Decision register and traceability¶
Temporary planning document. Planning only, not implementation approval. It lists what Chris has confirmed, what earlier designs recovered, what remains a proposal and what is still open, and where each item lands in the integrated plan. It changes no decision. The authoritative owner record remains the owner decision ledger. Where that ledger and this register disagree, the ledger wins and this register must be corrected.
Precedence rules used throughout the package¶
- A later explicit owner decision supersedes an earlier one. Example: DP6/DP7 supersede the DP1 cross-stage wording that still appears in older sections of the stage/step handoff (lines 118–135). Likewise LC1/RX2 (3 October) supersede eligibility decision D3a (25 September) for the new stage model; that is recorded here, not asked again.
- Recovered baselines are earlier documented designs that Chris has not re-decided but
that the ledger tells us not to reopen. Example:
requireReanswer/autoUpdate/doNothingfrom Annotation Versioning §3.1–3.3. - Proposals are recommendations from earlier drafts, from research (including COMPARISON findings) or from this plan. They need approval before implementation. Earlier drafts marked "UNAPPROVED PRELIMINARY MATERIAL" are inputs only. Their slices and defaults are not binding.
- Open items are genuinely undecided. Provisional assumptions are working assumptions this plan makes so that sequencing can proceed. Each one is listed in open questions and assumptions with the cost of being wrong.
- The v10 Claude Design pack and the April 2026 QM v2 planning are historical evidence. Their Open/Resolved labels do not override the ledger.
- Release names collide across documents. This plan's R0–R7 (with sub-releases such as R2a) are unrelated to FEAT-011's "Release ½/3" checklists, FEAT-001's release "R1", the QM v2 tracker's "R1/R2/R3" column and the "#2461 QM v2 R1 umbrella". The mapping of FEAT-011 checklist items to this plan's releases is in migration §7.
Evidence labels¶
| Label | Meaning |
|---|---|
CODE-MAIN |
Verified in source on main at 78c6d097d (3 October 2026) and re-checked against 2949ca3a7 |
CODE-PR |
Present in an open, unmerged PR at a recorded head; not shipped |
DOC-APPROVED / DOC-DRAFT |
Repository document with that front-matter status; not proof of implementation |
OWNER |
Confirmed by Chris in the ledger, with ID and date |
RECOVERED |
Earlier documented design the ledger says not to reopen |
PROPOSAL |
Unapproved recommendation (earlier draft, research or this plan) |
OPEN |
Undecided; listed in the open-questions document |
ASSUMPTION |
Provisional working assumption made by this plan |
1. Confirmed owner decisions¶
The plan column names the release (R*) or lane (L*) in the integrated plan that delivers each decision. "Engineering" means the behaviour is settled but its mechanism needs a design contract.
1.1 Shared forms, sessions and provenance¶
| ID | Decision (short) | Plan placement | Remaining engineering |
|---|---|---|---|
| SF1 | A form is the project-level evidence/requirement owner. One reviewer-owned study/form session is reachable from every stage that uses the form. | R2a (one stage), R2b (several stages), L1/L2 | Form/version compatibility boundaries; legacy session mapping (E10) |
| SF2 | The form owns its review target. A reviewer contributes once across stages, retries and corrections. | R2a, R2b, L1/L7 | Contribution derivation in statistics and allocation (C7, C8) |
| SF3 | Compatible same-question/same-context answers are shared across overlapping forms; each form keeps its own completion. | R2d, L1 | Context identity contract (C2) |
| SF4/RE3 | The target is a minimum. Every qualifying compatible effective assessment takes part in reconciliation; the UI must handle more than two candidates. | R4a, L6 | Scalable comparison layout (U1) |
| SF5 | Show the reviewer's own prior answer and all ancestor answers across forms and stages, in the exact entity/branch context. Changing shared answers creates a new version and flags other sessions "contains outdated annotations". Fix explicitly creates a current incomplete session version and opens that session's form. | R2d, L1/L5 | Legacy duplicate-conflict detection, stale-base writes (E2) |
| SF6 | A current Complete still counts despite an outdated-answer warning. A recorded action that creates a current incomplete version removes qualification until a valid Complete. | R2d, L1/L7 | Trigger catalogue per recorded action |
| SL1 | Autosave preserves draft history without creating an explicit version on every edit. | R2a, L1 | Drafts contract (E21) |
| SL2 | Save creates an immutable incomplete version. Complete validates and creates an immutable completed version. | R2a, L1 | Atomic version and receipt commit; applicability specification (E23) |
| SL3 | The latest explicit Save or Complete is current. An incomplete Save after Complete removes completed qualification. Autosave alone never supersedes. | R2a, L1/L7 | Projection updates and readiness effects |
| PV1 | Each annotation revision records source stage/step, stage-settings version, question version and the accepted-answer version actually shown. | R2a, L1 | Provenance schema (C3) |
| PV2 | Stage settings are versioned and bind profile/form versions; historical work pins its requirements. | R2a (minimal binding), R2b (several stages), R3a (steps), L4 | Adoption and binding transition UX |
| GS1 | Gold is an immutable, versioned snapshot per study referencing exact reconciled revisions. | R4a, L6 | Snapshot identity, pointer CAS and current selection (E8) |
1.2 Versioning, publication and statistics freshness¶
| ID | Decision (short) | Plan placement | Remaining engineering |
