Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
<!-- markdownlint-disable-file -->
# Changes Log: Claracle Relaunch Follow-Up Execution

## Related Plans

* .copilot-tracking/plans/2026-08-02/claracle-relaunch-followup-execution-plan.instructions.md
* .copilot-tracking/plans/2026-08-02/claracle-gated-rollout-cost-plan.instructions.md

## Implementation Date

2026-08-02

## Summary

Published the PR review correction, reconciled production GA4/GSC observations, refreshed acceptance evidence, created one owner-action register, and produced implementation-ready rollout and cost plans. External account actions and human approvals remain owner-gated.

## Added

* .copilot-tracking/research/subagents/2026-08-02/claracle-ga4-gsc-followup-research.md
* .copilot-tracking/research/subagents/2026-08-02/claracle-acceptance-gates-followup-research.md
* .copilot-tracking/research/subagents/2026-08-02/claracle-rollout-cost-followup-research.md
* .copilot-tracking/research/2026-08-02/claracle-relaunch-followup-execution-research.md
* .copilot-tracking/plans/2026-08-02/claracle-relaunch-followup-execution-plan.instructions.md
* .copilot-tracking/plans/2026-08-02/claracle-gated-rollout-cost-plan.instructions.md
* .copilot-tracking/details/2026-08-02/claracle-relaunch-followup-execution-details.md
* .copilot-tracking/details/2026-08-02/claracle-gated-rollout-cost-details.md
* .copilot-tracking/plans/logs/2026-08-02/claracle-relaunch-followup-execution-log.md
* docs/review/data-observatory-relaunch/owner-action-register.md

## Modified

* hugo.toml
* docs/growth/ga4-gsc-baseline-2026-07-29.md
* docs/prds/claracle-data-observatory-relaunch.md
* docs/review/data-observatory-relaunch/README.md
* docs/review/data-observatory-relaunch/security-review.md
* docs/review/data-observatory-relaunch/status-of-record.md
* .copilot-tracking/research/2026-08-02/claracle-relaunch-readiness-reconciliation-research.md
* .copilot-tracking/plans/2026-08-02/claracle-relaunch-readiness-reconciliation-plan.instructions.md
* .copilot-tracking/changes/2026-08-02/claracle-relaunch-readiness-reconciliation-changes.md

## Completed Work

* Pushed correction commit `8fddceb` and resolved both PR #647 review threads
* Confirmed production GA configuration on the main site and standalone embed without relying on checked-in identifiers
* Recorded owner-confirmed GA4 stream operation, GSC verification, root sitemap submission, and GA4-to-GSC product link; FR-035 is complete
* Reconciled SEC-01 and SEC-04 with current sanitization and lifecycle tests
* Implemented SEC-02 with a no-referrer official iframe snippet and frame-local explicit-consent tests
* Implemented SEC-03 exact CSV, metadata, nested-object, and source-path allowlists
* Documented the SEC-05 defense-in-depth recommendation and limitations without recording acceptance
* Classified #622 as non-blocking polish and #626 as independent hardening
* Added exact owner actions for analytics, security, accessibility, protected Podcaster, visual, and sponsor evidence
* Planned report-only cost attribution, one dynamic-topic canary, and repository-page activation with rollback

## Validation

* Full pytest: 1,389 passed, 19 skipped, 34 subtests passed
* Focused acceptance suite: 45 passed, 4 skipped
* Ruff lint and format: passed
* Data-page, public dataset, and trend-export checks: passed
* PR #647 at `8fddceb`: 13 successful checks, including Production site
* Editor diagnostics and `git diff --check`: passed
* Security closure focused suite: 217 passed
* Rendered embed/export suite with Hugo 0.161.1: 10 passed
* Public dataset freshness, Hugo production build, internal links, Ruff, and diff whitespace: passed
* Local Playwright analytics execution was attempted but the host lacks Chromium runtime libraries; CI browser execution remains required
* Final local suite after Squad and Google evidence updates: 1,392 passed, 19 skipped, 34 subtests passed

## Known Inherited Discrepancy

`discover_topic_candidates.py --check` reports the candidate registry stale at the inherited commit. Temporary regeneration preserves 2,173 total candidates and the same five eligible candidates while rotating four sanitized keys. The owning publish workflow should refresh this generated state.
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
<!-- markdownlint-disable-file -->
# Changes Log: Claracle Relaunch Readiness Reconciliation

## Related Plan

.copilot-tracking/plans/2026-08-02/claracle-relaunch-readiness-reconciliation-plan.instructions.md

## Implementation Date

2026-08-02

## Summary

Reconciled the Claracle relaunch plans, PRD, BRD, and issue evidence into one status of record. One review iteration corrected stale issue-state claims for closed issues #599 and #644 while preserving the outstanding GA4/GSC launch gate.

