lead-signal punch list landed: no live browser check of P1-P6 since ship,
no curated demo dataset, no narrative script, no async artifact, pilot
guide is the wrong doc for a day-1 interest demo. Clerk after_sign_in_url
fix still blocked on Kisa pulling the production secret. Receipts routing
work parked in favor of this chain per today's priority ruling.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JKggvk1KyHRGytFDPZhbnv
MemPalace retired 2026-07-28 (thin KG, never held a brand fact, empty
tunnel/hallway layer, junk in two of four palace rooms, and a single
test mine burned 20+ min CPU with no way to cancel it short of killing
the server). Replaced by decisions-ledger.md + current-state.md.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
signal-ui/src/main.jsx hardcoded WEBAPP_URL to https://signal-ui-xi.vercel.app
and passed it to signInUrl/signUpUrl/afterSignInUrl/afterSignUpUrl. The
production Clerk instance (clerk.sttilsolutions.com) rejects that origin with
400 origin_invalid on every write path, so sign-in was handed back to an origin
that cannot authenticate. Verified live: POST /v1/client/sign_ins returns 400
from the Vercel origin and 200/422 from signal.sttilsolutions.com.
Redirect target now derives from window.location.origin, overridable via
VITE_APP_URL, so it cannot drift from the deployed domain again. Also replaced
afterSignInUrl/afterSignUpUrl with signInFallbackRedirectUrl/
signUpFallbackRedirectUrl, deprecated in Clerk Core 2.
Build verified: pnpm build succeeds, dead Vercel URL absent from dist output.
NOT verified: a real sign-in completing end to end. Needs deploy first.
Also updates the pilot readiness table: hosted-URL row now names
signal.sttilsolutions.com (confirmed canonical by Kisa 2026-07-27), login row
moved from PASS to OPEN. Honest count 11/13 clean, 1 open, 1 disputed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Aqzsyo1PudjabuV9XQzxwp
Clerk blocker (open since 2026-07-07) root-caused as two faults:
- production Clerk instance rejects the Vercel origin (HTTP 400 origin_invalid);
the missing Google button was a symptom of that rejected /v1/environment call
- after_sign_in_url points at the marketing site, so a successful sign-in
still lands off-app
Pilot readiness corrected to 12/13 while the Vercel link is under test.
Playwright MCP restored (AIOS Group D item 12). KG settled by challenger:
fresh 2-day store, data lives only in the WAL sidecar, palace/Chroma absent.
ACTIVE merged with the earlier session's entry rather than overwriting it,
per the parallel-sessions rule. NEXT extended with the re-derive warning on
AIOS Groups C/D/E (the review assumes 15 agents, there are 16).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016CbDARAjAnpQCnjfUyfeDQ
ACTIVE/NEXT rewritten. Four decision lines added covering the scp verification
failure, the silent-success pattern, the cto-architect PHI verdict, and the
Hazel scope confirmation.
Records an OPEN DISAGREEMENT: Kisa said she does not fully agree with the
Gmail-recovery / ops-steward proposal and stopped before saying which part.
Marked so the next session does not treat it as agreed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011bZhDfpTgToFvDX1CDE8oh
The readiness table warning named only the login row. The "Real PHI blocked
PASS" row rests on the same architecture reading flagged DISPUTED thirty
lines above it, and a reader told "one row is stale" will trust the rest.
Sound as "no supplier data loaded", unsound as "the design excludes PHI".
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011bZhDfpTgToFvDX1CDE8oh
Three corrections, none of which resolve a question that belongs to counsel.
- PHI Architecture: the bullets accurately describe an architecture that
excludes direct identifiers, but they do not establish that Signal is
PHI-free and were being read that way. An internal account number is one
of HIPAA's 18 identifiers. context/current-state.md said the opposite
outright. Both now carry a matching DISPUTED flag pointing at each other,
with instructions to build to the more restrictive reading until Clyde
Mathes replies. Deliberately not resolved here.
- Attorney rows named Bittinger/Nixon. The bundle went to Clyde Mathes
~2026-07-23.
- Readiness table: it reads 13/13 and "100% pilot-ready" as of 2026-06-16,
but the row "Demo login / controlled access working: PASS" is contradicted
by the CLERK LOGIN thread dated 2026-07-07 recording that sign-in fails.
Added a warning not to quote the percentage externally until that row is
re-tested. Re-counting a table doesn't help when a row has gone stale.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011bZhDfpTgToFvDX1CDE8oh
Recipient filled, Florida governing law asserted, NDA 10.2 mirrors LOI S14 arbitration,
signature name aligned to Arkisia Fenn per the executed DocuSign, docx regenerated.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The worklist now shows one row per patient carrying the rollup verdict,
expanding into device coverage lines with doc checklists and rule citations.
Green is earned only from the readiness verdict. Kisa-approved design
(mockup v2, decisions A/B/C/D/E locked 2026-07-07): purple Plan Type Needed
badge + Map-the-plan-type CTA; ◇ column-not-mapped chips; not-processed
strip with download; Data-gaps filter (honest labels, no sixth status);
extended legend; per-line work-queue export (backend lines[] support,
audit-logged). Tabs count patients. SWO/PA cycling is device-scoped and
returns the re-rolled patient through the P4 echo contract; Confirm Visit
fans out across the patient's echoed lines. Legacy table remains at
?legacy=1 (its DOCS_REQUIRED stopgap intentionally kept while it exists —
literal deviation from the plan's remove-in-same-change line, logged).
Independent audit: SHIP; its MEDIUM (line-identity merge collision) and two
LOWs fixed in-commit. 171 backend tests green; frontend builds clean.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Kisa ruling 2026-07-07: failed CSV info must be visible and Signal never acts
on rows whose required information was not provided. Rows that survive
normalization but die in the scoring engine (no coverage rule for the
component) previously vanished from the response; they now append to
skipped_reasons before persistence so the stored count matches what the
supplier saw. Auditor SHIP; its MEDIUM (persist-order) fixed in-commit.
Known bound (auditor LOW, tracked): a dropped component inside an otherwise
scored same-DOS group is covered by the scored line and not separately
reported. 169 tests green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Full client-mapped plan_type pipeline: complete header alias set (bare
'plan'/'plan_name' stay payer aliases), value canonicalization map (Medicare
Part B / FFS / MA / Part C / private / employer etc), unrecognized values
grade Plan Type Needed with a hashed once-per-value warning. Once-per-batch
deprecation fence when records lack plan_type (timing guesses from payer,
legacy; readiness never does). CSVImport mapping review gains Plan Type.
All 66 demo/drift fixture CSVs authored with plan_type columns (variant
headers + variant values on the drift corpus); corpus sweep: 66/66 map, 100%
typed. Echo paths canonicalize through the same value map (audit Low fixed).
_normalize_payer and the default config entry remain untouched (Phase 2c,
Kisa-gated). Independent audit: SHIP. 169 tests green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Ends the override leak: an SWO/PA save now applies to one device's line, not
every device the patient has. doc_status gains device_type ('' = legacy
patient-scoped row, applies until re-saved); the old unique key is dropped by
introspected name and replaced with the 4-col scope key. Staff overrides now
FEED THE VERDICT (device-scoped, staff wins over the CSV cell) instead of
display-only; visit overrides keep their patient-scoped fan-out via
confirmed_visits. PUT /api/doc-status and /api/confirm-visit accept an
optional echo of the patient's lines and return {lines, rollup_status}
recomputed through the same engine (stateless, no batch rebuild). Frontend
minimal fix: doc-status state and writes keyed patient:device. Independent
audit: SHIP (migration reproduced empirically on both old-key shapes; guard
scoped per its nit). 162 tests green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
lead-sttil drafted, ops-steward independently reviewed (6 findings fixed).
Entity name corrected to KJF Professional Services LLC dba STTIL Solutions.
Formation state left as attorney question 1. LOI/NDA v3 live in STTIL-Vault/Projects/Legal.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
core/rollup.py implements the locked truth table: worst gradeable line wins;
a Plan Type Needed line caps the patient at Action Needed; non-gradeable
lines are displayed but never touch the light; no-graded-lines patients carry
None (no label invented). /api/upload gains additive patients[] (one entry
per patient, nested device lines with doc checklists, citations, timing
flags, dedup display fields) and patient_stats (counts patients, not rows).
Flat records payload untouched until P6. Independent audit: SHIP; its LOW
findings fixed (date coercion on timing keys, empty-rollup guard, severity
divergence documented). 151 tests green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
core/rules.py format-tolerant readers + stable registry (R001-R004 plan-scoped,
R100-R102 universal per LCD L33822). payer_rules.json wrapped in the same
commit as both engine readers (coupling hazard closed). Every DocItem now
cites the rule that decided it; NOT_EVALUATED cites nothing. Independent
audit: SHIP (registry-drift test added per its L2 finding). 138 tests green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Readiness verdicts now ride additively on /api/upload and /api/confirm-visit:
- core/worklist_readiness.py: ReadinessIndex — row-to-line membership resolved
through the dedup group key (patient_id, device_type, DOS), never re-derived
from a row's own plan_type (kills a reviewer-reproduced false green)
- RecordOut gains plan_type / readiness_status / readiness_items (additive,
default None); UploadResponse gains readiness_stats (reconciles with rows)
- Minimal plan_type CSV mapping (client-supplied, lowercased+trimmed, never
guessed) per the umbrella reactivation plan; full enforcement lands in P5
- Fixes pre-existing record_lookup miss for order-numbered CSVs; fallback
fields now come from the dedup MergedShipment (latest-non-null, collected
order numbers) so doc_state and the verdict grade from the same values
- confirm-visit normalizes plan_type identically to the CSV path
Verification: 132 tests green (108 baseline + 24 wiring/regression);
adversarial 3-lens review + refutation pass (7 findings confirmed, all fixed,
regression-locked); independent code-auditor verdict SHIP; Pi E2E 33/33.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- docs/build-plans/00-signal-reactivation-plan.md: umbrella re-activation plan
(two-currency logic, critical path, Week1/Week2/backlog sequence with
owners+gates, labABLE-vs-Gaboro call, compliance guardrail, 2026-07-06 findings).
