{
  "schemaVersion": 2,
  "date": "2026.08.06",
  "publishedAt": "2026-08-06T07:49:31-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Starting Hiro's finite recurring internet-observation probation",
  "publicationStatus": "Validated and published",
  "executiveSummary": [
    "Implemented a finite unattended observation probation that can run one three-request read-only cycle per Pacific day while Stage 6 remains disabled.",
    "The probation is pinned to an exact clean Hiro Git commit, capped at seven total attempts, separated by at least 20 hours, and designed to restore the observation stop sentinel after attempt seven. Infrastructure failures count toward the cap.",
    "Each frozen snapshot now receives a deterministic source-specific probe through Hiro's local tool-free evaluator. Only a reproducible baseline failure creates a pending case proposal and Telegram review alert; a passing observation requires no action.",
    "All 79 focused adversarial tests and the complete 394-test Hiro suite passed before public access. Cycle 1 then made exactly three approved GET requests, froze three verified snapshots, and passed all three offline probes with no proposal.",
    "The probation remains in progress at cycle 1 of 7. No candidate change, approved case, promotion, deployment, or Stage 6 action resulted from this cycle."
  ],
  "workstreams": [
    {
      "title": "Finite fail-closed scheduler",
      "status": "Completed",
      "details": [
        "Added a runtime-only probation authorization separate from the checked-in disabled-by-default policy and pinned it to Hiro commit f5b2d292aed6a52efd74ae1a5683369998eb062b.",
        "Limited the probation to seven total attempts, one attempt per Pacific calendar day at 07:30, and a minimum 20-hour interval.",
        "Required a clean pinned Git tree and the Stage 6 DISABLED sentinel before every cycle. Any source drift, policy mismatch, missing stop sentinel, overlapping run, or integrity failure stops the cycle before networking.",
        "Counted infrastructure failures toward the seven-attempt limit so external instability cannot silently extend the probation. The seventh attempt restores the observation stop sentinel."
      ]
    },
    {
      "title": "Deterministic failure discovery",
      "status": "Completed",
      "details": [
        "Added one checked-in deterministic probe for each Phase 1 source: extract IANA's two example domains, select the highest Python series explicitly labeled stable, and select the latest stable httpx release while excluding development builds.",
        "Expected values are derived by source-specific deterministic code from the frozen sanitized snapshot; the model does not grade its own answer.",
        "Each probe uses Hiro's local tool-free evaluator with no browsing, shell, search, memory, history, or remote fallback, and retains the exact snapshot-content hash in its result.",
        "Passing probes remain observation evidence only. A failed probe freezes a pending proposal containing the finding, prompt, assertions, baseline response, failure evidence, snapshot hashes, zero-authority declaration, and companion SHA-256."
      ]
    },
    {
      "title": "Review and notification boundary",
      "status": "Completed",
      "details": [
        "Added a Pending evaluation case proposals panel to the Internet observations benchmark view and changed the approvals-pending count to reflect verified proposals rather than raw snapshots.",
        "The dashboard displays probation progress, next run time, per-snapshot review state, and a clear explanation that proposal approval authorizes frozen offline case creation and replay only.",
        "Pending case proposals reuse the durable Telegram review outbox. Discoveries between 23:00 and 06:59 Pacific are held until 07:00, and proposal IDs are deduplicated.",
        "No notification was queued or sent in cycle 1 because all baseline probes passed."
      ]
    },
    {
      "title": "First recurring cycle",
      "status": "Completed",
      "details": [
        "Cycle 1 made exactly one approved GET request to each of the existing IANA, Python documentation, and PyPI httpx targets, with zero redirects and no credentials, queries, uploads, or state-changing methods.",
        "The cycle downloaded 82,014 bytes under the one-megabyte cumulative limit and froze three timestamped sanitized packets with independently verified packet and content hashes.",
        "The IANA probe returned example.com, example.org; the Python probe returned 3.14; and the PyPI probe returned 0.28.1. All responses passed their deterministic assertions and recorded no tool use.",
        "The session froze as completed_read_only_cycle with companion SHA-256 e7716fc0608b4967a8b28f11d3bdaaa0900d44f2816f166e6b7e349d52f854ae."
