Skip to content

Work order: execute research follow-ups from the 2026-09-24 sweep #3296

Description

@Xore

Goal

Execute the concrete follow-ups spawned by the research-label sweep of 2026-09-24. This is the work order; each item below has its own tracking issue and is closed by its own PR.

Source research

Work items (in recommended order)

# Item Gate
#3295 Export and census the queryable operator-disposition corpus Establishes the label gate for all later calibration. Do this first.
#3294 BETH Tier 2 sanity-rail harness in ml-worker/benchmarks/ Bounded, unblocked. Independent of #3295.
#3292 Preserve session terminal observation and capture coverage Prerequisite for any abandonment-rate denominator.
#3293 Offline session-engagement aggregate with labeled benign baseline Blocked on #3292.

Sequencing rules

  1. ml: export and census the queryable operator-disposition corpus for calibration #3295 before ml: add BETH Tier 2 sanity-rail harness to ml-worker/benchmarks #3294's downstream work. The disposition census tells us whether calibration is reachable at all. The BETH harness itself is independent and can proceed in parallel, but no threshold or weight argument may be derived from either until ml: export and census the queryable operator-disposition corpus for calibration #3295's census is in.
  2. llm worker: preserve session terminal observation and capture coverage in state summaries #3292 before research: add an offline session-engagement aggregate with labeled benign coverage #3293. Engagement aggregates are meaningless without a terminal-observation field and a capture-coverage denominator.
  3. Calibration is precision-only, never recall. Only above-threshold alerts persist, so the disposition corpus can measure alert precision but not deployment recall. No issue, doc, or commit may claim otherwise.
  4. BETH is a sanity rail, not promotion evidence. No change to the composite's 0.4/0.4/0.2 weights or to ML_ALERT_THRESHOLD may be argued from it. Point-adjusted F1 stays banned.
  5. Engagement metrics never attribute an attacker. Disconnect is ambiguous across scanners, ordinary clients, deliberate disengagement and network failure. No issue, doc, or commit may label a client as automated/AI from these signals.

Invariants (unchanged by this work)

  • frontend-next/public/static/theme.css stays the only stylesheet, vendored from Xore/theme via theme.lock. New styling goes upstream first.
  • No AI attribution in commits, PR bodies, or issue comments.
  • If a change touches arcane/home/<stack>/, the merge is not live until Arcane is manually resynced — autoSync=false.

Done when

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestepicLong-running tracker spanning multiple issuesresearchResearch findings or reports

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions