Marketing Growth Control v1.3 — Build Report (2026-08-19)

Workstream: marketing-growth-control-website-v1.3 (claim landed on main, d435e90) Branch: claude/marketing-growth-control-website-v1.3 — build LOCAL until in-session APPROVED: MERGE (GATE 1) Governing spec: # MIZ OKI 3.5/docs/marketing-growth-control-v1.3/CLAUDE_CODE_MASTER_PROMPT_MIZOKI3_MARKETING_GROWTH_CONTROL_v1_3.md Authorization: owner selected "Build the v1.3 /marketing page" (in-session disambiguation of Approved:commit, 2026-08-19 ~19:5xZ).

Step 0 — verification before editing

The change (exactly two files)

  1. # MIZ OKI 3.5/marketing/index.html — replaced with the audited v1.3 visual plus exactly four named edits: - a version/provenance HTML comment after <html> (§8.1.5; the final sha256 lives HERE, never inside the hashed file); - an @media print block appended inside the inline <style> (§5.2 — print keeps status/governance labels; verified below); - one <noscript> paragraph (class disclosure) after the scenario tablist (§5.2 JS-off honesty; the CPA trace is fully server-rendered); - the §6.12-required pilot paragraph ("Verified pilot numbers—not marketing copy—are what may later flip Preview labels…" + owner-inputs sentence) — added on the verifier's finding 6. The print block's nav selector was corrected to the page's real header elements on the verifier's finding 3 (header nav, .header-cta). No copy edits. The v1.2 → v1.3 content deltas are the package's own (posture rail, §00 four loops, §05B ValidationPassport, §08B Net Yield, F1–F5 frontier cards, expanded O-1 card, corrected hero language).
  2. # MIZ OKI 3.5/tests/test_marketing_site.py — landing contract updated to v1.3 (6 tabs/scenarios; RECOMMEND / NO MUTATION replaces the v1.2 No REQUEST_EXECUTION marker) plus a new GrowthControlV13ContractTestCase pinning the §8.2 battery: the five exact posture labels, four loops, ten ordered contract questions, six jobs, five frontier statuses + their gates (DATA_INSUFFICIENT, no-F3-dispatch, Level-2 approval, two clean cycles, NOT_CONFIGURED), ValidationPassport fields with DecisionProof absent, I-01…I-05 retention + consent-fail-closed + O-1 denial line, net-yield missing-cost / observed-return-cycle / writeback-off rules, "Prediction never grades itself" + registered holdout, version comment + print + noscript + reduced-motion — and a both-directions seeded-mutation test (_v13_contract_violations): the real page returns zero violations and each of ten §8.2 mutations (external URL, internal route link, flipped writeback, removed O-1 denial, F3 dispatch wording, F4 no-approval, F2 extrapolation, F5 always-active, affirmative guarantee, bare performance figure) is caught by name. All other test classes (nested pages, mirrors, divisions, simulator, storyboard, drift guard) preserved unchanged.

Hashes

Route isolation (§9.1)

Gates on the changed tree

Rendered QA (§10)

Chromium (Playwright, pre-installed browser), file:// load of the built page:

Independent verification (§11)

Verdict: no BLOCKING findings. Full verbatim report: appended below as §A. Disposition of every finding:

# Severity Finding Disposition
1 MAJOR §8.2 test pins missing (EventSource/cookie/indexedDB markers; focus-visible + breakpoint; F1 human-approval gate sentence; scenario outcome states; sensitive-category denial; prose passport fields; MEASUREMENT_WRITEBACK seed; social-proof absence; $-figure arm) FIXED — all pins added; suite 66→68; both seeded directions re-proven
2 MINOR Report untracked + placeholder hash FIXED — report committed with this change set; final sha frozen above
3 MINOR Dead nav .links print selector FIXED — header nav, .header-cta (real elements); labels still print
4 MINOR Hero CTAs #trace/mailto vs §6.1's #pilot/#decision-trace naming RECORDED, not changed — inherited from the owner-audited design source; targets are local fragments with existing ids; changing the reviewed artifact's CTA wiring is a design decision, not a truth fix
5 MINOR Four-loop explainer static, not selectable RECORDED, not changed — conservative direction (less simulated interactivity); inherited from the audited design
6 MINOR §6.12 label-flip statement absent FIXED — sentence added to the pilot section (edit 4) and test-pinned
7 MINOR Five scenarios JS-only RECORDED — all six live in the page source per §7.1; the added <noscript> disclosure states exactly this
8 MINOR Wordmark https self-links RECORDED — the sanctioned sole-canonical-URL exception, codified in the tests

Caveats / GATE status


§A — Independent verifier report (verbatim)

Note on the verbatim below: it describes the PRE-disposition tree (three-edit delta, 66 tests, sha fe549670…, untracked report). The disposition table above records what changed in response; the frozen post-disposition state is sha 4dfa4e4c…, four named edits, 68 tests.

