| DEF-001 | The four prior working files state costs, timeframes and rates with no resolvable source, and several are now factually wrong. | GOV-F8.8 | Major | Produced without a source register and without a currency date; superseded by the July 2026 mandatory registration regime, the 2026-27 price limits and the 1 July 2026 SCHADS increase. | Master Brain | Files moved to 04_Inputs/legacy_unsourced and archived to 06_Archive/_versions. Every figure in the new study is traced to a SRC-### row. The specific corrections are tabulated in the study's section 2. | Checker C05 confirms zero material claims in 05_Outputs without a SRC reference. | Closed |
| DEF-002 | The first pass at the labour model treated base wage plus casual loading plus superannuation as a fully-loaded cost. | GOV-E1.3 — met the letter of the requirement, missed its purpose | Moderate | WorkCover premium and the Victorian portable long service leave levy were omitted, both of which are mandatory for a Victorian employer of casual support workers. | Independent verifier V2 | On-cost stack rebuilt from source: superannuation 12.00%, WorkCover 1.8%, portable long service leave 1.65%. Fully-loaded cost corrected from $50.71 to $52.28 per hour. | V2_wage_verification.md, corrected on-cost table; margin restated at $21.30 per hour. | Closed |
| DEF-003 | Weekend and public holiday casual penalty rates could not be sourced and were extrapolated in the first pass. | GOV-F8.8 | Moderate | Every primary Fair Work wage page was robots-blocked, and the one secondary source located was internally arithmetically inconsistent. | Independent verifier V2 | The extrapolated weekend figures were removed rather than corrected. The financial model runs on weekday rates only and states plainly that a weekend-heavy roster is not modelled. | V2_wage_verification.md section C3 — verdict NOT CONFIRMED, figures withdrawn. | Closed |
| DEF-004 | The study stated that employing a manager pushes break-even past 126 billable hours a month. That is the PAID-ADMINISTRATION break-even, a different scenario. The correct employed-manager figure is 411. | GOV-F8.8 and GOV-E1.3 | Major | Two distinct scenarios were conflated in the one box that poses the capital question to Zaid. The dashboard carried the right figure and the study the wrong one, so the two artefacts also contradicted each other. | Independent verifier V3 | model_params.breakeven_hours_employed_manager() added as a first-class computed figure, driven by ASM-011's $95,000 manager salary. Study, dashboard and decision pack all now read from it. | V3_deliverable_verification.md ANOM-01; re-derived independently as (847.33 + 7,916.67) / 21.3042 = 411.4. | Closed |
| DEF-005 | The support coordination six-month capital figure was overstated by $1,288 and did not reconcile with its own row. | GOV-F8.8 | Major | runway_downside() did not pass workers=0, so the default three workers' screening and first-aid costs were charged to the scenario whose own label reads 'no workers'. The error fell on the option the trade study ranks first, making it look more capital-hungry than the model says. | Independent verifier V3 | runway_downside() given an explicit workers parameter; the support coordination branch passes workers=0. Figure corrected from $10,045 to $8,757. | V3_deliverable_verification.md ANOM-02; $3,673.20 + 6 x $847.33 = $8,757.18. | Closed |
| DEF-006 | ASM-008 recorded the wrong consequence, with the wrong sign, for the project's most dangerous assumption. | GOV-F1.9 and GOV-D4.10 | Critical | A figure of $10.85 was stranded from an earlier draft. Every other artefact said negative $2.07. The register whose entire purpose is to record what breaks if an assumption is wrong recorded a survivable margin where the truth was a loss on every hour sold. | Independent verifier V3 | ASM-008 rewritten to state the negative $2.07 outcome at 0.40 hours and the $15.46 outcome at 0.10 hours, so the register spans the full viable-to-unviable range. | V3_deliverable_verification.md ANOM-03; checker C09 extended to compare the registers against the model. | Closed |
| DEF-007 | Three different open-item counts were published across the README, the dashboard and the metric lineage, caused by three off-by-one column indexes. | GOV-F2.2 and GOV-D4.10 | Major | The backlog status column was read as the owner column, so six open items vanished from the README and the dashboard printed 'On the AI - 0 open'. The issue status column and the change-record status column were read one place left, so three CLOSED changes were counted as open. | Independent verifier V3 | All three indexes corrected, and a single open_items() function added to project_data so the README, the dashboard and the transfer pack now project one computed count rather than three independent recounts. | V3_deliverable_verification.md ANOM-04; checker C11 extended to reconcile the published count against the registers. | Closed |
| DEF-008 | The Definition of Done and the Part I compliance audit overstated four lines, including recording an independent verification as PASSED before that verification had run. | GOV-I1.2 and GOV-E3.4 | Critical | The DoD and the audit were hand-written prose asserting outcomes rather than projections of evidence that existed. Gate 5 claimed a recalculation that had left no trace in the artefact; gate 6 cited a checker that never opened the workbook; gate 3 and audit lines 42-49 recorded V3's verification and cold-start test as passed in a document baselined before V3 ran; audit line 33-37 tested a weaker bar (two alternatives) than REQ-SYS-03 requires (three). | Independent verifier V3 | Both appendices are now GENERATED from the checker run log and the V3 verification record, and both state the actual counts. Lines that cannot be evidenced are named as such rather than marked PASS. | V3_deliverable_verification.md ANOM-05; regenerated Appendix A and B cite checker_run_log.txt and V3_deliverable_verification.md by path. | Closed |
| DEF-009 | The delivered workbook computed a different fixed-cost band from the study, because the low and high columns of two cost lines were wired to a single driver cell. | GOV-D4.10 | Major | Bookkeeping and general overhead each carry a low/base/high band in model_params, but the workbook pointed all three columns at one Drivers cell. The delivered file computed $751.50 to $1,088.17 where the study reported $602 to $1,438, and the README tells Zaid the workbook is where he changes assumptions. | Independent verifier V3 | The workbook now carries the full three-column band for both lines, with the base column linked to the Drivers cell so the driver still drives. | V3_deliverable_verification.md ANOM-06; checker C28 now compares the workbook's computed band against model_params. | Closed |
