Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 14 additions & 1 deletion docs/BUILD_LOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -392,4 +392,17 @@ Evidence: `docs/v0.3/ADR-009-DECISION-FUTURES.md`; updated PRD, thesis, research
- Added delayed AI-off transfer, longer-delay and field boundaries, privacy/minimization rules, ordered analysis, event contracts, and kill criteria that remove mechanisms when they do not add behavioral value.
- Grounded the design in current coding-skill and human-agency research without treating immediate quizzes, surveys, interviews, or target thresholds as product evidence.

Evidence: `docs/v0.3/R8_COMBINED_PILOT_PROTOCOL.md` and updated experiment/execution handoff documents. No participants were enrolled, no target was measured, and implementation remains gated by the complete R7 expert audit plus R5/R6 runtime.
Evidence: `docs/v0.3/R8_COMBINED_PILOT_PROTOCOL.md` and updated experiment/execution handoff documents. No participants were enrolled, no target was measured, and implementation remains gated by the complete R7 expert audit plus R5/R5.1/R5.2/R6 runtime.

## 2026-08-01 — Operator Projection / Dual Source hypothesis

- Identified the remaining category gap: Intent Ledger, Operator Model, and Decision Futures were individually specified but the repository still appeared to be the only source of truth for both agents and humans.
- Proposed ADR-010: agents maintain the complete Software Source while a pure Operator Projection renders immutable human commitments, decisions, invariants, control handles, and bounded control evidence for critical seams.
- Defined a one-way event algebra, stale-base/concurrency rules, forward agent obligations, reverse Operator Deltas, derived display states, no-self-certification laws, deterministic invalidation, and a participant projection that does not require maintaining a DSL or reading a full diff.
- Distinguished the proposal from Microsoft Programming with Representations, Apple Athena, bidirectional views, tests, AI-generated architecture graphs, and model-driven development.
- Added a matched representation pilot. Operator Source is removed from the product core if it does not improve causal localization per active minute over the existing Intent Ledger and Operator Model projection.
- Triaged current practitioner remedies—generation/explanation, random code questions, second-agent review, AI-free quotas, contract-first work, spaced repetition, and simplification—into comparators or bounded supporting tactics. Added causal checksum and maintenance escrow as executable adaptations rather than comprehension rituals.

An adversarial architecture review rejected a second mutable source and duplicate readiness state. The revised ADR makes “Dual Source” a falsifiable product metaphor over one event authority, separates stable node identity from immutable revision projections, keeps accountability failure off the production critical path, adds explicit R5.1/R5.2 runtime workstreams, and isolates live authority in R8 with matched prebuilt alternatives and separate speculative cost.

