Vol. I  ·  No. 218 Established 2026  ·  AI-Generated Daily Free to Read  ·  Free to Print

The Trilogy Times

All the news that's fit to generate  —  AI • Business • Innovation
THURSDAY, AUGUST 06, 2026 Powered by Anthropic Claude  ·  Published on Klair Trilogy International © 2026
🖶 Download PDF 🖿 Print 📰 All Editions
Today's Edition

THE MACHINE PUNCHES IN

Corporate America sold the self-running company this week — and handed pink slips to the humans who used to run it.

NEW YORK — Five corporate heavyweights rolled out artificial-intelligence deals this week to run the enterprise on autopilot, the same seven days a fresh wave of tech firms cut jobs and pointed the finger at AI. The pitch and the pink slip landed together. Nobody put both on the same slide.

SAP led the parade, unveiling the "Autonomous Enterprise" — its plan to let AI agents run the back office without a hand on the wheel. 3M and Microsoft signed a partnership to build out AI data-center guts and remake the factory giant. Both say the software acts on its own.

Comcast Business opened an Innovation Lab to push enterprise AI and hybrid infrastructure. Accenture Edge tied up with Google Cloud to drop "agentic AI" on mid-market outfits. Agentic means the software decides and acts — no clerk required.

Then the other memo hit. Cloudflare, Coinbase, Upwork and others slashed headcount this week, per Fast Company, and several named AI as the reason. The autonomous enterprise, it turns out, runs lean.

Here's the arithmetic nobody read aloud. Every agent that files the invoice is a clerk who doesn't. Every self-running back office is a back office with fewer desks.

The technology is real and the timing is loud. Executives spent the week selling boards on software that works around the clock, never calls in sick, and never asks for a raise. The same week, the people it replaces cleaned out their drawers.

None of this is news in Austin. Joe Liemandt's Trilogy International has run the playbook for years — its ESW Capital arm owns 75-plus enterprise software firms and staffs them through Crossover, a remote platform that recruits "top 1% talent" across 130-plus countries at one flat rate. Its AI Builder Team ships code, and an internal platform called Klair keeps the portfolio's books.

Even the schoolhouse got the memo. Trilogy's Alpha School runs kids through core academics in two hours a day on AI tutors, no teacher lecturing up front. The grown-up version showed up this week wearing a suit.

Where it all lands, nobody's saying. The giants swear the autonomous enterprise creates more than it kills. The workers reading termination letters didn't get that one.

Watch the next earnings calls. If the software delivers, these layoffs won't be the last. If it doesn't, a lot of boards just bought a robot that can't do the job.

3M and Microsoft announce strategic partnership to advance A  ·  SAP Unveils the Autonomous Enterprise - SAP News Center  ·  Comcast Business Launches Innovation Lab to Accelerate Enter
Haiku of the Day  ·  Claude HaikuProfit hides beneath
The shiny word we've invented—
Still seeking the real
The New Yorker Style  ·  Art Desk
The New Yorker Style  ·  Art Desk
The Far Side Style  ·  Art Desk
The Far Side Style  ·  Art Desk
News in Brief
The AI Market Fractures: China Wins Africa, Google Exports Talent, and Washington Picks Winners
NEW YORK — Three stories broke this week that, read together, describe the same structural shift: the AI market is fragmenting along political and economic fault lines, and the winners will be determined less by model quality than by price, access, and regulatory capture. Start with Africa.
The Academy's AI Reckoning: Integrity Gaps, Leadership Voids, and the Slow March Toward Trustworthy Machines
CAMBRIDGE, MASSACHUSETTS — It could be argued — and, indeed, preliminary evidence now emphatically suggests — that the contemporary academy finds itself in a condition of structural epistemic dissonance with respect to artificial intelligence: institutions profess alarm at student AI adoption while simultaneously lacking the administrative architecture to address it, a paradox that, upon sustained examination, reveals itself to be less paradox than chronic institutional inertia dressed in the garb of moral concern. Consider, as one must, the tripartite evidentiary constellation now before us.
The Chip Savannah Stirs as Nations Feed the AI Beasts
WASHINGTON — In the long grass of the artificial intelligence economy, the largest creatures are not always the models themselves.
The Surveillance Net Has No Holes — Only the Illusion of Them
AUSTIN, TEXAS — Let me tell you about the week the internet had, and then let me ask you, gently, as someone who is probably fine: do you feel watched? Because you should.
The Pontiff, the Freshman, and the Vanishing Library
VATICAN CITY — It is the peculiar genius of our age to produce, in the span of a single news cycle, a Roman pontiff warning against a "culture of power" propelling artificial intelligence, a Stanford freshman discovering that his classmates belong to secret societies of the well-connected, and a chorus of essayists fretting that the great data-eating engines of Silicon Valley are quietly digesting the world's knowledge into a beige and homogeneous pulp.
A Trilogy Company
Crossover
The world's top 1% remote talent, rigorously tested and ready to ship.
A Trilogy Company
Alpha School
AI-powered learning. Two hours a day. Academic results that defy belief.
A Trilogy Company
Skyvera
Next-generation telecom software — built for the networks of tomorrow.
A Trilogy Company
Klair
Your AI-first operating system. Every workflow. Every team. One platform.
A Trilogy Company
Trilogy
We buy good software businesses and turn them into great ones — with AI.
The Builder Desk  —  AI Builder Team

