Skip to content

GCL-TCS pilot evidence index

Operation: GCL-TCS-PILOT-INSTITUTIONALIZATION-001
Tracker: grandchallenge/MATH-PROGRAMME#788
Measurement baseline protected main: 66aaa9175fe8d91907c3cf113efc2d08a113a780
Status: non-authoritative discovery surface

Purpose and authority boundary

This file is a shallow navigation surface for the institutionalization pilot. It points to governed records without copying their authority into this index.

This index is not a GCL-TCS normative source, GCL-POS authority record, GHOS terminal ledger, MATH-CORE state store, mathematical Claim Ledger, certification record, review disposition, publication authorization, or source of mathematical truth. When this index and a governed source disagree, the governed source controls.

Candidate Stage-A pilot packages are evidence for institutional learning. Their protected repository presence does not promote their GCL-TCS authority; each remains governed by its own recorded authority_status, promotion_status, dimensions, and review state.

Controlling doctrine

Routine pilot-record work does not acquire a generic Human Steward or Referee gate. G8 matters when an actual promotion transition is requested under the controlling instrument.

Candidate standard and version-1.0 criteria

The candidate standard remains GCL-TCS-00 version 0.1.0. Version-1.0 readiness is separate from authority to conduct this pilot.

Real pilot evidence by required class

Mathematical

Stage-A protected merge: 66aaa9175fe8d91907c3cf113efc2d08a113a780. The supplement remains candidate/in-review and does not alter Lean, certification, Claim Ledger, prior-art, publication, or MATH-CORE authority.

Experimental / computational

The original institutionalization pass correctly recorded an explicit deficit because no completed non-synthetic P04 result package had then been verified. A plan, harness, notebook, or manufactured experiment was not counted merely to fill criterion 8.

Successor operation GCL-TCS-P04-PILOT-001, tracked by issue #819, applies P04 retrospectively to the independently pre-existing TCM-C72-INTERFACE-001 computational result. The subject was already protected-merged in grandchallenge/QUANTUM-TECHNOLOGIES as aa53dc3c0e99c39f766f4ccb0c0d0629cd9093db after a frozen 64-shard exact computation over 329 inputs and independent PR approval. The GCL-TCS candidate P04 supplement does not rerun, tune, or alter the experiment.

The P04 pass preserves all finite positive and negative outcomes, the exact execution and corpus identities, the distinction between the source artifact status candidate_executable_not_promoted and its finite scientific adjudication C72_TCM_SHARED_DECODER_INTERFACE_CERTIFIED, and the source prohibitions on C90 execution, broader family/asymptotic claims, hardware superiority, learned decoding, approximation, autonomous search, and adjacent programme authority. It also retains one real source limitation as P04-D001: the original workflow used mutable ubuntu-latest, so exact runner-image reconstruction is not established even though Python/action revisions were pinned and host size was non-scientific.

Software

Stage-A protected merge: 4a13fefdf213979ed255bfaacc677d0f1d062bcd. Its observations include one live successor-routing example, synthetic FP/FN probes, fail-closed ambiguity handling, acquisition-layer burden, and the explicit absence of representative empirical error rates.

Operational

The historical GHOS result remains terminal within its original scope and is not rewritten by later estate changes.

Governance

Stage-A protected merge: f48244ccac621fa59d64daff0b84f3dd5b0877e4. The supplement does not amend the directive.

Public

Stage-A protected merge: 20c4796ccd6d1e9d4fd8578ffc7c3f7847b40eb6. The supplement preserves the certified C001/C003 public claim set and audited C004/C005 boundaries without republication or mathematical promotion.

Measurement and successor evaluation

  • Machine-readable pilot selection — historical non-authoritative bounded selection record for the six required pilot classes; exposed here without changing its original authority or status.
  • Machine-readable pilot measurement — defects, FP/FN evidence and limits, burden proxy, ambiguities, preserved controls, and automation opportunities.
  • Machine-readable readiness assessment — historical criterion-by-criterion assessment produced by the completed institutionalization operation.
  • Fresh protected candidate remeasurement — GCL-TCS-CANDIDATE-REMEASUREMENT-001, a ten-criterion recomputation from protected baseline ad2ae735860af73526243304238544aa294abebf; it remains immutable historical successor evidence.
  • Current fixed-revision candidate remeasurement — GCL-TCS-CANDIDATE-REMEASUREMENT-002, recomputed from signed protected baseline db3adf0f57ce44f14fff2bd975dad6a8e93cdc2f; criteria 1–9 are materially satisfied and criterion 10 is reserved to a distinct fixed-candidate Referee promotion operation.
  • GCL_TCS_PILOT_MEASUREMENT_001.md — human-readable measurement and successor recommendation.

