Sibyla Development Plan v5.0 — FDR + Claude CLI + Layer 5

GOTT Sibyla — project evolution

Generated 2026-08-05 (revised through Aug 7, 10:41 UTC — Pieces A, B and C all independently accepted; Piece D twice stopped honestly in TDD: D-M1 closed by Miguel's Option A amendment, D-M2 now decided as D-M2-A with its records commit pending; O5 preparation independently accepted after a three-pass review cycle and merged to main, leaving only Miguel's target-host session; and the development-time series re-measured from the Hermes session store — 52h00 of merged execution time since Aug 1) from git history, the FDR control log, and the backlog across both repositories. The roadmap was reissued on Aug 3 as Development Plan v5.0, merging the v4.0 backlog with the Fiscal Document Registry's Stage 8–10 work built in parallel by Luís Nascimento between Jul 30 and Aug 3. PostgreSQL mirrors the FDR layer 1–5 table model, single-document extraction runs on headless Claude CLI, and .NET remains the deterministic decision, persistence, and side-effect layer. Bank movements and reconciliation moved out of Phase 2 into Phase 1; ERP integrations and the management layer stay parked.

What is new in this revision — Aug 7, continued: Piece D reached TDD twice and stopped honestly twice; O5 preparation closed its whole review cycle; and the clock is finally measured, not estimated. Piece D: the first authorized TDD run stopped on D-M1 — PostgreSQL retains dropped attribute-number slots across Piece A's Down/Up, so the approved literal S1/S3 physical-ordinal equality is unsatisfiable by design, not by defect. Miguel closed it with the Option A amendment ("Aprovo a opção A e o mapping Piece D revisto", pushed at 6554a8e): physical ordinals become observed diagnostics, excluded only from S1/S3 logical equality, with the complete dynamic catalog oracle untouched. The fresh TDD attempt from that tip then delivered items 1–4 and the folded item-8 roster green with measured proof — the eight-file byte-identity check, the complete deterministic catalog snapshot, full logical S1==S3, exact logical+physical S0==S2, and zero non-control-plane direct DOCFLG writers — before item 6 stopped on a new collision, D-M2: for the only non-vacuous fixture (a valid ACTIVE-company row), the exhaustive Status partition proves the mapped native direct-UPDATE proof can never reach the composite FK — Open/InReview dies first on the accepted P1-1a lifecycle CHECK and every terminal mutation dies first on Piece C's accepted replacement trigger, all as 23514, while the tempting inactive-company 23503 is a wrong-object anti-vacuity trap. The run stopped rather than self-authorize, removed every transient edit byte-for-byte, and left no candidate. Miguel has since chosen D-M2-A — one atomic Open→terminal UPDATE satisfying every orthogonal prerequisite, asserting SQLSTATE 23503 and the exact constraint name — with the records commit and mapping re-approval pending, after which Piece D implementation resumes. O5 preparation: the candidate survived a full independent review cycle — REJECT #1 (inheritance conversion, PS5.1-fatal process-tree kill, egress-mechanism lifecycle, acceptance honesty, secret-store account matching), a self-found PS5.1 ArgumentList blocker that would have thrown on first real launch, REJECT #2 (password rotation, the per-job Claude CLI cache lifecycle, five Lows), a third-pass ACCEPT with 2 Lows, and a focused independent confirmation of those two fixes — ACCEPT, no findings. 91/91 Pester, analyzer clean, and an honest off-host battery (21 PASS / 17 HOST-SESSION / 1 BLOCKED-P1-2, zero FAIL). It was committed, merged into feature/p1-1b (a445478) and on into main (f1488ac). O5 itself stays open — only the target-host session closes it. The two open items are exactly D-M2's records commit and O5's host session; everything else on the board is decided.

Carried from the earlier Aug 7 revision — Piece D, the integration gate, went from go-ahead to an approved test plan — and the test-plan gate earned its keep twice more. The go-ahead (dated Aug 6, accepted in a three-path governed records commit) restated amendment 3's scope: no new migration content — Piece D proves Pieces A+B+C, run cumulatively on the accepted P1-1a catalog, byte-exact-invertible and complete (combined Up→Down→Up with post-Down equal to the accepted P1-1a catalog exactly), with item 8 turning the Piece C review's non-binding GUC observation into a tested invariant: a measured roster proving zero application/executor roles can reach direct DOCFLG DML, plus a reproduced owner-level bypass probe as the evidence of why that roster matters. The checklist→test mapping was then recorded — and was not ready: a fresh independent review found one Critical (item 2's pg_catalog snapshot had been narrowed to a curated seven-table list where the go-ahead demands the complete surface, dynamically enumerated), two High and two Medium/Low; a second review found four more (item 8's roster check double-counted as its own Fact instead of folding into item 3's single cumulative run; a second 52-row synthetic fixture the "exactly one exception" claim had missed; an overclaimed four-checks-in-one-test description; stale inventory arithmetic). Every finding was applied in place, and the corrected mapping reported two observations rather than resolving them silently: Observation 1 — item 5 ("the five real baselines, one run") is infeasible as written: no importer exists anywhere in the repo, Scope 1 has never run, and the only fixtures are authored synthetic counts that happen to match 119 and 52; Observation 2 — the checklist's "six accepted migration files" undercounts the measured roster, which is eight. Miguel decided both by name: Observation 1 option (b) — item 5 is formally carved out of Piece D's Accept and the real-population confirmation deferred to Scope 1, where those rows will actually exist, rejecting synthetic count theatre — and Observation 2's eight-file roster, with the Designer/ModelSnapshot sub-question explicitly out of scope. The approved inventory: 6 new tests + 1 helper, 2 strengthened, 7 regressions re-run, 14 verification commands, and honestly no test for item 5. Remaining: the approval's records commit, TDD implementation from the pushed approval tip, then the fresh integration-focused independent review — whose Accept is what finally authorizes the Scope 1 restart against pin b917685.

Carried from the late-night Aug 6 revision — Piece C, the governed commands, went from go-ahead to independently accepted inside one long Aug 6, surviving two honest stops on the way. The go-ahead (6880bbf) restated amendment 3's scope: AssignDOCEFLItemClass (O10-D2's atomic NULL-only snapshot completion) and the evidence-append command, plus exactly the roles and SECURITY DEFINER surface they need. The 20-item checklist→test mapping went through the gate with six observations reported rather than silently resolved, was corrected in a follow-up records commit after an independent review found three internal contract defects (item 8's collision with the byte-identical rule stated as impossible-as-written on either path; R6 completion made atomically all-or-nothing; R3's concurrency tests rebuilt around a real shared parent-row-lock protocol), and Miguel approved the corrected mapping — “aprovo mapping”, with the recorded, honestly-labelled interpretation that it adopts all six recommended resolutions, including the one narrow, explicitly waived CREATE OR REPLACE of RejectTerminalDOCFLGMutationFn. TDD then stopped the piece twice, correctly. Live disposable testing proved the accepted, untouchable RequireActiveCompanyRegistryFn also rejects a P11aCommandAudit row for an inactive company — making the approved inactive-company audit requirement structurally impossible without an unauthorized waiver. Everything uncommitted was deleted, the one touched tracked file restored byte-exactly, and the decision escalated instead of worked around. Miguel decided “Aprovo B” — amend the audit requirement, don't waive the accepted function: an inactive affected company is excluded before membership is even considered and never gets its own audit row; the calling company's audit row carries a fixed skippedInactiveCompanies array with per-company observed NULL counts; all-or-nothing authorization now ranges over active affected companies only. The implementation was then recreated from zero from the Option-B tip (fd9dbd9): 1 fail-closed role, 2 SECURITY DEFINER functions behind REVOKE ALL FROM PUBLIC, the one approved function replacement, and nothing else — 0 new tables, columns, triggers, constraints or indexes on any accepted object. TDD caught two real defects before review (a STORED GENERATED-column BEFORE-trigger comparison bug in the approved exception, and fragile query-text concurrency detection replaced with PID-scoped pg_stat_activity lock-wait polling). Measured: build 0/0, ordinary 646/646, focused 6/6, disposable PostgreSQL 17 55/55 reproduced twice. The fresh independent adversarial review of candidate ce983b2 reproduced every figure, traced all 20 items, ran eight original probes beyond the candidate's suite — a hostile pre-existing role failing Up atomically, an all-or-nothing authorization rollback, a direct exercise of the narrow-exception GUC mechanism (real, but unreachable: no role in the entire accepted schema history holds direct DOCFLG DML — recorded as a non-binding observation for Piece D), search_path and injection-surface reviews, and genuine two-connection concurrency re-reads — and recorded Accept: 0 Critical, 0 High, 0 Medium, 0 Low. Three pieces down, one to go: Piece D's integration gate seeks its go-ahead next, and Miguel has green-lit O5-prep to run in parallel on its disjoint surface.

Carried from the mid-Aug 6 revision — Aug 6 became the piece-decomposition day: Piece A is accepted, Piece B was rejected once on a real transactional defect, and its remediation is approved. After the third monolithic Reject, Miguel's pattern review landed as amendments 3, 4 and 5: the unchanged O9/O10 implementation is decomposed into four independently reviewed pieces; the prototype preflight is reformulated around snapshot integrity (checks 1–5 hard stops, live-tip divergence logged by hash without reading post-pin content); and three standing instruments are adopted — one exhaustive consolidated checklist per piece, the five-rule proof-pattern annex, and a test-plan gate requiring the checklist→test mapping to be recorded and approved by Miguel before any implementation code. The instruments promptly earned their keep. Piece A: candidate 6f86023d was rejected (0 Critical, 1 High, 2 Medium, 1 Low — Reject #1) and neutralized; amendment 5 bound the findings as A-R1…A-R4 and authorized attempt #2 as a remediation of the rejected candidate behind the test-plan gate; the 20-item mapping was recorded and approved with one named DOCFLG widening; attempt #2 applied exactly that and nothing else — build 0 warnings, ordinary 637/637, focused 37/37, disposable PostgreSQL 16/16 — and the fresh independent re-review recorded Accept: 0 Critical, 0 High, 0 Medium, 0 Low. Piece A has an accepted implementation. Piece B: Miguel's go-ahead scoped it to RegistryFieldProvenance alone; its 20-item mapping was recorded and approved verbatim ("Aprovo o mapping de Piece B e ambas as resoluções propostas"); it was implemented from zero — 9 columns including two STORED GENERATED discriminators, 7 triggers, 3 trigger functions; ordinary 640/640, focused 3/3, disposable 27/27, accepted migrations byte-identical — and the first independent adversarial review returned Reject #1: 0 Critical, 1 High, binding finding B-R1, proven empirically on a live disposable PostgreSQL 17: the target-side re-check trigger and the provenance-side trigger are both immediate, so neither statement ordering of a legitimate value/provenance co-update can ever succeed — the only working sequence exploits an undocumented delete-update-insert validation gap, which would have broken Piece C's O10-D2 assignment command the day it was built. Candidate b8fa033 is neutralized byte-for-byte. The B-R1 remediation mapping followed on the record: split company agreement (kept immediate) from absent/value agreement, re-implemented as DEFERRABLE INITIALLY DEFERRED constraint triggers that re-query live state at COMMIT, so both natural orderings succeed while any unaccompanied one-sided change still fails closed at commit; eight new disposable tests (both orderings × DOCEFL/DOCFLG, both one-sided negatives, and a direct two-UPDATE-only assertion that no test relies on the rejected gap); all 19 Pass rows carried forward as regression requirements. Miguel approved the mapping — Observation R-1 resolved as option (b), both orderings must succeed; Observation R-2 accepted (recorded at 1627dd6, which also repaired an inverted-wording defect in PROJECT-STATE.md's not-authorized list). The remediation was then implemented the same evening as commit 7059809 — a remediation of rejected b8fa033, applying exactly the approved diff: the item-5/item-7 split (RequireCompanyAgreementFn kept immediate; RequireProvenanceAgreesWithTargetFn redesigned to re-query live state at COMMIT behind three DEFERRABLE INITIALLY DEFERRED constraint triggers), R1a–R1g, the item-16 reshape, the item-20 design-note correction, and the widened 8-trigger/4-function roster — build 0 warnings, ordinary 640/640, focused 3/3, disposable PostgreSQL 17 34/34 (16 Piece A + 18 Piece B), accepted P1-1a and Piece A migrations byte-identical, WaiveDOCFLG byte-identical, Up/Down/Up stable, 0 residual containers. The fresh independent adversarial review — the second and final Piece B attempt — recorded Accept: 0 Critical, 0 High, 0 Medium, 0 Low (256da9c): B-R1 was re-verified genuinely fixed via live pg_trigger deferred/immediate timing measurement and six original adversarial probe transactions beyond the candidate's own suite (both statement orderings, a same-transaction duplicate-firing toggle, the previously exploited no-provenance window now failing closed, the delete-update-insert sequence remaining valid but unneeded, genuinely immediate company agreement, and a combined move-plus-value-change scenario), all six passing on first run; every Reject #1 Pass row still holds and all 20 checklist items dispose Pass. Piece B now has an accepted implementation; per amendment 3, Piece C — the governed commands — may seek its own go-ahead. Piece D and Scope 1 remain gated; baselines 119 / 119 / 52 / 221 / 2,787, pin b917685, and every O8/O9/O10 decision are unchanged; O5-prep stays deferred by decision, and O5 remains the only other open project item.

