diff --git a/academy/Module-16-Medical-Regulatory/C15-GATE-RECORD.md b/academy/Module-16-Medical-Regulatory/C15-GATE-RECORD.md new file mode 100644 index 0000000..d44a362 --- /dev/null +++ b/academy/Module-16-Medical-Regulatory/C15-GATE-RECORD.md @@ -0,0 +1,55 @@ +# Competency-15 Gate Record — PASSED + +> **Date closed:** 2026-07-21 · **Candidate:** Vinay (Founder) · **Examiner:** Claude (adversarial; grades, never answers) +> This record closes the 15-competency core arc and freezes Academy v1.0 per the README freeze policy. + +## Process (as agreed during the gate) + +The gate was split into two parts — a founder-proposed refinement, adopted on its merits: +- **Conviction Gate** (Q6, Q7 core): founder-only, non-delegable. AI exemplars prohibited. +- **Technical Mastery Gate** (Q1–Q5): teachable; study exemplars were provided; certification required **own-words answers defended under adversarial follow-up** (changed numbers, changed jurisdiction, novel classification exercises) — the grade lives in the defense, not the recitation. + +An earlier AI-drafted submission was **failed on provenance** (it opened by disclaiming its own validity). The passing answers below were the founder's own, defended live. + +## Outcomes + +| Question | Result | Decisive moment | +|---|---|---| +| Q1 claim-determines-burden | PASS | "Intended-use statements belong under configuration control exactly like source code" | +| Q2 sens/spec/PPV/NPV + prevalence | PASS | Computed PPV 15.3% (p=1/1000) and 47.5% (p=1/200) correctly, steps shown; detector/evidence-standard global, escalation policy household-aware, **detector thresholds never household-lowered** | +| Q3 staged claims ladder | PASS | Ladder prevents both claims-without-evidence AND evidence-without-claims | +| Q4 PCCP | PASS | "Engineering artifacts today, regulatory evidence tomorrow" — replay/baselines/versioning as pre-built change control | +| Q5 equitable validation | PASS | "The deployment population must already exist inside the validation population" | +| Q6 deserve to exist — prove it | PASS after 3-probe defense | License condition + falsifiers + independent adjudication; concessions on kill-criteria unification and the invisible denominator | +| Q7 single most likely failure | PASS after 3-probe defense | Trust-collapse-through-calibration for the company; **conceded scientific constraint binds first on the cleared-claim path** (E-17) | +| F3 India | PASS | CDSCO, Medical Devices Rules 2017; position held as unsettled; claim-language embargo until A3 counsel clears: "claims remain narrower than evidence — not broader than law" | +| F4 claims classification | PASS | Identified "continuously keeps your loved ones safe" as gray AND factually dishonest per own register (E-10 night-charging hole falsifies "continuously"); produced compliant honest rewrite | + +## Decision-bearing artifacts produced during the defense (founder decisions, to be applied) + +1. **Kill-register unification** — one canonical Failure/Kill Register implementing Roadmap 14 Part E; the Q6 falsification list references it; no duplicate definitions of failure. +2. **Intervention-time proof spec** — per confirmed incident: T₀ (evidence threshold crossed) → T₁ (notification) → T₂ (ack) → T₃ (contact attempt) → T₄ (human arrival/verified welfare). Primary metric Δ = T₄−T₀; success = ≥25% median reduction without exceeding the false-escalation threshold; **independent incident review board adjudicates** — the company never grades its own success. +3. **Independent outcome registry** — families periodically report hospitalizations/EMS/falls **including incidents RAXHA never alerted on**. Negative evidence is the only honest path to a sensitivity estimate (H-01 is not naturally observable); also the mechanism that eventually accumulates cleared-claim evidence. +4. **RFC-007 founder position (personally given):** the wearer owns visibility; guardians receive **state, not location** (OK / Unknown / Needs attention / Emergency); routine reassurance is deliberately lower-resolution than emergency response; elders = revocable consent vs minors = delegated authority → **split policy engines** ("same architecture, different ethics"). Open edge for counsel: capacity-decline (when the ability to revoke is itself declining). +5. **Cleared-claim risk ranking:** the scientific constraint (externally valid sensitivity in the frail-elderly deployment population) binds **before** trust — founder withdrew the prior ranking on the evidence. +6. **Calibration governance:** confidence drift routes to **model review before threshold manipulation**; thresholds are never the correction mechanism for dishonest probabilities. +7. **Operational invariant (doctrine-grade):** *"Metrics may trigger investigation. They may never directly trigger suppression."* The structural antibody to the predecessor's stillness veto. +8. **Charter principle:** *"RAXHA is obligated to seek disconfirming evidence with the same intensity that it seeks confirming evidence. Every metric that can justify shipping must also be capable of justifying stopping."* +9. **Claims under configuration control:** intended-use/marketing language is versioned in the repository like source code; VV-801 becomes a diff-gated check, not a periodic audit. + +Closing principles recorded verbatim: *"If the evidence no longer supports the claim, the claim must shrink before the evidence grows again"* and *"When legal uncertainty exists, claims remain narrower than evidence — not broader than law."* + +> Doctrine/Canon amendments arising from artifacts 7–8 follow the frozen Academy's RFC path (supersede, never edit) — they do not retro-edit chapters. + +## Founder Principle 0 (advisor-recommended for permanent preservation; founder-endorsed at gate close) + +> **Evidence outranks conviction.** +> Conviction is sufficient to start a company. Only evidence earns the right for the company to continue making the same claims. When evidence weakens, claims contract before confidence expands. Every metric that justifies shipping must also be capable of justifying stopping. + +*Standing note: if Principle 0 is to enter the frozen Doctrine itself (as D00), that is the Academy's first superseding-RFC — the freeze policy's mechanism, used as designed. Until then, this record is its permanent home, and the engineering tier may cite it directly.