ORACLE Pre-Conversion Intent v1.0 — BUILD Report
Date: 2026-08-18
Session: oracle-preconv (cloud; master prompt v1.2)
Branch: claude/oracle-preconversion-intent-v1.0 — LOCAL, UNPUSHED (awaiting in-session APPROVED: MERGE, GATE 1)
Rebase base (v1.2 pre-push re-gate): rebased onto origin/main @ 49c1795 (8 commits ahead of the original branch point e929cda); the one overlapping file tests/shared/test_virtuoso_models.py 3-way-merged cleanly (main's new Gemini-enum/failover tests + this build's moved schema-hash pin + additive test both preserved, non-overlapping regions). All gates below were re-run on the rebased tip. If main moves again before APPROVED: MERGE, this rebase + re-gate repeats (v1.2 §6.2).
Coordination note + reconciliation (owner chose "Reconcile first"): a takeover record on main (4c2cb70, 20:46Z) directed a separate y3m3cq session to run this same v1.2 build and asked this session to stand down. Reconciliation, evidence-based: y3m3cq produced the excellent pre-flight review (docs/reports/ORACLE_PRECONV_PROMPT_REVIEW_2026-08-18.md, already on main) + the takeover record, but committed/pushed NO build code — its branch claude/google-drive-file-review-y3m3cq is 0 commits ahead of main, and its board row self-reports "Step 0." This session's build is the only actual build, and it already incorporates every y3m3cq review finding (F1 real canon gate, F3 Firestore-not-Neo4j wording, F10 creative-suite inherited-inventory check; F2/F4/F5/F7/F8/F9 independently matched). There is no duplicate build to lose — only the review (folded in) and the build (this session). Recommendation: this session's build lands; the ledger records the supersession honestly (y3m3cq did the review that shaped it). The branch is not on origin; this session has not pushed and awaits APPROVED: MERGE.
Memory standing-gate note: claude_memory.py check --strict logs a pre-existing main-side ERROR (module-missing: .claude/memory/archive/2026-08-18-CLAUDE-7.0.0-3183f42dda01.md — a dangling index reference from a main-side rollover). Verified identical on a clean origin/main worktree, and this build touches no memory files, so it neither caused nor affects it. Out of this build's scope (a separate memory-governance item); flagged, not swept.
Plan of record: docs/ORACLE_PRECONVERSION_INTENT_v1.0.md (sha256 bd8096f786d0e31d356f82ab30d0d26266d93c71dbf093cb4f296ff31dd3fa66)
Step 0 report: docs/reports/ORACLE_PRECONV_STEP0_2026-08-18.md
claim_label for everything here: built, pre-benchmark. Nothing below is a performance claim. Every new capability flag defaults OFF; flag-off is byte-identical to pre-v1 (asserted by test).
Diffstat
45 files changed, 4,585 insertions(+), 21 deletions(-) — 30 non-test, 15 test files. Five commits:
docs(oracle-preconv)— plan of record (byte-identical) + Step 0 reportfeat(A)— Cell 33 VDI & passive-attention capturefeat(B)— Cell 34 session sequence transformer (shadow-only)feat(D)— Cell 35 latent intent bridges (hypothesis-only)feat(C)— creative-aesthetic vectors
Test counts (fresh venvs, one process per cell)
| Suite | Result (rebased tip) |
|---|---|
Cell 33 (src/cells/cell33/tests) |
255 passed, 42 subtests (was 217 baseline; +38) |
Cell 34 (src/cells/cell34/tests) |
293 passed, 122 subtests (incl. erasure-coverage guard + latency benchmark) |
Cell 35 (src/cells/cell35/tests) |
348 passed, 29 subtests (was 333 baseline; +bridges/creative, guards updated, +4 category-coverage after the adversarial fix) |
Shared virtuoso_models (tests/shared) |
40 passed (main added 5 Gemini-enum/failover tests on the rebase; this build's schema-hash pin + additive test coexist — all green) |
Shared creative_aesthetic |
16 passed |
Extender + /pixel/events |
40 passed (30 baseline + 10 pixel) |
Capture-core JS (node --test) |
11 passed |
Total: 999 Python + 11 JS, all green in freshly-built environments on the rebased tip.
