{
  "schema": 1,
  "generated_at": "2026-09-15T21:23:22.053473+03:00",
  "timezone": "Europe/Vilnius",
  "title": "Kairos Daily Brief",
  "audience": "Kairos team",
  "privacy": "Team-safe activity and selected findings only. Money, private timing, deductions, raw evidence, and personnel reads are excluded.",
  "latest_date": "2026-09-13",
  "days": [
    {
      "date": "2026-09-15",
      "milestone": null,
      "attention": [],
      "findings": [],
      "status": "no-activity-filed"
    },
    {
      "date": "2026-09-14",
      "milestone": null,
      "attention": [],
      "findings": [],
      "status": "no-activity-filed"
    },
    {
      "date": "2026-09-13",
      "milestone": "Kairos · Day 35",
      "attention": [
        {
          "title": "The selected-customer record was widened and its owner-private story now carries a complete attempt sequence",
          "detail": "A wider authorized-corpus audit reconciled the saved sources and raw events, adding the real attempt chronology and the Billing-to-Help sequence to the record. The owner-private story edition retained the missing-field and identity limits, so the narrative is richer without claiming a shared customer join or independent certification.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The Elsewhere VPN prototype now proves a bounded residential proxy path without calling it device protection",
          "detail": "The engine and connection identity were repaired, then a real selected-country residential HTTPS request traversed the owned proxy and shut down cleanly. Ordinary traffic was observed after teardown, while whole-Mac protection and native activation remain unproved.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The native VPN path now checks conflicts, DNS and recovery as observations, not protection claims",
          "detail": "Connection orchestration now checks service/default-route conflicts, interface-bound DNS, IPv4/IPv6 reachability and helper/controller loss before native activation. Those probes and their refusal paths are covered by the regression suite, but signing, activation and protected-traffic acceptance remain open.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The first Mac tunnel trials now show bounded IPv4 use and restoration, with IPv6 still unresolved",
          "detail": "Two actual Mac tunnel trials changed the IPv4 exit, carried probe traffic through the tunnel, and restored the original routes and DNS on disconnect. IPv6 did not return inside the tunnel, so the result is bounded IPv4 connect/use/disconnect evidence—not full protection, DNS-leak freedom or failure recovery.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The native activation boundary now refuses to cross missing signing or administrator permission",
          "detail": "The prototype prepared a bounded helper with one connection, owned-resource cleanup and explicit permission refusal; signing and native activation remain unavailable. The refusal path is exercised, so the next meaningful step is an authorized activation and protection test, not more interface polish.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "The customer record supports a sequence, not a causal explanation",
          "detail": "The widened record now shows what happened in order, but upstream identity and experience gaps remain. It can support a trace of the observed attempt and support contact; it cannot yet prove why the customer left or generalize one record to the population.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "A successful residential proxy request is not device-wide VPN protection",
          "detail": "The selected-country proxy path now gives a real HTTPS exchange and clean teardown, but that traffic boundary is narrower than whole-Mac protection. Native signing, activation, IPv6 tunnel behavior and failure recovery remain separate acceptance gates.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "Native conflict, DNS and recovery probes cannot certify protected traffic",
          "detail": "The prototype now measures pre-activation conflicts, resolver state and helper/controller loss, and refuses unsupported transitions. These observations reduce uncertainty around the native path but do not prove traffic protection or leak freedom.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "Mac tunnel restoration passed for IPv4 while the IPv6 path remains unresolved",
          "detail": "The two Mac trials restored the pre-trial routes and DNS after disconnect, but IPv6 returned no response inside the tunnel. The evidence supports bounded connect/use/disconnect behavior only; seamless recovery and full dual-stack protection remain open.",
          "test": null,
          "receipt_count": 2
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-12",
      "milestone": "Kairos · Day 34",
      "attention": [
        {
          "title": "The research reader now rebuilds the room it feeds, and its evidence labels cannot drift silently",
          "detail": "The reader source was brought back in line with the team-facing room, with its machine brief, evidence status and open-decision state generated from one source. A red-tested parity check now fails when the source, generator and deployed pages diverge, so a deploy-only repair cannot disappear on the next rebuild. The room is live behind the War Room gate; recipient use is still unconfirmed.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The VPN economics argument now carries its matched subset, bounds and competing explanations",
          "detail": "The residential reading is now stated as 91.7% of the matched subset (7,724 of 30,212 identities), with a 36.5%–96.7% whole-network bound. The fee-share field is no longer treated as corroboration, and demand constraint now sits beside geographic scarcity as a competing hypothesis. A full grid search replaced the earlier corner estimate, so the binding case is visible rather than chosen by eye.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The residential-versus-datacenter test now refuses to call a non-causal screen a verdict",
          "detail": "A frozen claim table replays four earlier screens and labels each as observation or association rather than cause or recommendation, with four hypotheses and a precommitted crossover named as the next discriminator. The trial harness now watches guard liveness throughout and requires an attributable response, token, date and rendered content before a run can be clean. The next crossover still needs Lee at the VPN gate.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The weekly call is readable on both sides, and the capture path now proves audible input before it reports healthy",
          "detail": "The missing remote track was recovered and read alongside Lee's track, then turned into a Kairos analysis with its attribution limits kept in the record. The recorder now resolves devices by name, checks all 16 channels and distinguishes bytes arriving from speech actually present; a real device-index swap made the failure visible and was refused. The two-way gate still needs a live far end before it can be called complete.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "One shared Margin editor now serves every War Room room, and its answer path is live",
          "detail": "The forked editor was retired: notes anchor to passage content and a question asked in a room can be handed to a running agent, with the answer left in place. The shared editor and room-scoped authorization are live across the War Room; recipient use by Ro and Gitanas remains the next check.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The selected-customer record was widened without pretending the joins are stronger than they are",
          "detail": "The admitted sources were paginated and reconciled, adding profile, payment and support facts to the record while retaining the limits around shared identity. The owner-private story was updated from the same evidence, but no complete customer join or general population claim was added. The reauthentication boundary remains explicit for the next pass.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The engagement's operating machine now records coverage and provenance instead of hand-waving them",
          "detail": "The team-facing Coverage Ledger state card is live, while identity, source-parity and evidence-ceiling checks were tightened around the rooms that changed. The machine now distinguishes a room state it actually measured from stale or unmeasured claims, and keeps the next read bounded by named evidence rather than a hand-entered count.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The Elsewhere VPN prototype's engine now has guarded local behavior, while protection acceptance remains open",
          "detail": "The prototype's authenticated engine and consented local-model path were repaired, with boundary and state tests covering the hand-off. Real Mysterium traffic, device protection and user-acceptance gates remain open, so this is an engineering continuation rather than a usable VPN claim.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "The current quality labels grade customers after purchase, not before it",
          "detail": "Two production classifications were found in the operating record, but both are retrospective: one tracks value after a plan is held and the other grades margin health after the transaction. The acquisition question remains unanswered, so the phrase higher-quality customers cannot yet carry an acquisition bar.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The residential screen cannot support a causal or recommendation claim yet",
          "detail": "The earlier screens were replayed in the frozen claim table and each failed the causal or recommendation gate because multiple variables moved together or completion evidence was not attributable to the trial. The record supports screening-grade observations and named hypotheses only; the same-country crossover is the test that could change that.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "A healthy capture status can mean bytes arrived without speech",
          "detail": "The call-capture guard now distinguishes a growing file from audible two-way content. The earlier status line could pass with a silent remote return; a speech-floor and role-group check now refuse that reading, while a real far-end run is still required to prove the two-way gate.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The selected-customer record supports a sequence, not a complete identity",
          "detail": "The admitted sources were reconciled, but the shared identifier join remains unproven and the reauthentication boundary is explicit. The record can carry observed profile, payment and support facts without turning one trace into a population claim.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The prototype's engine repair is not a working-VPN verdict",
          "detail": "The repaired controller and limited engineering checks establish guarded local behavior, not a working device VPN. Real traffic, dependable device protection and user acceptance are still separate gates; none is promoted from a local or synthetic check.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-11",
      "milestone": "Kairos · Day 33",
      "attention": [
        {
          "title": "The first sprint's answer was cut from a list of five opportunities to one, and rebuilt so that nothing is decided on a floor whose foundation is still missing",
          "detail": "The day opened by reconciling the four live opportunity records into a current five and evaluating each on payoff, evidence grade, whether it can actually be executed inside the business, what this engagement can capture, the cheapest test that would settle it and the condition that would kill it. It ended on one opportunity instead: rebuild the product from the ground up, in three parts — know every customer and what each one is worth, fix the product starting with the obvious leaks, and build a lean operating model around them. That was then rebuilt a second time into dependency order, because the first version put moves before the knowledge they depend on. It now runs as seven steps, each carrying its question, what is known today, what is missing, the work it takes and the bar that says it is done: one record per customer, who buys and why, what each customer earns or costs, the customers to build for, the product tested as they actually use it, the product fitted to the job it is bought for, and the business built around them. Only the no-regret fixes and one spending guardrail start before that knowledge exists, and each is marked where it sits. The page carries a finish line, a kill condition with a date on it, an explicitly empty external side with one named partner-channel test, the board question stated as a question, and a table of everything rejected with the reason. It is held closed until it is presented, which is why there is no door to it here.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The one recommendation was put against an independent challenger that produced its own list of opportunities and named two blocking defects in ours",
          "detail": "The day's opportunity set was put through two rounds of independent adversarial review at the highest model available, and the reviewer was asked for its own answer to the same question rather than only for objections: it named four opportunities for the business outright, left a fifth open and put one question to the board, and declared where its own list was not independent of ours instead of claiming a clean read. The first round named two blocking defects in our ranking and nine smaller ones, and all eleven were carried into the page that replaced it — one opportunity's payoff rested on scarcity while the numbers behind it fit demand limitation instead, and another's stated kill condition could never have fired, so nothing could ever have retired it. A second round over the rewritten pages returned one further blocking objection of the same shape and thirteen wording corrections; that objection is carried open and owned rather than quietly closed. This is a separate review from the one over the sprint's own account — a different document, its own rounds and its own counts — so the two sets of findings are not comparable.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The whole first sprint was read back end to end, and every headline figure in that account was re-checked at its source before it was allowed to stand",
          "detail": "Nine read-only passes over the sprint's own dated record produced an analysis of what the first sprint actually did, most important first. No figure was quoted forward: each was re-derived at source, and the two that did not reproduce were dropped rather than softened. The account was then put through two rounds of independent adversarial review at the highest model available, the reviewer working from a shared-safe copy. The first round returned fourteen findings, of which thirteen were adopted and one survived with a wording change; the second round verified those repairs, returned six more on the changed text, and closed on the reviewer's own stated condition — no number had moved, so no third round. What the review kept disagreeing about is worth naming: two counts of the same population, taken at different times, no longer match, and the analysis now says which one it is using and why.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The argument about what a VPN physically is, and what has actually been measured, is now open to the whole Kairos team",
          "detail": "The room holds the ground-up argument and the atoms page behind it, and on request it moved from a closed audience to everyone who signs in to the War Room, the team included. Before it opened, its live pages were brought to exactly what the record supports and no further: twelve destinations run across three exit classes with the same client, nine indifferent to exit class, two refusing every class including a household exit, one separating this network's datacentre addresses from a competitor's, and no cause claimed behind any of it. A page that had never been finished was taken out of the room rather than tidied. Each page names the machine that wrote it. The door itself is tested rather than assumed: the audience suite for this room was made to fail before it was made to pass, and the same pass restored a door missing from the team index since the index was built.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The research reader and the customer-recovery prototype are open to the whole Kairos team",
          "detail": "Until today these were a private reading surface: a reader carrying seven days of research with its sources attached, a working prototype of a recovery flow built from that research, and the comparison that sets it against what exists. They now open for everyone who signs in to the War Room, and the pages say so — where they previously told the reader they opened for one person, they now name the team, the MN side included. Each page carries a machine-readable brief and a visible record of what it is, which evidence it rests on and which decisions it supports, so a reader can see the standing of a claim without asking. The three pages were checked on the live surface at two screen sizes in both themes before the audience changed.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Twenty customer journeys were reconstructed end to end and scored under one rule, which is the first measured answer to whether a customer can be followed at all",
          "detail": "The recommendation rests on being able to follow one customer from first touch to renewal through the systems as they stand, so that question was measured rather than assumed. Twenty journeys were reconstructed from the records and scored under a single rule, with two of them traced in full as worked cases a reader can check line by line. A journey stitched across sources scores higher than the best single record manages on its own, and both sit well clear of a random baseline under that rule, which is the first evidence that stitching is worth the work rather than an article of faith. Joint reachability across the six core tables was measured, and the seven tables left out of that read are named rather than silently excluded. Every figure on the page is derived from receipts by the build itself, which refuses to ship if the aggregate stops reproducing from them.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The note layer runs from one shared editor in every room, and a question asked in a room no longer waits on a single agent",
          "detail": "Two editors had been running against the same surface; the fork is retired and every room now loads the one shared editor, whose anchors are tied to the content of a passage rather than its position, so a note stays on its words when a page is rebuilt. The harder half was answering. A reader's question in a room simply failed while the one agent able to answer was unavailable, and the cause was measured rather than guessed: the job was refused before any model ran, because of the shape of the identity attached to it. A question now goes to the first of the named agents that reports ready, a re-asked question can be re-addressed to whichever agent is actually running, and the answer says who wrote it. A second of the three named agents is now answering where one was. An answer carrying a private detail the discussion never contained is refused before it reaches the page, and the refusal is recorded with its reason and without the content.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Outside sources are now read three times over for this engagement, and the first signals are already filed against it",
          "detail": "What we read from the outside world — talks, threads, vendors' own documentation — used to be mined for how we work. It is now read on three layers on every source: the machine that runs our own work, the business as it stands today including how it sells and how it is run, and ventures that could be launched from the same substrate. Signal that belongs to this engagement lands in a dated ledger of its own rather than a general one, and a venture idea is only recorded with its substrate, its hypothesis, the cheapest test that would settle it and the condition that kills it, so nothing accumulates that cannot be killed. The first entries are in: the state of the checkout rails being built for purchases made inside AI assistants, what one large payments vendor's own internal deployment shows about building such a thing rather than buying it, and a first read on how fast the gap between frontier and commodity models is moving. A subscription-lifecycle test on a clock — renewals forced forward in the three stores rather than waited for — was added to the product immersion record from the same reading.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The machine that runs this engagement lost three ways of reporting a pass it had never actually measured",
          "detail": "The guard that checks every published address before anything ships could call a healthy site misconfigured when the network dropped one of the two lookups it made, and could print a pass over a host that never answered at all. It now asks once, retries an incomplete answer, and where it still cannot measure says so and blocks: a failed measurement is never a pass and never a verdict about the host. The visual check on published pages could hang waiting for fonts it was never going to receive over a weak connection and then time out; its waits are now bounded, all three type families must load on both pages in every state, and a deliberate block on the font host must be seen to fail before any pass counts. Room access is held to the same standard — both audience suites for the rooms that changed were made to fail before they were made to pass. The gain is narrow and worth stating plainly: the pipeline can still fail, and it can no longer tell us it passed something it never looked at.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "The exit screening supports the contrast it recorded and nothing about what causes it",
          "detail": "The twelve-destination screening across three exit classes was reviewed adversarially end to end, and what stands is the recorded contrast alone: nine of twelve destinations indifferent to exit class, two of twelve refusing every class tested including a household exit, one of twelve separating this network's datacentre addresses from a competitor's. No reading of the cause survives that review, because between the arms carrying the contrast the country, the operator, the address, the route and the moment of observation all moved together, so none of them can be credited with a refusal. This bears directly on the reading carried here yesterday, that the standing of this network's own addresses rather than the class they belong to might be the variable: the adversarial review named in that reading's kill test has returned, and this data does not support it — the reading is untested rather than dead, and testing it needs a comparison that moves one thing at a time. Two limits came with the verdict and apply to anything built on this kind of screening. The labels a lookup service attaches to an address are fallible classifications, not an ordered score of abuse, so an address that looks worse labelled has not been measured as worse. And a command-line client wearing a browser's name is not a browser, so nothing here says what an ordinary person's browser would have been served.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The checkout rails being built for purchases inside AI assistants can take a first payment but cannot renew one",
          "detail": "Read at the rails' own first-party documentation rather than from commentary about them: the payment flow being standardised for buying inside an AI assistant carries no subscription or renewal path today. For a business whose revenue is renewals rather than first purchases, that bounds what the channel can be worth right now — it can open an account and take the opening payment, and everything after that has to happen somewhere else, on a surface the customer has to be brought back to. It also names what to watch, because the bound is a product decision by one vendor rather than a property of the channel: the day a renewal path appears in that rail, the channel changes shape for this category and the question stops being whether to sell there and becomes how. Nothing here measures how much demand sits behind the channel; that is a separate read.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-10",
      "milestone": "Kairos · Day 32",
      "attention": [
        {
          "title": "The residential premise was measured through real tunnels for the first time, and on the destinations that refuse everything else it did not hold",
          "detail": "Before any tunnel went up the plan was cut from four arms to three, on a new rule about whether probing damages the thing being measured or a third party, and its target list was rebuilt from famous names to destinations qualified on observed behaviour. The argument page gained a rule of evidence alongside it: figures published by sellers are admissible for the size of a market and inadmissible as evidence that home-address access works, and the same rule disqualifies the network's own marketing as evidence for its own premise. Then the tunnels ran. A household exit on a consumer ISP and this network's own datacentre exits were pointed at the same destinations with the same client in one paired stretch, with each arm's exit class independently verified. Of twelve destinations, nine are indifferent to exit class altogether; two refuse every class tested, and the household exit meets the same challenge there as the datacentre one; one distinguishes this network's datacentre addresses from a competitor's and serves the household exit. Those two refusing destinations were the cell the premise needed, and home addresses do not rescue it. The banking page the plan had promoted to its main arm served every exit class, so the arm the plan was built around shows no contrast at screening strength, and the household line dropped requests the datacentre line did not, which is a cost of the premise rather than a refusal. An independent review of the whole process is out and has not reported.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The week-five one-pager, the edition that lands on the month-one review, is published, and now also stands as a room inside the War Room",
          "detail": "The whole in-window dated record was swept into the edition that arrives with the first month's review, and it is live at its public address: 1,091 records narrowed to 639 candidates, of which 574 were included and 65 parked, with none left unclassified. Those counts sit above the figures the draft carried earlier in the day because they are the same mechanical sweep re-run against a day that was still producing records. Five new classification rules were needed to get there, because the previous week's rules left 208 of this week's candidates unsorted. The edition's capacity finding was qualified before anyone read it: earning identities are not independent households, so installed capacity counted that way is an upper bound rather than a count, and a corroborating ratio was dropped because the field it came from combines two different components, so the finding keeps its inference label and now names two ways it could be killed instead of one. It names and links the customer prototype, and it carries forward an ask that is waiting on the team rather than on us, read-only access to the sales system, now in its third edition. The page is also generated into the War Room as a room of its own, from the published bytes, with a check that fails if the two ever drift.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The note layer began answering for the first time, gained the contract room's full set of actions, and was measured against every Kairos surface rather than one",
          "detail": "A reader can select a passage in any War Room room, leave a note anchored to those exact words, and now ask an agent about it from the same composer in one action, where before the ask hung off an already-saved note so a room with no notes showed no ask at all. A note can also be edited by its author, with the revision history the write path had always returned and only the panel never offered. The side that actually produces answers is live for the first time: one of the three named agents reports ready, the other two render as not ready instead of failing quietly, and an answer inherits the visibility of the note it answers, so an answer to a private note cannot surface in a team room. The layer's reach was then measured rather than assumed. It covers every room of the War Room, which is one of five Kairos surfaces; two of the other signed-in surfaces can take it unchanged, and the public edition host cannot, because a note's author comes from the sign-in identity and that host sits deliberately outside the gate, which is why the published edition became a room inside the War Room instead. Documents downloaded from the contract room also now arrive with readable filenames.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "A working customer product built on the residential premise now stands at a public address",
          "detail": "The demonstration for the Friday session stopped being a mock-up. The first version was rejected for wearing the engagement's own chrome and labels that broke the illusion; what replaced it is a complete product a stranger could use — its own name and offer, a purchase flow, an account, sharing, a globe that answers where the route is, and a film that actually plays and seeks cleanly from cold. The residential network is credited in the finished state, quietly and by name. It is reachable without a sign-in at its own address while the War Room itself stays gated and the application's source and authoring routes stay closed. All of the evidence behind it is our own instrumentation against the live surface: no recipient has opened it on their own device, and the network has neither been asked for nor given any acceptance of it.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The record of what node runners actually ask for was read, and most of it names a state the software could recognise on the machine itself",
          "detail": "A delegated window closed with six results on the node-runner support record. The largest category of labelled demand names a state that is detectable on the machine and has a known response, which means the node could say what is wrong and what to do without a person answering at all. Underneath it sit two different animals: a monitoring failure that runs continuously across the whole period read, and a stale-connection family that is a recent incident the node can heal by itself — the interface shows one bare status word for both, where the cause is already known to the software. The remedy a customer is left with after a disconnection is still switching node by hand. The session port was checked and is random across the whole configured range, which matters to anyone deciding what to filter.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "What the network can observe about its own traffic was pushed forward on five fronts, from queue behaviour to where a routing decision would have to live",
          "detail": "The week-long study of what is measurable from inside the tunnel added five results in one stretch. Whether a congested queue makes individual flows visible was modelled first with a fixed-rate sender and then again with a responsive one, and the validity checks that failed were kept in the record rather than dropped. The component that actually owns packets was located along with what it cannot schedule directly, and the gap between the shipped binary and its source was named. What a fleet of nodes could learn from one another's repairs was read from primary work on the subject, including the minority cases where a shared repair is wrong. A captive portal's own announcement of itself was mapped, and a delayed acceptance after a disconnection was found to report success without the fetch it implies. Each result carries what it does not cover: none of it has run on a live network or in the shipped application, and no model was trained or executed.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Where else a home address can come from, and how comparable networks answer the same question, was mapped against the public record",
          "detail": "A bounded study asked who else already supplies residential access and on what terms. Seventeen complete public aggregate responses from comparable networks were captured and reconciled, showing a real difference in access policy between them and in how much of each network's published supply is residential at all, with one country standing out as an exception rather than the rule. One class of substitute was characterised end to end and failed compatibility in three specific ways when it was actually run instead of assumed. The comparison was then repeated from scratch by a separate operator with no prior context, which reproduced the same dispositions and is what makes it a result rather than one person's run. Five candidate directions were compared on their economics, including one that would qualify supply rather than buy it. Nothing here was published and no supplier was contacted.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The machine that runs this engagement can no longer report a complete day from a source it could not read",
          "detail": "The daily coverage check used to treat an unreadable source log as an empty one and report the day as covered; it now fails outright, so a silent gap cannot pass as a clean day. The whole installed set of checks was run together and passed. A daily signal channel was found deaf across five consecutive runs, which means those editions were quietly short one source — visible now rather than silent. Alongside that, the month's deck was taken into the tracked series, the warehouse opened again on aggregates only, and the message rail carried the day's exchanges with every receipt acknowledged and expired claims swept. None of this shows up in a room; it is what keeps the rooms honest.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "A destination that refuses the whole country would have made the main arm return an empty result whatever the truth is",
          "detail": "Qualifying destinations before running them turned up a third way this test can manufacture an empty result. The plan already named two — a battery too small to contain a blocker, and a permissive path inside an otherwise strict destination. The third is a destination that refuses the exit's country outright. Measured on the direct line, one of the two chosen banking login pages answers with a refusal that states its own reason in words: the address, the country, and a country block. A home address in that country and a data-centre address in that country would both be refused identically, every trial would score as a denial, and the comparison rule discards that pair either way — the whole unattended block would have burned to nothing. This qualifying pass was made without a browser, which is itself a signature a destination can read, so it overstates refusal; the destinations have to be re-qualified through the real instrument before they are used.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "What this test is measuring may belong to one infrastructure vendor rather than to each destination",
          "detail": "Both banking destinations that qualify sit behind the same infrastructure vendor, and one of them tells refused customers to quote that vendor's own reference number when they call — the control being probed is the vendor's judgement of an address, not each bank's private fraud system. If that holds, two of the three surviving arms are not independent readings at all: they ask one company's opinion of an address twice, and any change that company makes moves both at once. It also explains a squeeze in the available destinations: from a Lithuanian exit the domestic banks are not behind that vendor and serve normally, while the institutions that are behind it refuse the country outright, so mechanism and geography barely overlap. One consequence is already settled: a date the plan treated as a deadline does not apply, because the vendor's changed default covers domains newly joining it and not the established zones every viable destination sits in.",
