GROWTH CONTROL ACTIVATION v2.1 — STEP 0 GROUND TRUTH
Date: 2026-08-21 · Session lane: growth-control-activation (board row + ledger claim landed via memory-only push, merge-verified) · Build branch: claude/growth-control-activation-v2.0 (LOCAL until GATE 1)
0.1 HEAD and baseline
origin/mainat claim time:06eddada—aed3e84verified an ancestor (git merge-base --is-ancestor aed3e84b5 origin/main= yes). Main is AHEAD of the prompt's baseline; no divergence.- Build branch created from
origin/main(06eddada). Claim commitf88f141amerged to main before branch-off.
0.2 Registry ground truth — and the honest limit
gcloud is NOT installed in this sandbox (which gcloud = nothing; the rule-02 known fact re-measured). A live gcloud run services list is therefore not possible from this session. Registry ground truth used instead, in authority order:
docs/architecture/CELL_REGISTRY.md— cells 33–36 rows (33intent-signal-ingest, 34intent-scoring-api, 35intent-graph, 36intent-causal; all deployed, IAM-locked, dispatch-only; 36 live-verified 2026-08-11). Cell 37 =market-signal-ingest, Data Injector & External Intelligence Gateway; deployed 2026-08-11; rev00038-tgkverified by the RUN PACK v2.1 session today (run 32501892239: unauth /health 403, authed 200, caller gate 200, readyz 200).production/service-registry.yaml— 37 registered services incl.service-policy-engine(:84),service-decision-control-plane(:99),service-audit-replay(:148–164,status: deployed-dispatch, run 32313888638, revservice-audit-replay-00021-qhj,auth: iam).- Dated live-verified session records ≤ 24 h old (session board + ledger).
Delta vs the prompt's assumption: services/lift-engine — the Workstream A home — has NO registry row, NO repo CI workflow, NO deploy workflow, and NO entry in config/service_endpoints.yaml (its .github/workflows/ci.yml is nested inside the service dir where GitHub never reads it; its cell_registration.json self-declares cell_lift_measurement but nothing registers it). Registry wins per the prompt's authority order: lift-engine is treated as an unregistered, un-deployed-by-CI code home, and Workstream A lands code + tests there without asserting any serving state. Registering/deploying it is an owner decision recorded in §0.8.
0.3 Standing gate commands — verified by file and CLI
| Gate | Asserted historically | Verified working command |
|---|---|---|
| Canon lint | mizoki_canon.py --check |
scripts/mizoki_canon.py has NO CLI (no argparse/__main__ — re-verified by grep; matches ORACLE_PRECONV finding F1 and the v1.3 prompt's rebinding). Real gate: python3 scripts/skill_sync.py --audit (imports mizoki_canon) |
| Skill parity | — | python3 scripts/skills_sync.py --check + python3 scripts/ontology_skills_sync.py --check (both run green at Step 0) |
| Frontier suites | — | pytest tests/governance -c tests/governance/pytest.ini (the -c is load-bearing: bypasses repo-wide cov gates). Baseline frozen at Step 0: 391 passed (fresh venv: pytest, fastapi, httpx, pydantic, pyyaml, pip install -e contracts) |
| Canon-status drift | — | python3 scripts/gen_canon_status.py --check (exists, deterministic; doc docs/CANON_STATUS.md present, drift register currently "none") |
| Registry validation | scripts/validate-registry.py |
FAILED GATE in this sandbox: import-time ModuleNotFoundError: aiohttp (live-probing tool; not runnable here). Registry checks in this run = the governance suite's registry-adjacent tests + manual YAML review |
| Memory | — | python3 scripts/claude_memory.py check --strict (green at Step 0, one pre-existing size warning) |
| Full pytest | — | Root suite carries a known env-shaped failure set (71F/27E measured by the 2026-08-21 close-all run); the gate for this run is failure-set byte-identity pre/post plus green on every touched suite |
| lift-engine suite | Makefile: pytest tests/ --cov=src from service dir |
Verified invocation: cd services/lift-engine && python -m pytest tests/ -q --confcutdir=. -p no:cacheprovider with the service deps installed. Measured pre-existing state (untouched base): 4 of 8 test modules fail COLLECTION on real API drift (test_bayesian/test_lag_analysis/test_recommender/test_window_sizing import functions that do not exist in their source modules), and the collectable remainder runs 36 failed / 5 passed — the suite is broken against its own code, consistent with no CI ever running it. Gate for this run: the pre-existing failure set stays byte-identical (Workstream A adds files only) AND the new dosage tests are green and hermetic (numpy-only) |