The historical successor recommendation remains:

CONTINUE_CANDIDATE__NARROW_AND_SIMPLIFY__NO_V1_PROMOTION

Historical measurement and readiness records remain correct for their own protected baselines and are not rewritten by successor work.

Successor hardening: criterion 4

GCL-TCS-CANDIDATE-HARDENING-001 is tracked by issue #806 and implemented by PR #807.

The successor adds ci/gcl_tcs_exception_control.py and tests/test_gcl_tcs_exception_control.py, with the test registered in the existing Programme contract-test manifest. The control is bound to the candidate GCL-TCS-00/0.1.0 machine policy and fails closed for unresolved or unauthorized approval authority, missing approval identity, absent review/expiry timing on approved exceptions, attempted waiver of machine-declared non-waivable requirements, empty or placeholder compensating controls, malformed records or dates, and missing/expired/revoked/non-approved required exceptions at promotion evaluation. It includes a positive narrow approved-exception case.

The exception control does not invent profile authority. Authorized approvers remain resolved by the governing caller and review record.

Successor hardening: criterion 2

GCL-TCS-CANDIDATE-HARDENING-002 is tracked by issue #808.

The canonical derivative P01–P07 profile owner/reviewer authority map maps each profile to already-established institutional functions. Steward owns profile lifecycle for every profile because standards selection, impact class, and lifecycle governance already belong to that role. Every artifact still supplies its own mandatory owner; no person, agent identity, or repository team is preassigned by profile.

The map projects the existing G0–G9 gate matrix onto active Council functions. Amanuensis, Cartographer, Grammarian, Verifier, Adversary, domain offices such as Axiomatist, Formalist, Experimentalist, Mechanist, and the existing Referee function appear only where the current profile/gate semantics call for them. G8 remains promotion-only. Material-specific specialist and independence requirements remain governed by the existing G5, impact-class, external-authority, and review-record rules.

ci/gcl_tcs_profile_authority_control.py is a test-bound derivative validator, executed only through the existing governed contract-test route. It fails closed on profile/version drift, gate-applicability drift, missing lifecycle ownership, artifact-owner substitution, unknown role creation, or any attempt for the map to become an authority registry, confer authority by role name, activate promotion, or claim constitutional expansion.

Successor hardening: criterion 7

GCL-TCS-CANDIDATE-HARDENING-003 is tracked by issue #810.

ci/gcl_tcs_cross_surface_orphans.py adds a library-only reference graph for the bounded GCL-TCS pilot surface. It discovers repository references from Markdown, HTML, static text, TeX, JSON and YAML, validates local target resolution, rejects repository-root escapes, requires each definite governed pilot package and current gcl_tcs_*.json record to remain discoverable from this existing evidence index, and rejects strong governed identity markers hidden in conventional scratch paths. Deliberately unregistered scratch with no governed identity remains outside registration and is neither promoted nor treated as an orphan.

The control deliberately does not reproduce Documentary Library membership. Existing ci/validate_programme.py continues to invoke the authoritative Documentary Library contract, whose manifest-driven discovery covers web pages, TeX source records, candidate source locks, documentary assets and asset directories, JSON edition records, and root static inventory. The new cross-surface suite verifies that composition and adds synthetic adversarial coverage for the generic parsers rather than constructing a second manifest.

tests/test_gcl_tcs_cross_surface_orphans.py is registered in the existing governed contract-test manifest. The live test requires the current repository discovery graph to be clean; fixture tests separately exercise Markdown/HTML, source and candidate records, assets, static text, TeX, JSON, governed directories, missing targets, path escape, scratch exemption, and governed material concealed in scratch.

Successor hardening: criterion 1

GCL-TCS-CANDIDATE-HARDENING-004 is tracked by issue #814 and implemented by PR #815.

GCL_TCS_NORMATIVE_AGREEMENT_MATRIX.md gives the human-readable clause-level reconciliation. The governed machine index at governance/gcl_tcs_normative_agreement_matrix.json binds seven source-specific shards to the exact candidate source package and assembled SHA-256 ea750b9b80b53c7d6ed755978fa4bdf59413fad93cec1db81eb3238372ce61c9. It contains 119 substantive requirement rows plus six normative-keyword semantic bindings. Each row records the normative requirement, machine representation, validator/test surface, machine-checkability class, and remaining gap.

The candidate correction binds the policy manifest to the protected normative source identity, represents previously implicit claim/evidence/review/exception/gate/conformance/release record contracts, tightens the declaration schema to exact GCL-TCS-00/0.1.0 and profile 0.1.0 version locks, adds the record-contract schema and normative candidate templates, and registers tests/test_gcl_tcs_normative_agreement.py through the existing governed contract-test shard. MACHINE_CONTRACT_MIGRATION_0.1.0-R1.md records that these are candidate machine-contract corrections, not source changes or v1 promotion.