Carried from the Aug 5 revision: the first schema code of Phase 1 landed on Aug 5. Commit e2f4c2afeat(persistence): implement P1-1a registry schema — put 9,665 insertions across 18 files on feature/p1-0d-follow-up and pushed it: one regeneratable migration 20260805180000_P11aFdrSchema, the governed registry commands, the ported identity-stability verifier, synthetic fixtures, and a disposable-PostgreSQL acceptance suite. Build is clean at zero warnings; 601/601 normal tests pass and 9/9 database tests pass against a throwaway PostgreSQL 17 cluster that the runner destroys in finally. Measured wall time from first verifiable implementation step to push: 2h55 (14:13:55 → 17:08:56 UTC). One deliverable of two is done. Deliverable 2 — the validation service — was explicitly scope-blocked in the commit message for want of Scripts/validate_registry.py. Later on Aug 5 that diagnosis was overturned: the script has never existed. It is absent from pin 9359c67, from the prototype's entire fetched git history, and from the prototype machine's filesystem including backups; the prototype's own skill review (roadmap line 120) independently found it described in five places in SKILL.md as a live, hard-fail pipeline gate that was never written — the registry never once ran the validation gate it believed it had. This is a P1-0c-class category error, not a mechanical clone block. Amendment 1 (docs/AGENT-PROMPT-v5-P1-1a-d2-amendment-1.md) replaces the source gate with the documented check set — the project-todo.md validation-service item with its C9 scoping and CaptureQuality decisions, the orphan-DOCLOG and (Filename, EntryCode)↔LGCode checks, the prototype SKILL.md §15/§10/§7/§5 at the pin, and p1-0-vocabularies.md — lifts the reconstruction prohibition it was written under, and keeps stop-and-report wherever the sources are silent. The assignment still carries the seed-completeness assertion P1-0e handed forward. By end of day the amended assignment had executed: deliverable 2 is implemented and verified in the working tree — sixteen checks with per-check source citation in docs/p1-1a-d2-status.md, hardened through two adversarial review rounds (the second, proc_06a923bbda7a, tied authorization to the application principal — sub/NameIdentifier → active UserProfile → active Membership → active CompanyRegistry — proved cross-company isolation even under a shared database role, and ran PostgreSQL through a non-owner role holding only the eleven SELECTs the snapshot source needs). Verification: 28/28 focused, 629/629 unit, 10/10 disposable-PostgreSQL, 0 warnings, 0 residual containers. The closure then executed the same evening: deliverable 2 was committed and pushed as 719407cfeat(validation): implement P1-1a registry checks, 20:58 UTC — and a single closure commit 74d8635 (21:22 UTC, one parent, no history rewrite, clean 7-line body with no literal \n defect) corrected the four records: p1-1a-status.md's stale denial of the e2f4c2a commit/push, PROJECT-STATE.md's O6 row and changelog, project-todo.md's three validation-service items, and p1-1a-d2-status.md's final state. Local, upstream and remote SHAs agree; working tree clean; final verification immediately before the commit: 28/28 focused, 629/629 ordinary, 10/10 disposable-PostgreSQL, 0 warnings, 0 residual containers. O6 is closed. One successor item was opened: O7 — the CaptureQuality nullable-with-default versus backfill rule — Miguel-owned and explicitly non-blocking. P1-1a is now code-complete on both deliverables and awaits only independent review/sign-off; everything data-bearing (live reference import, 2026 history, seeding, the hash-index swap, BRCode issuance) is P1-1b.

Deployed the same evening. Under Miguel's explicit operational authorization, the P1-1a branch reached main (the closure commit 74d8635 is confirmed an ancestor of origin/main) and the stack was deployed live: binary version 601ec77 across Sibyla.Api, Web, Worker and the PDF helper, with live appsettings, logs, IIS and service configuration preserved. Pre-deploy verification re-ran clean — Release tests 629/629, disposable-PostgreSQL runner 10/10, 0 residual containers, -WhatIf before the real copy. The startup migrator applied 20260805180000_P11aFdrSchema to the live database — the 66 P1-1a tables now exist live, deliberately empty: 0 reference/history rows imported, 0 command-audit rows. Health is green (live/ready/info 200, unauthenticated 401, OIDC redirect with ui_locales=pt and state present; 0 relevant event-log or runtime errors; live binary hashes match the published artifacts). Rollback is staged and verified: application and IIS backups plus a pre-deploy PostgreSQL dump (SHA-256 recorded, pg_restore --list clean) under the approved SibylaBackups hierarchy. P1-1a acceptance was explicitly not declared by the deployment, and no authenticated business flow was exercised — that verification remains manual.

And then, before midnight, the acceptance itself: P1-1a is independently accepted with notes. A fresh on-machine review session (Apolo), working from docs/AGENT-PROMPT-v5-P1-1a-review.md and explicitly not using the remote pre-review as evidence, re-derived the whole set: build 0/0 in 27.8 s, ordinary suite 629/629, focused validator 28/28, disposable PostgreSQL 17 10/10, 0 residual containers, clean worktree after. The structural review verified the decoy-survives-Down test, the forged-GUC denial, receipt-gated purge, and gap-burning allocation with line-level citations; all sixteen validation checks were re-derived against their pinned sources, confirming the C9 scope feeds exactly three checks and the warning set is exactly the specified three. No blocking findings. Of the remote pre-review's advisories, A1/A3/A4/A5 were confirmed as accepted advisories and A2 was dismissed with pinned evidence — the prototype's uniqueness assertions use exact-string set semantics, so Ordinal is the faithful implementation. The two-commit closure topology was accepted as disclosed. The verdict rides in docs/p1-1a-signoff.md (f435813, merged as e13f702); PROJECT-STATE.md now reads “P1-1a accepted on 2026-08-05” with the acceptance-limits sentence intact: it does not authorize P1-1b imports, further shared-database migration, production while O5 is open, or the O7 decision. The feature branch was merged to main and its remote ref deleted; P1-1a's chapter is closed end to end — specified, built, adversarially reviewed, closed on the record, deployed, and independently accepted, all inside one day.

P1-1b then started — and stopped exactly where its discipline required. On feature/p1-1b off accepted main, the records stage (536eeac) committed the authorization prompt, closed O7 prospectively (historical rows keep honest NULL CaptureQuality with absent provenance and produce no finding; new captures must supply it; only non-imported missing values warn), recorded Luís's relayed stability confirmation, and took the fresh read-only pin 06825b5 with a complete 48-blob source roster — metadata only, no blob opened. Scope 1's mandatory preflight then read exactly one rostered blob, entbnk.json, and measured what C8 predicted: 48 rows, 43 distinct (CodeName, Company) keys, five duplicate pairs, ten rows — the same five pairs C8 assigned to Luís on Aug 4, still unmerged. C8 literally mandates the import fail closed until they are merged at source, so Scope 1 stopped before any importer, migration, database or container work (2b8c708); an independent review round refined the records (f86b912), and the unchanged baseline was re-verified: build 0/0, 629/629, focused 28/28, secret-scan 0, 0 residual containers. No count was copied into the repository; the evidence is counts-only. The resume condition was one source action: merge the five pairs keeping both Flag notes and the natural key — then a records amendment pins anew and Scope 1 restarts its preflight. This is the C8 restraint paying for itself: the defect was caught by a one-second read at the gate, not halfway through a live import. The whole run — Git preflight 22:51 UTC, branch 22:54, records commit 23:00, C8-stop record 23:05, review corrections 23:14, final independent review and remote verification ≈23:17 — was about 26 minutes of active work.

Earlier on Aug 6 — O9 closed on the record, and historical conformance gaps stopped being blockers. Miguel's amendment docs/AGENT-PROMPT-v5-P1-1b-o9-amendment.md (Aug 6) records five governed decisions plus one standing policy. O9-P splits import findings into two permanent classes: identity-class violations — permanent-code conflicts, unknown vocabulary literals, natural-key collisions, roster drift — keep their exact fail-closed semantics, while completeness-class gaps on imported historical rows import as honest SQL NULL with absent provenance and are measured as named data-quality findings to work down over time, never Scope 1 stops. The five decisions apply that split: O9-D1 — the provenance register misdeclared ENTMST.DirectDebit a source column (a P1-0c-class register defect); it becomes target-only nullable, 119 honest NULLs. O9-D2TaxIdVerificationStatus mirrors O7: nullable, NULL on the 119 historical rows, mandatory at creation for Sibyla-era rows, validator warning scoped to non-imported rows. O9-D3DOCEFL.ItemClass becomes nullable; the 52 imported rows carry NULL and assignment happens over time through a governed, audited command restricted to the closed D8 vocabulary. O9-D4 — the normative annex table wins: the accepted five-literal ReviewPriority CHECK is completed to the six exact literals including Routine, and the two pinned rows import verbatim. O9-D5 — the terminal-state ResolutionEvidence CHECK is re-scoped to non-imported rows; the 221 historical terminal rows stay honestly absent, enrichable later by governed append. All of it lands in one additive corrective migration (P11bImportContractAlignment, TDD-first, the accepted P1-1a migration untouched), after which Scope 1 restarts at its preflight against the unchanged pin b917685 and the five counts — 119 / 119 / 52 / 2 / 221 — become expected baselines (the four completeness findings are 119 / 119 / 52 / 221). Nothing is invented: absence stays absent. The governed records commit is complete; migration, validator scoping, and restart remain pending, so no implementation or import result is claimed.

Earlier state — step 3 was independently rejected and neutralized, which opened O10. O9-P and O9-D1…D5 remained governed and closed, and the four 119 / 119 / 52 / 221 data-quality improvements remained non-blocking. Independent review returned Reject on pushed commit b324a3e. A normal branch-tip stop commit neutralized all 13 code, test, and migration paths back to parent 6e18e1c; no reset, amend, force push, history rewrite, or reversal of the governed records occurred. The review exposed the O10 contract gate: O9-D3 requires all 52 imported DOCEFL ItemClass values to be honest NULL/absent while accepted S2 had required every DOCFLG instance to retain a non-null snapshot through the composite FK (EFCode, ItemClass, ReviewPriority, BlockingLevel). The Reject blockers were High — that contract impossibility, caller-controlled GUC command bypass with an owner-only test boundary, and a weak non-company-scoped ImportEvidenceRow predicate inside a CHECK — and Medium — Down/Up constraint-name drift and an imported unknown non-null ItemClass validator escape. Green build and tests were insufficient semantic proof. No migration/import/live action ran outside disposable tests, and no acceptance, deployment, import, or reconciliation claim was made.

O10 foundation — governed records are closed; the fresh reviewed reimplementation is pending. Miguel's amendment docs/AGENT-PROMPT-v5-P1-1b-o10-amendment.md (Aug 6) resolves the contract impossibility the review exposed, on the same principle O9 established: O10-D1 — absence snapshots as absence. DOCFLG snapshot ItemClass becomes nullable; every imported instance whose parent rule is unassigned imports with an honest NULL/absent snapshot; the accepted composite FK stays declared and self-scopes under SQL MATCH SIMPLE (a row with any NULL member is not checked), a plain FK on EFCode keeps instance→rule linkage enforced for every row, and a prospective CHECK requires all snapshot members non-null on every non-imported instance — so Sibyla-era detections are fully enforced while history stays honest. This adds a fifth named completeness finding, DOCFLG snapshot ItemClass absent, expected baseline 2,787. O10-D2 makes the governed assignment command complete absent snapshots in the same atomic audited operation (NULL → assigned value, absentauthored) and forbids it from ever modifying a non-null snapshot; the audit states the rule, value, actor, and exact completion count, and the finding shrinks by exactly that count. The five review findings are now binding remediation requirements with per-item test evidence: the O10 contract cases, server-side principal only with non-owner-role and forged-GUC denial tests, a company-scoped strong-identity ImportEvidenceRow predicate, Up/Down/Up cycle integrity, and an identity-class vocabulary gate on every row. The reimplementation must start fresh from the stop-record tip — b324a3e remains neutralized evidence, never code to resurrect — and pass a mandatory independent review gate with a recorded Accept verdict before Scope 1 restarts. This records stage implements none of it. O5 is the only open project item.

Earlier on Aug 6 — the third O10 implementation was rejected and neutralized; monolithic reattempts stopped (since superseded by the piece decomposition above). Fresh independent review of pushed candidate 7ea6c0f returned Reject: 0 Critical, 2 High, 4 Medium, 1 Low. Provenance cardinality/value/hash integrity was bypassable, accepted waiver could leave contradictory provenance, and global assignment crossed the authenticated company boundary; the validator could not reproduce the governed ENTMST population, the required real NULL round trip and exact catalog proof were incomplete, and generated columns were absent from the EF model semantics. All 15 implementation paths are restored byte-for-byte to records parent 01c92cb. O9/O10 decisions and the 119 / 119 / 52 / 221 / 2,787 baselines remain closed and unchanged. Amendment 2 now stops all further reimplementation pending Miguel. Scope 1 and Scopes 2–8 have not started; O5 remains the only open project item, while this Reject is a phase gate rather than a reopened decision.

Earlier on Aug 6 — O8 closed, and Scope 1 stopped at O9 before TDD. O8-D1 fixes the governed source manifest at all 52 rows, EF0000001EF0000052: source EF0000046 remains the visual-read rule, while the never-used authored Monthly-gap rule moves once to verified-free EF0000053 and remains inactive behind governed activation. O8-D2 explicitly excludes the uncoded twentieth source DOCTYP row, Bank Statement | External | Exclude; the import manifest remains 19, and the authored Include | ArchiveOnly target rule is unchanged. The restarted preflight passed the repository, 49/49 roster, 48-file surface, C8, C13, EF-code and 20/1/19 DOCTYP controls, then the accepted import-contract comparison found exactly five sanitized contradictions: 119 ENTMST rows lack declared source/non-null DirectDebit; 119 have no governed value for production/non-null TaxIdVerificationStatus; all 52 source DOCEFL rows lack governed target-only ItemClass; the vocabulary annex showed six ReviewPriority literals in its table but named five in prose (now corrected), while the accepted five-literal CHECK still rejects the table-derived sixth literal used by two source rows; and 221 terminal DOCFLG rows honestly lack ResolutionEvidence required non-blank by the accepted CHECK. O9 opened as the Miguel-owned stop — since decided by the amendment above. No importer, source, fixture, test or migration changed; no import, container, or database work ran; Scopes 2–8 remain unstarted. The accepted P1-1a migration stays immutable, and its historical synthetic fixture still proves the old Monthly-gap EF0000046; P1-1b must update or replace that fixture and its tests for EF0000053 before seeding.

Carried from the previous revision: P1-1a's prompt was audited before hand-off. It predated P1-0d and P1-0e, so it carried none of their specifics — most dangerously a removal: MatchGroupID’s CodeLedger bucket came out of ledger scope when A3 was resolved, and an implementer reading the older draft would recreate it without noticing. An implementation index was added to docs/AGENT-PROMPT-v5-P1-1.md covering that removal, the BRCode alternate key, the new DOCEFL/BNKMAT nullability with its explicit NULLS NOT DISTINCT, the RequireRunnableActiveDecisionDOCEFL CHECK and ActivateDOCEFLRule command, and one residual P1-0e leaves behind — nullable columns can no longer catch an import that silently drops a value on the 45 imported rules, so the validation service now owes a seed-completeness assertion. P1-0 and its P1-0e follow-up are closed. The four-item carve-out that survived acceptance — C9, C11, C12, C15 — was closed on Aug 5 by P1-0d, after P1-0c stopped at its own source gate. The stop was correct against its instructions and wrong against the project: three of the six values it was told to extract verbatim are rows that the deciding corrections create, so no earlier pin could hold them. P1-0d replaced the blanket gate with per-field provenanceextracted, authored, absent — transcribed the 19 DOCTYP tuples, the 45 existing DOCEFL rows and the two ITMCLS codes from the pin with blob SHAs, authored EF0000000, EF0000046 and BT000012, and resolved A3 by measurement instead of extraction. P1-0e then made the authored rows insertable without invented values: 29 previously forbidden cells are honest NULLs and BT000012.RequiresReview is authored Yes; EF0000046 seeds inactive behind governed atomic activation. At that point O5 was the only open item on the whole project; O6 was opened on Aug 5 when the validation service was scope-blocked.