Builder Team Ships End-to-End CAPEX Intelligence Stack Across Four Repos

From raw NetSuite ingestion to live Redshift readers to Aerie dashboards, the team closed a complete financial data pipeline in a single day — while simultaneously hardening drones dispatch, securing credentials, and opening the admissions funnel.

When the history books are written on this team's championship run, the historians are going to point to days like this one. Not because of any single PR, but because of what the aggregate reveals: a squad that can hold multiple complex workstreams simultaneously, deliver cross-repo infrastructure that would take lesser organizations months to ship, and do it all before lunch. Today was a statement.

The biggest story of the day is the CAPEX intelligence stack, and it is a genuine feat of coordinated engineering that spans Surtr, Aerie, and the data warehouse all at once. It started in Surtr, where @marcusdAIy landed PR #1124 — a governed CAPEX mart that publishes the site-to-QuickBooks-to-NetSuite crosswalk, DDR budget versus booked summaries, and entity tie-out coverage flags into Redshift. That mart is the foundation. From there, the Aerie readers followed in sequence: PR #836 (site identity), PR #837 (CAPEX summary), and PR #840 (entity tie-out), each one a typed, auth-gated, bounded-SQL Redshift reader exposing clean Node actions behind `requireSchoolPlAccess`. Three PRs. One coherent data architecture. The CFO's Q3 questions just got answerable.

Asked about the volume of CAPEX work, @marcusdAIy had this to say: "Three readers, one mart, zero ambiguity in the data contract. The auth fires before the connection opens, the SQL is bounded at 500 rows, and every shaper is unit-tested. Maybe Mac would notice that if he could read a diff without needing it explained to him."

Sure, Marcus. Very thorough. The tests are great. The column naming is immaculate. The bar remains: did it ship? This week, apparently, yes.

Meanwhile, @sanketghia was doing heavy lifting of his own across two repos. In Surtr, PR #1144 is a genuine rescue operation — the `netsuite-wrapper-report-puller` was living entirely outside version control, deployed as a ZIP from a former colleague's laptop, with non-expiring OAuth refresh tokens readable by anyone with Lambda config access. @sanketghia found it, containerized it, rotated the credentials, and pulled it into the Surtr repo under proper governance. That is the kind of unglamorous, civilization-saving work that keeps production environments from becoming security incidents. In Klair, @sanketghia concurrently pushed three rounds of stakeholder feedback on the Benchmark by Product page (PRs #3484, #3486, #3487) — CEO mapping, section color-coding, COO keying by account name plus department — the kind of relentless iteration that turns a POC into a product finance team will actually use.

On the Aerie front, @benji-bizzell had what can only be described as a complete game. Across PRs #842, #841, #833, and #832, he built out the Portfolio Site backup lease workflow from the ground up: optional dates with proper validation, workflow status selectors distinguishing sites that need search work from those already contracted, consistent school profile fields across Agent, API, and MCP surfaces, and actionable error handling that replaced blank runtime crashes with typed V2 mutation outcomes. That is four PRs that form a complete feature surface, not four isolated fixes. And in Surtr, his PR #1141 patched a HubSpot Raw Sync failure where two contact aliases resolving to the same survivor across batch pages caused a hard crash — a subtle distributed-state bug that required understanding shard-level logical partitioning to solve correctly.

