V3 — FINAL INDEPENDENT VERIFICATION (PASS 3, AFTER CR-005)
Agent: V3, independent verifier (GOV-C3.2, GOV-E2.3). Built nothing; participated in no correction. Date: 2026-08-20 · Baseline: v1.0.0 as rebuilt under CR-005 Prior reports, both retained unchanged as evidence: 02_Work/scratch/V3_deliverable_verification.md (pass 1), 02_Work/scratch/V3_reverification.md (pass 2). Method: the coordinator's account of CR-005 was treated as a claim to be tested. Every verdict below comes from opening the artefact and, where arithmetic is involved, recomputing it. Nothing was edited. I declined the offer to run the checker suite: the current checker_run_log.txt is itself evidence in finding 3RD-01, and re-running would overwrite it. Every check I rely on was verified by reading its source instead, which is what the charter requires.
PART 1 — VERDICT ON THE FIVE SECOND-PASS FINDINGS AND THE ASM-013 RESIDUAL
| Finding | Verdict | What I opened, and what I found |
|---|---|---|
| NEW-01 tile said 26, breakdown summed to 27 | FIXED | open_item_count() now adds parked_decisions() and carries a docstring naming DEF-015. The METRIC_LINEAGE formula was updated to match: "…in RQ, ACT, CR, DEF, RSK, ISS and BKL, plus every decision parked with Zaid." Headline and breakdown now both read 27, and so do README.md (line 13), 00_Handover/HANDOVER.txt (line 45) and the function itself. Four artefacts, one number, and the definition is published. ✔ |
| NEW-02 rebuild command machine-dependent | FIXED | build_all.py now resolves tools through _find(), which tries an environment override (NDIS_RECALC, NDIS_SOFFICE), then an absolute path, then shutil.which. Every step carries a mandatory/optional flag; recalculation, the deck and the PDF render are all optional and non-fatal, and the node step is guarded by shutil.which("node"). On a machine with none of those tools the build now completes all six mandatory steps instead of dying at step 4 of 9. Good design detail: if recalculation is skipped, C28 then fails the build for a workbook with no cached values — the degradation is caught rather than silent. ✔ |
| NEW-04 dead evidence paths, and V3 credited for failed requirements | PARTIALLY FIXED | The dead-path limb is fixed: I re-resolved all 26 evidence records independently — every cited file exists and every cited workbook sheet is in sheetnames. Checker C30 is a real implementation of that test (it regex-extracts the path, os.path.exists it, and opens the workbook to check the sheet name). The deeper fix is better than what I asked for: IV_VERDICT transcribes my recorded verdict, the REQ status column is derived from it, and C31 fails the build if the register disagrees, if any requirement has no verdict, if a verdict exists for a non-requirement, or if the cited verdict source file is missing. The project now publishes 21 of 26 rather than 26 of 26. Residual: the EVD column is headed "REQ ID proven", and rows still assert proof for requirements the verdict records as failing — EVD-019 claims REQ-CON-01 proven, which my verdict below still fails. Nothing cross-checks EVD against IV_VERDICT the way C31 cross-checks the status column. |
| NEW-05 C27 accepted internal IDs, so 1.000 was not the stated test | FIXED | C27's reference pattern is now SRC/ASM only, and study rows that previously cited a derived artefact now cite the sourced inputs behind it. I re-ran the strict test independently over the delivered .docx: 84 of 87 dollar-bearing units cite a SRC or ASM = 0.966, against the 0.90 threshold. The three unattributed units are the legacy-comparison row and two DEF history rows in Appendix B2 — internal records, not external claims. The published 0.966 and my own 0.966 agree exactly. ✔ |
| ASM-013 residual | FIXED | Now reads: "At 35 percent utilisation the support coordination model returns about $59,089 a year net to the owner instead of about $98,664 — a 40 percent fall for a 20-point drop in utilisation." Both figures match model_params.sc_sensitivity() to the dollar, and the stray $71,000 / $112,000 pair is gone. The added sentence — "utilisation, not volume, is the whole business" — is the correct reading of the model. ✔ |
PART 2 — ARE THE REQ-SYS-01 AND REQ-SYS-10 AMENDMENTS LEGITIMATE?
This is the question I was asked to scrutinise hardest, so I will answer it plainly before giving reasons.
