{
  "schemaVersion": 2,
  "date": "2026.08.06",
  "publishedAt": "2026-08-06T07:09:56-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Adding internet-observation review to Hiro's benchmark page",
  "publicationStatus": "Validated and published",
  "executiveSummary": [
    "Restored Hiro's stopped API service and added a dedicated read-only Internet observations view to the Evaluation Observatory benchmark page.",
    "The view now lists all three snapshots from the first low-budget Phase 1 shadow session, including source, timestamp, HTTP result, retrieval budget usage, sanitization results, packet and content hashes, and expandable sanitized text.",
    "Every record is reverified against its SHA-256 companion before the API exposes it. A packet that fails integrity validation is counted but excluded from review.",
    "Focused dashboard and observation validation passed 63 tests, and the complete Hiro suite passed all 383 tests before the service restart.",
    "The observation capture policy remains disabled, the observation sentinel and Stage 6 sentinel remain present, and dashboard visibility grants no case-conversion, promotion, deployment, or Stage 6 authority."
  ],
  "workstreams": [
    {
      "title": "Verified observation API",
      "status": "Completed",
      "details": [
        "Added a read-only evaluation API route that discovers timestamped snapshot packets beneath the configured runtime snapshot root.",
        "The route verifies each packet's companion SHA-256, sanitized-content SHA-256, schema, untrusted-evidence marker, and zero-authority boundary through the existing snapshot verifier.",
        "The response exposes sanitized text and review metadata only. Raw response bodies, cookies, credentials, and local snapshot filesystem paths are not returned.",
        "The response reports total, verified, and rejected packet counts while keeping promotion_authorized false."
      ]
    },
    {
      "title": "Benchmark review interface",
      "status": "Completed",
      "details": [
        "Added an Internet observations tab alongside Overview, Nightly, Autonomous changes, Performance, Runs, Compare, and Lineage.",
        "The view summarizes captured snapshots, verified integrity, rejected packets, total retrieved bytes, capture-policy state, and promotion authority.",
        "Each collapsed record shows its source and status. Expanding it reveals request metadata, content type, sanitizer actions, injection indicators, hashes, authority, and scroll-bounded sanitized content.",
        "All external text and metadata are escaped before insertion into the page, so sanitized evidence remains data rather than executable markup or instructions."
      ]
    },
    {
      "title": "Service restoration",
      "status": "Completed",
      "details": [
        "Diagnosed the loading failure as a stopped Hiro API origin while the existing remote-access tunnel remained active.",
        "After user authorization, started Hiro through its pinned hidden launcher without changing the separate no-automatic-recovery marker.",
        "Verified successful listeners for the main API, local HTTP API, and loopback-only Evaluation Observatory origin.",
        "Verified that the public benchmark address reaches its existing access-control boundary and that the local origin now returns the benchmark page and observation API successfully."
      ]
    }
  ],
  "decisions": [
    "Keep autonomous candidate review and internet snapshot review as separate tabs because one represents tested code variants and the other represents untrusted source evidence.",
    "Verify snapshots on every API read rather than trusting directory presence or previously recorded status.",
    "Exclude integrity-failed snapshots from the returned review list while surfacing their count.",
    "Show sanitized content for operator review but never expose raw downloaded bodies or local runtime paths.",
    "Do not infer that reviewing or displaying a snapshot authorizes conversion into an evaluation case.",
    "Leave observation capture disabled and retain both observation and Stage 6 stop sentinels after restoring the general Hiro API service."
  ],
  "validation": [
    {
      "check": "Focused dashboard and observation tests",
      "status": "passed",
      "result": "All 63 focused tests passed, covering dashboard authentication boundaries, autonomous candidates, router performance, observation sanitization, snapshot verification, path restrictions, and the new review endpoint and page contract."
    },
    {
      "check": "Complete Hiro suite",
      "status": "passed",
      "result": "All 383 tests passed in 119.76 seconds before the service was restarted."
    },
    {
      "check": "Live observation API",
      "status": "passed",
      "result": "The restored loopback API returned three captured snapshots, three verified snapshots, zero integrity failures, 81,403 total retrieved bytes, capture disabled, and promotion authority false."
    },
    {
      "check": "Browser-rendered benchmark page",
      "status": "passed",
      "result": "Browser inspection confirmed the new tab renders all three sources, the aggregate safety cards, expandable metadata and sanitized content, exact hashes, and no browser console errors."
    },
    {
      "check": "Service listeners and remote boundary",
      "status": "passed",
      "result": "The API is listening on its three expected ports; the loopback benchmark origin returns HTTP 200, and the remote benchmark address reaches the configured access login boundary."
    },
    {
      "check": "Implementation commit",
      "status": "passed",
      "result": "The read-only snapshot review API and benchmark UI were committed at 397fa21 on Hiro's existing development branch."
    }
  ],
  "currentState": [
    "Hiro's API service and Evaluation Observatory are running.",
    "The benchmark page includes separate Autonomous changes and Internet observations tabs.",
    "All three Phase 1 snapshots are visible for read-only operator review and currently pass integrity verification.",
    "The checked-in capture policy remains enabled false, and the observation DISABLED sentinel remains present.",
    "Stage 6 DISABLED remains present; no candidate was promoted, merged, deployed, or used to restart another service."
  ],
  "limitations": [
    "The new view is an evidence browser, not a review-decision editor; it does not create review records or assertions.",
    "Sanitized snapshots remain untrusted external evidence even when their integrity is verified.",
    "The first session contains only three pages and does not establish readiness for continuous or broad-domain internet observation.",
    "Remote access still depends on the existing authenticated access boundary and local Hiro service availability."
  ],
  "nextSteps": [
    "Review the three displayed snapshots for usefulness rather than treating successful retrieval as an evaluation result.",
    "Choose any observation that reveals a concrete, reproducible Hiro failure and define explicit assertions for it.",
    "Convert only affirmatively reviewed observations into frozen evaluation cases.",
    "Run baseline and candidate against the identical selected snapshot hash before considering the case as improvement evidence.",
    "Keep future public sessions small while accumulating reviewed evidence about reliability and usefulness."
  ],
  "disclosureNote": "This public entry contains no credentials, private held-out cases, personal data, raw retrieved page content, local runtime paths, or actionable details about unresolved security weaknesses."
}