| DEF-010 | The workbook shipped with no cached formula values, so any reader without a calculation engine saw blank cells. | GOV-F5.5 | Moderate | openpyxl writes formulas as strings with no cached results. The recalculation step was run manually during the build and then lost when the workbook was regenerated. | Independent verifier V3 | Recalculation is now a step inside 01_System/build_all.py rather than a manual action, and checker C28 fails the build if the delivered workbook contains no cached values. | V3_deliverable_verification.md ANOM-07; the recalculation log reported 398 formulas and zero errors when the workbook had nine sheets at the v1.0.0 baseline. It now carries fourteen sheets, and checker C28 reads the delivered file rather than a log. | Closed |
| DEF-011 | Four checkers asserted more than they tested, and their descriptions were quoted elsewhere as evidence. | GOV-E1.4 and GOV-I1.2 | Major | C05 tested whether a number appeared anywhere in a register rather than whether a claim carried a reference, which is exactly how DEF-006 survived twenty-six green checks. C09 compared four strings and never opened the workbook. C11 never compared dashboard metrics to lineage rows. C20 never scanned the delivered study. | Independent verifier V3 | C05, C09, C11 and C20 rewritten to test what they claim, and C27 and C28 added. The claims made about them in the study and the README were narrowed to what they actually prove. | V3_deliverable_verification.md ANOM-08; the rewritten checks are in 01_System/checkers/run_checks.py. | Closed |
| DEF-012 | A Windows absolute path appeared in the delivered study, under a gate marked PASS for cloud portability. | GOV-F4.2 | Moderate | The Definition of Done named the delivery location as an absolute machine path. A reader opening the project on another machine is directed to a location that will not exist. | Independent verifier V3 | The study now names relative paths only. The absolute delivery location is stated in the covering message to Zaid, which is where GOV-F3.3 requires it, not inside a portable artefact. | V3_deliverable_verification.md ANOM-09; checker C20 now scans the delivered study as well as the text artefacts. | Closed |
| DEF-013 | Four requirement statements carried unquantified qualifiers, and the checker's banned-word list was too narrow to catch them. | GOV-B3.6 | Moderate | REQ-SYS-03 'credible', REQ-SYS-08 'specific', REQ-CON-04 'legible', REQ-MOP-01 'material'. C01 tested seven literal strings and matched none of them. | Independent verifier V3 | All four statements rewritten with a measurable test, and C01's banned list widened to include the qualifier class rather than seven literals. | V3_deliverable_verification.md ANOM-10; C01 now also flags any qualifier with no adjacent threshold. | Closed |
| DEF-014 | The ISS register row was column-shifted, so the mitigation appeared twice and the status column held the owner's name. | GOV-F1.5 | Moderate | The register projector mapped a seven-field tuple through a six-field expression. | Independent verifier V3 | Mapping corrected. The row now carries mitigation, owner and status in their own columns. | V3_deliverable_verification.md ANOM-12; 03_Registers/ISS.csv re-generated. | Closed |
| DEF-015 | The repaired open-items tile contradicted itself in one sentence: the headline said 26 and the breakdown printed beside it summed to 27. | GOV-D4.10 | Moderate | open_item_count() totalled seven registers per the published lineage formula; open_breakdown() appended an eighth line the count excluded. The same defect class as DEF-007, in the same tile, introduced by the fix for DEF-007. | Independent verifier V3, second pass | A decision parked with Zaid is an open item — it blocks a recommendation and has not reached a terminal state — so it is now counted, and the lineage formula says so. | V3_reverification.md NEW-01; checker C11 reconciles headline against registers. | Closed |
| DEF-016 | build_all.py hard-coded two absolute tool paths that exist only on the machine that built the project, and exited on the first failure. | GOV-F4.2 and GOV-F9.15 | Major | The recalculation and PDF-render steps were added while fixing DEF-010 and adding CI-014. On any other machine the build would die at step four of nine — and the README tells the next operator to run exactly that command. | Independent verifier V3, second pass | Both tools are now discovered at run time, overridable by environment variable, and their steps are OPTIONAL: absent tooling prints a warning and the build continues. | V3_reverification.md NEW-02; 01_System/build_all.py _find() and the required flag on each step. | Closed |
| DEF-017 | The claim-attribution checker accepted a wider set of references than the requirement it certified. | GOV-I1.2 | Moderate | REQ-MOP-01 states SRC or ASM. C27's pattern also accepted REQ, DEC, RSK, DEF, BKL and ACT identifiers and the literal string 'Financial Model', reporting 1.000 where the requirement's own test gave 0.860. | Independent verifier V3, second pass | C27 narrowed to SRC and ASM only, and the study rows that cited a derived artefact now also cite the sourced inputs behind it. Strict ratio measured at 0.965. | V3_reverification.md NEW-05; 01_System/checkers/run_checks.py C27. | Closed |
| DEF-018 | Two dashboard tiles shipped with no metric lineage entry, and the checker that certifies lineage never compared the tiles to the lineage rows. | GOV-G3.7 | Moderate | The tiles were added while fixing an earlier contradiction. C11 counted lineage rows and reconciled the open-item figure but never looked at the tile set. | Independent verifier V3, second pass | Every tile now declares the lineage metric it renders as a data-metric attribute, and links to it. C11 fails if any declared metric has no lineage row. | V3_reverification.md; checker C11. | Closed |
| DEF-019 | Four evidence records cited artefacts that did not exist, and fifteen attributed evidence to the verifier whose own report recorded those requirements as failing. | GOV-F1.12 and GOV-E2.4 | Major | The evidence set was written by the builder, naming a workbook sheet and a build script that had never existed, and asserting that an independent verifier had produced evidence proving requirements that verifier had failed. This is the root cause of DEF-008 surviving in a register the appendix fix did not reach. | Independent verifier V3, second pass | Every evidence path corrected and made machine-checkable by new checker C30. Requirement status is no longer self-declared at all: IV_VERDICT is transcribed from the verifier's report and checker C31 fails if the register disagrees with it. The project now reports 21 of 26 independently verified rather than 26 of 26 self-declared. | V3_reverification.md NEW-04; checkers C30 and C31. | Closed |