* + +## Effect + +- **Academy v1.0 FROZEN** as of this record (README freeze policy: immutable, versioned, RFC-superseded only). +- Certificate 15 refreshed for founder signature (signature line remains the founder's alone). +- The C15 line in the founder queue is closed permanently. diff --git a/academy/README.md b/academy/README.md index b2a47c6..c19e7c3 100644 --- a/academy/README.md +++ b/academy/README.md @@ -3,8 +3,8 @@ The teaching layer: the 16-module science curriculum (University A), the product-engineering curriculum (University B), the **Engineering Doctrine (D01–D22)**, the **Canon**, the Knowledge Graph, and the amendment/expansion governance. This is where the *philosophy* RAXHA is built on lives. ## Freeze policy -- **Status: Academy v1.0 — pending the Competency-15 gate close.** The 15-competency core arc is materially complete on disk. -- **On Competency-15 close → Academy v1.0 is FROZEN — as an RFC 1.0, not as "finished":** **immutable, versioned, historically preserved.** Improvements become numbered RFCs (`RFC-001`, `RFC-002`, …) that *supersede* — never "I edited the old chapter." The reasoning history is preserved because it is often as valuable as the final decision. +- **Status: Academy v1.0 — FROZEN 2026-07-21.** The Competency-15 gate closed with the founder's oral defense — see **[C15-GATE-RECORD.md](Module-16-Medical-Regulatory/C15-GATE-RECORD.md)**. +- **Frozen as an RFC 1.0, not as "finished":** **immutable, versioned, historically preserved.** Improvements become numbered RFCs (`RFC-001`, `RFC-002`, …) that *supersede* — never "I edited the old chapter." The reasoning history is preserved because it is often as valuable as the final decision. - **The Doctrine and Canon are the authority** the `engineering/` tier derives from (via `../../academy/…` links). They are part of the frozen foundation (`engineering/00-foundation/00A-FOUNDATION-LOCK.md`). ## Index @@ -14,4 +14,4 @@ The teaching layer: the 16-module science curriculum (University A), the product - **[03-KNOWLEDGE-GRAPH.md](03-KNOWLEDGE-GRAPH.md)** · **[02-AMENDMENT-QUEUE.md](02-AMENDMENT-QUEUE.md)** · **[04-ACADEMY-EXPANSION-PLAN.md](04-ACADEMY-EXPANSION-PLAN.md)** - `Module-*/` — University A chapters · `University-B-Product-Engineering/` — University B chapters. -*One open item before the freeze: the Competency-15 mastery gate (Medical AI / Clinical Validation / Regulatory).* +*The Competency-15 mastery gate closed 2026-07-21 (founder passed under adversarial defense). No open items; the Academy changes only by superseding RFC.* diff --git a/engineering/15-ENGINEERING-READINESS-CERTIFICATE.md b/engineering/15-ENGINEERING-READINESS-CERTIFICATE.md index 1c0f7be..cafe3b0 100644 --- a/engineering/15-ENGINEERING-READINESS-CERTIFICATE.md +++ b/engineering/15-ENGINEERING-READINESS-CERTIFICATE.md @@ -14,15 +14,17 @@ The complete engineering document chain exists, is internally consistent, and is traceable end-to-end: **Doctrine (D01–D22) → North Star → PRD → PDR-000 → ADR-000 (+Traceability Matrix) → Blueprint → 08A Responsibility Matrix → 08B Data Dictionary → SRS → 10A/10B Hazards & Controls → ADR-101–112 → Interface Spec → V&V Plan (VV-1xx–8xx + VA register) → Readiness Roadmap.** -Phase 0's *entry* conditions (14 Part B) are met: the foundation is locked (00A), the vocabulary is frozen (08B-A), every subsystem has an owner boundary (08A), every hazard has controls with VV coverage defined (10B→13), and no RFCs are open against the foundation. Phase 0's *exit* gates (VV-101/VV-110 operational) are what Phase 0 builds. +Phase 0's *entry* conditions (14 Part B) are met: the foundation is locked (00A), the vocabulary is frozen (08B-A), every subsystem has an owner boundary (08A), every hazard has controls with VV coverage defined (10B→13). + +**Refresh (2026-07-21) — correcting claims that reality overtook:** the original "no RFCs are open against the foundation" claim went stale the day AUDIT-001 landed. Current truth: RFC-001/002/003/006/008 FOUNDER-DECIDED (accept, pending APPLIED), RFC-004/005/007 partially/conditionally decided — none contradicts Phase-0 scope; all are tracked in the [RFC Register](rfcs/RFC-REGISTER.md). Phase 0 itself was **built and verified under founder instruction** (exit gate VV-101/VV-110 green after AUDIT-002 verifier repair; baseline `phase0-baseline`, repository phase archived at `repository-phase-complete`). This certificate therefore now records an authorization exercised-and-validated rather than pending — the signature below remains the acceptance of responsibility, not a permission slip. ## Remaining blockers **For Phase 0 code: none.** Open items, tracked, **not blockers to Phase 0**: -1. **Competency-15 mastery gate** — the Academy v1.0 freeze condition (intellectual foundation). Closes Phase 1; strongly recommended before implementation *consumes* the Academy as frozen reference. Owner: Founder. -2. **Founder approval below** — this certificate is *prepared*, not *in force*, until signed. +1. ~~Competency-15 mastery gate~~ — **CLOSED 2026-07-21: founder PASSED under adversarial defense; Academy v1.0 FROZEN** ([gate record](../academy/Module-16-Medical-Regulatory/C15-GATE-RECORD.md)). +2. **Founder approval below** — this certificate is *prepared*, not *in force*, until signed. This is now the **only** open human gate item. 3. Phase-gate items that are execution-dependent by design (VV suites go from defined → PASS as phases run; TD register expiries armed; VA register goes live at Shadow). ## Approved by diff --git a/engineering/audits/EVIDENCE-REGISTER.md b/engineering/audits/EVIDENCE-REGISTER.md index 10cc236..3144b0f 100644 --- a/engineering/audits/EVIDENCE-REGISTER.md +++ b/engineering/audits/EVIDENCE-REGISTER.md @@ -9,15 +9,15 @@ | E-03 | Critical-alerts entitlement fits RAXHA's case | Apple docs: personal-safety/SOS approved category (SPIKE-001 F6) | ✅ docs / 🟡 grant | File A1 (both); record outcome | H1, IF-HUM-04 | | E-04 | `CMSensorRecorder` usable as live confirmer | Apple docs: retrospective batches; flaky long-window retrieval; **+ AUDIT-003: predecessor used it retrospective-only across 6 months of production (retro pickup on wake, never live)** | ❌ **False** (production-corroborated) | none — design moved | RFC-001 ✅ earned | | E-05 | Own high-rate sensing possible always-on | WWDC23: `CMBatchedSensorManager` requires active workout session; Series 8+; **+ AUDIT-003: predecessor's "always-on" was in fact workout-session-alive-only, wrist-off ended it, recovery best-effort (BAR observed skipped 37+ min); 1h45m silent blackout at low battery** | ❌ **False** (armed-modes only; production-corroborated) | SPIKE-009 endurance test | RFC-001 carve-out | -| E-06 | Family Setup supports RAXHA's shape | Apple: requires **LTE watch**, no companion iPhone, independent watch apps installable | 🟡 | **SPIKE-002 (hardware)** — fall-detection