Independent Adversarial Verification — /marketing growth-control v1.3

Verified from /home/user/MIZOKICloudRun at origin/main = d435e900 (branch tip identical; the change is the two uncommitted working-tree modifications). Tree restored as found: post-verification sha256 of both files identical to pre-stash (fe54967065bd46ec…, 00b8b5e5d85bbad7…), git stash list empty.

BLOCKING

None found.

MAJOR

1. §8.2-required test pins that do not exist in # MIZ OKI 3.5/tests/test_marketing_site.py. The page itself is clean on every one of these (I verified each on the page), but the delivered test contract cannot catch their regression. Proof: grep -c "<token>" tests/test_marketing_site.py returned 0 for each of: - EventSource, cookie, indexedDB — §8.2 names all three in the network/storage ban; the marker list (test line 185–189) covers only fetch(, XMLHttpRequest, sendBeacon, WebSocket, localStorage, sessionStorage, serviceWorker, window.location. A future document.cookie or new EventSource(...) passes the suite. - focus-visible, max-width — §8.2 explicitly requires "focus styles … mobile breakpoint" tests; only skip link, reduced-motion, print, noscript are pinned (test line 365–369). - Generated creative — F1's required gate ("F1 provisional/human approval") is pinned only as the status label; the gate sentence "Generated creative always requires human approval." (page line 523) is unpinned. - POLICY VETO, HALT AT APPROVAL, RECOMMEND / NO DISPATCH — the §6.5-required scenario outcomes (present on the page, lines 582/590/598) and the "F5 … veto" half of §8.2's frontier list are unpinned. - Sensitive-category — "Sensitive-category inference is denied at ingest and hypothesis creation." (page line 423) is the §8.2 "sensitive deny-list" item; unpinned. - 13 of 18 §6.6 passport field names — PASSPORT_FIELDS pins only decision_id, loop_id, job_id, signal_refs, action_dispatch_or_veto (+ SHA-256 + the hard-constraint sentence). hypotheses_ranked, plan_options, validation_gate_results, DEL_score, autonomy_level, approval_record, rollback_plan_ref, predicted_outcome, measurement_window, realized_outcome, learning_update_ref, tenant, sha256 are unpinned; the page carries them as prose ("ranked hypotheses", "Selected + rejected plans", "Gate results", "DEL score", "autonomy level", "approval record", "rollback reference", "Measurement window", "realized outcome", "learning-update reference", "tenant" — all grep-confirmed present), so §8.2's "all required field names" is met in word form but not snake_case, and the tests pin neither reading completely. - MEASUREMENT_WRITEBACK · ON — the _v13_contract_violations checker covers both flags, but the seeded-mutation proof flips only NET_YIELD_WRITEBACK; the MEASUREMENT direction is never demonstrated to fire. - testimonial / customer-logo absence unpinned; the bare-performance-figure regex covers % and × but not $ figures.

MINOR

2. The page's provenance comment makes a present-tense claim that is not yet true. Line 11–13: "Final sha256 of THIS file is recorded in docs/reports/MARKETING_GROWTH_CONTROL_BUILD_2026-08-19.md". That report is untracked (?? docs/reports/… in git status; not part of the two-file diff) and its hash field is a placeholder: line 76 reads **New v1.3 marketing/index.html (content freeze):** TO-FREEZE. If only the two allowlisted files merge, the pointer dangles and the promised hash (fe54967065bd46ec844b3a0c97b3160511fece3aaf3c89ec4502aa98c78c5c9b as of this review) is recorded nowhere.

3. Dead selector in the added print block. nav .links { display:none } (page line 311) matches nothing — this page's nav contains bare <a> children (line 321–323, no .links class; that class exists only on the nested pages). Header nav links therefore still print. The builder report's "tabs/nav suppressed by the print block" is half-true: .tabs yes, nav no. Governance/status labels do survive print (nothing hides .status), so §5.2's actual requirement holds.