|---|---|---|---|
| FV1 | Adding a question creates a new form version. | R2a (a used version never changes), R2c, L2 | — |
| FV2 | Publishing checks sessions under any prior version and prompts the admin to choose their treatment. | R2c, L2/L7 | Category-specific application (E1); two-phase publication (E22) |
| FV3 | Whether earlier completed contributions count against the new requirements follows the admin's publish-time choice. | R2c, L2 | Reproducible counts |
| FV4 | An admin may later revise an unnecessary update/re-answer requirement, with history; immutable versions and work are preserved. | R2d, L2 | Authority mapping; effects on already-performed work |
| Recovered | Per-question requireReanswer / autoUpdate / doNothing, confirmed by the admin before commit (Annotation Versioning §3.1–3.3). |
R2c, L2 | Application to completed, saved-incomplete and draft-only sessions; option mapping is Q-34 |
| VU1–VU3 | Invalidated answers stay visible as Needs updating; a valid replacement is required before Complete. Optional "Why it changed" and "What reviewers need to do differently" fields; a missing reason warns but never blocks. | R2c, L2/L5 | — |
| PS1 | Use materialized, version-aware usage statistics for form versions and questions. | R2c, L7 | Stage-free usage family with the FEAT-024 owner (C8); production path is Q-31 |
| PS2 | Before publishing, make the relevant statistics current: wait for catch-up, refresh them in a targeted way, or briefly pause reviewing. | R2c, L7 | Protected boundary, fences, pause recovery (E3) |
| PS3 | Publish only when the required statistics are current and the admin's handling choice is recorded; currentness must survive concurrent writes. | R2c, L7 | No timestamp-only race; authoritative affected identities |
1.3 Visibility, blinding and exposure¶
| ID | Decision (short) | Plan placement |
|---|---|---|
| VS1 | Step-level "show reconciled answers to candidate reviewers", with a stage default. Own answers stay visible; other candidates' answers stay hidden. | R3a (setting), R4a (gold exists), L4/L5 |
| VS2 | Agreement statistics separate independent answers from answers given after viewing gold; ordinary progress counts both; record the exact version shown. | R4a (exposure), R5c (statistics), L6/L11 |
| BL1 | Reconciliation identity blinding is stage-owned and consistent across the workspace. | R3a (setting), R4a, L6 |
1.4 Workflow, access and lifecycle¶
| ID | Decision (short) | Plan placement | Remaining engineering |
|---|---|---|---|
| DP6 | Within a stage, the reviewer's own Include opens dependent steps, subject to a collective-Exclude veto. Cross-stage routing is configurable. | R3a, L4 | Propagation/concurrency (E5) |
| DP7 | The cross-stage default is Collective Include required, with an advanced own Include sufficient option. Both keep the collective-Exclude veto. Optional strict within-stage collective mode is a proposal only. | R3a, L4 | Strict mode is OPEN (Q-01); interpretations Q-15 |
| PR1 | PRISMA reports the collective authoritative outcome: a collective Excluded stays Excluded even when extra extraction exists. Preserve that work and its provenance. | R3a/R5b, L12 | Report fixtures |
| EW1 | Stage default Allow finishing previously saved work after collective exclusion, with an advanced per-step override (alternative: preserve only). | R3a, L4 | Surplus assessment record |
| DP2 | A reviewer may deliberately correct their own Exclude to Include from their review history while review is still possible; new immutable submission; no automatic re-invitation. | R3b, L3/L5 | Exact controls (U18) |
| RX2 | Recovered: automatic completion when all studies are resolved, automatic reopening when new studies arrive, manual mode, frozen completed bindings, drafts preserved, status history. | R3c, L4 | Runtime events not yet verified |
| LC1 | Automatic completion also needs no unresolved applicable work, including drafts and corrections. Alert the admin and get confirmation before admitting a change that would reopen a Completed stage. | R3c, L4 | Exact flow is PROPOSAL (Q-02); completion trigger (E29) |
1.5 Screening profiles¶
| ID | Decision (short) | Plan placement |
|---|---|---|
| DP3 | A rule-derived individual decision is confirmed only on explicit submission. Field changes and autosave never vote. Show triggering criteria and own answers as reasoning. | R3b, L3/L5 |
| DP4 | Screening eligibility questions and configuration belong to their profile. Templates are copied, never live-linked. Stages sharing a profile share its answers; separate profiles never do. Reuse the question editor. | R3b, L2/L3/L13 |
| DP5 | Profile On/Off toggle for exclusion-reason reconciliation. Off keeps recorded reasons and history; decision resolution stays separate. | R3b/R4p, L3/L6 (E11 for the Off-collection combination) |
| RX1 | Recovered: decision agreement and supporting-answer agreement are separate. Supporting-answer work appears in the reconciliation of a stage that uses the profile, without duplicate authority. | R4p, L3/L6 |
1.6 Reconciliation, gold and queries¶
| ID | Decision (short) | Plan placement |
|---|---|---|
| RA1–RA4 | Shared pool by default. Optional assignment of a study to an eligible reconciler. Stage expiry default with audited override, applying only to explicitly assigned, unstarted work. Started assignments never auto-expire; admin release keeps saved work and requires reacquisition. | R4a, L6/L8 |
| RA5 | Requesting one additional independent review after the target needs its own Request an additional review capability. The result returns to the reconciler, never sets gold and never changes the target. | R4a, L6/L8 |
