owner-held
G-06 Channel rails Klaviyo puller secret VERSION needed (register item 6) operator Klaviyo lifecycle suppression R-06 owner-held
G-07 Shopify app ~~OAuth is OFF — source literal False; no enabled secret version~~ OAuth ARMED 2026-08-21 (PR #768, deploy env list; source literal stays False) and secrets populated + mounted 2026-08-25; the gap is now the first real install — none has ever completed (corrected 2026-09-30) operator + owner Any merchant install; entire Shopify commercial offering R-06 owner-held; L-07
G-08 Shopify app Web Pixel flag-off — PIXEL_COLLECT_ENABLED unset operator (GATE-2) Session-level micro-signal capture from Shopify stores L-07
G-09 Shopify app No real pilot tenant; pilot-report generator per spec renders "no data" (WS-8) operator + owner First verified pilot numbers; Preview→Verified label flip L-05 BLOCKED-ON-REAL-PILOT; L-07
G-10 Decisioning KMS key + verify PEM = GATE 2 owner work operator Cryptographic passport signing in production R-02 owner-executed; R-50 owner-executed
G-11 Frontiers F2 BQ table unset; F2 findings require ≥2 observed quarters operator + time LTV regime activation L-13 BLOCKED-ON-OWNER
G-12 Frontiers F5 real treasury config values needed owner Treasury-gated spend governance beyond fail-closed L-13 BLOCKED-ON-OWNER
G-13 Governance Erasure gateway leg (CANONICAL_ERASER_URL) prod env unset operator Full erasure cascade for canonical store R-27 closed (build)
G-14 Reporting Pilot-report generator implemented per spec (WS-8, 2026-09-02) but every data section renders "no data" — no verified numbers exist time (pilot) Launch claim that pilot reports contain real data L-05 BLOCKED-ON-REAL-PILOT
G-15 Fleet 78 of 107 services run as default compute SA (register item 14) build + operator Least-privilege posture for full fleet R-14 owner-held
G-16 Measurement Measurement secrets VALUES + BQ DDL confirms needed (register item 22) operator CAPI/Enhanced Conversions with real credentials R-22 closed (build); operator values pending
G-17 Channel rails All 13 action-runner adapter execution switches OFF; tenant allowlist empty operator (by design) Any spend-affecting action — intentionally gated on pilot L-13; L-07
G-18 Decisioning DEL authorization formula in code (linear weighted average) differs from canon doc (clipped-ReLU). Concept correct, math differs. build Canon-code alignment for DEL authorization surface L-09 canon consistency
G-19 Decisioning Code implements 2-stage autonomy (Stage 3 recommend-only / Stage 4 bounded) vs canon 6-level L0–L5 ladder. Promotion is manual POST, not automated. build Launch claim accuracy for autonomy ladder; customer-facing autonomy presentation L-09 canon consistency
G-20 Decisioning Autonomy promotion gate evaluation (Brier/AUC/cycles) exists only as metric-contract descriptions, not as executing code. L5-CERT-1 program explicitly "still open debt." build Automated promotion gate decisions; L5 certification path L-09 canon consistency
G-21 Channel rails Enhanced Conversions has no standalone action-runner adapter — exists only in measurement-rails and boss agentic code build Execution-path parity with Meta CAPI (which has action-runner adapters) —
G-22 Reporting LearningRecord pydantic model exists but has no writer — learning_update_ref always absent from passport packages build Complete passport assembly; learning-loop closure —
G-23 F4 F4 rollback drill not executed — cannot be claimed from unit tests operator Operational readiness evidence L-06D OPEN
G-24 F4 F4 cap-approach proactive alert does not exist — hard-cap refusal exists but no early warning build Operational safety L-06E OPEN
G-25 Cross-domain (r1.4) ~~content_qa does not scope repo-root docs/marketing/ or docs/product/~~ CLOSED 2026-08-26: content-truth-gate (ci.yaml) now also runs scripts/check_canon_docs.py (ratchet gate over docs/marketing/*.md + docs/product/*.md, baseline scripts/canon_docs_baseline.json, self-tests on seeded violations before scanning) build Automated claim-discipline enforcement for repo-root docs Closed 2026-08-26; was found when this PR reported the old gate green without being scanned
G-26 Cross-domain (r1.4) Three coexisting Canonical Event Envelope schemas (v1.0.0 superseded, v3.5.1 live, journey-event.json via MAPPERS) with no committed convergence date beyond DATA-001 tracking build Schema clarity for any new connector work New 2026-08-26
G-27 Cross-domain (r1.4) No single "Unified Connector Gateway" exists — service-canonical-ingestion and MAPPERS[source]→ingest_gate are parallel, non-unified paths with different envelope shapes build Marketing claims about "one gateway" New 2026-08-26; docs/product/CONNECTOR_GAPS.md
G-28 Cross-domain (r1.4) OpenRTB has no HTTP adapter and is unreachable via service-canonical-ingestion — journey-lane mapper only build OpenRTB connector claims New 2026-08-26

CODE-VS-CANON DISCREPANCIES

The following features exist in canon documents with one description but are implemented differently in code. Neither side is "wrong" — the canon describes the design intent, the code describes the shipped reality. This matrix reports shipped reality with the discrepancy noted.