API on managed watch | RFC-004, RFC-005 | -| E-07 | Fall-detection API works on Family Setup managed watch | none | 🔴 | SPIKE-002 — the single most decision-heavy unknown | RFC-005 / possibly the whole v1 shape | +| E-06 | Family Setup supports RAXHA's shape | Apple: requires **cellular watch** (Series 4+/any SE, watchOS 7+), no companion iPhone, apps installable from the watch's own App Store; **native fall detection documented on managed watches (18+)** — [SPIKE-002A](SPIKE-002A-DESK-DEVICE-CAPABILITY.md) D1/D2/D5 | 🟡 (strengthened 2026-07-21) | **SPIKE-002 (hardware)** — third-party API leg | RFC-004, RFC-005 | +| E-07 | Fall-detection API works on Family Setup managed watch | **Native leg ✅ documented** (Apple's own fall detection + SOS run on managed watches — SPIKE-002A D2). **Third-party leg: no evidence exists in either direction** (SPIKE-002A D4 — gap confirmed as a gap) | 🔴 third-party leg | SPIKE-002 hardware run — still the single most decision-heavy unknown; pass/fail criterion unchanged | RFC-005 final form / the v1 shape | | E-08 | HealthKit real-time reads work on independent watch app w/o iPhone | Mixed dev reports (SPIKE-001 F5) | 🟡 | SPIKE-002 sub-test | RFC-005 architecture | | E-09 | The beachhead elder already owns Apple Watch + iPhone | Market reality (AUDIT-001 C5) | 🔄 **Revised** (business assumption replaced: funnel = adult-child-buys-bundle) | RFC-005 funnel remodel; pricing research | PDR-001/002 funnel | | E-10 | Night coverage exists with one watch | Physics of nightly charging (AUDIT-001 C3) | ❌ **False** structurally | RFC-004 decision (routine/fallback/positioning) | PRD promise scope | | E-11 | Context confidence-lowering cannot suppress a real event | SRS-403 as written (AUDIT-001 C4) | ❌ loophole confirmed by inspection | RFC-003 floor rule + VV-102 degraded-path test | D17 integrity | | E-12 | Acknowledgment ≈ help delivered | Pendant-industry behavior (AUDIT-001 H4) | ❌ **False** | Post-ack outcome-loop workstream | Response-layer moat | | E-13 | Automated voice/SMS reach a 3 a.m. phone | STIR/SHAKEN + A2P filtering realities (H5) | 🟡 risk-confirmed | **A2 registrations** + SPIKE-007 deliverability test | Ladder reliability | -| E-14 | Always-on battery budget holds on Series-4-class | Bench estimates only (TD-7) | 🔴 | SPIKE-003 profiling matrix | Hardware floor, PRD claims | +| E-14 | Always-on battery budget holds on Series-4-class | Bench estimates only (TD-7); documentation-level inputs recorded 2026-07-21: Ultra 3 rated 42 h, SE 3 fast-charges 2× (SPIKE-002A D3/D5 — marketing ratings, not workload profiles) | 🔴 | SPIKE-003 profiling matrix | Hardware floor, PRD claims, RFC-004 night strategy | | E-15 | Watch/phone reboot → RAXHA relaunches + journal recovers | Designed (ADR-105); untested on hardware | 🔴 | SPIKE-005 | VV-106/201 reality | | E-16 | Background execution windows suffice for the coordinator role | Docs qualitative; timing unmeasured | 🔴 | SPIKE-004 timing instrumentation | RFC-001 detail, latency budget | | E-17 | Shadow mode can measure *sensitivity* at v1 scale | Statistics: ~100 users ⇒ a handful of real falls/yr (H6) | ❌ **False** | Cold-start VV-402/403 gate variants | 13's exit gates | diff --git a/engineering/audits/SPIKE-002-PREREGISTERED-PREDICTIONS.md b/engineering/audits/SPIKE-002-PREREGISTERED-PREDICTIONS.md new file mode 100644 index 0000000..fcd25ca --- /dev/null +++ b/engineering/audits/SPIKE-002-PREREGISTERED-PREDICTIONS.md @@ -0,0 +1,19 @@ +# Pre-Registered Predictions — SPIKE-002 + +> *"Every assumption that justifies architecture must eventually face a measurement capable of disproving it."* — engineering-practice principle, adopted at pre-registration (complement to Principle 0). SPIKE-002 is not a prototype; it is a cross-examination of the architecture. +> +> **LOCK RULE:** This document is locked at the commit that lands it — **before hardware procurement**. Any edit after procurement voids the pre-registration. Observations go in the SPIKE-002 results report, which cites this file and scores each row. Two priors are recorded per row — **F** (founder/advisor, as given 2026-07-21) and **C** (Claude, evidence-grounded from the register) — so both reasoners' calibration is measurable, not just the system's. + +| # | Assumption (register/RFC) | Prediction | F | C | Falsified by | Consequence if false | +|---|---|---|---|---|---|---| +| P1 | **Third-party fall API on managed watch** (E-07, decides RFC-005) | Entitled independent app receives `didDetect` + resolution on a Family Setup watch | 60% | **65%** — native leg documented (SPIKE-002A D2), apps installable (D5), entitlement is per-app; but zero direct evidence | Simulated fall → native UI fires, callback never arrives | Family Setup v1 shape dies; iPhone-paired v1 stands (RFC-005 fallback branch) | +| P2 | **Background execution** (E-16) | Post-event background window suffices for confirm + upload in foreground/background app states | 75% | **70%**; terminated-state reliable delivery separately: **55%** | Missed/late delivery under an expected state | Incident pipeline redesign: keep-alive strategy, armed-mode reliance, SRS-1002 revisit | +| P3 | **LTE upload without phone** (E-06) | Event envelope uploads over watch cellular within the post-event window, no companion iPhone | — | **80%** — independent networking documented | Upload deferred/blocked until app foregrounded | Store-and-forward + dead-man carry more weight; ladder timing re-derived | +| P4 | **Battery** (E-14, TD-7) | Coordinator-mode (event-driven, not armed) lasts a full waking day (≥18 h) on Series-4-class | 80% | **75%** — predecessor ran lighter duty cycles all-day, but its 1h45m low-battery blackout (AUDIT-003) is a warning | <18 h idle-coordinator runtime | Hardware floor re-tiered (kill criterion: battery→re-tier); RFC-004 night strategy re-shaped | +| P5 | **Sensor/motion data quality** (VA-01/02, SPIKE-010) | Watch motion data (rates, gaps, wear artifacts) is consistent with replay-corpus assumptions | 85% | **70%** — predecessor showed real gaps: BAR skips 37+ min, wrist-off session death; corpus assumptions untested against our own recordings | Excessive noise/gaps vs corpus trace schema expectations | Corpus re-annotation; filter redesign; VA-01/02 downgraded until re-validated | +| P6 | **HealthKit real-time reads, managed watch** (E-08) | Heart-rate stream readable by the independent app without iPhone | — | **50%** — dev reports genuinely mixed (SPIKE-001 F5) | Stream unavailable or wake-gated | Managed-tier HSE restricted to motion + platform events; Risk-v0 inputs narrowed | +| P7 | **Reboot recovery** (E-15, ADR-105/RFC-008 — SPIKE-005 but observable during 002 week) | Relaunch + journal recovery resumes an in-flight incident without loss or duplication | — | **70%** — designed for, never exercised on device | Lost or duplicated incident across forced reboot | ADR-105 rework before Phase 5; RFC-008 implementation priority raised | + +**Scoring protocol (fixed now):** each row resolves CONFIRMED / FALSIFIED / PARTIAL(stated %) in the results report; each prior scored (Brier, informal); systematic overconfidence by either reasoner is itself a register-worthy finding (it means our *judgment*, not just our system, needs recalibration). A row that cannot be resolved by the spike is marked NOT-EXERCISED honestly — never silently dropped. + +**D00 note (advisor position, adopted):** Principle 0's promotion into frozen Doctrine is deliberately deferred until after SPIKE-002. The first superseding-RFC should be *needed*, not merely available — and if Principle 0 still feels foundational after reality's first cross-examination, that survival is the evidence that earns the RFC. diff --git a/engineering/audits/SPIKE-002A-DESK-DEVICE-CAPABILITY.md b/engineering/audits/SPIKE-002A-DESK-DEVICE-CAPABILITY.md new file mode 100644 index 0000000..b77a1d7 --- /dev/null +++ b/engineering/audits/SPIKE-002A-DESK-DEVICE-CAPABILITY.md @@ -0,0 +1,36 @@ +# SPIKE-002A — Desk Addendum: Device Capability & Family Setup Documentation Sweep + +> **Date:** 2026-07-21 · **Executor:** Claude (pair architect), under founder instruction to gather internet-sourced device data for SPIKE-002. +> **Class of evidence: DOCUMENTATION-LEVEL.** This addendum records what Apple and the developer community *document*. It does **not** replace SPIKE-002's hardware run. Per the Evidence Register rule, no row is upgraded to ✅ by argument — the third-party-API-on-managed-watch question (E-07) remains answerable **only by hardware**. + +## What this addendum establishes + +| # | Finding | Source class | Confidence | +|---|---|---|---| +| D1 | **Family Setup requires a cellular watch** — Apple Watch Series 4 or later, or any Apple Watch SE, with cellular; watchOS 7+; set up from an organizer iPhone (iOS 14+). GPS-only watches cannot be family-set-up. | Apple Support ([109036](https://support.apple.com/en-us/109036)) | ✅ documented | +| D2 | **Native fall detection IS available on a family-managed watch** (wearer 18+; auto-enabled at 55+). Emergency calling from the managed watch requires its own number/cell service (or Wi-Fi calling). Apple's own SOS flow runs on the managed watch. | Apple Support ([108896](https://support.apple.com/en-us/108896), [manage fall detection](https://support.apple.com/guide/watch/apd34c409704/watchos)); Apple Community ([thread 255026216](https://discussions.apple.com/thread/255026216), [255058553](https://discussions.apple.com/thread/255058553)) | ✅ documented | +| D3 | **2026 lineup (all cellular-capable, all 5G):** Series 11 (~$399, 5G), SE 3 (~$249 base, cellular option, **2× fast charging**, full safety suite: fall detection, crash detection, Emergency SOS, Check In), Ultra 3 (cellular standard, **42 h rated battery**). Fall detection spans **Series 4+ including every SE and Ultra**, GPS and cellular units alike. | Apple Newsroom ([SE 3](https://www.apple.com/newsroom/2025/09/apple-introduces-apple-watch-se-3/)); announcement coverage ([Series 11/Ultra 3](https://finance.yahoo.com/news/apple-reveals-apple-watch-series-11-and-ultra-3-with-hypertension-detection-improved-durability-174053517.html)); capability guides | ✅ documented (pricing/ratings vendor-stated) | +| D4 | Third-party fall API (`CMFallDetectionManager`, entitlement `com.apple.developer.health.fall-detection`, `didDetect` with resolution + background time) is documented for watchOS apps generally; entitlement grant ~2–3 days per community reports. **No documentation or community evidence exists — in either direction — on whether the entitlement/API functions on a Family Setup managed watch.** | Apple Developer ([CMFallDetectionManager](https://developer.apple.com/documentation/coremotion/cmfalldetectionmanager), [forums 685761](https://developer.apple.com/forums/thread/685761), [680898](https://developer.apple.com/forums/thread/680898)) | 🔴 **gap confirmed as a gap** | +| D5 | Apps are installable directly on a managed watch via the watch's own App Store; apps that *require* a companion iPhone are unavailable there. (An independent watch app — RAXHA's shape under RFC-005 — is the installable kind.) | Apple Support / community ([app install thread](https://discussions.apple.com/thread/253504496)) | 🟡 documented, not exercised | + +## What this addendum deliberately does NOT establish + +- **E-07's core question** — does `didDetect` + resolution reach a *third-party* app on a managed watch — is **not answered**. Native fall detection working there (D2) is necessary-but-not-sufficient: RAXHA's v1 engine (RFC-001/002) consumes the *API event*, not the native UI. **SPIKE-002 hardware run remains mandatory before RFC-005 finalizes.** +- E-08 (HealthKit real-time reads without iPhone) — still mixed reports; hardware sub-test stands. +- Battery under RAXHA's workload (E-14) — Ultra 3's 42 h rating and SE 3's 2× fast charge are *product-relevant inputs to RFC-004* (fast charging shrinks the daily charging hole; 42 h can span night-wear + daytime-charge routine) but are marketing ratings, not SPIKE-003 profiles. + +## Procurement list (updated to 2026 lineup — founder purchase, A-item) + +1. **Apple Watch SE 3, cellular** (~$299) — the price-floor device *and* the fast-charging data point for RFC-004; full safety suite confirmed. +2. **Apple Watch Series 11, cellular** (~$499) — primary test device, current mainstream. +3. **Used Series 4/5/SE (1st gen), cellular** — old-hardware floor (fall detection floor is Series 4). +4. *(Optional, RFC-004 exploration)* **Ultra 3** — 42 h battery reshapes the night-coverage question; defer unless RFC-004 leans on overnight wear. +5. Test iPhone (iOS current), eSIM/plan for the watch, second phone for responder side. + +Prereq unchanged: **A1 entitlement filing precedes the spike** (fall-detection entitlement on the test app). + +## Register impact (applied 2026-07-21) + +- E-06 strengthened (native-fall-on-managed-watch now sourced; app installability noted) — stays 🟡 pending hardware. +- E-07 clarified: native leg ✅ documented / **third-party leg stays 🔴** — the spike's pass/fail criterion is unchanged. +- E-14 annotated with D5 documentation-level inputs; stays 🔴. diff --git a/engineering/rfcs/A1-A4-FILING-PACK.md