Programme phases 0–3 implementation audit¶
Updated 2026-09-24. The 3B reviewer-annotation row below is corrected: #3567
merged 2026-09-23 (6e72eb37b515523207006c2787bbe2391af38f95), delivering the producer/calculator/baseline
this matrix originally recorded as missing. See STATUS.md for the full current reconciliation.
Audit started 22 September 2026 against main 9ddb8ec659bd63fa3b7b9fb65a05bad205471790.
This uses the programme's approved phase numbers. Implementation authorization is not acceptance,
merge, deployment or activation authorization. The latest instruction authorizes implementation of phases 0–3 followed by phases 4–6,
with independent work in parallel, while preserving those gates. This is a live evidence matrix, not a claim every listed
test has been rerun or every phase is complete.
The matrix below records the starting audit. The 22 September implementation inventory records the subsequent baseline, daily observation, history, consumer and fleet PRs and their combined regression evidence. Starting gaps in this matrix must not be read as claims that those implementations are still absent. Deployment and measured acceptance remain separate.
Requirement matrix and disposition¶
| Phase / requirement group | Existing evidence | Current disposition / work |
|---|---|---|
| 0: metric families, scope/formulas and ownership | Phase-0 catalogue and mutation matrix, merged #3070 | Reuse; review source/consumer drift rather than restart inventory |
| 0: datasets, benchmarks and budgets | #3076; committed PS-DS02 read and screening-write benchmark evidence | Defined, not all acceptance gates passed; PS-DS03–05/CI #3194 still outstanding |
| 0: all chart consumers and history semantics | Four history selectors return null, area renderer exists | Gap corrected by historical chart plan; no fabricated legacy history |
| 0: reliable source chronology | Screening inherits DateTimeCreated but corrections update decision/StageId without edit history | Correct catalogue's claim of no timestamp: creation exists but cannot reconstruct edits; no historical reconstruction promised |
| 1A: bounded collections/indexes/class maps | Schema/contracts, registry/index/class-map tests; #3512 rolling-reader fix | Implemented; targeted fresh regression evidence still to be recorded |
| 1B: source/receipt/current/delta atomicity, retries, bounds | Transaction coordinator, source receipt, snapshot and write tests; #3232 capacity admission | Implemented; preserve shared transaction/unknown-commit invariants and verify selected regressions |
| 1B: coalescing notification outboxes and crash recovery | Durable outbox/dispatcher; #3534 host delivery | Implemented code; browser cross-pod/reconnect acceptance is separate and not established |
| 1C: snapshot reads, authorization, epochs, fallback and telemetry | Reader/mode service, authorization/selection/cursor/response-budget tests; #3482/#3515 | Implemented; operational collector and load/soak evidence remain distinct |
| 1D: rebuild/publication fences, leases, checkpoint/history/compaction/retention | Lifecycle and Mongo checkpoint/backfill/history suites | Implemented primitives; pending fixture runs and open recovery/retention findings must be resolved by severity |
| 1D: ordinary daily observations | ProjectStatisticsDailyObservationProducer and real-Mongo daily tests | Partial: RunAsync observes today, single admission attempt, no operating schedule. Catch-up/backoff/gap lifecycle requires implementation/proof; #3147 tracks gaps |
| 2A: screening classification and transactional moves | ProjectScreeningStatisticsWriter/classifier and authoritative calculator tests, #3149/#3159 | Implemented; no new screening materializer required |
| 2B: submit/correct/rescreen/config/import/bulk/delete | Source adapters, operation fences/receipt tests and lifecycle source integration | Implemented paths; audit coverage for retry, source-only fallback and failure recovery rather than assume one happy-path test suffices |
| 2C: baseline/rebuild, parity and compatibility seam | #3195/#3196, admin pilot #3523/#3531; current ReviewController mixed FullStats boundary | Implemented; broad FullStats still aggregates by design, not a performance cutover |
| 2C: staging and performance acceptance | User-supplied Fresh screening parity; read benchmark; write benchmark all eight overhead gates failed on loaded host | Not accepted as complete. Controlled load, failure drills, actual soak and write budget remain; no production enablement |
| 3A: stage candidate/reconciliation profiles | #3166 classifier/writer/query tests; stage baseline #3505 | Stage operational baseline implemented; multi-state/parity and history proof required |
| 3B: membership-stage profiles | MembershipStageAnnotationScopeCalculator and tests, signed annotation moves; runtime router registration and admin baseline/rebuild routes merged #3561 (2026-09-23) | Implemented; family flag off by default, no member-stage consumer migrated |
