← Files VeraARCHIVED FILE

modules/bandi-agevolazioni/skills/bandi-agevolazioni/references/acceptance-matrix.md

7.3 KB · Oct 4, 2026 · 12:28 UTC

↓ Download file

# Intelligence acceptance matrix

| Public behavior | Required evidence | Gate |
| --- | --- | --- |
| Single-client and portfolio radar scopes remain distinct | Second-profile rejection and portfolio multi-profile tests | Required |
| Portfolio profiles remain opaque and matches cannot cross client facets | Schema and negative reference tests | Required |
| Document-observed profile facets close to same-client receipted evidence | Missing and cross-client evidence negative tests | Required |
| Radar workspace is explicitly authorized, path-bound, private and outside Git/published roots | Missing-confirmation, path-binding and prohibited-root tests | Required |
| Source-plan coverage measures checks, not discovery probability | Exact ratio, failed/unavailable, and disclosure tests | Required |
| Pending plan entries never inflate reviewed-plan coverage and rejected entries are separately excluded | Proposed/returned/rejected denominator tests | Required |
| Semantic source selection never becomes a universal deterministic map | Skill/reference inspection and representative source-plan review | Required |
| Every scan binds every exact query territory and category to a model-led, professionally reviewed covered-or-gap claim | Cross-territory claim-closure, missing-review and rendered-worklist tests | Required |
| A rejected source outside the reviewed query-scoped selection cannot deadlock later complete scans | Veneto-rejected/Lazio-selected end-to-end scan test | Required |
| Recent discovery executes the reviewed priority-source registry before semantic web search | Worklist ordering and early-semantic-search rejection tests | Required |
| A temporal scan cannot claim complete with failed, unavailable, missing or unreviewed priority sources | Coverage-gate and explicit-unverified-source report tests | Required |
| Attempted failed or unavailable source checks report partial rather than not-started coverage | Attempted-failure status regression test | Required |
| Coverage evidence states checked sources, requested window, last verification and semantic-web posture | Rendered-report assertions | Required |
| Source cursors persist across zero-result scans without replacing the requested historical window | Multi-scan cursor test | Required |
| DGR, DDR, BUR, annex, FAQ and amendment families remain reviewed metadata, not deterministic authority rules | Schema, skill and deterministic-boundary inspection | Required |
| Announced, approved, published, future, open, expiring, extended, modified and closed observations are source-backed proposals | Lifecycle contract tests and professional review | Required |
| Opportunity status history is time-aware and append-only after confirmation | Lifecycle extension and rewrite rejection tests | Required |
| Formal amendments revise confirmed dates through append-only events and invalidate dependent matches | Deadline-amendment and stale-match tests | Required |
| Monitoring is resumable and completed scans are immutable | Running-to-complete and rewrite rejection tests | Required |
| Economic net ranges reproduce exact supplied assumptions | Valid and contradictory range tests | Required |
| Handoff requires fresh confirmed evidence, checked sources, check results, profile, opportunity and match | Pre-review and post-check-change rejection tests | Required |
| Handoff is strict, selected-client-only and independently verifiable on import | Malformed-object, hash-tamper, cross-client and registration tests | Required |
| Radar never contacts clients or claims eligibility | Report, skill and handoff limitation assertions | Required |
| Packet is bounded and state-aware | Tests across intake, sources, requirements, evidence, assessments, costs, forms, narratives, consistency, issues, and authority simulation | Required |
| Task packets include only permitted collections and exact reference closure, with no first-N truncation | Per-task projection, reverse/forward reference, inventory and over-limit failure tests | Required |
| Insufficient task context stops without substantive recommendations and requests a fresh explicit expansion | Strict output-contract positive and negative tests | Required |
| An over-limit global collection can be rerun from exact professional-selected IDs without truncating or narrowing other required collections | Representative 501-item failure plus exact-ID drilldown success | Required |
| Stage B model-session references cannot be reused across contributions | Packet, record, retry and duplicate-session tests | Required |
| Radar evidence mapping is client-isolated and public discovery plus portfolio matching use separate session references | Cross-client and bidirectional mapping-to-public-session reuse negative tests | Required |
| Unmistakable credentials are blocked without treating names or tax identifiers as secrets | Credential-pattern true-positive and professional-identifier false-positive tests | Required |
| Intake applicant object and local paths are not copied by default, while possible identity in relevant facts/excerpts and absence of automatic anonymization are disclosed | Packet inspection tests and privacy review | Required |
| Evidence cannot escape its packet | Unknown-reference negative tests | Required |
| Model output has no authority on record | Workbench byte-equivalence before decision | Required |
| Exact model provenance is retained | Schema and public workflow tests | Required |
| Repeating an exact record request does not create a second run | Stable idempotency-key retry and conflict tests | Required |
| Acceptance requires explicit professional confirmation | Missing-confirmation negative test | Required |
| Accepted content remains proposed | Normalization and application tests for every collection family | Required |
| Confirmed or blocked work cannot be overwritten | Update negative tests | Required |
| Changed inputs invalidate undecided intelligence | Intake, source, and workbench stale tests | Required |
| Interrupted acceptance is resumable and non-duplicating | `APPLYING` recovery tests | Required |
| Protected field values remain empty; final submission needs separate approval | Contract and final-validator negative tests | Required |
| Validation cannot pass during partial application | `APPLYING` audit test | Required |
| Dossier discloses model contribution and decision state | Markdown, manifest, and hash assertions | Required |
| Structural evaluation passes | `intelligence_quality_cases.json` at 100% | Required |
| Semantic quality is acceptable | Qualified-professional representative evaluation; thresholds approved before broad rollout | Pilot blocker, not claimed by offline suite |
| Radar relevance and timeliness are acceptable | Professional gold cases across territories and issuer families; missed-opportunity, false-match, override, timeliness and estimate-calibration measures | Pilot blocker, not claimed by offline suite |

## Release quality gates

Run the component tests, filesystem/privacy tests, plugin packaging tests, static
format/type/security checks applicable to changed files, drift verification,
and package rebuild. A release must retain `ready_to_file=false`, only approved
portal preparation and separately authorized final submission, no authentication,
declaration acceptance, signature, payment, secrets or credentials, and an explicit disclosure that structural
evaluation does not establish legal accuracy.

SHA-256: 1a3e105a8a83aabe98c6189028e2e598a12784d35ea07afcec38c64dfb96e1fa