| DEF-020 | The Governance Standard itself — CI-001, the artefact the whole project is built to obey — was never filed inside the project. The CI register named a path in 05_Outputs that did not exist. | GOV-F5.6, GOV-F5.7, GOV-F9.8 and GOV-D1.1 | Major | The Standard arrived as a chat attachment and was read from the upload directory. It was recorded as CI-001 on the assumption it would be filed, and never was. Nothing checked CI locations — C30 validated evidence paths but not configuration-item paths — so twenty-nine green checks and four independent verification passes all missed it. Raised by Zaid, not by the project. | Zaid | The .docx is now filed at 05_Outputs/AI_Project_Governance_Standard_v3.7.docx. 01_System/build_governance.py generates two projections from it: a complete plain-text version in 05_Outputs so an operator with no Office suite can read every rule (GOV-F9.8), and 01_System/governance_core.md carrying the 115 rules GOV-A1.6 requires be loaded at the start of every session. New checker C32 fails the build if ANY configuration item points at a path that does not exist. | Checker C32 over all 16 configuration items; 01_System/checker_run_log.txt. | Closed |
| DEF-021 | BUSINESS_PLAN_A3.html shipped at 2,169 rendered pixels against the 1,123 an A3 landscape sheet holds — very nearly two pages, while its file name, its generator's docstring and the Standard all called it a single-page A3 document. | GOV-F5.5, REQ-BUS-009 | Major | The generator asserted the format in a comment and nothing measured it. A claim about a rendered page cannot be checked by reading the code that renders it. | Master Brain | The layout was rebuilt from a three-column row grid to a masonry column flow, which recovered roughly 600 pixels of whitespace sitting under the shorter card in every row, and the typography was tightened. C34 was then written to open the page in a browser, release the sheet's fixed height, and measure what the content actually wants. It also fails when the margin is under 15 pixels, because a margin inside measurement noise is not a margin. | C34 measured 1,103 pixels of content in the 1,123 available, 20 to spare. Proven able to fail: injecting 400 words produced 'content overflows the A3 sheet by 184 px'. Recorded in 02_Work/scratch/V5_negative_tests_business_layer.md. | Closed |
| DEF-022 | model_agedcare.py cited SRC-060 through SRC-067 and ASM-020 through ASM-027 as the sources for its inputs, and not one of those rows existed in any register. | GOV-D1.1, GOV-F8.8 | Major | The aged care model was written from the research records directly, before the register rows that formalise those records had been added. Every input looked sourced and none was resolvable — which is the exact failure mode C05 and C27 exist to catch on the study, and neither of them looks at the models. | Master Brain | All twenty rows were written into the source and assumption registers with their URLs, publishers, accessed dates, confidence levels and, for every source below High, the reason it is below High. Two mis-citations were corrected at the same time: the IHACPA domestic-assistance and nursing prices had been attributed to SRC-061 when they come from the same document as SRC-060, and the payment lag had been recorded as a source when it is an assumption, now ASM-030. | C36 now resolves every SRC and ASM identifier cited by either financial model against the registers, and was proven able to fail. | Closed |
| DEF-024 | The workbook and the aged care model disagreed on the headline contribution per client: $1,044.78 against $1,002.06, a 4.3 per cent gap on the number the whole aged care recommendation rests on. | GOV-B4.1, GOV-D4.10 | Major | The care-management and administration rate was an unnamed expression buried inside client_economics() — coord_rate = NDIS.loaded_wage('l3') — so when the workbook was written it reasonably used the aged care award instead. Neither figure was wrong on its face and no check compared them, because C09 checks twelve named figures and this was not one of them. A fact held in two places is two facts (GOV-B4.1). | Master Brain | The rate is now a named input, wage_coordinator_base, with its own assumption ASM-031 and a documented reason: the Social and Community Services rate is used deliberately because IHACPA prices care management between $116.22 and $126.83 an hour, implying a role well above a home carer, and because the alternative would RAISE the contribution by about $43 a client a month. A modelling choice that flatters the recommendation deserves more scrutiny than one that does not. The workbook now projects that input rather than restating a rate. | C37 compares the workbook's cached aged care figures against the model cell by cell and was proven able to fail. | Closed |
| DEF-023 | The aged care one-off cost carried the Aged Care Quality and Safety Commission registration fee at exactly $0.00 across the low, base and high columns. | GOV-F8.2 | Major | A cost that is unknown was entered as zero rather than as a band, so the capital requirement was understated by the whole registration fee and nothing in the model said so. A zero is a claim; an unknown is a band. | Master Brain | The line now carries $600 to $1,200 to $3,000 against SRC-065 at Low confidence, with the reason recorded: the Commission's calculator returns a fee only after category and size inputs that depend on decisions not yet made. The aged care six-month runway rose from $15,917 to $17,117 as a result. | The runway and one-off figures regenerate from the model, and C09 re-checks them against every delivered artefact. | Closed |
| DEF-025 | BUSINESS_PLAN_A3.html printed to TWO A3 landscape pages while checker C34 reported it fitting one with twenty pixels to spare. | GOV-F5.5, REQ-BUS-01 | Major | C34 measured the height of a DOM element in a 1600-pixel screen viewport. The requirement is about PAGINATION, and the DOM height is identical under print emulation while the printed output still splits inside the column flow. The check was written to close DEF-021 and it closed the symptom, not the mechanism. Independent verifier V6 printed the file three ways in the same browser the checker uses and got two pages every time, the second carrying 8,127 characters. | Independent verifier (V6) | C34 now asks Chromium to PRINT the page and counts the pages in the resulting PDF, and also checks the media box is A3 landscape. The layout was then fixed at the cause: the page margin was 8mm while the sheet was the full 420 by 297 millimetres, so the sheet could never fit inside its own content box. Margin set to zero, sheet set half a millimetre under the page, print-media rules added, and the type tightened. | C34 prints and counts: exactly 1 page, 420mm x 297mm. The rendered page was read to confirm all nine sections and the verdict block survived the tightening. | Closed |
