Signal for Shopify — Phase Binding and Workstream Zero
Status: Active roadmap binding (v1.0, 2026-08-11) · INTEGRATION PROMPT v2.3, F2 + F8.2
Authority split: the L5 Autonomous Media Architecture blueprint is authoritative on
platform phases (B1–B5); docs/product/SIGNAL_SHOPIFY_MASTER_v4.md §3.3 is authoritative on
Shopify product phases and exit criteria (P1–P4); docs/product/SIGNAL_OVERVIEW_v5.md §5 is
the top-level three-clocks view. On conflict: escalate to the owner, never silently pick.
Binding rule (non-negotiable)
No product phase outruns its platform phase. P1 work may not begin ahead of B1 capability, P2 not ahead of B2, and so on. Certification artifacts are shared — covenants cite platform gates, never re-assert them.
B×P binding table
| Platform phase (blueprint) | Months | Product phase | Product scope (master authoritative) | Product exit criterion |
|---|---|---|---|---|
| B1 Control foundation | 0–4 | P1 Foundation | Shopify app, Canonical Event Envelope, NCM-v1, value feeds, L0–L1 | Clean Shopify-vs-tracked reconciliation across 10 design partners; blueprint 30-day plan = P1 workstream zero |
| B2 Measurement & world model | 4–9 | P2 Measurement | Holdout UX, ghost bids, cohort experiments, causal-credit reports, L2–L3 | First auditable incrementality artifact per partner |
| B3 Bounded autonomy | 9–14 | P3 Yield | Geo, lift-calibrated mini-MMM, cross-channel, miNCM, covenant GA | Sustained miNCM accuracy over 2+ cycles at ≥3 T3 merchants |
| B4 Hardening & scale | 14–19 | P4 Scale | Cold-start GA post-artifact, pooled priors (gated by docs/architecture/FLEET_INTEGRITY.md), App Store, Audiences interop |
Per master §3.3 |
| B5 Certified L5 | 19–24 | post-P4 | Covenant GA per action class, reversible classes first | ≥1 merchant running a certified L5 class a full quarter, zero breaches |
Phase-name verbatim binding — verification status (owner decision 12)
D-12 RULED 2026-09-15: the five phase names above (B1 "Control foundation" … B5 "Certified L5") are the names of record by owner ruling 2026-09-15 (D-12) — owner ruling 2026-09-15, docs/reports/OWNER_RULINGS_2026-09-15_REGISTER_CLOSEOUT.md. The [Assumed — verify] marker is retired; the paragraph below is kept as the measurement history that led to the ruling.
The blueprint phase names above were carried from
master §3.3, whose own label was: functional mapping [Validated by logic]; name bindings
"Assumed — verify" (now closed by D-12). Measured 2026-08-11: the L5 Autonomous Media Architecture blueprint
document itself was not located on the Drive MIZOKICloudRun board (searches for its title and
distinctive phrases returned no standalone document), so the names could not be verified verbatim
against the source. The flag stood and was escalated in
SIGNAL_SHOPIFY_LANE_STATUS_2026-08-11.md: owner to drop the blueprint on the board or confirm
the five names, closing decision 12. The owner confirmed the five names on 2026-09-15 (D-12); the mapping logic was never name-dependent and is unaffected.
Workstream zero — the P1 kickoff checklist (30-day plan ∪ P1)
Master §3.3 rules that the blueprint's 30-day plan is P1 workstream zero. The blueprint text is not on the board (above), so the checklist below is derived from the P1 definition in the master and the F6 kickoff scope in INTEGRATION PROMPT v2.3; items that the 30-day plan may add are marked. Owner decision 13 (30-day plan wholesale vs. triaged into P1) stays open.
- [ ] Shopify app scaffold — OAuth with minimum protected-customer-data scopes;
orders/*,refunds/*,inventory_levels/*,fulfillments/*webhooks; bulk-operation backfill. (Boundary hardening already merged on the gateway: replay-cache dedupe, GDPR-topic ACK-never-ingest, fail-closed consent gate — PR #654 / merge59782a39; webhook flow itself remains blocked on operator secrets, register item 6. Webhooks + bulk backfill are built; the multi-merchant OAuth install flow is the open half —P1_BUILD_PLAN.md§C4, design note first.) - [x] Canonical Event Envelope mapping for every app stream — no Shopify-special data model.