Feature Canon description Code reality Severity
DEL authorization Clipped-ReLU: authority_c = min(cap_c, max(0, DEL_score − threshold_c)) Linear weighted average: 100 * (0.5*passport_pass_rate + 0.3*evidence_completeness + 0.2*verification_weight) + HMAC-signed proof Medium — concept (threshold-gated authority) is correct; activation function shape differs
WITHHOLD verdict Named verdict for documented non-action No formal WITHHOLD in Eligibility enum; closest are blocked + advisory-only Low — semantics equivalent, vocabulary differs
L0–L5 autonomy ladder Six-level ladder per (account × action class) Two-stage model: STAGE_3_RECOMMEND_ONLY, STAGE_4_BOUNDED_AUTONOMY High — customer-facing claims reference L0–L5; code cannot express levels 0, 1, 2, or 5
Promotion gates Automated evaluation: Brier ≤ 0.20, AUC ≥ 0.72, ≥ 2 cycles Thresholds described in metric_contracts.py docs only; no evaluator code; promotion via manual POST High — no automated gate exists; all promotions are human-performed
Enhanced Conversions adapter Action-runner execution adapter Measurement-rails rail only; no action-runner adapter Low — rail-only posture is correct for current observe-only mode
"Unified Connector Gateway" (r1.4 draft) One named gateway component normalizing 15 sources No component named "gateway" in code; two parallel mechanisms (service-canonical-ingestion, MAPPERS→ingest_gate) with different envelope shapes; 7 of 15 named "sources" are not ingestion sources at all Medium — real connectors exist and are governed, but the "one gateway" framing is inaccurate; corrected in r1.4 §14.1
"Domain Desks" (r1.4 draft) Counsel/Capital/Estate/Risk/Nexus run "the same loop and gates" as marketing, spec'd in r3.5.1 Deterministic fixture-only demo engines on the marketing site; Capital/Risk/Estate do not exist as production cells (OFFERING_MAP.md row 5); r3.5.1 does not mention any of these terms High — original draft attributed a false citation and implied production parity; corrected in r1.4 §14.5

LAUNCH PACK STATUS

LAUNCH_DEVELOPMENT_PACK_v1.0.md: NOT FOUND in repo or Drive prompt board. Searched: - Repo: find across all paths — no match - Drive: MIZ/ tree — no match (Drive search timed out on deep traversal; prompt-board folder contents enumerated — no LAUNCH_DEVELOPMENT_PACK present)

Per task instructions: the pack is unreachable. This matrix was derived directly from the four canon documents + OFFERING_MAP + SIGNAL_OVERVIEW + service registry + Cell Registry + live code verification. Parts B–D (LAUNCH_KIT_v1, PILOT_REPORT_SPEC_v1, SHOPIFY_INSTALL_ACCEPTANCE_v1) were not found and are not reconstructed.


VERIFICATION METHOD

Each row's status was derived from: 1. Canon documents — the four named sources plus OFFERING_MAP v2.3 §6 deployment state table and amendment r3.5.2 2. Service registry (production/service-registry.yaml v2) — deployed revision, auth posture, adapter inventory 3. Cell Registry (docs/architecture/CELL_REGISTRY.md v1.1) — cell function, deploy status, live-verified dates 4. Code verification — three independent subagent sweeps (intent pipeline, DCP/governance, Shopify/commerce/channels) reading actual source files in src/cells/, services/, contracts/, config/ to confirm implementing artifacts exist and match canon claims. Test counts: Cell 33 (246 tests / 9 files), Cell 34 (307 / 14), Cell 35 (341 / 14), Cell 36 (111 / 6), lift-engine (81 / 8). 5. Register items — cross-referenced against .claude/memory/active/current-priorities.md open work register

Status labels follow the canon vocabulary: LIVE / PARTIAL / IN BUILD / PROPOSED. Where a capability is built but flag-off by design, DARK is appended. Every gap becomes a register item in the Gap Register above.

Claim discipline note: Five code-vs-canon discrepancies were found and documented in the CODE-VS-CANON DISCREPANCIES section above. Two are HIGH severity (L0-L5 ladder and promotion gates), affecting customer-facing claims. This matrix reports code reality, not canon aspiration, per TRUTH.md 4.5.

← All docsView source on GitHub →