**REQ-SYS-01's amendment is legitimate. It is the GOV-C4.11 "correct the requirement at its source" move,
not the GOV-E3.4 move. REQ-SYS-10's amendment is legitimate but is drafted more weakly than it should be,
and I would tighten its wording.**
The test I applied. Goalpost-moving has a signature: the wording changes, nothing else does, the failure disappears, and the change is not visible to the person relying on the result. A legitimate source correction has a different signature: the original requirement was unsatisfiable for a reason outside the builder's control, the obligation is preserved in a different form rather than deleted, the artefact changes too, and the amendment is declared. I checked for all four.
1. The original requirement was genuinely unsatisfiable. REQ-SYS-01 demanded a total pre-revenue capital figure for every candidate model. For SIL/SDA that figure is dominated by property and 24/7 rostering, and no property parameters exist — Zaid never supplied any, and BKL-005 has carried that gap openly since the first build. No amount of correct work produces the number. A requirement that cannot be met by correct work is a defective requirement, and correcting it is not the same as evading it.
2. The obligation was preserved, not deleted — and in one respect strengthened. The amended statement reads "…for each candidate service model, or record a decision excluding that model from financial modelling together with the reason", and the amended criterion ends "FAIL on any unreferenced line or any silently omitted model". The precise defect I found in pass 1 was silent omission. Silence still fails. What is now permitted is an explicit, reasoned, recorded exclusion — which is a higher standard of disclosure than the original wording ever demanded, because the original was silent about what to do when a model cannot be costed.
3. The artefact changed too, and substantively. Table 5.1 now carries a fourth row: "SIL / SDA supported accommodation [DEC-005; SRC-016, SRC-034, SRC-036] — Registration pathway only: about $8,600 to $16,900 … NOT MODELLED — see below", with a caption explaining that a property figure "would be invention rather than estimation". DEC-005 is a full decision record — three alternatives, scoring inside DEC-003's weighted criteria, a sensitivity statement ("not close"), and a rationale citing SRC-016, SRC-021 and SRC-050. The project produced a computable partial figure where one existed and marked the rest NOT MODELLED. A goalpost move produces no new table row.
4. The change is declared, classified and escalated. CR-005 records it as Class 1 with deciding questions Q2 (re-scopes approved requirements) and Q6 (invalidates the previously recorded 26 of 26), names the affected requirements and interfaces, and states that the amendment "is surfaced to Zaid explicitly in the covering message rather than buried in this record".
5. The decisive test — the builder did not award itself the pass. After amending both requirements, the register still reads REQ-SYS-01 Open and REQ-SYS-10 Open, because the status column is now derived from my recorded verdict and C31 fails the build if anyone overrides it. The amendment changed what the requirement asks; it did not and could not change who decides whether it is met. That is the structural difference between GOV-C4.11 and GOV-E3.4, and it is enforced in code rather than promised in prose.
Where I part company with the drafting. REQ-SYS-10 now reads "…for each candidate service model that is carried forward for modelling". That phrase lets the project's own choice define the requirement's scope, which is one step from self-scoping. The acceptance criterion repairs most of it by binding the exclusion to a recorded DEC-### and requiring the excluded model to be named — but a reader who reads only the statement cannot see the obligation. Recommendation (not a failure): redraft REQ-SYS-10 to mirror REQ-SYS-01's construction — "…for each candidate service model, or record a decision excluding that model from modelling together with the reason" — so the duty is visible in the statement and not only in the criterion.
PART 3 — REQUIREMENT VERDICTS, ALL 26
This is the verdict to transcribe into IV_VERDICT. It is mine. 25 PASS, 1 FAIL.