| RE1 | Reconciled-answer explanations are optional, even when the answer differs from every candidate. | R4a, L6 |
| RE2 | Final reconciliation submission accepts the valid displayed answers, including prefill. Autofill is clearly marked. Unseen relevant controls trigger a warning; Complete anyway is allowed. No per-field confirmation; validity is still enforced. | R4a, L6/L5 |
| RE4 | One reconciliation task per study and form, reachable through any stage using the form; exact versions pinned. Screening-profile reconciliation is a separate part of the workspace. | R4a, R4p, L6 |
| RE5 | Free text prefills only on exact text match in the same question/version/entity/branch context. No fuzzy matching or normalisation. | R4a, L6 |
| MG1 | Suggest closest entity/cohort matches from labels and answers. The reconciler adjusts and confirms. v10 §4.3 scoring is a proposal; weights are not approved; no ML required. | R4a, L6 (E7) |
| NT1 | Contextual notes stay in candidate annotations; copies keep original authorship. | R4a, L6 |
| UA1 | Required applicable questions cannot be blank in completed candidates; the reconciler decides optional blanks; blank is not N/A. Completeness scope/default and missing-state statistics are proposals. | R4a, L6 (Q-04) |
| QY1–QY7 | Gold stays effective while queried, with a pending flag. One work item per accepted-answer version with per-concern outcomes. Resolve invalidated children before a replacement snapshot. Audited self-review is allowed for query reviewers, though a different authorised reviewer is preferred (QY4). Rejection explanation optional. Per-raiser private notices. Anyone who can view the answer may raise a query. | R4b, L6/L14 |
| QY8–QY9 | A replacement that demonstrably satisfies a concern closes it as "addressed by update". Unsatisfied concerns stay open against their original target and are flagged for current-applicability review. | R4b, L6 |
1.7 Agreement statistics, export and history¶
| ID | Decision (short) | Plan placement |
|---|---|---|
| AG1 | Viewing agreement statistics is a separate grantable capability; it does not come with Reconcile and never exposes candidates. | R5c, L8/L11 |
| AG2 | Multi-select agreement requires identical selection sets; option overlap is shown separately. Agreement alone never publishes gold. | R5c, L11 |
| AG3 | N/A+N/A agree; Applicable vs N/A disagree; compatible differing question versions are compared with clear flags; incompatible versions are not compared automatically. Missing/unanswered treatment is open. | R5c, L11 (Q-04) |
| EX1 | Current answers are the default download. Previous versions and the review state as of a date must also be downloadable. | R2a (versions), R5a (as-of), L11 |
| EX2 | Include all recoverable history, including pre-migration data. No arbitrary cutoff, no fabricated legacy versions. | R5a/R6, L11/L15 |
1.8 Permissions¶
| ID | Decision (short) | Plan placement |
|---|---|---|
| PM1 | Configurable project groups with project- and stage-scoped grants, under Members & groups with permission subsections. Ordinary admins get most or all ordinary permissions by default. Workflow actions get explicit permissions. Holding a capability is not the same as administering it. Ownership transfer stays outside the admin default. | R1b (visibility, owner-only enforcement), R1c (groups), per-feature capabilities, L8 |
| PM2 | The owner can give permission administration to a group, deliberately extending today's owner-only AssignPermissions. Bounded, non-recursive delegation is a recommendation. | R1d, L8 (Q-03) |
1.9 Outcomes, templates and migration¶
| ID | Decision (short) | Plan placement |
|---|---|---|
| OC1 | The first outcome-schema release includes a legacy-compatible schema, an event-count schema and project schema creation/customisation. Field examples are not a mandatory bundle. | Lane release O1, L10 |
| OC2 / ODIR1 | Direction ("greater is worse") is versioned metadata on the outcome measure, with one direction across cohorts in a paper/population and no context override. Different meanings need separate measures. It is never derived automatically from numeric type, and it is neither a numeric validator nor a treatment-effect claim. Conflicting legacy values need reviewed mapping. | O1/O2, L10 |
| TC1 | Templates default to existing legacy entity types (disease model, disease-model intervention, treatment). Cohort, outcome-measure and experiment system types apply only when the extraction/export feature is used. | C1/O1, L9/L10/L13 (E14) |
| MIG1 | Outcome migration planning is authorised; execution is not. | O2/R6, L15 (Q-05) |
| IP1 | Concrete implementation planning is authorised, not runtime code. | This package |
1.10 Setup and operations¶
| ID | Decision (short) | Plan placement |
|---|---|---|
| SET1 | Default screening-profile templates, an encouraged editable initial annotation form, ordinary question-library selection and optional guided preclinical setup. | R1a, R2a, R3b, R3d, L13 |
| SET2 | Guided setup replaces CreateProjectWizard/ProjectSetup; it is not a parallel wizard. | R3d; the old wizard retires at GA, L13 |
| OPS1 | Integrate existing materialized statistics, allocation, active-work tracking and batching, plus project/stage overviews and project/stage/step settings. | All releases, L7/L16 |
| NOTIF (3 Oct addition) | Existing/current/planned notification infrastructure is in planning scope. Planning only; no notifications to project users. | All releases, L14 (notifications integration) |
1.11 Decisions from Chris's review of this package (3 October 2026)¶
These were given after the adversarial reviews, in response to the package. They are recorded here with the identifiers this package uses; the ledger should record them too when its owner next updates it.