Superseded P1-0b snapshot: the P1-0 design freeze was delivered on Aug 4 — six normative drafts and an AGENTS.md rewrite — and then reviewed against the pinned prototype rather than accepted on its face. The review found 19 blocking defects, ten of them proven to fail on counted rows at import. On Aug 5 the correction pass P1-0b applied all nineteen to the drafts themselves: fifteen were fully closed — C3's open half was decided the same day — and four (C9, C11, C12, C15) landed structurally but were then unseeded for want of row-level data recorded in the repository. At that moment P1-0 could not yet be signed off because of the missing-seed problem; P1-0d subsequently closed it under per-field provenance, and P1-0e closed the nullability/activation follow-up. The flow diagram was reissued as v14, rebuilt against the freeze.

v5.0 backlog progress
21%
24 of 113 live items — P1-0 closed Aug 5 (16 items); P1-1a's migration train and its three validation-service items landed the same day; 22 more have a working FDR reference to port
Current phase
P1-1b
Pieces A and B both independently accepted 0/0/0/0 — Piece B's B-R1 remediation (deferred constraint triggers, both co-update orderings) was implemented as 7059809 and accepted at 256da9c on the second and final attempt; the O8/O9/O10 records stay closed; Piece C is independently accepted; Piece D's go-ahead and test plan are approved and its TDD has stopped honestly twice — D-M1 closed by the Option A amendment, D-M2 decided as D-M2-A with records pending — after which the integration review and then the Scope 1 restart against pin b917685 follow. No import or database work outside disposable tests has run
Scope change v4.0 → v5.0
+45%
78 → 113 live P1 items; 10 → 14 phases (recounted from both backlogs — supersedes the 79 → 133 figure shown earlier)
Sibyla commits
195
On main as of Aug 7, 10:31 UTC (every side branch is fully merged). 113 of them landed Aug 3–7 (author dates UTC): 34 on Aug 5 — the P1-0→P1-1a arc — then 61 on Aug 6 alone, the repository's busiest day ever: the full amendments 3–5 piece cycle, Pieces A, B and C from rejects to independently accepted implementations; Aug 7's 10 carry the Piece D test-plan approval, the Option A amendment, the D-M2 stop record, the accepted O5-prep candidate, and the merges closing at f1488ac
FDR rounds Jul 30 – Aug 3
47
Stage 8 R2–R14, Stage 9 R1–R9, Stage 10 R1–R6 — 13 passes on Aug 3 alone
Correction outcome
19 / 19
All closed — the last four seeded by P1-0d on Aug 5; ~40 residual triaged A/B/C and deferred

Three tracks back this project: GOTT.Sibyla (orchestration, extraction, integration — Miguel Teixeira), GOTT.IdentityServer (OIDC/OAuth login — Miguel Teixeira), and the Invoice Skill Build / FDR prototype (Luís Nascimento), which is where the domain model and the corpus-validated rules are proven before they are ported. All three are detailed below.

What changed in v5.0 — three decisions and a scope move

Decision D1 — architecture
DOCRQE is a persisted queue, not a live view. v4.0 specified it as a recomputed severity-tiered view, "never a capture-forward snapshot." Stage 9 R7 converted it to a persisted table with permanent ReviewIDs, never-delete semantics, and decision state that survives a full pipeline rerun. v5.0 adopts the persisted model: a live view cannot carry a ReviewID for a decision engine to cite, and cannot record that a rejected proposal must never be re-proposed. Severity tiering survives as ordering. The same model governs RECREV.
Decision D2 — data · CLOSED Aug 4
The real issue is identity, and it appears three times. Settling the natural keys is what gates the schema freeze. This decision was published as an LGCode data-cleanup blocker; that framing was wrong twice over and is corrected here. Luís took the rows apart on Aug 3 and found three populations, not one: 89 retired identities (P/F/O EntryCode is a per-period sequence, so re-ingesting an overlapping statement regenerates existing rows under new numbers), 18 future-dated loan-schedule rows correctly removed, and 27 rows carrying a real €142,835.50 gap — 2026 Jan–Jun payroll had no FDCHDR row at all, since the cash was matched to a ledger reference rather than a document. He rebuilt those entries the same morning. A blanket delete, which the original decision proposed, would have erased the only surviving trace of it. Underneath sit three unstable code families — P/F/O EntryCode, LGCode (assigned per placeholder filename), and PAYCODE/RCVCODE (reassigned on every rebuild). All three are now closed. Luís fixed them overnight on 3–4 Aug: BMCode's key had SourceFile in it, a field the pipeline deliberately rewrites in place, so it was dropped and the generated documents re-anchored on the movement's natural key — proven by renumbering all 1,960 BMCodes and changing every SourceFile, after which 426 of 426 generated documents re-anchored with zero duplicates, where the old rule would have silently regenerated €639,943.78. LGCode was re-keyed on (Filename, EntryCode), issuing 512 fresh codes and migrating DOCFLG's 509 references in one transaction, so 1,475 DOCLOG rows now carry 1,475 distinct codes. And a stability check now runs every pass that shuffles rows, blanks every code and reassigns from the ledger alone: nothing moves — 0 of 481 PAYCODEs, 0 of 245 RCVCODEs, 0 of 1,960 BMCodes. The .NET side inherits proven keys instead of inventing them.
Decision D3 — scope
FDR Layer 5 moved into Phase 1. Bank movements, reconciliation, and the RECREV queue are no longer parked. The prototype is materially further along than v4.0 assumed, and keeping it in Phase 2 would fork the queue model, the flag machinery, and the review UI between the document side and the bank side. It brings a minimum slice of Layer 6 with it — PAYCTR/RCVCTR supply ground truth to the matchers and cannot be separated — and it moves go-live out. ENTBLC balances, aging, and payment-priority views stay in Phase 2.
Decisions D4–D9 — taken Aug 4
With the identity problem closed, four decisions were outstanding and all are now taken. D4 — import the full 2026 history as opening balances plus the complete reference layer; 2025 stays out under the scope rule, which leaves the Toorist related-party position uncloseable across years as a known bounded gap. D5 — Reference Only becomes a first-class document state: captured, archived and searchable, but issued no EntryCode by design so it cannot reach balances, aging or the matchers. Deliberately not folded into Discard, because discard means junk and these are evidence. D6 — "reconciled is not recorded" gets its own BNKMAT match status, excluded from the reconciliation percentage. Chosen over a flag on an otherwise-Matched row because a separate status makes the movement impossible to count as clean by construction, rather than relying on whoever reads the metric to filter. D7 — grandfathered blocking flags import with their DetectedAt and prospective enforcement is honoured, so the 29 open blocking instances stay visible without manufacturing a go-live queue. D8 — ItemClass is frozen at Decision / Status / Annotation as a closed enumeration: every detector must declare which of the three it emits, and a fourth class later is a migration — friction that is the point, since it is what stops a phantom backlog re-forming. D9 — recurring payment-control imports are additive and keyed by period, so re-importing a period replaces only that period; the prototype's single hardcoded filename left the next period's file with no ingestion path at all.

Also corrected in v5.0, from drift accumulated between Jul 29 and Aug 3: MNGAPLMNGACC; DOCTYPEDOCTYP (Luís truncated it to the project's standard six-character table code on Aug 2); the history-import estimate from "826+ headers" to 1,096; COCACC and DOCFLG added to the P1-0 table roster; and the reconciliation baseline from 93.8% to 91.8% — 13 wrong matches were removed by a new eligibility gate, so the earlier figure was partly counting mistakes as successes.

P1-0 design freeze — delivered Aug 4, corrected Aug 5, accepted Aug 5

The .NET repository moved for the first time since Jul 29, and what it produced is the design freeze itself: six normative drafts, ~1,700 lines, plus an AGENTS.md rewrite that binds every future session to v5.0. The prototype was inspected read-only at a pinned SHA (9359c67c) and no prototype data was copied. All changes are documentation; no src, no migrations, no schema.

DraftWhat it settles
p1-0-claude-extraction-contract.mdThe single-document proposal contract. Claude returns proposals only; intake Document and ExtractionAttempt may persist first, but strict deterministic validation is atomic and precedes every extraction-derived projection. Seeded type is exactly Invoice Receipt; the warning maximum is five because the vocabulary has five codes
p1-0-schema-mapping.md718 lines of field-level PostgreSQL mapping for the corrected layer 1–5 roster, DOCARC/export support, the Layer 6 ground-truth slice, history import, grandfathering, RelatedParty, company scope, and the parked integration ledger
p1-0-codes-taxonomy-archive.mdPermanent-code ledger and non-cycling sequences, the proven identity keys, DOCTYP seed rows, and the collision-safe class-based Nextcloud layout
p1-0-discard-purge-lifecycle.mdSoft Discard, authorized Purge, never-delete DOCLOG, tombstone, and exact-hash resubmission — written to be usable by both Sibyla and FDR, which is the answer to Luís's open governance question
p1-0-user-ai-roles-responsibilities-policy.mdThe superseding fourteenth Engagement Rules document: exception-and-learning queue semantics, and the AI-proposal / deterministic-action boundary
p1-0-design-freeze-summary.md19 captured decisions, the SVG cross-check disposition, and a per-item checklist self-review that marks its own gaps
Design decisions worth flagging
Three of the nineteen change how P1-1 must be written. LGCode is the DOCLOG row identity on (Filename, EntryCode) and no DocLogId is added — so P1-1 validates the pair↔LGCode bijection, not one-code-per-EntryCode, which is the opposite of the constraint v4.0 specified. Sequence allocation is INSERT … ON CONFLICT DO NOTHING RETURNING followed by a new-statement winner read and full-key comparison; nextval() is deliberately non-transactional, so rollbacks, crashes and concurrency losers leave gaps that can never be reused, and runtime setval/restart is forbidden. And a malformed payload creates no ExtractionRevision and no DOCLOG — only an ExtractionAttempt plus an attempt-keyed DOCFAI/Decision review with a NULL LGCode — while a schema-valid NOT_A_DOCUMENT is a different thing entirely and takes the normal ExtractionRevision → DOCLOG → DOCFAI → Decision route. Conflating those two would have made junk indistinguishable from a parser failure.
Flow diagram — now in the repository, and cross-checked
The organigram was moved out of its working location and committed to docs/, so it is version-controlled alongside the drafts and every future revision belongs there. It was then cross-checked line-by-line against the frozen design: it is well-formed, and no normative correction was required — but nine of its labels are now stale and the drafts, not the picture, are authoritative. The stale ones: "strict validation before persisting"; ledger-reference/no-entry counted as reconciled; NOT_A_DOCUMENT flowing automatically to Discard/Purge; human validation before queue persistence; posting shown before the DOCFLG gate; "LGCode unique per EntryCode"; the warning that P/F/O, LGCode and PAY/RCVCODE are unstable (D2 closed that); the generic {Empresa}/{DocClass}/{Período} Nextcloud layout, now class-specific; and "dedup by hash" read as capture suppression. It also omits the ReferenceOnly branch, the failure routes, and the exact grandfathering predicate. v14 has since been drawn and replaces it: every stale label corrected, and the omitted limbs — ReferenceOnly, the two distinct failure routes, the ground-truth inputs, the blocking predicate — drawn explicitly. v13 stays in the repository only because the cross-check record cites it.

The P1-0 review — Aug 4–5, against the pinned prototype

The freeze was not accepted on its face. It was verified field by field against the FDR prototype at its pinned SHA, read-only, with the schema and key claims tested on the live data rather than on the drafts' description of it. The identity model held; the field-level mapping did not.

Blockers, proven on data
10
Would fail on counted rows at import — not "might"
Blockers, by analysis
9
Design and governance defects
Decisions frozen in name only
4
Text exists; the operative value or mechanism does not
Claims verified clean
~40
Including all three of D2's identity closures
What held
D2's identity work is correct and the .NET side can inherit it. Re-verified on live data: DOCLOG carries 1,475 rows and 1,475 distinct LGCodes with (Filename, EntryCode) unique and not one collision; SourceKey is present on 426 of 426 generated documents and genuinely excludes the mutating SourceFile; PAYCODE/RCVCODE are stable under a shuffled cold rebuild. A worry about a fourth ItemClass value turned out to be a false alarm — Information is a DOCRQE Priority and Informational a DOCEFL ReviewPriority; the class itself has exactly three values. Roughly forty further checks passed clean. The expensive part was right.
What did not
Almost every defect is the same failure repeated: the freeze was written from the rendered sheets and from memory, not from the data. The FL natural key collides on 78 rows because SourceTextHash was left out of it — the prototype's own detector has it. SourceTextHash is declared char(64) against a pinned value of 12. Every blocking predicate is false against pinned data because Non-Blocking is hyphenated and the drafts wrote NonBlocking. The ENTITM.EntityCode rule is inverted and would reject 100% of rendered rows. Seven aggregate payroll documents — one joining 15 movements — cannot satisfy the single-row foreign key the mapping gives them: 419 of 419 single documents resolve, 0 of 7 aggregates do. In each case the right answer already existed in the prototype's code or files and was transcribed wrong. None was a conception error — which is why nineteen corrections, not a redesign.
The two that would have hurt most
Grandfathering. DOCEFL already carries EffectiveFrom, populated on all 45 rules — and every one of the 29 open blocking instances was detected on or after its own rule's date. Seeding EnforcementStartsAt from it grandfathers none of them, so all 29 would block on day one: precisely the go-live queue D7 exists to prevent. The fix is to recognise that EnforcementStartsAt is a Sibyla concept and EffectiveFrom is FDR provenance — two different things the draft was about to collapse into one.