| REQ ID | Verdict | Evidence and reasoning |
|---|---|---|
| REQ-SYS-01 | PASS | Amended AC met. Core supports: $9,110–$12,786 (base $10,791) with every cost line citing SRC-025 to SRC-041. Support coordination: $3,673. SIL/SDA: partial figure $8,600–$16,900 for the registration pathway plus an explicit NOT MODELLED marker, DEC-005 and BKL-005 named. No model is silently omitted, which is the failure the criterion names. Amendment judged legitimate in Part 2. |
| REQ-SYS-02 | PASS | Verification 4–6 months and certification 9–12 months, both SRC-021; ASM-015 sets first client at month 4; roadmap §10 sequences it week by week. |
| REQ-SYS-03 | PASS | Three alternatives; DEC-004 records weights fixed 2026-08-20T09:40 AEST against scores at 11:05; sensitivity names the flipping weight; rationale present. |
| REQ-SYS-04 | PASS | All three models scored on identical weighted criteria; 3.70 v 3.30 v 2.20, flipping at a 40% regulatory-stability weight; escalated under GOV-B6.4 rather than decided. |
| REQ-SYS-05 | PASS | UnitEconomics!B11 derives from Inputs!B5/B8/B10/B11/B12/B13, each citing SRC-002, SRC-009, SRC-011, SRC-012, SRC-013. Cached value 21.30424 read from the delivered file; recomputed independently. |
| REQ-SYS-06 | PASS | §4.1 obligations table: authority, cost, frequency, lead time and SRC on every row, no empty cell. |
| REQ-SYS-07 | PASS | Scenarios DOWNSIDE rows give a month-by-month position; single runway figure $15,875; recomputed. |
| REQ-SYS-08 | PASS | §9 lists five reversal conditions, each naming a register ID (ASM-008, ASM-002, SRC-002, ASM-015, SRC-049) and who could check it. |
| REQ-SYS-09 | PASS | §10 roadmap, explicitly conditional, sequencing every dependency in §4.1. |
| REQ-SYS-10 | PASS | Amended AC met. Core supports 39.8 and 126.5 hr/month from BreakEven!B6/B7 (cached values read from the delivered workbook); support coordination 8.5 hr/month from SupportCoordination!B13; SIL/SDA excluded by DEC-005 and named in the same table. Drafting reservation recorded in Part 2 — it does not change the verdict. |
| REQ-SYS-11 | PASS | BreakEven!B12 derives working capital from wage, hours driver and the ASM-007 lag; cached 7,318.61; recomputed. |
| REQ-SYS-12 | PASS | July-2027 consequence and readiness cost stated per model; SIL/SDA carries "already in force". |
| REQ-SYS-13 | PASS | 10 diagrams on disk, 10 embedded in word/media/, verified by unzip. |
| REQ-SYS-14 | PASS | C10's nine regex probes read and confirmed as real searches over the delivered Help Hub. |
| REQ-SYS-15 | PASS | Every tile generated from the registers; the open-items tile reads the canonical counter; "On Zaid — 9 open" and "On the AI — 4 open" both resolve the correct owner column. No hand-entered value. (Display gap noted at RES-02; it does not breach this criterion.) |
| REQ-SYS-16 | PASS (was FAIL) | METRIC_LINEAGE now carries 13 rows including the two contribution metrics and High-confidence sources; the gross-margin formula-in-words now names the 1.1545 multiplier and states it is before administration. All 9 dashboard tiles carry a data-metric attribute, and I confirmed each of the 9 names resolves to an existing lineage row. C11 fails the build if a declared metric has no row. Metrics without a lineage entry: zero. |
| REQ-SYS-17 | PASS | I re-hashed the transfer pack myself rather than trusting C22: 14 manifest files, 0 mismatched. C23's tamper-and-restore negative test read and confirmed genuine. |
| REQ-SYS-18 | PASS | 53 sources; every row below High confidence carries a non-empty "why below High". Re-scanned. |
| REQ-CON-01 | FAIL | Materially improved and still not met. Strict SRC/ASM attribution over dollar-bearing units is 0.966, and "269,000+ providers" now carries its reference. But the criterion is "zero material external claims without a SRC-### reference", and two remain, in the most consequential location in the document: §1 and §9 both state "national SDA sits at 53.7% utilisation against a surplus of 4,638 places" with no inline reference, and that statistic is the stated basis for the recommendation "DO NOT start with SIL or SDA". Both figures are sourced at SRC-050 and cited correctly in the §7 table — so this is an attribution gap in the recommendation prose, not an unsourced claim. Remedy: add [SRC-050] to those two bullets. I have now named these same two figures in three consecutive reports. |
| REQ-CON-02 | PASS | Every jurisdiction-dependent obligation names Victoria. |
| REQ-CON-03 | PASS | All 53 SRC rows carry accessed date 2026-08-20; re-scanned. |
| REQ-CON-04 | PASS | Re-measured after the rebuild: 2,253 runs, minimum effective size 10.0pt (855 at 10.0, 279 at 10.5, 1,088 inheriting Normal 10.5, the rest headings); 28 tables, maximum width 5 columns. |
| REQ-CON-05 | PASS | 15 assumptions, all with confidence and failure consequence; ASM-008 and ASM-013 now both reconcile to the model. |
| REQ-CON-06 | PASS | C08's pattern set read and confirmed; no credential, identifier or third-party datum found in my own sweep. |
| REQ-MOE-01 | PASS | ACT-009 owned by Zaid, due 2026-09-05, blocking "the base case … the service model recommendation, and the go/no-go itself (ASM-008)". |
| REQ-MOP-01 | PASS (was FAIL) | C27 narrowed to SRC/ASM only — the checker now implements the requirement's own wording. Independently measured 0.966 ≥ 0.90 over 87 units. |
Movement across the three passes: 18 PASS → 21 PASS → 25 PASS. One requirement remains failing, and the remedy is two bracketed citations.