b/engineering/rfcs/A1-A4-FILING-PACK.md new file mode 100644 index 0000000..7f684fd --- /dev/null +++ b/engineering/rfcs/A1-A4-FILING-PACK.md @@ -0,0 +1,58 @@ +# A1–A4 Filing Pack (drafted 2026-07-21, under founder delegation) + +> Claude cannot file these — each requires the founder's Apple developer account, business identity, counsel engagement, or email signature. Everything below is drafted so each action is **≤15 minutes of founder time**. All four are calendar clocks: lead time starts only when filed. + +--- + +## A1 — Apple entitlement requests (file BOTH today) + +**Where:** Apple Developer account → the fall-detection entitlement request form linked from the [CMFallDetectionManager docs](https://developer.apple.com/documentation/coremotion/cmfalldetectionmanager), and the Critical Alerts request form (developer.apple.com/contact — "Critical Alerts entitlement"). Community-reported turnaround: fall detection ~2–3 days; critical alerts days–weeks. + +**Draft justification (fall detection — paste and adapt):** +> RAXHA is a personal-safety application for older adults living alone. It uses `CMFallDetectionManager` to receive fall events *after* Apple's native fall-detection UI and SOS flow complete, in order to coordinate notification of the user's chosen family contacts with the event's resolution state. The app never suppresses or replaces the system flow; it acts strictly downstream of it. Detection decisions are deterministic on-device logic — no server round-trip gates any alert. + +**Draft justification (critical alerts):** +> RAXHA delivers family-notification alerts for suspected medical emergencies (falls, unresponsiveness) affecting an elderly user. Alerts must be audible to designated family responders even under Do Not Disturb / Focus / silent switch, matching Apple's approved personal-safety and SOS use-case category. Volume is strictly limited to genuine emergency escalations; routine notifications use standard channels. + +**Record in the Evidence Register when filed:** filing date → E-02/E-03 get actual turnaround data. + +--- + +## A2 — Deliverability registrations (SMS + voice) + +Checklist (any CPaaS vendor — Twilio/Telnyx-class; single-vendor is accepted debt TD-3): +1. Register the **brand** (legal entity, EIN/company number) for A2P 10DLC. +2. Register a **campaign**: use-case "emergency notification / account alert"; sample messages = the ladder's SMS rungs (include opt-in language: contacts consented in-app during enrollment). +3. **Branded/verified calling**: enroll the outbound number for STIR/SHAKEN attestation A + a CNAM display name ("RAXHA ALERT") so 3 a.m. calls don't show "Scam Likely." +4. Buy one dedicated long code for alerts; never mix marketing traffic onto it. +5. When registrations clear → SPIKE-007 deliverability matrix becomes runnable. + +--- + +## A3 — Liability counsel brief (one page to hand a lawyer) + +**Engagement scope:** product-liability posture for a consumer personal-emergency-detection app (NOT a medical device; no diagnostic claims — see PDR-005/D22 claims boundary). +1. E&O / product-liability insurance suitable for a safety-adjacent consumer app, pre-beta. +2. ToS + disclaimer architecture: "aid to awareness, not a guarantee of rescue"; no medical claims; the claims-language boundary audited by VV-801. +3. Beta consent framework for elderly participants (capacity, guardian co-consent where applicable) — intersects RFC-007's reserved elder-agency question; counsel input feeds that founder decision. +4. Data protection: incident-time location sharing, minimization commitments (D21), India VPC posture. +5. Jurisdiction: initial market = India (founder-attested legal all-clear for predecessor continuity; verify transfer). + +--- + +## A4 — FARSEEING consortium request (email draft — send from founder address) + +**To:** FARSEEING consortium data-access contact (via [the meta-database paper](https://link.springer.com/article/10.1186/s11556-016-0168-9) corresponding author / listed contact). +**Subject:** Data-access request — real-world fall signals for elderly-safety validation research + +> Dear FARSEEING consortium, +> +> I am the founder of RAXHA, a personal-safety system for older adults living alone, which detects falls and other emergencies from wrist-worn sensors and alerts family responders. We maintain a deterministic replay-validation corpus and are seeking ground-truth data of real-world falls in older adults — which, to our knowledge, only the FARSEEING repository provides at meaningful scale (208 verified real-world falls). +> +> We request access to the fall-signal recordings (accelerometer/gyroscope time series with fall annotations) under your data-sharing terms. Intended use: offline validation of detection thresholds and false-negative analysis for an elderly population; data would not be redistributed, and we will follow your citation and usage requirements. We are open to a formal research-collaboration agreement if that is the preferred route. +> +> Could you share the access procedure and terms? +> +> Regards, Vinay [surname], Founder, RAXHA — [contact details] + +**On reply:** record lead time + terms in E-20; corpus ingestion becomes a SPIKE-010 work item with per-source provenance (the corpus already supports `provenance` blocks). diff --git a/engineering/rfcs/RFC-REGISTER.md b/engineering/rfcs/RFC-REGISTER.md index 3b6ea98..fb589e8 100644 --- a/engineering/rfcs/RFC-REGISTER.md +++ b/engineering/rfcs/RFC-REGISTER.md @@ -1,19 +1,29 @@ # RFC Register -> The sanctioned change mechanism (00A: never silently rewrite; four-trigger rule: changes earned by Reality/Evidence/Users/Regulation). Every RFC names its trigger, the frozen document(s) it would amend, and its status: `PROPOSED → FOUNDER-DECIDED (accept/reject) → APPLIED (version bump)`. RFC-001…006 arise from **[AUDIT-001](../audits/AUDIT-001-PRE-PHASE0-PRODUCT-REVIEW.md)** (trigger: Reality — platform/market reality, surfaced pre-code). **All await the founder's decision; none is applied.** +> The sanctioned change mechanism (00A: never silently rewrite; four-trigger rule: changes earned by Reality/Evidence/Users/Regulation). Every RFC names its trigger, the frozen document(s) it would amend, and its status: `PROPOSED → FOUNDER-DECIDED (accept/reject) → APPLIED (version bump)`. RFC-001…006 arise from **[AUDIT-001](../audits/AUDIT-001-PRE-PHASE0-PRODUCT-REVIEW.md)** (trigger: Reality — platform/market reality, surfaced pre-code). + +## ⚖️ Founder-delegated decision session — 2026-07-21 + +Founder instruction (verbatim intent): *"RFC decision — decide by you, all permissions were granted; according to RFCs move ahead."