| ID | Decision (short) | Plan placement |
|---|---|---|
| UI1 | UI design must be consistent and modern, and every new and updated UI screen uses Material 3. | All releases: UI standard UI-1 to UI-11 and its width matrix (acceptance criteria §3); AC-ALL-08; C17 |
| AC1 | Well-defined acceptance criteria are crucial and must be in the plan. | Acceptance criteria: Source and Status on every row; the traceability check fails on an uncovered decision (AC-S0-04, AC-ALL-16) |
| QD1 | Permanently deleting a question is not allowed once it has been published under the new versioning system. | R2a, C4; adopted questions count as published (migration §3) |
| SEC1 | Fix the unenforced ownership transfer now: owner-only transfer, and no grants of owner-reserved activities. | PR #3964, merged 3 October 2026, 85e6facf7; #3969 closed; R1b entry criterion |
| Q-10 | Make the #3944 reconciliation-conversation changes (reviewer-private one-to-one threads, completed sessions only, exposure record, no editable context link, reconciler eligibility, conversations on their own flag). | PR #3965, stacked on #3947 |
| Q-07 | Pilots are new projects and the seeded projects in the staging and preview environments; add seed projects where helpful. | Acceptance criteria §6; plan §5.10 |
| Q-08 | Harvest the dormant QM v2 stack rather than revive it. | F1a; plan §8 |
| Q-09 | #2224's author has left; harvest its work into R1c. | R1c; plan §8 |
| Q-13 | As recommended: "Library" stays with Study Management; the question area is "Design"; the reusable collection is "question templates". | R1a; C17 |
| Q-03a | As recommended: group create/edit under EditMemberships with anti-escalation; ChangeOwner never grantable; AssignPermissions only through R1d's envelope; Delete as Q-03 decides. | R1c, R1d; C10 |
| Q-25 | As recommended: per-flag routes for production pilots. | Plan §5.11 |
| Q-31 | As recommended: R2c production publication waits for FEAT-024 production readiness; for named pilot projects only, authoritative counting under the same protected boundary if gate (b) isn't reached when R2c is otherwise ready. | R2c; C8 |
| Q-06a | Amendments A, C, D, G, H, I and J approved. Also incorporate ASySD deduplication inside SyRF, as described in the deduplication plans, and manual reporting of deduplication and other steps done outside SyRF for PRISMA diagrams. | PRISMA amendments A–L; P1, P2, R5b |
1.12 Decisions during the round-2 review (3 October 2026)¶
| ID | Decision (short) | Plan placement |
|---|---|---|
| D1-01 | Keep PR #3964 for the ownership-transfer fix. Port #3969's active-member check and its tests into #3964, then close #3969. (#3964 compares the caller with the persisted owner, so a stored ChangeOwner grant cannot bypass it; the policy #3969 relied on can be satisfied by such a grant.) | PR #3964, merged 3 October 2026, 85e6facf7; #3969 closed; programme integration §9 |
Correction recorded against Q-25 (round 2, RT-02). Q-25's recommended route said active reviewer tracking is "not needed for slot-reservation claims". The code shows the opposite: claims, capacity guards and typed admission exist only when tracking is effective, and tracking is off in every deployed environment (on only in the E2E stack). Chris's answer to Q-25 stands for the other flags; the production route for claims returns to Chris as Batch D question D3-16 (open questions).
Answered by the evidence (no decision needed). The RA5 part of Q-10 (requested additional reviewers excluded from conversations until they return their review) is met by #3965's completed-sessions-only eligibility. One reconciliation task per study and form is already RE4; the round-1 "version-compatibility class" in the task key contradicted it and is corrected.
1.13 Batch D1 answered (3 October 2026, evening)¶
Chris approved D1-02 to D1-09 as recommended ("1-8. Yes I agree, approved", in reply to the eight recommendations listed after verifier V3). With D1-01 (§1.12), Batch D1 is complete. Each decision below is the recommendation's text in open questions.
| ID | Decision (short) | Plan placement |
|---|---|---|
| D1-02 | Precedence with the architecture-review roadmap (#3961): its Phase 0 security fixes continue; #3985 and #3973 are F1a prerequisites (X-ARCH-a); #3986 is decided before R0 guards PM consumers; #3988 is folded into E24 or deferred until after R2a; #3989 runs only as L5 seam slices until R3a ships. | Plan §6.1 F1a entry; delivery operating model §15; programme integration §10, §12 (X-ARCH-a to d) |
| D1-03 | ProjectStatistics (#3987): activate the families this plan uses, on a date still to be set; freeze is not chosen, so Q-31(b) is not extended to GA. | Plan §6.1 F1a entry ("#3987 decided"); X-STATS-b1 to b7 on the GA path |
| D1-04 | Implementation is authorised per freeze gate, not per PR: Chris approves each gate's dossier, including its slice list and decisions; merges keep his /approve, batched daily; he keeps every product decision, production enablement and adoption wave. |
Plan §6.1 "Authorises" column and §12; delivery operating model §2, §3 |
| D1-05 | Merge the owner ledger, this package and its research inputs to main now, as a docs-only PR (PR #3617); promote contracts into ADRs and feature specs as they freeze; keep one append-only ledger on main. |
G0 entry (step 0), met: PR #3617 merged on 3 October 2026 (f5318074d); plan §11 and §12 |
| D1-06 | Tester panel: five CAMARADES reviewers and administrators for T1 releases and three for the rest; sessions batched monthly; at least two external SyRF users where possible. The names are still needed for G0. | Acceptance criteria release tiers and §5; UX strategy §9; G0 exit |
| D1-07 | Production opt-in pilots before GA: yes, for new projects whose creators opt in, after the release passes staging acceptance, R0 has completed a production soak and AF2 per-project admission exists; one production pilot per family (R2, R3, R4a) before GA. | Plan §9 (pilots); acceptance criteria §5.2; A-23 |
| D1-08 | Write-path gate: zero engine-caused exhausted submissions at 1, 2, 5 and 10 concurrent reviewers (same study and different studies); absolute p95 budgets set after M0, starting at Save ≤ 150 ms and Complete ≤ 300 ms on a 200-question form; three benchmark tiers (50, 340 and 2,023 questions); E28 in pins and bytes. The start thresholds apply now; F1a confirms them from M0 evidence. | AC-M0-02, AC-ALL-26, AC-R2a-19; M0 go/no-go; F1a |
| D1-09 | Notification merge order: the ownership fix (done, #3964), then #3932 → #3938 → #3941 → #3942 (tolerant preferences) → #3943 → #3944 → #3965 → #3945 → #3947; restack #3965 onto #3944 if the stack owner agrees, otherwise keep it on #3947 and land it in the same train before any environment enables conversations. | Notifications integration merge order; programme integration §8; X-NOTIF |
What G0 still needs. These answers satisfy G0's "D1-02 to D1-09 answered". G0 itself is still Chris's approval of this package, and its entry and exit also need (step 0, D1-05, is met: PR #3617 merged on 3 October 2026): the Q-03 catalogue subset answered, D4-18's mapping part, the tester panel named (D1-06), a date for #3987's activation (D1-03) and the PR dispositions listed in plan §6.1; D3-14 and D3-15 too if S0-4 and S0-7 are to be enabled early. Nothing is built under this plan before G0 (D1-04).