          "test": "Run the same destinations through an exit the vendor rates differently but whose country is not refused, and run one arm against a qualifying destination that is not behind that vendor at all. If outcomes track the vendor's rating rather than the destination, the two arms are one arm; if a destination off that vendor refuses on its own, they are independent and this is dead.",
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The network already owns and pays for the first hop of a two-hop design, and runs it as the one place that sees both who the customer is and where they are going",
          "detail": "Read from the product's own immersion record rather than executed by us: the German box is the endpoint the customer's client dials, and the household router sits downstream of it, so the destination sees the household line and never the relay. Two things follow. The residential claim is stronger than it looked, because nothing in front of the exit lends it a hosting classification; what remains is whether the extra leg perturbs timing and packet characteristics enough for a destination to notice, and that is a question the measurement arm can answer. And the shape of a two-hop design is already built and already paid for — the customer's traffic crosses infrastructure the network controls before it reaches the household exit. Handing that first hop to an independent party would add almost nothing to the delay already being paid, and would mean no single party sees both the customer's identity and their destination. The relay exists for a plain engineering reason, that a household behind a router cannot accept an inbound connection, which is exactly what makes the position stable enough to build on.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The traffic counter in the declared implementation moves for maintenance traffic that delivers nothing",
          "detail": "Read at source and checked against components we can run, the declared implementation's counter increments on protocol maintenance traffic with no inner packet delivered. A non-zero counter is therefore not evidence that anything reached the other end, which matters everywhere that number is read as delivery — a node's contribution, a session's health, or what a customer is shown. One in-memory test and an exact-data control both pass, so the behaviour is characterised rather than assumed. It was not run in the shipped application, on any route, or in the field, and it says nothing yet about how large the maintenance share is in practice.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "Most of what node runners ask for names a state the node could recognise on the machine itself",
          "detail": "Of the node-runner support requests labelled in one quarter, 54% name a state that is locally detectable and has a known response — the node could say what is wrong and what to do without a person answering. Two families sit underneath: a monitoring failure that is chronic across the whole period read, 2023 to 2026, and a stale-connection family that is a 2026 incident the node can heal by itself. The interface shows one bare status word for both, where the cause is already known to the software. Against a different and much wider population — every node-runner question asked in the period, rather than one quarter's labelled requests — the share going unanswered rose from 36% in 2023 to 49% in 2026, so the demand a local answer would absorb is growing rather than shrinking. The two shares are not comparable to each other; they measure a labelled sample and a whole population.",
          "test": "Instrument the node to detect the named states and answer them in place, then measure the share of new support requests that still arrive for exactly those states. If it does not fall well below the labelled share, the states are not what people are actually asking about and this is dead.",
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "On the only destinations that refuse every datacentre exit, a household exit is refused identically",
          "detail": "Twelve destinations were run across three exit classes in one paired stretch with the same client: this network's datacentre supply, a household exit on a consumer ISP, and a competing operator's datacentre exit. Two of the twelve refuse every class tested, and the household exit meets the same challenge page as the hosted one. Those two are the cells the residential premise needed, because they are the only places where exit class could be the difference between access and refusal; nine of the twelve are indifferent to exit class and would be served by anything. One of the two sits behind the same infrastructure vendor whose judgement the banking arm was built to probe, and it challenges a household address exactly as it challenges a hosted one, which is the first evidence for a reading the plan had raised and left unsupported, that such a vendor can recognise commercial residential proxying as a category of its own. These are the first runs with a tunnel up; the destination-qualifying pass reported alongside them deliberately had none, which is why its count of measured routes is zero. Bounds: two repeats per cell rather than five, one household address per run, a plain client rather than the instrument, and logged-out browsing only.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "The variable may be this network's own addresses rather than the class they belong to",
          "detail": "A competing operator's datacentre exit carries a strictly worse reputation label than ours, flagged as both hosted and proxy, a heavily shared public endpoint reported near its load ceiling, and the one destination that refuses our datacentre addresses serves it. If that holds, the class is not what such a control acts on, something specific to our own ranges is, and the remedy is hygiene on the addresses we already hold rather than buying household supply. It also answers part of a circularity worry: had the destination and the classification service drawn on the same upstream data, the address labelled proxy should have been refused hardest, and it was served, so the destination's judgement is independent of those labels. Held at measured strength and not put forward as a recommendation: one competing operator is a single case, one destination carries the contrast, and that exit sits in a different country from every other arm, mitigated but not controlled by the refusal naming network security rather than country and by the control destination serving every arm.",
          "test": "Run the same contrast against a second destination that refuses our datacentre addresses, and add a second non-competing operator's datacentre exit in the same country as ours. If our addresses are refused where other operators' datacentre addresses are served, the standing of our own ranges is the variable; if every operator's datacentre exit is refused alongside ours once country is controlled, the class reading survives and this is dead. An adversarial review of the whole process is already out, and its verdict is part of the test.",
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-09",
      "milestone": "Kairos · Day 31",
      "attention": [
        {
          "title": "What the company means by a high-quality customer has two working definitions, and both grade a customer only after the sale",
          "detail": "The question was taken to the whole record rather than to one deck: nine years of dated company slides read at both the slide text and the speaker notes, the full internal chat archive, a column sweep of every warehouse dataset, and the company's own audience research. Two real production classifications came back — one grading accounts high or low value, one a margin rule an analyst built — and both are applied to customers already bought. What did not come back, anywhere, is an acquisition-side bar: no lead score, no ideal-customer model, nothing tied to a channel or a campaign. Reading the same corpus at the image layer closed a hole in it first: the slide archive holds no native chart data and no embedded workbooks at all, so every chart in it is a picture that a text scan cannot see, and all of them have now been read.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The limits everyone accepts about VPN speed were taken back to physics, and each one now carries the measurement that would disprove it",
          "detail": "Six things that actually bind a residential-IP network were written down first — light in glass, the triangle inequality, the fact that somebody must know where a request is going, a home node's upload as its ceiling, the difference between a home machine and a server, and reputation as a shared resource. Nine limits the market treats as fixed were then set against them, each one carrying what the market assumes, what the physics permits, why the gap exists, and the cheapest measurement that would prove the claim wrong; a claim with no falsifier was not allowed to stand as one. The floors are computed great-circle distances at a fixed route factor and are checked against the client's own source and against stored registry aggregates, not against measured paths, and none of it has been run on a live network. It is one readable page that can be marked and questioned passage by passage, with the anchor bound to the text of the passage so a comment refuses to paint rather than re-point itself at different prose when the page is edited.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The test of whether a home connection gets through where a data-centre one is blocked was rebuilt, and the earlier empty result was withdrawn as evidence",
          "detail": "The plan that decides whether the residential premise actually holds was taken apart twice in the same night. The first defect is arithmetic rather than argument: the only published base rate anyone could find is a 2016 measurement in which 3.67% of the top thousand sites blocked, and it measured Tor exit addresses rather than proxies, so a sixteen-destination battery had under a coin's chance of containing a single blocker and its empty result was the likely outcome whether or not the effect is real. That result no longer counts as evidence, and every empty result from here is reported together with the chance it had of finding anything. The second change inverts how destinations are picked: choose on published operational evidence of blocking, such as an error code or a dedicated restriction page, and never on what a service's terms say, because the most aggressive enforcer in the category says nothing about it in its terms and names it only in its help pages. A third fault sits inside single destinations, where enforcement varies by subscription tier and by what is being watched, so a result is now reported against the exact path probed and never against the brand. Four mechanism classes replace the old list of famous names, and the one class that only proves the apparatus works is labelled as calibration wherever it appears, so a hit there is never read as support for the premise.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The reporting gaps were checked against available warehouse data",
          "detail": "The reporting gaps were compared with the warehouse schema and refreshed tables. The recorded schema search found no cost or advertising-spend columns in the inspected warehouse, while refreshed churn and lifetime-value tables provide inputs for further analysis. A monthly churn calculation was produced, but its numerator and denominator have not been established as comparable populations. Data availability does not by itself validate a retention rate or explain why a metric was absent from a deck. The latest all-hands deck was captured, and an earlier source route remains unavailable to the accounts checked.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The paying-account map and the blind support labels are now a room the team can open",
          "detail": "The map filed yesterday stopped at two boundaries — the support audit and the deployment itself — and both are now cleared. The blind audit was restarted and carried to completion in batches, and all 339 labels are published alongside the 14,328 qualified paying accounts on a customer-journey page behind the team sign-in. Anonymous requests for the page, its data, its scripts and its images are all refused, and every asset served matches the package that was built. What the page does not do is resolve by publishing: the contrast certificate is still unavailable, mobile follow-ups are held, and the source, financial and purpose uncertainty and the withholding of text prevalence stay stated on its face.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Marking and commenting was built across every War Room room, and the rule that keeps the rooms separate was proven before it ships",
          "detail": "A reader can now select a passage inside a room, leave a note on that exact passage, and get a reply there rather than in a separate message. What began as one page's interaction was extended across the whole War Room. The two obstacles named when the work was queued both dissolved into things that already existed: the set of people who may hold a note is the same set the sign-in already knows, and an agent that answers is identified by a declared label that cannot widen what it is allowed to reach. The part that had to be right is room separation, and it is enforced on the server: asking the notes interface for a room you cannot open returns nothing, and a note marked private is not returned to anyone else. Anchors are bound to the words of the passage rather than to a position, so a note left on prose that has since been edited refuses to paint and says the passage changed instead of quietly re-pointing itself at different text. It is checked end to end in a real browser and is not live yet; the release waits on its data store being bound.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The warehouse holds two accounts of the same customer history, and they stop agreeing at a date",
          "detail": "The older dataset and the newer one were diffed month by month across users, purchases, churns, refunds and traffic, joined on each pair's real date and account keys rather than on a column that does not exist in both. The older set stops writing on 27–28 April 2026 and has no traffic table at all. Users and churns disagree from the first month the two share, while purchases and refunds track each other closely until January 2026. The revenue view the company reads in its reporting tool reconciles to the newer lineage, not the older one. Following the largest gap: 86.89% of the April difference in refund amount between the two lineages sits after 27 April, and the 126-row refund gap is bounded to between 119 and 131 exact row copies whichever way full-row duplicates are removed. Who writes the refund table, and how its lifetime-value counterpart is calculated, both came back unresolved — the live table metadata carries no calculation description and a bounded writer lookup found no matching job.",
          "receipt_count": 3,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "The growth-metrics workbook was extracted twice, blind, and the two readings were red-teamed on denominators",
          "detail": "Two independent extractions of the 20-tab workbook were taken without either reader seeing the other, then diffed, with every disagreement settled on what each number is a share of. What the workbook says about itself: 58.4% of the 2026 cells that are due are empty — 5,031 cells due across weeks 1 to 35 on the 11 visible tabs — and the board tab carries 858 broken references. The lifetime-value series stops at week 14 after fourteen consecutive misses; where it does run, 44 product-level values sit against 22 blank cells on the company summary for the same 22 weeks, which is not evidence the two definitions agree. Its own churn line is 50.1% of its revenue line, and 1.2% of purchases are attributable to recorded advertising spend. Separately the task tracker was reconciled: of 7,068 retained tasks, 24 carry a tracked-effort field, so questions about how much work anything took cannot be answered from that record as it stands. A slide was built so this reading can be walked through on the Friday call rather than sent as a file.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Every free-text cancellation answer was read against one codebook, and the flow that asks for feedback keeps nothing",
          "detail": "All 4,692 free-text answers customers left while cancelling were coded against a single codebook rather than sampled. Counted by users, \"something was broken\" is the largest stated cause at 631 and \"no longer needed\" follows at 600. The review-prompt feedback path was traced in the same pass and stores nothing at all, so whatever a customer types there is not recoverable afterwards. The wrong-plan complaints date to the Basic and Plus split of 6 January 2026, and a distinct Nigeria profile was separated out rather than folded in with the rest. The blind support labels were then scored against a second reading of the same records: 10 of the 16 label dimensions clear 90% agreement, and the six that do not are named rather than averaged away. Raw customer text is held outside the record; only the codes and the counts enter it.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The company's own task record was reconciled whole, and it holds plans where an effort read would need actuals",
          "detail": "The retained task record was read end to end rather than sampled: 7,068 tasks reconciled against their own state, reproduced deterministically and checked against a recorded state hash. Of those 7,068, 24 carry a tracked-time field and 1,718 carry a positive estimate, and in the support area of the record none of its 66 tasks carries a positive time field, so the gap is not evenly spread. The scope the record leaves out was confirmed separately rather than assumed, and historical overlapping area counts were kept visible rather than collapsed. That bounds what this source can be asked: it is a live account of what work was planned and where each piece stands, which is what the deployment state of the cancellation flow was read from, and it is not a basis for an effort, workload-trend or cost read.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The installed app's entry, notification and upgrade paths were run at source, and three of them lose what the customer chose",
          "detail": "Rather than describing the client, its actual composition was exercised: real store, router and tab classes taken from pinned source and driven through controlled sequences. A product a customer picks before signing in does not become the selected one after login. A notification marked handled before its destination is rejected for being signed out is not resumed by the later sign-in signal, and remounting the handler does not recover it either — freshly issued destinations succeed, so the loss is specific to the one already consumed. The connection display does keep \"connected\" and \"selected\" apart, but a parent fallback mismatch reproduces in fixture. On upgrades, the plan-verification helper traces the caller's success events and interface states, while the locked status contract exposes 13 fields against the 9 the app maps, and nothing in either establishes whether an entitlement changes at once or at the next cycle. None of this carries a field incidence: these are source-level behaviours, not measured customer outcomes.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "What makes the app's picture of a customer's plan go stale was tested at source, and the easy explanation lost",
          "detail": "The question the upgrade paths left open — whether what a customer is entitled to changes at once or only later — was taken back to pinned public source and to components we can actually run. Fifteen source files were traced from a subscription change downstream into capability and location state, and resuming the app explicitly forces a refresh, which weakens the standing explanation that customers are simply looking at a stale local cache. The background-refresh path was then characterised on its own components and passed every one of them, and a candidate that would have merged overlapping refreshes was rejected on a counterexample it failed, leaving the cache writer's boundary observed rather than assumed. None of this measures how often any of it happens to real customers, and no production change was made. What it does is take one explanation off the list instead of adding another to it.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The request a customer makes was followed through startup at source, and a candidate that keeps it was built against the real client",
          "detail": "The path a request takes from the moment a customer makes it through app startup was traced on pinned public source rather than described: how the client hands its base configuration to the native wrapper, how the reachability callback behaves, and where a request that genuinely persists differs from a route the app merely visited last. Against that trace a private candidate was built so the request survives the point where the app currently drops it, and exercised through fixture journeys on real card and store classes with an unchanged incumbent alongside it as control. It passes its own tests and nothing more: no independent review, no production change, no customer exposure, and no measurement of whether the same behaviour holds on a live install. A separate desktop-routing feasibility check compiled only and carries no runtime claim.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The seven excluded product tables were read in aggregate; two are inert",
          "detail": "Google_events.google_subscription_lifecycle holds one week of September 2024 and is dead. vpn_web_tracking.events_recent keys on a web id that matches none of the 4,127 frame accounts. App_session_connections is a 30-day rolling table with no Windows rows. only_users_connection has one status value or null. All meanings unconfirmed.",
          "receipt_count": 0,
          "link": null,
          "featured": false
        },
        {
          "title": "The programme for the next working session is set — the consumer product first, proxies an optional extra — and a whole experience was built to carry it",
          "detail": "Priorities for the next working session were extracted from the record and then corrected on a direct instruction: the consumer VPN is the main programme, proxies are an optional bonus, and any later shift of attention is conditional on foundations being agreed and on operational execution. A standing set of product and craft principles was written as Kairos canon alongside it, including recovery that asks the customer for no interaction at all — direction, not a claim that anything is built. The session's surface was then built as a complete product experience rather than a form: a doorway, customer vignettes, a presenter view and a written decision record, checked in a real browser across every route in every viewport and theme state, with the defects that pass found and repaired. It has had no independent review and no acceptance, and contrast certification is still open.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Whether a broken stream can be warned about before it breaks was tested on a frozen public trace, and first warnings behave nothing like repeat ones",
          "detail": "A two-day public measurement trace was replayed under a contract frozen before the run: acceptance conditions written first, inputs archived outside temporary storage, and the whole thing replayed a second time to check that every original output reconciles. Across 121,444,240 reports, how precise a warning is and how much it covers differ sharply between the first warning for a stream and a repeat of one, so a single accuracy number for warnings hides two different behaviours. Warning timing was measured on the same frozen window and bounded to server-side observation only. Outcomes are missing for one specific class of warning, and that gap is carried rather than filled. Nothing here touches a customer, a node or our own product.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The registry watch finished its frozen programme, and recovery was raced on owned fixtures instead of argued about",
          "detail": "The scheduled observation programme completed all 82 of its planned requests across seven rounds, and the direct comparison returned every one of its 20. Two controlled experiments then took up what to do when a request is slow: an eight-case counterexample in which the slower fallback wins, and a twelve-case comparison of keeping the first request against replacing it, with cancellation and byte accounting reconciled rather than assumed. On the playback side, 18 loopback trials compared waiting, appending and reopening — recovering faster did not prevent zero-media-time frame callbacks, which still appeared in 2 of 4 delayed reopens. Eight fixed cases then showed that a mirrored request wins every race while the shared condition delays both tasks, which is the cost side of redundancy the published model does not settle. All of it ran on media and endpoints we own; no node, customer or production path was exercised.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "What a buyer is billed for and what packaging does to their choice were read on primary sources, and the two policies conflict in one place",
          "detail": "Two lanes of one commercial question. On billing: the metering path was traced through 12 archive-matched public source files with four of the upstream calculator's own tests passing offline, and the current and legacy policies conflict on what is metered at all — that conflict is recorded, not resolved. Candidate buyers of measurement were dispositioned seven ways, one workflow account retained qualified and the rest narrowed, and a public measurement sample returned 4 answers from 5 selected probes, all four answering for different domains, which bounds what a single sample can be read to mean. On packaging: a bundled-distribution premise was set against a vendor's own historical expansion and retirement of the same kind of offer, subscription access was separated from bundle installation, two primary meta-analyses and their corrigendum put a cost on offering more choice at all, and a controlled trial separates what customers prefer before use from what satisfies them after. Nothing is adopted — the comparators enter the evaluation with their limits attached and no packaging winner is inferred.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "What counts as a contribution on the supply side was read at source, and the public counters there measure connections and bytes rather than people",
          "detail": "The supply side was taken on its own sources. Five pinned node files and five public pages were read for what the product itself treats as a contribution, and an analogous volunteer-run contributor network was read beside it: its published counters track connections and transferred bytes, which are neither unique people nor impact. Two primary papers on how visible work is valued and on reporting after the fact were assessed and adapted rather than adopted, with their limits kept attached. What this bounds is how any published supply count can be read, including the node-pool figure already on this page; it does not establish what population sits behind such a count. No runtime test, node measurement or customer read was involved.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "What a customer can do when the connection breaks was built into a comparator base, and the week's evidence now reads as one document",
          "detail": "The recovery half of the consumer question was worked as one lane. Primary sources were pinned for what competing and adjacent products do at the boundary: selection-preserving startup against accidental-disconnect retry, published service-status feeds and the workarounds still standing in them, constrained offline preparation, eSIM fallback with its supplier conflict retained, provider-funded diagnosis and its escalation path, built-in browser routing with its eligibility and quota limits, and configuration paths that separate what a customer prefers from what is actually applied. Alongside them, fixtures we own rather than claims: host access was separated from player absence on 2 of 3 against 3 of 3 observed documents, an optional-host grant journey could not complete because the native control is unavailable, and a paired-presentation prototype ran six fixture cases under one policy across seven viewport and theme states. Primary trials on congestion, in-situ learning and feedback control were read for what transfers and what does not. All of it was assembled into a single reading that ended the day at 18 sections and 44 source references, with three conditional commercial decisions written against the sources that would have to hold for each. Nothing installed, no customer or network experiment, and no product or packaging decision taken.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "A false investigation now has a definition, and the next warehouse question has to survive it before it runs",
          "detail": "The standard is one sentence: an investigation is false if its method could not have produced the opposite answer. It is now built into how the next warehouse question runs. Step zero reproduces the source's own headline numbers from the warehouse first and stops if they do not reproduce, because a headline that will not reproduce is the larger finding. Step one pre-registers the query scope, the confounds that would have to be ruled out, and a numeric decision rule, all committed before anything runs. Step two dispatches a reviewer who sees the schema, the plan and the rule but not the claim under test, not whose hypothesis is whose and not any result, and who must answer one question — for each possible outcome, what conclusion does it license, and is there any outcome that would license the opposite? A circular design means rebuild rather than proceed. Step three reports against the pre-registered rule even where that contradicts the framing that raised the question, with \"undetermined\" an allowed answer. Alongside it a working process for the day's own investigations — observe before selecting, freeze acceptance before building, test on matched but private-safe data, stop on yield — was written and put through an opposing critique before being adopted.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The plan for the next warehouse question was red-teamed blind before it ran, and every defect the review returned was taken into the rule",
          "detail": "The method for testing the company's own claim about customer quality was pre-registered and committed first, then handed to a reviewer from a different model family who saw the schema, the plan and the numeric decision rule but not the claim under test, not whose hypothesis was whose, and no results — the isolation held by fact rather than by promise, because no result existed yet. The review came back sound with defects, and none of them was argued down: the word \"quality\" was changing meaning between the hypothesis and the ruling; the set of possible outcomes was incomplete, with ties and null effects unhandled; the gate meant to catch a payment-gateway effect could pass while the amounts underneath it were inflated, since the gate was computed from those same amounts; and the second stage left its nesting order and its interaction allocation unspecified. The repairs make the company's own explanation harder to confirm rather than easier, which is the only direction that makes a confirmation worth anything. The reviewer declared it might have partly guessed what it was reading, and that is recorded rather than dismissed. No decomposition has been run: the tightened rule is what the next session runs against.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Shared-channel coordination and daily-review tooling",
          "detail": "The contract-review link was delivered across the shared agent channel, its receipt archived and its in-flight claim released. The nightly warehouse pass ran its inventory, fitness and squeeze batch on aggregates only. Daily-review tooling was tested against eight historical runner attempts: the inspector identifies a recorded blocker and distinguishes a failed attempt from an older completion. Production integration remains under evaluation; an accepted improvement in the user's experience has not been established. Queued settings and review work remain separate from transport acknowledgement.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Pay and write to support on the same day: the first-day chain",
          "detail": "Twenty six-key journeys drawn blind: account, subscription and first paid cycle land on day 0 for 18 of 20, and 9 of 20 open a support conversation that same day. No churner has a subscription cancel event; every exit is a cycle that ends without a successor. One case paid five cycles for 0.27 GB while filing in-app cancel reasons from day 0; another is kept alive by monthly card-decline retry storms and finally a Primer rescue.",
          "test": null,
          "receipt_count": 0
        },
        {
          "evidence_state": "fact",
          "title": "The older warehouse lineage stopped writing at the end of April, and the reporting layer reconciles to the newer one",
          "detail": "Diffed month by month on both sides, the older dataset's customer tables end on 27–28 April 2026 and it has no traffic table at all. Users and churns disagree between the two lineages from the very first month they share, so the divergence is not a late drift; purchases and refunds track closely until January 2026 and then separate. The revenue view read in the reporting tool reconciles to the newer lineage. Anything still reading the older one is reading a record that stopped.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The feedback the app asks a customer for after a review prompt is stored nowhere",
          "detail": "Traced in the same pass that coded the cancellation answers: the review-prompt feedback flow persists nothing. Whatever a customer writes into it is not recoverable, which means the absence of complaints on that path is not evidence of their absence, and any read of customer sentiment has to come from the cancellation answers and the support record instead.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The largest cause customers type when they cancel is that something was broken, not that they no longer need it",
          "detail": "Across all 4,692 free-text answers left at cancellation, coded against one codebook and counted by users: \"something was broken\" leads at 631 and \"no longer needed\" follows at 600. These are the answers customers chose to type, which is a different population from the churned subscriptions the billing record labels — the earlier billing-retry share was a share of churned subscriptions, this is a share of the people who wrote something, so the two are not measuring the same denominator.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The classifier behind the aggregate cancellation report disagrees with the report's own semantics on most of a written test set",
          "detail": "The unchanged classifier was run against 13 authored cases built to probe its boundaries and mismatched the report's semantics on 7 of them. Separately, the report excludes answers it judges to hold no meaningful text, so the population any rate is taken over is itself set by an untested rule. Both together mean a rate lifted from that report cannot be used as a customer-population rate until the denominator is validated.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "hypothesis",