| DEF-026 | The modelled three-year net was stated as $145,621 in a trade study score rationale and in ASM-029, and no function in the project produced that number. The computed figure is $144,421.10. | GOV-B4.1, GOV-F8.8 | Major | A figure was typed into a rationale instead of computed, then repeated. The whole design of trade_study.py is that every score cites the figure it rests on; here the figure it rested on did not exist. | Independent verifier (V6) | The trade study now computes the figure from the same business-plan builder the plan itself uses, and ASM-029 carries the computed value with a note recording where the wrong one was found. | trade_study.py imports the builder at run time; the value appears in the delivered study, the deck and the business plan from one source. | Closed |
| DEF-027 | The trade study weights record could not evidence its own ordering: it held the weights AND the scored results in one file, and its modification time was fifteen seconds LATER than the file holding the scores. | GOV-B6.3, GOV-C3.2 | Major | The results were appended to the weights file after scoring, which overwrote the only evidence the file existed to carry. Its claim that nothing below the line existed at the timestamp was an attestation by the builder, and GOV-C3.2 gives a builder's statement about its own work zero weight. | Independent verifier (V6) | The record was split into an immutable weights file and a separate results file, and the weights file now states plainly that the ordering is attested rather than proven, what actually happened, and why the real protection is different: the weights are live in the workbook's TradeStudy3 sheet, so a reader who does not trust the ordering can set them and get their own answer without trusting the author at all. | Two files exist; the weights file says what it can and cannot prove; the workbook sheet recomputes on a changed weight. | Closed |
| DEF-028 | Checker C29 enforced the ten-point legibility floor over one of three delivered Office artefacts and reported the result as if it settled a requirement whose words are 'every delivered Office artefact'. | GOV-E1.5, REQ-CON-04 | Major | The check opened only the study. The decision pack carried eight nine-point runs and the workbook 145 nine-point cells. A green check over a subset is worse than no check, because the definition of done cites its counts as proof. | Independent verifier (V6) | C29 now iterates every .docx, .pptx and .xlsx in 05_Outputs, measuring runs, cells and table widths in each. The workbook and deck fonts were raised to ten point. The governing Standard is excluded because it is Zaid's document rather than this project's output, and the exclusion is derived from the configuration register's owner column rather than hard-coded. The six-column limit is applied to document tables and not to worksheet grids, recorded as DEC-008 and parked with Zaid rather than self-granted as a waiver, and C29 reports the widest worksheet in every run so the fact is never hidden. | C29 measures three delivered artefacts: zero runs or cells below ten point, zero document tables above six columns. | Closed |
| DEF-029 | Two Help Hub entries stated facts that were false, and the dashboard's capital tile showed a third of the study's own headline figure. | GOV-G3.7, GOV-D4.3 | Major | The Help Hub told a reader diagnosing a disagreement between documents that every artefact carries 20 August 2026, and told a reader chasing a stale source that every register row says the same. Twenty-one source rows say 7 September. The fifteen-minute reading route sent the reader through Part I only and never mentioned the aged care business or the recommendation that actually stands. The dashboard's capital tile read $15,875, the NDIS entity alone, against a study headline of $44,483 to $52,848. The surfaces were built for one business and not rebuilt for two. | Independent verifier (V6) | Both sentences are now generated from the currency date and the register's actual accessed-date distribution rather than typed. The reading route was rewritten to cross both parts and to lead with the comparison the recommendation turns on. The dashboard gained the combined capital figure, both per-client contributions, and kept the NDIS-alone figure beside the combined one with a label saying to read them together. | C11 reconciles every tile against METRIC_LINEAGE and the register counts; the two generated sentences move with the register. | Closed |
| DEF-030 | The delivered workbook's own README made three false statements about the workbook: a v1.0 title on a v2.0 file, a claim that every external figure was verified on the currency date, and a claim that nothing in it is a typed-in result. | GOV-D4.3, REQ-CON-03 | Major | The currency claim is the exact falsification CR-007 amended REQ-CON-03 to prevent — the amendment fixed the register and left the claim standing inside the delivered artefact, where nothing was looking. Fifty-three of the sources were verified eighteen days before the currency date. | Independent verifier (V6) | The title is generated from the project name and baseline. The currency sentence is generated from the register's actual accessed-date distribution and names the date the FIRST source expires rather than a date derived from the wrong wave. A new row states exactly which two sheets hold projected values rather than formulas, and why, and names the checker that reconciles them. | The README regenerates from project_data and the source register on every build; C37 reconciles the projected sheets to the models to the cent. | Closed |
| DEF-031 | The figure that carries the whole of REQ-AC-04 — $16.10 per client per day — appeared in the study, the deck, a risk row and the business plan, cited to a source register row that does not contain it. | GOV-D1.1, GOV-F8.8 | Major | It was derived honestly in verification record V4 from quoted survey text, but a scratch verification file is not a source register. Checker C36 tests that a cited identifier EXISTS; it does not test that the cited row CONTAINS the figure, which is the same failure one level down from the one C36 was written to catch. | Independent verifier (V6) | SRC-074 was added carrying the two component figures — $63.85 revenue and $47.75 direct cost per client per day — from the survey PDF, at Low confidence with the transcription route and the sampling limitation both stated. | The figure now resolves to a row that contains it. | Closed |
