# Intelligence acceptance matrix

| Public behavior | Required evidence | Gate |
| --- | --- | --- |
| Single-client and portfolio radar scopes remain distinct | Second-profile rejection and portfolio multi-profile tests | Required |
| Portfolio profiles remain opaque and matches cannot cross client facets | Schema and negative reference tests | Required |
| Document-observed profile facets close to same-client receipted evidence | Missing and cross-client evidence negative tests | Required |
| Radar workspace is explicitly authorized, path-bound, private and outside Git/published roots | Missing-confirmation, path-binding and prohibited-root tests | Required |
| Source-plan coverage measures checks, not discovery probability | Exact ratio, failed/unavailable, and disclosure tests | Required |
| Pending plan entries never inflate reviewed-plan coverage and rejected entries are separately excluded | Proposed/returned/rejected denominator tests | Required |
| Semantic source selection never becomes a universal deterministic map | Skill/reference inspection and representative source-plan review | Required |
| Every scan binds every exact query territory and category to a model-led, professionally reviewed covered-or-gap claim | Cross-territory claim-closure, missing-review and rendered-worklist tests | Required |
| A rejected source outside the reviewed query-scoped selection cannot deadlock later complete scans | Veneto-rejected/Lazio-selected end-to-end scan test | Required |
| Recent discovery executes the reviewed priority-source registry before semantic web search | Worklist ordering and early-semantic-search rejection tests | Required |
| A temporal scan cannot claim complete with failed, unavailable, missing or unreviewed priority sources | Coverage-gate and explicit-unverified-source report tests | Required |
| Attempted failed or unavailable source checks report partial rather than not-started coverage | Attempted-failure status regression test | Required |
| Coverage evidence states checked sources, requested window, last verification and semantic-web posture | Rendered-report assertions | Required |
| Source cursors persist across zero-result scans without replacing the requested historical window | Multi-scan cursor test | Required |
| DGR, DDR, BUR, annex, FAQ and amendment families remain reviewed metadata, not deterministic authority rules | Schema, skill and deterministic-boundary inspection | Required |
| Announced, approved, published, future, open, expiring, extended, modified and closed observations are source-backed proposals | Lifecycle contract tests and professional review | Required |
| Opportunity status history is time-aware and append-only after confirmation | Lifecycle extension and rewrite rejection tests | Required |
| Formal amendments revise confirmed dates through append-only events and invalidate dependent matches | Deadline-amendment and stale-match tests | Required |
| Monitoring is resumable and completed scans are immutable | Running-to-complete and rewrite rejection tests | Required |
| Economic net ranges reproduce exact supplied assumptions | Valid and contradictory range tests | Required |
| Handoff requires fresh confirmed evidence, checked sources, check results, profile, opportunity and match | Pre-review and post-check-change rejection tests | Required |
| Handoff is strict, selected-client-only and independently verifiable on import | Malformed-object, hash-tamper, cross-client and registration tests | Required |
| Radar never contacts clients or claims eligibility | Report, skill and handoff limitation assertions | Required |
| Packet is bounded and state-aware | Tests across intake, sources, requirements, evidence, assessments, costs, forms, narratives, consistency, issues, and authority simulation | Required |
| Task packets include only permitted collections and exact reference closure, with no first-N truncation | Per-task projection, reverse/forward reference, inventory and over-limit failure tests | Required |
| Insufficient task context stops without substantive recommendations and requests a fresh explicit expansion | Strict output-contract positive and negative tests | Required |
| An over-limit global collection can be rerun from exact professional-selected IDs without truncating or narrowing other required collections | Representative 501-item failure plus exact-ID drilldown success | Required |
| Stage B model-session references cannot be reused across contributions | Packet, record, retry and duplicate-session tests | Required |
| Radar evidence mapping is client-isolated and public discovery plus portfolio matching use separate session references | Cross-client and bidirectional mapping-to-public-session reuse negative tests | Required |
| Unmistakable credentials are blocked without treating names or tax identifiers as secrets | Credential-pattern true-positive and professional-identifier false-positive tests | Required |
| Intake applicant object and local paths are not copied by default, while possible identity in relevant facts/excerpts and absence of automatic anonymization are disclosed | Packet inspection tests and privacy review | Required |
| Evidence cannot escape its packet | Unknown-reference negative tests | Required |
| Model output has no authority on record | Workbench byte-equivalence before decision | Required |
| Exact model provenance is retained | Schema and public workflow tests | Required |
| Repeating an exact record request does not create a second run | Stable idempotency-key retry and conflict tests | Required |
| Acceptance requires explicit professional confirmation | Missing-confirmation negative test | Required |
| Accepted content remains proposed | Normalization and application tests for every collection family | Required |
| Confirmed or blocked work cannot be overwritten | Update negative tests | Required |
| Changed inputs invalidate undecided intelligence | Intake, source, and workbench stale tests | Required |
| Interrupted acceptance is resumable and non-duplicating | `APPLYING` recovery tests | Required |
| Protected field values remain empty; final submission needs separate approval | Contract and final-validator negative tests | Required |
| Validation cannot pass during partial application | `APPLYING` audit test | Required |
| Dossier discloses model contribution and decision state | Markdown, manifest, and hash assertions | Required |
| Structural evaluation passes | `intelligence_quality_cases.json` at 100% | Required |
| Semantic quality is acceptable | Qualified-professional representative evaluation; thresholds approved before broad rollout | Pilot blocker, not claimed by offline suite |
| Radar relevance and timeliness are acceptable | Professional gold cases across territories and issuer families; missed-opportunity, false-match, override, timeliness and estimate-calibration measures | Pilot blocker, not claimed by offline suite |

## Release quality gates

Run the component tests, filesystem/privacy tests, plugin packaging tests, static
format/type/security checks applicable to changed files, drift verification,
and package rebuild. A release must retain `ready_to_file=false`, only approved
portal preparation and separately authorized final submission, no authentication,
declaration acceptance, signature, payment, secrets or credentials, and an explicit disclosure that structural
evaluation does not establish legal accuracy.