The other decisions the round-2 reviews raised are Batch D2 to D4 in the open questions. None is decided until Chris answers.
2. Superseded wording that implementers must not follow¶
| Superseded text | Where it still appears | Replaced by |
|---|---|---|
| DP1: personal Include carries across stages | Stage/step handoff lines 118–135; parts of COMPARISON and research docs | DP6/DP7 |
| Per-step sessions and targets | Earlier handoff drafts; v10 OD14/OD19 "Prototype currently" | SF1/SF2 |
| Completed stays effective until a new Complete | Older lifecycle wording | SL3 |
| "Questions added: no impact on existing sessions" | Annotation Versioning §3.2 | FV1–FV3 |
One mutable pendingAnswer per Annotation as the draft model |
Annotation Versioning (In-Review) | SL1; the C5 drafts contract (PROPOSAL) |
| Gold = "the latest annotation version on its reconciliation annotation" | Annotation Versioning (In-Review) | GS1 and QY3 snapshot gold |
| Single-annotator studies auto-promoted to reconciled ("SingleAnnotator") versions | Annotation Versioning migration step 6; FEAT-006 design decisions; reconciliation data-model migration; QM v2 RECON-03, MIG-08 | RE2/AG2 (gold needs an explicit final submission); target-1 path is Q-29 |
Rollback by $unset (FEAT-006 D18; FEAT-011 three-level model) |
FEAT-006 design decisions; FEAT-011 | Canonical-aware rollback (research §5); FEAT-011 amendment I (approved, Q-06a) |
| Platform-wide backfill of lifecycle status and screening outcomes (MIG-11, MIG-12) | FEAT-011 Phase 16 | Per-project adoption (MIG1 planning, A-04); FEAT-011 amendment G (approved, Q-06a) |
ScreeningOutcome with one stageId and no legacy authority value |
FEAT-011 lifecycle and source taxonomy | Per-profile outcome with route provenance; amendment H (approved, Q-06a) |
| "Delete Study removes its Citations" | FEAT-011 three-level model | Reversible deletion; amendment J (approved) and Q-33 |
| ASySD runs as an R subprocess | FEAT-012 brief (Draft) | The Approved FEAT-012 service specification: native C# implementation (amendment L) |
| FEAT-012 scenario 1 "delete secondary Study" | FEAT-012 service specification, scenario table | Secondary study kept with status Duplicate, as the scenario's own steps say (amendment L) |
| PRISMA identification counted only from imported records | FEAT-011 flow mapping | Reported external counts for steps done outside SyRF (amendment K, requested by Chris) |
| Agreed answers prefilled and individually confirmed (RD5, FEAT-006 "confirm each") | v10 RECONCILIATION §1, §4.2 | RE2 |
| One reconciliation task per study × step | v10 RD4 / RECONCILIATION §1 | RE4 (study × form) |
| Blinding chosen per profile/form; "most restrictive wins" | v10 RD7 | BL1 (stage-owned); multi-stage tasks per Q-28 |
| Unversioned step reconciliation settings | v10 RD3 | PV2 |
| Screening reconciliation always first; Exclude always hides form reconciliation | v10 RD4/RECONCILIATION §1; QM v2 SCR-06 | Configured dependencies and terminal policy under DP6/DP7; COMPARISON F4 is the research recommendation (PROPOSAL) |
| v10 step settings "who reconciles, per part"; "earlier gold … candidates never see it"; "EDIT RECONCILIATION reopens it" | v10 RECONCILIATION | Stage grants (C10); VS1; GS1/QY route. Dispositions in contracts, C9 (PROPOSAL) |
| Selecting ordinary project questions as screening criteria | Earlier recommendation | DP4 |
| System-catalogue-only outcome schemas in the first release | 27 September restriction | OC1 |
| Open context override for outcome direction | Earlier proposal | ODIR1 |
| Correction re-checks only the edited answer | v10 RECONCILIATION §6 | Not decided: COMPARISON F3 recommends the smallest supported dependency closure (PROPOSAL, R4b) |
pmReference / ImportRecord three-level model |
QM v2 tracker ARCH-07, PRISMA-03 | Publication/Citation/Study (CLAUDE.md domain model) |
| Angular 21 baseline | v10 AGENTS/README, stage-review handoff, QM v2 FORM-01 | Angular 22.1 (current package) |
| Eligibility D3a: no stage closure/reopening state machine | docs/planning/review-eligibility-policy.md (In-Review, 25 Sep) |
LC1/RX2 for the new stage model, by the precedence rule |
| Eligibility D3b: annotation never needs a screening prerequisite | Eligibility policy; ReviewEligibilityPolicyTests.cs:176 |
Kept for independent steps and migrated combined stages; DP6/DP7 for configured dependency edges (Q-24, A-16). D5 (excluded work) is unaffected. |