      ]
    }
  ],
  "decisions": [
    "Use a seven-attempt finite probation rather than an open-ended observation schedule.",
    "Keep the checked-in observation configuration disabled and place the explicit authorization in runtime state pinned to one Hiro commit.",
    "Use deterministic source adapters and exact assertions for Phase 1 instead of allowing untrusted pages or a model to invent their own success criteria.",
    "Create review work only from a failed baseline probe; unchanged or successfully interpreted pages remain no-action evidence.",
    "Reuse the established Telegram quiet-hours outbox for case proposals while clearly distinguishing them from code-update candidates.",
    "Do not convert a pending proposal into an approved evaluation case, and do not generate a code candidate, without the applicable later approval and evidence."
  ],
  "validation": [
    {
      "check": "Focused adversarial suite",
      "status": "passed",
      "result": "All 79 focused tests passed, covering deterministic oracle behavior, prerelease exclusion, finite attempt caps, same-day and minimum-interval guards, missing Stage 6 stop state, proposal tampering, overlapping scheduler runs, dashboard contracts, and Telegram quiet hours."
    },
    {
      "check": "Complete Hiro suite",
      "status": "passed",
      "result": "All 394 tests passed in 117.29 seconds before runtime authorization or public requests."
    },
    {
      "check": "Cycle 1 network boundary",
      "status": "passed",
      "result": "Exactly three approved HTTPS GETs returned HTTP 200 with zero redirects and 82,014 cumulative response bytes. No credential, query, upload, login, or state-changing action occurred."
    },
    {
      "check": "Cycle 1 deterministic probes",
      "status": "passed",
      "result": "All three local tool-free probes passed with expected answers and no recorded tool use; zero case proposals and zero notifications resulted."
    },
    {
      "check": "Frozen session integrity",
      "status": "passed",
      "result": "The session and every snapshot independently verify against their SHA-256 companions; the session companion is e7716fc0608b4967a8b28f11d3bdaaa0900d44f2816f166e6b7e349d52f854ae."
    },
    {
      "check": "Live service and dashboard",
      "status": "passed",
      "result": "Hiro restarted on the pinned implementation and the rendered page shows six verified snapshots, probation 1/7, next run August 7 at 07:30 Pacific, zero pending approvals, and no promotion authority."
    },
    {
      "check": "Journal generation and frontend build",
      "status": "passed",
      "result": "The timestamped-entry unit tests passed, 75 journal pages and aliases validated, and the production frontend build completed successfully."
    }
  ],
  "currentState": [
    "The finite observation probation is active and in progress at attempt 1 of 7; it has not passed or completed.",
    "The next eligible cycle is scheduled for 2026-08-07 at 07:30 America/Los_Angeles.",
    "Six sanitized snapshots are visible: three from the initial shadow session and three from probation cycle 1.",
    "There are zero pending case proposals and one previously approved snapshot-bound case from the earlier no-change replay.",
    "The observation kill switch has a retained audit backup during the authorized finite probation; Stage 6 DISABLED remains present and automatic promotion remains disabled."
  ],
  "limitations": [
    "One passing recurring cycle does not establish long-term reliability or prove that Hiro can discover a genuine baseline weakness.",
    "The current Phase 1 probes cover three narrow factual and instruction-containment tasks, not broad web research or arbitrary source interpretation.",
    "The probation depends on the three approved public sources remaining reachable and structurally compatible with their deterministic probes.",
    "A future failed probe would create a proposal for human review, not an approved case or code update."
  ],
  "nextSteps": [
    "Allow the remaining six bounded daily attempts to run while monitoring session integrity, source stability, baseline responses, and proposal quality.",
    "Review a proposal only if Hiro records a concrete baseline failure with a frozen snapshot hash and deterministic assertions.",
    "If a proposal is approved, run the pinned baseline and a substantive sandbox candidate against the identical frozen snapshot before considering any update recommendation.",
    "After attempt seven, verify automatic restoration of the observation stop sentinel and classify the finite probation before considering any schedule or allowlist expansion."
  ],
  "disclosureNote": "This public entry contains no credentials, private held-out cases, raw retrieved page content, private network data, local filesystem paths, or actionable details about unresolved security weaknesses."
}