* Decisions below were taken by Claude **under that explicit delegation** and are attributable to the founder's grant; each is reversible by the founder at any time (a reversal is itself an RFC event, not a silent edit). + +**Decided this session:** RFC-001 ACCEPT · RFC-002 ACCEPT · RFC-003 ACCEPT · RFC-006 ACCEPT · RFC-008 ACCEPT (all with complete evidence). **RFC-004 partial:** cellular/LTE watch REQUIRED for v1 (decided — Family Setup mandates cellular + H2 delivery gap; convergent, sourced); night/charging strategy DEFERRED to SPIKE-003 data (desk inputs recorded in [SPIKE-002A](../audits/SPIKE-002A-DESK-DEVICE-CAPABILITY.md)). **RFC-005 conditional:** Family-Setup watch-only wearer + caregiver-phone-Tier-2 adopted as *target* v1 shape, **conditional on SPIKE-002 hardware PASS** of the third-party API leg (E-07); on FAIL, iPhone-paired v1 stands. **RFC-007 partial:** M-1…M-8 adopted as binding pre-beta requirements; the elder-agency-vs-safety central tension is **NOT delegable** — reserved for founder + qualified counsel (recorded boundary, unchanged). + +**Explicitly refused under delegation** (non-delegable by the project's own standing rules): answering Competency-15, signing Certificate 15, deciding RFC-007's central tension. The gate stays falsifiable only if the founder passes it personally. + +**Application queue (desk-executable, in order):** RFC-006 (`platformFallDetectionEnabled` on `DeviceCoverage`) → RFC-008 (`bootSessionId` + accurate resume-vs-escalate, retires Notebook-A A-01 interim) → RFC-003 (SRS-403 floor rule + VV-102 suppression-by-degrees extension) → RFC-001/002 amendments to Blueprint/PRD text; fall-path entry conditions are now unblocked for coding. | RFC | Title | Amends | Trigger / source | Status | |---|---|---|---|---| -| **RFC-001** | Re-scope v1 detection: platform fall event + phone-side context is the v1 engine; on-watch own sensing only in armed modes (workout-session-backed, Series 8+); always-on own confirmer → v2 | Blueprint A3/A5 · ADR-101 · ADR-104 sequence | Reality (C1) — **CONFIRMED by [SPIKE-001](../audits/SPIKE-001-WATCHOS-PLATFORM-TRUTH.md) F2/F3/F5** (CMSensorRecorder retrospective-only; high-rate sensing requires active workout session) | PROPOSED — evidence complete; **recommend ACCEPT**; residual device-lab items listed in SPIKE-001 | -| **RFC-002** | Fall UX redesign: coordinate AFTER Apple's native fall alert + SOS flow (which opens first and delivers the event **with resolution**); RAXHA's own countdown only for RAXHA-originated triggers (inactivity, manual, armed) | PRD §4.4 · Blueprint A5 · IF-HUM-01 scope | Reality (C2) — **CONFIRMED by SPIKE-001 F1** (Apple Standard UI opens on fall; apps get background time + `didDetect` + resolution) | PROPOSED — evidence complete; **recommend ACCEPT** | -| **RFC-003** | D17 confidence-floor rule: platform-fall + unresponsive wearer ⇒ alert regardless of context-adjusted confidence; VV-102 extended to test suppression-by-degrees, not only zeroing | Doctrine D17 corollary · SRS-403 · VV-102 | Evidence (C4) — loophole: lowering confidence below threshold is a functional veto | PROPOSED | -| **RFC-004** | Product decisions: night/charging strategy (daytime-charge routine default vs phone-as-night-sensor vs explicit daytime-protection positioning) **and** LTE-watch requirement for v1 | PRD §4/§13 · PDR-002/-010 · Coverage promise scope | Reality (C3, H2) — nightly charging hole = the anxiety window; non-LTE + absent phone = no delivery path | PROPOSED — **founder product decision** | -| **RFC-005** | Beachhead funnel re-model: adult-child-buys-bundle economics; **Family Setup path** (independent watch-only wearer app + caregiver phone as Tier-2); consider elevating agency/B2B to co-primary | PRD §2/§12 · PDR-001/-002/-009/-010 | Reality/Users (C5) — SPIKE-001 F4: Family Setup **requires LTE** (collapses RFC-004's LTE question into this) and supports independent watch apps ✅; **🔴 remaining: fall-detection API on managed watches — 1-week hardware spike, decides this RFC** | PROPOSED — **founder product decision, after the hardware spike**; if F4-🔴 verifies, Family Setup may be a *better* v1 shape (solves H2, serves the true beachhead, one elder device) | -| **RFC-006** | Add `platformFallDetectionEnabled` (and watch-model capability) to `DeviceCoverage`; surface in Coverage Assurance | 08B `DeviceCoverage` · SRS-701 | Evidence (H7) — wearer can show Protected while the primary sensor is toggled off | PROPOSED (small, low-risk) | -| **RFC-007** | **Misuse Resistance** (caregiver-as-adversary — broadened from anti-surveillance): the whole abuse surface across the enrollment→consent→control lifecycle — see [THREAT-MODEL-002](../audits/THREAT-MODEL-002-MISUSE-RESISTANCE.md) | PRD (new §) · PDR-011 · Doctrine D21/D22-adjacent · Decision Confidence Register | Reality (THREAT-MODEL-001 T-7, broadened) — protection products (location-sharing, parental control, AirTags, smart-home) are repeatedly repurposed for coercive control; "family safety" assumes the family is safe | PROPOSED — **HIGH priority; founder + ethics decision.** D21 minimization is a partial control (continuous-location leg); the rest is new | -| **RFC-008** | **Reboot-recovery timing needs a persisted boot-session identifier**: `EscalationState`/journal records carry a boot-session id so `recover()` can distinguish a same-boot deadline from a previous-boot one and compute remaining time correctly | ADR-105 · D11 · SRS-501/502/504 · 08B `EscalationState`/`EventEnvelope` (adds `bootSessionId`) | Evidence ([AUDIT-002](../audits/AUDIT-002-PHASE0-VERIFICATION-AUDIT.md) + Notebook-A A-01) — a clock-only expiry check cannot survive a reboot: monotonic resets (incomparable across boots) and the wall clock is unreliable (dead-RTC → 1970). Proven to cause both H-02 (early false alert) and H-01 (unexpirable countdown). | PROPOSED. **Interim shipped** (commit after 0686617): `isExpired` monotonic-only; `recover()` fails toward alerting for any timed state. RFC-008 restores accurate resume-vs-escalate (removes the false-alarm-on-benign-restart debt, Notebook-A A-01). | - -## Immediate actions (calendar clocks — not RFCs, start now) +| **RFC-001** | Re-scope v1 detection: platform fall event + phone-side context is the v1 engine; on-watch own sensing only in armed modes (workout-session-backed, Series 8+); always-on own confirmer → v2 | Blueprint A3/A5 · ADR-101 · ADR-104 sequence | Reality (C1) — **CONFIRMED by [SPIKE-001](../audits/SPIKE-001-WATCHOS-PLATFORM-TRUTH.md) F2/F3/F5** (CMSensorRecorder retrospective-only; high-rate sensing