Purge scope. The review found that sharing byte storage through a canonical hash could make purging one discarded capture destroy the bytes of a Posted sibling. B1 subsequently closed that risk with per-capture byte storage: captures never share byte objects, RetainedContentHash is only a duplicate-detection index, and no reference counting is implemented.

Two review findings were withdrawn on re-check — ENTBNK's comma-join model and the RelatedParty funding classification were both correctly specified, and the review was wrong. Both are marked as withdrawn in the record, and the correction assignment is told explicitly not to "fix" them.

P1-0b — the correction pass — executed Aug 5, documentation only

Nine commits on Aug 5 turned the erratum into the drafts. The pass changed exactly nine pathsAGENTS.md, the five active P1-0 drafts, the freeze summary, p1-0b-status.md and project-todo.md — with no prototype access, no remeasurement, and nothing under src/, tests/, migrations/ or the database. Counts and conclusions stay pinned at 9359c67, re-confirmed at 6146004. dotnet build passes with 0 warnings and 0 errors, the scope scan confirms the nine paths, and the known-bad grep list — NonBlocking, SourceTextHash char(64), control-header PaymentSequence=1, positive DocLogId, unhyphenated Invoice Receipt — comes back clean.

Fully applied at P1-0b checkpoint
15
Historical count: C1–C8, C10, C13, C14, C16–C19, and C3 on its Aug 5 decision
Historical partials
4
C9, C11, C12, C15 — subsequently closed by P1-0d
Paths changed
9
Documentation only; build PASS, scope scan PASS
New proposal
C20
The generated vocabulary annex is not a row-level seed annex
What the fifteen closed at the P1-0b checkpoint
The structural defects are gone. C1 replaced the scalar movement FK with SourceKeyHash and an ordered junction, so the seven aggregate payroll documents — one joining 15 movements — now have a shape they can satisfy. C4 propagated through all six drafts: generated domains, exact literals including the hyphenated Non-Blocking, the Waived value, one-row applies-to expansion preserving SourceOrdinal, distinct priority and status types, nullable CaptureQuality. C7 pinned SourceTextHash at 12-hex md5-12 with a discriminator and a ban on cross-algorithm comparison; C13 gave DOCFLG its complete natural key with a DetectedAt tiebreaker, closing the 78-row collision. C18 made the reconciliation metric executable — numerator, denominator and rate exposed through BNKMOVReconciliationRate, P1-11 acceptance restated as 55.9% ±0.1%, with 94.6% explicitly labelled a differently defined prototype metric. Every matcher is now forced through MatcherProposal, and rejection identity deliberately excludes MatcherKind, so a rejection from matcher A blocks matcher B.
Historical P1-0b partials — subsequently closed by P1-0d
At the P1-0b checkpoint, the target shape was specified but the rows to seed it had not been recorded in the repository. Then missing were all 19 exact DOCTYP tuples with every source field; the complete DOCEFL seed rows, including exact EFCodes for the Monthly-gap and related-party rules; the literal ITMCLS CLCodes for Banks / Financing and Revenue / Intercompany; and the exact BTCode plus the complete 14-field BNKMAT governance row D6 needed. The repository search found no verbatim row-level source anywhere, no prototype was accessed, and — correctly — no row was invented. That restraint was the point: a plausible seed would have been indistinguishable from a real one six weeks later. Proposal C20 recorded that historical gap; P1-0d closed it under per-field provenance.
C3 — closed the same day
P1-0b left one sub-decision open on purpose: what happens when EnforcementStartsAt changes after import. It was decided on Aug 5 — the column is immutable after import or first use, enforced by a named reject trigger, with no recompute path and no recompute audit table. Correcting a rule means issuing a new DOCEFL rule version; persisted IsGrandfathered verdicts are never rewritten. Chosen for the same reason the phantom-backlog episode taught: a decision someone already took must not change underneath them. With that, nothing in C1–C19 was undecided. The four remaining P1-0b partials were data gaps rather than design gaps and were subsequently closed by P1-0d.

Also settled by omission: the residual-triage A and B items stayed out of scope by assignment and none is treated as a P1-0b blocker — A1 in particular did not make C1 impossible, since only the bank-generated index and referential model changed. Duplicate/External resolved as Include/ArchiveOnly preserving the real EntryCode, not D5 ReferenceOnly. SourceKeyHash is a pgcrypto SHA-256 generated expression over UTF-8 SourceKey bytes, NULL-preserving — and P1-1 must preflight pgcrypto/digest(bytea, text) and fail closed before migrating. No diagram was redrawn; the summary now names v14 as current and withdraws the earlier over-claim about v13.

P1-0c → P1-0d — the seed gap, and how it actually closed

P1-0c was written to close the carve-out by extracting six values verbatim from the pinned prototype, behind a mandatory gate: find nothing, invent nothing, stop. It found three of the six and stopped on the other three. The gate fired on a category error, not on a project blocker. C11 decides to add a sentinel DOCEFL row; C12 decides that gap detection becomes a new governed rule; D6 introduces a match status described in its own text as “a v5.0 addition”. A pin taken before those corrections were written cannot contain rows those corrections create. The fourth finding was real and different: build_bnkrec.py assigns BRCode from row order, which falsifies A3's premise that a permanent natural key existed to be extracted.

Rows transcribed from the pin
66
19 DOCTYP + 45 DOCEFL + 2 ITMCLS, each field extracted with source file and blob SHA
Rows authored as v5.0
3
EF0000000, EF0000046, BT000012 — each with a written code-allocation rule
Fields left absent
34
16 + 12 + 6 across the three rows; none filled to make a row look complete
Open items, whole project
1
O5 — P1-2 restricted-token / service-identity design, Miguel. O7 is closed prospectively; O6 opened and closed on Aug 5
The mechanism that replaced the gate
Per-field provenance instead of an all-or-nothing stop. Every seed field now carries exactly one of extracted (copied verbatim, with source file and blob SHA), authored (written as a v5.0 decision, citing the deciding clause), or absent (no defensible value exists; blank, with the search recorded). This preserves what the gate existed to protect — a plausible invented value cannot be mistaken for a real one later — while allowing an incomplete row to land and be audited instead of blocking four deliverables that never depended on it. The result is verifiable rather than asserted: the 45 DOCEFL rows are embedded as verbatim JSON and re-parse to 45 unique EFCodes with no gap in EF0000001EF0000045; all 19 DTCodes and both CLCodes check out against their stated blobs.
A3 — resolved by measurement, the way C13 already was
MatchGroupID loses its CodeLedger bucket: it is a per-run grouping label over a recomputed view, recorded as explicitly non-permanent and never to be quoted as stable identity. BRCode keeps its bucket and gets a key chosen by measuring candidate tuples against all 2,072 pinned BNKREC rows(BMCode) collides 112 times, (BMCode, EntryCode) reaches 2,072 distinct / 0 collisions. The production key is (Company, BMCode, EntryCode, FindingDiscriminator), whose pin-equivalent is the measured pair because every imported row carries the ordinary discriminator. Issuance stays P1-1b. This is the same evidence-first method C13 used when it kept three residual collisions visible rather than hiding them.
Historical P1-0e snapshot — independent-review findings closed at that point
At the P1-0e review, independent re-checking confirmed every headline claim: the rows were in the drafts, C9/C11/C12/C15 were ticked, the A2 column-provenance register was exhaustive by construction, B1–B4 and B12 governance was specified, and PROJECT-STATE.md was current for that review. The then-current nullability collision was resolved: 29 previously forbidden authored-row cells mapped to honest SQL NULL, while BT000012.RequiresReview was authored Yes. The then-authored EF0000046 seeded with Active=No; O8 later moved that Monthly-gap row to EF0000053. B1 closed under per-capture, unshared byte storage with no reference counting or confirmation dependency.
Historical P1-0e hand-off to P1-1a
At that point, making fourteen DOCEFL columns nullable had a cost: the then-governed 45 imported rules all carried values in those columns, so the schema could no longer reject an import that silently dropped one. The seed/import completeness assertion was therefore handed to P1-1a's validation service. O8 later extended the current source manifest to 52; this callout preserves the earlier hand-off rather than describing the present manifest.

The two leaked patch-marker + headings in p1-0-codes-taxonomy-archive.md and p1-0-schema-mapping.md are fixed. Repository text is now governed as LF by root .gitattributes; the separate renormalization commit is intentionally empty because the index was already normalized, and both line-ending commits are complete.

P1-1a — shipped, deployed, and independently accepted with notes, all on Aug 5

The first feat commit since Jul 23 — and the first schema code this project has had. It is one migration, not a train of incremental ones — 20260805180000_P11aFdrSchema, regeneratable, applied only to a disposable container and never to anything shared. Around it: P11aSchemaSql (1,764 lines of explicit DDL), the EF model configuration, the ported CodeIdentityStabilityVerifier, synthetic authored-row fixtures, and a 765-line disposable-database test class. No live reference data, no 2026 history, no shared database, no merge to main.

Lines added
9,665
18 files, 12 deletions — commit e2f4c2a on feature/p1-0d-follow-up, pushed
Normal suite
601 / 601
0 failed, 0 skipped; build clean at 0 warnings
Database suite
9 / 9
Disposable PostgreSQL 17, synthetic data, container removed in finally — none left behind
Implementation window
2h55
14:13:55 → 17:08:56 UTC; ≈2h59 including the post-push verification round
The correction that matters most — authority does not come from the caller
Runtime authority derives from a server-side RuntimePrincipal resolved through company membership and an authority mapping keyed by session_user. Caller-set sibyla.actor and sibyla.authorities GUCs grant nothing, and a test proves it by deliberately forging forged-allocation-actor / AllocatePermanentCode and requiring the allocation to fail anyway. That is the right shape of test: it does not check that the happy path works, it checks that the obvious attack does not. Governed activation, code bootstrap and allocation, matcher routing and decisions, control snapshots, disposition, counter-signature and purge all sit behind that boundary, and direct table/function grants stay revoked.
Purge implemented as receipts, not as deletion
B1's decision — byte storage per capture, never shared — arrives in code as an authenticated durable StorageDeletionReceipt tied to the exact Document, per-capture DocumentCaptureHash and original FileAsset. Only a successful durable receipt can mark a document Purged, and DeletionReceipts keeps every attempt including the failed and ambiguous ones, ordered. No external storage deletion was performed. The Down step drops only the exact sequence regclass values recorded in the two registries — proven by an unrelated P11aCode_-prefixed decoy that survives Down in the Up-Down-Up test, which is the same class of check as the shuffle-based identity-stability test: it fails if the implementation is merely plausible.
Superseded Aug 5 — “the block is mechanical” was the wrong diagnosis
This callout previously said the fix was “to clone it, not to rewrite the requirement.” Both halves were wrong. The d2 agent cloned the prototype at the pin and stopped correctly at the source gate: Scripts/validate_registry.py is not at pin 9359c67, not anywhere in the fetched history under any equivalent name, and not on the prototype machine's filesystem — and the prototype's own skill review reached the same conclusion independently. The script was authored and run only inside ephemeral working sessions and was never persisted; the requirement itself had to be rewritten. This is the same category error as P1-0c — an instruction to read a source no pin can contain — and it stands recorded here rather than silently corrected.
Executed Aug 5 — deliverable 2 implemented under Amendment 1
docs/AGENT-PROMPT-v5-P1-1a-d2-amendment-1.md designated the surviving documented check set as the primary specification, lifted the reconstruction prohibition, and kept stop-and-report where sources are silent or conflict. The agent implemented sixteen checks, each citing its specifying source in docs/p1-1a-d2-status.md, and recorded every source difference it resolved — C9's Source <> 'BNK' scoping, the checklist's (Period, Currency) shorthand resolved to (Period, From, To=EUR) from the pinned lookup implementation rather than guessed, the historical Receivable Treatment mapped to the target's ProcessingRoute domain, CaptureQuality as a warning with the nullable-vs-backfill decision escalated, not taken. Two adversarial review rounds hardened it: the second (proc_06a923bbda7a) bound authorization to the application principal (sub/NameIdentifier → active UserProfile → active Membership → active CompanyRegistry), proved cross-company isolation under a shared database role, ran the disposable suite through a non-owner role with only the eleven table-level SELECTs the snapshot source needs, and deferred reference_only_documents.json explicitly to P1-1b. Verification: 28/28 focused, 629/629 unit, 10/10 disposable-PostgreSQL 17, 0 warnings, 0 residual containers, prototype worktree clean at the pin. The pinned counts quoted in the backlog (“640 rows”, “1,425 of 1,475”) remain indicative, not authoritative — they came from ephemeral-session runs. Shipped later the same evening as 719407c — by prior instruction the implementation was committed and pushed before the closure prompt arrived, so the closure preserved that commit rather than rewriting history.
O6 closed Aug 5 — the four closure duties executed as 74d8635
A single closure commit — one parent, no rebase, no merge, no force-push — corrected the four records in the ordered sequence the closure prompt required. (1) docs/p1-1a-status.md now states what git records: e2f4c2a committed and pushed, deliverable 2 committed and pushed as 719407c. (2) PROJECT-STATE.md closes O6, updates header, decision table, phase row and changelog, and registers the CaptureQuality decision as O7 — Miguel-owned, non-blocking. (3) project-todo.md ticks the validation service, orphan-DOCLOG and bijection items with the Amendment 1 §4 annotation, marking the session-derived counts indicative. (4) docs/p1-1a-d2-status.md records the final state. The commit body was verified with git log -1 --format=%B: 7 real lines, zero literal \n sequences — e2f4c2a's defect was not repeated. Immediately before the commit: 28/28 focused, 629/629 ordinary, 10/10 disposable-PostgreSQL, build 0/0, 0 residual containers, git diff --check clean, prototype pinned at 9359c67 with a clean worktree.
Resolved — the status-vs-git discrepancy is corrected on the record
docs/p1-1a-status.md formerly closed with “No … commit, push, merge, or rebase was performed” while git showed e2f4c2a committed and pushed at 17:08:56 UTC. Per PROJECT-STATE.md §4 the contradiction was reported rather than silently resolved, and the closure commit 74d8635 amends the file to supersede the stale claim explicitly — the correction is itself part of the record, not a rewrite. The literal \n sequences in e2f4c2a's pushed commit body remain recorded as-is; history was not rewritten.
Deployed Aug 5 — the schema is live, empty, and reversible
Under explicit operational authorization the stack went live at binary 601ec77 (Api, Web, Worker, PDF helper; live configuration preserved) and the startup migrator applied the P1-1a migration to the live database: 66 tables created, 0 rows imported, 0 command-audit rows — the schema exists, the data-bearing work stays P1-1b. Pre-deploy verification re-ran clean (Release 629/629, disposable runner 10/10, 0 residual containers, -WhatIf first); post-deploy health is green end to end, live binary hashes match the published artifacts, and 0 relevant errors appear in the event log or runtime logs. Rollback is real, not nominal: application + IIS backups and a pre-deploy PostgreSQL dump with recorded SHA-256 and a passing pg_restore --list, ACL-restricted to Administrators/SYSTEM. Sanitized evidence JSON archived with its own hash.
Accepted with notes Aug 5 — the independent sign-off, docs/p1-1a-signoff.md
A fresh on-machine session re-derived everything without using the remote pre-review as evidence: build 0/0, 629/629, focused 28/28, disposable PostgreSQL 10/10, 0 residual containers, worktree clean after. Structural review with line citations (decoy survives Down, forged GUCs denied, receipt-gated purge, gap-burning allocation, container removed in finally); all sixteen checks re-derived against the pinned sources — Source != 'BNK' occurs exactly once and feeds exactly three checks; the warning set is exactly the specified three; an unavailable source fails every data check. No blocking findings. A1/A3/A4/A5 confirmed as advisories; A2 dismissed with pinned evidence (the prototype's uniqueness assertions are exact-string, so Ordinal is faithful); the two-commit closure topology accepted as disclosed. The sign-off's closing sentence limits its own reach: no P1-1b imports, no further shared-database migration, no production while O5 is open, no O7 decision.
Resolved — the deployment-before-acceptance window closed the same evening
The schema went live at ~21:50 UTC under explicit operational authorization, ahead of the sign-off — flagged here at the time as the board's most time-sensitive exposure, mitigated by empty tables and a verified pre-deploy dump. The window lasted hours: the acceptance landed before midnight with no blocking findings, so the live schema and the accepted schema are the same schema. What remains from the deployment's own limitations: the authenticated smoke test is still pending. The feature branch was merged to main (601ec77, then 7dc1b66) and its remote ref deleted; the sign-off merged as e13f702, now the tip of main.