0.4 Capability inventory (per §2) — all homes EXIST; none absent at STOP level
| Capability | Canonical home (verified paths) | State |
|---|---|---|
| Edge inference | miz-oki-adk-agents/boss/edge_inference_integration.py (1927 L; registry/consumer/gate/orchestrator; routes + MCP tools registered from boss_agent_core.py:2538–2562, 27819–27845, env ENABLE_EDGE_INFERENCE default "true") + browser client miz-oki-command-center-ui/lib/edge-inference/onnx-runtime-web.ts (658 L; dead code — zero importers) + dead gateway mapping services/api-gateway/main.py:137 (prefix mismatch /api/v1/edge-inference vs registered /api/v1/edge/...) |
Prototype. Fail-open at 4 measured sites (browser gate :369–371, :379–382; server unknown-treatment → default LEARNING-allow :959–965 + :1006–1013; Firestore-read failure falls through to the same allow). No model signing/integrity anywhere (zero hits for signature/checksum/sha256/integrity in all three files); version is an unenforced string; POST /api/v1/edge/models takes onnx_path with no auth. Client auto-treats on positive CATE (treatThreshold = 0.0, :508–515). Edge→platform-adapter path measured fully severed (no adapter/HTTP hits either direction; action-runner requires DCP-signed single-use authorizations) |
| Continuous dosage | — | ZERO code repo-wide (only a benchmark-taxonomy enum TreatmentType.CONTINUOUS_DOSE in miz-oki-adk-agents/boss/causal_reasoning_uplift.py:55). lift-engine learners are hard-binary (meta_learners.py T == 1 masks; uplift_scoring.py:55 discrete_treatment=True). Confirmed the primary net-new |
| Micro-geo calibration (F4) | src/shared/growth_control/f4_calibration/ (config/matching/reservation/estimator/priors/cycle/store) |
Built, flag F4_CALIBRATION_DEFAULT = False. Config config/f4_geo_candidates.yaml all-empty → every proposal refused by name (spend_cap_not_declared, perturbation_bounds_not_declared, no_candidate_geos). L2 gate = structural (requires_approval: not autonomy.eligible, actuator f4-geo-reservation deliberately unregistered; autonomy flip evidence-gated at parse, needs ≥2 clean_cycle_refs). Delta: "L2" is posture, not a routing primitive — service-approval-routing/main.py has no materiality/level branch |
| Creative unbundling (F1) | src/shared/creative_aesthetic/ (elements.py CreativeSemanticProfile :296–335; dr_effects.py AIPW estimator) |
Built, flag OFF, provisional enforced at three independent layers (config gate, provisional=True hard-wired, store seam refuses non-provisional). Volume floors 10000/8 raise-only. Config null-template. No runtime caller — library + tests only |
| Multi-quarter LTV (F2) | src/shared/growth_control/f2_ltv/ |
Built. quarterly_discount_factor: null → not_configured; MIN_OBSERVED_QUARTERS = 2 code floor (raise-only, data_insufficient shape pinned both ways); Net Yield connection = formula copied verbatim from net_contribution.sql/compute.py (pure-Python constraint forbids import; drift-diff test absent — noted) |
| Inventory sync (F3) | src/cells/cell37/market_cell/ (f3_inventory.py, f3_config.py, f3_store.py; routes main.py:515–549) |
Built, flag OFF, recommend-only enforced structurally at 4 points (unregistered actuator, prose-as-data vectors, neutered DCP proposal estimated_value 0, transport-required seam). Config all-null → not_configured. Freshness rules ABSENT from the schema entirely (no key, no evaluator age check; observed_at is evidence-only; BQ reader unwindowed) — a schema extension is in scope for E (key + null default), values stay owner-supplied |
| Treasury governance (F5) | contracts/mizoki_contracts/treasury.py (+ treasury_feed.py v2 stub) → service-policy-engine/main.py:43–120 (treasury FIRST among hard blocks) → DCP main.py:197–216 (breach → non-redeemable human review) → audit-replay GET /api/v1/treasury/breaches |
Built v1, per-proposal only. No commitment/reservation ledger anywhere (zero repo hits; the config header itself declares cumulative tracking v2 scope). No snapshot signature fields/verification anywhere. Config all-null + TREASURY_CONSTRAINTS_PATH unmounted → doubly OFF. Workstream D builds the ledger + signed snapshots in this home |