PART 4 — WHAT THE SECOND ROUND OF FIXES BROKE
Five findings. None changes a number Zaid would decide on; three concern the assurance layer, which is where this project's defects have consistently lived.
3RD-01 — HIGH — The Definition of Done reports the previous build's checker result, and it is structurally incapable of reporting the current one
Appendix A gate 1 of the delivered study cites its evidence as "Evidence: 01_System/checker_run_log.txt (30 passed, 1 failed)". The delivered 01_System/checker_run_log.txt contains zero lines matching FAIL and ends "ALL CHECKS PASSED — 31 of 31". Cause, traced in the source: build_study.py lines 744-749 read the log at import time and format "(%d passed, %d failed)" into the gate. build_all.py runs build_study.py at step 5 of 9 and the checker suite last, after the transfer pack. The study can therefore only ever quote the run that preceded it — the DoD published inside an artefact can never cite the run that validated that artefact. Today that produces a delivered study telling its reader that one of the project's own checks was failing at delivery, while the delivered log says none were. Two controlled artefacts disagree about the project's compliance state, which is the exact property C09 exists to protect, and C09 does not compare the DoD's self-report to the log. Remedy: either generate the appendices after the checker run (a second study pass), or have gate 1 cite the log by reference and timestamp instead of quoting a count into a frozen document.
3RD-02 — MEDIUM-HIGH — The gate that proves measurement over assertion contains an asserted number, and it is wrong
Appendix A gate 13 reads "checker C29 opens this document and measures 1,051 text runs, confirming zero below 10 point." That figure is a hard-coded string literal at build_study.py:801 (% "1,051"). C29 in the delivered log measures 1,138; the delivered document contains 2,253 runs, of which 1,138 carry an explicit size. The number has not moved across two rebuilds while the true count moved twice. This is DEF-008's pattern — an assurance outcome asserted rather than measured — surviving inside the single gate whose subject is a measurement, and inside the appendix that was rewritten specifically to end that practice.
3RD-03 — MEDIUM — Gate 1 is marked PASS against a rule the same table quotes to forbid it
Gate 1 "Requirements met" is marked PASS on the evidence "21 of 26 REQ verified", while Table A.1's own caption reads "GOV-E3.1: a partial pass is a fail. All thirteen lines pass." Twenty-one of twenty-six is a partial pass by any reading, and the table declares partial passes to be failures. The honest tally that CR-005 introduced is exactly right; the gate result was not updated to follow it. On today's verdict the tally becomes 25 of 26, which does not resolve the tension — gate 1 should read FAIL, or PASS WITH EXCEPTIONS naming REQ-CON-01, until the last requirement passes.
3RD-04 — LOW-MEDIUM — The new SIL/SDA capital range is hand-written, and its low and high are built from different line items
The row added to satisfy the amended REQ-SYS-01 states "about $8,600 to $16,900". It is a literal string in build_study.py:374, not a value from model_params. Recomputing from the components the row itself names: low 6,000 + 1,800 + 636 + 108 = **8,544**; high 12,000 + 3,700 + 636 + 108 + 429.20 = **16,873**. The low excludes the $429.20 per-person screening and first-aid line that the high includes. Both round to the stated figures, so the range is not misleading — but in a study whose discipline is that every figure recomputes from a named input, this is the one number a reader cannot reproduce from the model, and it is asymmetric by $429. It also weakens the dashboard's OBJ-5 claim that a second operator can reproduce every number in the study.