The seven normative source parts are unchanged. The historical issued submission manifest retains the originally issued machine-policy and conformance-schema hashes, and the historical #788 readiness record remains unchanged. Criterion 1 satisfaction here is candidate-readiness evidence only and does not authorize G8/G9 or version-1.0 promotion.

Successor hardening: criterion 3

GCL-TCS-CANDIDATE-HARDENING-005 is tracked by issue #816 and implemented by PR #817.

The governed mandatory-semantic coverage record derives the tested surface from exact rows of the protected normative agreement matrix rather than from an independent checklist. ci/gcl_tcs_mandatory_semantics.py dynamically re-derives the declaration and record required-field sets from the live candidate schemas and fails closed if the coverage record, candidate identity, policy required fields, agreement-matrix row set, source digest, governed test registration, or candidate-only authority boundary drifts.

tests/test_gcl_tcs_mandatory_semantics.py mutation-tests omission of every mandatory top-level and nested conformance-declaration field and every required claim, evidence, review, exception, gate, conformance-statement and release-record field. It also adversarially tests exact standard/profile locks, enumerations, patterns, formats, collection constraints, explicit-empty/not-applicable forms, claim statement-or-pointer exclusivity, ASSURED review linkage to the exact source revision, and gate/review revision plus NOT_APPLICABLE consistency. The existing dedicated exception-control suite remains the single control for non-waivable rules, approved review/expiry timing, and missing/expired/revoked required-exception semantics.

The completeness claim is limited to mandatory machine fields and field semantics represented by the agreement matrix. Rows classified review-only remain review-only and are not falsely converted into automated authority. Criterion 3 satisfaction here is candidate-readiness evidence only; it does not promote GCL-TCS-00 or activate G8/G9.

Successor pilot: criterion 8

GCL-TCS-P04-PILOT-001 is tracked by issue #819. It uses the next suitable naturally completed GCL computational result rather than manufacturing an experiment for GCL-TCS.

The P04 application maps the protected TCM-C72 subject to all eleven P04 emphasis areas. The machine-readable measurement records the real source defect P04-D001, structural burden, unresolved status-layer ambiguity, zero incremental scientific computation, exact positive/negative result preservation, and the unchanged claim firewall.

The subject's scientific bytes remain untouched. The GCL-TCS supplement is candidate/in-review with all dimensions DECLARED and G8/G9 deferred. Criterion 8 satisfaction is therefore candidate-readiness evidence for the six required real artifact classes, not promotion of the source experiment, the supplement, or GCL-TCS-00.

Prior version-1.0 readiness — protected remeasurement 001

GCL-TCS-CANDIDATE-REMEASUREMENT-001, tracked by issue #821, recomputed all ten acceptance criteria from protected baseline ad2ae735860af73526243304238544aa294abebf. It did not carry forward the historical 1 / 6 / 2 / 1 counts by assumption.

Criterion Status Protected finding
1 SATISFIED The protected 125-row agreement matrix binds all seven normative source parts to policy/schema/template/validator representations and closes the identified candidate machine-contract gaps without changing normative source meaning.
2 SATISFIED The protected P01–P07 map supplies a lifecycle owner and G0–G9 review-role map for every profile while preserving per-artifact ownership and existing institutional authority.
3 SATISFIED Mandatory declaration/record field sets and matrix-bound machine semantics have protected mutation/adversarial test coverage; review-only obligations remain review-only.
4 SATISFIED Dedicated protected exception tests fail closed on invalid/missing authority, timing, non-waivable-rule, compensating-control, malformed-record and lifecycle failures.
5 PARTIAL Gate/review records required and compared reviewed_revision, but the schemas still accepted arbitrary nonempty strings and did not establish standard-wide immutable binding.
6 PARTIAL Candidate supplements were operationally separate from authoritative subjects, but the conformance schema had no structurally distinct candidate and authoritative-source forms.
7 SATISFIED Protected cross-surface controls cover docs, web, source/candidate records, assets, static text, TeX, JSON/YAML and governed directories while preserving the deliberate scratch boundary.
8 SATISFIED All six required real artifact classes have completed protected pilot conformance reviews.
9 SATISFIED Protected measurements record false-positive evidence, false-negative evidence, burden, unresolved ambiguities, defects and explicit unknown empirical-rate limits.
10 INACTIVE__PREREQUISITES_NOT_MET Criteria 5 and 6 were PARTIAL, so no fixed v1.0 candidate revision or Referee promotion disposition was proper at that baseline.