| DEF-032 | The classification-range table started at $12,000, which is not a classification, so the study never showed its own weakest row. | REQ-AC-02 | Moderate | A round number was used as the bottom endpoint instead of the registered bottom ongoing classification of $10,731, which buys 1.80 service hours a week. The model held the right figure and the workbook's own note advertised it; only the table missed it. The effect was to make the weakest case look better than the project's own model said it was. | Independent verifier (V6) | The range now runs between the two endpoints held in the model's INPUTS, so it cannot drift from SRC-064 again. Diagram D11 renders the same range. | The bottom row reads $10,731 at 1.80 hours a week and $302.14 a client a month. | Closed |
| DEF-033 | The business plan builder wrote a placeholder that always evaluated to zero and repaired it 250 lines later; the delivered JSON was correct only because of the repair. | GOV-B4.1 | Moderate | Any refactor that dropped the trailing patch would have shipped 'NDIS $0' onto the A3 page with nothing failing. A fact repaired after the fact is a fact waiting to break. | Independent verifier (V6) | The value is written once, where it belongs, and the repair line is gone. Two related corrections were made in the same pass: the three-year benefit now uses the unrounded contribution per hour rather than the published $6.70, and the support coordination revenue line is now stated gross like the other two, with an explicit note that it is excluded from the cost-benefit because its hours are already charged as the owner's opportunity cost and counting them twice would flatter the case. | The delivered JSON carries the correct baseline with no post-hoc repair; the CBA basis states what it excludes and why. | Closed |
| DEF-034 | Five requirements were only partly satisfied because their answers were given for the NDIS business alone after the project became a two-business project. | GOV-D5.2, REQ-SYS-02, REQ-SYS-06, REQ-SYS-09, REQ-SYS-12, REQ-SYS-13 | Major | CR-007 is a Class 1 change, and GOV-D5.2 requires a Class 1 change to re-verify every requirement traceably downstream. Part II was added and the Part I answers were not re-asked. The obligations table had no frequency column and no aged care equivalent; the roadmap omitted the WorkCover and portable long service leave registrations that must precede any pay run; time to first revenue and cost to be ready were stated for core supports only; and Part II carried no diagram at all. | Independent verifier (V6) | Table 4.1 gained a frequency column and Table 4.2 was added for the aged care entity, naming its two honest weak points. Table 10.1 gained the two employer registrations with a BEFORE ANY PAY RUN marker and the Working with Children Check, and Table 10.2 was added for the aged care sequence. Table 7.0 answers time to first revenue and cost to be ready for all four candidate models, including the observation that support coordination's zero cost to be ready is a paused regime rather than a saving. Diagrams D11 and D12 were drawn for Part II. | Re-verification pass V7 tests each of these against its own acceptance criterion. | Closed |
| DEF-035 | Twenty-six requirements sat at Verified on an independent pass taken against a single-business artefact set, after every one of those artefacts had been rebuilt with a second business, six new sections and eighteen new tables. | GOV-E2.3, GOV-E2.4, GOV-D5.2 | Major | The verdict map carried no baseline. C31 proved the register agreed with the verdict map; it could not prove the verdict map was still about the artefacts on disk. A v1.0.0 verdict silently certified a v2.0.0 artefact — which is not a false claim about verification, it is a true claim about a document that no longer exists. | Independent verifier (V6) | A verdict is now a triple: result, the baseline it was taken against, and the source report. Verdicts taken against a retired baseline are reported as STALE rather than as PASS, and are kept rather than deleted so a retired verdict is visible as retired. Checker C41 fails on any requirement marked Verified against a baseline other than the current one. | All twenty-six v1.0.0 verdicts reported STALE and every requirement returned to Open until pass V7 ran against the current baseline. | Closed |
| DEF-036 | The fix for DEF-025 did not make the A3 page fit. It CLIPPED it: overflow:hidden made the page count read one while the printed PDF silently lost a table, a whole section, the value-validation verdict block and the footer. | GOV-F5.5, GOV-E1.5, REQ-BUS-01 | Major | Two compounding errors. The layout used CSS multi-column, which packs beautifully on screen and FRAGMENTS ACROSS PAGES in print — Chromium filled columns one and two and put column three on a second sheet, and when the container was given a height it overflowed into a fourth column off the right edge. Neither failure is visible from the DOM, which is why the sheet measured 1,097 pixels against a 1,122 pixel page and still printed two. Then the attempt to force it onto one page clipped it. Independent verifier V7 rasterised the PDF, read what was missing, and then proved the check could not fail by quadrupling the content and still getting a PASS. | Independent verifier (V7) | The layout no longer asks the engine to decide anything: the generator fills three explicit columns, which cannot fragment. Nothing clips. C34 now extracts the printed text and requires every section heading, the verdict block and the footer to be present, so a page that fits by truncation fails. | Both failure modes proven: clipping the sheet to 150mm produced 'the page printed on one sheet but 2 elements never reached the paper'; adding 900 words produced 'prints to 2 A3 pages'. Recorded in 02_Work/scratch/V5_negative_tests_business_layer.md. | Closed |