- docs/compliance/fda-cds-exemption-memo-DRAFT.md: attorney-review draft (Fable).
Primary position = Signal is administrative/billing software outside the FD&C
201(h) device definition; CDS-exemption kept as the secondary argument. Citations
grounded against current FDA sources (CDS guidance updated 2026-01-29).
Flags: internal 2026-06-04 whitepaper overstates the CDS claim; attorney of
record unconfirmed (Bittinger/Nixon vs Clyde Mathes).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Captured on Fable before access ends. Two grounded, execute-from starter
templates under docs/build-plans/:
- 01-readiness-model-wiring.md: wire dedup+readiness into the live pipeline
via a post-process orchestrator (avoids the dedup->coverage_calculator
circular import); flags that the normalizer does not yet ingest plan_type,
so every live verdict reads 'Plan Type Needed' until a plan_type column is mapped.
- 02-readiness-model-completion.md: P2-P6 (citation IDs, patient rollup,
device override, plan-type enforcement, frontend nesting).
Readiness+dedup engine verified 57 tests green (2026-07-06); corrects the
stale '73 tests' figure in current-state.md.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Preserves active investor + pilot state (labABLE executed LOI, Robert
Robinson/Gaboro priority path, Puff on hold) into the Signal repo as
the flat auto-memory is retired in favor of the compound + current-state.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Merge Pi's parallel update (AIOS map done). Record dedup+verdict commits
(c07d054, 206bf71), auditor-fixed false-green holes, labABLE brief sent, and
the prioritization decision: Signal pauses at this checkpoint while Claude+Kisa
finish the Insight Engine to July 4; Pi advances Signal UX async.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Grade one coverage line's five documentation items on two separated axes the
old code conflated: required_state (from plan_type + payer_rules.json) and
input_state (SUPPLIED | ABSENT). A line is "Clear to Ship" only when EVERY
required item is satisfied by positive evidence — a required item with no data
is NOT_EVALUATED and blocks green, never granted by absence of contradiction.
- plan_type never guessed: None / unmapped / casing-variant -> "Plan Type Needed",
structurally cannot be green; PECOS/PA sit NOT_EVALUATED while universal items
(SWO/visit/diagnosis per LCD L33822) still grade.
- Required-ness reads from payer_rules.json (single source of truth), removing
the latent Python-set-vs-JSON divergence.
- Config-surface fail-safe: a known plan missing/partial in config cannot grade
green (NOT_EVALUATED), and the green gate checks every item.
- Diagnosis accepts a real ICD-10 code as on-file; only explicit negatives gap.
Additive only: not wired into the live pipeline. 27 tests green (full suite 73),
code-auditor reviewed (H1/H2/M1/M2/M3/M4/L1 fixed).
PROVISIONAL, flagged for Pi/Kisa: gap->label mapping (At Risk/Action Needed/
On Track) and the visit-recency scope boundary (timing layer, not readiness).
Spec: docs/readiness-model-brief-2026-06-23.md section 4
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Group normalized shipment rows into deduped shipments and gradeable
coverage lines (patient -> device -> shipment), the structural fix for the
row-keyed worklist bug (six months of orders no longer = six worklist lines).
- Locked dedup key (patient_id, device_type, date_of_service); order_number
is display-only. Monthly resupplies stay separate, not duplicates.
- Client-mapped plan_type carried through, never guessed from payer name;
conflicting plan types in a group route to "plan type needed".
- Quantity merge: sum across distinct component configs, max within a config
(duplicate guard) with a warning breadcrumb on disagreement.
- CGM gradeable this phase; pumps preserved/displayed but not graded.
Additive only: not yet wired into the live pipeline, grading unchanged.
30 tests green (full suite 46), code-auditor reviewed (M1/M2/L1/L2/L3 fixed).
Design: docs/dedup-design-2026-06-24.md, docs/readiness-model-brief-2026-06-23.md
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- dedup: separate client-mapped plan_type (not payer) so CoverageLine never guesses plan type; fix merge_quantities to sum across distinct component configs (blanket-max dropped qty in mixed dup+split groups)
- convex-spike: shipments orderNumber/hcpcs -> arrays (post-dedup multi-value); de-stale dedup note to LOCKED
- ledger: Design Verification section added
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>