FEAT-008 Included, Conflict pass-forward; FEAT-010 "stages unordered"; FEAT-026 "no sequential stage-step model" |
Feature docs (In-Review) and #3936/#3939 | DP6/DP7 |
| Global anonymised-candidate invariant; "Annotator A vs B" two columns | FEAT-006 docs, AF2 README | BL1 (stage-owned), SF4/RE3 (more than two candidates) |
| FEAT-001 D28: one global question collection for all AQs with scope and owner fields | docs/features/annotation-versioning/README.md:614; FEAT-006 design-decisions.md:993 |
Project-scoped QuestionDefinition (record GUID, {ProjectId, QuestionId} unique) plus a system-scoped SystemQuestionVersion collection; principle 5 of the domain model (PH-16) |
| FEAT-001 D43: answer versions embedded in the Annotation document | docs/features/annotation-versioning/design-session.md:360 |
Revisions in their own collection, never embedded (VB blueprint, domain-model §1.1) |
FEAT-001 D49: no entity-instance concept; annotationId is the entity identity |
design-session.md:366 |
Entity instances exist: identity = the label head's ID in the author's scope, with rename, withdrawal and duplicate semantics (VB-09); E27 (PH-16) |
| FEAT-001 D50-revised: Study holds no back-references to annotations or sessions, to avoid contention | design-session.md:367-368 |
Study.CanonicalSummary and the Study version bump in every canonical transaction (per-study serialisation, E20); contention is per study, not per project (PH-16, DC CR-1) |
| FEAT-001 D57: versions identified by (rootId, versionNumber), not GUIDs | design-session.md:375 |
Revisions and versions carry GUIDs (client-proposed, validated) plus a per-parent Seq; aggregates with natural keys use deterministic GUIDs (E27, VB-16) (PH-16) |
| FEAT-006 D12: a rationale may be made required per stage | docs/features/reconciliation/design-decisions.md:344, :977 |
RE1 (explanations optional); a required rationale exists only for screening-decision adjudication as a profile setting if Q-32 allows (PH-26) |
| FEAT-006 D15: no annotation reconciliation bypass | design-decisions.md:980 |
Target-1 forms create no task (Q-29, PROPOSAL); bulk approve is Q-11 (PH-26) |
| FEAT-006 D19–D27: reference-first cross-scope sharing, four ownership scopes, an Organisation aggregate, researcher libraries, a community Published flag | design-decisions.md:984-992 |
DP4 and SET1: templates are copied, never linked; template scope per D2-15 (system catalogue plus project copies); no Organisation aggregate in this plan (PH-26) |
| FEAT-006 D33: the reconciliation session is a materialised record on the study document, not an entity | design-decisions.md:998 |
ReconciliationTask aggregate with a ReconciliationSession entity; gold as immutable StudyGold snapshots (GS1, RE4) (PH-26) |
| FEAT-006 D35: cross-stage disagreement resolved by the later stage's reconciler overriding | design-decisions.md:1000 |
One task per study × form (RE4); shared-question gold is revised only with a new snapshot or by query (QY); whether only the first publisher owns it or the second form's reconciler may also revise it is per D2-09 (open) (PH-26) |
| Three releases and sixteen phases; "staging shares the same database" | docs/roadmap/product-features-roadmap.md (Draft) lines 47–63, 295–304 |
This plan's release structure and the delivery operating model; the roadmap is replaced at G0 (PH-21) |
Auto-promotion of single-annotator answers, rollback by $unset, platform-wide backfill |
docs/roadmap/migrations/release-2-migration.md lines 29, 40; release-3-export-prisma.md line 29 |
RE2/AG2; amendment I (canonical-aware rollback); amendment G (per-project adoption) (PH-21) |
| Random-only reconciliation assignment; "Annotator A/B" two-candidate view | docs/user-guide-drafts/FEAT-006-reconciliation-workflow.md lines 31–36 |
RA1–RA5 (pool default plus explicit assignment), BL1, SF4/RE3 (more than two candidates) (PH-21) |
Per-question pendingAnswer autosave as the AF2 draft model |
docs/features/annotation-form-v2/README.md lines 59, 193–204 |
SL1 and the C5 drafts contract (versioning model §7, consistency model §4) (PH-21) |
The inventory §6 gives the full list of existing documents and code to amend in each implementing PR.
3. Dispositions of earlier unapproved proposals¶
These earlier drafts were inputs. This plan's disposition is itself a proposal for Chris.
