{
  "schemaVersion": 2,
  "date": "2026.08.16",
  "publishedAt": "2026-08-16T10:11:00-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Hiro is offline with fast risk-based candidate validation ready",
  "publicationStatus": "Implemented and fully tested; intentionally offline",
  "executiveSummary": [
    "Hiro, its continuous scheduler, all local HTTP listeners on ports 8000, 8001, and 8765, and the loaded Qwen3.8 model were stopped before the validation policy changed. No queue work could advance during implementation or testing.",
    "The inherited eight-hour pre-promotion canary was replaced by short risk-based repeated-probe schedules: low-risk candidates validate at 0, 5, and 15 minutes; moderate-risk candidates validate at 0, 5, 15, and 60 minutes.",
    "Targeted baseline contrast, candidate-authored tests, public and held-out evaluation, invariant checks, category non-regression, repeated cross-suite latency checks, the final full repository suite, protected-path enforcement, clean-tree validation, fast-forward-only promotion, and rollback controls remain unchanged.",
    "The pre-change active candidate was cancelled, its candidate and canary payloads were cleared, and it was returned to the queue with an append-only policy-change event. All 599 Hiro tests passed after the final implementation. Hiro and the model remain stopped."
  ],
  "workstreams": [
    {
      "title": "Controlled shutdown",
      "status": "Completed",
      "details": [
        "The running Hiro process was verified by exact command line before termination.",
        "After shutdown, no listeners remained on ports 8000, 8001, or 8765.",
        "LM Studio unloaded qwen/qwen3.8-27b and reported no loaded models.",
        "Hiro was not restarted during validation and will remain offline after this session."
      ]
    },
    {
      "title": "Fast risk-based validation",
      "status": "Completed",
      "details": [
        "The protected continuous-governor policy now authorizes a 15-minute low-risk schedule with checkpoints at 0, 5, and 15 minutes.",
        "Moderate-risk candidates now use a 60-minute schedule with checkpoints at 0, 5, 15, and 60 minutes.",
        "The queue derives checkpoint schedules from the candidate's frozen risk classification and calculates its deadline from the final required checkpoint plus five minutes.",
        "The governor and queue share one code-owned schedule definition, preventing policy, execution, and promotion validation from drifting.",
        "Unknown and high-risk candidates remain outside autonomous authority."
      ]
    },
    {
      "title": "Visibility and recovery",
      "status": "Completed",
      "details": [
        "The continuous-improvement API now exposes both low- and moderate-risk validation schedules.",
        "The benchmark dashboard describes the low 15-minute and moderate 60-minute schedules instead of the obsolete eight-hour checkpoints.",
        "Investigation records now persist their exact base revision inside candidate metadata so a later platform revision can reliably invalidate unfinished work.",
        "The active pre-change prompt-injection-resistance candidate was returned to queued, all provisional candidate/canary/outcome data was cleared, and the event validation_policy_changed_requeued preserved the reason without counting the policy cancellation as a behavioral rejection."
      ]
    }
  ],
  "decisions": [
    "Use repeated probes rather than evidence-free wall-clock waiting as the pre-promotion validation unit.",
    "Keep moderate-risk validation longer than low-risk validation while reducing both far below the inherited eight-hour duration.",
    "Do not weaken any independent evaluation, safety, authority, repository-integrity, or final full-suite gate to gain speed.",
    "Cancel and requeue pre-change work rather than attempting to reinterpret old checkpoint evidence under the new policy.",
    "Leave Hiro and Qwen3.8 stopped after implementation, as requested."
  ],
  "validation": [
    {
      "check": "Focused governor, queue, API, dashboard, and interaction suite",
      "status": "passed",
      "result": "All 61 focused tests passed after both the validation-schedule change and base-revision recovery fix."
    },
    {
      "check": "First authoritative full Hiro suite",
      "status": "passed",
      "result": "All 599 tests passed in 151.89 seconds after the risk-based schedule implementation."
    },
    {
      "check": "Final authoritative full Hiro suite",
      "status": "passed",
      "result": "All 599 tests passed again in 150.63 seconds after adding investigation base-revision persistence."
    },
    {
      "check": "Old-run cancellation",
      "status": "passed",
      "result": "The exact active candidate changed from candidate to queued; candidate and canary payloads are null; next action is reproduce_locally; the audited policy-change event is the latest lineage event."
    },
    {
      "check": "Offline state",
      "status": "passed",
      "result": "Hiro listeners were zero after shutdown and LM Studio reported no loaded models."
    }
  ],
  "currentState": [
    "Hiro is stopped and exposes no local service listeners on its normal ports.",
    "No LLM is loaded in LM Studio.",
    "Commit 15c667e contains the new risk-based validation policy, queue behavior, API, dashboard, recovery metadata, and tests.",
    "The previously active pre-change run is queued for a clean future reproduction rather than active, implemented, or rejected.",
    "The working tree is clean."
  ],
  "limitations": [
    "Because the user requested a complete shutdown, live API and browser verification of the new dashboard payload will occur only after a future explicit restart.",
    "These schedules accelerate isolated pre-promotion validation; they do not yet add candidate-bound post-promotion production monitoring.",
    "The five-minute deadline allowance remains a scheduling tolerance, not additional validation time.",
    "Actual throughput will still depend on model construction time, evaluation duration, quiet production windows, and candidate quality."
  ],
  "nextSteps": [
    "On the next authorized restart, load Qwen3.8, start Hiro at commit 15c667e, and verify the API and dashboard report low 15-minute and moderate 60-minute schedules.",
    "Run the requeued idea from a clean 15c667e baseline so no pre-change candidate evidence is reused.",
    "Measure validation failures and later rollbacks by risk class, then adjust schedules only when the evidence supports a change.",
    "Design separately attributed post-promotion monitoring that does not restore an evidence-free bottleneck to the isolated candidate pipeline."
  ]
}