Evidence: `docs/v0.3/ADR-010-DUAL-SOURCE-OPERATOR-SOURCE.md` and synchronized PRD, thesis, research, experiment, completion-audit, and handoff documents. This is a proposed projection and experiment, not implementation or skill-preservation evidence; full R7 remains the entry gate.
9 changes: 5 additions & 4 deletions docs/PROJECT_STATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,8 @@ Branch `codex/shadow-cockpit-rnd` resets the product R&D thesis around **Dual-Co
- The preregistered R7 collector froze 30 eligible patches from six repositories after evaluating 457 bounded eligibility records. Manifest `a4ef6cbfa48c66cb9d384bcc2834ecbfae8ff08810abfd1863b395b8aa47d149` contains 12 development and 18 held-out patches; `docs/v0.3/results/R7_CORPUS_COLLECTION.md` reports repository and first-match exclusion counts. No compiler or human outcome influenced selection.
- The frozen R7 automatic audit passed its preregistered automatic threshold: 17/18 held-out identities compiled and 16/18 were valid end-to-end. The frozen blind expert packet set and deterministic rating join exist, but two independent ratings and adjudication remain pending. Full R7 has not passed; R5/R6 stay gated.
- ADR-007 proposes an Executable Operator Model and shadow-control protocol. ADR-008 adds a bidirectional Intent Ledger for artifact accountability. ADR-009 adds Decision Futures and a Takeover Envelope so an on-time pre-reveal human commitment can determine a live integrated branch while agents retain implementation. Together they cover artifact accountability, demonstrated control, and real decision authority; none is implementation evidence.
- `docs/v0.3/R8_COMBINED_PILOT_PROTOCOL.md` now defines the draft four-condition human study needed to test the combined architecture against ordinary autonomous use and a fixed active-review comparator. It has no participants or measured outcomes and cannot be frozen until full R7 and the R5/R6 runtime exist.
- ADR-010 proposes Dual Source only as a falsifiable product metaphor: agents maintain the complete Software Source while a pure, sparse Operator Projection renders immutable human commitments and bounded control evidence. It owns no state or readiness authority and must beat the existing representation in a matched pilot before becoming core.
- `docs/v0.3/R8_COMBINED_PILOT_PROTOCOL.md` now defines the draft four-condition human study needed to test the combined architecture against ordinary autonomous use and a fixed active-review comparator. It has no participants or measured outcomes and cannot be frozen until full R7 and the R5/R5.1/R5.2/R6 runtime exist.
- `GOAL_COMPLETION_AUDIT.md` maps the original product goal to current evidence. It explicitly records that the live agent plane, v0.3 cockpit, cold relay, delayed-transfer study, and skill-preservation claim remain incomplete.
- The readiness ledger and v0.3 cockpit do not exist yet. R0–R4.5 remain a closed reviewed-fixture mechanism and do not execute arbitrary participant or workspace code.
- No skill-retention or speed metric has been measured. Values in the PRD are predeclared R&D targets.
Expand Down Expand Up @@ -156,9 +157,9 @@ No external input blocks the repository-owned fixture R0–R4.5 mechanism in `do
## Next ordered actions

1. Obtain and adjudicate two independent blind expert ratings for packet index `54d78382b3ddbe15cba1f8153275e8149d32ddaa5192163f99ca5f43d903e8fe`.
2. If full R7 passes, review ADR-007, ADR-008, ADR-009, and the R8 combined protocol together, then freeze the Operator Model, Intent Ledger, Decision Future, and Takeover Envelope schemas, hash domains, projections, evidence authorities, timing policy, selector ablations, and four-condition study contrasts before implementation.
3. Add the local readiness ledger and minimal cockpit only after the complete R7 expert gate passes.
4. Freeze and run the four-condition delayed-transfer pilot only after the technical runtime can instantiate every condition; run the longitudinal field pilot before making a sustained skill-retention claim.
2. If full R7 passes, review ADR-007–010 and the R8 combined protocol together, then freeze the baseline ledger/model schemas and one offline Operator Source prototype.
3. Implement the local R5 evidence ledger and run Experiment 2.5 with identical evidence in both projections; make Operator Source the R6 default only if it improves causal localization per active minute without increasing false confidence.
4. Build the minimal cockpit with the surviving projection, then freeze and run the four-condition delayed-transfer pilot; run the longitudinal field pilot before making a sustained skill-retention claim.

## Recent milestone commits

Expand Down
2 changes: 1 addition & 1 deletion docs/v0.3/ADR-009-DECISION-FUTURES.md
Original file line number Diff line number Diff line change
Expand Up @@ -407,7 +407,7 @@ Preserves autonomous implementation and unrelated progress while giving a small
This ADR does not authorize R5/R6 implementation. Before acceptance:

1. complete and adjudicate the two-rater R7 expert audit;
2. review ADR-007, ADR-008, and ADR-009 as one architecture;
2. review ADR-007–010 as one architecture and either accept Operator Source as their shared projection or remove the extra abstraction;
3. freeze Decision Future projections, hash domains, alternative validity, deadline semantics, and integration authority in `CONTRACTS.md`;
4. compile one offline natural disagreement fixture with a false-fork negative control;
5. compare shadow-only and live-influence modes before expanding the cockpit;
Expand Down
Loading
Loading