Backlog progress by phase — Sibyla v5.0

Foundations Carried over from v3.2 + FDR
100%
P1-0 Contract and schema design freeze CLOSED — CARVE-OUT SEEDED BY P1-0d
100%
P1-1 Schema migration and reference-data seed P1-1a ACCEPTED AUG 5
50%
P1-2 Claude CLI runtime
0%
P1-3 Production skill v1
0%
P1-4 Deterministic pipeline
0%
P1-5 Flag governance — DOCEFL/DOCFLG NEW
0%
P1-6 Review queues — DOCRQE + RECREV NEW
0%
P1-7 Decision-application engine NEW
0%
P1-8 Reference-layer management UI
0%
P1-9 Review and document UI
0%
P1-10 Archive (Nextcloud)
0%
P1-11 Bank movements and reconciliation FROM PH2
0%
P1-12 Excel export (on demand)
0%
P1-13 Channels, durability, pilot
0%
Done in .NET FDR reference implementation exists — port pending In progress Not started

P1-0 was accepted on Aug 5 and closed the same day — all sixteen of its items are now ticked. The four that a signature could not close, C9, C11, C12 and C15, were closed by P1-0d transcribing 66 rows from the pin and authoring three under per-field provenance. P1-0e resolved the authored-row nullability follow-up; the bar reads 100% for the design freeze itself and does not mean nothing follows from it.

The percentage column counts .NET completion only — the violet segment is deliberately not counted as progress, because a working Python prototype is a specification, not a shipped feature. It does mean those phases carry far less design risk than a 0% bar normally implies: P1-5, P1-6, P1-7 and P1-11 all have running code to port and a control record proving it behaves.

Phase 2 (parked, not counted above): the remainder of FDR management layer 6 (ENTBLC, aging, payment priority, dispute/hold), the already-implemented provider-neutral integration core + Moloni adapter (sandbox/live acceptance pending), the parked Hermes financial-agent proposal engine, item and archive flag dimensions, deeper Legal/Procurement metadata, and the full-history 2025+2026 reconciliation. Nothing here was deleted — it's built or specified and waiting for re-planning, not re-work.

Estimated time remaining

Elapsed since kickoff
37 days
Jul 1 kickoff to Aug 7
Elapsed since v5.0 reissue
4 days
Aug 3 merge of v4.0 with FDR Stage 8–10, measured to Aug 7
v5.0 velocity baseline
One data point
P1-0 closed Aug 5 and P1-1a's migration train shipped the same day in a measured 2h55 — one measurement is not a rate, but it is the first one this project has had
Projected date
Withheld
P1-0 and P1-1a closed Aug 5; revisit once P1-1b lands — two measured phases will make the first defensible projection

The v3.2 pace numbers this section originally showed (~35% done, ~Sep 9 projection) stopped applying on 2026-07-29, and the v4.0 denominator stopped applying on 2026-08-03: the backlog was reissued as Development Plan v5.0, growing from 79 to 133 P1 items. A projection across two denominator changes in six days would be arithmetic, not evidence. What can honestly be said is that the scope grew but the risk fell: 22 of the 133 items now have a working reference implementation with a verified control record behind them, which is a different position from 79 unbuilt items even though the percentage looks worse. A meaningful estimate needs P1-0 and P1-1 closed first.

Activity timeline — code, prototype, and operations

Three tracks on one date axis so they can be read together, in separate charts because the units differ — commit counts, prototype pipeline runs, and hours are not the same thing, and stacking them would imply an equivalence that doesn't exist. The section was, until Aug 3, a picture of a handover of momentum — five days in which every bar belonged to the prototype and none to .NET. That gap closed: Aug 3 to Aug 7 put 113 commits back on the Sibyla series — 34 on Aug 5 (the P1-0→P1-1a arc, including e2f4c2a, the migration train, and 719407c, the validation service — the first feat commits since Jul 23) and then 61 on Aug 6 alone, now the repository's busiest day ever: the entire amendments 3–5 piece cycle — Piece A rejected then accepted on attempt #2, Piece B rejected then accepted on the B-R1 remediation, Piece C twice honestly stopped, amended and accepted — nearly all of it records of proof, review and governed stops rather than feature code. Aug 7's 10 carried the Piece D test-plan corrections, the Option A amendment, the D-M2 stop record, the accepted O5-prep candidate and the merges to main. The signal this section said to watch for — commits that are not documents — arrived on Aug 5 and has since been joined by its governance tail: the piece cycle's commit volume is what independent verification looks like in git.

Sibyla commits IdentityServer commits
Sibyla commits by date: Jul 1: 0, Jul 3: 1, Jul 6: 1, Jul 7: 5, Jul 8: 0, Jul 9: 0, Jul 10: 0, Jul 14: 0, Jul 15: 2, Jul 16: 3, Jul 17: 5, Jul 20: 6, Jul 21: 25, Jul 22: 11, Jul 23: 14, Jul 24: 1, Jul 25: 2, Jul 26: 0, Jul 27: 0, Jul 28: 0, Jul 29: 6, Jul 30 through Aug 2: 0, Aug 3: 2, Aug 4: 6, Aug 5: 34, Aug 6: 61 (the repository's busiest day — the full A/B/C piece cycle), Aug 7: 10, ending with the merge of feature/p1-1b into main (f1488ac). IdentityServer commits by date: Jul 1: 3, Jul 16: 1, all other dates 0.
FDR prototype — pipeline runs (Invoice Skill Build)
FDR pipeline runs by date, counted as distinct backup timestamps: Jul 21: 8, Jul 22: 15, Jul 23: 12, Jul 24: 27, Jul 25: 8, Jul 26: 5, Jul 27: 16, Jul 28: 7, Jul 29: 12, Jul 30: 16, Jul 31: 12, Aug 1: 1, Aug 2: 15, Aug 3: 13, Aug 4 through Aug 7: not yet counted. All earlier dates: 0.

Counted as distinct backup timestamps, each of which is one governed pipeline run with its own control record. Aug 1 shows a single run because Stage 10 Round 1 was explicitly review-only — it produced the 72 KB open-item register that became the v5.0 planning basis and deliberately changed no data. A low bar there is the process working, not a slow day.

Server configuration and tooling (hours)
Development agent (hours)
Development agent hours by date: Jul 21: 6.4, Jul 22: 3.7, Jul 23: 6.8, Jul 24: 0.5, Jul 25: 0.4 (previous estimation basis), Jul 26 through Aug 3: 0, then measured from the Hermes session store (state.db): Aug 4: 3h31, Aug 5: 14h34, Aug 6: 23h18 — the piece-cycle marathon, now measured rather than approximated — and Aug 7 up to 10:41 UTC: 10h38. Total since Aug 1: 52h00 merged elapsed execution time (56h17 before removing overlaps), including autonomous overnight processing; this is elapsed agent execution, not human intervention hours.

Two measurement bases, deliberately not blended: Jul 21–25 was estimated from active intervals between messages and tool calls (pauses over 45 minutes removed, overlapping sessions merged). From Aug 4 the bars are measured from the Hermes session store (state.db): 20 Sibyla-related CLI sessions, parallel intervals united so no period counts twice, subagents not re-counted, non-Sibyla work excluded, and two post-completion idle gaps over 30 minutes removed. This is elapsed execution time including autonomous overnight Codex/Claude processing — not human intervention hours. It supersedes the earlier commit-bounded Aug 4–6 floor estimates (2.6, 5.5, 0.9), which are retired rather than added. Detail in the development-agent time section below.

Hours by date: Jul 1: 0, Jul 3: 1.1, Jul 6: 2.5, Jul 7: 5.4, Jul 8: 5.2, Jul 9: 4.2, Jul 10: 0.5, Jul 14: 2.4, Jul 15: 3.4, Jul 16: 0.1, Jul 17: 2.5, Jul 20: 0, Jul 21: 9.4, Jul 22: 3.3, Jul 23: 0.4, Jul 24 through Aug 7: 0.

Runtime topology — v5.0

Hermes Gateway
email / WhatsApp / Mattermost
GOTT IdentityServer
OpenIddict OIDC/OAuth 2.0 provider
Sibyla API
IIS, OIDC login + channel identity
PostgreSQL jobs
FOR UPDATE SKIP LOCKED claims
Sibyla Worker
Windows service, stages job dir + invokes Claude CLI
Claude CLI (headless)
single-document extraction — P1-2/P1-3
.NET deterministic
FDR persistence, gates, side effects
Flag governance
DOCEFL catalogue → DOCFLG instances — P1-5
Bank reconciliation
BNKMOV / BNKMAT / BNKREC — P1-11
Persisted queues
DOCRQE (document) + RECREV (line) — P1-6
Decision-application engine
one engine, both queues — P1-7

The bottom two rows are new in v5.0 and all four boxes have a working FDR reference implementation. Replaces hermes -p documental-agent as the extraction engine; the restricted-runtime security pattern and PDF text/image staging pipeline are reused, re-targeted at the Claude CLI child process (P1-2). The full flow diagram is docs/2026-08-04 Sibyla_Organigrama_Fluxo_v14.svg, drawn from the frozen design and version-controlled alongside it. v13 is kept because the P1-0 cross-check record refers to it, but it is superseded and should not be handed to an implementer.

Open risk — O5 host session pending, prep accepted and merged · Pieces A, B and C accepted · Piece D stopped at D-M2, D-M2-A chosen, records pending