3RD-05 — LOW-MEDIUM — C31 governs the status column; nothing governs the evidence register
IV_VERDICT and C31 are the strongest governance mechanism in this project, and they cover exactly one field. The EVD register's column is headed "REQ ID proven", and EVD-019 asserts REQ-CON-01 proven while my verdict records it as failing. Two rows also still read "Produced by V3" for requirements V3 did not pass — now moot for REQ-SYS-01 and REQ-SYS-10 since I pass both today, live for REQ-CON-01. Remedy: extend C31 to fail when an EVD row claims a requirement proven whose independent verdict is FAIL.
RES-01 — carried residual — two open items are counted but never displayed
BKL-002 (first-party read of the SCHADS pay guide) and BKL-003 (Victorian payroll tax threshold and disability-sector WorkCover rate) are open and owned by Zaid. The dashboard's "On Zaid" list renders only the 9 ACT rows and the "On the AI" list filters BKL to owner != Zaid. The tile says 27; the page displays 25. Both concern the confidence of the model's cost side. Raised in pass 2, not addressed in CR-005.
RES-02 — carried residual — objectives are still self-declared
OBJ-1 to OBJ-5 are marked "Met" on the dashboard by hand, with no equivalent of C31 behind them. OBJ-5 in particular ("a second operator can reproduce every number in the study from its cited source within 15 minutes") is contradicted in one instance by 3RD-04. The requirement layer has been de-self-certified; the objective layer has not.
PART 5 — INDEPENDENT ARITHMETIC, THIRD PASS
Every figure below was recomputed from register values and then compared to the delivered artefact, not read from the project's own output.
Open items. RQ 0 + ACT 9 + CR 0 + DEF 0 + RSK 10 + ISS 1 + BKL 6 + DEC parked 1 = **27** — matches the tile, the tile's own breakdown, the README, the transfer pack and the published lineage formula. ✔
Attribution. 87 dollar-bearing units after C27's exemptions; 84 cite SRC or ASM → 0.966 ≥ 0.90 ✔ (published 0.966 — identical). Three unattributed, all internal history rows.
SIL/SDA registration pathway. low 6,000 + 1,800 + 744 = 8,544 → "about $8,600"; high 12,000 + 3,700 + 744 + 429.20 = 16,873 → "about $16,900". Components trace to SRC-034 (certification audit $6,000–$12,000) and SRC-036 (certification manual $1,800, mega pack $3,700). Asymmetry noted at 3RD-04.
ASM-013, recomputed. 55%: 38 × 0.55 × 52/12 = 90.57 hr/mo × $100.14 = $9,069.35/mo − $847.33 = $8,222.02 → **$98,664/yr**. 35%: 57.63 hr/mo × $100.14 = $5,771.40/mo − $847.33 = $4,924.07 → **$59,089/yr**. Fall = 1 − 59,089/98,664 = **40.1%**. Register now states $59,089, $98,664 and "a 40 percent fall". ✔
Carried figures re-read from the delivered workbook's cached values (not from Python): UnitEconomics!B11 = 21.30424 · BreakEven!B6 = 39.7729904 · Costs!C28 = 847.3333 — all match my own arithmetic and all three published bands (601.5, 847.33, 1438.17) are unchanged. ✔
Transfer pack. 14 manifest entries re-hashed with SHA-256 by me: 0 mismatched. ✔
Legibility. 2,253 runs, minimum effective 10.0pt; 28 tables, max 5 columns; 10 diagrams embedded. ✔
PART 6 — VALIDATION AGAINST PURPOSE, AND DELIVERY VERDICT
"Zaid can decide, on evidence rather than impression, whether to commit personal capital to starting an NDIS provider business in Victoria."
This is fit to put in front of Zaid as the basis for a capital decision, with its stated limitations.
The three defects that actually distorted the decision were found in pass 1 and are gone: the employed-manager break-even now reads 411 rather than 126 wherever it appears, so the branch of ACT-001 Zaid is being asked to choose is shown at its true cost; the support-coordination capital figure is $8,757 rather than $10,045, so the option the trade study ranks first is no longer penalised by costs for workers it does not employ; and ASM-008 records that at 0.40 administration hours every billable hour loses money, rather than a survivable $10.85. I have recomputed all three from source in this pass and they hold. Nothing found in pass 2 or pass 3 touched a decision figure — the later defects were all in the layer that tells Zaid how much to trust the first layer, which is a meaningful distinction and an improving one.