| 3B: reviewer annotation | Stage-scoped calculator, runtime router entry and guarded admin baseline/rebuild routes merged #3567 (2026-09-23) | Implemented; family flag off by default, no page consumer migrated and no production baseline built. Do not confuse with already merged reviewer screening #3297 |
| 3C: question family | QuestionAnswersAuthoritativeCalculator, #3178 definition fences, #3234 current-selector/post-commit fixes; runtime baseline/rebuild route merged #3562 (2026-09-23) | Implemented; family flag off by default, answer-count DTO/edit-lock consumers not yet migrated |
| 3A/3D: domain reconciliation | Authoritative calculator and annotation classifier moves; runtime operational baseline route merged #3564 (2026-09-23) | Implemented; family flag off by default, intended stage/domain consumers not yet migrated |
| 3D: shared mutation/configuration integration | Annotation writer, reservation/session adapters, definition rewrites, shared digest; local two-family proof | Existing integration reused; complete per-family baseline and representative concurrency/parity/rollback acceptance |
| 3: family history and storage growth | Shared immutable observations/definitions and family payloads | Test retained definitions and phase-3 family transitions; operating daily history depends on phase-1 producer gaps |
The existing five runtime calculator families are ProjectScreening, MembershipScreening, ReviewerScreening, SearchPopulation and StageAnnotation. SearchPopulation and transactional reviewer screening are already merged. DerivedSummary is coherent virtual composition, not a missing physical backfill adapter. The four other physical family gaps above do not mean their existing classifiers, calculators or fences must be rewritten.
Evidence locations and validation discipline¶
Main implementation roots:
src/libs/project-management/SyRF.ProjectManagement.Core/Services/ProjectStatistics/:Write,Read,Lifecycle,History, and family subdirectories.src/libs/project-management/SyRF.ProjectManagement.Mongo.Data/ProjectStatisticsFamilyCalculatorRegistry.cs: runtime family/router and backfill registration; admin routes are in API ProjectStatisticsAdminController.src/libs/project-management/SyRF.ProjectManagement.Core.Tests/ProjectStatistics/: domain/control/history/read/family contracts; Mongo.Data.Tests adds pinned snapshot, lifecycle, backfill/daily observation, index/registry and calculator integration tests.
Run targeted domain, registry and real replica-set tests for each changed slice; record command, commit and outcome in its PR. Add a regression exposing the confirmed gap before fixing it where useful. Do not treat test class existence as a passing test run. No new phase-wide runtime test result is claimed by this initial matrix. Existing implementation PR results and dated staging observations remain in STATUS; failed/unrun load and transport gates remain visible.
Ordered delivery and boundaries¶
- Correct chart/current-status and catalogue drift in docs PR #3554. Keep the new presentation/gate decisions reviewable before dependent phase-5 work.
- Done — Complete an independently usable phase-3 membership-stage baseline/rebuild slice: runtime calculator, bounded authoritative scope enumeration, existing admin authorization/flags, truthful empty-family behavior and meaningful tests. Reuse existing calculator and publication protocol. Delivered by merged #3561; family flag remains off and no consumer is migrated.
- Done — Complete remaining approved question/domain/reviewer-annotation operational gaps in separate bounded slices, preserving shared mutation ownership and existing default-off gates. Avoid duplicate work with open fleet PR #3253/#3263; fleet scheduling and retention are their own phase-6 delivery. Delivered by merged #3562 (question), #3564 (domain reconciliation) and #3567 (reviewer annotation); family flags remain off and no consumer is migrated.
- Resolve phase-1 producer recovery requirements with a concrete bounded catch-up/retry contract that never backdates current state. Scheduling must use the existing host/job ownership and rollout controls; any conflict between phase-1 ordinary-history requirement and later fleet operations is recorded explicitly.
- Run and record the phase-0–3 regression/acceptance matrix, then implement remaining phase-4 summaries/adapters, phase-5 consumer/history slices and phase-6 operations in dependency order. Reuse existing open PRs and parallelize independent slices. Report code-complete versus unaccepted environment/performance gates; do not stop after this audit or the first passing slice.
Ordinary history scheduling is a phase-1 delivery obligation for the single allowlisted pilot, whereas fleet-wide orchestration/retention remains phase 6. The first rollout must not carry optional richer charts, new event-throughput semantics, unit/outcome materialization or speculative optimizations. Correctness, authorization, bounded storage and existing acceptance requirements remain in scope.