Skeptical review pass over all closed decisions #33

Closed
opened 2026-08-02 15:24:37 +00:00 by christian · 1 comment
Owner

Task

A deliberate negative review of the twelve closed decisions, run before the code layout is drawn:
prove the concepts, hunt contradictions, check alignment. Recorded here so the findings survive.


Parent: #1

## Task A deliberate negative review of the twelve closed decisions, run before the code layout is drawn: prove the concepts, hunt contradictions, check alignment. Recorded here so the findings survive. --- Parent: #1
christian added the
wayfinder:task
wayfinder:ticket
labels 2026-08-02 15:24:37 +00:00
Author
Owner

Resolution

Twelve closed resolutions reviewed against each other and against the destination. Nothing
previously decided was reversed
— the decisions are individually sound and the through-lines
(tools not access; we establish facts, retailers make judgements; entitlement gates convenience,
never correctness
) hold up. What the pass found is interaction damage: places where two correct
decisions produce a wrong outcome together, and places where a decision handed a constraint to a
surface nobody is tracking.

Contradictions — ticketed

1. A taxonomy split silently un-qualifies every vendor on the node.
Category taxonomy decision 4 rescues matching through supersession while decision 3
forbids eligibility from deriving anything. After a split, eligibility rows point at a dead node and
the vendor vanishes from rule-defined audiences with no error — the exact silent degradation
decision 3 existed to prevent. ->
Resolve taxonomy supersession against eligibility exactness

2. Free vendors may be structurally unqualifiable.
The vault accrues eligibility from typed vault documents; entitlement gives free
vendors no vault; visibility makes eligibility the input to audiences. Both readings of a
free vendor's per-RFP upload break something, and one of them is entitlement gating retailer-facing
correctness, which the entitlement decision forbids in as many words. ->
Define the eligibility path for a vendor with no vault

Gaps — carried as constraints, not new decisions

3. RLS has at least two sanctioned bypasses and they are not enumerated. The anonymised
acceptance count reads other retailers' rows; the expiry scheduler runs with no actor at all. The
layout owes an explicit reviewable list of privileged paths, not just a hard-to-bypass entry point.
The k-floor is privileged code. Noted on tenancy, constraint added to data release.

4. criterion_requirement is authored, not extracted, and has no provenance. The mapping is
implicit in nearly every real RFP, so the confirmation surface asks the retailer to manufacture
structure the binding document does not contain — the one object with no span to point at. Needs its
own attribution, and ranking must visibly separate document-derived from human-authored structure.
Noted on the schema, carried to extraction confirmation and ranking.

5. The evaluation scenario is a disclosure decision. Publishing the volume basket up front is
required for price fairness; volume commitments are exactly what the optional acknowledgement gate
protects. Release timing unspecified. Carried to data release.

6. Win rate is the banned global rating in different clothes. Promoted to a standing guardrail
in the map's Notes rather than left to discipline.

7. The vault's per-category expiry consequence predates the taxonomy decision and must mean the
retailer-local category. Noted on the vault and the catalogue.

The extraction completeness hole, framed

Recorded as unfixed by the schema and now owned by extraction confirmation, with the
framing worked out: it is buyer-side; span coverage over the source document is the primary
mechanism and the schema already carries the spans; a second independent pass — not a re-run of
the same extractor — is what tightens the noise; vendor reports are a cheap but systematically
biased secondary detector; and it must not be sold as a paid vendor feature, because that
monetizes our own defect and does not reduce the retailer's exposure. The legitimate paid feature
next door is response completeness, which is a different thing.

The map-level finding

The destination is a code layout and no ticket produces it. Four resolutions have now handed
structural requirements to a layout that is not on the frontier and does not exist: a single
database entry point (tenancy), a scheduled-job entry point that establishes actor context
without a request (the vault), an entitlement assertion helper carrying the
convenience-not-correctness principle (entitlement), and the enumerated privileged-path list
(this pass).

Left as an open observation rather than a ticket, since it is arguably the terminal ticket the whole
map feeds and creating it now would put an unbuildable item on the frontier.

## Resolution Twelve closed resolutions reviewed against each other and against the destination. **Nothing previously decided was reversed** — the decisions are individually sound and the through-lines (*tools not access*; *we establish facts, retailers make judgements*; *entitlement gates convenience, never correctness*) hold up. What the pass found is interaction damage: places where two correct decisions produce a wrong outcome together, and places where a decision handed a constraint to a surface nobody is tracking. ### Contradictions — ticketed **1. A taxonomy split silently un-qualifies every vendor on the node.** [Category taxonomy](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/26) decision 4 rescues *matching* through supersession while decision 3 forbids eligibility from deriving anything. After a split, eligibility rows point at a dead node and the vendor vanishes from rule-defined audiences with no error — the exact silent degradation decision 3 existed to prevent. -> [Resolve taxonomy supersession against eligibility exactness](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/31) **2. Free vendors may be structurally unqualifiable.** [The vault](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/13) accrues eligibility from typed vault documents; [entitlement](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/20) gives free vendors no vault; [visibility](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/12) makes eligibility the input to audiences. Both readings of a free vendor's per-RFP upload break something, and one of them is entitlement gating retailer-facing correctness, which the entitlement decision forbids in as many words. -> [Define the eligibility path for a vendor with no vault](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/32) ### Gaps — carried as constraints, not new decisions **3. RLS has at least two sanctioned bypasses and they are not enumerated.** The anonymised acceptance count reads other retailers' rows; the expiry scheduler runs with no actor at all. The layout owes an explicit reviewable list of privileged paths, not just a hard-to-bypass entry point. The k-floor is privileged code. Noted on [tenancy](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/11), constraint added to [data release](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/14). **4. `criterion_requirement` is authored, not extracted, and has no provenance.** The mapping is implicit in nearly every real RFP, so the confirmation surface asks the retailer to manufacture structure the binding document does not contain — the one object with no span to point at. Needs its own attribution, and ranking must visibly separate document-derived from human-authored structure. Noted on [the schema](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/10), carried to [extraction confirmation](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/16) and [ranking](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/15). **5. The evaluation scenario is a disclosure decision.** Publishing the volume basket up front is required for price fairness; volume commitments are exactly what the optional acknowledgement gate protects. Release timing unspecified. Carried to [data release](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/14). **6. Win rate is the banned global rating in different clothes.** Promoted to a standing guardrail in the map's Notes rather than left to discipline. **7. The vault's per-category expiry consequence predates the taxonomy decision** and must mean the retailer-*local* category. Noted on [the vault](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/13) and [the catalogue](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/27). ### The extraction completeness hole, framed Recorded as unfixed by [the schema](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/10) and now owned by [extraction confirmation](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/16), with the framing worked out: it is **buyer-side**; span coverage over the source document is the primary mechanism and the schema already carries the spans; a second *independent* pass — not a re-run of the same extractor — is what tightens the noise; vendor reports are a cheap but systematically biased secondary detector; and it must **not** be sold as a paid vendor feature, because that monetizes our own defect and does not reduce the retailer's exposure. The legitimate paid feature next door is *response* completeness, which is a different thing. ### The map-level finding **The destination is a code layout and no ticket produces it.** Four resolutions have now handed structural requirements to a layout that is not on the frontier and does not exist: a single database entry point ([tenancy](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/11)), a scheduled-job entry point that establishes actor context without a request ([the vault](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/13)), an entitlement assertion helper carrying the convenience-not-correctness principle ([entitlement](https://gitea.stephenmann.io/christian/helmdocs-proposal-system/issues/20)), and the enumerated privileged-path list (this pass). Left as an open observation rather than a ticket, since it is arguably the terminal ticket the whole map feeds and creating it now would put an unbuildable item on the frontier.
christian referenced this issue from a commit 2026-08-03 21:21:06 +00:00
Sign in to join this conversation.
No description provided.