Standing gates (v1.2-VERIFIED COMMANDS — the mizoki_canon false-green corrected)
| Gate (verified command) | Result |
|---|---|
Canon lint — python3 scripts/skill_sync.py --audit |
exit 0 (no HIGH; only pre-existing LOW findings in skill files this build never touched). Corrects the v1.1 false green: mizoki_canon.py --check is a library no-op that always exits 0 (Step 0 §0b; y3m3cq review F1). |
python3 scripts/skill_sync.py --check |
parity OK — 14 skills, derived copies match |
python3 scripts/skills_sync.py --check |
OK — all skill copies byte-identical, versions in parity |
python3 scripts/ontology_skills_sync.py --check |
OK — 8 profiles, governance preserved |
| Hardcoded-model-string grep (changed source) | clean — no literal model string outside test fixtures / model_registry.py |
| Pre-merge hygiene V1 (SRDAL) / V2 (retired models) / V3 (PA-API) | clean on changed files |
python3 scripts/claude_memory.py check --strict |
structurally valid (only pre-existing size warnings) |
| Flag-off byte-identity (all four flags) | 15 tests pass (cell33 ×7, cell34 ×4, cell35 ×4) |
Protected paths (.github/**, deployment/terraform/**, deployment/cloudbuild*, CODEOWNERS) |
NONE touched |
Site-visible / canon-locked (# MIZ OKI 3.5/**, canon.lock.json, deploy-homepage) |
NONE touched |
virtuoso_models twin byte-identity (journey-event.json) |
byte-identical |
What was built, per workstream
A — Cell 33: VDI & passive-attention capture (INTENT_BEHAVIORAL_V1, default OFF)
- Closed
behavioralblock on the IntentSignal contract (src/shared/mizoki_intent/signal.py):vdi,dwell_ms,scroll_velocity_px_s,swipe_vector,partial_watch_depth,inline_expand_pause_ms,element_class(coarse token, never raw text/URL),field_class,sequence_id(26-char ULID) +sequence_index. - O-1 keystroke-dynamics prohibition — named rejection tag
DISALLOWED_KEYSTROKE_DYNAMICS, plus gaze/geo bright lines beside the existing audio prohibition. None flag-gated — a bright line does not toggle. Form-lifecycle allowlist (form_started/field_focused/form_completed/form_abandoned) + coarsefield_class(email|payment|other). - Taxonomy v1.1.0 registers the v1 signal types (reviewed commit). VDI emit-rule thresholds as cell33 config (
INTENT_VDI_EMIT_THRESHOLD0.6 /INTENT_VDI_MIN_DWELL_MS300, O-2 tunable). Additiveintent_signalsDDL (behavioralJSON +sequence_id/sequence_indexcolumns) with an idempotentALTER. - JourneyEvent schema gained an optional additive
behavioralblock; theresponse_schema_hashbump is deliberate (686738a05b36…→9d3b72621221…), both homes byte-identical, the production-contract pin moved with its reason, old events still validate (rollback level 3). - Client capture core (
services/intent-shopify-extender/pixel/capture-core.js) — batching 25/5s/pagehide +sendBeacon, client-side VDI, ULID sequencing; the Shopify-app pixel wraps it (one collector, shared core). A source-safety test asserts NO keystroke/gaze/audio/geo listener is wired. Flag-off/pixel/eventsreceiving door on the extender (IAM-locked, 404 when off, forwards through the one Cell 33 door — no reopened public receiver).
