Hiro development journal

The eight-hour canary is inherited policy, not useful current evidence

Historical and architectural diagnosis; no policy change Machine-readable JSON

Executive summary

The continuous governor originally authorized a 30-minute low-risk canary and a 120-minute moderate-risk canary. Commit 1d2964b on August 11 changed both classes to 480 minutes with checkpoints at 0, 60, 240, and 480 minutes while unifying interaction failures with continuous improvement.

The eight-hour value came from the older Stage 6 post-promotion probation design, where a change was already live and the system needed time to collect service availability, error-rate, latency, and at least 40 compatible observations before retention.

The current continuous engine uses the same duration before promotion while the candidate remains in an external worktree. Each checkpoint reruns a deterministic probe against that isolated worktree. Wall-clock waiting between identical probes supplies little additional evidence and blocks candidate construction and promotion throughput.

The user's expectation of faster improvement is correct: the present eight-hour pre-promotion canary is a policy carryover that no longer matches the evidence being gathered.

Work completed

Policy provenance

Confirmed
  • Git history shows the initial continuous governor used low-risk checkpoints at 0, 5, 15, and 30 minutes and a 30-minute duration.
  • The same initial policy used a 120-minute moderate-risk duration.
  • The interaction-failure unification changed both risk classes to one eight-hour schedule without adding a distinct evidence rationale for isolated pre-promotion candidates.

Old versus current canary semantics

Diagnosed
  • The older Stage 6 probation design fast-forwarded a verified change before probation and monitored the live revision for eight hours.
  • Its design called for repository identity checks, service and model availability, error and p95 latency comparisons, and at least 40 compatible observations, making elapsed time relevant.
  • The current continuous queue performs all targeted, public, held-out, invariant, category, and latency evaluation before canary, leaves the candidate outside the active branch, and reruns a stable worktree probe at scheduled times.
  • Because the candidate is not serving production traffic, the current eight-hour wait does not accumulate real user exposure or live candidate telemetry.

RSI throughput effect

Quantified
  • The governor allows only one active canary. An eight-hour minimum therefore caps theoretical promotion throughput at three changes per day before construction and evaluation time.
  • While a canary is present, the queue can investigate another idea but parks candidate construction and testing, so the wall-clock gate also slows experimentation upstream.
  • The original 30-minute low-risk policy allowed a theoretical 48 low-risk decisions per day; the original two-hour moderate policy allowed 12, before other constraints.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Git provenance passed Blame and commit inspection identified 1d2964b as the change from 30/120 minutes to 480/480 minutes and showed the exact policy diff.
Current probe semantics passed Code inspection confirmed that each continuous canary checkpoint runs the candidate worktree probe before governor promotion and records its result in the queue ledger.
Legacy probation rationale passed The Stage 6 design explicitly associates eight-hour post-promotion probation with live health, error-rate, latency, identity, and observation-count evidence.

Current state

Next steps