What makes this deliverable unusual is not that it is free of defects — nineteen have been found and fixed across three passes, and five remain open below. It is that the project now cannot award itself a pass. IV_VERDICT holds the independent verdict, the REQ status column is derived from it, and C31 fails the build if anyone edits the register to disagree, if a requirement has no verdict, or if the verdict's source file is missing. The dashboard publishes 21 of 26 — not 26 of 26 — because that is what the verifier said, and it will publish 25 of 26 when this report is transcribed, for the same reason. Appendix B2 prints all nineteen defects, their severity and their correction, unprompted, including a three-fold error in the study's own headline answer. A reader who distrusts the recommendation can start from the register of everything that was wrong with it. That is a materially better position than a clean-looking artefact whose cleanliness is self-asserted, and it is the single strongest thing about this pack.
Against the purpose, specifically. Zaid can now state, from the artefacts alone: what he risks (about $15,875 of business cash over six months at zero revenue, $51,875 if he draws $6,000 a month, plus $7,319 to $15,683 of ring-fenced working capital); what each hour earns ($21.30 gross, $6.70 if administration is paid, minus $2.07 if administration runs at 0.40 hours — with that last figure flagged as the assumption that spans viable to unviable); what the volumes are (40 hours a month to break even doing his own administration, 126 if paid, 411 with an employed manager, 274 to draw $5,000); what the clock is (unregistered core supports closes July 2027, verification takes 4–6 months, so the application starts in month one); which model the evidence favours and on exactly which weight it flips (support coordination 3.70 v core supports 3.30, flipping at a 40% regulatory-stability weight, escalated rather than decided); and what he must do before spending anything (ACT-005 to ACT-009 — four phone calls, two quotes, and one conversation with an operating provider about administration hours, all costing nothing).
The limitations he must be told, and all of them are in the pack. Two of the four inputs the study needs are still owed by him (ACT-001, ACT-002), and until they are answered the capital and break-even figures are ranges, which the study says on its first page. Eleven of fifteen assumptions are Low confidence and named as such. The single most important of them, ASM-008, has no published benchmark anywhere and now carries ACT-009 to close it. Supported accommodation is scored as a candidate and costed only for its registration pathway, with the property side declared NOT MODELLED and the exclusion recorded as DEC-005 — Zaid is comparing two fully costed options and one argued elimination, and he should be told so in those words. Every external fact is current at 2026-08-20 and stale after 2027-08-20.
Delivery verdict: FIT TO DELIVER, with two conditions I would not waive. First, gate 1 of the Definition of Done and its "30 passed, 1 failed" evidence line must be corrected before this reaches Zaid (3RD-01, 3RD-03) — a study that misreports its own compliance state undermines the honesty that is this pack's main asset, and it takes one build-order change to fix. Second, the two unreferenced SDA statistics in the recommendation bullets should carry [SRC-050] (REQ-CON-01) — thirty seconds of work that closes the last failing requirement. The remaining findings (3RD-02, 3RD-04, 3RD-05, RES-01, RES-02) should be registered and carried openly; none of them justifies delaying delivery, and this project has demonstrated three times that it registers what it is told.
FINAL VERDICT
PASS — FIT FOR DELIVERY WITH TWO PRE-DELIVERY CORRECTIONS AND FIVE CARRIED DEFECTS. Requirements: 25 PASS, 1 FAIL (REQ-CON-01), up from 18/26 at first verification. Five of the six items from pass 2 are fully fixed and one partially. The REQ-SYS-01 amendment is a legitimate source correction under GOV-C4.11, not a GOV-E3.4 goalpost move; the REQ-SYS-10 amendment is legitimate but should be redrafted to carry its obligation in the statement rather than only in the criterion. Five new or carried defects are recorded above, three of them in the assurance layer and none in a decision figure. The arithmetic in this deliverable is sound and I have recomputed every headline figure independently in all three passes.
Verified by V3, independent verifier. No artefact under verification was modified. The checker suite was not run, in order to preserve checker_run_log.txt as evidence for finding 3RD-01; every check relied upon was verified by reading its source. This file and the two earlier reports are the only outputs written.