          "title": "The wrong-plan complaints are an artefact of the Basic and Plus split rather than a standing confusion",
          "detail": "Reading the coded cancellation answers, the complaints about being on the wrong plan date to the Basic and Plus split of 6 January 2026 rather than spreading evenly across the record. If that holds, the cause is a one-off migration boundary and is already behind the product; if it does not, the plan choice itself is confusing customers and will keep doing so.",
          "test": "Take the wrong-plan complaint rate as a share of all coded cancellation answers in each month before and after 6 January 2026. If the rate does not step at that boundary and instead runs at a similar level on both sides, the split is not the cause and the standing-confusion reading stands.",
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "A product the customer picks before signing in is not the one selected after they sign in",
          "detail": "Driven through the app's real store and tab classes from pinned source: an intent expressed on the products surface before authentication is rejected, and the later sign-in does not restore it as the selection. The same holds for a notification destination marked handled before it was rejected for being signed out — the auth signal does not resume it and remounting the handler does not either, while a freshly issued destination succeeds. How often either happens to a real customer is unmeasured; this is what the composition does, not how common it is.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "was_connected_total now has a definition and a blind spot",
          "detail": "Cross-checked on all 120,595 churned users against the daily activity table, the session-connections table through the tracking-id bridge, and server-side cycle traffic. It means: at least one Firebase-telemetry connect on or before the churn date. It is faithful to its source; the source cannot see Windows. Of churned Windows-only users the flag calls never-connected, 81% have server traffic (1,753 of 2,170), against 10% on iOS and 8% on Android.",
          "test": null,
          "receipt_count": 0
        },
        {
          "evidence_state": "fact",
          "title": "Customer value has two production definitions in the company's own systems, and neither one grades a customer before the sale",
          "detail": "One live classification grades accounts high or low value across 1.6M rows. A second is a margin rule an analyst built, and nothing in the stated acquisition priority uses it. Both are applied after a sale has happened. Four sweeps — nine years of dated decks at slide text and speaker notes, the full internal chat archive, a column sweep of every warehouse dataset, and the company's own audience research — returned no lead score, no ideal-customer model and no bar tied to a channel or a campaign. Quality, as the record uses the word, is a grade on customers already bought rather than a filter on which ones to buy.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "In the company's own value classification, a high-value customer is largely a long-plan customer",
          "detail": "The live high-or-low value grade moves with plan length and market tier: 15-25% of monthly subscriptions are graded high value against 62-92% of yearly and two-year ones, and 34% of tier-one-market users against 17% of tier-three. That makes \"customer quality rose\" and \"plan mix moved longer\" close to the same sentence in the data model. It does not restate the August result already on this page: that one measured revenue per new purchase against a population of new purchases only, while these shares are of subscriptions by plan term, so the two carry different denominators and neither settles the other.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "hypothesis",
          "title": "The reported rise in customer quality is a plan-term mix shift rather than a change in who is being acquired",
          "detail": "The value grade the company's own systems apply tracks plan length, and a rise in revenue per new purchase is what a shift toward longer terms mechanically produces. If that is what happened, the quality claim describes composition and not a better customer being won. The decomposition that would settle it was registered before anything ran, with its numeric decision rule fixed in advance, and both explanations were given explicit falsifiers.",
          "test": "Run the pre-registered decomposition of the August change in revenue per new purchase into plan-term mix and price, holding country mix fixed. If plan-term mix accounts for little of the rise, the mix reading fails and something other than term composition is moving revenue per sale.",
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The retention claim behind the quality reading has no support anywhere in the reporting record",
          "detail": "The claim that customers in one market retain better was checked against the whole dated deck corpus rather than argued with: no retention rate appears in any 2026 deck after June, and retention is never broken out by country in any year of the record. Cost of acquisition, revenue per user and payback appear in no deck at all. An innocent explanation is carried explicitly — the current reporting template has no field for any of them — and no motive is asserted. The warehouse can answer the retention question directly, and that is the open test.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "Every chart in the dated deck archive is a picture, with no underlying data anywhere in it",
          "detail": "Thirty-three dated decks were opened at the file-format layer: not one holds a native chart part and not one holds an embedded workbook, so every chart in the corpus is a flat image and a scan of slide text alone cannot see a single one. That hole is now closed — all 187 unique images across 1,093 slides were read, with optical text recovery proved positive-and-limited first on a table it recovers verbatim and a chart it does not. Any number that exists only inside a chart in this archive has to be read off the picture; it cannot be extracted.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The April divergence between the two warehouse lineages sits almost entirely after the date the older one stops writing",
          "detail": "Following the two lineages already on this page: a bounded daily aggregate places 86.89% of the April difference in refund amount after 27 April, which is the date the older dataset stops writing. The remaining row gap is bounded rather than guessed — a 126-row difference stays between 119 and 131 rows after any full-row de-duplication, and 30 April carries 13 rows for 13 distinct users. What produced the older dataset is still unresolved, and identical schemas are not evidence of a shared producer.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The retained task record cannot support a read of operational effort",
          "detail": "7,068 retained tasks were reconciled deterministically against their own state: 24 of them carry a tracked-time field and 1,718 carry a positive estimate, so the record holds estimates far more often than it holds anything actual. Any effort or workload read taken from it would be a read of estimates, and no labour figure is claimed from it here. The scope that is omitted from the record was confirmed separately rather than assumed.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "Much of the reported growth in the node pool is a reclassification of supply already there",
          "detail": "The node pool reported as moving from 33,000 to 40,000 is not 7,000 nodes newly joined: at least 43% of that growth is migration of an existing software-kit bucket into the pool, and the slide reporting the growth carries the qualification itself. The denominator is the growth, not the pool. Read as a count of new supply won, the figure overstates it by whatever share of the movement is that migration, and 43% is the floor on that share rather than an estimate of it.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The inspected warehouse lacks the cost inputs needed for acquisition-cost analysis",
          "detail": "The recorded schema search across twenty warehouse datasets found no cost, spend or finance columns, and none of the ten inspected ingestion connectors was an advertising platform. The marketing dataset contains purchase events, not advertising costs. Those inspected inputs are insufficient to calculate acquisition cost. This does not establish that cost data is absent from every company system or explain why a figure was omitted from a deck. An external cost source and validated attribution would be needed for the proposed analysis.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "Refreshed tables make retention analysis possible; the illustrative churn rate is not certified",
          "detail": "The recorded inspection found 2.24M lifetime-value rows and refreshed churn and active-user tables. A January–August 2026 calculation ranges from 17.4% to 21.9%: its numerator counts dated rows in the churn view, while its denominator counts distinct user IDs seen in active-user history during each month. Whether those populations are comparable remains unresolved. This is evidence that a calculation can be produced, not a certified subscription-loss rate, retention result or country comparison. It is also distinct from the workbook ratio of its churn value to its revenue line.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "By August, almost all purchase events in the inspected marketing table were direct or unattributed",
          "detail": "In the recorded January–August 2026 comparison, paid-search-attributed purchase events fell from 51 in January to 9 in August, while the share recorded as direct or null rose from 85% to 99.2%. The 99.2% figure is the August endpoint, not a share of the entire historical table. Direct or null attribution does not establish the real acquisition-channel mix; instrumentation or consent effects may contribute. These are purchase events in one warehouse dataset, not the population behind the workbook attribution figure, and neither measurement establishes acquisition efficiency.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "The August year-on-year headline reproduces exactly, and the fall in sales it reports is specific to new purchases",
          "detail": "Reproduced from the warehouse before anything was decomposed, August 2026 against August 2025, gross, all countries and all gateways, counted by purchase date: new purchases fall from 4,132 to 4,057 transactions, down 1.8%, while their gross revenue rises 41.4%, so revenue per new purchase is up 44.0%. The same two figures return from the revenue view and from a purchase-level copy of the same record. Six candidate populations were tested and the reported 1.7% fall matches new purchases; of the other five, one — new plus winback — also falls, by 0.5%, and the rest rise, by up to 8.0%. Measured across the whole record instead, August transactions rise 6.1% and revenue per transaction rises 35.9%, so the same month reads differently depending on which population is counted, and the two figures are not in conflict. Refunds sit at 5.5% of gross in both years and carry no purchase reference, so a net figure per new sale is not computable on either side. Why revenue per new purchase rose is not settled here; the split between plan-term mix and price is pre-registered and has not been run.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The cancellation flow reported as releasing within the week is not deployed in the company's own task record",
          "detail": "The latest all-hands deck reports the cancellation flow as releasing within the week. The company's own task record shows the app build marked ready to deploy but not deployed, the dashboard task closed against a test address, and the analytics task dated to early October. The cancellation-reason table has meanwhile been collecting since June 2025 and holds 18,633 rows, so the answers customers type when they leave are being captured while the surface meant to use them is not live. This is what the two records say against each other; it does not establish which of them is current, and neither was written to be read against the other.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "hypothesis",
          "title": "Destination-aware exit selection may reduce geographic detour",
          "detail": "A computed Bangkok-to-US-East example compares six exit choices using great-circle distances and a fixed route multiplier. The destination-adjacent exit adds no delay in that geometric model, while the modeled Los Angeles and Singapore alternatives each add about 20%. These are modeled propagation values, not measured routes or proof that the nearest exit to a destination is always fastest. The recorded client-source inspection describes concurrent TCP probes to region hosts; it was not executed in this investigation. Testing destination-aware selection is a candidate, not a product decision. Local ranking could avoid sending the destination to an additional selection service; it would not hide the destination from the exit that forwards the traffic.",
          "test": "Measure flag-selected and path-selected exits from real probes to twenty destinations customers actually reach. Drop the proposed performance improvement if median improvement is under about 5%. No live-network test or measured routing improvement has been established.",
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The earlier test of the residential premise was too small to have found what it was looking for",
          "detail": "An earlier battery tried sixteen destinations from a data-centre address, found none of them blocking, and that emptiness was being carried as evidence against the premise. Against the only published base rate available — a 2016 measurement in which 3.67% of the top thousand sites blocked, and which measured Tor exit addresses rather than proxies — sixteen independent draws carry about a 45% chance of containing even one blocker, so finding none was the more likely outcome even if the effect is entirely real; the seven-destination screening that followed carried about 23%. The empty result is therefore withdrawn rather than counted. This says nothing about whether the premise holds, only that nothing so far has tested it at a size that could tell. The search for a more recent comparison of the two kinds of address turned up nothing published since that 2016 study, which is why the base rate is that old.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-08",
      "milestone": "Kairos · Day 30",
      "attention": [
        {
          "title": "When the client reconnects it drops the address the customer chose, and we now hold a candidate that keeps it",
          "detail": "The paths a customer uses to pin a specific address were read in the shipped source rather than inferred from behaviour. On a resume the client accepts, the retry discards the pinned target, and the same shape appears again in the selector that carries a provider name. Both now have unapplied candidates that preserve the choice, each held against control traces that must not move, and a private goal-preserving retry simulation was built and walked through every viewport and theme state so the behaviour can be seen rather than described. Alongside it the current profile composition of one incumbent and the preset retirement of another were read as counterexamples, which replaced an earlier and false framing that a customer must choose between speed and place. What is still unproved is how often a real customer meets this and which cohorts have the path enabled. Nothing was applied to the product.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The 2026 paying-account map is filed, with its qualifying rule, its excluded population and its ceiling all stated on the face of it",
          "detail": "The map that turns the subscription record into a population of paying accounts was completed and filed. Every admitted source pull ran to completion, the frozen accounts were dispositioned rather than dropped, and the qualified set is a stated share of them rather than a residue left after filtering. From the retained aggregate a conditional ceiling of 23.6% was derived on the volume held by the top 96 of 9,548 comparable accounts, bounded by the observation window it was measured over and measured on retained aggregate volume rather than on revenue or on the whole paying base. An independent numerical and case verification certified the packet exactly, with a cosmetic dissent kept on the record rather than resolved away. The map has not been released to a room: it stopped at the support-audit and deployment boundaries, and the prevalence of support labels across the population is still unresolved.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The node quality score was reconstructed from the published artefact, and its inputs now have names",
          "detail": "The score that ranks supply had until now been read only from its outputs. The deployed artefact was taken apart statically and the calculation reproduced offline against the frozen registry response, with every stored score compatible with the reconstruction. The named recording rules behind its inputs were pulled and their misleading names and regional selection resolved, and the separate refresh pause, entry expiry and bandwidth lookback windows were separated rather than blurred together. A comparator with explicit per-request denominators and a baseline ablation now exists, and an opposing review of the whole reconstruction was run against it and certified with its dissent preserved. One question went out on the authorised channel — which deployment actually computes these fields — and came back as a named gap. The reconstruction is static throughout: it is not proof of what production runs.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "How the network hands out nodes was traced through the published discovery path, and the scheduled registry watch completed two more slots",
          "detail": "The disagreement between two registry views was carried further by reading the discovery path in the published artefact instead of guessing at it: selection happens before enrichment, the country list is capped by published defaults with a documented fallback, and the quality filter is only conditionally enforced. Two prescribed observation slots ran on schedule, every direct key lookup resolved, and the responses stayed compatible with the frozen branches while still carrying input tuples we had never seen. Country record counts were distinguished from the limited and enriched lists they are often confused with, and the supply inventory was read alongside on address identity and protocol, keeping published and non-global entries apart. A private timeline figure now separates fixed-key returns from list overlap so the two are not read as one signal. Nothing on the network was operated or changed.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The settlement path operators are paid through was read in the running code, including the routes that settle without anyone asking",
          "detail": "Two automatic forced-settlement routes were identified in the source and exercised against handler cases that pass unchanged against pinned code. The historical behaviour behind an empty return was localised to an address separation dated to early 2021, with the intention behind it and its production impact both still unknown. Fee incidence was then measured on a frozen August sample rather than asserted: groups charging above the halfway mark recur across windows, but they are a very small share of the settled value in that sample, and a secondary probability-weighted pass found that variance concentrated in particular window pairs rather than spread across the month. Alongside this the live recording rules behind operator earnings were named and their stored output checked against a direct aggregate, which agreed to within a rounding-scale difference. No settlement was requested and no payment claim follows from any of it.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Three routes to reading renewal, identity and exit were tested, and each one stops at a named place",
          "detail": "We asked what the record as it stands can actually answer about a customer leaving. The cycle and plan membership in the export does not supply survival from a fixed entry point, recomputed row by row rather than taken on trust. The backend user identifier was traced into the analytics identity and the conversion path, and the correspondence holds only conditionally — the warehouse origin and which runtime writes it remain unknown, and a bounded own-account job lookup around the table's creation exposed no producer. On the product side the renewal, management and access states were separated from one another, with the purchase call bound to a pinned platform dependency that constrains what a customer can do from inside the app; what actually happens when they try is still unknown. None of this required a new customer read.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "What a buyer is actually charged for across the proxy and scraping products, and how the comparators price the same thing",
          "detail": "The commercial contract a customer meets was read from the public surface rather than assumed from the catalogue. The first-request contract for the managed scraping API is now clear from the published pages and worked examples, though the grain at which a successful request is debited is not. The exhaustion notice a customer sees counts successful refreshes rather than connection resets, and the top-up route still does not settle how allowance, usage and expiry hand over to one another. Against that, three managed-browser platforms were compared on their own official pages across their published tiers, separating what is charged for acceptance from what is charged for use, and the live wording corrects a stale indexed claim about custom plans that a comparison would otherwise have carried forward. Financial replenishment, usable quota and resource continuity were kept as three separate things rather than one. Nothing was bought and no traffic was sent.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "A direction opened: selling the finished job rather than the route to it, and what would have to be true for it to pay",
          "detail": "Interest in products that sell a completed outcome with network infrastructure underneath was tested against sources rather than talked about. Comparators that already do this were read on their own terms — a device-and-browser testing service that sells runs, an observation platform that sells vantage points, and a streaming provider whose own documentation separates controlling the route from controlling what the player does. Published choice studies were read for how buyers trade attributes, with both stages hypothetical and the attribute sets differing enough to limit the inference, and the historical work on inferring content from traffic was qualified by ground-truth coverage and protocol exclusions rather than adopted. An earlier framing that the value must rest on infrastructure nobody else has was corrected: the interface and observation layer is an admissible place for it to sit, which makes it a hypothesis with a test rather than a preference. Separately a full company export was audited so prospect relevance, manual tiering and purchasing intent are separated instead of collapsed into one score.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "What could stand in for a residential exit was read on primary sources, and where each substitute stops is now written down",
          "detail": "A site that wants proof it is dealing with a genuine client has routes open to it other than a residential exit, and those routes were read rather than characterised from memory. Three primary sources were retained and set against an explicit requirements list: a client-attestation route, taken with its fallback behaviour rather than only its intended path, and a shared-relay design, taken at its stated development status rather than at its ambition. A task-level test was written for the comparison and deliberately left unrun, and nothing was integrated or exercised against a live service. What this leaves is a named list of what each substitute would have to do before it reached supply, which is what decides whether any of it matters.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The installed consumer app was exercised in the field, and one connected session carried IPv4 while IPv6 never answered",
          "detail": "The shipped Mac build was checked against what the storefront currently offers and the two still agree on the same version and build. Automated attempts to drive the app's connect path returned no available window every time, so that route was inconclusive as a control; a manually initiated connection was sampled instead and stayed connected across every sample, with the observed exit address matching what the app displayed. Over that same connected window every IPv6 probe timed out while every HTTPS probe over IPv4 succeeded. Direct egress was restored afterwards and a healthy control unit was added to the record so later comparisons have a baseline. Public release signals were triaged the same day and the selected application files compared at two pinned commits: the application files are identical and only dependency lock blocks moved, so the successor release changes nothing in the area we track.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "A random support sample was drawn under a frozen design, and the moment the app asks for a rating was traced in its own source",
          "detail": "The support reading from earlier in the week was extended with a properly drawn sample: the design was frozen before any case was opened, the conversations were classified against it, and the result was verified by replaying the source and checking overlap with cases already read, so continuity and trial stage are distinguished rather than assumed. No outcome rate or revenue estimate is claimed from it. In parallel the review prompt was read in the pinned client source and its lock-pinned plugin files against the official contracts: what the app logs before it acts is not the same as what it shows a customer, and the selection rules were retained without any claim about rating impact. The settings cached on an installed copy match the pinned defaults, with no targeting and no percentage rules present. A separate countercheck read the retained low-rating selection against the question of whether a customer's goal survives a failure.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The remaining read of the customer estate is now a written programme rather than a session-to-session habit",
          "detail": "What is left to read across the customer estate was set down as a programme instead of being carried from one working session to the next. It states a verdict rule — what has to hold before a field counts as answered rather than merely seen — and opens five dedicated sessions, each on a single question, so a question is either being worked or is visibly waiting. It also records which parts of the estate have already been read, so the same ground is not covered twice. The programme asserts nothing new about the estate itself: it is the order the reading will follow and the standard each answer has to meet.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "Two questions about where things are defined came back as gaps rather than pointers, and both are now named on the record",
          "detail": "Where a mechanism has no documented source, saying so plainly is worth more than a plausible guess. Two asks were raised on the authorised channel — where the additional-purchase and refill semantics for the proxy allowance are defined, and which deployment computes the quality fields the discovery path serves. Neither has a shared source. Adjacent pointers were named instead, a public candidate exists for the second with no binding to what production runs, and both gaps are recorded on both sides rather than left as an assumption. The lineage of the tables held out of the journey work is still waiting on warehouse access being re-authorised. One older access route was closed as superseded after the shared folder it depended on never arrived and a different route now serves it.",
          "receipt_count": 3,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "The sign-in the team uses is now watched through one scoped path, and a check that cannot answer counts as blind rather than as a pass",
          "detail": "Monitoring for the War Room sign-in was consolidated onto a single scoped credential path instead of divergent ones, and every monitoring probe that cannot answer is now counted as blind, so an unanswered check can no longer be read as a healthy one. Historical fixtures were separated from the current sign-in coverage so the suite measures the door that is actually in use. Alongside it a read-only review of the dynamic surfaces — sign-in, monitoring and the deploy path — ranked four chained findings, with nothing mutated, scanned, configured or deployed; those remain with Lee to authorise. The rest of the engagement's own machine ran underneath all of this: the brief pipeline, the private git rail carrying the exchange, the scheduled observation timers that fire the registry slots, and the evidence gates that refuse a result without a receipt. That machinery is why the numbers on this page can be checked rather than taken on faith.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "A resume the client accepts still discards the address the customer pinned",
          "detail": "Read in the shipped source and exercised against isolated harnesses, the accepted-resume path drops the pinned target address on retry, while five control traces stay unchanged under the candidate that preserves it. A single source-bound aggregate query over the telemetry names found the pinned-address feature present in one of two shards and the resume-path names absent from both, so the paths are not uniformly exercised across the estate. This is a source-level and metadata-level result: how many customers meet it, and which cohorts have the path enabled, are not established.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Two crashes from August resolve to the same accessibility null-parent dereference in the app framework",
          "detail": "Private crash sites were retained and compared against matching official symbols and executable bytes, and both August crashes land on a null-parent dereference in the framework's accessibility layer. The shared stack was already on the record in late August; what is new is the symbolication that names the site. What triggers it is not established, and the September tunnel failures are a separate matter that this does not explain. A reproduction attempt was parked rather than pushed when it met a safeguard.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The bandwidth term in the node score is computed over a multi-day lookback, and for a large minority of entries that changes the number materially",
          "detail": "One predeclared aggregate comparison with a frozen timestamp and partition controls measured the ratio between the score's lookback bandwidth term and its instantaneous counterpart. 8,766 of 39,340 entries in that comparison sit above a ratio of 1.25 and 3,403 of 39,340 above 2, so for a substantial minority the window is doing real work rather than smoothing noise. That population is the measure set behind this comparison, not the registry response counted elsewhere in this record where the denominators were 10,520 provider records and 6,381 residential entries; the two do not measure the same thing. The historical-summary and customer-effect limits stand: nothing here says what a customer experiences.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "When the quality map is empty the discovery path skips the quality filter entirely",
          "detail": "Read in the published discovery artefact: the filter that excludes entries by quality is only conditionally enforced, an empty quality map bypasses it, and missing-entry flags and finite preset rules decide the rest. Two bounded counterexamples were constructed against the reconstruction rather than argued for. Selection also happens before enrichment, so an entry can be chosen on a shape that the enriched view would have argued against. How often the map is empty in production, and how frequently this path is taken, cannot be established from a published artefact and are not claimed here.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The exhaustion notice a customer meets counts successful refreshes, not connection resets",
          "detail": "Traced through the pinned protocol serialisers and the source behind the notice: the counter that drives the exhaustion message increments on an explicit refresh that succeeds, and an ordinary connection reset is not that event. A customer who reconnects repeatedly is therefore not necessarily spending the allowance the notice describes, and the converse holds as well. Where this parks is what the backend treats as a distinct address for uniqueness purposes, which is not settled from the client side.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "High-fee settlements recur across windows, but they are a very small share of settled value in the sample",
          "detail": "A frozen August sample of 3,420 settlement events across 62 windows and 31 strata was read read-only. Groups charging above the halfway mark recur across windows rather than appearing once, which is why the pattern is worth naming at all, but they account for 0.179% of the settled value in that sample. A separate probability-weighted pass found the variance concentrated in particular window pairs rather than spread across the month, so a single-window reading would mislead in either direction. This is one sample: no month-level estimate, no operator economics and no recommendation follows from it.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The cycle and plan membership in the export cannot answer whether a subscription survived from a fixed entry point",
          "detail": "The export was recomputed independently rather than trusted: cycle and row-plan membership describe which period a row belongs to, not whether an account that entered at a given point was still there later, so a survival curve cannot be built from it as it stands. A historical discrepancy between the cycle recipe and the newer rounded profile was preserved rather than smoothed away, and the script that consumes it was scoped. Reading renewal survival needs either the producer's own definition or a different field, and the producer is still unidentified after a bounded own-account job lookup returned nothing.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "The value in a job-outcome product may sit in the interface and observation layer rather than in network infrastructure nobody else has",
          "detail": "An earlier framing required a defensible infrastructure difference before an outcome product could be worth building. Reading the comparators that already sell outcomes does not support that requirement: a device-and-browser testing service sells runs on commodity capacity, an observation platform sells vantage points, and at least one existing player sells the measurement layer over infrastructure it does not own. Selling a finished job over a network already in hand is therefore an admissible direction rather than one ruled out for want of a moat. Nothing is committed and no demand has been measured.",
          "test": "Read the priced unit of the three named comparators against their published terms: if what the customer is billed for is in each case network capacity or throughput rather than completed jobs or observations, the interface-value framing is dead and the requirement for an infrastructure difference stands.",
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-07",
      "milestone": "Kairos · Day 29",
      "attention": [
        {
          "title": "The verdict that the customer journey cannot be assembled did not survive its own review",
          "detail": "The standing answer that the journey cannot be stitched end to end was put through two independent blind reviews, each dispatched to a reviewer who could not see the previous round or the reasoning behind the claim. Both rounds supported the headline and dismantled the argument underneath it: the flat statement that identifiers are never recorded gave way to a four-class account of where the join actually breaks, one exclusion turned out to be defensible rather than fatal, and the real omission was named — nobody had ever measured how many accounts are reachable across sources at the same time. That measurement was then run on the 2026 account frame, gated on a dry run and a byte ceiling, with fifty-one diagnostic traces drawn across the cells so the counts can be inspected case by case. The engagement now holds a measured reachability picture where it had a verdict.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "A complete customer journey would carry 69 fields; the best one we can assemble carries 17",
          "detail": "A contract was written for what a full journey would contain, field by field, and then held against real accounts rather than against the schema. The best account we can currently assemble reaches 17 of the 69 fields, a randomly drawn one reaches 4, and neither resolves any of the 10 fields that would let someone state an outcome. Three readable pages were built so this is visible rather than argued: one traced account, a side-by-side of complete against best against average, and the reachability measurement itself. Beside them sits a plain assessment of the data machine — what exists, what is usable, what is broken, what is missing, and what shape a pipeline would have to take to close the gap.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Every 2026 paying account will be mapped, and the method is red-teamed before a single account is pulled",
          "detail": "The decision taken is to map the whole paying base rather than keep arguing from samples — roughly 8,900 accounts carrying a succeeded charge in the 2026 frame. The order is deliberate: the process specification goes to a blind adversarial review first, and only a design that survives it earns the right to pull data. Orchestration and criticism are handed to separate agent lanes, so the design and its critic do not share a head. Nothing has been pulled yet and the decision stands as proposed rather than in force.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The test that decides which VPN jobs actually need residential exits is built and ready to run attended",
          "detail": "Lee named the question as one of the engagement's main tasks: which jobs are objectively better performed on residential addresses than on server ones. The plan for answering it went through three blind adversarial rounds, each dispatched to a reviewer who had not seen the one before, and was rewritten after each. It now carries a safeguard that fails closed, an attended gate, a screening stage with a stop rule, the address as the sampling unit, fresh-completion tokens and explicit rules for anything the cutoff interrupts; findings fell 4 then 7 then 3 across the rounds and the last returned nothing blocking. It ships with a frozen task battery, an outcome classifier and a runner, so what comes back is classified evidence rather than impressions, and the run is set for tonight with Lee present. A warehouse companion was assembled beside it — connection, refresh, exhaustion and session-length counts by exit class over two comparison weeks — so the trial can be set against what the population already does.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The node ranking in the product's own source does not order by quality or by price, and a small change makes it",
          "detail": "Working from the product's own published source pinned to a fixed revision, we ran the real ranking code rather than a model of it: sorting by price left 16 of 24 synthetic orderings unsorted, and on each of four quality metrics 16 of 24 orderings came back in the wrong order with 8 of 24 picking the wrong node first. Replaying a captured discovery response through the same sorter reproduced 16 order failures and 6 cases where the best node was not chosen first. A small candidate change makes all of them pass — 11 of 11 named checks and 8 new package checks green, with the package's 10 original tests still passing. It is held as a candidate and nothing was proposed for release: this is a source-level reproduction, and how often it reaches a customer in the shipped app is not established.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The link from the product's published source to the app a customer installs is now partly established, and the next release is already diffed",
          "detail": "A result read out of the published source only matters if that source is what customers actually run, and that link was partly closed today: the release pipeline recomputes the installed build number, and 8 of 8 client source files we had already examined match that candidate exactly. The installed artifact's own identity is still unproved, so source-level results stay source-level for now. The shipped consumer app was read without installing it — 15 native files across 30 slices in build 219, carrying the tunnel library's platform metadata and configuration-API markers, with a mismatch between the public tag and the package manifest kept on the record — and the successor release was captured and compared before it ships: it changes 5 of the 8 files we track and adds reconnection paths keyed on target address and protocol. Separately the client's provider selection was exercised: an explicit provider pin holds inside the scope it declares, while selecting from a country pool can return a different provider, which matters to any trial that assumes it kept the node it asked for.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The paying-account picture was recomputed, and the job register now carries what customers say they use it for",
          "detail": "The account-level read was recomputed on a controlled method instead of the modal-account shortcut it had been resting on, which restores 6,888 identifiers the earlier method dropped; raw bands and revenue-join coverage are now recorded with their exact field and window limits attached. Alongside it the discovery census was refreshed across the whole support record, and the uses customers state themselves were added as explicit rows — gaming, team use, software testing, account creation for others, research contact. The ranking in the register was deliberately left where it was: self-reports inside a selected read are discovery, not a share of the base. No customer was contacted and nothing went out.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Occasional use is a fit question inside the products that already exist, not a missing way to buy",
          "detail": "We asked whether someone who needs a residential address for one short job can buy it, use it, stop and come back. The catalogue already answers the billing half: alongside the subscription there is a metered route that charges on both data volume and connection time, and prepaid time is sold by an incumbent elsewhere in the market, so flexible-duration buying is not novel. What the metered route does not carry, as documented, is the phone platform where the subscription is the only way in. The question therefore narrows to fit and platform rather than to a category nobody sells. Separately the residential entry pages were walked through to an unsubmitted checkout: the pricing comparison does distinguish the tiers — the entry tier is marked as excluding residential addresses and the recommended tier as including them — but the order summary a buyer confirms carries only the tier name, not the capability they arrived for. That is a comprehension question rather than a defect, and it was written up as a bounded test with a control, so a change could not be scored a success merely for moving everyone onto a costlier plan. Nothing was bought, changed or proposed for release.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Customer outcomes can now be read out of the support and review record at scale, and we know where that reading breaks",
          "detail": "Support is the only place customers say in their own words what they were trying to do, so a repeatable way to read it was built rather than improvised: a written contract per pass, a frozen packet of conversations, an encoding engine, a verifier and a recorded adjudication, so a coding cannot be reshaped once the answer is visible. The engine was then attacked rather than demonstrated — on a frozen set it met 14 expected encodings but also accepted 2 deliberately corrupted inputs, an attempt to isolate the cause of its failures came back inconclusive, and the semantic gaps a person catches were kept in the record rather than smoothed over. It is therefore a screening aid and not evidence on its own, which is why nothing it produced was allowed to move a ranking. Around it the record was read by hand where it counts: 430 unlinked support cases split into 218 that bridge to an account and 212 that do not, 60 conversations re-coded for repeat purchase, 483 messages followed up across four accounts, and all 160 selected high-star consumer reviews read for what a satisfied customer says the product actually did for them.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Reading the warehouse's own tables turned up a dated shape change and fields whose meaning is not established",
          "detail": "The tables the engagement depends on were read against themselves rather than against the documentation of them, aggregate-only and with every job receipted. One dimension in the review table changes shape from 31 August across 25,197 rows; a cross-check shows the protocol report does not reproduce that shift, a column-order change is the suspected cause, and the producer writing those rows is still unidentified after nine own-account jobs found no matching destination. In the same read the plan identifier is null on 99.975% of the rows the query returned, so nothing can currently be split by plan, and two tables the coverage census carries as never queried were in fact queried and still return a hash-matching result — the never-queried flag is not evidence a table is unused. Alongside this, 476 mobile rows carry an email-shaped user identifier with no established web-side counterpart, and the usage counters concentrate on a recurring set while repeated rows, future-dated rows and missing dates stay in the population rather than being quietly netted out.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The supply side was read on its own terms: what node operators ask about, how the registry moves, and what a quality score can be counted on to mean",
          "detail": "The network's supply side had not been read directly, so it was. The operator support record was captured on selected fields — 56,604 rows, of which 425 are eligible under the contract — and a seeded 30-record sample plus a 20-record follow-up were coded, with the official reward and settlement definitions pulled alongside so operator-facing promises, settlements and receipt evidence are separated rather than blurred. A bounded registry observation now runs on a fixed schedule: its first slot returned 11 successful requests, resolved 20 of 20 keys on direct lookup, and recorded 4 reported attribute changes. On the score itself, 34 of the 10,520 provider records in the captured registry response sit at a colliding default value, as do 25 of the 10,401 WireGuard entries — all of them, not the 6,381 residential subset counted elsewhere in this record — so a node at that value may be unmeasured rather than measured and average; the gap between the stored schema version and the node's own is on the record. No node was operated, no operator contacted and nothing on the network was changed.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Ten carried questions were checked against live systems, and two of the engagement's boundaries became decision-ready",
          "detail": "Every open question on the board was re-checked against the systems that answer it now, rather than against the note that raised it: current task states and ownership on their side, a live warehouse re-probe, the current cancellation classifier path, the paid-media picture, and the dispute measure, whose denominator is now stated as successful charge identifiers. Several closed as already answered or superseded instead of being asked a second time, and one was closed from their side within the day. Two boundary records were prefilled to the point of decision — the transaction perimeter and the initial data-and-systems schedule — each enumerating the exact choices their owner has to make and marking plainly what is inactive or unapproved. One question still waits on a person on their side and has not been sent.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The search-visibility source stopped accepting fresh reads, and the data-room map now shows it as a retained snapshot",
          "detail": "The key that reads our search-visibility source is no longer accepted: three bounded read checks were refused and the available browser profile showed no authenticated workspace. The capture taken on 27 August is still readable and still hash-matches, so the mapped denominators it supports — own-domain keyword rankings, ranking pages and live referring domains — continue to hold; what is gone is the ability to take a current reading. The room on the data-room map now states that plainly: a retained snapshot rather than a live connection, its maintenance stage marked blocked, and the map's evidence cut moved to today. The owner of that source on their side is still unnamed, so restoring an authorized read is an ask that sits with them. The warehouse doorway was re-probed the same day and answered live, and one further ask went across for the lineage of the seven tables excluded from the journey work.",
          "receipt_count": 3,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "A seven-day research window is open on the product and its market, and every unit inside it is written down before it runs",
          "detail": "A standing research window was authorized and now runs continuously against one goal. Every unit inside it opens with a written contract naming what will be checked and what would count as an answer, and closes with a findings file and a verification receipt, so a result cannot be reshaped after it arrives and a negative stays a negative. More than forty units ran today across the product's own published source, its live dashboards, the support record, the warehouse and the adjacent proxy market. Nothing from any of them is published or sent onward, and the window's state file names the next test rather than a conclusion.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The agent lane we work through is now installed on the other side, and the ledger surface answers only to core identities",
          "detail": "The message lane our agents use between runtimes was handed over as a convention rather than as a program: the parts that transplant cleanly were named, and so was the part that would have to be rebuilt instead of copied. It was adopted and installed on their side the same morning. A private channel for documents that must not sit in shared version control was accepted there as well, and its first package — three review drafts — arrived attended with no mismatches. On the War Room the ledger surface was narrowed to core identities and a check now runs on every deploy, so that boundary cannot drift back open unnoticed.",
          "receipt_count": 3,
          "link": "/system/",
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Three in four accounts in the 2026 frame appear in no source beyond the account root",
          "detail": "Of 241,540 accounts in the 2026 frame, 26,952 — 11.2% — appear together in identity, events and connection data; 13,485 of those also carry a payment record, and 4,115 appear across all six sources. 74.4% appear in none of the five sources beyond the root itself. This measures whether an account is present in a source at all, not whether that customer connected or paid, so it is not the same measure as the paying-base and never-connected figures carried earlier this week: those start from customers with a payment, this starts from every account in the year.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The stamp that reads as an event time is a period boundary",
          "detail": "Every one of the 87,569 rows in the 2026 window carrying this stamp is an update event, and on all of them the stamp equals the start of the period being reported. A delay computed from it measures the length of a reporting period, not when anything arrived, and the long tail such a calculation produces is an artefact of that length. Delivery lag across this pipeline is therefore unmeasured, and measuring it needs a different field. Separately, everything in this table before September 2025 arrived in three later bulk loads and is backfill rather than live capture.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "For paying customers, whether the product actually worked is answerable with what already exists",
          "detail": "A per-cycle table carries, for every paying user, data volume, sessions, online seconds, requests, errors, device count, a health indicator and churn — the product and usage stream in one place, and it sits outside the excluded set. The general read that the warehouse cannot answer whether the VPN worked for a given customer holds for accounts that never paid; for paying accounts it does not hold. Nothing new has to be instrumented to ask the question of them.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Residential and server exits can be told apart on two event types and not on session length",
          "detail": "The exit-type field is a clean binary on connection success and on the exhausted-refresh message, and null on refresh and connection-error events, so a residential-versus-server comparison is available on connection outcomes. The session-length table cannot be split by exit class at all: it carries no verified per-row key to join on, and 32% of its rows are exact duplicates that have to be removed before anything is counted. Any claim that residential sessions run longer or shorter has to come from a trial carrying its own duration evidence, not from this table.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Nothing in the account record says whether a customer is a business",
          "detail": "The company field is empty across all 885,269 contacts, so business-versus-consumer cannot be read from the account record at all. The only evidence of who a customer is and what they use the product for is what they write in support: across 92,376 conversations, 1,414 name gaming, 19 recent ones describe team use, 9 describe software testing and 4 describe creating accounts for others. These are self-reports inside a selected read, not shares of the customer base, which is why they were filed as discovery rather than allowed to move the ICP ranking.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "On Windows, one tracking key covers rows belonging to different accounts",
          "detail": "Aggregate reads across the warehouse show the tracking identifier carried on Windows rows collapsing into single groups, and the same key pairing rows that belong to different user identifiers. Any join that treats it as standing for a device or a person therefore merges customers rather than separating them, which is one concrete mechanism behind the join failures reported elsewhere in this record. This measures what the key does, not why it is constant, and it says nothing about the other platforms.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "Windows rows may still be attributable through click-side dimensions rather than the device key",
          "detail": "Joining on click-side dimensions instead of the collapsed device key resolved the Windows keys on a development sample and again on a holdout window locked before the test was run, with the unresolved residuals kept rather than discarded. If it holds, attribution for the Windows population is recoverable from data that already exists, with nothing new instrumented. Nothing was implemented in production and the route stands as a candidate.",
          "test": "Apply the same click-side join to the prespecified second holdout window, which has not been opened: if the share of Windows rows left unresolved does not fall, the route is dead.",
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Taking the five best-scored residential nodes in a country can put all five on one network",
          "detail": "A captured registry response holds 10,520 provider records, of which 6,381 are residential WireGuard entries spread across 114 country groups. Selecting the five highest-scored entries in a country with a deterministic tie-break landed all five on a single routing-policy network label in the strongest case, a country where one label covers 151 of its 165 residential entries. Choosing differently only among entries that score identically raises network coverage in 24 of the 42 country groups large enough to supply five labels, and costs nothing in score to do. This matters for any trial that tries several addresses and reads the result as broad coverage: distinct providers are not distinct networks. The labels were checked for form only, not against current assignments or observed exits, and a discovery response is capped and filtered rather than a census of supply.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-06",
      "milestone": "Kairos · Day 28",
      "attention": [
        {
          "title": "Connection stability is now something we can measure the same way twice",
          "detail": "Three stability runs completed end to end, each keeping its raw capture rather than only a summary, so any run can be re-read later without being repeated. The harness that runs them is filed with its own documentation alongside the study's source material, and a standing rule now governs every reading it takes: a measurement whose conditions were not bracketed at the moment it was taken is discarded rather than interpreted. One run was also carried out live and attended, so the harness is not the only witness to what it reports. Nothing from this study is published or sent onward yet — the headline question forks on one further test, and it has not been run.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "Four questions about grace, recovery and where payments fail were taken up under a written contract",
          "detail": "One investigation worked four subjects side by side: why historical grace was granted the way it was, how the dashboard behaves for someone actually operating it, what a recovery requires of a customer, and which payment and geography conditions qualify an outcome. Each was set out in advance in a contract naming what would be checked and what would count as an answer, so a result cannot be reshaped after it arrives. Nothing from it is published or sent onward and none of the four is settled tonight. What the engagement holds is the qualified version of four questions it had been carrying loosely.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Tonight's readings can be re-run by someone who was not there",
          "detail": "The investigation carries its own replay: scripts that reproduce each reading, a coverage record naming what was looked at and what was not, and a separate record of what has actually been established rather than assumed. Two snapshots taken from public sources during the work were kept rather than discarded, so a reading can be checked against the material it came from without going back out to collect it again. The replay reaches the warehouse without a credential stored beside it. The effect is that a result from this evening does not depend on the session that produced it.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-09-05",
      "milestone": "Kairos · Day 27",
      "attention": [
        {
          "title": "The five internal cohort checks are answered, and one of them changes how a lost customer should be read",
          "detail": "All five checks the review synthesis named were run to completion against the internal record rather than left as open questions: churn and refunds, the account-restriction cohort, support, reliability, and the June review mix. Every one is answered from closed cycles and recorded events, so each lands as a count with a stated population behind it instead of an impression. Two came back with the answer, two came back with a limit that is itself the finding, and the fifth is explained by the company's own launches — a support macro pointing customers at the public review site went live in late May and an in-app review prompt shipped in June, which is the review mix that month. The support denominator was settled along the way: support sits across three separate workspaces and 97.7% of support-flagged users of the product are in one of them, so counts taken from that one are close to the whole.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The affiliate rail is seven times bigger than the tag that is supposed to mark it",
          "detail": "The affiliate network's own record was re-pulled at the correct account scope, walked from the start of 2024 to this month, and joined to the warehouse. 9,333 of 9,403 distinct paid-subscription order numbers — 99.3% — resolve to subscriptions in the revenue table, and those subscriptions carry 5.9% of the warehouse's recorded gross: seven times what the click tag on the revenue channel field accounts for. Only 1,078 of the 9,333 carry that tag. This sits beside rather than against the 0.934% share this page carried yesterday — that number is what the tags say, this one is what the network's own order numbers prove, and the gap between them is the point. The earlier pull that came back with every metric cell empty was an unscoped request, not a closed door: with the account id supplied, the day report returns 320 of 416 populated cells for a single month and the order-level report carries the order number, amount and partner the join needs. A 10,000-row sample of signup-completion order numbers resolves to nothing at all, so signups on this rail are not subscriptions and must never be counted as them.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The complaints study is now a ranked briefing anyone can read, and it states what it will not claim",
          "detail": "The room carrying the complaints study was rebuilt around one ranked table of all 22 complaint types in plain words, each glossed from the codebook definition, followed by three findings, the rival products it is measured against — six similar-sized services plus the two largest — and the full table folded underneath. The published confidence intervals and the certification layer around them were dropped as a deliberate call: they produced 357 near-identical sentences where the ranking underneath is what the question actually needs. No figure on the page is typed by hand; all of them are read from the claims ledger, 175 of them marked live against the data. The page closes with a block naming four things it will not claim — including the share of claims on which two independent coders disagree, and the classes of source the corpus does not cover — so a reader can see the edge of the evidence without having to ask for it.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Four tables nobody had ever queried were opened, and the restricted-data map now covers the schema",
          "detail": "Warehouse coverage moved on three lanes. Four tables that no query had ever touched were read for the first time: the store's grace-period notifications, web checkout, click-to-connect timings, and a model-comparison table that was opened but not yet read out. Web checkout is the loudest of them and carries its own finding below. The grace-period notifications this page flagged yesterday now have their step — 97 in March 2026 before the run of zeros that begins in April — which fits a setting switched off in March rather than a gradual fade. Click-to-connect is usable but carries device-clock dates running out to 2032, so it has to be filtered before anyone reads elapsed time from it. Separately, the restricted-data class map now covers the schema at name-inferred grade across a linkage set of 215 tables, with the health-score false positives flagged rather than quietly counted; sampling to confirm the inference is the named next step and has not been done. Coverage of the warehouse now stands at 118 of 223 tables read.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The MN Daily room is publishing again and now recovers on its own",
          "detail": "The daily signal room had been serving a stale edition since late August. The cause was traced end to end rather than guessed at: the machine ran out of disk, the run silenced its own failed commit, the reconcile step then refused the resulting dirty tree with no way forward, and the scheduler re-ran that identical refusal every few minutes for ten days. All four links are now closed — the reconcile step commits its own generated output as a recovery path and refuses only changes it did not make, the run checks for free space before it starts, and a bounded retry budget stops the loop instead of hiding it. Today's edition is live and carries 13 items, verified by reading the room through the access wall rather than by trusting the deploy's own report.",
          "receipt_count": 3,
          "link": "/mn-daily/",
          "featured": false
        },
        {
          "title": "The last shut data room now has a dated ask standing on Mysterium's side",
          "detail": "The per-room liveness probe now recognises the case where a pending file has not yet come down from cloud storage: it asks for the download, waits, and declines to file a duplicate rather than reporting a room dead because a file was slow. With that noise gone, one room is genuinely refusing us — the SEO tool, whose key has returned an authorisation failure since late August, which is not something this side can repair. A written ask went out today in Lithuanian and English for a replacement: named for this engagement, read-only, one-year expiry, no unit cap, delivered outside chat. That is the whole remaining blocker on that room. The advertising-spend column named here yesterday still stands as well — one invitation from Mysterium's side clears it.",
          "receipt_count": 3,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "A blind cross-family review settled the retrieval question: no vector database, for any of the three jobs",
          "detail": "The question of whether this work needs retrieval-augmented generation or a vector index — raised on last week's call — was sealed into a brief and put to a reviewer from a different model family, read-only, with our own prior view held back until the verdict came in. All three of the brief's exercise gates passed before the verdict was opened. It splits three ways. For the engagement's own working retrieval: a source-discovery procedure across the full census of warehouse tables, no persistent index. For what we would recommend Mysterium adopt: a thin identity-aware layer over the search already native to each source, provisional and held internal until tested. For the private working vault: direct search with hand-built indexes, plus a standing rule that an incomplete search is not a negative result. Opening the held-back prior afterwards, the review converged with it on the vector question and diverged on where the real gap is — discovery, not embeddings. Three acceptance tests with named denominators and kill criteria are queued and none has been run.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The machine that runs this engagement stopped being able to lose work",
          "detail": "One aggregate on the operating side, where several lanes moved. Work in progress can no longer sit only in a temporary directory the operating system is free to delete: a detector now runs on a schedule, copies anything uncommitted or unpushed somewhere durable, and never deletes, commits or pushes anything itself — its first real run rescued four in-flight lines of work. A shell guard now refuses any script that pipes a command without failing on the pipe, wired into the write path; its first scan found 16 silently masked pipelines across 7 scripts. The War Room's own monitoring now tells a dead instrument apart from a lost network link, backfills whatever it missed when the link returns, and escalates on a curve instead of shouting once per run — tonight's three-hour outage would have produced 2 alerts instead of 20. Every warehouse evidence read now forces its file down from cloud storage before reading it. And the deploy rail that had been refusing every push in the repository is clear again, which is what let today's pages ship. All of it was built red first: the failing case was watched failing before the fix went in.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "A customer lost to a failed renewal does not come back; a refunded customer does",
          "detail": "Across 148,106 closed subscription cycles, 0.0% of customers whose subscription ended on a failed billing retry — 26,764 of those cycles — bought again within 90 days, and 0.0% of those who cancelled voluntarily did. Of those who were refunded, 25.0% did. These are not two degrees of the same loss: on this evidence one outcome is terminal and the other is not. It follows that anything shortening the recovery window on a failed renewal is a different class of decision from anything touching refund policy, and the two should stop being traded off against each other.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Roughly half of this year's invoices are never collected, and disputes are not the problem",
          "detail": "Of 49,460 invoices raised on the card processor in 2026, 49.2% were never collected. The same thing counted per charge attempt rather than per invoice reads 74.7%, and that figure should not be quoted anywhere: invoices average 2.09 attempts each, so retries inflate it against the invoice-level truth. On the other side of the same book, exactly 1 charge out of 111,794 was disputed. Collection at the moment of renewal, not chargebacks, is where this rail leaks — the chargeback question is answered and it is close to zero.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Customers keep being billed after they tell the app they are cancelling",
          "detail": "6,636 paid cycles ran against 2,565 distinct customers after those customers had already filed an in-app cancellation reason. 2.9% of those cycles were refunded. Filing a reason inside the app is not the same act as ending the subscription at the store or the card processor, so this is a seam between two systems rather than a billing fault — but from the customer's side it is being charged after saying stop, and it is measurable, dated and fixable at the seam.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The account-restriction tag is a support tag, not telemetry, so that cohort cannot be sized",
          "detail": "2,512 of the 2,517 users carrying the restriction tag had contacted support, which is what the tag actually records: it marks a conversation, not a restriction event. There is no column for it in the data at all — the neighbouring tags in the same family exist, this one does not. Nothing anywhere records what triggered a restriction, whether it was a false positive, or how long it took to lift. The consequence is two numbers that cannot be set against each other: the tag reaches 1.6% of all users, while 18.2% of customers who answered the cancellation survey name this as their reason, and those populations are not comparable — one is everybody, the other is people who both cancelled and chose to answer. Sizing this cohort honestly needs an event that does not exist yet, and that is a build, not a query.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "The flagged cohorts are the higher-paying customers, and one of them churns less than the base",