B — Cell 34: session sequence transformer (LII_REALTIME, default OFF)
transformer.py: 4-layer/128-dim/4-head causal encoder (numpy, exact-pinnednumpy==1.26.4) over closed-vocabulary tokens(signal_type, element_class, VDI bucket, dwell bucket, Δt bucket)— no raw text/URLs. Three heads (stage-transition-180s, calibrated next-interest, hesitation). Attention summary IS the explanation payload.- Serves beside the BQML batch path, never replacing it. SHADOW ONLY (plan §4): scores land in
intent_scores_shadow, never served by a read route. UNTRAINED by default — deterministic seeded init, every output stampedtrained: false/sst-v1-untrained. - CPU inference latency-benchmarked p95 < 200ms on a full 256-token trajectory (real measurement in the test).
- Shadow table is identity-linked → added to
IDENTITY_LINKED_TABLES+ cell34SUBJECT_STORESwith a cascade erase leg + Art. 15 disclosure. Erasure-coverage guard stays exact; two pinned receipt-set guards moved deliberately.
D — Cell 35: latent intent bridges (LATENT_BRIDGES, default OFF)
LatentBridgenode +EVIDENCES/IN_STATEedges extend the FROZEN namespace. Deny-list screening AT CREATION on the inferred construct: label + each evidence topic + the composite — a sensitive composite (gym + meal-replacement) is rejected at write time, never stored-unsurfaced.SENSITIVE_COMPOSITESregistry is reviewed + extends-only.status: "hypothesis"is the ONLY writable status (promotion is owner-gated). A bridge needs ≥1 internal evidence topic — Cell 37 external evidence corroborates, never mints one alone.- Generation via
Role.DATA_CAUSALthrough the registry (lazy import, flag-gated) — no hardcoded strings; the LLM's candidate name is deny-screened before any write.IN_STATE(subject-owned) erased with the subject; the shared bridge retained (aggregate, published to auditors).
C — creative-aesthetic vectors (CREATIVE_VECTORS, default OFF)
src/shared/creative_aesthetic/: pure-Python (no numpy) embeddings viaRole.CREATIVE_MM(never a hardcoded CLIP string — asserted), per-customer aesthetic vector derived fromRESONATED_WITHedges, and the ranker with auto-revert to default rotation built in (flag off / no aesthetic vector / lift-refuted campaign all fall back — not a TODO).- Cell 35:
Creativenode (tenant-scoped asset) +RESONATED_WITHedge (subject-owned) extend the frozen namespace; the aesthetic profile is erased with the subject by construction (edge-derived — no second identity-linked table).unified.creative_vectorsDDL (NOT identity-linked — campaign assets). - Registry-wins deviation recorded: the plan's "stored beside the intent vector" resolves to edge-derived because (a) the intent-vector table does not exist in the tree and (b) a derived projection of already-erasable edges cannot drift from the erasure cascade.
Registry-wins deltas (plan vs. tree; the tree won)
- Plan header "37-cell" → 39 registered cells.
- Plan's Cell 35 "Neo4j intent graph" → Firestore-journal + in-memory serving (Neo4j retired 2026-08-09); bridges/creative wired to the shipped store.
- Plan's
LII_REALTIME"existing flag" → created (did not exist);unified.intent_predictionsrealized-loop → the realintent_outcomes→intent_training_examplesloop;unified.intent_vectors/unified.creative_vectors→ resolve tomizoki_unified_data.*. - Shadow table
unified.intent_predictions_shadow→mizoki_intent.intent_scores_shadow(twin of the real scores table). - The Shopify Web Pixel JS is not in this repo (ships with the app project); Workstream A ships the shared capture core it wraps + the receiving door, not a second collector.
Rollback (verified, per plan §5)
- Level 1 — flags: turning each flag OFF fully reverts behavior with no deploy. TESTED:
INTENT_BEHAVIORAL_V1,LII_REALTIME,LATENT_BRIDGES,CREATIVE_VECTORS,PIXEL_EVENTS_ENABLEDeach have a flag-off test proving byte-identical / no-op behavior. - Level 2 — revision: no deploy in this run (GATE 2). Pre-deploy revision capture is an operator step recorded at deploy time.