| DEF-037 | The fix for DEF-026 moved the inconsistency instead of removing it: the trade study computed a three-year net of $144,386.98 while the assumption register and the plan's own justification said $144,421.10. | GOV-B4.1 | Moderate | The fix recomputed the net from the business plan's ROUNDED cost and benefit fields instead of reading the plan's own computed value. Two derivations of one number is the same defect as two typings of one number. | Independent verifier (V7) | The builder now stores the computed net once as cba.net_benefit, and every consumer — the trade study score rationale, the plan's justification, the A3 page and the assumption register — reads that field instead of re-deriving it. | One value, $144,386.98, in every artefact that states it. | Closed |
| DEF-038 | The published open-item count was two short: parked_decisions() matched the literal string 'Parked-Zaid' while the decisions actually written carry 'Parked with Zaid', so DEC-007 — the go/no-go recommendation itself — and DEC-008 were uncounted. | GOV-F2.2, GOV-B4.1 | Moderate | A count that depends on an exact spelling is a count waiting to be wrong. The two decisions it missed are the two that matter most: the recommendation escalated to Zaid, and the requirement interpretation escalated with it. | Independent verifier (V7) | The match is now on substance rather than spelling, and the published figure moved from 47 to 49. | C11 reconciles the dashboard and README figures against the register count on every build. | Closed |
| DEF-039 | Checker C41 verified only that the verification report FILE EXISTED, not that the verdicts came from it. | GOV-E2.4 | Major | Independent verifier V7 defeated it in a sandbox: it wrote a report reading 'EVERY REQUIREMENT FAILS. 0 of 32 PASS', transcribed all thirty-two as PASS, and got C31 reporting '32 of 32 independently verified' and C41 reporting '32 of 32 against the CURRENT baseline'. The transcription step was the unguarded one, and the transcription is the step where a builder could quietly overrule a verifier. | Independent verifier (V7) | Every verification report now ends in a machine-readable verdict block, and C41 parses that block and compares it line by line against what the project transcribed. A verdict the project claims and the report does not carry is a failure, and so is a verdict the report carries and the project ignored. | C41 detected all thirty-two verdicts as untranscribed the moment the block was introduced, and passed only once each one matched. | Closed |
| DEF-040 | Every register and every deliverable was generated BEFORE the last edit to the source of truth, so ten defects existed in the source and in none of the delivered registers, and the dashboard's headline tile published a requirement count from a retired verification pass. | GOV-D4.11, GOV-B4.1 | Major | Every individual check passed, because each one compared an artefact against another artefact of the same vintage. Nothing compared the CLOCK. This is the most ordinary failure available — editing a source and forgetting to rebuild — and the suite had no guard against it. | Independent verifier (V7) | Checker C42 compares the modification time of every source of truth against every generated artefact and fails when a deliverable is older than the fact it is meant to carry. | C42 detected fourteen stale artefacts on its first run and passes only after a full rebuild. | Closed |
| DEF-041 | Four statements in delivered artefacts were false or unsourced after the previous fix round: the $90,000 opportunity-cost sensitivity said 'roughly 10 per cent' where the computed figure is 14.9; the business plan attributed the bottom-classification contribution to a $12,000 budget after that endpoint had been corrected to $10,731; SRC-074 was created for the $16.10 reconciliation figure and nothing cited it; and the A3 page stated a market size of 717,000 participants that appears in no register, cited to the price schedule. | GOV-F8.8, GOV-D4.3 | Moderate | Each is a sentence that was true before a fix and was not revisited after it. A fix that corrects a number and leaves the prose describing the old one has moved the defect rather than closed it. | Independent verifier (V7) | All four corrected: the sensitivity is stated from the computed figures, the classification sentence names the endpoint the model actually uses, the reconciliation figure now cites SRC-074 which carries its two components, and the market-size row cites SRC-043 and SRC-044 without restating a figure neither of them carries. | C05 and C27 re-run over the rebuilt study and plan; C36 resolves every cited identifier. | Closed |
| DEF-042 | Trade study 1 published weighted totals of 2.85, 4.05 and 2.30 that its own published matrix cannot produce. The correct totals are 3.50, 4.10 and 3.25 — one was out by 1.20 on a five-point scale, more than half its own value — and the stated margin of 1.20 was really 0.60. | GOV-B6.1, GOV-B6.3, REQ-SYS-03 | Major | The scores were hard-coded strings in the study builder while trade studies 2 and 3 were computed. Nothing recomputed them, and C09 compares twelve figures across artefacts of which these were not among. It survived THREE independent verification passes, two of which recorded that they had recomputed the totals by hand and found them correct. The arithmetic is four multiplications and an addition; nobody did it. The stated sensitivity — that the answer would flip only above about 55 per cent on addressable market — was not reproducible under any donor criterion; the real figure is 37 per cent. Separately, the third alternative scored was 'remain unregistered indefinitely', which the study's own evidence shows is unlawful for a core-supports business from July 2027, so the three-alternative bar GOV-B6.1 sets was being met by padding it with an option that could not be adopted. | Independent verifier (V8) | All three trade studies now run through one engine in 01_System/trade_study.py: criteria, weights, scores and the figure each score rests on, with weighted totals and a sensitivity computed rather than typed. The unlawful alternative was replaced with a lawful third one — run support coordination during the registration window — and the eliminated option is shown as eliminated, with its reason, rather than scored. The study renders the computed matrix, a second table giving the figure behind every score, and a computed sensitivity. | Checker C43 recomputes every published total from its own scores and weights, confirms each score cites a figure, confirms the weights sum to one, confirms at least three alternatives, and confirms each total actually appears in the delivered study. | Closed |