Closed history — seed, C3 and group A
This callout records a superseded P1-0b-era gate; it is not current state. P1-0d supplied the pinned-prototype provenance rows for C9 and C15, authored the new C11, C12 and D6 rows with explicit authored/absent provenance, and supplied A3's measurement. Group A and C3 are decided, and P1-0e reconciled the authored rows with schema nullability and governed activation. These matters no longer block import. P1-0c is superseded and must not be rerun. O6 opened and closed within Aug 5: unblocked by Amendment 1 after the “missing clone” diagnosis was disproven (the prototype validator script never existed), implemented, hardened through two adversarial review rounds, committed and pushed as 719407c, and closed on the record by 74d8635. Current state: two items are open — Piece D's D-M2 gate (decided as D-M2-A, records commit pending) and O5's target-host session; O7–O10 are closed decisions. P1-1b advances piece by piece under amendments 3–5: Pieces A, B and C are all independently accepted — Piece B on its second and final attempt after the B-R1 remediation, Piece C after two honest TDD stops and the Option-B audit amendment — and Piece D -- the integration gate over the combined A+B+C catalog -- has its go-ahead accepted and its twice-corrected checklist→test mapping approved by Miguel on Aug 7 (Observation 1 option (b): item 5's real-population claim deferred to Scope 1; Observation 2: the corrected eight-file roster, Designer/ModelSnapshot out of scope). TDD then ran twice and stopped twice, correctly: D-M1 (physical attnum retention across Down/Up) was closed by Miguel's Option A amendment (6554a8e); the fresh attempt proved items 1–4 and the folded item-8 roster green before item 6 stopped on D-M2, the accepted lifecycle CHECK / terminal trigger pre-empting the mapped composite-FK proof. Miguel has chosen D-M2-A; its records commit and mapping re-approval are what reopen Piece D. O5-prep completed its entire review cycle — two REJECTs remediated, third-pass ACCEPT, focused confirmation ACCEPT — and is merged to main; only the target-host session remains for O5.
Closed O7 — prospective data rule
Imported historical DOCLOG.CaptureQuality values that are SQL NULL with absent provenance are excluded from the validator warning. A missing value on a non-imported row warns, and every new Sibyla capture must provide CaptureQuality at capture time.
Closed O9 — governed contract retained; implementation neutralized
docs/AGENT-PROMPT-v5-P1-1b-o9-amendment.md closes all five contradictions without inventing a single value: O9-D1 corrects the register defect — ENTMST.DirectDebit is target-only, nullable (119 honest NULLs); O9-D2 makes TaxIdVerificationStatus nullable under the O7 mirror — NULL on the 119 historical rows, mandatory for new Sibyla-era rows; O9-D3 makes DOCEFL.ItemClass nullable with governed, audited assignment over time from the closed D8 vocabulary (52 to assign); O9-D4 completes the ReviewPriority CHECK to the normative annex table's six literals, admitting the two Routine rows verbatim; O9-D5 re-scopes the terminal ResolutionEvidence CHECK to non-imported rows, keeping the 221 historical rows honestly absent and enrichable by governed append. The standing policy O9-P makes every future completeness-class gap on imported historical rows a counted data-quality finding, never a stop — identity-class controls stay fail-closed unchanged. The accepted P1-1a migration remains immutable. The corrective implementation is currently neutralized after the third Reject; Miguel review must precede any new implementation or Scope 1 restart.
Closed O10 decision — piece cycle running under amendments 3–5
O10-D1/D2 remain closed: honest nullable imported snapshots, the composite and plain rule links, prospective completeness, and atomic NULL-only completion remain the governed contract. Three monolithic implementations — b324a3e, 57f0f023, and 7ea6c0f — plus piece candidates 6f86023d (Piece A Reject #1) and b8fa033 (Piece B Reject #1) are rejected and neutralized evidence only, never resurrected. Amendments 3–5 replaced monolithic reattempts with four independently reviewed pieces behind a test-plan gate. Piece A attempt #2 is independently accepted (0/0/0/0), and Piece B's B-R1 remediation — deferred constraint triggers validating live state at COMMIT, both co-update orderings proven — is implemented (7059809) and independently accepted (256da9c, 0/0/0/0) on the second and final attempt. Piece C — the governed commands (AssignDOCEFLItemClass, evidence append, fail-closed role provisioning, multi-company all-or-nothing authorization, genuine concurrency) — is implemented from zero off the Option-B amendment tip and independently accepted (candidate ce983b2, 0/0/0/0), with the review's one non-binding GUC observation carried forward into Piece D by Miguel's decision. Piece D's go-ahead is accepted, its test plan is approved, and TDD has run twice with two honest stops: D-M1 closed by the Option A amendment (physical ordinals reported diagnostically, excluded only from S1/S3 logical equality), and D-M2 — the accepted lifecycle CHECK and Piece C's terminal trigger pre-empting item 6's native composite-FK proof — now decided as D-M2-A, records commit pending. No candidate exists; Scope 1 stays gated on Piece D's own recorded Accept.
Open O5 — security
Carried over from v3.2, now wider in scope (P1-2): the restricted-token/service-identity design must cover both the PDF text-extraction helper and the new Claude CLI child process the Worker invokes for extraction. ACLs need to grant only helper read/execute plus transient-job-directory access, deny network-capable SIDs beyond what the CLI itself needs, and allow no application, database, or secret access. Everything automatable off-host is now done and independently accepted — provisioning scripts, acceptance-battery runner, injection fixtures and runbook survived two REJECT remediation passes, a third-pass ACCEPT and a focused confirmation ACCEPT, and are merged to main. What remains is exactly the target-host session per docs/deployment/o5-target-host-runbook.md (estimated under an hour) and its recorded evidence; production stays gated until Miguel records that closure.
Closed — was the migration gate
Published Aug 3 as a P1-1 data blocker; corrected the same day and reclassified. The prototype's three code families — P/F/O EntryCode, LGCode, PAYCODE/RCVCODE — are not stable identities: the first renumbers when an overlapping bank statement is re-ingested, the second inherits identity from filenames that are sometimes placeholders standing in for many rows, and the third is reassigned on every rebuild. None of this is corrupt data; all of it is a missing identity model. P1-0's permanent-code issuance solves it structurally, provided the natural key per bucket came from Luís first. It did, on 3–4 Aug, with proof for each — see decision D2 above. P1-1 is no longer gated. The P1-1 uniqueness check as originally specified would have rejected internally consistent data and has been restated against the keys actually in use.
Watch — metric integrity (not an open item)
This is an acceptance discipline, not a current open project risk. The bank reconciliation rate moved 93.8% → 91.8% → 94.6% in a single day, and the middle number is the instructive one. A new eligibility gate reverted 13 matches that should never have been allowed — a bank's own recurring charge settling a vendor invoice, an ATM withdrawal "settling" a receivable, a €6.59 document matching a €13.64 charge — and two of the three rule classes were invisible before, because only a double-claimed document raised a flag. The rate then passed its original level as the day's captures and corrections landed. Regression-test against 94.6%; read the 91.8% dip as the shape of removing wrong matches, never as a target. v5.0's Definition of Done states the principle directly: a metric that improves because a check was removed is a regression, not progress. The same day produced its mirror image — a queue reporting 2,616 open items that was 93% Statuses and Annotations, and a reconciliation rate that counted movements matched to a ledger reference with no financial entry behind them.

Re-baselined Aug 5, and this is the part to read carefully. The 94.6% figure turned out not to be reconstructible from the reconciliation table: six plausible definitions — by row, by movement, by amount, with and without internal transfers and ground-truth matches — land between 47.8% and 58.3%, and the 865 unmatched rows are genuinely unresolved. The metric was never defined in any draft, so P1-11's "reproduce 94.6% ±0.1%" was unrunnable. An explicit definition was adopted — distinct movements carrying at least one non-Unmatched match, over all movements — giving a baseline of 55.9%. This is a definitional change, not a regression, and anyone seeing both numbers side by side will assume otherwise unless told. Luís's definition is still worth having so the two can be reconciled rather than one quietly replacing the other.

Next steps — as at Aug 7, after the D-M2 stop and the O5-prep acceptance

State of record is docs/PROJECT-STATE.md — created Aug 5 as the single source of truth, after three separate reports treated decisions taken on Aug 4 as still open. Every other document, this page included, yields to it.

#OwnerAction
1Agent · P1-0d/eDONE Aug 5 — seed and nullability follow-ups closed. P1-0d transcribed the available rows and authored the new v5.0 rows under per-field provenance; P1-0e reconciled their schema nullability. P1-0c is superseded and must not be rerun
2MiguelDONE Aug 5 — C3 decided immutable and P1-0 accepted. EnforcementStartsAt is immutable after import or first use, with no recompute path. Acceptance still does not authorize shared-database migrations. The cheap check passes: no NonBlocking, no DocLogId, no char(64) on SourceTextHash, no unhyphenated Invoice Receipt
3MiguelDONE Aug 5 — all sixteen P1-0 items ticked; P1-0d closed the four-item carve-out and P1-0e closed the independent-review follow-up
4Agent · P1-1a d1DONE Aug 5 — the migration train shipped as e2f4c2a. One regeneratable migration, governed registry commands behind a server-side principal, ported identity-stability verifier, synthetic fixtures; 601/601 and 9/9 green, 0 warnings, disposable database only, no live data. 2h55 measured. Deliverable 2 was scope-blocked in the commit message for want of the prototype clone — see #4b
4bAgent · P1-1a d2DONE Aug 5 (implementation) — the validation service, under Amendment 1. The original instruction (“read Scripts/validate_registry.py at the pin”) proved unsatisfiable — the script never existed; the agent's stop proved it and the prototype's own skill review confirmed it. Under docs/AGENT-PROMPT-v5-P1-1a-d2-amendment-1.md the sixteen documented checks were implemented with per-check source citation, hardened by two adversarial review rounds, and verified 28/28 + 629/629 + 10/10 with 0 warnings. Committed and pushed as 719407c
4cAgent · P1-1a d2 closureDONE Aug 5 — closure commit 74d8635, pushed. One single-parent commit, no history rewrite; the four records corrected in order (p1-1a-status.md, PROJECT-STATE.md with O6 closed and O7 registered, project-todo.md, p1-1a-d2-status.md); commit body verified clean of the e2f4c2a \n defect; local = upstream = remote, working tree clean. O6 is closed
4dIndependent reviewerDONE Aug 5 — P1-1a accepted with notes. Fresh on-machine session, full re-derivation (build 0/0, 629/629, 28/28, 10/10, 0 containers), structural and sixteen-check review with line citations, A1/A3/A4/A5 advisory, A2 dismissed on pinned evidence, topology deviation accepted. docs/p1-1a-signoff.md, merged to main as e13f702; PROJECT-STATE.md updated. Acceptance explicitly does not authorize P1-1b imports, further shared-DB migration, production (O5), or O7
4fAgent · deploymentDONE Aug 5 — deployed live under explicit operational authorization. Binary 601ec77 on all four components, live config preserved; P1-1a migration applied by the startup migrator, 66 tables, 0 rows; health green, hashes match, 0 errors; rollback backups + verified PostgreSQL dump staged. Acceptance explicitly not declared
4gMiguelAuthenticated smoke test. The deployment verified everything except a logged-in business flow — log in through the OIDC redirect, open the review queue and a document, and exercise one harmless write. Ten minutes, and it closes the deployment's one stated limitation
4eMiguel → Agent · P1-1bO8 CLOSED Aug 6; Scope 1 restarted and stopped at O9. O8-D1 governs all 52 source DOCEFL rows, keeps source visual-read EF0000046, and re-authors inactive Monthly-gap as EF0000053. O8-D2 excludes the uncoded twentieth DOCTYP source row and keeps the 19-row import plus authored Include | ArchiveOnly target rule. The restarted controls passed, then the five accepted import-contract contradictions opened O9. No importer/source/fixture/test implementation, import, migration, container, or database work ran; ordered Scopes 2–8 remain unstarted
4hMiguelDONE Aug 6 — O9 decided by amendment. docs/AGENT-PROMPT-v5-P1-1b-o9-amendment.md records O9-D1…D5 — register correction plus three NOT NULL relaxations, the six-literal ReviewPriority CHECK, and the imported-row re-scope of the terminal-evidence CHECK — and the standing policy O9-P: completeness gaps on imported historical rows are data-quality findings to improve over time, never blockers; identity-class controls stay fail-closed
4iAgent · P1-1bO9 governed records DONE Aug 6; first implementation pass (commit b324a3e) REJECTED by independent review and neutralized fail-closed at the branch tip. High blockers: the DOCEFL-NULL vs DOCFLG composite-FK contract impossibility (→ O10), caller-controlled GUC command bypass with owner-only test coverage, weak non-company-scoped ImportEvidenceRow predicate; Medium: Down/Up constraint-name drift, imported unknown non-null ItemClass validator escape. Green tests were insufficient semantic proof
4jMiguelDONE Aug 6 — O10 decided by amendment. docs/AGENT-PROMPT-v5-P1-1b-o10-amendment.md: O10-D1 (absence snapshots as absence — nullable DOCFLG snapshot, self-scoping composite FK, plain EFCode FK, prospective full-snapshot CHECK, new 2,787-row data-quality finding) and O10-D2 (governed assignment completes absent snapshots atomically, never modifies a non-null one), plus the five review findings as binding remediation requirements
4kAgent · P1-1bSTOPPED Aug 6 — fresh step-3 implementation 57f0f023 received mandatory independent verdict Reject (0 Critical, 4 High, 3 Medium) and was neutralized fail closed. A normal additive branch-tip commit restores exactly all 14 code/test/migration/model paths byte-for-byte to records parent 15679e78. O10-D1/D2 remain closed and the governed 2,787 baseline is unchanged. Scope 1 has not started. Full findings and positive confirmations: docs/p1-1b-o10-independent-review.md. No remediation or reimplementation is authorized by this stop
4lMiguel → Agent · P1-1bDONE Aug 6 — amendment-2 governed records accepted. All seven second-review findings are binding R1–R7 requirements; all four missing-coverage items require explicit mapped proofs; and the third fresh implementation is bound to strict additive minimal-surface discipline. O10 stays closed, the 119 / 119 / 52 / 221 / 2,787 baselines and two verbatim Routine rows are unchanged, and rejected b324a3e/57f0f023 remain neutralized evidence. Step 3 has not begun
4mIndependent reviewer · P1-1bSTOPPED Aug 6 — third implementation 7ea6c0f rejected and neutralized. Verdict 0 Critical, 2 High, 4 Medium, 1 Low; all 15 implementation paths restored byte-for-byte to 01c92cb. Amendment 2's terminal condition now applies: no further reimplementation or Scope 1 restart pending Miguel's review of the repeated pattern
4nMiguelDONE Aug 6 — amendments 3, 4 and 5: the piece decomposition. The unchanged O9/O10 implementation splits into four independently reviewed pieces; the prototype preflight is reformulated around snapshot integrity (checks 1–5 hard stops; live-tip divergence logged by hash, no post-pin content read); three standing instruments adopted — consolidated checklist per piece, five-rule proof-pattern annex, and the test-plan gate: checklist→test mapping recorded and approved by Miguel before any implementation code
4oAgent + reviewer · Piece ADONE Aug 6 — Piece A accepted. Candidate 6f86023d Reject #1 (0/1/2/1) → findings bound as A-R1…A-R4 → 20-item mapping recorded and approved with one named DOCFLG widening → attempt #2 implemented as a remediation, exactly the approved diff — 0 warnings, 637/637 ordinary, 37/37 focused, 16/16 disposable — → fresh independent re-review Accept: 0 Critical, 0 High, 0 Medium, 0 Low
4pMiguel → Agent + reviewer · Piece BDONE Aug 6 — implemented from zero; REJECTED on B-R1; neutralized. Go-ahead scoped to RegistryFieldProvenance alone; 20-item mapping approved verbatim; implementation green on every figure (640/640, 3/3, 27/27, accepted migrations byte-identical) — and the adversarial review still proved, empirically on live PostgreSQL 17, that neither statement ordering of a legitimate value/provenance co-update can succeed (both triggers immediate; only an undocumented delete-update-insert gap works). Candidate b8fa033 restored byte-for-byte to base 87499a1
4qMiguelDONE Aug 6 — B-R1 remediation mapping approved. docs/AGENT-PROMPT-v5-P1-1b-piece-b-remediation-approval.md: Observation R-1 decided as option (b) — item 7 re-implemented as DEFERRABLE INITIALLY DEFERRED constraint triggers so both natural statement orderings succeed at COMMIT while one-sided changes still fail closed; Observation R-2 accepted (items 5/15/16 change proof mechanism, not outcome); eight new disposable tests R1a–R1g plus the item-20 design-note correction; 19 Pass rows carried as regression
4rAgent + reviewer · Piece B remediationDONE Aug 6 — remediation implemented (7059809) and independently ACCEPTED (256da9c, 0/0/0/0) on the second and final attempt. Exactly the approved diff: item-5/7 split, three DEFERRABLE INITIALLY DEFERRED constraint triggers re-querying live state at commit, R1a–R1g, 8-trigger/4-function roster; 0 warnings, 640/640, 3/3, disposable 34/34; WaiveDOCFLG byte-identical. The review re-proved B-R1 fixed via pg_trigger timing measurement plus six original probe transactions; all 20 items Pass. Piece B has an accepted implementation
4sMiguel → Agent + reviewer · Piece CDONE Aug 6 — Piece C independently ACCEPTED (candidate ce983b2, 0/0/0/0). Go-ahead 6880bbf → 20-item mapping with six reported observations, corrected after an independent review found three contract defects, approved by Miguel (all six resolutions adopted, incl. the one waived CREATE OR REPLACE of RejectTerminalDOCFLGMutationFn) → honest TDD stop: accepted RequireActiveCompanyRegistryFn also blocks inactive-company audit rows; clean neutralization, escalated → Miguel: “Aprovo B” — audit requirement amended (skippedInactiveCompanies on the caller's audit row; all-or-nothing over active companies only) → recreated from zero off Option-B tip fd9dbd9: 1 fail-closed role, 2 SECURITY DEFINER functions, 0 new objects on any accepted surface; two TDD-caught defects fixed; build 0/0, 646/646, 6/6, disposable 55/55 ×2 → fresh review reproduced everything, 20/20 traced, eight original adversarial probes, Accept: 0/0/0/0, one non-binding GUC observation flagged for Piece D
4tMiguel → Agent · Piece DIN PROGRESS — Piece D: go-ahead accepted and test plan approved (Aug 7); implementation next. No new migration content — verification that Pieces A+B+C together are byte-exact-invertible and complete: cumulative R2 (recorded pg_catalog snapshot, combined Up→Down→Up, post-Down equal to the accepted P1-1a catalog exactly), R7 end to end, the five baselines 119 / 119 / 52 / 221 / 2,787 plus the two verbatim Routine rows in one disposable run, unknown-ItemClass fail-closed both imported and native, and — added by Miguel's decision — the DOCFLG direct-DML roster proof turning the Piece C review's non-binding GUC observation into a tested invariant. Records commit also restores PROJECT-STATE.md consistency with the Piece C Accept. The go-ahead and Miguel's mapping approval are done: the mapping survived two fresh independent correction passes (1 Critical + 2 High + 2 Medium/Low, then 1 High + 3 Medium -- every finding applied in place) and both observations were decided by name: Observation 1 option (b), item 5's real-population claim formally deferred to Scope 1, no synthetic count theatre; Observation 2, the corrected eight-file byte-identity roster, Designer/ModelSnapshot explicitly out of scope. Approved inventory: 6 new tests + 1 helper, 2 strengthened, 7 regressions re-run, 14 verification commands, no test for item 5. TDD has since run twice with two honest stops: D-M1 (dropped-attnum slot retention across Piece A's Down/Up makes literal S1/S3 physical equality unsatisfiable) closed by Miguel's Option A amendment (6554a8e); the fresh attempt proved items 1–4 + folded item 8 green with measured proof before item 6 stopped on D-M2 (the accepted lifecycle CHECK / Piece C terminal trigger pre-empts the mapped native direct-UPDATE composite-FK proof as 23514; the inactive-company 23503 is a wrong-object trap). No candidate exists. Miguel has chosen D-M2-A — atomic Open→terminal UPDATE, asserting 23503 plus the exact constraint name. Remaining: D-M2-A records commit + mapping re-approval → TDD resumes → fresh integration-focused independent review. Accept here is what authorizes the Scope 1 restart at preflight against pin b917685
5Miguel → Agent · O5-prepGREEN-LIT (night of Aug 6–7) — O5-prep runs in parallel with Piece D. The governed design is recorded (docs/p1-2-o5-restricted-identity-design.md) and its prep prompt (docs/AGENT-PROMPT-v5-P1-2-o5-prep.md) is now authorized by Miguel to start: idempotent provisioning scripts (identities, ACL matrix, both egress mechanisms, job-root layout), the D-O5-6 acceptance-battery runner with synthetic injection fixtures, and the target-host runbook — on branch feature/p1-2-o5-prep, a file surface disjoint from P1-1b by construction. What closes O5 itself remains the target-host session, which is Miguel's. Carried since v3.2 and still gating production
6Luís (FDR) · review on returnNothing is blocked on Luís. The C8 five-pair merge was executed on his behalf under Miguel's Aug 6 authorization and is flagged for his review on return (prototype commit b917685). O8, O9 and O10 are decided and closed and await nothing from Luís. Classifying the residual DOCFLG collisions (now seven; all resolve on DetectedAt) remains an FDR-side action that does not gate import. The 94.6% definition reconciles two metrics; 55.9% is defined and stands alone
7MiguelDONE Aug 5 — all seven group-A items decided. The decisions are recorded in docs/p1-0-a-group-decisions.md; the older residual-triage action is closed and must not be reopened
8BothRestore measurement. FDR runs since Aug 3 are uncounted and the ops session log has had no entry since Jul 23 — two of the three tracks on the timeline above are reporting stale. Re-measure the pinned figures after the 19 pending inputs are ingested rather than reconciling them twice