| Earlier draft | Disposition in this plan | Why |
|---|---|---|
| Preliminary implementation sequence (M0–M8 slices; M1 ordinary pilot as first usable release) | Revised. M0–M8 remain the semantic dependency spine for the common engine. Release boundaries were redrawn twice: first as R1–R7 plus lanes, then, after review, as small releases (R0, R1a–d, R2a–d, R3a–d, R4a/p/b/c, R5a/b/c) with separate freeze and ship gates. | Chris asked not to impose earlier slices silently. Only one ordering is forced by a confirmed decision: queries need gold (QY act on accepted answers). Engine before profiles is a technical choice, not a decision: DP4 requires reuse of the shared editor and engine, not a sequence; canonical screening decisions need the engine, so the order is kept and labelled PROPOSAL. As-of export (R5a) and agreement (R5c) no longer wait for PRISMA identification or each other. See integrated plan §5. |
| Permission matrix | Adopted as the proposal to approve (Q-03, with Q-03a in Batch A), with one change: new capabilities ship with the feature that uses them, never as inert switches | Matches PM1/PM2 and the RBAC research; avoids exposing permissions that do nothing |
| RBAC research | Adopted as background and acceptance cases | Primary-source grounded |
| Lifecycle/gold settings | Adopted as proposals for Q-02 (LC1 flow) and Q-04 (gold completeness, missing-state statistics) | Settled policy is kept separate from mechanisms still to approve |
| Access-policy strict mode | Deferred behind Q-01. R3a ships the confirmed defaults and advanced option; strict mode is designed so it can be added in R3c as a tighten-only setting. Assumption A-18 departs from this proposal's "personal policy + no own decision" rule (Q-15, part b). | DP7 marks strict mode a proposal; the full scope keeps it as a candidate, not a release blocker |
| Guided setup/templates | Adopted with re-sequencing: question templates and import in R1a, initial form in R2a, profile templates in R3b, replacement wizard in R3d, extraction shape after O1 | Follows real dependencies |
| Statistics/allocation/batching integration | Adopted as the contract amendment list for the owning programmes (C7, C8), plus lane release AL1 for shared-form allocation. The plan doesn't take over their PRs. | OPS1 |
| Outcome migration plan | Adopted as the proposal for Q-05, with the default-value rules added, sequenced as O2 after O1 and the PRISMA identity gate | MIG1 authorises planning only |
| PRISMA A–F amendments | Adopted as required amendments through the FEAT-011 change policy, extended with G–L and consolidated in PRISMA amendments. Chris approved A, C, D and G–J (Q-06a) and asked for K and L; B, E and F (Q-06b) remain open, before F6b | Approved source specs are not silently changed |
| Publish-pause queued-retry UX | Kept as a recommendation (U5), not built until approved | The ledger explicitly marks it unapproved |
| v10 IMPLEMENTATION_PLAN S0–S10 | Superseded by this plan's lanes; v10 acceptance walkthroughs are reused as acceptance scenarios where they agree with the ledger | COMPARISON F8: S0 too broad, S8 after S7 wrong, S9 too late, S10 missing dependencies |
4. v10 register crosswalk (44 entries)¶
| v10 ID | Current status | Plan placement |
|---|---|---|
| RC10 | Split. Screening decisions: recovered, profile rules re-run after a submitted correction, with manual work only if still needed. Annotation-form gold: candidate agreement after a correction never confirms gold automatically; the reconciler's final submission is required (RE2, AG2, SF4, RE5) | R4b, L6 |
| RC9 | DP5 settles the toggle; collection-Off combination is E11 | R3b/R4p |
| RC6 | Open UI choice: per-step Skip/handoff versus study-level Skip (U2) | R3a |
| RC8 | Open layout choice: population context placement (U3) | C1 |
| X2 | TC1 settles template defaults; catalogue checks are E14 | C1/O1 |
| X3 | RX1 recovered | R4p |
| OD1 | DP6/DP7 settle routing; strict mode is Q-01; profile-version evolution remains open (Q-26) | R3a, R3b |
| OD2 | Engineering: partial combined-step reservations (E5) | R3a |
| OD3 | DP2 settles | R3b |
| OD4 | SF4/RE3 settle participation: every qualifying assessment takes part, and SF4 forbids choosing a subset; what remains is display and performance for many candidates (U1) | R4a |
| OD5 | Recovered invariant: route warnings never reveal votes (U5 copy) | R3a |
| OD6 | PM1/PM2 settle the architecture; the matrix is Q-03; which transitions need explicit confirmation remains open | R1b–R4a |
| OD7 | DP4 settles ownership; storage representation is engineering | R3b |
| OD8 | DP3 settles | R3b |
| OD9 | OC1 settles initial scope; field specs are E12 | O1 |
| OD10 | FV1–FV3 settle the publication check; schema-upgrade UX is engineering | O1, R2c |
| OD11 | ODIR1 settles | O1 |
| OD12 | Follow-up breadth after C2: rule chaining, set algebra, ontology authoring, population merging and cross-type count solving; no release assigned (follow-up) | After C2 |
| OD13 | Engineering: evidence-based legacy session mapping (E10) | R6 |
| OD14 | SF1 settles | R2a, R2b |
| OD15 | PV1/PV2 settle | R2a, R3a |
| OD16 | Engineering and owner approval: cascade effects of cross-stage corrections (Q-27) | R3a |
| OD17 | GS1/EX1/EX2 settle the intent; manifests are E8 | R5a |
| OD18 | RX2/LC1 settle; exact flow Q-02 | R3c |
| OD19 | SF2 settles | R2a, R2b |
| OD20 | SL1–SL3 settle; drafts contract is E21 | R2a |
| RD1 | MG1 settles; weights E7 | R4a |
| RD2 | One-sided items keep provenance; RE2 acceptance applies; no per-field confirm. Prefill applies only to matching answers (RE2, RE5), so whether an item recorded by only one reviewer is prefilled remains open | R4a |
| RD3 | PV2 supersedes unversioned step settings | R3a/R4a |
| RD4 | RE4 settles | R4a |
| RD5 | RE2 supersedes | R4a |
| RD6 | RE5 settles | R4a |
| RD7 | BL1 settles | R4a |
| RD8 | PM1 settles; Members & groups page is in scope (L8) | R1b, R1c |
| RD9 | RA1–RA4 settle assignment; bulk reassignment remains open | R4a |
| RD10 | Profile resolution routes: extra votes (R3a), RA5 capability (R4a), adjudication (R4p) | R3a/R4a/R4p |
| RD11 | RE1 settles | R4a |
| RD12 | FV4 settles | R2d |
| RD13 | GS1 settles; "v2.1" is display only | R4a |
| RD14 | AG2/AG3 settle parts; formula and missing states remain (Q-04, E9) | R5c |
| RD15 | Declared resolved in v10: outcome reconciliation matrix and dialog | R4c |
| RD16 | Declared resolved in v10: keep the shipped matrix/dialog/spreadsheet pattern | Existing (CODE-MAIN: AF2 outcome summary matrix, cell editor with spreadsheet grid, graph-region assignment); extended in O1 |
| RD17 | Open: 4a+3a recommendation; must scale to more than two candidates (U1) | R4a |
| RD18 | AG1 settles agreement access; non-admin pool visibility follows Q-03 | R4a/R5c |
5. QM v2 requirement crosswalk (April 2026 tracker, 101 requirements)¶
The QM v2 requirements tracker is Approved planning context. Phases 1, 2, 2.1 and 2.2 are documentation-complete; Phases 3–16 are pending. Code for M001–M004 exists only on open PRs (#2461, split as #2572–#2575) and was never wired to the API. The tracker's own "R1/R2/R3" release column is unrelated to this plan's releases. This crosswalk keeps every requirement group visible.