4. Hero CTAs deviate from §6.1. Spec: "one primary local CTA to #pilot and one secondary local CTA to #decision-trace". Page (lines 335–336): primary → #trace, secondary → mailto:. No #decision-trace id exists (#trace is the trace section). Inherited unmodified from the audited design source (delta vs source is only the three sanctioned blocks).

5. §6.3/§7-item-2 "selectable four-loop explainer" not implemented. L1–L4 are static <article>s (lines 356–359); the only scripted interaction is the scenario tablist. Conservative direction (less simulated interactivity), but the spec text is imperative ("Make each loop selectable locally").

6. §6.12's required statement is absent. "State that verified pilot numbers—not marketing copy—are what may later flip Preview labels" — grep -i "flip\|pilot number\|verified number" marketing/index.html finds only "Writeback requires its own verified pilot and separate approval" (line 510). CANON_STATUS row "90-Day Pilot" and OFFERING_MAP §B.6 both carry the flip-on-verified-numbers rule. Absence claims less, not more, so it is not a truth violation.

7. Five of six scenario traces are unreachable without JavaScript. All six exist in the HTML source (inline <script> data object, lines 551–600 — satisfies §7.1 "may reveal/switch it but not fetch it"), but with JS disabled only the server-rendered CPA panel displays; strict §5.2 reading ("all material content remains available") is not met. The added <noscript> paragraph (line 439) honestly discloses exactly this.

8. Wordmark links are absolute-https self-links. Header line 320 and footer line 546 use href="https://mizoki3.com/marketing" — in tension with §2.3/§8.2 "every non-mailto link is a local fragment", though they are the sanctioned sole https URL and leak no route. The test codifies the exception (allowlist: exact canonical | #… | mailto:hello@mizoki3.com, test lines 161–167).

PASS-NOTES (what I ran, what I saw)

9. Scope / route isolation (task 1): git diff --name-only origin/main → exactly # MIZ OKI 3.5/marketing/index.html and # MIZ OKI 3.5/tests/test_marketing_site.py. app.py untouched. Independent Flask-test-client served-body hashes on the changed tree: / 2743581928fac9c9, /signal ae0e75bdc0b4f776, /media 9587fcf070c279cf, /pricing cfeea2fc0fb4c767, /shopify 29a24a6943ded2ae — all serve files untouched by the diff — and /marketing fe54967065bd46ec == the file's own sha256, so the route serves exact file bytes (also pinned by test_exact_route_serves_the_authenticated_file, which passed).

10. Design-source delta (task's DESIGN SOURCE check): sha256sum of the visual = 45740b1a…e89f5 (matches the stated pin). diff visual marketing/index.html = exactly three insertions: comment block at 3a4,14 (directly after <html lang="en">), @media print at 295a307,314 (inside <style>, lines 27–315; includes one accompanying whitespace-only line), <noscript> at 419a439 (immediately after the tablist </div>). Nothing else.

11. Claim accuracy vs CANON_STATUS/OFFERING_MAP §B.6 (task 2): Intent Engine v2 → page "Preview · in development" + rail "Intent evidence · Shadow / no action" + I-05 "IN BUILD" (≤ IN BUILD shadow — legal-conservative). Net Yield → "08B / NET YIELD · IN BUILD" + "NET_YIELD_WRITEBACK remains OFF". F1 IN BUILD · PROVISIONAL, F2 IN BUILD · DATA-GATED, F3 IN BUILD · OBSERVE-ONLY, F4 IN BUILD · PER-ACTION APPROVAL, F5 IN BUILD · CONFIG-DECLARED — each matches its row. Grep for LIVE|ACTIVE|PRODUCTION|AUTONOMOUS|PROVEN|DEPLOYED returned only denials ("They are not live capabilities…", "not production telemetry", "not live tenant data"), gate-conditions ("rollback are proven" as a future gate), the route comment, and "the named synthetic covenant rule is active" (config-qualified synthetic scenario — the legal form §8.2 itself requires). Zero performance figures in visible copy (all % hits are inside <style>; no $, no ×-figures; "Attributed ROAS remains flat" carries no number). Frontier section states "advanced from roadmap to governed implementation … not live capabilities, customer results, permission to act."

12. O-1/consent/identity/writeback/holdout/approval language (task 3): keystroke/audio/gaze/fine-geolocation appear exactly once, only as the prohibition card (line 422: "Keystroke dynamics are prohibited." + DISALLOWED_KEYSTROKE_DYNAMICS + the denial list). "Prediction never grades itself." and "A registered holdout is required before activation." both at line 361; "Consent failure means no processing", "Sensitive-category inference is denied at ingest and hypothesis creation", "Probabilistic identities do not enter causal-effect math", "No persistent psychological dossier is created." all present. No mind-reading/true-cause/proves-causality/physiological language (grep empty). "ranks the most supportable causal hypothesis" present.