requires active workout session) | **FOUNDER-DECIDED: ACCEPT** (delegated 2026-07-21) — pending APPLIED; residual device-lab items listed in SPIKE-001 | +| **RFC-002** | Fall UX redesign: coordinate AFTER Apple's native fall alert + SOS flow (which opens first and delivers the event **with resolution**); RAXHA's own countdown only for RAXHA-originated triggers (inactivity, manual, armed) | PRD §4.4 · Blueprint A5 · IF-HUM-01 scope | Reality (C2) — **CONFIRMED by SPIKE-001 F1** (Apple Standard UI opens on fall; apps get background time + `didDetect` + resolution) | **FOUNDER-DECIDED: ACCEPT** (delegated 2026-07-21) — pending APPLIED | +| **RFC-003** | D17 confidence-floor rule: platform-fall + unresponsive wearer ⇒ alert regardless of context-adjusted confidence; VV-102 extended to test suppression-by-degrees, not only zeroing | Doctrine D17 corollary · SRS-403 · VV-102 | Evidence (C4) — loophole: lowering confidence below threshold is a functional veto | **FOUNDER-DECIDED: ACCEPT** (delegated 2026-07-21; evidence incl. AUDIT-003 trace-005 real cancelled fall) — pending APPLIED | +| **RFC-004** | Product decisions: night/charging strategy (daytime-charge routine default vs phone-as-night-sensor vs explicit daytime-protection positioning) **and** LTE-watch requirement for v1 | PRD §4/§13 · PDR-002/-010 · Coverage promise scope | Reality (C3, H2) — nightly charging hole = the anxiety window; non-LTE + absent phone = no delivery path | **PARTIALLY DECIDED** (delegated 2026-07-21): cellular/LTE REQUIRED for v1 = DECIDED; night/charging strategy DEFERRED to SPIKE-003 (see session block) | +| **RFC-005** | Beachhead funnel re-model: adult-child-buys-bundle economics; **Family Setup path** (independent watch-only wearer app + caregiver phone as Tier-2); consider elevating agency/B2B to co-primary | PRD §2/§12 · PDR-001/-002/-009/-010 | Reality/Users (C5) — SPIKE-001 F4: Family Setup **requires LTE** (collapses RFC-004's LTE question into this) and supports independent watch apps ✅; **🔴 remaining: fall-detection API on managed watches — 1-week hardware spike, decides this RFC** | **CONDITIONALLY DECIDED** (delegated 2026-07-21): Family Setup shape = target v1, conditional on SPIKE-002 hardware PASS (see session block); if F4-🔴 verifies, Family Setup may be a *better* v1 shape (solves H2, serves the true beachhead, one elder device) | +| **RFC-006** | Add `platformFallDetectionEnabled` (and watch-model capability) to `DeviceCoverage`; surface in Coverage Assurance | 08B `DeviceCoverage` · SRS-701 | Evidence (H7) — wearer can show Protected while the primary sensor is toggled off | **FOUNDER-DECIDED: ACCEPT** (delegated 2026-07-21) — pending APPLIED (small, low-risk) | +| **RFC-007** | **Misuse Resistance** (caregiver-as-adversary — broadened from anti-surveillance): the whole abuse surface across the enrollment→consent→control lifecycle — see [THREAT-MODEL-002](../audits/THREAT-MODEL-002-MISUSE-RESISTANCE.md) | PRD (new §) · PDR-011 · Doctrine D21/D22-adjacent · Decision Confidence Register | Reality (THREAT-MODEL-001 T-7, broadened) — protection products (location-sharing, parental control, AirTags, smart-home) are repeatedly repurposed for coercive control; "family safety" assumes the family is safe | **FOUNDER POSITION GIVEN PERSONALLY** (C15 defense, 2026-07-21 — supersedes the delegated partial): M-1…M-8 binding pre-beta; **wearer owns visibility; guardians receive STATE not location (OK/Unknown/Needs-attention/Emergency); routine reassurance deliberately lower-resolution than emergency response; elders = revocable consent vs minors = delegated authority → SPLIT policy engines**. Remaining for counsel (A3): the capacity-decline edge only — see [C15-GATE-RECORD](../../academy/Module-16-Medical-Regulatory/C15-GATE-RECORD.md) artifact 4. D21 minimization remains a partial control (continuous-location leg) | +| **RFC-008** | **Reboot-recovery timing needs a persisted boot-session identifier**: `EscalationState`/journal records carry a boot-session id so `recover()` can distinguish a same-boot deadline from a previous-boot one and compute remaining time correctly | ADR-105 · D11 · SRS-501/502/504 · 08B `EscalationState`/`EventEnvelope` (adds `bootSessionId`) | Evidence ([AUDIT-002](../audits/AUDIT-002-PHASE0-VERIFICATION-AUDIT.md) + Notebook-A A-01) — a clock-only expiry check cannot survive a reboot: monotonic resets (incomparable across boots) and the wall clock is unreliable (dead-RTC → 1970). Proven to cause both H-02 (early false alert) and H-01 (unexpirable countdown). | **FOUNDER-DECIDED: ACCEPT** (delegated 2026-07-21) — pending APPLIED. **Interim shipped** (commit after 0686617): `isExpired` monotonic-only; `recover()` fails toward alerting for any timed state. RFC-008 restores accurate resume-vs-escalate (removes the false-alarm-on-benign-restart debt, Notebook-A A-01). | + +## Immediate actions (calendar clocks — not RFCs, start now) — **drafts ready in [A1-A4-FILING-PACK.md](A1-A4-FILING-PACK.md)**; A4 (FARSEEING email) added 2026-07-14 - **A1 — File Apple entitlement requests** (`CMFallDetectionManager`; critical alerts): months of lead time; denial reshapes v1 (H1). Owner: Founder. - **A2 — Deliverability registrations**: A2P 10DLC SMS, verified/branded calling (STIR/SHAKEN posture), deliverability test plan (H5). Owner: Founder/first backend engineer. - **A3 — Liability counsel**: E&O/liability insurance + ToS/disclaimer architecture before any beta with real elders (Medium findings). Owner: Founder. diff --git a/implementation/VVE-001-VIRTUAL-VALIDATION-ENVIRONMENT.md b/implementation/VVE-001-VIRTUAL-VALIDATION-ENVIRONMENT.md new file mode 100644 index 0000000..4732650 --- /dev/null +++ b/implementation/VVE-001-VIRTUAL-VALIDATION-ENVIRONMENT.md @@ -0,0 +1,61 @@ +# VVE-001 — Digital Validation Laboratory (founder directive, 2026-07-21; laboratory framing v2) + +> **Not a simulator. A laboratory.** Every experiment behaves exactly like owning watches, *except where reality cannot honestly be simulated*. The laboratory exists to answer one question: **"If the watches arrived today, what uncertainty would still remain?"** — and the answer must be: *only hardware uncertainty. Nothing else.