## Changes by Category

### Added

* .copilot-tracking/details/2026-08-02/claracle-relaunch-readiness-reconciliation-details.md
* .copilot-tracking/plans/2026-08-02/claracle-relaunch-readiness-reconciliation-plan.instructions.md
* .copilot-tracking/plans/logs/2026-08-02/claracle-relaunch-readiness-reconciliation-log.md
* .copilot-tracking/research/2026-08-01/restore-consistency-640-research.md
* .copilot-tracking/research/2026-08-02/claracle-relaunch-readiness-reconciliation-research.md
* docs/review/data-observatory-relaunch/status-of-record.md

### Modified

* .copilot-tracking/plans/2026-07-29/claracle-data-observatory-relaunch-remediation-plan.instructions.md
* .copilot-tracking/plans/2026-07-31/claracle-deploy-hydration-remediation-plan.instructions.md
* docs/brds/claracle-data-observatory-relaunch-brd.md
* docs/prds/claracle-data-observatory-relaunch.md

### Removed

* None

## Review Iteration

PR #647 review found that #599 and #644 were described as open after both had closed as completed on 2026-08-01. The research and status-of-record artifacts now show the final dispositions. FR-035 remains partial because #599 closed with GSC, platform-receipt, and baseline actions still outstanding; later production verification confirmed secret-backed GA configuration is present.

## Validation

* Focused documentation tests: 10 passed
* PR #647 status checks: 13 passed, 0 failed
* Editor diagnostics: no errors in the corrected files
* Git whitespace validation: passed

## Release Summary

The repository now has one evidence-backed relaunch readiness view. Delivered remediation work is distinguished from pending external acceptance gates, and closed issue state is no longer used as evidence that GA4/GSC acceptance work shipped.
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
<!-- markdownlint-disable-file -->
# Implementation Details: Claracle Gated Rollouts and Cost Measurement

## Cost Experiment Contract

Every variant starts from a clean destination and the same hydrated source state. The machine-readable record must include main SHA, publish SHA, workload variant, source counts by page class, Hugo and Pagefind versions and raw durations, rendered and indexed counts, output bytes, runner identity, exit state, and Actions URL.

Use cumulative variants so marginal cost can be calculated without changing generator logic:

1. Observatory generated classes excluded
2. Five checked-in topic hubs included
3. Three generated data pages included
4. 263 checked-in repository pages included
5. Optional approved dynamic canary included

Do not derive a blocking budget from one run. Retain at least three comparable runs and calculate median plus nearest-rank p95 separately for Hugo and Pagefind.

## Dynamic Preview Contract

A preview must evaluate the same eligible-candidate and assignment path as write mode while performing no filesystem mutation. Its structured output must identify candidate slug, title, evidence weeks, supporting sources, proposed hub path, proposed weekly assignments, registry effect, and skip reason. Tests must compare preview output with the corresponding isolated write transaction.

The first canary uses explicit deferrals in `ignore_topics`; no threshold change is permitted. Threshold-based canaries are unsafe because repository generation can classify existing pages as obsolete.

## Repository Activation Contract

The isolated enabled preflight must preserve the existing recurrence threshold and hydrated publish state. A reviewer must disposition every obsolete or expired path. No removal is accepted from mere crawl absence. The second generation must be byte-stable.

Rollback has two parts:

1. Disable the production flag to stop future mutation.
2. Revert the generated-state transaction to undo pages, ledgers, registries, assignments, and logs already committed.

## Approval Contract

Hermes approves security and lifecycle policy. URL approves workflows, secret scope, and retained artifacts. jmservera separately approves the dynamic-topic canary and repository-page activation. Each approval identifies the exact revision, evidence, conditions, rollback owner, and date.
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
<!-- markdownlint-disable-file -->
# Implementation Details: Claracle Relaunch Follow-Up Execution

## Phase 1: Publish Review Corrections

Commit and push the reviewed #599/#644 state corrections, then resolve the two PR #647 threads only after the changed diff is visible remotely.

