Skip to content

TRUST-001 — One canonical derived report and no weaker downstream trust #7

Description

@chaoz23

Priority: P0
Type: architecture/trust/UX
Size: L

Problem

On the authorized live sheet, derive --brief correctly marks AC and spell preparation/slots for confirmation, while QA labels uncertain fields OK, quiz privately grades against the uncertain AC and omits missing slot questions, and stance/seatpack/intake present downstream values without equivalent warning. Trust evaporates as data is projected.

Proposed contract

Every field in DerivedCharacterV1 carries:

{
  "value": null,
  "state": "trusted | confirm | unsupported | unknown | invalid | not_applicable",
  "formula": null,
  "inputs": [],
  "sources": [],
  "rules_profile": null,
  "findings": [],
  "confidence": null,
  "authority": "source | player | dm | rules_engine | session_host",
  "as_of": null,
  "stale": false,
  "sensitivity": "mechanical | persona | player_private | dm_private"
}

Views may omit detail but may never improve state or remove a material finding.

Acceptance criteria

  • Define and version one canonical report schema used by CLI, MCP, brief, report, QA, stance, quiz, seatpack, intake, and future UI.
  • Trust state is field-level and distinguishes numeric base values from conditional defenses/advantages.
  • Quiz never supplies an expected answer for a confirm, unsupported, unknown, or invalid field.
  • Stance either marks uncertain inputs inline or declines dependent calculations.
  • Aggregate readiness/status is derived from canonical findings with documented severity thresholds.
  • Every projection carries engine/schema/rules versions, source fingerprint, and as_of.
  • Observed build facts, deterministic derivations, player declarations, DM rulings, and mutable session facts retain distinct authority and freshness.
  • Role filtering, summarization, context truncation, and dependent agent calculations may never improve trust state or remove a material warning.
  • Unknown global scope prevents “everything clean/trusted.”
  • A projection-invariant test enumerates every canonical field and proves output state is equal or more conservative in every view.

Test plan

  • Golden authorized-sheet replacement; synthetic uncertain AC/slots/speed/defense; unhandled unknown; cross-view property tests; backward-compat fixtures.

Dependencies

Architectural prerequisite for QA-001, CLI-001, MCP-001, UX-001, and WORKFLOW-001.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions