Skip to content

Round 2 — verifier V3: whole-package consistency check

Fresh-context, read-only verification of the whole package after round-2 integration, run at about 20:25 BST on 3 October 2026 against planning commit aac4debcd. Saved verbatim; fixes are recorded in the round-2 resolution matrix §7.

I found no new Blockers. All 12 round-2 Blocker resolutions are in place, but cross-document drift is still real: 6 Major and 27 Minor findings.

Verdict

Each of the 12 Blockers (VA-01, VA-02, VB-01, DC-01, DC-02, AC-01, UX-01, UX-02, DS-01, DS-02, AP-01, RT-01) has its resolution text at the locations the matrix cites, and that text resolves the finding. The matrix totals add up (362 findings: 12 Blocker, 186 Major, 134 Minor, 30 Note), and every row's severity matches the source review. Every cited AC, contract-test, fixture, E, U, A and Batch D ID resolves to a definition, and no relative link or anchor is broken. Nothing in scope has disappeared since the pre-round-2 snapshot. Most core rules agree across documents: the reconciliation task key (study × form), the command ledger versus FEAT-024 receipts, no per-project document in interactive transactions, D2-07, the claim contract, and the X-TRACK → X-RECLAIM rename.

What remains is drift that would mislead an implementer: - Study summary states: two incompatible sets of member states for Study.CanonicalSummary (one includes draft_only). - Q-20 notices: a notice trigger ("publication autoUpdate") that cannot fire under D2-01. - C15 v2 and C10 gate: frozen at F1a in programme integration, F1b everywhere else. - Decision timing: Batch D decisions marked "needed by F1a" are scheduled for later sittings and are not F1a entry conditions. - UI-validation gates: the plan's F3–F5 exit lists are missing validations the UX strategy assigns to those gates. - Missing patch files: several documents point readers to drafter patch files that are not in the package.

Findings

ID Severity File:line Finding Evidence Suggested fix
V3-01 Major contracts.md:129, :530; domain-model.md:335; programme-integration.md:152-153 vs consistency-model.md:161, :174-177 Two incompatible definitions of the Study summary's per-reviewer state. Three documents put draft_only on Study. The consistency model says drafts never reach Study and uses a different set of states. A reader following C1 would write Study on first autosave, which AC-R2a-36 forbids. contracts:129 "per-reviewer membership markers (session state draft_only, saved_incomplete, completed or withdrawn…)"; domain-model:335 same list. consistency-model:161 "{state: placeHeld, savedIncomplete, completed or withdrawn; standing…}"; :174-176 "Drafts never reach Study… draft_only state therefore appears on Study only as placeHeld, and only when a Study-writing command recorded it" Use the consistency model's states (placeHeld/…/withdrawn plus standing) in C1, C7 (E20 row), domain-model §5 and programme-integration §3.2, and state that draft_only is read from pmFormSession/pmSessionDraft.
V3-02 Major open-questions-and-assumptions.md:74; acceptance-criteria.md:531; programme-integration.md:1054-1056; notifications-integration.md:186 Q-20's recommendation, and the criterion and catalogue rows built on it, list "a publication autoUpdate" as a cause of "contains outdated annotations". Under D2-01 an autoUpdate writes no revision, and Q-34's derived revisions are excluded from SF5 flags, so this cause can never occur. open-q:74 "when the cause is a support on-behalf-of write, a publication autoUpdate, an adoption remap or a shared-gold revision"; AC-R2d-08 same. versioning-model:744 "autoUpdate (… no revision is written)"; :840 "derived revisions are excluded from SF5 outdated flags"; contracts:331-332 "it writes no revision" Remove "publication autoUpdate" from Q-20, AC-R2d-08, programme-integration §8.2 and the notifications catalogue. Publication effects are already covered by the "form version published" kind.
V3-03 Major programme-integration.md:950, :1113 (N4), :1115 (N6), :1125, :1150, :1075-1076; open-questions-and-assumptions.md:293 (E73), :172 (D3-20) vs integrated-plan.md:1047; contracts.md:81, :86; delivery-operating-model.md:276, :1582 The C15 v2 capture contract and the C10 catalogue additions are said to freeze at F1a in programme integration and E73. The plan, contracts, delivery model and matrix all say F1b. That changes what the F1a dossier must contain. PI:950 "C15 v2 is frozen at F1a (contract)"; PI:1150 "Catalogue additions (C10, at F1a)"; E73 "ADR in W0; frozen at F1a". plan:1047 F1b "C10 catalogue and export disclosure… the C15 v2 capture contract and disclosure hook"; contracts:86 C15 "F1b (contract)"; DOM:1582 "C15 v2 freezes at F1b" Change programme integration §8.2–§9, N4, N6, E73 and D3-20's "Needed by" to F1b.
V3-04 Major open-questions-and-assumptions.md:168, :169, :172, :186, :188, :194, :200, :201, :158, :164, :177, :124, :126, :162 vs delivery-operating-model.md:198-205, :1486, :1488, :1492, :1495; integrated-plan.md:1046; contracts.md:223 The "Needed by" column in Batch D disagrees with the decision calendar and the gate entry criteria. Several decisions marked "F1a" are scheduled for later sittings, and F1a's entry requires only "D2 answered", so C7 (claim contract v2) and C3 (observation markers, "frozen at F1a") could freeze before the owner's answer. D3-17 "F1a (C7)" and D3-16 "F1a (contract)" are in sitting 5 (F3); DOM:1495 gives D3-16 as "F3". D3-20 "F1a (C10)" is in sitting 3. D4-06 "F1a (R1a catalogue)", D4-12 "F1a (markers in C3)" and D4-18 "G0 (mapping)" are in sitting 7. D4-04 and D4-19 (F3) are in sitting 6. D3-06 (F1c) is in sitting 5. D3-12 (F3) is in sitting 7. D3-25 (F4) is at G-NOTIF. D1-07: open-q "G0" vs DOM:1486 "The first production pilot". D1-09: "Before #3932 merges" vs DOM:1488 "Before #3941 rebases". D3-10: "F2 (a), F3 (b, c, d)" vs DOM:1492 "F2" for b and d. plan:1046 F1a entry "D2 answered" only. Pick one gate per decision (or decision part), align the open questions, the DOM §2.8 sittings and §17.1, and add the decisions F1a/F1c/F3 actually need to those gates' entry criteria in plan §6.1. Alternatively, mark the affected contract parts "not frozen until Dn-nn".
V3-05 Major integrated-plan.md:1050, :1051, :1052 vs ux-strategy.md:638, :655, :667, :668, :672; acceptance-criteria.md:519 The plan's F3–F5 exit evidence leaves out UI validations that UX §11 assigns to those gates. U4's "F3 (Fix part)" serves R2d, which freezes at F1a/F2, not F3. plan:1050 F3 "U2, U5 (route part), U7, U10, U12, U30, U33 and U35 (tour)" – missing U4 (Fix), U34, U38. plan:1051 F4 – missing U21. plan:1052 F5 – missing U33. UX:638 U4 "F3 (Fix part), F4"; :655 U21 "F4"; :667 U33 "F3, F5"; :668 U34 "F1c, F3"; :672 U38 "F1c, F3". AC:519 R2d "freezes F1a (C2), F2 (policy revision)" Make plan §6.1 and UX §11 list the same U items per gate. Move U4's Fix part to the gate R2d actually consumes (F2), or add F3 to R2d's freezes.
V3-06 Major methodology-coverage.md:19, :51, :387, :580, :712; ux-strategy.md:21-22, :721, :773; versioning-model.md:17-18; programme-integration.md:168, :234, :512, :628, :767, :793, :809, :951, :975, :1056, :1062, :1190 Body text sends readers to drafter patch files that do not exist in the package (no *patches* file under docs/planning). methodology:19 "companion patches file (methodology-coverage-patches.md)"; :387 "Amendment M (new; exact text in the patches file)"; ux:21-22 "ux-strategy-patches.md"; PI:951 "its full text is in the patches (§3.4)" Replace each pointer with the package section that now holds the text, e.g. prisma-amendments §M, contracts C15, open-questions A-08/A-09/Q-25/Q-20, acceptance criteria rows.
V3-07 Minor integrated-plan.md:577-579 vs acceptance-criteria.md:505, :506, :1563-1564 The plan's R2a acceptance includes compatibility declaration and option-ID validity. The authoritative criteria put both in R2c. plan:577 "11. Compatibility is declared per question version, immutable once pinned… renaming an option keeps answers valid" (R2a). AC-R2c-21, AC-R2c-22; C4-T07/T08 "First release R2c" Align the release: move item 11's first two clauses to plan R2c, or move AC-R2c-21/22 to R2a.
V3-08 Minor acceptance-criteria.md:413 AC-R2a-17 uses the retired collection name. "moved idempotently to pmHistoryCapture" vs domain-model:306 "pmLegacyWriteLedger; was HistoryCapture"; consistency-model:1082 Rename to pmLegacyWriteLedger.
V3-09 Minor acceptance-criteria.md:918, :932, :969 vs :1431, :1434-1435 Lane fixture IDs drift. P2 cites unsuffixed FX-PRISMA-07, whose 07b part is R5b's report assertion. C2 has no criterion or header entry for its fixture part FX-PRISMA-06c. P2 header "FX-PRISMA-07"; AC-P2-09 "FX-PRISMA-07 pass"; §7.2 "FX-PRISMA-07a P2", "07b
V3-10 Minor acceptance-criteria.md:1398-1399 The PRISMA fixture deadlines in §7.1 are later than the releases that first need the parts, which conflicts with §7.1's own rule for other fixture families. "FX-PRISMA-02, 03 and 04 are written before F3… 05, 06 and 08 before F6b", while 02a/04a are R2a, 04b R2c, 06a C1, 06b O1, 06c C2 and 08a P2 (:1414-1436) Express deadlines per part: written by the freeze gate of the part's first release.
V3-11 Minor prisma-amendments.md:22-23 vs domain-model.md:692; open-questions-and-assumptions.md:190, :312 (E92); acceptance-criteria.md:1439 Amendment O freezes at F6b in one place and at F-P in others, yet it is used in P2. prisma:22-23 "B, E, F and O at F6b"; domain:692 F-P "Amendments K, M, N, O"; D4-08 "Needed by F-P"; FX-PRISMA-09 "P2"; E92 "P2 (O)" Choose F-P for O and update prisma-amendments' preamble.
V3-12 Minor acceptance-criteria.md:1161, :827, :886-887 vs integrated-plan.md:919, :1262, :880, :912; delivery-operating-model.md:485 Entry criteria in the acceptance-criteria headers drift from the plan and delivery model. X1 "entry: O1 and R4c" vs plan "O1, R4c, R5a; F6a (C11); D4-09". R5c adds D4-12, which plan:880 lacks. P1 "entry: R0 floor step; X-DEL design join" omits X-IMPORT (plan:912; DOM:485) Align the three headers with plan §5.7–§5.8.
V3-13 Minor acceptance-criteria.md:1122; delivery-operating-model.md:646; programme-integration.md:1040 vs integrated-plan.md:1222, :977; programme-integration.md:84, :1274 X-NOTIF's notice consumers omit R4b in some places. AC:1122 "Notices in R1c, R2c, R3c, R4a"; DOM:646 same. Plan graph "XNOTIF -.notices.-> R4b" Add R4b everywhere.
V3-14 Minor open-questions-and-assumptions.md:37, :73, :222, :243, :279, :308, :385; decision-register.md:191; delivery-operating-model.md:321; methodology-coverage.md:186; versioning-model.md:94, :134, :393, :487, :1017, :1025, :1122, :1206-1214, :1285; domain-model.md:366, :795; consistency-model.md:1485; source-status-inventory.md:448 Bare "F1" remains where F1a/F1b/F1c is meant. The versioning model's E36–E44 table says "F1" while open-questions §2 says "F1a". e.g. open-q E2/E23 gate "F1"; E88 "F1 (markers)"; DOM:321 "the F1 and C15 v2 ADR drafts"; versioning §15.2 column "F1" Replace each with the specific split gate.
V3-15 Minor source-status-inventory.md:303, :305; notifications-integration.md:266, :287 vs programme-integration.md:68, :84, :938, :1158-1159; integrated-plan.md:1357, :1366 The 3 October snapshot of #3964 and #3965 disagrees between documents. inventory:303 "#3964… six commits pushed"; :305 "#3965… eight commits pushed (about 19:30 BST)". PI:68 "#3965 now has eight commits not yet pushed"; PI:1158 "#3964's three commits are local and not yet pushed"; plan:1366 "#3964's commits are not yet pushed" Re-read once and use a single timestamped state in all four documents.
V3-16 Minor open-questions-and-assumptions.md:122; integrated-plan.md:1367; source-status-inventory.md:302; delivery-operating-model.md:1484 vs README.md:110-111 The claim that the ledger and package are untracked is out of date. git ls-files shows the owner ledger, permission matrix and package are tracked; they are committed on this branch (commit aac4debcd), though not yet on main. D1-05 "they exist only as untracked files in a conflicting PR's worktree"; plan:1367 "untracked files". README:110 "committed in this branch's docs/planning/" Reword: committed on the PR #3617 branch, not on main.
V3-17 Minor README.md:26; integrated-plan.md:153 vs delivery-operating-model.md:655; open-questions-and-assumptions.md:118 Counts include the already-decided D1-01. README "nine decisions needed before G0"; plan "Still open… Batch D… (71 questions, nine of them needed before G0)". DOM "Batch D 70" Say eight open D1 questions and 70 open Batch D questions.
V3-18 Minor validation-evidence.md:50 The file is identical to the pre-round-2 snapshot and is now contradicted. The matrix (§8) says it will be updated. "No PR, issue, label, comment or review was created or changed." vs matrix:585-588 (issues #3997–#4000 filed) and plan:1531 "follow-ups filed during round 2" Update it, or mark it pre-round-2 in README item 17.
V3-19 Minor reviews/round-2/round-2-resolution-matrix.md:334 PH-08's stated resolution is not at either cited location. The Where cell says "open questions Q-35; programme integration §11", Note "An aggregate-only production count… (a first read-only attempt on 3 October timed out…)". Neither document contains it (grep) Add the text to Q-35 or programme integration §11, or correct the row.
V3-20 Minor round-2-resolution-matrix.md:261 The DD-06 note is stale against the documents. Matrix: "the 25 September precedence rule is written as a proposal because its source was not re-verified". domain-model:778 "recorded as RECOVERED (… verified…)"; versioning-model:57 lists it as RECOVERED Update the matrix note.
V3-21 Minor round-2-resolution-matrix.md:368 UX-02 points to the wrong document for the AF2 parity exit set. The Blocker's core resolution is present. "AF2 parity exit set named in programme-integration"; it is only at integrated-plan:1341 Point to plan §8.
V3-22 Minor round-2-resolution-matrix.md:128-130, :334 vs programme-integration.md:70; consistency-model.md:58 The package contradicts itself on whether database reads were made. Matrix: "A read-only count on 3 October found no project in production or staging…"; "a first read-only attempt… timed out". PI:70 "Limits: no database reads"; consistency:58 "no database or Atlas reads were made" Say which session made which read-only queries, and scope each "no reads" statement to its drafter.
V3-23 Minor integrated-plan.md:360-361; acceptance-criteria.md:272; domain-model.md:683; programme-integration.md:1221 vs delivery-operating-model.md:133-136 "Owners sign" wording survives the DS-01 resolution. AC-M0-04 is marked confirmed although only its Q-08 part is an owner decision. plan "The FEAT-024, presence and allocation owners sign the C7 identity amendments"; AC-M0-04 "…owners sign… | confirmed". DOM:133 "Every 'owner signs'… becomes a fresh-context agent checklist" Reword to "checklist passes; Chris rules on exceptions". Mark AC-M0-04 PROPOSAL, or split the row.
V3-24 Minor acceptance-criteria.md:492 AC-R2c-08 is confirmed but drops Q-31's condition and includes proposal content. It says "…or for named pilot projects under Q-31(b)… staging pilots need X-STATS-a | confirmed". decision-register:196 Q-31 says "only if gate (b) isn't reached when R2c is otherwise ready"; X-STATS-a is MS-10 (Adopted, a proposal) Restore the condition and mark the X-STATS-a clause PROPOSAL.
V3-25 Minor open-questions-and-assumptions.md:73; integrated-plan.md:1519 vs integrated-plan.md:1043; delivery-operating-model.md:198, :262, :276 The Q-03 catalogue subset has three different deadlines. Q-03 "catalogue at F1… Needed by F1"; plan:1519 "needed earlier, at F1b". G0 exit "the Q-03 catalogue subset answered"; F1b entry "(answered at G0)" Use G0 throughout.
V3-26 Minor acceptance-criteria.md:390 R2a's entry criterion contradicts the soak rule. "entry: R0 deployed and soaked" vs DOM:686 "neither soak holds R2a's build" and plan:554-556 (ships after R0's staging rehearsal; production soak gates production pilots only) Use "R0's staging rehearsal passed; production pilots need R0's production soak".
V3-27 Minor integrated-plan.md:741-742 The R3c text keeps the pre-rewrite X-BATCH definition. "entry requires #3939 merged or its completion definition extracted" vs PI:288-293 (six criteria), DOM:650, AC:631 "X-BATCH if batches are used" Use the readiness source decided at F3, with X-BATCH only if batches are used.
V3-28 Minor integrated-plan.md:605-606, :1005, :918 Allocation refusal is described for shared forms only. A-09 and E65 refuse allocation on every canonical stage from R0. "Proportional shares are refused for shared-form stages until AL1"; "R2b (refusal for shared forms)". A-09 (open-q:389) "every canonical stage, whether… one stage or several… R0 refuses"; AC-R2a-41 Reword to all canonical stages from R0 (E65 guard).
V3-29 Minor integrated-plan.md:354 vs acceptance-criteria.md:269 M0's research acceptance cases differ. plan "A1, A3, A8, A13, A14 and A20–A23"; AC-M0-01 "A1, A3, A7, A8, A11, A13, A14 and A20 to A23" Add A7 and A11 to the plan.
V3-30 Minor decision-register.md:263 The register states the open question D2-09 as if it were settled. "shared-question gold is owned by the first publisher and revised only with a new snapshot (D2-09) or by query (QY)" vs D2-09 recommendation "The second may revise" (open-q:140) Say "per D2-09 (open)".
V3-31 Minor versioning-model.md:760, :1038 vs domain-model.md:584-592 The two collection maps disagree about the policy record. versioning:760 "IssuePolicyRecord… (part of FormVersionIssue)" yet :1038 lists a separate pmIssuePolicyRecord; the domain-model collection list has no such collection Pick one shape and state that the F1a naming ADR decides it.
V3-32 Minor open-questions-and-assumptions.md:264; versioning-model.md:393 vs domain-model.md:685; delivery-operating-model.md:277 E44's gate conflicts. E44 "F1a (contract); R2a"; versioning "at F1". domain:685 and DOM F1c list the VersionedAnnotationFormDataSource port as an F1c AF2 extension point Set E44 to F1c (seam), R2a.
V3-33 Minor acceptance-criteria.md:652, :1418; programme-integration.md:301 The pool-entry event name differs from the glossary. "write a PoolEntryEvent" vs domain-model:384 event StudyEnteredPool in StudyPoolLedger; glossary :521 Use StudyEnteredPool (or record PoolEntryEvent as FEAT-011's alias in §8).

What was checked and found clean

Blockers (all 12 confirmed at the cited locations): - VA-01: versioning model §3.5/§3.6, AC-R2c-21, C4-T07, contracts C4 "frozen at F1a". - VA-02: §6.1 classSeq in the key, C2 key, C2-T07, AC-R2d-11. - VB-01 and DC-02: consistency model §3.3–§3.5, AC-R0-09, AC-R2a-12. - DC-01: CR-2, §11, AC-R2a-20, AC-M0-07. - AC-01: Source and Status on every row, a CONF row for every release including X1, and the named new rows (AC-R2a-26, R3a-15, R4a-42/16/17/15/21, R3d-06, C1-07, R4b-07, UI-11, R3a-18). - UX-01: UX strategy §9 and §10, AC-UX-01..09, PE-05 redefined, realistic-content seed. - UX-02: UX §6.1–§6.3, AC-ALL-24/25, AC-R3a-28, plan R3a/R3b. - DS-01: delivery model §2.1–§2.9, §3.2, §16.2. - DS-02: programme integration §10 and §12 X-ARCH-a..d, delivery model §15 and §16.4. - AP-01: E20/E64, AC-R0-10, C7-T01. - RT-01: X-RECLAIM in programme integration §6.2 and §12, E6 "always", AC-R4a-36..39, C9-T07, delivery model §3.4/§6.3. No X-TRACK residue remains.

Matrix rows sampled (non-Blocker, all 14 sources): - V2-01, 05, 07, 08, 15, 16, 17, 20, 21, 26 - VA-04, 05, 10, 13, 22 - VB-05, 10, 11, 13 - DC-03, 05, 11, 15, 17, 21 - DD-06 (V3-20), 07, 09, 12, 22 - AC-02, 14, 15, 24, 33 - PH-05, 07, 08 (V3-19), 09, 14, 15, 16, 17, 20, 21, 22, 26, 31 - UX-02 (V3-21), 08, 09, 12, 19, 20 - DS-06, 08, 13, 14, 19, 23, 24 - SR-01, 02, 09, 12, 18 - AP-02, 03, 05, 06, 10, 13, 16, 17 - MS-03, 04, 10, 14, 16, 23, 24 - RT-05, 11, 12, 16, 18, 19, 20, 23, 24, 27 - NS-02, 05, 06, 12, 17, 20, 24, 26

Mechanical reference checks: - 577 AC references resolve to 595 defined rows. AC-DC-nn and AC-C15-nn are reviewer aliases mapped in consistency model §18 and C15. - All Cn-Tnn references resolve; C6-T01/T04/T11 resolve through range rows. - FX references resolve, with FX-VM-01..45 in versioning model §14. - D-IDs are in range; E1–E99, U1–U45 and A-01–A-40 are contiguous; amendments A–O are all present. - No broken relative links or anchors. - Matrix totals and per-row severities match the 14 source reports.

Meaning spot-checks (more than 25): VA-01↔AC-R2c-21, VA-02↔C2-T07, AP-01↔AC-R0-10, DC-01↔AC-R2a-20, RT-01↔C9-T07, PV1↔AC-R2a-26, VS1↔AC-R3a-15, RE1↔AC-R4a-16, NT1↔AC-R4a-17, TC1↔AC-R3d-06, QY5↔AC-R4b-07, RE4↔AC-R4a-15, Q-10↔AC-R4a-21, Q-13↔UI-11, amendment H↔AC-R3a-18, AC-DC-06→AC-R2b-11, AC-DC-07→AC-R0-11, AC-C15-02→C15-T02, A16→AC-R2a-14, D2-07↔AC-R2a-37, D3-16↔AC-T-09, D4-21↔AC-P2-01r, E6↔X-RECLAIM, E64↔AP-01, A-09↔D3-13a, M↔D4-07, O↔D4-08, FX-ELIG↔AP-01, FX-APPLIC↔PH-07.

Core rules found consistent: publication writes no evidence (apart from V3-02); task key study × form; command ledger versus FEAT-024 receipts (correlation only); no per-project document on the interactive path; D2-07 wording; the claim contract fields are identical in contracts C7, domain model §4.11, programme integration §6.2 and AC-R2b-12; CanonicalEnrolment and FormVersionIssue naming.

Scope versus the snapshot: no Q, E, U, A, C, L, AC, PE, X, R, F, W or MIG ID was lost. All 227 snapshot AC rows are still defined; the 5 retired IDs are listed with replacements in §4.37. Removed headings are renames only. Dispositions are recorded for E35→E50 and X-TRACK→X-RECLAIM.

Acceptance-criteria sufficiency: every release and lane, including M0, GA, R6, R7 and X1, has numbered rows with a verification method, source and status. Each has a tier, freeze and fixtures header, with pilot-entry rows in §5.2. The gaps found are V3-09, V3-10 and V3-12.

In-flight programme integration: programme integration §2.1 and plan §8 and §5.11 agree on status and on the recommended changes for allocation, batches, eligibility, tracking and claims, FEAT-024 and notifications. Each recommended change maps to a release, gate or join and a Batch D question; the only exceptions are V3-03 and V3-13.

One process note: early on I accidentally created a temporary file, scratchpad/defined_ac.txt, in the session scratchpad. Nothing in the repository or package was created or changed. I left the file in place because the brief also forbids deleting.