| ValidationPassport | contracts/mizoki_contracts/passport_package.py (single home; eight-object closed set decision_objects.py:61–213, closure rule miz_oki_source_of_truth.py:283–293) served by services/service-audit-replay/main.py (deploy workflow deploy-governance-services.yml, registry row present) |
Built. Seal = plain unkeyed SHA-256 (:51–55); immutable_hash same; ActionAuthorization = HMAC (DCP_SIGNING_KEY, dev-default refused when deployed). KMS: absent from all application code (only Terraform binary-auth/CMEK). Canonicalization: two coexisting json.dumps schemes (sort_keys+default separators vs envelope's compact separators); no JCS; no canonicalization-stability test |
0.5 Config templates — current null/empty state (all verified in-file)
config/f1_creative.yaml (thresholds at code floors, pilot_validated: false, evidence null) · config/f2_ltv.yaml (quarterly_discount_factor: null) · config/f3_triggers.yaml (all SKU/default thresholds null, fulfillment_nodes: {}) · config/f4_geo_candidates.yaml (geos: [], caps/bounds null, autonomy.eligible: false) · config/treasury_constraints.yaml (all monetary values null, curve empty; only max_position_age_days: 7) · config/net_yield_costs.yaml (all cost fields null; placeholder SKU). Every header carries the "system never invents values" contract. This run populates NOTHING (no owner values supplied in-session); Workstream E verifies gates-as-code and ships the owner-input checklist (§0.8).
0.6 Plans of record + canon state (Workstream F items 1–3 = already landed; verified)
docs/MIZOKI_SIGNAL_GROWTH_CONTROL_UNIFIED_SYSTEM_r2.0.md— sha256397ebcdb97e0784666e96d6a4c8503dc1a47cc891154cd96a520cc8f692d9f33docs/MIZOKI_3.5_WHITEPAPER_r3.5.1_AUG2026.md— sha2566f0ded9ce9bbdc1df8195001c13c5efc9dffe8ea58497b91ea496ee048c8d48bdocs/MIZOKI_3.5_WHITEPAPER_r3.5.2_AMENDMENT_AUG2026.md— sha2566d827a5849c48767…3509f410afbad8b3- Vocabulary ratification: executed (ruling 2026-08-19-A;
RATIFIED_VOCABULARYatscripts/mizoki_canon.py:80; rule 03 documents both directions). OFFERING_MAP is v2.3 FINAL (2026-08-19).docs/CANON_STATUS.md+ generator +GET /api/v1/status/canon+ CI-warning mechanism all exist (F.4 pre-satisfied; this run verifies freshness).
0.7 Coordination
Ledger + board checked at claim time (main 06eddada): no overlapping growth-control-activation claim. Claim recorded and merge-verified before build. The superseded Completion v1.1 prompt (docs/prompts/CLAUDE_CODE_MASTER_PROMPT_GROWTH_CONTROL_COMPLETION_v1.1.md) is NOT being run; it receives a supersession banner in Workstream F so no future session executes it.
0.8 Owner-input checklist (the critical path this build cannot cross)
pilot tenant selection · net_yield_costs.yaml real costs · treasury floors/covenants/dated cash position (+ KMS key for snapshot signing once C lands) · F4 candidate geos, historical panels, perturbation limits, spend caps · F2 quarterly discount factor · F3 SKU thresholds + freshness bounds · creative-asset access for F1 volume · decisions: register/deploy lift-engine (it is currently an orphan: no CI, no registry row, retired-Neo4j client in its src/integration/knowledge_graph.py) · KMS key provisioning (PASSPORT_SIGNING_KMS_KEY) · whether approval-routing should grow a real materiality/level branch (today "L2" is enforced structurally, not by the routing service).
0.9 Scope notes recorded before building
# MIZ OKI 3.5/**(site source +site_docsmirrors) is untouched — §9 forbids site-visible changes; mirrors regenerate at owner dispatch.- Skill/skillpack semantic updates are logged as deltas, not edited — rule 03: skill bodies change only through the Boss's skill process. Parity checks still run green (no skill files touched).
- "distillation": measured zero occurrences tied to the edge ONNX prototype (the term's repo uses are MII trace-capture and Cell 16 KD — legitimate, untouched). Workstream B introduces none.
- Historical reports/prompts quoting the
--checkno-op remain as records; the live correction = supersession banner on v1.1 + this report; forward-looking docs already carry the v1.3 correction.