13. Posture rail (task 2/§4.2): all five labels present directly below the hero in the required order; source is mixed-case but .status span { text-transform:uppercase } renders the §4.2-exact uppercase strings. Tests pin the source-case form.

14. Link/network contract (task 5): the only http(s) URL anywhere is https://mizoki3.com/marketing (5 occurrences: route comment, og:url, rel=canonical, two wordmarks). Every # href has an existing target id (also test-pinned). No fetch/XHR/WebSocket/EventSource/storage/cookie/indexedDB/serviceWorker/sendBeacon/url(/@import, no <form>/<input>/<textarea>, no og:image/twitter meta, no setInterval/setTimeout/new Date/Math.random/Date.now, no links to /, /signal, /media, or nested /marketing/* (grep exits confirmed empty).

15. Accessibility (task 6): one h1; skip link → existing #marketing-main; tablist with role=tablist/tab/tabpanel, aria-selected, roving tabindex (0/-1 swapped in selectTab), aria-controls, panel tabindex="0" + aria-live="polite"; ArrowLeft/Right/Up/Down/Home/End handled with preventDefault; :focus-visible outlines; prefers-reduced-motion block; @media print; breakpoints at 1120/840/580px with single-column ≤580px. Caveat: I could not independently exercise the hydrated DOM (no Playwright in this environment) — keyboard behavior is verified by source review plus the passing contract tests, not by an independent browser run; the builder's screenshot claims remain builder assertions.

16. Gates (task 7), all run from # MIZ OKI 3.5: content_qa.py --self-test → "SELF-TEST PASS — the gate fires"; content_qa.py --root . → "CONTENT QA OK — 59 scoped files clean" (this page IS in SCOPE_FILES, line 210). check_marketing_surfaces.py --root . → "MARKETING SITE OK — 12 pages + engine, stylesheet, routes, and tests all present". check_design_canon.py --root . → "CANON OK — 20 core surfaces match v1.5-night-dossier". Repo-root scripts/mizoki_canon.py --check exit 0; claude_memory.py check --strict structurally valid (2 pre-existing size warnings).

17. Suites (task 7): focused: venv/bin/python -m pytest tests/test_marketing_site.py -q → 66 passed. Full tests/: changed tree 8 failed, 488 passed; after git stash push of the two files (tree == origin/main, diff count 0) the base run produced the identical 8 FAILED tests (diff of sorted failure lists → "IDENTICAL FAILURE SETS"): 2× test_content_qa (debt-ids cross-check, signal link-preview), 3× test_demo_platform (icon set, homepage teaser, division pages), 3× test_signal_capability_site (hub links, sec-marks, hub ledger) — all pre-existing on untouched main, none introduced by this change. git stash pop restored both files byte-identically (sha256 match against pre-stash record).

18. Test-diff hygiene (task 8): only 4 removed lines, all justified baseline moves with intent kept: assertEqual(3→6, len(tabs)); scenario tuple 3→6; test rename; "No REQUEST_EXECUTION" marker (absent from the v1.3 design, confirmed 1 hit on old page / 0 on new) replaced by "RECOMMEND / NO MUTATION" in the same list. The seeded-negative machinery is genuinely two-directional: the real page must return zero violations and each of ten §8.2 mutations must be caught by name — all nine §8.2-listed mutation classes are represented (external URL, route link, fake result via % figure and affirmative guarantee, flipped writeback, O-1 removal, F3 dispatch, F4 no-approval, F2 extrapolation, F5 always-active), and O-1 denials are tested contextually (required present, never flagged).

19. Context note: an untracked docs/reports/MARKETING_GROWTH_CONTROL_BUILD_2026-08-19.md sits at repo root (the repo's actual reports convention). It is not part of the diff; see finding 2 for its placeholder hash. Its served-route hashes independently reproduce against my own measurements.

Bottom line: no blocking findings. The two-file scope, three-block design delta, status-table conservatism, O-1/writeback/holdout language, F1–F5 gates, link/network contract, and route isolation all hold under adversarial measurement, and every full-suite failure reproduces on base. The one MAJOR item is test-contract completeness against §8.2 (finding 1); findings 2–8 are minor spec deviations or housekeeping, several inherited from the audited design source.

← All docsView source on GitHub →