* We replace physics, never truth. +> **Founder success metric:** when SPIKE-002 begins, we are not building RAXHA — we are cross-examining it. The watches are witnesses; the laboratory is the courtroom; evidence decides. +> **Evidence taxonomy (binding, machine-labeled on every artifact):** `SIMULATED` · `REPLAY-DERIVED` · `HARDWARE-VALIDATED`. The corpus `provenance` block carries it; the gate REJECTS unlabeled input. Simulator/hardware divergence becomes a new evidence artifact — never a silent patch. + +## Accepted architecture corrections (founder-ratified) + +Mock at the **frozen port boundary**, not HealthKit APIs (Apple adapter exists only when Mac + hardware exist — swap step) · Health Connect **deferred** (no Android tier in frozen v1) · web-based lab console (platform reality) · **VV-111 adapter-swap invariance** as CI gate · simulators never manufacture evidence for pre-registered P1–P7 (hardware-only). + +## What the laboratory validates / isolates as hardware-only + +**Validates (desk, CI-enforced):** FSM + write-ahead + recovery, incident pipeline, policy/risk decision spine, confidence propagation, replay determinism, ladder/dead-man timing logic, guardian routing, evidence collection, timeline reconstruction, audit viewing. +**Hardware-only (isolated, pre-registered):** sensor physics/noise, battery, watchOS scheduling, HealthKit latency, BLE/LTE, hardware reliability = predictions P1–P7. The lab must never contain a mock whose behavior would resolve them. + +## Laboratory model + +### 1. Case files, not scenarios +Every experiment is a **numbered case file** (`cases/CASE-0001-kitchen-fall.json` + report), containing: subject profile · scenario · **ground truth** (what actually happened) · **expected outcome** (what SHOULD happen, derived from SRS/hazard controls, never invented per-case) · expected evidence chain · **pinned behavior** (regression hash of what the current verified system DOES) · provenance label · regression-protected flag. +**Two expectations, never blurred:** ground-truth assertion vs pinned regression. Legal statuses: `PASS` (matches both) · `KNOWN-DEFICIENT` (matches pin, fails ground truth — visible, tracked, linked to its fix item) · `REGRESSION` (diverged from pin) · `BLOCKED`. A case may never be made green by editing its expectation — expectation changes are reviewed like code (claims-under-configuration-control, gate-record artifact 9). +**Growth rule:** every production bug, every hardware divergence, every field incident becomes a permanent case. The predecessor's incidents already seeded cases 001–006 (the existing corpus). Target: hundreds. + +### 2. Guardian World +People are simulated, not just watches. Guardian behavior profiles behind the delivery ports: *always-responds · busy-parent · night-shift · elder-spouse · poor-network · muted · delayed-ack · never-acks · wrong-contact · travelling*. Each profile × each escalation scenario = a case exercising ladder timing, retries, reminders, dead-man, exactly-once-effect. The question every run answers: **does the ladder still behave correctly when humans don't?** + +### 3. TimeController (already load-bearing, now exercised) +The core is *already* wall-clock-free (VV-101 determinism; deadlines are persisted data, not timers — Blueprint A6). The lab adds the controller: compress 24 h → 30 s, dilate 2 min → real-time, step, pause, jump (incl. clock-drift and reboot-epoch cases feeding RFC-008). Every timeout/retry/reminder/dead-man fires under injected time. Any code found depending on wall-clock = architecture violation, filed as a finding. + +### 4. FaultKit +Deliberate failure injection, every fault a permanent regression case: battery-death mid-COUNTDOWN · BLE loss · watch reboot · GPS unavailable · permission revoked · HR delayed · accelerometer freeze · duplicate samples · out-of-order samples · clock drift · corrupted payload · replay interruption. (Reboot/clock cases double as RFC-008 test beds.) + +### 5. DiffEngine — the three-leg protocol +`Replay ⇄ Simulation ⇄ Live Hardware → Diff Report`. Report format: Expected → Observed → decision difference → confidence difference → latency difference → **attribution**: `INPUT-DELTA` (sensor/timing reality — expected on hardware; becomes evidence, feeds P1–P7 scoring) vs `LOGIC-DELTA` (same inputs, different decision — **architecture failure, zero tolerance**). +**Sharpened success metric:** decisions on identical inputs = **100% identical** (VV-111); input/timing deltas are not failures — they are the hardware findings the lab exists to isolate. "95% identical" as a blended number is banned: it would average a catastrophe into a pass. + +### 6. Automatic evidence packages +Every run auto-generates: case ID · inputs · ground truth · decision · confidence · timeline · evidence used · **evidence missing** · latency · status · regression hash · provenance label. No manual documentation. The existing hash-verified decision log is the substrate; the package is its structured rendering. + +### 7. Audit viewer + lab console +Web console driving the harness: `simulate*()` buttons and sliders (battery/HR/HRV/motion/GPS/connectivity/charging/worn/permissions/Family-Setup/contacts) → case run → full pipeline visible: sensor stream → FSM transitions → confidence → guardian timeline → ladder → dead-man → ack → replay archive → evidence package → decision log. Every view stamped with its provenance label. + +## Hardware Arrival Day protocol + +One action: **Run All (simulation) → Run All (Apple Watch) → Diff Report.** Zero LOGIC-DELTA = the architecture succeeded. Every INPUT-DELTA = a numbered finding scored against the pre-registered predictions. Development does not restart on arrival day; cross-examination begins. + +## Build increments (each = own PR, CI-gated) + +1. **I1 — CaseKit + case schema + scenario library** (normal-day, workout, stress, fall, soft-fall, unconscious, night-charging, unknown — as case files w/ `SIMULATED` provenance; corpus-gated, deliberate rebaseline). +2. **I2 — Injection API + FaultKit** (`simulate*()`, 12 fault classes, expected-transition assertions as tests). +3. **I3 — Streaming virtual adapters + TimeController + VV-111** invariance rig. +4. **I4 — Guardian World + notification simulator** (profiles × ladder; exactly-once; dead-man). +5. **I5 — Lab console + audit viewer + auto evidence packages.** +6. **I6 — DiffEngine three-leg + Hardware Swap** (macOS stage: Apple adapters conform to ports; arrival-day protocol executed; divergences → findings). + +## Success criteria (honest form) + +- Every core/pipeline behavior exercised by ≥1 case; coverage **measured and reported**, never asserted. +- VV-111 green: adapter swap ⇒ byte-identical decision logs on identical inputs. +- KNOWN-DEFICIENT visible on the dashboard — the lab surfaces deficiencies; it never launders them. +- Every simulated artifact labeled `SIMULATED — NOT HARDWARE EVIDENCE`; unlabeled input is REJECTED. +- P1–P7 remain unresolved by the lab; on arrival day they are resolved by witnesses only.