(Built for the gateway streams —
_shopify_record→ canonical ingestion; the per-topic fulfillments field review remains,P1_BUILD_PLAN.md§C5.) - [x] NCM-v1 metric-contract service — versioned per master §2.5; dashboards, covenants, and
CAPI feeds pin the version. (
services/measurement-rails/ncm_v1.py, frozen term set.) - [x] CAPI / Conversion-Value-Rules value-feed skeleton — feeds ship OFF until L1's
14-day clean reconciliation passes. (Rails pre-existing flag-off; the L1 gate is
ncm_value_feed.pywith the OFF default test-asserted at the source literal; the attestation instrument isreconciliation.py. Wiring =P1_BUILD_PLAN.md§C3.) - [x] COGS onboarding worksheet (per-variant landed COGS, bundle-decomposed; 3PL pick/pack;
gateway fees; return-processing costs) for ERP-less merchants.
(
docs/onboarding/COGS_WORKSHEET.md+ template CSV; validated importcogs_import.py.) - [ ] L0 observe posture wired end to end — recommendations + reasoning paths only; no spend authority anywhere in workstream zero.
- D-13 ruled 2026-09-15: triaged into P1; nothing wholesale — blueprint 30-day-plan items beyond the above are triaged row-by-row into P1 as they surface, never imported wholesale (owner ruling 2026-09-15,
docs/reports/OWNER_RULINGS_2026-09-15_REGISTER_CLOSEOUT.md).
P1 kickoff (F6) opens only after F1+F2 land, on a branch per repo conventions; it is deliberately not part of the F1–F5/F7/F8 report gate.
Stage 1–4 deployment benchmarks bound into P1/P2 exits (F8.2)
The per-customer deployment clock (overview §5, sourced from the capabilities documentation) nests inside P1–P2: a design partner's Stage 1–3 is exactly the P1→P2 exit-criteria path. Binding, per stage:
| Deployment stage | Benchmark | Bound into |
|---|---|---|
| Stage 1 Sense & See (wks 0–6) | ≥80% identity/attribution coverage | P1 exit precondition per partner — a partner below 80% coverage does not count toward the 10-partner reconciliation exit |
| Stage 2 Score & Explain (6–12) | Model promotion only at Brier ≤ 0.20 / AUC ≥ 0.72 / ≥2 purchase cycles (docs/architecture/DEL_AUTHORIZATION_FUNCTION.md) |
P1→P2 boundary — intent surfaces stay advisory below the bar |
| Stage 3 Prove (8–16) | Refutation-passing iROAS with CI clearing the hurdle | P2 exit — this is the "first auditable incrementality artifact" |
| Stage 4 Act & Compound (Q2+) | Ledger-driven reallocation under 2-cycle revert rules | P2→P3 boundary — no reallocation authority without the Stage-3 artifact |
Owner decision 17 (open, flagged for the status report): whether Stage 1–4 benchmarks are contractual SLAs or internal targets. Until decided, every stage benchmark above is an internal target and must not appear in merchant-facing contract language.
Current build state (corrected 2026-08-12 — the previous "F6 not opened" line went stale the
hour it was written): F6 is opened; workstream zero landed the NCM-v1 contract
(ncm_v1.py), the L1 value-feed gate (ncm_value_feed.py), the COGS worksheet, and the
follow-on session landed the validated COGS import (cogs_import.py) and the
Shopify-vs-tracked reconciliation harness (reconciliation.py) — live P1 state and remaining
steps: docs/roadmap/P1_BUILD_PLAN.md. The gateway boundary hardening is deployed with zero
live traffic (operator secrets, register item 6), and no merchant attestation exists yet — the
harness awaits real totals. The LII backtest is still short of the 0.72 promotion gate, but as of
2026-08-16 that shortfall is not a model verdict: 0.6884 was the offline fallback scorer on one
seed, and the fixture's oracle ceiling (0.7277 mean) puts 0.72 out of reach for ANY scorer on
synthetic data — real forward labels are the blocker (register item 17 → 6c/23;
docs/reports/LII_BACKTEST_MODEL_QUALITY_2026-08-16.md). The Stage-2 gate is exactly what this
is for.