Success: commit `8fddceb` is on the PR branch and both threads are resolved.

## Phase 2: Reconcile GA4/GSC Evidence

Keep both checked-in Hugo defaults empty. Record only presence-level production observations and secret names. Never record the GA identifier or GSC token.

Owner handoff completed on 2026-08-02:

1. The deployed ID maps to the intended Claracle stream.
2. The GSC property is verified without requiring the optional HTML-tag secret path.
3. `https://claracle.com/sitemap.xml` was submitted and the GA4 stream was linked to GSC.
4. GA4 is operational, and a GSC performance export was supplied.

Remaining evidence work:

1. Transcribe the supplied GSC performance values once the attachment is available as a readable file.
2. Retain denied and granted production consent observations.
3. Confirm GSC processing and review indexed and excluded URL counts.

Success: FR-035 connection and submission are complete; baseline transcription and NFR-008 production consent evidence remain open.

## Phase 3: Refresh Acceptance Evidence

Update the security record to acknowledge implemented candidate-title sanitization and lifecycle fixtures while retaining Hermes disposition requirements. Add owner-ready evidence records for manual accessibility, visual review, protected Podcaster execution, and sponsor decisions. Do not mark a human gate complete from automated tests.

Protected Podcaster sequence:

1. Confirm downstream idempotency or authorize a specific eligible week.
2. Define required reviewers and branch policy for a real-generation environment.
3. Bind the real generation job to that environment through a separately reviewed workflow change.
4. Run once and retain the approver, week, manifest run, article digest, Actions URL, downstream job ID, and final conclusion.

Success: the acceptance index identifies current automated evidence and exact remaining owner actions.

Repository-executable security closure added on 2026-08-02:

1. SEC-02: generated iframe snippets use `referrerpolicy="no-referrer"`; analytics remains disabled
until explicit consent inside the Claracle frame. Tests cover rendered markup, default-off wiring,
and the existing browser consent behavior. Publisher edits and third-party storage remain stated
limitations.
2. SEC-03: production export code defines and validates exact CSV, metadata, nested ranking, weekly
count, and source-path allowlists. Schema expansion now requires an intentional code and test
change.
3. SEC-05: the record recommends defense-in-depth acceptance for human review while retaining
sanitization, fencing, canary, output/frontmatter validation, prompt lint, and red-team controls.
Semantic paraphrases remain outside phrase-matching guarantees.

These changes provide implementation evidence only. Hermes, URL, and sponsor sign-off remain pending.

## Phase 4: Plan Gated Rollouts and Cost Measurement

Cost experiment:

1. Use one main SHA and one hydrated publish SHA for every workload variant.
2. Measure baseline, topic hubs, data pages, repository pages, and optionally the reviewed dynamic canary.
3. Collect at least three comparable CI runs, preferably five.
4. Retain raw Hugo and Pagefind samples, workload counts, output sizes, medians, nearest-rank p95, absolute deltas, and per-added-page deltas.
5. Keep thresholds report-only until an owner approves the budget and enforcement date.

Repository-page activation:

1. Resolve stable GitHub identity risk or record an explicit accepted-risk disposition.
2. Seed lifecycle parity twice while disabled and require byte-identical output.
3. Run enabled checks and two generations in an isolated checkout at the unchanged threshold.
4. Review every created, rewritten, obsolete, and expired path.
5. Obtain Hermes, URL, and sponsor approval for the exact revision.

Dynamic-topic canary:

1. Review the five eligible candidates and select one unambiguous canary.
2. Add the other four to `ignore_topics` as explicit deferrals.
3. Preview the exact mutation in an isolated checkout because current `--dry-run` is a no-op.
4. Validate hub output, registry changes, weekly assignments, taxonomy, log event, rendered output, and rollback behavior.
5. Obtain security and sponsor approval for one publish transaction.

Success: both rollouts have bounded, reversible execution plans and production flags remain disabled.

## Phase 5: Validate and Review

Run focused tests for workflow mapping, internal links, sanitization, lifecycle, taxonomy, export policy, and documentation. Use PR CI for Hugo, browser, axe, and Lighthouse validation when local binaries or system libraries are unavailable.
Loading