| DEF-043 | Three of the four checkers written in the previous two fix rounds were defeatable, and the independent verifier defeated all three in under an hour. | GOV-E1.5, GOV-E2.4 | Major | C34 scraped its sentinels from the very file it was testing, so deleting a whole section from the page deleted its own sentinel and the check passed. C41 took the FIRST machine-readable verdict block in a verification report, so a decoy all-PASS block inserted above a report whose real verdicts carried failures produced a green suite. C42 compared modification times rather than content, so deleting three rows from a delivered register and running touch on the file produced ALL 44 CHECKS PASSED. Each of the three was written to close a real defect and each closed the instance rather than the class. | Independent verifier (V8) | C34's sentinels now come from business_plan.json, the twin the page is a projection of, so a page that has lost a section no longer matches the thing it projects. C41 refuses a report carrying more than one verdict block, because a second block can contradict the first. C42 regenerates every register projection in memory from the source of truth and compares it row by row, keeping the clock test as a second line for artefacts that are not registers, and its source and artefact lists were widened from five and fourteen to fourteen and forty. | C34 proven able to fail by deleting section 9 from the page; C42 proven by an unforced content difference in DEC.csv on its first run. Recorded in 02_Work/scratch/V5_negative_tests_business_layer.md. | Closed |
| DEF-044 | The Help Hub, the transfer pack and the study's own compliance appendix published counts about the deliverables that had quietly gone false: ten slides where there are twelve, 398 workbook formulas where there are 455, a diagram range ending at D10 where there are twelve, and the study called 32 pages in one entry and 47 in another when the delivered PDF has 73. | GOV-D4.3, GOV-F8.8 | Moderate | Every one of these was correct when it was written. They are the ordinary cost of typing a count instead of taking one: the artefact grew and the sentence describing it did not. | Independent verifier (V8) | A shared helper counts the diagrams, slides, workbook formulas, sheets and PDF pages from the artefacts themselves, and the three generators use it. Where a count sits inside a literal HTML block it is written as a token and substituted at write time. | Checker C44 fails on any unresolved token and recounts every published figure against the artefact it describes. | Closed |
| DEF-045 | Four statements corrected in an earlier round had reached some artefacts and not others: the $90,000 sensitivity, the bottom-classification sentence in the risk register, the citation for the $16.10 reconciliation figure, and the aged care market-size row. | GOV-D4.3 | Moderate | A correction applied where the defect was found rather than everywhere the fact appears is half a correction, and the half that is left is now inconsistent with the half that was fixed — which is worse than leaving both wrong, because a reader who checks one believes the other. | Independent verifier (V8) | All four propagated to every artefact that states them, and the six evidence records that still read 'PENDING V6' were updated to name the pass that will actually rule on them. | C05, C09 and C27 re-run over the rebuilt set; C42 now proves every register projection matches the source of truth row by row, which is the mechanism that would have caught this class. | Closed |
| DEF-046 | The fix recorded against DEF-043 for checker C41 was never written into the file. The check still took the FIRST verdict block in a verification report, and the attack it was supposed to close still worked. | GOV-E2.4, GOV-D5.1 | Major | The defect record described a fix that did not exist. GOV-D5.1 requires proving that a change DID what it was meant to do; here the edit failed silently and nothing re-ran the attack afterwards. Independent verifier V9 reran V8's decoy-block attack verbatim and got a green suite reporting 32 of 32 independently verified, with the real block in the same file recording two failures. | Independent verifier (V9) | C41 now counts the machine-readable verdict blocks in the report and fails on more than one, because a second block can contradict the first. The fix was proven by rerunning the attack: inserting a decoy block produces 'the v2.0.0 verdict report carries 2 machine-readable verdict blocks; exactly one is allowed'. | Proven able to fail, and the proof is recorded in 02_Work/scratch/V5_negative_tests_business_layer.md rather than asserted in this row. | Closed |
| DEF-047 | The trade study 1 weights record cited by DEC-004 and by the trade study engine did not exist at the path they named. | GOV-B6.3, GOV-D1.1 | Moderate | The ordering evidence for trade study 1 lived only inside the decision register's own free text — the party that made the decision asserting its own procedure. C36 resolves source and assumption identifiers; nothing resolved a cited FILE path outside the configuration register. | Independent verifier (V9) | 02_Work/scratch/T1_trade_study_weights.md was written, and it states plainly that it was written after the fact, that the ordering is attested rather than proven, and what the real protection is: the matrix, the weights and the figure behind every score are published so a reader can redo the arithmetic in two minutes, and C43 redoes it on every build. | The file resolves; C32 covers configuration item paths and the record is now a configuration item. | Closed |
| DEF-048 | Three checkers passed on artefacts that were wrong, because each compared a proxy rather than the thing: C43 substring-matched a total anywhere in the document, C44 looked in one file with three patterns, and C12 counted diagram files without looking inside them. | GOV-E1.5 | Major | Independent verifier V9 put the old, wrong trade study totals back into the delivered study and C43 passed, because those same numbers also appear in the sentence of defect history that records them as wrong. It set the Help Hub to forty slides, 1,200 formulas and five pages and C44 passed on two of the three. It replaced three diagrams with copies of a fourth and C12 passed, because three files are three files whatever is inside them. | Independent verifier (V9) | C43 now reads the WEIGHTED SCORE row out of the actual table in the delivered .docx and compares it to the computed totals in order. C44 sweeps every generated surface and register for any sentence stating a count of an artefact, in figures or in words, and allows a historical count only where the same sentence dates or corrects it. C12 hashes every diagram, fails on two identical ones, and requires every diagram on disk to be embedded in the study by content hash rather than by count. | All three proven able to fail by rerunning V9's own attacks: the wrong totals, the falsified Help Hub counts and the duplicated diagram each now produce a named failure. | Closed |