Sequencing note: #1, #4, #4b–#4d, #4f, #4h–#4s are complete; the live edge is twofold — #4t, Piece D resuming from the pending D-M2-A records commit (two honest TDD stops so far: D-M1 closed by the Option A amendment, D-M2 decided as D-M2-A), and #5, O5's target-host session, its preparation now independently accepted and merged to main. P1-1a is closed end to end; Pieces A, B and C are all independently accepted; every P1-1b decision gate (C8, O8, O9, O10, the piece go-aheads, the test-plan approvals, the B-R1 remediation approval and the Option-B audit amendment) is decided and recorded. O10-D1/D2 are not reopened. Scope 1 stays gated on Piece D's recorded Accept; #4g stays a ten-minute check and O5 gates the P1-2 production runtime. The records are mutually consistent through the Piece D mapping gate; the mapping-approval prompt's own records commit closes the loop. Two items stand open — D-M2's records commit and O5's host session; O7, O8, O9 and O10 are closed. The reconciliation baseline moved to 55.9% under an explicit definition — see the metric-integrity note above before quoting either number. A velocity baseline still cannot be published.

Foundations carried over — what's implemented — Sibyla v5.0

Teal check marks are shipped .NET; violet diamonds are FDR prototype assets that v5.0 commits to porting rather than redesigning.

Recent activity — FDR prototype, Jul 30 – Aug 3

DateStageRound
Aug 4R29/35/36The identity problem closed. BMCode re-keyed off the mutating SourceFile — 426 of 426 generated documents re-anchor under a full renumbering, 0 duplicates, against €639,943.78 that would have been silently regenerated
Aug 4R36LGCode re-keyed on (Filename, EntryCode) — 512 fresh codes, 509 DOCFLG references migrated in one transaction, 1,475 rows / 1,475 codes
Aug 4R29Code-stability check on every pass: shuffle rows, blank codes, reassign from the ledger — 0 of 481 PAYCODEs, 0 of 245 RCVCODEs, 0 of 1,960 BMCodes move
Aug 3S10 R6Reference Only — a third document state: 7 documents, €27,458.62, captured with no EntryCode by design
Aug 3S10 R6End-to-end flow test — 20 documents captured, 51 archived, inbox cleared. Found the inbox is shared between Gott and Itoorer with no company signal in the folder
Aug 3S10 R6Phantom backlog fixed at source — new ItemClass field (Decision / Status / Annotation); DOCRQE 2,616 open → 64 Decision-class, 41 of them open at the pin
Aug 3S10 R6630 stale DOCRQE items closed as Superseded across three separately evidenced classes
Aug 3S10 R6Zero blocking flags — the MEO "conflict" was never real; ground-truth tolerance 10% → 5% capped at €50; exact beats approximate; new own-account identity guard
Aug 3S10 R68 documents captured twice, €14,979.32 double-counted — found and corrected
Aug 3S10 R62026 Jan–Jun payroll rebuilt — six months with no FDCHDR row at all, €142,835.50 reconciled as cash but never recorded as entries
Aug 3S10 R6Correction to the stale-DOCLOG finding — 134 rows split into 89 retired identities, 18 future-dated schedule rows, and the 27 that exposed the payroll gap
Aug 3S10 R6Blocking flags 108 → 12; orphan P/F/O rows removed; Toorist intercompany classified; user_observations.json durability
Aug 2S10 R6Execution review report; skill + reference review, trim and update
Aug 2S10 R6Reconciliation matrix rounds 1–4; July BCP ingestion; VAT refund NoDocMov created
Aug 2S10 R6DOCTYPEDOCTYP rename + Observations field on both queues
Aug 1S10 R2Conflict-row report; Critical items from the open-item register closed
Aug 1S10 R1Roadmap, open-item, gap and conflict review — review-only round; produced the register v5.0 is built on
Jul 31S9 R1–R9DOCEFL/DOCFLG; entity and item entry flows; reconciliation, review and archiving procedures
Jul 30S8 R2–R14Data update governance; MNGAPLMNGACC; COCACC seeded; two lost engines rebuilt

Every row above closed with a verified control record. Aug 3 alone ran 13 pipeline passes; v5.0 was published from the 09:30 state and refreshed to 19:30. Three of these changed the .NET plan rather than just the prototype: ItemClass is now a P1-6 schema requirement, "reconciled is not recorded" is a P1-11 match status (D6), and Reference Only is a P1-4 document state (D5). The Aug 4 rounds closed the last thing gating the schema freeze.

Recent activity — Sibyla (.NET)