- Level 3 — schema: the
response_schema_hashbump is additive-only; old-schema events still validate (TESTED:test_journey_behavioral_block_is_additive). All new columns are nullable/optional; theALTERisADD COLUMN IF NOT EXISTS. - Additive BigQuery + Firestore-backed graph: new tables (
intent_scores_shadow,creative_vectors) and Cell 35 Firestore-backed store labels/edges (LatentBridge/Creative,EVIDENCES/IN_STATE/RESONATED_WITH) are additive; rollback = stop writing (flag off), never drop, until a separate owner-approved cleanup. Not "Neo4j labels" — Neo4j was retired 2026-08-09; Cell 35 serves in-memory with a Firestore journal, and the namespace extensions are frozen-allowlist additions in that store (y3m3cq review F3 / §5.4).
Independent adversarial verification (blind pass) + the one fix it drove
Per verification-discipline rule 01, an independent verifier reviewed the diff blind to the builder's reasoning. Verdict: 8 of 9 claims PASS with run-command evidence — flag-off byte-identity (probed real inputs, 0 collisions), bright lines not flag-gated (no keystroke signal acceptable through any path), erasure coverage (9/9 + subject-owned edges erased / aggregates retained), no hardcoded model strings, twin byte-identity, schema-hash pin exact, latency measured (median ≈ 48.5ms / p95 ≈ 62.3ms on 256 tokens), no protected/site-visible paths.
The one real finding — bridge composite deny-screen was materially incomplete — is FIXED (commit 5bd41ff). The verifier got 8 sensitive composites past the original 3-rule substring screen (whole categories — mental-health, addiction — uncovered; phrasing variants evading the food/fertility rules). Fix:
- BRIDGE_SENSITIVE_TERMS — individually-sensitive bridge terms (mental-health / addiction / self-harm); one hit refuses.
- broadened SENSITIVE_COMPOSITES clusters (phrasing variants).
- claim reframed honestly: the deny screen is DEFENCE IN DEPTH, not a complete oracle — the real guarantees are layered (individual deny-list + sensitive terms + composites + hypothesis-only status + flag-off default + steward approval before promotion).
- CI category-coverage gate: all 8 slip-throughs now refuse and benign near-misses still pass (both directions) — the gap is visible to CI, not just to an adversarial reader. Re-probed independently: all 8 REFUSED. cell35 suite 348 (was 344, +4).
Inherited-inventory check (y3m3cq review F10) — creative lane
Before building the Workstream C ranker, checked the occupant of the "creative" slot (rule 01 inherited-inventory discipline): registry cell26 = Creative Suite (cloud-run-extended-services/creative-suite-service, deployed-fleet). Measured — it does brand-affinity scalar weighting + channel ranking + hyperpersonalization (hyperpersonalization.py: brand_affinity, _rank_channels), not per-customer aesthetic-embedding cosine ranking from VDI dwell. The creative_aesthetic module (128-dim aesthetic embeddings via Role.CREATIVE_MM, per-customer affinity derived from RESONATED_WITH/VDI dwell, cosine rank of creative variants) is a distinct capability, not a duplicate. It is a shared library the DCO/creative lane would consume; wiring it into a serving path is a GATE-2/activation concern, out of scope here.
What remains for the owner
- GATE 1 (
APPROVED: MERGE) — this build is unpushed pending the exact string. - GATE 2 (
APPROVED: DEPLOY, separate) — operator applies the additive DDL (intent_signalsALTER,intent_scores_shadow,creative_vectors) BEFORE any flag flip; captures pre-deploy revisions. - Open owner decisions carried from the plan: O-2 VDI-threshold tuning in shadow, O-3 bridge steward-approval tier, O-4 sample-rate economics at GA, O-5 dashboard surfacing of hesitation states. O-1 is CLOSED — keystroke dynamics permanently rejected (
DISALLOWED_KEYSTROKE_DYNAMICS, tested both directions). - Activation of any kind (hesitation retargeting, aesthetic serving, bridge targeting), holdout registration, and dashboard surfacing are out of this build's scope entirely — no holdout, no activation flag, no causal-credit-math change was touched.