| DEF-049 | REQ-CON-04's acceptance criterion made the requirement unsatisfiable for a spreadsheet, and the project responded by interpreting its way around it rather than by fixing the criterion. | GOV-F4.5a, GOV-B3.6 | Major | GOV-F4.5a asks that an Office artefact be readable on a phone without horizontal scrolling and without six-point text. REQ-CON-04 operationalised that as a flat six-column limit on every table INCLUDING worksheet grids — this project's drafting, not the Standard's words — and a twelve-month cash projection is fourteen columns across or eight transposed. The project recorded an interpretation (DEC-008) and escalated it to Zaid rather than self-granting a waiver, which was procedurally right and substantively wrong: it left a requirement failing and a decision parked with the owner over a problem the project had created in its own drafting. | Independent verifier (V9) | REQ-CON-04 was amended under CR-007 to ask of a worksheet what the rule actually wants — that scrolling does not lose the labels — and every sheet in the delivered workbook now freezes a label column and a header row. DEC-008 is superseded, nothing is parked with Zaid on this, and the requirement is satisfied rather than interpreted around. There is precedent: REQ-CON-03 was amended the same way, for the same reason, under the same change record. | C29 checks the frozen panes on every worksheet above six columns, across all three delivered Office artefacts. | Closed |
| DEF-050 | 04_Inputs and 06_Archive/_versions were empty in the working copy while the Help Hub recovery path, the dashboard, the README and two change records all asserted files were there. | GOV-D1.7, GOV-F9.6 | Moderate | The legacy source files and the v1.0.0 archive existed on Zaid's computer and had never been carried into the working copy, so the project's own recovery instructions pointed at empty folders. A recovery path that does not resolve is not a recovery path. | Independent verifier (V9) | The five legacy input files and the v1.0.0 archive were staged from Zaid's computer into the working copy, so the folders now hold what the project says they hold. | The folders resolve and C32 covers the configuration items that name them. | Closed |
| DEF-051 | REQ-CON-04 was amended to cover 'every delivered Office artefact' and the check enforcing it still walked one folder. The delivered register workbook — CI-004, cited by name in the study, the Help Hub and the dashboard — failed BOTH halves: 27 cells at 9 point and 27 sheets wider than six columns frozen only at the header row. | GOV-E1.5, REQ-CON-04 | Major | The same defect as DEF-028, one directory up. Widening a requirement without widening the check that tests it produces a green result over a narrower set than the requirement names, and the definition of done then cites that green result as proof. Independent verifier V10 opened the workbook the check never opened. | Independent verifier (V10) | C29 now measures every .docx, .pptx and .xlsx in 05_Outputs AND in 03_Registers. The register workbook's fonts were raised to ten point and its freeze is now at B3, holding the identifier column as well as the header row. | C29 measures four delivered artefacts: zero runs or cells below ten point, zero document tables above six columns, every wide worksheet freezing both a label column and a header row. | Closed |
| DEF-052 | Several statements in delivered artefacts were durations or provenance measured from an unstated 'now', and had gone quietly wrong: 'about eleven months away' for a fixed July 2027 date, a business plan footer reading 'PENDING - pass V5 has not yet run' through six passes that ran, and 'four working files' where there are five on disk. | GOV-D4.3 | Moderate | A duration measured from an unstated now goes wrong every day, silently, forever. A provenance field that names a pass by number goes stale the moment the next pass starts. | Independent verifier (V10) | The months to July 2027 are computed from the project's currency date. The business plan's verified-by field names the pass that actually set the current statuses and reads the count from the register. The file count is corrected to five. | C44 sweeps every generated surface for counts that disagree with the artefact. | Closed |
| DEF-053 | Three checkers can still be defeated by an attacker with write access to the delivered artefacts: C43 by appending a duplicate trade study table, C44 by a case-sensitivity bug in one diagram pattern, C12 by a single flipped bit in a copied diagram, C34 by white-on-white print CSS or by replacing every figure with the same number, and C42 by substituting a whole workbook. | GOV-E1.5 | Moderate | Independent verifier V10 demonstrated all five in sandboxes. The class is real and the boundary is worth stating plainly: these checks defend against a MISTAKE — a stale rebuild, a hand-edit, a fix that did not take — and they have caught many. They do not defend against a determined party with write access to both the artefacts and the checkers, and no check inside the same tree can. Configuration control, the source manifest and independent verification are what cover that, and they are the reason a verifier found these rather than a checker. | Independent verifier (V10) | NOT FULLY CLOSED, and recorded as open rather than written off. The declared stopping rule for this baseline was that findings from the closing pass are recorded, not fixed in another round. The specific hardening is carried as BKL-013. | Open — carried to BKL-013 with the attacks named so the next pass can rerun them. | Open |
| DEF-054 | Several statements first raised by earlier passes remain unfixed at the close of this baseline: the daily audit log still carries an entry dated to the v1.0.0 baseline, the $16.10 reconciliation figure is still cited to SRC-068 in the study and the deck rather than to SRC-074 which carries it, a capital figure cites a workbook sheet that does not contain it, and the compliance appendix still says 'both trade studies' where there are three. | GOV-D4.3, GOV-F8.8 | Moderate | Each is a sentence a fix made false and did not follow through on. None changes a number a decision turns on; all of them cost a reader who checks one of them their trust in the ones they did not check, which is the real cost. | Independent verifier (V8, V9, V10 — raised three times) | NOT CLOSED. Recorded as open under the declared stopping rule for this baseline and carried as BKL-014. They are named here individually so the next pass does not have to find them again. | Open — BKL-014. | Open |