DateTypeCommit
Aug 7mergeO5-prep and the piece-cycle branch land on main — the accepted O5 preparation (0c2a1e1) merged into feature/p1-1b (a445478), then feature/p1-1b merged into main (f1488ac)
Aug 7featO5 preparation accepted after a full review cycle — provisioning scripts, acceptance-battery runner, injection fixtures and target-host runbook: two independent REJECTs remediated (inheritance stripping, PS5.1-fatal process-tree kill and ArgumentList, egress lifecycle, password rotation, per-job Claude CLI cache), third-pass ACCEPT with 2 Lows fixed, focused independent confirmation ACCEPT; 91/91 Pester, honest off-host battery 21 PASS / 17 HOST-SESSION / 1 BLOCKED-P1-2. Only the target-host session remains for O5
Aug 7docsPiece D TDD stop #2 — gate D-M2 opened (3edaee8): items 1–4 + folded item 8 green with measured proof (complete logical S1==S3, exact S0==S2, byte-identity, zero direct-DML roster); item 6's mapped native direct-UPDATE proof cannot reach the composite FK — every ACTIVE-company path dies first as 23514 on accepted objects. Clean stop, no candidate; Miguel has since chosen D-M2-A, records pending
Aug 7docsPiece D Option A amendment approved — D-M1 closed (6554a8e): "Aprovo a opção A e o mapping Piece D revisto" — physical ordinals/attnums become observed diagnostics excluded only from S1/S3 logical equality, after TDD stop #1 proved PostgreSQL's dropped-slot retention makes literal physical equality unsatisfiable across Piece A's Down/Up
Aug 6–7docsThe piece cycle completes A, B and C — 61 commits on Aug 6, the repository's busiest day: Piece A Reject #1 → accepted attempt #2; Piece B Reject #1 (B-R1) → accepted remediation; Piece C two honest stops → Option-B amendment → accepted from-zero implementation; each behind its approved checklist→test mapping and fresh independent adversarial review (all three Accepts 0/0/0/0)
Aug 6docsO10 amendment 2 accepted on the record — all seven findings from the second Reject are binding R1–R7 remediation requirements, the four missing-coverage items require explicit mapped proofs, and strict additive minimal-surface discipline governs the third fresh implementation. O10-D1/D2 remain closed; expected baselines 119 / 119 / 52 / 221 / 2,787 and the two verbatim Routine rows are unchanged; step 3 has not begun
Aug 6docsO10 step 4 rejected and neutralized — mandatory independent review of pushed implementation 57f0f023 returned Reject: 0 Critical, 4 High, 3 Medium. The additive stop commit restores all 14 implementation paths byte-for-byte to parent 15679e78 and records the full findings in docs/p1-1b-o10-independent-review.md. O10-D1/D2 and the 2,787 baseline remain closed; Scope 1 has not started; no remediation or reimplementation was attempted
Aug 6docsO10 amendment issued and governed records completeddocs/AGENT-PROMPT-v5-P1-1b-o10-amendment.md was already tracked at the records base; the records pass closes O10 with O10-D1/D2 honest historical snapshots, the new 2,787 baseline, and all five review findings as binding remediations. Fresh implementation and its mandatory independent review remain pending; b324a3e stays neutralized evidence
Aug 6docsStep 3 rejected and neutralized; O10 opened — implementation commit b324a3e (Align P1-1b import contract) received an independent Reject; a normal branch-tip stop commit restores all 13 changed code/test/migration paths byte-identically to parent 6e18e1c, records the three High and two Medium findings, and opens the O10 contract gate. No history rewrite; the governed O9 records stand
Aug 6docsO9 amendment issued and governed records completeddocs/AGENT-PROMPT-v5-P1-1b-o9-amendment.md was already committed at the records base; the follow-on records commit applies O9-P/O9-D1…D5 to current state, status, register, annex, and backlog without rewriting the prompt. Corrective migration P11bImportContractAlignment and Scope 1 restart remain pending
Aug 6docsRecord the accepted import-contract stop134d458: after every count control passed, five sanitized source/provenance/schema contradictions opened O9 and stopped Scope 1 before TDD, implementation, import, container, or database work
Aug 6docsClose O8 and restart Scope 1dabf328 records O8-D1/D2; ca9942b governs all 52 source DOCEFL rows, retains source visual-read EF0000046, re-authors Monthly-gap as EF0000053, and explicitly excludes the uncoded twentieth DOCTYP row while keeping the 19-row import manifest
Aug 6docsRecord the governed manifest stop16531b9: the restarted Scope 1 preflight verified all 49 roster blobs, passed C8 43/43/0/0 and C13 2,787/2,787, then stopped on the 52-row DOCEFL manifest conflict and the uncoded Bank-Statement DOCTYP row. O8 opened, Miguel-owned
Aug 6docsC8 amendment and closure1d9497d (Miguel's written authorization for the on-behalf source merge) and 6a17e83 (records: prototype commit b917685 merges the five ENTBNK pairs keeping both Flag notes; 48 of 49 roster blobs byte-identical; new immutable pin fixed; flagged for Luís's review)
Aug 6mergeSync: docs/project-evolution-sync merged into main (fa77288) and origin/main merged into feature/p1-1b (92e4692)
Aug 5docsP1-1b records + C8 stop series536eeac (authorization, O7 closed prospectively, fresh pin 06825b5 + 48-blob roster), 2b8c708 (the measured C8 stop: five duplicate ENTBNK pairs, fail closed, no database work), f86b912 (independent-review record corrections), b793970 (state sync)
Aug 5mergeMerge the P1-1a sign-off into maine13f702; carries f435813 docs(p1-1a): record independent acceptance. P1-1a is accepted
Aug 5mergeMerge feature/p1-0d-follow-up into main601ec77 (the deployed binary version), then 7dc1b66 bringing the review handoff; the feature remote ref was deleted after merge
Aug 5docsAdd the P1-1a independent review handoff05a9d69: the reviewer assignment (AGENT-PROMPT-v5-P1-1a-review.md), the remote pre-review report (accept-recommendation with advisory findings A1–A5), and the refreshed evolution page
Aug 5docsClose the P1-1a D2 records74d8635: O6 closed, O7 registered, the four record corrections in one single-parent commit with a verified-clean body. The closure commit that ended the day
Aug 5docsAdd the P1-1a d2 closure handoff — the ordered four-correction closure assignment
Aug 5featImplement the P1-1a registry checks719407c: the validation service, sixteen documented checks with per-check source citations, hardened by two adversarial review rounds; 28/28 + 629/629 + 10/10, 0 warnings. Second feat commit of the day
Aug 5docsAmend the P1-1a validation handoff — Amendment 1: the source gate replaced by the documented check set after the “missing script” diagnosis was disproven
Aug 5docsAdd the P1-1a D2 handoff — the validation-service assignment with its then-mandatory source gate
Aug 5featImplement the P1-1a registry schemae2f4c2a, 18 files, 9,665 insertions: one migration, 1,764 lines of explicit DDL, governed registry commands, identity-stability verifier, disposable-database suite. First feat commit since Jul 23
Aug 5docsAlign the P1-1a handoff with P1-0e — the implementation index covering the MatchGroupID bucket removal and the new nullability
Aug 5docsReconcile authored seed nullability — P1-0e: 29 honest NULLs, BT000012.RequiresReview authored Yes, governed ActivateDOCEFLRule
Aug 5choreDefine and apply the LF line-ending policy — .gitattributes plus a dedicated renormalization commit
Aug 5docsComplete the P1-0d design-freeze follow-up — 66 rows transcribed from the pin, three authored under per-field provenance, A3 measured
Aug 5docsDecide the B1 purge storage model — per-capture bytes, no sharing, no reference counting; purge is not erasure
Aug 5docsSupersede P1-0c with a corrective assignment, and record the P1-0c source-gate findings
Aug 5docsRecord P1-0 acceptance and create docs/PROJECT-STATE.md as the single state of record
Aug 5docsStabilize P1-0b scope wording — the branch's changed-path claim restated against its upstream baseline so the scope scan is reproducible
Aug 5docsClose final P1-0b review findings — last independent-review items resolved; known-bad scan and dotnet build both PASS
Aug 5docsCorrect independent P1-0b findings — cross-matcher rejection identity, BankInputEvidence composite FKs, SourceKeyHash pgcrypto preflight
Aug 5docsRecord P1-0b correction statusdocs/p1-0b-status.md: register of C1–C19, the five partials, proposal C20, and what still needs Luís
Aug 5docsRefresh the P1-0 correction summary and mark supported entries complete in project-todo.md
Aug 5docsApply P1-0b design corrections — C1–C19 written into the five active drafts, the freeze summary and AGENTS.md; nine paths, documentation only
Aug 5docsAdd P1-0 residual triage and handoff — ~40 non-blocking findings sorted A/B/C, seven of them import blockers
Aug 5docsEstablish the P1-0 correction gate — precedence rule making p1-0-corrections.md win over the drafts
Aug 5docsRecord the P1-0 review and the P1-1a handoff
Aug 4docsRecord P1-0 SVG cross-check — nine stale diagram labels catalogued as superseded; no normative correction required
Aug 4docsRelocate Sibyla flow diagram2026-08-03 Sibyla_Organigrama_Fluxo_v13.svg committed into docs/; references updated in three files
Aug 4docsFreeze P1-0 contract and schema design — 6 new drafts, ~1,693 lines, plus 64 lines of v5.0 AGENTS.md instructions
Aug 4docsDocument the read-only FDR prototype workflow in the P1-0 agent prompt
Aug 4docsClose v5 schema decisions (D4–D9) and update the P1-0 handoff; FDR-to-Sibyla decision pack for Luís
Aug 3docsRefine v5 P1-0 handoff and FDR decisions
Aug 3docsPublish v5.0 roadmap and archive the v4 plans
Jul 29choreUpdate .NET packages to 10.0.10
Jul 29docsRevise v4 roadmap after repository sync
Jul 29mergeorigin/main → feature/document-type-settings
Jul 29mergefeature/moloni-multi-erp-core → main
Jul 29mergehotfix/whatsapp-lid-sender → feature/moloni-multi-erp-core
Jul 29docsUpdate roadmap for FDR development plan v4.0
Jul 25mergemerge/whatsapp-lid-to-main → main
Jul 25mergehotfix/whatsapp-lid-sender
Jul 24fixAuthorize strict WhatsApp LID senders
Jul 23featAdd Moloni reconciliation
Jul 23featAdd Moloni sales pull
Jul 23featAdd Moloni purchase writer pilot
Jul 23mergefeature/document-type-settings → main

Jul 29's commits were the v4.0 pivot, and the repository then went quiet for four days while the prototype ran ahead. Aug 3–5 brought 42 commits: the v5.0 reissue, the D4–D9 closures, the P1-0 freeze, its review, the nine-commit P1-0b correction pass, then P1-0c → P1-0d → P1-0e, P1-1a's two feat commits with their handoffs and closure, the review handoff, the merges to main, the sign-off, and the P1-1b records/C8-stop series — capped by the live deployment and the independent acceptance, with the sync merges spilling into the small hours of Aug 6. The two this section spent three revisions waiting fore2f4c2a and 719407c — are not documents. Thirty-one non-feature commits bracketing one 9,665-line migration and one sixteen-check validation service is the freeze-then-correct sequence working as designed: the design debt was paid down first, and the code was written once against settled keys rather than three times against moving ones.

GOTT.IdentityServer — supporting service

Self-hosted .NET 10 OpenID Connect / OAuth 2.0 provider (OpenIddict, ASP.NET Core Identity, PostgreSQL 18.4) that issues the OIDC/JWT identity Sibyla authenticates against. Separate repository, shared roadmap. Unchanged since Jul 30.

Commits
4
Jul 1 kickoff, Jul 16 UI/identity update
Working tree
40 files
Uncommitted: profile self-service, email change, multilingual UI
Tests
19
Client secrets, localization routing, profile (3 test files)
Lines of code
~5.3k
Plus ~0.8k in tests, excludes generated migrations
  • OpenIddict authorization code + PKCE and client-credentials flows
  • Admin console: clients, roles, scopes, per-client branding
  • Multiple named client secrets per client, zero-downtime rollover
  • ASP.NET Core Identity with password reset via Office365 SMTP
  • Multilingual UI (English / Portuguese) added Jul 16
  • Docker Compose, container or local PostgreSQL launch profiles
  • Production issuer configured at login.gottsolutions.net
  •  In progress, uncommitted: self-service profile page, verified email-change flow

Development agent time — GOTT.Sibyla · Jul 21–25 estimated · Aug 4–7 measured from the Hermes session store

Time spent by the development agent on work directly related to GOTT.Sibyla, in two windows on two explicitly different bases. Jul 21–25 was estimated from active intervals between messages and tool calls, pauses over 45 minutes removed, overlaps merged — 17h50, unchanged. Aug 4–7 is now measured from the Hermes session store (state.db): 20 Sibyla/GOTT.Sibyla CLI sessions, parallel intervals united so no period is counted twice, overlapping subagents not re-counted, Postiz/IdentityServer and other non-project work excluded, two post-completion idle gaps over 30 minutes removed, timestamps in +0000. This is elapsed execution time — it includes autonomous overnight Codex/Claude processing, not only human intervention — and it supersedes the earlier commit-bounded Aug 4–6 floor estimates (2h38, 5h27, 0h53), which are retired, not added. The raw sum of individual session durations before overlap removal was 56h17. This remains engineering effort, separate from the manual infrastructure track below; the two windows' totals should not be added across bases without saying so.

Measured since Aug 1
52h00
Aug 4 – Aug 7 10:41 UTC, Hermes session store; 56h17 raw before overlap merging; Aug 1–3 measured 0h00
Busiest day
23h18
Aug 6 — the amendments 3–5 piece cycle: Pieces A, B and C from rejects through accepted implementations, running nearly around the clock
Jul 21–25 window
17h50
Previous estimation basis — intake, Moloni, multi-ERP; kept separate, not summed with the measured window
Aug 7 so far
10h38
To 10:41 UTC — Piece D test-plan corrections and approval, Option A amendment, the D-M2 TDD stop, and the O5-prep remediation/acceptance cycle
DateTimeMain work
Jul 216h25Document cataloging, VAT/company intake fix, documental and WhatsApp intake
Jul 223h42Documental intake, validations, and the start of Moloni / multi-ERP
Jul 236h49Development and review of the Moloni / multi-ERP core
Jul 240h29Moloni plan continued
Jul 250h25Moloni plan continued
Jul 26 – Aug 30h00No direct GOTT.Sibyla activity identified
Aug 1–30h00No Sibyla-related session time in the Hermes store — the FDR prototype's Stage 10 rounds ran in Luís's repository, outside this measurement
Aug 43h31Project resumed: the v5.0/P1-0 design work on document-type-settings, D4–D9 closures, the P1-0 freeze and the start of its review. Hermes-measured; supersedes the 2h38 floor estimate
Aug 514h34The full P1-0→P1-1a arc, now measured end to end: P1-0b execution, reviews and corrections, the P1-0c/P1-0d/P1-0e sessions previously untimed and now included, the P1-1a migration train (its 2h55 first-step-to-push window stands inside this figure), the deliverable-2 validation service with its two adversarial review rounds, the closure and sign-off sessions, and the P1-1b records + C8-stop run. Hermes-measured; supersedes the 5h27 partial estimate that had explicitly flagged the day's true total as materially higher — it was: nearly 3×
Aug 623h18The piece-cycle marathon, no longer an unmeasured window: the early-morning C8-amendment/restart/O8-stop pass, then amendments 3–5 and the full cycle — Piece A Reject #1 and accepted attempt #2, Piece B Reject #1 and the accepted B-R1 remediation, Piece C's two honest stops, the Option-B amendment and its accepted from-zero implementation — including the independent adversarial review sessions and overnight autonomous processing. 23h18 of merged execution inside one 24-hour day is parallel sessions overlapping, counted once
Aug 7 (to 10:41)10h38Piece D's twice-corrected test-plan mapping and Miguel's approval, the Option A amendment records (D-M1 closed), the fresh TDD attempt to its D-M2 stop, and the O5-prep remediation cycle through the focused confirmation ACCEPT — plus the merges to main
Window and main contentTimeBasis
Jul 21–25 — cataloging/VAT/documental intake (10h07), Moloni and the multi-ERP core (7h25), unattributed (0h18)17h50Estimated — message/tool-call intervals
Aug 4 — v5.0/P1-0 design and freeze3h31Measured — Hermes session store, overlaps merged, subagents counted once, includes autonomous processing
Aug 5 — P1-0b→P1-0e, P1-1a train + validation service, sign-off, P1-1b records/C8 stop14h34
Aug 6 — the amendments 3–5 piece cycle: Pieces A, B, C from rejects to accepted implementations, with their independent reviews23h18
Aug 7 to 10:41 UTC — Piece D test plan/Option A/D-M2 stop; O5-prep remediations through focused ACCEPT; merges to main10h38

Worth reading against the commit chart: the Jul 21–25 block was 17h50 of production code — intake, Moloni, multi-ERP — while the measured Aug 4–7 block is 52h00 across 111 commits whose overwhelming majority are records: freezes, corrections, checklist→test mappings, rejects, remediations, independent reviews, and honest stops, bracketing one 9,665-line migration, one validation service, four accepted P1-1b pieces and one accepted O5 preparation. The measured figure also settles what the previous revision could only flag: Aug 5's "materially higher" true total was nearly three times the 5h27 floor, and Aug 6's unmeasured marathon was 23h18 of merged execution — the most expensive day of the project, and the day that bought three independently accepted pieces. Two caveats keep the number honest: this is elapsed execution including autonomous overnight processing, not human hours; and per-category shares are not recomputed across the two bases, because a merged-elapsed hour and an active-interval hour are not the same unit.

Server configuration and tooling

Manual infrastructure and operations work across both .NET projects — Hermes Gateway, Mattermost, WhatsApp, IdentityServer OIDC, and Apolo channel intake — tracked by session rather than by commit. Charted alongside code commits above. No sessions logged since Jul 23.

Total tracked time
40h29
13 sessions across Jul 3–23
Longest session
9h23
Jul 21 — Mattermost/Apolo intake, Graph/WhatsApp config split
Recurring focus
OIDC
Mattermost + IdentityServer logout patch, Jul 8–17
DateTimeMain focus
Jul 31h06Hermes/web/search configuration; started Hermes/SibylaMem backup
Jul 62h32Codex/Hermes setup and auth; Hermes update; backup continued
Jul 75h24Hermes backup cron, WhatsApp allowlist, memory/profile, Dashboard + IdentityServer OIDC, WebSocket
Jul 85h14Apolo/Hermes profile configuration; Mattermost Docker/OIDC bring-up
Jul 94h14Mattermost + IdentityServer/OIDC
Jul 100h29Mattermost/IdentityServer follow-up
Jul 142h26Hermes Dashboard logout patch validation/OIDC
Jul 153h22Continued OIDC logout patch validation
Jul 160h06Small logout/OIDC follow-up
Jul 172h31Final logout/OIDC verification
Jul 219h23Mattermost/Apolo channel intake + Graph/WhatsApp/Hermes config distinction + operational handoffs
Jul 223h18Sibyla live deployment checks, IIS/AppPool/Worker verification, backup and PostgreSQL dump/hash evidence, health/OIDC endpoint checks
Jul 230h24Model/tooling configuration decisions, brief Hermes/channel-intake follow-up