| Group | Disposition | Plan placement |
|---|---|---|
| ARCH-01, ARCH-02 | Complete (Phase 1). ARCH-02 refers to Angular 21 signal forms; re-verify against Angular 22.1 | — |
| ARCH-03 (scope/owner/derivedFrom), ARCH-04 (Study optimistic concurrency), ARCH-05/06 (question and question-set collections) | Retained as engine/versioning candidates; collection layout is decided in the C1/C2 contracts, not presumed | R2a, L1/L2 |
ARCH-07, PRISMA-03 (pmReference, ImportRecord) |
Superseded by Publication/Citation/Study | L12 |
| PRISMA-01..04 | Complete as the Approved FEAT-011 package | L12 |
| PRISMA-05..07, DEDUP-01..08, EXP-05/06 | Retained in the PRISMA lane; amendments A–J apply | P1, P2, R5b |
| QM-01..05 (draft question, assign to disabled stage, DQ→AQ on stage enable) | Revised: activation happens through form publication with impact prompts (FV1–FV3), not stage enablement | R2a, R2c, L2 |
| QM-06..12, QM-14 (structural/content split, AQV, QSV, ancestor integrity, library, history/diff, version badge) | Retained (QSV becomes the form-version selection; see contract C4) | R2a, R2c, L2 |
| QM-13 (admin decision framework) | Retained and extended to any prior form version, the three session categories and shared cross-stage use | R2c, L2 |
| FORM-01/02 (signal forms) | Revised: AF2 on main is the reviewer form; reuse it rather than rebuilding |
L5 |
| FORM-03 (per-question autosave creating AnnotationVersions) | Revised by SL1: autosave is draft-only | R2a, L1 |
| FORM-04/05 (immutable SessionVersion with explicit revision IDs) | Retained, adapted to form sessions shared across stages | R2a, L1 |
| FORM-06..08 | Retained (FORM-08 candidate isolation is VS1); check AF2 parity and the stale virtual-scroll PR #3017 | L5 |
| PGRP-01..04 (custom groups; backend in PR #2224, incomplete frontend) | Retained under PM1/PM2 | R1c, L8 |
| RECON-01, 02, 04, 05 | Revised to GS1 snapshots and SF4/RE3 participation | R4a, L6 |
| RECON-03 (SingleAnnotator auto-promotion when MinAnnotators = 1) | Revised: no automatic promotion; target-1 path is Q-29 | R4a, R6 |
| RECON-06 (random only, no claiming) | Revised by RA1–RA4: pool default plus optional admin assignment. "Reconcilers still don't cherry-pick studies" is PROPOSAL (from RECON-06 and v10 r2) |
R4a |
| RECON-07 (annotators never see other candidates' answers) | Retained as VS1 candidate isolation (with FORM-08) | R3a/R4a |
| RECON-12 (anonymised candidate presentation) | Retained as BL1 | R4a |
| RECON-08 (reconciler's own annotation) | Retained, read through RE2: final submission is the reconciler's acceptance | R4a |
| RECON-09 (bulk approve) | Open (Q-11): not confirmed or rejected by the ledger | After R4a |
| RECON-10 (scope = current stage question set) | Revised by RE4: study × form task | R4a |
| RECON-11 (cross-stage visibility per stage) | Revised by VS1: step policy with stage default | R3a/R4a |
| RECON-13..16 | Retained; formulas need approval (E9, Q-04) | R5c |
| RECON-17 (optional per-answer rationale) | Retained (RE1) | R4a |
| SCR-01..05, SCR-07, FILT-01..05, STAGE-01..04 | Retained, revised by DP4–DP7, RX1 and PV2 | R3a, R3b, L3/L4/L12 |
| SCR-06 (screening reconciliation must come first) | Superseded by configured routing under DP6/DP7 | R3a/R4p |
| MIG-01..07, MIG-09..14 | Revised into the reviewed, per-project adoption programme (no blanket rewrite) | L15, R6 |
| MIG-08 (single-annotator studies auto-promoted) | Revised: no automatic promotion at adoption (Q-29) | R6 |
| EXP-01..04 | Retained | R2a/R5a, L11 |
| SHARE-, AQM- (deferred v2) | Still deferred; AQM-01 impact assessment is now core (FV2) | R2c |