          "detail": "Customers carrying the restriction-related flags have paid about 3.9 times the average across the whole base, and the cohort carrying the telemetry flag churns less than the base rather than more — 63.9% against 79.3%. That is the opposite of what a restriction story predicts, and it is worth carrying forward precisely because it is inconvenient. The obvious confound is named rather than argued away: flagged customers have been on the book longer, and tenure alone lifts both lifetime spend and apparent survival.",
          "test": "Recompute both figures inside tenure bands. If the flagged cohorts still pay more and still churn less within the same band, tenure is not the explanation and the inversion is real; if the gap closes, the flags are simply landing on older accounts.",
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Fraud screening blocks a fifth of US card attempts and less than a tenth of Nigeria's",
          "detail": "The card processor's own fraud screening blocks 21.4% of card attempts originating in the United States, against 8.7% of attempts originating in Nigeria. That is the reverse of what a risk rule written on intuition would encode. It sits alongside rather than against yesterday's read that the Nigerian decline is concentrated on the app-store rail: this measures the card rail, where that cohort barely transacts, so a low block rate here does not soften that finding. What it does say is that the largest market is losing a fifth of its attempts at the screen before a payment is ever tried, and that is answerable from the processor's own rule set without any new instrumentation.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Three web checkout attempts in four are declined, and nearly half of a month's users never settle at all",
          "detail": "On the web checkout table, between 75% and 78% of attempts end in a decline. Read per person rather than per attempt, 1,763 of the 3,998 users who tried in August — 44% — never completed a payment. No query had ever touched this table before today. It is a different measure from the invoice collection rate on the card processor and should not be added to it: that one counts renewals of subscriptions that already exist, this one counts people trying to start one.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The field that looks like proof a customer connected is not one",
          "detail": "A question this work has carried for weeks is settled: the total-connections field is a telemetry flag, not a record that a connection happened. 49.59% of users the field marks as never having connected do have recorded traffic. Any cohort built on that field — including anything read as 'never activated' — is counting the flag rather than the behaviour, and roughly half of it is wrong. With the false negatives removed, 33,147 paying customers remain in the genuinely-never-connected population, and that residual is the number worth acting on.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-04",
      "milestone": "Kairos · Day 26",
      "attention": [
        {
          "title": "Nigeria's fall is demand meeting the one payment rail it cannot route around",
          "detail": "The decline in the Nigerian cohort's paid cycles from January to August — the open question this page carried yesterday — was decomposed by payment gateway. Google Play carries 819 of the 881 net lost cycles, 93% of the whole fall, while that same rail is down only 2.1% in the rest of the world over the same months, so the rail itself is working. The cohort runs 71.8% of its paid cycles through Google Play against 10.9% for the United States on near-identical volume, and when a repricing suppressed Play purchases the US base moved onto Apple and onto cards, up 51.7% and 39.7% on those rails, while this cohort had nowhere to move. Measured free of plan mix the repricing is about 40% on new cycles in both markets, so one global price change is landing on two differently built payment bases: not a rail failure, not a reliability problem, and not a decision taken about Nigeria. Country was settled before anything was counted — billing country is constant across 100.0% of multi-cycle subscriptions while device country changes in 34.5% of them — so the whole read is on where a customer is billed rather than where the app connected from.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "Affiliate revenue is in the warehouse after all, and most of the network's own sales are never tagged",
          "detail": "The affiliate reconciliation was re-run across the whole revenue book instead of the fifteen-order sample it started on, and it moves two earlier readings. The warehouse does record affiliate revenue: the two networks' tags together account for 0.934% of the recorded book on the revenue table — which sits beside rather than against the earlier result that none of 145 network-proven orders were attributed, because that test read the marketing event path, and that path still carries zero affiliate rows across all 40,060 of its events. A network order number joins to its subscription at 99.5% on 200 checked, so the two sides can be matched, and the gap is at the till: only 43.0% of the network's own proven sales carry a tag in the warehouse, while a tag once present survives 100% of that subscription's later cycles. Running the other way, 30 of 116 tagged subscriptions — 25.9% — are missing from a network capture that reported every month complete, and the programme's start is now fixed: it went live in late August 2025 and paid its first commission that September, so the zeros before then are the programme not existing rather than performance.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Every data room now has its own liveness check, and the unlock page is cut against what actually arrived",
          "detail": "A probe now tests all eight data rooms individually rather than treating the warehouse as a proxy for access, with 47 failure cases watched failing before it went in; its first production run caught one room refusing our key outright. The data-unlock page has been re-cut byte-exact against what the warehouse open and the room captures actually delivered — five standing asks answered across the SEO tool, the email platform, the affiliate networks, Slack and ClickUp — and now waits on the lane that owns the room to publish it. What is still shut is named rather than assumed: the marketing dataset holds a single event table with no cost column, so the ad-spend ask stands and one invitation from Mysterium's side clears it; two datasets in the inventory are empty shells; and the affiliate-network capture that did arrive came back with every one of its 13,481 metric cells empty and no order number on the report type it covers, so the joinable reports were never in scope.",
          "receipt_count": 3,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "Our own product and a major competitor were measured in the same hour, on the same link",
          "detail": "The two products finally share a control: both were run from one machine on the same connection and the same battery state within a single hour, each bracketed by a direct baseline before and after. Our own controlled sequence ran direct, a Šiauliai datacenter exit, a Vilnius residential exit, then direct again, and the exits themselves checked out — the datacenter exit classifies correctly as hosting and sits in the right city, and DNS leaves from the exit's own address range rather than from home. Two new residential exits both classify as ordinary residential lines carrying the correct Vilnius city, which puts the earlier city mismatch at one sample in four rather than a pattern. The competitor's product carries a state defect of its own: after disconnecting, its app still displays the exit as the user's address while the machine is already direct — a stale display rather than false protection. Two measurement sets that straddled a session ending were thrown out rather than reported.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Two decisions carried past this week's checkpoint, and both sit on Mysterium's side",
          "detail": "The weekly checkpoint ran with the working group, and the company's all-hands was attended earlier the same day, so the week's picture comes from the rooms themselves rather than from reports about them. Two items on the week's list could not close and now carry forward: the board pack, and the disaster-recovery and backup decision. Both are owned on Mysterium's side, and neither can be settled from ours. Both calls were recorded and written up into the engagement's own record; the remote side of each recording carries the group as a single voice, so nothing in it is attributed to any named person.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Week 4 of the engagement is published, built from a continuous sweep rather than the nearest artifact",
          "detail": "The canonical weekly account was assembled from an unbroken sweep of 29 August through 4 September, passed a sealed independent review before it went out, and is live at the weekly address with a public parity receipt showing the published page matches the source it was built from. Every ask it carries now names its owner and whether it moved, so the report reads as accountability rather than as a list. A separate Week 4 review room was prepared and deployed on the same team route and verified live behind the door. Five of the asks standing on the report are owned by Mysterium and remain open.",
          "receipt_count": 3,
          "link": "/reviews/sprint-01-week-04/",
          "featured": false
        },
        {
          "title": "The opportunity board narrowed to the VPN, and the asset candidates behind it became one register",
          "detail": "The ranked board was re-scoped to the consumer VPN. Three surfaces belonging to the direct-proxy side were removed into a separate later mission rather than carried along, leaving twenty-three surfaces and twenty-two constructs, three ranked opportunities, two open slots and six contenders. The rule governing the split is written down beside it: the two maps are compared only once both exist, and opportunities that sit in neither territory are kept rather than dropped. Separately, the VPN product, operating-data and adjacent node-network asset candidates that had been discussed across several places were consolidated into a single register, each candidate carrying where it came from and how mature it is. The previous version of the board stays reachable from the current one.",
          "receipt_count": 3,
          "link": "/opportunities/",
          "featured": false
        },
        {
          "title": "Every claim in the competitor complaints study now ties back to the pass that produced it",
          "detail": "The coding passes behind the study were re-run so that each one carries a hash written at the moment its output was produced, rather than a hash of a copy made later — the classification of 5,918 units and the holdout pass both. Three method gates now stand in the way of anything weaker, and each was proven against the exact failure it exists to catch before it was wired in: an output with no contemporaneous hash is refused, an adjudication not written by the adjudicator is refused, and an unhashed holdout is refused. The discovery pass was deliberately left out of the rerun and the reason is on the record rather than left silent: its output is the frozen codebook the whole study is coded against, so rerunning it would start a different study instead of re-evidencing this one. The study builds with 357 claims and no rejects; publication to the War Room waits on the reviewer's approval.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The customer-journey execution passed an independent review, and its replay is now runnable by the reader",
          "detail": "An independent reviewer read the sealed execution packet and returned sixteen findings, two of them blocking. All sixteen were accepted and answered rather than argued: the selected replay was made executable and aggregate-only, so a reader can re-run the selection without touching a single customer's row, all forty-two fixture properties were published, and the denominator, packet and call claims were corrected to what the evidence actually supports. One check could not run because a warehouse credential had expired; it was left failed and stated as failed rather than filled in with older counts. The reader surface is live behind the team door with its acceptance recorded against the live route.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The One Big Thing room reached a sealed release that claims no authority until a schedule is signed",
          "detail": "The room went live at its War Room address after a review cycle, with all thirty-two of its current and archived files signed and matched exactly against what was deployed, so the page and its record cannot drift apart unnoticed. Its boundary is written on the page rather than assumed: it holds no authority and starts no material pursuit. One thing stands between the room and pursuit, and it is not ours to supply — a signed Opportunity Schedule.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The engagement's own machine gained provable review authorship and a retention rule on every model surface",
          "detail": "Independent review passes now run through a headless runner that survives a restart and emits a machine record naming the model and the run, so who authored a review is established by the record rather than asserted — the exact provenance an earlier reviewer said could not be established here. The rule for handing work to any model surface now includes that surface's data-retention terms as part of the test it has to pass, with a local, non-cloud path for the slice too sensitive to send anywhere at all. The shared evidence rail carried five publications, each verified at the far end rather than assumed on push, and the warehouse's nightly pass ran its inventory, fitness and squeeze batch on aggregates only.",
          "receipt_count": 3,
          "link": "/system/",
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "An exit inside Lithuania cost more round-trip time than a competitor's exit in the Netherlands",
          "detail": "Measured in the same hour on the same link, bracketed by a direct baseline before and after, our own product's exit inside Lithuania ran 101–106 ms round trip while a major competitor's exit in the Netherlands ran 59–69 ms, against 24–35 ms on the same link direct. Throughput was deliberately not compared: two direct runs ten minutes apart differed by more than four times on the upload side, so ordinary link variance is larger than any effect a single pair of runs could show. This is one pair of runs on one machine and one link. It establishes that the latency gap is worth sizing properly against production, not how large that gap is in production.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "Every connect attempt in the controlled run ended by itself, and traffic went back out the real address each time",
          "detail": "Across five connect attempts in one controlled sequence, all five sessions ended on their own — some within seconds, the longest a little over four minutes — each reporting the same internal plugin error, with no crash report written and the application process gone afterwards. Each time, traffic resumed straight out through the real ISP address instead of stopping. This is the same fail-open behaviour recorded earlier when the tunnel provider was killed deliberately; what is new is that nothing was killed. One boundary is open and stated rather than glossed: these launches were driven by a harness in the background, so an application fault cannot yet be separated from how the application was started.",
          "test": "One attended connect, started by hand and held for several minutes: if the session survives, the harness is implicated and the application is not.",
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Inside our tunnel IPv6 has no route at all; inside the competitor's it carries through to the exit",
          "detail": "On the same machine within the same hour, our own product's tunnel offered IPv6 no route, so IPv6 traffic fails closed and cannot slip out around the tunnel, while the competitor's tunnel carried IPv6 through and exited with it. Both are defensible designs, but they are different promises: one refuses that traffic, the other protects it. Anyone comparing the two products on privacy has to say which of the two they mean, because a single privacy score hides the difference. In both cases DNS left from the exit itself rather than from the home connection.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The Nigerian decline overstates the damage about threefold once margin is counted",
          "detail": "Paid cycles in the cohort are down 36.8% from January to August — the same measure this page carried yesterday — but profit from that cohort over the same months is down 11.8%, because margin on it rose from 59.0% to 72.1%. Over the same window the United States grew 30.4% in revenue on 10.8% more cycles, which is the same repricing read from the other side. A cycle count is the wrong instrument for the size of this problem: it measures how many customers are transacting, not what the cohort is worth.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "Grace-period notifications from the store stopped entirely in April and nothing has flagged it",
          "detail": "Across the whole subscription base, notifications that a subscription had entered its grace period ran between 1,259 and 1,449 a month through February 2026 and have been exactly zero every month since April 2026, while the on-hold notifications that normally follow grace continue at ordinary volume. The pattern fits grace being switched off in the store's subscription configuration. The Nigerian decline is measured from January, before these zeros begin, so this is not that cause — but if grace is genuinely off, every failed renewal on that rail loses its recovery window, in every market at once.",
          "test": "Read the current grace-period setting in the store's subscription configuration: if grace is still enabled there, the zeros are a gap in how those notifications are captured or routed, not a product change.",
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Affiliate attribution fails at the moment of purchase, not over the life of the subscription",
          "detail": "Of the affiliate network's own proven sales, 43.0% carry a tag in the warehouse; of the tags that are present, 100% survive every later cycle of the subscription they sit on. Those two numbers together locate the loss precisely — the tag is either written at the till or never, and nothing erodes it afterwards. An earlier reading that the warehouse attributed none of 145 network-proven orders was measuring the marketing event path, a different table from the revenue channel field these shares are read on, so the two do not disagree. The place to fix this is the purchase handoff, and the size of the prize is the 57% that goes untagged.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-03",
      "milestone": "Kairos · Day 25",
      "attention": [
        {
          "title": "The nine-month take-back campaign now has a dated room and a verdict that holds on four instruments",
          "detail": "The zero purchases on that campaign page were re-verified on four instruments outside the lineage the first read came from: Mysterium's own session tracker, same-session analytics, a user-level analytics view over two months of ever-bought behaviour, and the purchase and subscription source streams, which name no such campaign while naming the brand and shopping ones. The traffic itself was re-read at the same time — the bought sessions arrive as video, display and in-app ad taps, nine tenths of them from one ad platform, and almost none from search on the keywords that page's subject would imply. All 470 distinct articles were classified and only 17 of them touch VPN or privacy tools, so the editorial run did aim at the single stated persona. The room is live behind the team door with the run's duration, the sibling initiatives, the paid book, the target-customer comparison, and the one unknown that would close it.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The company's whole paid acquisition book was measured, channel by channel and page by page",
          "detail": "Every 2026 paid purchase was traced back to its origin rather than assumed: three channels and one page carry almost all of it, with the offer page alone holding 84.9% of paid purchases. Paid clicks account for 13.5% of new purchases company-wide and 24.8% of the web door, so roughly 86% of new customers arrive with no paid click at all. Two social buys were measured on the converting pages as well — one bought 45,396 offer-page sessions for 25 purchases, another 50,104 sessions for 2 — so paid-social weakness is not confined to the awareness family. Named campaigns skew hard to brand search, which captures demand that already exists.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The consumer VPN's unit economics were read off Mysterium's own cost tables",
          "detail": "The warehouse's fee, cycle and traffic tables were opened on their cost columns rather than their revenue columns, which puts direct network fees at 11.1% of revenue and traffic at 11.9%, and leaves 71.5% of revenue as contribution after those direct lines. Nigeria was then closed as a question on the same cycle table: that cohort keeps 64% of a paid cycle against 73% for the United States, every payment gateway is positive, and it consumes 27% of gigabytes for 16% of revenue. What stays open is the decline — paid cycles in that cohort are down 37% from January to August. Nine rerunnable evidence tables and the query set behind them are filed, so none of these figures rests on a one-off read.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The paying base was profiled customer by customer across app, revenue, refunds and payments",
          "detail": "August's paying installs were joined at customer grain across four systems that normally sit apart — app events, revenue, refunds, and the payment processor's own dispute and risk records — and then profiled by home country, ten countries against thirteen signals each: gateway mix, protocol, client version, session length, time of day, and support contacts per thousand. The connect path was read on the same population, so the profile carries how often connecting actually works, not just who pays. The profile also separates heavy honest use from abuse instead of assuming they travel together: card-testing signals sit on cards issued in North America, while the countries carrying the largest usage show ordinary dunning failures. Country is taken from upload location throughout, because exit country describes an exit and not a customer.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The consumer-VPN ICP now has membership rules that run against the warehouse",
          "detail": "A jobs register and a behavioural ICP table were built and then rewritten through four adversarial rounds with every round's findings integrated in full: nineteen candidate jobs, fifteen ICP rows, sixteen survey screener rows, every figure sourced to a named result file, and geolocation taken from upload location rather than exit country. The rules run as warehouse predicates over the 102,912 paying installs of August, with sizes, home-country lifts, an economics join and overlap tests; that population is August paying installs, not the avatar-matched cohort behind the earlier twelve-cell threshold run. By decision the register stays a working note and becomes canonical only when one link reaches tested. The evidence room behind it was widened from owner-only to the whole authenticated Kairos team and verified live for each of them.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The opportunity board was re-ranked blind, and the VPN case narrowed to one learning commitment",
          "detail": "The opportunity portfolio was re-ranked under a blind, denominator-first rule, and what is filed is byte-identical to the candidate an independent review tested, so the ranking on the record is exactly the ranking that was examined. The review's authority and its no-effect boundary are filed with it: the re-rank proposes an order and changes nothing until it is adopted. Alongside it, a VPN-only provisional learning commitment was assembled — the single thing worth learning first if the VPN is the subject — and put through a red team before it was filed. One candidate now has a room of its own, owner-scoped for now, carrying the current version beside the historical one it replaced, each preserved as an exact copy that cannot drift.",
          "receipt_count": 3,
          "link": "/opportunities/",
          "featured": false
        },
        {
          "title": "The turnaround proposal became a concrete six-week rescue simulation with named gatekeepers",
          "detail": "The agent-run idea was reframed as a new product inside the existing company rather than a spinout, and the proposal page was rebuilt as a six-week Second-Attempt Rescue operating simulation: every customer-contact and production gatekeeper named and counted, the repository and delivery mechanics sealed, and the headline stated as a literal division of work between Kairos and Mysterium. Architecture ownership was settled — the documented architecture owns the design, on two conditions: it must be executable at the silent seams, and it must escalate to a human through a written decision record. A twenty-six-operation recurrence table was built from the company's own record alongside it, naming eight constants that run the full nine years. One board-pack page for Robertas is queued next.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The full customer journey is now a room behind the team door, with six evidence dossiers",
          "detail": "The journey room was moved off an unauthenticated host into the authenticated War Room team door, with twelve interactive scenes, role-scoped search, theme persistence and five responsive widths checked live. Six evidence dossiers were then added with pointer, click and keyboard panels, so a reader can see what each stage's evidence would have to look like instead of taking the claim. A stitchability audit ran against the retained trace queries and every room ledger and reached a firmer answer than the earlier one: the existing evidence is not exhausted, an unknown beginning does not erase the observed journey, and the untested joins are now named without any new extraction. The blind, denominator-first process for exhausting all six streams is frozen for later execution.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The competitor complaints study cleared its architecture review and opened collection",
          "detail": "The frozen architecture went through nine adversarial rounds to approval, each round's items repaired in code against isolated negative fixtures, and the publication pipeline now generates the page from its ledger and refuses anything that is not byte-identical to it. Enumeration over 650 products froze eight comparison members across three tiers, their review corpora were captured on a stated capture date, and a codebook was adjudicated out of two blind discovery passes. Two independent coders then classified 5,918 units with exact category-set agreement of 0.852, on a codebook whose holdout reliability reached 0.920. The consequence is that when this study reports a complaint share, it will arrive with a measured agreement figure and a pre-registered sampling design attached.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The authorized data-room capture ran, and the shared workspace is now reproducible offline",
          "detail": "The capture executed and verified across the workspace, the dashboards, the impact months, the customer-journey months and the campaign records: 2,510 records with none unparseable, 226 lists across 13 spaces, and all 152 dashboards with their folders and data sources. One room stayed out for want of a key. Storage is isolated from anything that commits or syncs, and its manifest records the authorization, the purpose, the scope, the exclusions, the retention and the deletion trigger. The credential scan is clean, and the personal-data content was measured rather than assumed — every address counted and classified by domain, so the handling question can be answered with a number.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The open asks went out one at a time, and the owed-data list now names rows",
          "detail": "One question went out for forwarding: the server bill, what actually runs on it, and which nodes the company runs itself. The customer-journey commissioning brief's send is on the record with its forward, receipt and response states left explicitly unknown rather than assumed. The owed-data table now names specific rows instead of subjects — dispute syncs, gateway country and risk scores, store refund and dispute exports, the blocked list, the node session log and the proxy database — and the advertising cost column is named as the single unknown that would close the campaign verdict. A census of the warehouse we already reach shows 108 of its 223 substantive tables have never been opened, about a dozen of which matter. A working agreement carrying confidentiality and data-processing terms is an open gap, and it is the next ask alongside the missing key.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "A governed first pass through a major competitor's free product is on the record",
          "detail": "The whole free-tier path was walked in sequence and recorded as it went: install, first launch, the signup funnel, account creation and password recovery, the desktop app and its system network extensions, the first tunnel, a one-change server replacement, and a repeat quick connect — each with paired direct and tunnelled measurements and a clean return to direct. The funnel presents the paid plan before the free one, and two telemetry choices arrive already switched on. Every observation was preserved privacy-bounded before any conclusion was drawn, and the conclusions are bounded to what one governed pass can carry. It gives the engagement a like-for-like onboarding baseline to set our own product's first connection against.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The team door is proven end to end with a human sign-in, and the daily canon carries the week forward",
          "detail": "A person signed in with a real code through the whole path — code exchange, token, and a landing on the War Room — and the room recorded that read against his alias. Readership is therefore an instrument with a human read behind it, not a hope; a second browser was then confirmed as a human session on the same door. The daily canon was rendered forward on top of that: three new insights, a machine-readable hypothesis fixture, a cancellation-reasons card, the never-connected churn hypothesis, the first-sprint outcome review row for the sprint that closes on the eleventh, and three items recovered onto the shelf.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The engagement's own machine gained an upload lane and a deploy tree that matches what is live",
          "detail": "The git rail Kairos runs on gained a drop upload endpoint, built with its red test and pushed as a branch for deliberate landing by its author. The deploy checkout was brought current with the live lineage, so the surface checks and the data map now read the tree that is actually serving, at its full twelve rooms. The agent message lane was cleared end to end with red-first fixtures across the surface check, a lock-ordering guard, successor counters, fallback classification, the voice registry and the mirror fetch guard. And every number filed today has a rerunnable script or query standing behind it — the settlement, recurrence and forensic query sets, the never-queried table register, the evidence tables — so none of the day's evidence has to be rebuilt by hand to be checked.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "The same ad account ran a converting destination and a non-converting one side by side for nine months",
          "detail": "In the same account and the same months, the take-back destination took 426,435 paid sessions and recorded no purchases, while the offer, deal and pricing destination took 213,985 paid sessions and recorded 2,931 purchases, a rate of 1.37% of those sessions. This is the same population the earlier zero was measured on — 527,284 page sessions, 87.7% of them bought — now cross-checked on four instruments outside that lineage and set against a sibling destination in the same account. Tracking works, the ad platform works, and a converting campaign is demonstrably runnable; the variable is destination and message. What the click split cannot tell us is the money split, because the two halves bought different inventory at different prices and the cost column is not in our hands.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Roughly 96% of the paid purchase book carries no campaign name where campaign names live",
          "detail": "The session tracker sees about 4,424 paid purchases in 2026, but only 176 of them carry a paid medium in the analytics property where campaign names are recorded — so about 96% of the paid book is invisible at the level anyone would use to judge a campaign. Of the 176 that are named, 129 are brand search, which captures demand that already exists. This is the mechanism that let a nine-month zero pass unnoticed inside the company's own reporting: spend lives in the ad platform, revenue lives in the warehouse, and no report joins them.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Installs are not accounts, and a small share of accounts holds most install slots",
          "detail": "Recomputed at account grain over August, 9.8% of accounts hold 54% of install slots, and several country groups that looked large in install counts collapse onto a few dozen accounts each. Any segment sized in installs therefore overstates the number of people behind it, and geolocation has to be taken from upload location rather than exit country before a country figure means anything. The stitching that would close the gap is itself thin: login events reach only 7,455 of August's 62,614 fresh installs, so install-to-account lag is unmeasured for the remaining 88%. This is the day's single question to Mysterium, sent with its aggregate tables.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The workspace task endpoint under-reports by 24% and gives no signal that it did",
          "detail": "The canonical task read path returned 5,379 of the 7,068 distinct tasks that exist, and it terminated cleanly on a last-page marker, so nothing in the response indicated a shortfall. An archived sweep recovered 578 more; the remainder came only from walking all 226 lists. Any count taken from that endpoint — including counts used internally — is low by roughly a quarter unless per-list enumeration is used instead.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The Payments space in the shared workspace is empty",
          "detail": "The Payments space holds two lists and no tasks at all, confirmed by live probes on both the archived and unarchived views rather than inferred from a count. Against a payment-recovery workstream that is one of the larger revenue questions in front of us, an empty space means the work either lives somewhere else under another name or has not been organised as work. It is a fact about where the record is kept, not a claim about whether the work happened.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The consumer VPN's direct network costs leave most of its revenue as contribution",