Historical summary for remeasurement 001: 7 satisfied / 2 partial / 0 unsatisfied / 1 inactive. Its precise blockers were criteria 5 and 6. That record remains immutable evidence for its own baseline.

Current version-1.0 readiness — fixed protected remeasurement 002

GCL-TCS-CANDIDATE-REMEASUREMENT-002, tracked by issue #829, recomputes all ten acceptance criteria from signed protected baseline db3adf0f57ce44f14fff2bd975dad6a8e93cdc2f after protected closure of criteria 5 and 6.

Criterion Status Fixed-revision finding
1 SATISFIED Normative/policy/schema agreement remains protected and green under the derivative criterion-5/6 machine hardening.
2 SATISFIED P01–P07 retain the approved derivative lifecycle-owner/review-role map without creating authority.
3 SATISFIED Mandatory machine fields and semantic mutation tests remain complete; the old synthetic review-revision fixture was updated to an immutable dummy identity without weakening the test.
4 SATISFIED Dedicated exception controls remain fail-closed.
5 SATISFIED Declaration, gate and review revision fields now require immutable Git/SHA-256 identities, reject mutable symbolic refs, and enforce exact declaration/gate/review binding.
6 SATISFIED Candidate, active authoritative-source, and terminal-source records are structurally disjoint schema forms under the existing authority_status vocabulary.
7 SATISFIED Cross-surface orphan controls remain protected; this successor record is registered on this existing index.
8 SATISFIED All six required real artifact classes retain protected pilot review evidence.
9 SATISFIED FP/FN evidence and limits, burden, defects and unresolved ambiguities remain recorded, including P04 observations.
10 INACTIVE__DISTINCT_PROMOTION_OPERATION_REQUIRED Criteria 1–9 now pass, but Referee approval with explicit limitations must occur only in the distinct fixed-candidate promotion operation.

Current summary: 9 satisfied / 0 partial / 0 unsatisfied / 1 inactive. Criteria 1–9 are materially satisfied. This authorizes beginning the separately governed v1.0 candidate-freeze and Referee-promotion path; it does not itself freeze, promote, or create a Referee disposition.

Readiness remains distinct from promotion authority. No mathematical, certification, GHOS, MATH-CORE, controller, publication, or external claim authority is changed by this remeasurement.

Defect and burden evidence

The four new Stage-A packages recorded three pre-merge defects: the software gate-semantic mapping defect, software compatibility/replay-documentation defect, and public synthetic-dependency-identifier defect. All were corrected before protected merge and affected candidate closures were revalidated.

The Workstream-D measurement transaction then exposed two documentation defects before merge. First, ci/validate_docs.py rejected the new measurement page because it was absent from MkDocs navigation. Second, after that repair, mkdocs build --strict rejected eight evidence-index links that incorrectly treated repository-root artifacts as docs-local relative targets. The index now uses docs-local links only for docs-tree artifacts and explicit GitHub repository links for governed artifacts outside docs/. Both failed heads were invalidated.

The four original Stage-A packages total 36 changed files, 2,138 added lines, zero deletions, and seven pre-merge commits. These counts are a narrow repository-diff burden proxy, not a time or cost measurement.

The successor P04 pilot records its own structural burden separately: ten candidate-package files, one governed contract test, two incumbent discovery/test-manifest surfaces, zero scientific-subject files changed, and zero incremental scientific computation. Operator and reviewer time remain UNKNOWN_NOT_MEASURED. It records P04-D001 rather than claiming no defect.

Successor routing

The bounded pilot should continue as a candidate institutional learning loop, but with a narrower operating envelope:

  1. preserve immutable identities, claim/evidence boundaries, negative evidence, material-closure invalidation, proportional CI, and domain-authority firewalls;
  2. keep reference discovery compositional: extend incumbent authoritative manifests and discovery surfaces rather than adding parallel inventories;
  3. avoid generating promotion-specific G8/G9 packet material until promotion is actually requested;
  4. retain the real TCM-C72 P04 pilot as the sixth-class evidence, preserve P04-D001, and do not extrapolate its finite C72 result or its scientific certification into broader experimental or artifact authority;
  5. criteria 1–9 are now materially satisfied at fixed protected baseline db3adf0f57ce44f14fff2bd975dad6a8e93cdc2f; proceed only through the separately governed v1.0 candidate-freeze and Referee-promotion operation for criterion 10.

Revalidation rule

A pointer or measurement update is routine when it exposes unchanged governed identities. Revalidation escalates only when a material object changes: normative/authority bytes, relevant workflow/controller/protection state, mathematical/certification/canonical state, evidence-bearing cross-domain authority bridges, C04-C07 capability, constitutional policy, security-sensitive controls, or reserved external claim/publication authority.