          "detail": "Measured on Mysterium's own fee, cycle and traffic tables, direct network fees run at 11.1% of revenue and traffic at 11.9%, leaving 71.5% of revenue as contribution after those lines. This measures the product's direct network cost only — not the group's overheads, payroll or shared functions — so it says the VPN product covers its own network cost with room to spare, and it says nothing about whether the group as a whole is profitable. Anyone setting this against a group-level figure is reading two different denominators.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "Nigeria is a customer, not a cost, and the open question there is the decline",
          "detail": "On the company's own cycle table, the Nigerian cohort keeps 64% of a paid cycle against 73% for the United States, every payment gateway it uses is positive, and it consumes 27% of gigabytes for 16% of revenue. Its retention runs at about 60% of the US level and its failures cluster in dunning rather than in card testing, which shows up on cards issued elsewhere. An earlier read that treated this cohort as a fraud and refund problem does not survive the cycle table: the refund picture is ordinary once a single defective row on an impossible amount is excluded. The live question is that paid cycles in the cohort are down 37% from January to August.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "A third of the paying installs that reached connecting met a connect error in August",
          "detail": "Read on Mysterium's own app events for the month's 102912 paying installs, 35.4% of those that reached connecting met a connect error, and 3.3% of those that tried never connected at all. The two leading codes are different in kind: one is a server-side failure, the other is the device-limit rule, which is policy working as written rather than a fault, and a third is a retry loop. This is not the same measurement as the 56.7% never-connected share filed for churned users, which is a warehouse label on people who had already left and is still open as a definition question; this one counts connection attempts by the paying base within one month. It is counted at install grain, so it says how many install slots met an error, not how many people did.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-02",
      "milestone": "Kairos · Day 24",
      "attention": [
        {
          "title": "The audience work found paid traffic reaching a page where the purchase journey never started",
          "detail": "The take-back-the-internet page received 527,284 sessions and recorded zero transactions across its measured run; 87.7% of those page sessions were bought. Google Ads sent 426,435 sessions to that page in 2026 while its click-through to pricing was 0.08%, versus 8.68% site-wide. The existing target-audience document remains hypothesis-grade and a provisional consumer-VPN ICP now carries an explicit next-test ceiling.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The customer-discovery branch now proposes one bounded first-connection pilot with an accountable owner",
          "detail": "Instead of governance language, the branch names a specific first move: a bounded pilot on the first-connection experience, the exact ask it puts to Mysterium, the actions and measures it would run on, and the conditions that would declare it failed. It carries one accountable Mysterium decision owner and a capped weekly effort ceiling on the Kairos side, so the commitment being asked for is legible before anyone makes it. The certified Ordinary VPN Customer Study architecture stands as its main result; the page was blind-reviewed and browser-verified on a persistent host against a hash-matched delivery mirror.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Controlled VPN tests established two protection failures and separated normal disconnect from app quit",
          "detail": "On one Mac and the current client build, terminating the tunnel provider exposed the direct ISP address, while a peer-only outage left the tunnel marked Connected with no traffic or recovery through the bounded observation window. Normal Disconnect removed the provider and tunnel; quitting the app followed a different teardown path. This is mechanism evidence from a controlled local run, not production incidence.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Cancellation evidence became measurable without pretending the sources agree",
          "detail": "The live in-app survey yielded 9,060 respondents across the exploded multi-select record: technical reasons appear in 60.7% of respondents, price in 35.8%, and testing in 17.3%. The measurement lane also found 90.1% of all-history churners and 69.0% of recent churners have no linked customer-authored voice. Linkage improves sharply in 2026 but remains selection-biased, so population incidence from Intercom stays prohibited.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "VPN complaints research moved from anecdote to a governed three-tier evidence programme",
          "detail": "Public review capture, internal customer voice, and product telemetry now sit behind one claim schema with denominator, linkage, comparison, and render checks. The architecture completed seven adversarial rounds; its current version rejects unbound percentages, bad comparisons, incomplete product lists, and unsupported causal wording. The product recommendation remains ADOPT-WITH-CONDITIONS until the measured complaint set and residential job value clear their gates.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "What Kairos needs from Mysterium became an ordered queue sent one ask at a time",
          "detail": "The open requests were collected and ordered rather than bundled into forwardable blocks: paid-media spend and live targeting evidence, a commissioning brief pinning the customer-journey semantics, lineage, identity, reconciliation and recoverability we need defined, and a search key that permits a full pull rather than a merely restored one. Each move names its own recipient and goes out singly, so nobody is handed a block to relay in someone else's words. One question has gone out under that rule and eight further moves are queued behind it.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Retention economics and the full customer-journey plan were rebuilt around separated effects and mature value",
          "detail": "The retention dossier and observatory now separate offer, product, gateway, identity, refund exposure, and mature retained cash instead of collapsing them into one lift claim. A companion customer-journey candidate maps evidence, implementation, benefits, and bounded prioritisation, and completed opposing review with no surviving dissent. The governing state remains no action until adoption and measurement authority are explicit.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "An agent-built shadow operating layer was assessed as a bounded opportunity, not a replacement",
          "detail": "We tested the idea of cloning the operation and rebuilding it with agents against the evidence corpus, and sharpened it into a shadow operating layer with a freemium win-back variant. The assessment names what has to be settled before the idea can move: the spinout structure, the risk of rebuilding the wrong organ, how merit would transfer, and the ownership gate. It is now an opportunity page carrying one bounded hypothesis and a closing framing, held as a candidate for discussion rather than a recommendation.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "GoProxies sales intelligence was reconciled against three competing ICP definitions",
          "detail": "The shared corpus now contains the three ICP definitions, the scored-company book, and the dry-run sales-intelligence pipeline. Against the 3,319-organization comparison book, 13.5%, 26.6%, and 40.7% met the three respective evidence frames, despite every organization carrying an ICP flag in the source. The result is an evidence map for measurement, not authority to launch outreach.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The data-room audit separated live doorways from stale labels and produced a capture plan",
          "detail": "BigQuery and the canonical ClickUp read path were live and reconciled; Ahrefs and Pipedrive remained unavailable, while the scheduled capture lane had stopped on repository divergence. With BigQuery excluded by Lee, the remaining named rooms fit an approximately 32 MB local capture across ClickUp, Grafana, impact, CJ, and Omnisend, plus Ahrefs when access returns. The working boundary is to preserve full reachable data without widening credentials or claiming unreachable rooms.",
          "receipt_count": 3,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "Kairos operating machinery gained verifiable readership, deployment, and evidence-bound release controls",
          "detail": "The War Room can now distinguish human browser reads from service-token navigation and count returning page reads across successful and not-modified responses. The canonical Kairos layer and shared push checks were strengthened to bind every vendored asset and the shipping state, while an explicit release continues through its existing access tier. These are one operating-machine gain, not separate product findings.",
          "receipt_count": 3,
          "link": "/system/",
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Connected does not prove a usable VPN data path",
          "detail": "In one controlled local run, a peer-only outage left the client and operating system reporting Connected while the tunnel carried no traffic and attempted no recovery through the observation window. Traffic resumed after the peer returned. This establishes a missing bounded data-path health check as a mechanism, not its production frequency.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "A paid campaign sent substantial traffic to a page that recorded no transactions",
          "detail": "Across the measured campaign-page population, 527,284 sessions produced zero transactions and 87.7% of those sessions were paid. Google Ads alone sent 426,435 sessions to that page in 2026, while its pricing-page progression was 0.08% against 8.68% site-wide. The evidence isolates a journey failure at the landing page; it does not by itself identify the creative, audience, or offer as the cause.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "hypothesis",
          "title": "The 56.7% never-connected churn signal may be a measurement-definition problem",
          "detail": "The warehouse label covers 56.7% of churned users and independently cross-checks at 53.1% zero-session on the curated layer. Yet 94.8% of flagged users also appear never-opened, and 64% of Apple-gateway users are never-opened, which points to a mapping or event-definition problem. Treat this as a hypothesis about measurement quality, not as customer behaviour.",
          "test": "Commission the connection and app-open field semantics, then reconcile them against session-level events by gateway and client version.",
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "No consumer-VPN customer profile exists in the shared workspace",
          "detail": "A read-only sweep of the authorized workspace covered all 19 documents and their 39 pages plus 5,378 of the 7,007 known task names, and found no VPN ideal-customer-profile, persona or customer-profile artifact. The only profile-named item workspace-wide belongs to the proxy business and its linked definition is empty; a closed task to prepare a persona plan carries no linked deliverable. The Q3-2026 backlog to build user-data and segmentation services describes the audience logic as fragmented, which corroborates the gap. This is an absence over 77% of known tasks and the full document set, not a claim that nothing exists outside that swept population.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-09-01",
      "milestone": "Kairos · Day 23",
      "attention": [
        {
          "title": "The Customer Observatory opened to the Kairos team with a VPN-only customer strategy set on a prospectively identifiable ICP, a governing Golden Loop, and a dual-outcome contract",
          "detail": "The customer-intelligence room widened from Lee-only to the authenticated Kairos team tier and passed sealed opposing verification. Inside, the customer strategy was set on a consumer-VPN-only scope with a granular, prospectively identifiable ICP as the north-star acquisition-retention thesis, a nine-part admission gate, and Delight sequencing from the ICP through the primary platform to the next segment. Lee's seven-step prospect-to-referral formulation was elevated as the governing Golden VPN Customer Loop, and every lower-level work must now trace to a named step. An independent VPN technical-service and customer-job success/failure/unknown outcome contract was established with the unknown outcome first-class.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "Payment Recovery live warehouse exhaustion certified and the category reframed as nested inside Customer Retention",
          "detail": "Authenticated aggregate BigQuery exhaustion completed across all 505 warehouse objects and 28 decision rooms, with every one of the 11 opposing-review findings from the terminal Opus 5 xhigh review integrated. Payment Recovery was then reframed under Lee's direction as absorbed into Customer Retention: it is eligible only when an affirmative continuation intent intersects a technical or operational failure, with rarity retained as a strong non-conclusive assumption pending a dedicated red team. A Kairos-facing decision page was deployed for the team.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The customer-intelligence work moved from claims to an executable measurement design",
          "detail": "A twelve-cell tenure and payment threshold sensitivity run was executed against the consumer-VPN population, and an equal-window first-pay cohort protocol was filed with overlapping outcome columns and an explicit retrospective-versus-prospective feasibility boundary. The highest-priority customer data rooms were ranked into a single retrieval set under the VPN-only scope, and pointer volume was placed on commissioned denominators with a ranked retrieval rule. The design fixes what any future customer claim has to carry before it can be made: a named population, a fixed window, and a stated comparison.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "One-customer full-chain reconstruction executed under a candidate-blind method to a bounded PARTIAL grade",
          "detail": "The frozen candidate-blind consumer-VPN full-chain reconstruction method was executed end-to-end. A privacy-safe HMAC binding draw selected one account without exposing selector material; bounded private queries ran across account history, subscription, extraction, support, and additional lanes; a cross-room scan exhausted both directions across the thirty-eight registered rooms; and the sanitized case facts and broken-link ledger were preserved. Post-verification privacy scans returned zero matches across the final artifact set and the private working copy was deleted. The mechanical grade landed at PARTIAL and independent verification remains open after reviewer transport failure. A second study, VPN-TRACE-002, was pre-committed under the same discipline.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The pre-committed second full-chain reconstruction VPN-TRACE-002 completed and returned an UNUSABLE grade",
          "detail": "VPN-TRACE-002 ran end-to-end as the random-selection variant of the one-customer full-chain reconstruction under the same candidate-blind discipline as VPN-TRACE-001. A single binding HMAC draw ran without replacement against a reproduced 150,263-row frame; bounded private queries executed; independent review and the terminal privacy scan completed; the private working copy was deleted. The final mechanical grade landed at UNUSABLE with no action authority, and the pending one-customer full-chain reconstruction handoff was retired alongside the frozen result.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Retention long-plan first-customer refund economics promoted to the primary proof on the observatory",
          "detail": "The all-history first-plan refund table was promoted to the primary proof, with the monthly long-plan first-customer history and same-period denominator shares added alongside twelve-month growth cases and the aggregate provenance. The recent customer/value cut was kept secondary with an explicit date boundary, the gateway comparison and concierge test were bounded, and terminal Opus 5 Extra High opposing verification returned PASS on the deployed page.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "A room now walks one consumer-VPN customer's story end to end and marks where the map goes missing",
          "detail": "The room follows a single customer through literal payment, VPN-failure, refund, continued-use, and support-contact events instead of abstract retention language, with an illustrative case attached to each stage. Where the chain cannot be joined, the room labels the gap in place and shows what the missing evidence would have to look like. It was rebuilt onto the canonical Kairos visual layer and verified across responsive widths, both themes, stage interaction, and deep-link stability before it was deployed.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Mysterium ground-up profitability turnaround proposal certified at r3",
          "detail": "The ground-up turnaround strategy was filed and adopted as the canonical Kairos proposal after a terminal Tris certification loop at r3 returned PASS with all seventeen accepted findings integrated, an opposing verification PASS, and a hash-bound receipt. It remains a proposed internal Kairos recommendation awaiting Mysterium adoption authority.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The Customer-Focused Operating System explainer released to the Kairos team behind the same Access gate",
          "detail": "The Customer-Focused Operating System explainer was released at a dedicated team-tier room after Opus 5 opposing review and access verification. The abstract exposition was replaced with one plain rule, one current VPN priority decision, a visible five-step loop example, one-sentence expansions of every abbreviation, and a single non-duplicated glossary. The page carries an explicit unadopted-standard boundary.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "GoProxies Conversion System evaluation completed with a terminal BLOCKED — measurement-only frontier verdict",
          "detail": "The evaluation architecture and data frontier were blindly derived and frozen. Twelve rooms and all 505 saved warehouse objects were dispositioned, the A/B/C/D evidence frontier ran to exhaustion with the prohibited warehouse-family gate preserved, and the final Opus 5 xhigh opposing verification returned PASS with zero remaining findings and zero surviving dissent. The terminal business verdict is BLOCKED — NO MATERIAL PURSUIT / MEASUREMENT-ONLY FRONTIER, and no recipient-facing artifact is required.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Kairos operating machinery: canonical visual layer became a first-build requirement for every branded web surface, and the shared push and sync boundaries were hardened",
          "detail": "The exact Kairos visual layer was made an automatic first-build requirement for every Kairos, MN, Mysterium, GoProxies, and SWAT web surface, sealed by an opposing verification pass. Shared-push authority coverage was extended to prove a clean worktree cannot mask a stale mirror, and the kairos-sync reconciliation completed with the remote canonical mirror regenerated and independently verified. The web-production skill now makes an explicit `deploy` or `go live` instruction sufficient to authorize the named release through its established production path; privacy discipline chooses the least-widening existing private tier and does not manufacture a second approval gate.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "No single tenure, payment, or platform cell qualifies as the consumer-VPN ICP",
          "detail": "The twelve-cell threshold sensitivity run found no tenure or payment cutoff that isolates a coherent segment. The largest modal cell, US and Apple and yearly, holds 150 of the 1,970 accounts in the avatar-matched cohort and does not carry analytical priority; the remaining 1,820 are an unmatched heterogeneous remainder rather than a comparable group. That cohort is the avatar-matched population, not the wider candidate frame used for the one-customer traces. Follow-up moves to full-cohort or closed mature-cohort analysis with controlled platform comparisons.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-31",
      "milestone": "Kairos · Day 22",
      "attention": [
        {
          "title": "Payment Recovery executed its frozen blind-first evaluation into a bounded BLOCKED decision dossier",
          "detail": "The certified blind-first evaluation system and its execution frontier were frozen. The evaluation swept 111 candidates in the warehouse and recorded a non-operational anti-neglect control. The dossier reached a bounded BLOCKED state that preserves every reversal-critical gap, and a room-and-object frontier self-test records the failing rooms, saved inventory hashes and the non-operational control boundary.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "Retention Economics executed its frozen blind-first evaluation into a bounded decision dossier",
          "detail": "The certified blind-first evaluation system and its data-utilisation frontier were frozen. The dossier was executed across every available room with reveal-stage evidence bounds integrated. All 506 saved warehouse metadata objects were dispositioned with explicit residue, and all 34 room rows were dispositioned to record every used, blocked and unresolved evidence surface. A deterministic warehouse metadata disposition audit was added, and a high-certainty evidence-gate receipt was filed with the final reviewer hold explicit.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Three whale opportunities were framed and handed off blind-system-first — Payment Recovery, Retention Economics, and Goproxies Conversion",
          "detail": "A source-bound strategic synthesis separated the three whale opportunities — Payment Recovery, Retention Economics, and Goproxies Conversion — from adjacent contract and material-pursuit lanes. Each opportunity was then prepared as a dedicated handoff that begins with blind system derivation and review, audits every available data room for unused evidence, executes the evaluation only after the method is frozen, and ends with an exhaustion red team.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Customer-Led Operating System and Customer Portfolio Intelligence were separated into blind-architecture-first workstreams with a bounded eighteen customer-family audit",
          "detail": "A dedicated Customer Portfolio Intelligence handoff separates realised customer goldmines from forward-looking profiles under full source-utilisation and final exhaustion review. A dedicated Customer-Led Operating System handoff separates permanent customer learning machinery from the portfolio and data-access systems. The Operating System workstream landed a bounded eighteen customer-family audit with primary-source winnowing, a vital-few implementation, a durable-owner workflow audit and an owner-ready adoption path, and its learning-gate prototype was hardened to sixteen negative-path tests and ten scenario falsifiers with an exact pre-merits review blocker recorded.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Two Kairos governance methods were frozen — the zero-base turnaround process design and the blind weekly-priority decision contract",
          "detail": "The zero-base turnaround process design was certified at r2 on a mandate-first, emergency-triage, real-expert, one-correlated-source frame after blind independent verification. Separately, a One-Thing-This-Week weekly-priority decision task was prepared blind-first without duplicating the active whale, customer or contract sessions, and its recommendation-blind decision contract was frozen after independent derivation and adjudication, with a seven-class normalized candidate denominator and blind-choice packet recorded at the evidence cut.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Kairos Services Agreement and mutual NDA counterproposals were prepared and the paid work commencement date was clarified",
          "detail": "Two provisional Kairos contracting counterproposals were produced and page-render-verified — a four-page Services Agreement and a two-page mutual NDA. Both were then made party-neutral with the selected Consultant as a pre-signature field. The Services counterproposal was revised to record the 2026-08-10 paid Kairos work commencement date, preserving accrued payment without administrative conditionality.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The supplied RichAds manual export was ingested as a bounded snapshot and source access stays SOURCE_BLOCKED pending controls",
          "detail": "The RichAds manual report was preserved with documented terminal-newline normalization, provenance and report-internal checks were written, and a passing schema-2 access receipt kept RichAds classified as SOURCE_BLOCKED. The Source Atlas row now carries the bounded-export evidence with its unresolved controls, and the MN Data Rooms Operating Map records the new snapshot, denominator and acceptance gaps.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "A controlled Mysterium VPN direct-to-datacenter-to-residential path test was blocked before connection by an app-scoped state",
          "detail": "A controlled test of the Mysterium VPN's direct-to-datacenter-to-residential connection path was blocked before connection by an app-scoped `noWindowsAvailable` state. The direct-connection end state and its associated error code were preserved without manufacturing a VPN result.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-08-30",
      "milestone": "Kairos · Day 21",
      "attention": [
        {
          "title": "The Case 1 six-lens internal review is certified, with VDAI and minimum-facts merits work still open",
          "detail": "An internal six-lens red-team review of the Case 1 answer was marked complete on the standing handoff. The certification closes the internal review lane on Case 1 while explicitly preserving two unresolved threads for merits work: the VDAI purpose-scope question and the minimum-facts follow-through. Nothing recipient-facing was released on this closure.",
          "receipt_count": 2,
          "link": null,
          "featured": true
        },
        {
          "title": "Warehouse perimeter tightened — claude.vpn_purchases sits outside the default Kairos access",
          "detail": "The Kairos operating map now records that the claude.vpn_purchases table sits outside the default perimeter and requires a named necessity case plus explicit reopening before any touch. The map carries full BigQuery namespaces so table references stay unambiguous about which data the engagement holds.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-08-29",
      "milestone": "Kairos · Day 20",
      "attention": [
        {
          "title": "The War Room sign-in door was rebuilt with dual login lifetimes and two live monitors",
          "detail": "Sign-in now runs two login lifetimes — an SSO lifetime plus a resumable lifetime with server-side convergence — replacing the prior single-session model. Two independent monitors landed alongside: a burst detector that fires on real client re-click patterns, and a tape-liveness watch that stays silent when the observability token dies. The login logs filter gains correlation events for future reads. Landed and live at origin/main c770bb3 after blind dual review converged at r3.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "Kairos operating machinery landed live-billing and source-access hardening",
          "detail": "The billing reply now renders paused-then-ended days as closed, and the recognition math is unified on the bucket-recognized rule so an adjustment cannot silently close a real gap. Kairos-sync source-access was reconciled to the schema-2 receipt gate; finalize now requires an explicit end-session and the exported mirror was regenerated. Repo-monitor migration failures write a durable receipt through a plain-write fallback. Six adjudicated repair bundles landed red-first, and the to-claude queue was drained in one dedicated session with all owed repairs routed with exact fixes.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-08-28",
      "milestone": "Kairos · Day 19",
      "attention": [
        {
          "title": "The VPN customer intelligence programme filed a spine, a cohort and a dominant customer profile",
          "detail": "The customer intelligence spine now binds the VPN evidence into one pillar with explicit unknowns and ranked next joins, and the Source Atlas registered the private BigQuery snapshot alongside the Intercom-to-economics contract. A deterministic Intercom conversation analysis and a reproducible aggregate-only cohort query landed with hashes, denominators and privacy ceilings preserved. The aggregate conclusion was published to the shared channel; the visual observatory and avatar report stay private and are not recipient-tested.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The Jubal Case 1 blind comparison is live inside the War Room",
          "detail": "The independent Case 1 dossier was frozen with a SHA-256 receipt before Ieva's reply was opened, and a blind comparison then found 13 of 13 control themes overlapping and no direct contradiction. One material purpose-scope mismatch remains for merits review. The comparison is Access-gated inside the War Room; the raw Ieva reply is excluded from the release.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The Week 3 one-pager now runs through the full 22 to 28 August cutoff",
          "detail": "The report was extended to the full window with a mechanical sweep of 466 landed records and zero unclassified. Stale ClickUp, Impact and Key Maker claims were corrected, and the Omnisend operating review, customer-intelligence layer, Pipedrive and Ahrefs source states, Themis and Jubal presentation and opportunity evidence programme were added. Deploy, responsive and custom-domain gates passed at production commit 4f98024.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The first-sprint week-three review answer is released as a team-tier War Room page",
          "detail": "Lee's first-sprint Kairos question and its evidence-bounded answer were packaged as a responsive Access page at the /reviews/sprint-01-week-03/ room. The anonymous Access boundary was verified with no page-text leak, and exact production copy was browser-verified at 390px and 1440px. The page is live but not yet recipient-tested.",
          "receipt_count": 3,
          "link": "/reviews/sprint-01-week-03/",
          "featured": false
        },
        {
          "title": "The Gitanas Claude and Obsidian onboarding handoff is live",
          "detail": "A private onboarding page was prepared, deployed and live-verified at seed.leematulis.com/gitanas/, with a selected continuity-promise hero and a v2 branded share card. The recipient contact was saved and the send boundary was filed. The page is live and writer-tested; recipient test is pending.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "War Room document links now open safely and are guarded by tests",
          "detail": "Document links inside the War Room now open in a new tab with noopener and noreferrer, backed by a runtime guard asset and a global link-policy test. Authenticated live render was verified at commit ea9dc84. The asset authorization fixture holds prevention against future release omissions.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Kairos operating machinery filed for the day",
          "detail": "The 2026-08-28 Kairos call was captured with a fail-closed receipt and a private evidence-bounded call analysis was synthesized against current context. Post-mix four-speaker diarization was retained as evidence but not identity-usable. Tested archive-and-rebase and pending-push guards were filed to keep publication of the shared channel clean of dirty overlap.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "The independent Case 1 answer overlaps Ieva's reply on 13 of 13 control themes with one purpose-scope mismatch",
          "detail": "The independent Case 1 dossier was frozen with a SHA-256 receipt before Ieva's reply was opened; the blind comparison then found 13 of 13 control themes overlapping and no direct contradiction on those themes. One material purpose-scope mismatch remains for merits review. The frozen baseline, immutable reply and comparison are preserved separately.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "A US-Apple-yearly modal cell sits inside the long-tenure high-payment low-support-visible VPN cohort",
          "detail": "Inside the active long-tenure, high-payment and low-support-visible VPN cohort, the corrected modal cell is US customers on Apple platforms with yearly plans. A high-error and high-churn counter-signal was preserved alongside the modal identification. The result stays aggregate-only under the current privacy contract.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-27",
      "milestone": "Kairos · Day 18",
      "attention": [
        {
          "title": "The Data Access OS now carries twelve governed source rooms",
          "detail": "The operating map now binds twelve rooms to current source evidence, working limits and next gates. Impact has a 49-report inventory and a working read path, while strict source readiness remains blocked until write denial is proven. ClickUp and Omnisend carry bounded inventories; Pipedrive remains source-blocked after the official identity probe returned 401.",
          "receipt_count": 3,
          "link": "/data-unlock/map/",
          "featured": true
        },
        {
          "title": "The opportunity portfolio gained one live pilot room and one visible contender",
          "detail": "Delight completed three bounded evidence rounds plus Slack and Grafana checks, stayed inside Retention Economics, and gained a team-room implementation addendum. Key Maker moved from a broad concept to an unassessed set of explicit claims and tests and is now visible as the first contender to replace rank five. Neither item carries launch or material-pursuit approval.",
          "receipt_count": 3,
          "link": "/opportunities/",
          "featured": false
        },
        {
          "title": "The VPN field programme can observe the app again and narrowed the crash question",
          "detail": "The exact disconnected blank-row path connected to Šiauliai and did not reproduce the intermittent crash during immediate observation. The evidence plan now separates local Apple crash reports from unverified Sentry or Crashlytics delivery. A team-tier Delight technical addendum records the current implementation gaps without treating the negative reproduction as a fix.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Sixteen Omnisend campaigns now have a first operating decision board",
          "detail": "All 16 campaigns were classified: 9 keep, 1 finish, 3 retire and 3 investigate. A new Customer Intelligence Spine joins that campaign evidence to the recovered VPN lifecycle task and the remaining source gaps. ClickUp relationships stay programme-level because the complete 3,023-task, 117-list inventory contains no stable campaign join key.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The governed legal-work protocol is available inside the War Room",
          "detail": "The Themis and Jubal protocol reached the access-controlled War Room and passed the anonymous, core and team access journeys. It makes the evidence hierarchy, adversarial review requirement and human-counsel boundary inspectable in one place. The page is an operating protocol, not legal clearance for a specific case.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The Week 3 one-pager now carries the full cutoff-to-cutoff work record",
          "detail": "The report was built from a mechanical sweep of the full reporting window before any headline or ranking was chosen, including weekend work. Every landed candidate was either represented or explicitly parked, and a wrapping guard now protects the reader-facing layout. No intended recipient has yet opened it.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Blocked source requests now have one action for each grant holder",
          "detail": "A core-tier coordination page translates the data map into one evidence-producing action for each blocked source. It separates already-readable tools from genuine access gaps and keeps identity or permission decisions with the relevant grant holder. The page is available inside the War Room; no access change is implied by its publication.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Source-access and peer-work records now fail closed on missing evidence",
          "detail": "Source-access receipts moved onto a fail-closed schema with explicit readiness, mapping and write-safety states. The peer rail now records queued, received and terminal work separately, and a Lithuanian Messages transcription bundle is prepared for attended installation. These changes are grouped as one operating-system stream rather than presented as separate product findings.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Slack did not yield a source-addressable lead for the affiliate attribution gap",
          "detail": "The bounded lineage contract searched the supplied Slack archive and returned LINEAGE LEAD NOT FOUND. It did not open a BigQuery extension. The warehouse attribution conflict therefore remains unresolved instead of being promoted into a new causal claim.",
          "test": null,
          "receipt_count": 3
        },
        {
          "evidence_state": "fact",
          "title": "The tested VPN blank-row path did not reproduce the intermittent crash",
          "detail": "From a disconnected state, the Lithuania datacenter blank-row sequence connected to Siauliai and the app remained alive through immediate observation. This narrows one reproduction path. It is not evidence that the intermittent crash is fixed.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-26",
      "milestone": "Kairos · Day 17",
      "attention": [
        {
          "title": "All eleven source connections now have evidence-backed commissioning ceilings",
          "detail": "BigQuery, CJ and Slack are bounded-ready for their commissioned uses; eight other sources each have a named blocking state and next gate. The evidence register covers eleven receipts against eleven source rows with zero omissions or duplicates. A ranked question map now limits follow-on work to one bounded contract at a time, beginning with Slack lineage for the warehouse attribution gap.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The data-room operating map went live with eleven rooms",
          "detail": "The team-tier map now puts key custody, current access, hard limits, completed work, untouched scope, next action and owner beside each of the eleven data rooms. The released page and its assets were checked through the authenticated team route, while anonymous requests reached only the Cloudflare Access wall.",
          "receipt_count": 3,
          "link": "/data-unlock/map/",
          "featured": false
        },
        {
          "title": "The Data Access Gold Standard page went live in the war room",
          "detail": "The /data-unlock/gold-standard/ page shipped to production behind the Kairos Core access wall, carrying the source estate, the machine-readable brief and the review record. An adversarial pass had already accepted the page with repairs before deploy, and the page's ceiling lifted from unreviewed to reviewed-and-accepted at that point. Anonymous requests still redirect to the access wall, and the managed access group is unchanged.",
          "receipt_count": 3,
          "link": "/data-unlock/gold-standard/",
          "featured": false
        },
        {
          "title": "The source-access system took a full red team and grew to eleven sources",
          "detail": "A sealed adversarial review of the source-access system returned twenty-six findings with fourteen blocking, and all twenty-six were adjudicated for repair with seven bounded implementation adjustments. The full source estate expanded from nine to eleven with evidence-bound durability classifications, and new source contracts landed for BigQuery and Slack. Explicit red-team cases plus observed-red interaction regressions were filed as a durable gate for the next repair pass.",
          "receipt_count": 3,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "The 21 August analysis shelf is assembled for War Room release",
          "detail": "The settled transcript and analysis sources were integrated into the shelf and handed to the release lane. Responsive browser QA, deployment and branded-route verification remain before the shelf can be presented as live.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The engagement's operating machinery tightened curation, source handling and review control",
          "detail": "The daily-brief pipeline now requires a denominator-bound curator verdict, and the Slack generator runs from a clean clone. The collaboration review loop reached terminal tested coverage for packet stability, ordered routing, claims and hash-bound evidence. Routine aggregate warehouse loading and the transcription entry point carried the day's supplied material through existing gates.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "The tested warehouse path classified none of the CJ-proven orders as affiliate",
          "detail": "Across ten correction-safe closed months, 146 independently CJ-proven orders entered the control; 145 reached both warehouse comparison spines, and zero of those 145 carried an affiliate attribution. The result is an attribution-integrity conflict plus one warehouse coverage gap. Profitability, partner quality and CJ reporting accuracy remain outside the tested perimeter.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-25",
      "milestone": "Kairos · Day 16",
      "attention": [
        {
          "title": "The Mysterium Slack archive is queryable on local disk",
          "detail": "The Slack archive Mysterium supplied is now a searchable local database covering 236 channels and 171,017 human messages. Full-text search and a read-only viewer run against that index on local disk, so the archive is never uploaded into a third-party workspace. The index answers board-pack research queries directly against the source material.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "A payment-recovery instrument is in development",
          "detail": "Work on the Mysterium payment estate moved from a written candidate case to a working recovery instrument built on the local archive index. Its headline benchmark was demoted to context after confound testing failed to clear the alternative explanations. The monthly control that attributes CJ records to the warehouse passed a terminal independent review approved for monthly runs. The instrument remains a candidate and carries no adoption or opportunity approval.",
          "receipt_count": 2,
          "link": null,
          "featured": true
        },
        {
          "title": "The three-agent collaboration architecture took in 17 review repairs",
          "detail": "The architecture for three agents working one task integrated 17 repairs raised during internal review, each promoted into the canonical design. Strict Mode A certification was still returning blocked or malformed results at the end of the day. The architecture therefore stands as integrated design with certification outstanding.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The operating machinery gained clock, dispatch and deploy guards",
          "detail": "The time ledger now refuses stale agent-runtime clock starts at the writer boundary, and open agent clocks on the live ledger stand at zero. The urgent peer-work executor that moves work between agents is live. The daily-brief deploy path gained a settle guard before it reports a deployment live, and the internal-review boundary between agents was tested end to end.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "The Mysterium payment estate runs multiple rails concurrently, not in sequence",
          "detail": "The archive names Stripe and Adyen together in the same message across fourteen distinct months of 2025 and 2026, and none of the seven migration phrases hunted with equal effort returned a hit. At least four rails carry current transactions: Stripe, Adyen, CoinGate, and PayPal.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "Reporting and data requests recur in every archive year",
          "detail": "A recurrence pass over the local archive index found 248 messages matching the reporting-and-data-request pattern, spread across 9 of the 9 years the archive covers, 2018 through 2026. Access and permissions friction appears in all 9 of those years as well. The pattern is measured on the request traffic itself, with no individual identified.",
          "test": null,
          "receipt_count": 1
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-24",
      "milestone": "Kairos · Day 15",
      "attention": [
        {
          "title": "First-hand product testing reproduced a tunnel-state defect and was re-scoped to feed the warehouse",
          "detail": "Paid product testing on macOS reproduced a state defect on the ordinary path: quitting the application ends the app but leaves the tunnel provider running, with the system still reporting a live connection and all traffic still leaving through the exit node. Coverage was also measured — of the residential exits the app offers in Lithuania, twenty-six addresses across seven cities, against three hundred and eighty-two in London alone. The study itself was restructured: a single machine cannot establish how often anything happens, so it now produces defects with named mechanisms and hands each one the warehouse query that would size it, with a provisional written account on 8 September.",
          "receipt_count": 1,
          "link": null,
          "featured": true
        },
        {
          "title": "Kairos built Themis and Jubal as its governed legal-work system",
          "detail": "Themis sets the rules, evidence hierarchy, adversarial obligations and amendment process for agent legal work. Jubal applies that standard to actual cases. The architecture went through 52 red-team rounds and two fresh-context audits; Lee accepted the operating core on 24 August while the measurement-statistics appendix stayed frozen for further review. Legally consequential conclusions still go to human counsel.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Jubal opened its first case on a pinned legal corpus",
          "detail": "Case one addresses which Mysterium data may lawfully be accessed, by whom and for what purpose. The work opened on 22 pinned legal sources, a citation checker that rejects text not matching the recorded source, and a scoping memo that cleared 66 of 66 citation checks. The blind-framing ask reached the Kairos group before the case matrix is framed.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The supplied Slack archive reached analysis and produced its first corpus map",
          "detail": "The archive reached Lee's disk and was checked against its recorded size and hash. A channel-routing map, marketing fitness scorecard and first opportunity hypothesis were produced from it, with raw messages kept off the team surface. An independent review checked the aggregate claims and the supplied-source boundary in two rounds.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "A shared profit architecture now tests the Mysterium VPN opportunity",
          "detail": "The model separates the path to profit into a profit equation, comparator anchors, supply asymmetry, classifier calibration, payback and durability gates. A three-arm falsifier states how the case can fail before any opportunity is promoted. The current state is an evidence-gated hypothesis; no launch or material pursuit is approved.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The workspace guest seat went live and its shared content was read in full",
          "detail": "View-only guest access to the Mysterium Network workspace was granted and accepted, and the shared list was read end to end without writing anything back. A receipt confirming acceptance and the read-only method was returned the same day, together with the outstanding question of whether the remaining spaces should be shared.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The Kairos relay gained a resumable large-file transfer path",
          "detail": "The new /drop route was proven through the public edge with a three-part test, exact hash match and cleanup, while the existing Git lane remained available. It gives the team a direct route for large supplied artifacts when ordinary sharing fails. The Slack archive arrived separately through Drive.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The engagement's agent channel and the guards around it were hardened",
          "detail": "The message relay gained an immutable materializer and guards over its effects and delivery paths. An injection route through the review router was closed after being reproduced first. A confinement check on review message paths was repaired once it was shown it could never fire, and a regression now holds it. The unattended job tree now pushes what it commits rather than only archiving it, and a new sentinel watches the daily product-test run and tells a genuine failure apart from a lost network.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Quitting the app does not end the tunnel",
          "detail": "On macOS, an ordinary quit terminates the application while its tunnel provider keeps running; the system continues to report a live connection and traffic keeps leaving through the same exit. Observed at six seconds and again at fifty-one with no application present, and cleared only from the operating system layer. A user who quits believes protection is off when it is not.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "The in-app review prompt is gated on three consecutive clean sessions",
          "detail": "Client configuration requires three consecutive clean sessions, and a minimum number of connections, before the app asks a user to review it. Users who are experiencing connection failures are therefore not asked. This shapes who ends up represented in app-solicited feedback, and is worth holding in mind whenever solicited review sentiment is read as a health signal.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "hypothesis",
          "title": "Residential exits may carry a large responsiveness cost that raw speed hides",
          "detail": "In one paired run on the same link within the same session, throughput held while responsiveness under load fell from roughly fifty-five to nine — the quality that decides whether a connection feels broken, rather than how fast a file arrives. One run, one exit, one link.",
          "test": "Repeat paired runs across several residential and datacenter exits on the same link; if datacenter exits show the same collapse, the cause is the link or tunnelling generally and not residential exits.",
          "receipt_count": 1
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-23",
      "milestone": null,
      "attention": [],
      "findings": [],
      "status": "no-activity-filed"
    },
    {
      "date": "2026-08-22",
      "milestone": "Kairos · Day 13",
      "attention": [
        {
          "title": "The engagement's operating machinery gained a release executor and new money and repository guards",
          "detail": "An off-computer release supervisor is now built and red-tested end to end and awaits Lee's install; it is bounded to a typed action seam and refuses to replay any generation, including the fork-to-process race that would otherwise double-dispatch. The earnings ledger now fails closed on undated recognition and reconstructs hours across rate changes, and the dashboard payload reconciles recognized money against clock-derived billable time. The Kairos repository refuses a commit on a detached HEAD or during an unfinished rebase, and the exchange archive stamps its own send and archive times from the server clock. The team-brief coverage check now excludes continuity and review records so the daily denominator counts only real releases.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-08-21",
      "milestone": "Kairos · Day 12",
      "attention": [
        {
          "title": "The Kairos Week 2 report is live for the team",
          "detail": "The weekly one-pager reports seven ranked shipped outputs from the week — the warehouse audit, opportunity ranking, the 410-review explorer and synthesis, 30-day Mysterium VPN user testing, a temporary MacBook Git relay, autonomous agent relay, and the team War Room surfaces. Every displayed label points to a live room, and the report ships with a branded share card so links preview cleanly.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The Mysterium VPN customer immersion added Day 2 evidence and a daily cadence",
          "detail": "A residential London exit was measured connected and disconnected, and a Šiauliai datacenter exit was paired against the disconnected baseline. A second crash was preserved as first-hand evidence. The immersion now runs on a bounded daily heartbeat with weekly gates and an action-time confirmation boundary.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The War Room team search now returns role-scoped results",
          "detail": "The team-visible search runs on a role-scoped corpus, so a Team reader sees the rooms they are allowed to see and never a Core-only room. Team-visibility and Core-leakage guards are wired into the build so the door cannot regress.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The team login now runs under a deterministic live-verification contract",
          "detail": "Every deploy proves the login door works before the door is called live, and mobile focus and release-scope isolation are held as separate concerns. Gitanas repeating the original Chrome journey is the last step to move this to recipient-tested.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The engagement's own machine gained new release-time protections",
          "detail": "The one-pager build proves that every displayed label maps to a live team room, that outputs are ordered by evidence and opportunity dependency, and that the weekly share card ships as declared and verifies live on the crawler. Journals or transcripts can no longer operate the Kairos clock; only direct instructions do. The dashboard door now runs on a single shared authentication path.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-08-20",
      "milestone": "Kairos · Day 11",
      "attention": [
        {
          "title": "The database audit is now a decision brief, not a table inventory",
          "detail": "The audit has been condensed into an executive report that separates verified warehouse facts from definitions Kairos still needs from MN. The next discovery step is bounded to five load-bearing tables and the trusted reports already used to interpret them, so the work can move from broad inventory to governed decisions.",
          "receipt_count": 3,
          "link": "/database-audit/",
          "featured": true
        },
        {
          "title": "We started testing Mysterium VPN as users",
          "detail": "A 30-day product immersion is now running from the customer side instead of relying only on records and public reviews. The first pass established a real tunnel, recorded the activation and trust journey, and opened a repeatable plan across connection types, protocols, geographies and everyday jobs. Product findings will remain first-hand observations until they are reproduced.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The public VPN review evidence now has a Kairos working synthesis",
          "detail": "The team page treats customer reviews as a warning system, not as prevalence or revenue evidence. The current improving label stays low-confidence because its direction changes under a documented sensitivity cut, and five internal checks are named before the evidence can change an opportunity ranking.",
          "receipt_count": 3,
          "link": "/reviews/synthesis/",
          "featured": false
        },
        {
          "title": "The opportunity board now separates Mysterium opportunities from Kairos leverage",
          "detail": "The August 20 ranking updates the MN opportunity slate and keeps the three Kairos leverage ideas in their own lane. The GoProxies evidence boundary is stated directly, and every survivor retains a prove-or-kill path instead of being promoted by narrative.",
          "receipt_count": 3,
          "link": "/opportunities/",
          "featured": false
        },
        {
          "title": "The Mammoth Protocol is now available to the team as a non-binding discussion draft",
          "detail": "The draft turns the opportunity-ownership architecture into a concrete sequence: register the opportunity, name the parties and contributions, choose an instrument, and sign the specific schedule before material pursuit. It gives the team something operational to challenge without treating the framework as adopted.",
          "receipt_count": 3,
          "link": "/notes/kairos-mammoth-protocol-v0-1-discussion-draft-2026-08-20.html",
          "featured": false
        },
        {
          "title": "Epistemic federation is now a team-readable operating model for sovereign agents",
          "detail": "The page defines how independently authorized personal operators can continue Kairos work without merging vaults, identities, or authority. It separates stored context from retrieval and authorized action, preserves sealed first sight and dissent, and labels the policy and coordination controls that remain proposed rather than live.",
          "receipt_count": 3,
          "link": "/notes/kairos-epistemic-federation-and-sovereign-operators-2026-08-20.html",
          "featured": false
        },
        {
          "title": "The agent relay now has a ranked use-case portfolio instead of one broad story",
          "detail": "The portfolio scores internal and external uses against current evidence, relay-specific advantage, existing substitutes, and a falsifier. This separates the shared work channel that already exists from larger product ideas that still have to earn their own case.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Agent onboarding now distinguishes received context from working access",
          "detail": "The parity harness and protected onboarding page show which Kairos context was delivered, what its integrity receipt proves, and which retrieval checks remain open. That keeps a package arriving from being mistaken for the receiving agent actually being able to use it.",
          "receipt_count": 3,
          "link": "/agent-onboarding/",
          "featured": false
        },
        {
          "title": "The daily Mysterium signal room published its August 20 edition",
          "detail": "The unattended public-source capture added the day’s external signals to the same dated room the team can read. This keeps the public evidence stream current while deeper and private analysis stays behind the appropriate boundary.",
          "receipt_count": 2,
          "link": "/mn-daily/",
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Ten of the 18 current-quarter rated reviews came from profiles showing one public review",
          "detail": "Nine of those ten reviews were positive. With every current-quarter rating, the captured average is 3.44 out of 5; without that group it is 2.00 out of 5, so the public direction is too sensitive to support a product-wide improvement claim on its own. A one-review profile is context, not proof of a fake reviewer.",
          "test": null,
          "receipt_count": 3
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-19",
      "milestone": "Kairos · Day 10",
      "attention": [
        {
          "title": "The data-unlock method is now one operating sequence instead of five disconnected asks",
          "detail": "The answer sent to Šaras now starts by mapping the available systems, then narrows the work to the one to three active systems that can answer the current decision. The same method is integrated into the War Room data-unlock board, so the next access handoff has one sequence rather than a list of tools.",
          "receipt_count": 2,
          "link": "/data-unlock/",
          "featured": true
        },
        {
          "title": "The two Kairos agent sides now share a receipt-backed context handoff",
          "detail": "A bounded context package reached Šaras's side with a complete integrity receipt, and the remaining gate is a live retrieval check rather than another transfer. The onboarding record now separates what arrived from what the receiving agent can actually use, so delivery cannot be mistaken for operational parity.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The engagement machine now carries message ownership, archive identity, and explicit day-close state",
          "detail": "The shared rail now records who holds a message claim, keeps unacknowledged messages under their original identity, and separates an open day from one that has actually closed. These controls reduce duplicate pickup, silent re-dating, and premature recognition without adding more manual coordination.",
          "receipt_count": 1,
          "link": "/system/",
          "featured": false
        },
        {
          "title": "The daily Mysterium signal capture published its August 19 edition",
          "detail": "The unattended capture added the day's public signals to the same dated room the team can read each morning. This keeps the external signal stream current while the deeper work stays in the private evidence layer.",
          "receipt_count": 1,
          "link": "/mn-daily/",
          "featured": false
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-08-18",
      "milestone": "Kairos · Day 9",
      "attention": [
        {
          "title": "The two-way autonomous rail between the Kairos sides passed its first unattended test",
          "detail": "For the first time an agent on Šaras's side fired without a human present — a trigger arrived on the shared channel, work was composed, pushed, and returned to Lee's side end to end. An in-flight-claim primitive was shipped on both sides so two agents cannot pick up the same message in parallel, and a short kill window is now derived from one constant on both sides so the two never drift. The rail is now the standing channel for Kairos work when either side is away.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "Šaras's side is now equipped to work in parallel with Lee's on the same evidence",
          "detail": "A private vault skeleton and the portable skills library were delivered to Šaras's system so his agent can carry Kairos work with the same shape as Lee's, rather than borrowing his setup by hand. The Mysterium evidence layer was also published to the shared Kairos repo so both peer agents read from one source. The counterparty relay is no longer bottlenecked on Lee's local tree being the only place that knows what has been seen.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The team git relay went dark for eleven hours pre-dawn; a probe now catches the next outage on its own",
          "detail": "The Kairos git relay ran unreachable from around midnight through late morning, and the outage reached us socially rather than by any monitor. A probe now runs against the tunnel connections at the origin, which are the only signal that answers when the rail is truly up; the hostname edge returns a healthy-looking redirect even during an outage, so any hostname check would have been silent. It notifies only on state change, so a live rail stays quiet.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The sign-in door's failure reason is unreadable without a Workers Observability token",
          "detail": "A three-attempt sign-in failure was probed. Cloudflare Access held one allowed row and gave no reason for the two failures. A reader was added for the IdP side of the funnel, but the underlying failure lines live in Workers Logs, and reading them requires an Observability token that no current sign-in carries. Until it is issued, the door's own health page forgets the reason after an hour and every failure surfaces only when a human notices.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The signal-row audit is blocked on Šaras's warehouse sign-in",
          "detail": "Six candidate signal rows were tested against their own pre-registered proceed clauses. None is settleable from what is already captured on disk — each needs a fresh warehouse query, an intercom dataset never queried, or a tier column today's cohort table does not carry. Reopening the warehouse needs Šaras's second-factor on the analytics account, which sits at the head of his queue. The away window is being spent turning what is already in hand into decision-ready work, not building more transport.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The engagement's own machinery got harder to lose a day on",
          "detail": "The brief pipeline now closes each day on a curator verdict, not on entries merely existing, and its coverage guard now fails a thin day, not only a blank one. A day close now records that its published surfaces were refreshed before it verifies, so a stale number cannot ride out under a fresh gate. Dead deploy claims release themselves so a corpse from an earlier session cannot block the next fold. Each of these was proven on the exact failure it exists to catch before it was wired in.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-08-17",
      "milestone": "Kairos · Day 8",
      "attention": [
        {
          "title": "The warehouse itself was graded, dataset by dataset",
          "detail": "An analytical-fitness audit went through the warehouse — 24 datasets and 503 tables — and gave each source a graded verdict on what it can and cannot support. The one events table too large to scan whole was measured under bounded sampled evidence rather than left unscored, so no room of the warehouse walked away unread. The coverage line now sits on the state room and points back to the graded report.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "Every claim on the opportunity board now states its own evidence grade",
          "detail": "An independent adversarial review went through the board and the state room claim by claim. What survived is stated as measured. What could not be supported was taken off the page rather than softened into a hedge. What remains untested now says so on the page itself, and names the single query that would settle it. The board carries a version chip and every earlier version stays readable at its own address, so a reader can see exactly what changed and when.",
          "receipt_count": 2,
          "link": "/opportunities/",
          "featured": false
        },
        {
          "title": "The hours ledger now separates Lee's clock from agent runtime",
          "detail": "The engagement now keeps two measures apart: time Lee explicitly starts, pauses, resumes or ends, with select backfill on his word, and agent runtime whose work actually targeted Kairos. The branded ledger publishes only after Lee's clock closes, so an open interval cannot inflate the number a reader sees. Gifted and waived time remain optional classifications rather than a third measurement system.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Three new blind spots joined the opportunity board",
          "detail": "The board added Android product experience, the billing-labelled churn remainder, and the Primer label seam as W6–W8. Each row carries the evidence boundary and the next prove-or-kill move instead of being promoted by narrative. The release also tightened the existing pricing and retention rows and removed a mobile claim that did not survive opposing review.",
          "receipt_count": 3,
          "link": "/opportunities/",
          "featured": false
        },
        {
          "title": "The data-unlock room now names where every invite and file lands",
          "detail": "Every block on the room states its return path: two Kairos addresses receive invites and read-only seats, and a shared Drive folder receives files, one sub-folder per system. A separate 'Where things go' block after the access ladder walks an exporter through setting the folder up. Guards on the copy assert both addresses and the folder are present before every deploy, so a page cannot ship without them.",
          "receipt_count": 3,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "Šaras now has one page and one button to connect Metis",
          "detail": "A gated relay page turns the switch-over into three numbered steps and one copy action, with Šaras's own desk pointing to it. The message carries the full instruction Metis needs; another team member sees a neutral page, and an agent cannot read the human surface. The operating path is now usable without asking anyone to assemble tokens and commands from separate notes.",
          "receipt_count": 3,
          "link": "/relay/",
          "featured": false
        },
        {
          "title": "A Kairos git stand-in is live so the team can keep pushing while Forgejo is down",
          "detail": "Forgejo has been unreachable since 12 August, with 93 commits stranded. A Cloudflare-Access-gated stand-in now runs on Lee's Mac at kairos-git.leematulis.com; a clone repoints in one command, and each person's War Room desk carries a personalised one-button switch for their agent. When Forgejo returns, one script hands the origin back and the stand-in retires.",
          "receipt_count": 3,
          "link": "/me/",
          "featured": false
        },
        {
          "title": "The Kairos sign-in now heals a silent restart class",
          "detail": "The Kairos War Room sign-in was silently restarting on the last hop for anyone who opened another Access-gated tab in the same browser mid-login. The door now heals a verified session Access never redeemed, once and within a short window, and past that shows a plain-words page instead of a blank restart. The class was reproduced three times before shipping and tested live after, so the next real user who hits it lands where they meant to.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "About 48 percent of subscriptions that churned in 2026 carry a billing-retry label",
          "detail": "Of the distinct subscriptions that churned in 2026 across every gateway, roughly 48 percent carry a billing-retry label and the rest read as voluntary. That is a share of subscription counts, not of money: the churn records carry no monetary denominator, so any claim about how much revenue sits behind involuntary churn would be unmeasured. It does not contradict the earlier finding that around 97 percent of failed renewals are involuntary — that share was measured inside a far narrower population, Stripe's July renewal invoices that failed and never recovered, and it answers whether a cancellation came before the failed attempt. This one answers how much of all churn reaches a failed payment at all. Read together: around half of departures pass through a billing failure, and almost none of the failures tested had been cancelled first. Whether a billing-retry label means the loss was involuntary in outcome still needs the key that pairs a labelled churn with its billing attempts.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "hypothesis",
          "title": "Roughly a third of what MN's leadership spends airtime on has something behind it in the warehouse",
          "detail": "Sixty-eight all-hands transcripts and the most recent all-hands deck were read to list every workstream the company discusses, merged into thirty-two kinds of fact, and weighted by how much attention each one gets. Scored against what the warehouse actually holds, the weighted share lands near a third, and near the same when the window is narrowed to the period of the current mandate. The shape carries more than the number: the consumer subscription base is answered well, while the node network, the proxy and B2B line, and the company's own functions each score under a fifth, and thirteen kinds have nothing behind them at all. Two limits travel with it. It measures one denominator, what leadership talks about, and not raw event volume, where the share would be far smaller. And a table existing is presence, not trustworthiness: the covered third is subject to the same governance findings as everything else.",
          "test": "Rescore the same thirty-two kinds of fact against a denominator MN owns rather than one we inferred, such as the current OKR set or the agendas of the two most recent all-hands. If the weighted share moves by more than ten points, attention is the wrong instrument and this number does not stand.",
          "receipt_count": 2
        },
        {
          "evidence_state": "fact",
          "title": "Some app-usage rows are dated years in the future, and part of that area has stopped refreshing",
          "detail": "Rows dated between 2030 and 2045 sit in the app-session table and in two connection tables. They come from device clocks rather than from the pipeline, so no event is lost, but any total grouped by month silently counts rows that have not happened unless the query restricts to today or earlier. Separately, seventeen of the thirty-eight tables in the app-usage area have taken no new rows in over a month, and one purchase table has no populated month after June. A dataset that looks current at the folder level can hold members that stopped long ago. Both are read-and-filter problems with a known fix rather than missing data.",
          "test": null,
          "receipt_count": 2
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-16",
      "milestone": "Kairos · Day 7",
      "attention": [
        {
          "title": "The blindspot map became a tool",
          "detail": "Every unscouted territory is now ranked, with the decision rule written before the data, an owner column, and a hard day-21 stop for the pilot. A session walking the map either signals, kills, or parks a row from its own evidence; the map cannot freeze because the tool builds time-derived state. Seven quests moved on it today, and the first one closed as a win before day 7.",
          "receipt_count": 3,
          "link": "/opportunities/",
          "featured": true
        },
        {
          "title": "The warehouse is open again for the first time since 12 August",
          "detail": "The connection returned on Šaras's own password and 2FA, and the standing squeeze batch ran the moment it opened — aggregates only, saved in full with a manifest, no customer-row grain. The map of the warehouse is now on record, so the freeze family that stopped rebuilding on 28 April is named, and the daily-replicated tables are named too. Every question that lands during this window pays for itself once and stays answerable from the saved evidence afterwards.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "The squeeze batch measured five lanes of the map in one pass",
          "detail": "With the warehouse open, five ranked lanes were measured against their pre-written decision rules in a single batch. Payment recovery: around 97 percent of failed renewals are involuntary, and the recoverable pool has already been retried around six times, so the ceiling is real and not the first move. Marketing: spend lives nowhere in the warehouse, and canonical channel attribution stopped functioning after 28 April. Pricing: at most a four-point renewal gap between tiers, around eighteen points across geographies — signal, not a verdict. Support: billing draws about a quarter of conversations and more of the tagged share; a cost per contact needs one line from finance. Fraud: disputes are near zero since mid-2025 and the lane closed as a win — refunds, at 5.8 percent, are the real leak. Each lane's evidence is saved and answerable from the record.",
          "receipt_count": 4,
          "link": "/opportunities/",
          "featured": false
        },
        {
          "title": "App usage was read for the first time",
          "detail": "Session and event tables across iOS and Android are now on record — connect ratios by platform, active-user connect share, churn versus usage, cancel reasons, and purchase rollups. A meaningful share of subscribers never use a byte; three quarters of churners were active in the last month. The mobile side of the operation is no longer invisible.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The lineage quest is a set of owner sit-downs, not another dashboard",
          "detail": "The question sheet is ready for each owner in turn — Šaras on rate and gates, the payments owner on the recovery lever, the revenue-model owner on what really drives the top line, finance on the runway edge, marketing on where spend actually lands. Each conversation resolves a layer the warehouse cannot answer; the answers land in the shared record.",
          "receipt_count": 1,
          "link": "/opportunities/",
          "featured": false
        },
        {
          "title": "A governance findings pack is ready for the next call",
          "detail": "Twenty items and nine questions from today's warehouse pass, ordered for the working meeting on 21 August — freeze family reframed, replica holes named, a July revenue reconciliation, an attribution stop, and the asks that turn each finding into an owner-answered action.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The data-unlock room is sharper by what today's evidence proved",
          "detail": "Intercom was scoped to articles only after the conversation and contact replicas were verified daily; the GA4 ask now covers the pre-mid-June history the warehouse export does not carry; a support cost line was added under finance; and the non-Stripe payment ask was named — PayPal and Coingate charge-level exports with attempts and outcomes. Every change came from a saved batch, not from recollection.",
          "receipt_count": 1,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "The warehouse pass runs unattended the moment access returns",
          "detail": "A local scheduled watcher checks the token every half hour; when it opens, it runs the whole standing pass without a person — inventory, fitness, squeeze batch, data-unlock diff, coverage line, report, and handoff. Its first real green run happened today on Šaras's own token.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The War Room sign-in is now the Kairos-branded page",
          "detail": "The door announces the engagement instead of the platform. Team members reach the same room; the sign-in is a Kairos-themed page hosted on our own login, not the shared Cloudflare card. It went live after being proven end-to-end.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Canonical revenue attribution stopped after 28 April",
          "detail": "The channel and source attribution on the canonical revenue table stopped functioning after 2026-04-28 — new revenue reads 0 percent attributed from May through August, where prior months carried 39 to 53 percent. The daily web-session model still tags around a fifth of new web revenue to a paid click but is a separate door-only source. Any decision anchored on the canonical attribution since May is anchored on a hole.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "Five materialised views froze on 28 April and never refreshed",
          "detail": "Five materialised views — cancel reasons, master users, web-source subscriptions, coupons, and fees — were created on 2026-04-28 and never rebuilt; the gemini refresh across the same set stopped on the same date. Every analysis of these tables from May forward is describing April.",
          "test": null,
          "receipt_count": 2
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-15",
      "milestone": "Kairos · Day 6",
      "attention": [
        {
          "title": "The weekly one-pager now reports what got done, not how long it took",
          "detail": "Hour counts came off the client-facing weekly report in every place they appeared: the section heading, the summary table, each past edition's collapsed line, and the in-page navigation. Spend against the monthly ceiling stays, because what has been used and what remains is a contractual fact rather than a measure of duration. The republished page was read back live to confirm that no hour count survives outside the rate terms.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The nightly refresh proves the live page before it reports it",
          "detail": "The unattended nightly rebuild of the ledger surface now announces a live verification only after the authenticated check has actually run and passed; the announcement is conditional on the result rather than printed on the way out. A test sits on that seam and was watched to fail before the change and pass after it, so the refresh can no longer report green on a page it did not read.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The ledger and the weekly one-pager are two surfaces for two readerships, verified in code",
          "detail": "The ledger room is core-only by construction: team-tier identities are routed away from it at the door, and the old ledger address forwards into the same gated room. The team's account of the week is the weekly one-pager on the Kairos site, the page corrected live during the Friday review. Both derive their figures from the same time ledger, so a value changed in one is derived into the other, never retyped.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        }
      ],
      "findings": [],
      "status": "reported"
    },
    {
      "date": "2026-08-14",
      "milestone": "Kairos · Day 5",
      "attention": [
        {
          "title": "The Friday review call settled what the work is waiting on",
          "detail": "The engagement's standing Friday review ran for an hour with the week-1 one-pager open on screen, corrected live as it was read. The room agreed without dissent that access to internal data is the one thing holding the work back, and separated it into two problems worth keeping apart: permissions on data that already exists, which can move within days, and data nobody holds yet, which is slower. The call was recorded by agreement and turned into a written record the same day, so each action carries an owner rather than a memory of who said it.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The data unlock is a full map of how the company runs",
          "detail": "The ask is laid out as a map of the operation, area by area: sales, marketing, customer support, product and network, payments, GoProxies as its own stack, finance, company knowledge, and the data warehouse. Each area names the systems behind it and who can grant each one, so a hole in the map shows up as a hole rather than staying invisible. A closing section reaches what no list can — twelve months of recurring software spend, the connected-apps list in Workspace admin, the names of password-vault entries, the domain inventory — plus three questions to each team lead: what you open every morning, where you write numbers, and which report you file and where its data comes from. It lives in one room with a copy button on every block, each item carrying its own state, and a stopping rule: on 21 August the analysis starts on whatever is open by then.",
          "receipt_count": 4,
          "link": "/data-unlock/",
          "featured": false
        },
        {
          "title": "The weekly one-pager was rewritten to be read, not decoded",
          "detail": "Two editions had already gone out to a finance director and a board member carrying unexplained internal shorthand. This edition adds a plain-language gloss on every specialist term at first use, a plain subtitle under all fourteen section headings, and a short how-to-read block at the top. Nothing in the substance changed; the barrier to reading it did.",
          "receipt_count": 3,
          "link": null,
          "featured": false
        },
        {
          "title": "Every opportunity now shows how good its evidence is, on the same picture as its grade",
          "detail": "The opportunities view previously showed a judgement without showing what the judgement rested on. It now plots evidence level against grade, so a weak claim and a well-supported one can no longer look alike. Checked against the live page rather than a local copy.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "A method for measuring MN's operations against the best comparable operators",
          "detail": "Introduced during the call and written up the same day. Map a vital operation function by function, assemble the standard a strong operator in the same business would hold for it, measure the distance between the two, and close the largest gap first. Marketing is the first candidate, because none of its numbers have been seen yet.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "Gitanas can open the War Room",
          "detail": "His access was provisioned and then read back off the hosting provider's own records rather than assumed from a successful deployment. He was told the same day.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "The shared code host has been unreachable since 12 August",
          "detail": "It has now been down for 45.5 hours across 432 consecutive attempts. The failure is in the connection itself, not in credentials and not in the size of what is being transferred. The practical effect is that signal from the other side has not been reaching us for two days, so anything sent through that channel since Wednesday afternoon should be assumed unseen.",
          "test": null,
          "receipt_count": 2
        },
        {
          "evidence_state": "hypothesis",
          "title": "The existing sales system may not be reusable as described",
          "detail": "It was described in the call as something already running that would not need rebuilding, on the strength of a secondhand account. Asked directly a minute later, nobody in the room could say what the system is. Until that is answered its state should be treated as unknown, and it belongs on the access list like everything else rather than being counted as already in hand.",
          "test": "One answer from the person named as knowing it: whether they built or maintain the sales system, and what it does today. A clear yes retires this.",
          "receipt_count": 1
        },
        {
          "evidence_state": "hunch",
          "title": "Only a small share of what happens inside MN is currently visible to us",
          "detail": "The working estimate offered in the call was roughly 3%, given as a rough judgement rather than a measurement. It is carrying a lot of weight: it is the reason data access outranks everything else right now. Nobody has counted what share of the operation is actually visible, and counting it would cost far less than the decisions resting on it.",
          "test": null,
          "receipt_count": 1
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-13",
      "milestone": "Kairos · Day 4",
      "attention": [
        {
          "title": "The two assistants exchanged their first message directly",
          "detail": "Kairos runs on two people's assistants being able to reach each other, and until today the only channel between them was the shared code host — which was unreachable all day. A private lane was designed, built and put live in one pass, with a written disclosure of exactly what crosses it read and approved before anything was sent. The message tool now falls back to that lane automatically when the code host fails, and the fallback was proven against the real outage rather than a rehearsed one. The first exchange completed and was acknowledged the same day.",
          "receipt_count": 3,
          "link": null,
          "featured": true
        },
        {
          "title": "The War Room front page was rebuilt as a hub",
          "detail": "The landing page had grown into one very long scroll, so a first-time reader met the whole project at once and a returning reader could not find anything. It is now a short hub that says what Kairos is in plain words and routes to each room, with the full current state promoted into a room of its own. Every load-bearing term is now defined where it appears rather than assumed.",
          "receipt_count": 2,
          "link": "/team/",
          "featured": false
        },
        {
          "title": "The way this work describes itself was corrected",
          "detail": "Several rooms had drifted into consultancy vocabulary — advisory engagement, advisory operation — which describes a relationship this is not. Every instance was cut and replaced with an accurate description of an asymmetric unit, and a build check now fails on that vocabulary so the drift cannot return quietly.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "A staleness check now stands behind every room",
          "detail": "Rooms go stale silently: the page still loads, the numbers still render, and nobody can tell the state behind them stopped moving. A freshness and coverage check now runs on every deploy and cross-checks that the hub, the state room and the machine-readable summary agree with each other.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "A daily public-source watch on the market went live",
          "detail": "A third intelligence line now collects what is said about the company in public each morning and republishes it as a dated digest carrying an explicit coverage map, so a quiet day can never be mistaken for a day when the collectors were blind. Everything it gathers is public-source.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The operational language of the work is written down",
          "detail": "The terms this work runs on now have a plain-words section on the system page, so a reader does not have to reconstruct our vocabulary from context before they can follow a decision.",
          "receipt_count": 1,
          "link": "/system/",
          "featured": false
        },
        {
          "title": "Renewal behaviour was situated against the outside world",
          "detail": "An outside-in teardown established that no consumer VPN publishes a first-renewal rate at all, found the one commensurable public benchmark, mapped the mechanisms the incumbents run at the renewal boundary and the litigation now attached to them, and named which of the decisive unknowns are already reachable in the warehouse.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The next communications layer was reviewed before it was built",
          "detail": "Three independent reviews — security, governance and systems — were run in parallel against the proposed layer, and their findings were adjudicated one by one before the build specification was accepted. The rule that this layer is reviewed before it is built, not after, was set the night before and held.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "An access-token defect was found and closed",
          "detail": "Machine access policies were being named after the audience they served rather than the application, so a second application sharing an audience would have silently merged its token set with the War Room's. The live policy was renamed in place without disturbing anyone's existing access.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The shared code host stayed dark, and the offsite copy was verified complete",
          "detail": "The host carrying the shared repository was unreachable for the whole working day. The cause was pinned to the backend rather than to credentials or the network edge, and the offsite copy was refreshed and verified to contain the commits that had been stuck outside it.",
          "receipt_count": 2,
          "link": "/repo-status/",
          "featured": false
        },
        {
          "title": "An identity design was killed by its own review before it shipped",
          "detail": "The planned personal-access surface relied on a mechanism an independent review showed could not be enforced on the storage it was built for. The mechanism was retired and the reasoning written into a durable decision record with the storage rules attached, so the same defect cannot be rebuilt later. The direction was then reopened on a correct foundation, and a first working version of the personal page went live overnight.",
          "receipt_count": 2,
          "link": "/me/",
          "featured": false
        },
        {
          "title": "Every label on the opportunity board now explains itself",
          "detail": "The board carried eighty-one labels — scores, ladder steps, column headings — that assumed the reader already knew our shorthand. Each one now explains itself where it sits, so the board can be read cold. A separate public door was also added, so a shared War Room link previews correctly when it is sent rather than arriving blank.",
          "receipt_count": 2,
          "link": "/opportunities/",
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "A record that cannot be read cold is not a record",
          "detail": "A reader given no context and no help scored the rebuilt arrangement 9 out of 10 against 7 out of 10 for the version it replaced, and the short machine-readable state summary alone answered 8 of the 10 questions that previously required crawling the entire front page. Length was working against comprehension, not for it.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "No competitor publishes a first-renewal rate",
          "detail": "A search across the major consumer VPNs, plus the filings from the one period a competitor was publicly listed, found no published first-renewal rate, cohort survival curve or voluntary-versus-involuntary split anywhere. The only commensurable public benchmark is an app-store subscription dataset whose closest category shows a 35 percent median annual first renewal, which places roughly a third in ordinary territory for an annual cohort. The two competitor retention figures that do exist are measured on different clocks and do not compare.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "hypothesis",
          "title": "The interesting question about first renewal is its composition, not its level",
          "detail": "If the figure blends monthly subscribers in, it is a weaker result than it looks, because monthly first-renewal medians run far above annual ones. If it is an annual cohort, it is unremarkable and the leverage sits elsewhere — in the first month, where a third of annual cancellations land, and in failed payments, which account for between a seventh and a third of cancellations in the store data.",
          "test": "Split first renewal by plan length in the warehouse, then split non-renewals into voluntary and failed-payment. If the annual cohort alone sits near the benchmark and failed payments carry a large share, the level is not the problem and the boundary work should target month one and billing recovery.",
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "A fallback is only proven by the outage it was built for",
          "detail": "The message fallback lane was not verified against a simulated failure. The shared code host was genuinely unreachable while it was being built, so the first real use was also the proof. A path that has never carried traffic during an actual outage should be treated as untested however carefully it was written.",
          "test": null,
          "receipt_count": 1
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-12",
      "milestone": "Kairos · Day 3",
      "attention": [
        {
          "title": "The meeting corpus was verified, and its blind spot named",
          "detail": "The delivered recordings were checked against their manifest rather than accepted on report: complete for what they cover, 51.3 hours across 67 meetings. Coverage ends in December 2024, so 2025 and 2026 carry no recorded meeting evidence.",
          "receipt_count": 1,
          "link": "/all-hands-2026-08-07/",
          "featured": false
        },
        {
          "title": "The opportunity board was re-derived blind and re-ranked",
          "detail": "Every candidate area was graded against a written evidence ladder with thresholds fixed before the evidence was read, then the board was re-ranked from those grades. The re-ranked board is live with its methodology and release record.",
          "receipt_count": 2,
          "link": "/opportunities/",
          "featured": true
        },
        {
          "title": "A revenue-perimeter reading was corrected against the primary source",
          "detail": "A presentation image from 2026 disproved a broad company-perimeter reading of earlier figures. The conclusion was reset and the remaining product-allocation boundary left standing as an open question.",
          "receipt_count": 1,
          "link": "/business-health/",
          "featured": false
        },
        {
          "title": "The deck archive is being brought in to cover 2025-2026",
          "detail": "209 decks across 129 events were located outside the shared store and requested into it verbatim, most recent years first, because for the uncovered period they are the only surviving record.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "War Room access was corrected for shared assets",
          "detail": "Files that belong to no room were being withheld from team-tier members, who saw a broken page where a permitted asset should have been. Shared assets are now served to everyone admitted, with room contents unchanged.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "A guided path for the four data-access grants went live",
          "detail": "Each grant that widens capture now has a walk-through page ordered by effort, starting with the quickest. The asks are specific, so granting takes minutes, not meetings.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "Cancellation measurement was pre-registered",
          "detail": "The stop rules and boundaries for the cancellation analysis were fixed in writing before the data could be queried, so the method cannot be shaped by its first result.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The shared repository outage was handled in the open",
          "detail": "The code host went unreachable in the late afternoon and stayed down into the night. An incident page carries the timeline, the observed evidence, the impact, and the recovery decisions that are ready for a call.",
          "receipt_count": 1,
          "link": "/repo-status/",
          "featured": false
        },
        {
          "title": "Spoken decisions now produce written readbacks",
          "detail": "Every structured conversation is paired with a written quote and definition within a day, because a conversation is not evidence until it produces a document. Silence is not confirmation.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Verification stops where the record stops",
          "detail": "The corpus is complete for what it covers and silent for 2025 and 2026. Decisions about the current period cannot cite meeting evidence that does not exist, which is why the deck archive matters more than the transcript count.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "Admitting a person is not the same as serving them a file",
          "detail": "Room-level authorization has to exempt shared assets, or a permitted member is admitted through the door and then handed a broken page. The gap was invisible from a higher-tier account.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "hypothesis",
          "title": "The remaining revenue difference may be a product-allocation boundary",
          "detail": "After the perimeter reset, the residual gap may come from which products are counted rather than from missing or duplicated source rows.",
          "test": "Reconcile one 2026 presented figure against the warehouse aggregate restricted to the same product set; if it reconciles, the boundary explains the difference.",
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "The BI feed inflated historical revenue against every clean source",
          "detail": "Reconciling the meeting-era records against primary sources shows the feed ran 6.5-28 percent above them through 2023-2024, while the clean sources agree within 1 percent. Any number quoted from that feed needs a source check before reuse.",
          "test": null,
          "receipt_count": 1
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-11",
      "milestone": "Kairos · Day 2",
      "attention": [
        {
          "title": "The September opportunity target became an operating contract",
          "detail": "The live board now separates screening from validation and launch. A candidate launches only after evidence, authority, ownership, and instrumentation gates hold.",
          "receipt_count": 1,
          "link": "/opportunities/",
          "featured": true
        },
        {
          "title": "Measurement baselines were reconciled across source layers",
          "detail": "The current warehouse and presentation layers were compared, and a material source-layer inconsistency was isolated instead of blended into one baseline.",
          "receipt_count": 1,
          "link": "/business-health/",
          "featured": false
        },
        {
          "title": "Retention and customer mapping moved onto measured evidence",
          "detail": "The working map now distinguishes what the available cohort evidence supports from what remains unproven.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "The All Hands corpus path moved forward",
          "detail": "The shared storage path was consolidated, transcript delivery is in progress, and a portable repository watcher is ready. Recipient installation and verification remain open.",
          "receipt_count": 1,
          "link": "/all-hands-2026-08-07/",
          "featured": false
        },
        {
          "title": "Inbound signal handling became loss-proof machinery",
          "detail": "Counterparty activity is now detected on its own monitor with repeat-until-acknowledged delivery, so a busy stretch cannot silently drop an inbound signal. The lane was rebuilt against a red-first test suite that surfaced and closed four real defects.",
          "receipt_count": 2,
          "link": null,
          "featured": false
        },
        {
          "title": "Operational language was tightened at the source",
          "detail": "Fact, hypothesis, assumption, and hunch now have distinct meanings. Shared writing must help collaborators judge the opportunity—not merely be safe to show.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The daily brief became a separate team surface",
          "detail": "A dated War Room view now shows where Kairos attention went and which findings are worth carrying, with Day 1 and Day 2 history. It refreshes nightly from a deliberately curated source rather than the private ledger.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Screening is not a launch",
          "detail": "The opportunity process now keeps discovery, validation, and launch as separate states, preventing early plausibility from masquerading as an operating commitment.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "A source label is part of the evidence",
          "detail": "When two measurement layers produce different outputs, naming the layer and its known limits is necessary for the result to remain decision-useful.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "hypothesis",
          "title": "The remaining baseline mismatch may be definitional",
          "detail": "The unresolved difference may come from perimeter definitions rather than missing source evidence.",
          "test": "Recover the exact source definition and reconcile its inclusion rules line by line.",
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "A team brief needs positive curation, not redaction",
          "detail": "A record can be safe for a private client ledger and still be wrong for automatic team publication. The shared surface must select what helps collaborators judge the work instead of trying to strip sensitivity after the fact.",
          "test": null,
          "receipt_count": 1
        }
      ],
      "status": "reported"
    },
    {
      "date": "2026-08-10",
      "milestone": "Kairos · Day 1",
      "attention": [
        {
          "title": "The operating kickoff set the first delivery sequence",
          "detail": "The first working session turned the immediate needs into four active lanes: data access, War Room identity, team onboarding, and All Hands extraction. Production followed that sequence the same day.",
          "receipt_count": 1,
          "link": null,
          "featured": true
        },
        {
          "title": "The shared repository moved to a private, self-hosted home",
          "detail": "The Kairos repository now lives on a private self-hosted instance with a guarded migration and structured onboarding for its three members. The shared record and its delivery channel are under the team's own roof.",
          "receipt_count": 2,
          "link": "/connect-kairos-git/",
          "featured": false
        },
        {
          "title": "War Room access moved to individual identity",
          "detail": "The shared password was replaced by per-person email verification, with deny-by-default access across the War Room.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The team onboarding path became self-serve",
          "detail": "Each teammate now has a tailored connection path and a copy-ready agent briefing instead of a shared setup document.",
          "receipt_count": 1,
          "link": "/connect/",
          "featured": false
        },
        {
          "title": "The All Hands archive gained an extraction path",
          "detail": "A lossless local procedure now preserves decks, audio, frames, provenance, and authorization state without requiring a full archive upload.",
          "receipt_count": 1,
          "link": "/all-hands-2026-08-07/",
          "featured": false
        },
        {
          "title": "The Simonas data-access conversation was prepared",
          "detail": "A focused call brief was written and published before the data-access conversation, with the earlier proposal preserved as reference rather than silently replaced.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The War Room's own blueprint went on the wall",
          "detail": "A room now explains how and why the War Room is built — what each surface is for and the rules the record follows. New readers can orient without a walkthrough.",
          "receipt_count": 1,
          "link": "/system/",
          "featured": false
        },
        {
          "title": "The publishing boundary got a researched verdict",
          "detail": "World practices on open-versus-private working were surveyed and a verdict filed: a private working repository plus a curated shared surface, with no mixed middle. The boundary is now policy, not habit.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        },
        {
          "title": "The daily reporting chain was repaired",
          "detail": "The Access migration had interrupted the reporting fold. The chain was rebuilt and redeployed so the dated record could refresh again instead of failing silently.",
          "receipt_count": 1,
          "link": null,
          "featured": false
        }
      ],
      "findings": [
        {
          "evidence_state": "fact",
          "title": "Identity access and room authorization are different gates",
          "detail": "Admitting a person through the War Room door does not decide which rooms they may read. Authentication belongs at Access; audience-specific room scope belongs at the origin worker.",
          "test": null,
          "receipt_count": 1
        },
        {
          "evidence_state": "fact",
          "title": "Archive usefulness does not require archive-sized transfer",
          "detail": "A local extraction can preserve decks, audio, frames, manifests, hashes, and authorization state while sending only the evidence bundle needed for the current question.",
          "test": null,
          "receipt_count": 1
        }
      ],
      "status": "reported"
    }
  ]
}