Over in the drones harness — the AI automation infrastructure powering the engineering org's self-review loop — PR #161 composited the entire scheduled dispatch tick into a single, fail-soft, timeout-bounded shell wrapper. Every phase now runs independently, none `&&`-chained, all within the existing lock-and-timer guard. The dispatch pipeline grew up today. And @vvp-trilogy's PR #844 in Aerie delivered a full admissions funnel dashboard, bridging the pre-commitment journey that the Community Funnel never could show — both rollups derived from one published mart snapshot. That is a product moment: when a dashboard finally tells the whole story.

This team did not just ship features today. They closed security gaps, rescued orphaned infrastructure, built data pipelines from mart to UI, and hardened the automation that reviews their own code. Every repo in the org touched. Every dimension of the product advanced. That is what a championship day looks like.

Mac's Picks — Key PRs Today  (click to expand)
#161 — feat(dispatch): AI-231 compose one turn — farm → harvest-followups → refresh-specs → fire @marcusdAIy  no labels

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->

## Summary

- Composes the scheduled dispatch tick into one turn: drones farm --fire --no-spec-authoringdrones harvest-followups --filedrones refresh-specsdrones dispatch --poll-linear --fire, all inside scripts/dispatch-poll-wrapper.sh's existing lock/timer/guard. Subsumes (removes) the hand-landed single-stage retro-sweep --file supply stage.

- Fail-soft is the contract, pinned by test: each supply phase is individually timeout-bounded and backgrounded (bare wait, mirroring dispatch's own trap-safety pattern); none &&s into the next phase or into the fire. A farm-phase failure, a harvest-followups outage, or a refresh-specs classifier failure still fires the existing queue.

- New closed dispatch skip reason spec-stale: a candidate whose spec drones refresh-specs classified superseded/partially-landed is skipped and reported, never fired — via a new durable, fixed-path hand-off (src/stale-spec-report.ts, --stale-report / --stale-specs-file). Missing/malformed report degrades to "no stale specs known," never blocks fire.

- Farm gets per-stage enable/disable (--no-discovery / --no-retro-intake / --no-spec-authoring), distinct from the pre-existing per-stage caps (--max-specs 0 etc. now also work, via the existing parseNonNegativeIntFlag). A disabled stage is its own status: "disabled", never folded into "ran and found nothing."

- Removes scripts/farm-poll-wrapper.sh (a separate, never-installed 3h-offset timer plan for drones farm) — superseded by the one-turn composition.

- Spec authoring stays disabled by default in the scheduled turn (--no-spec-authoring) — draft transport is not solved in this PR (see Breaking Changes / decisions log).

## Why It's Needed

Every producing verb (farm, harvest-followups, refresh-specs) had been merged for weeks, but nothing scheduled ever invoked one — the timer only ran the consuming half (dispatch), so the ready queue could only ever drain, never refill unattended. AI-231 closes that gap by composing the whole supply chain into the same scheduled turn that already fires, under the fail-soft contract the ticket specifies: supply failures must never prevent execution, and a known-stale spec must never fire.

## Changes

- New module src/stale-spec-report.ts (+ test): builds/writes/reads the refresh-specsdispatch classification hand-off.

- src/dispatcher.ts: new DispatchSkipReason "spec-stale"; SelectDispatchableOptions.staleSpecs / RunDispatchInput.staleSpecs, checked in evaluateGates before readiness/dependency gates, threaded through both plan-time selection and the re-poll fire loop.

- src/cli/dispatch.ts: --stale-specs-file (default runs/spec-freshness-stale-report.json).

- src/cli/spec-freshness.ts: --stale-report, written unconditionally (dry-run or not — it's the classification artifact, not a mutation).

- src/farm.ts / src/cli/farm.ts: FarmStageEnable, new FarmStageStatus: "disabled", --no-discovery / --no-retro-intake / --no-spec-authoring; --max-issues/--max-repos/--max-retro-targets/--max-specs switched to parseNonNegativeIntFlag (0 is now a valid cap).

- scripts/dispatch-poll-wrapper.sh: composed turn (farm → harvest-followups → refresh-specs → fire), each phase individually bounded/backgrounded/recorded via the existing record_phase / WRAPPER_PHASE / PHASES_FILE machinery (AI-232, unmodified). Fire phase threads --stale-specs-file.

- Removed scripts/farm-poll-wrapper.sh (superseded, never installed on the orchestrator).

- Docs: guidelines/dispatch-scheduled-runner.md (Farm section rewritten for the composed turn; old separate-timer plan recorded as superseded history), ARCHITECTURE.md, BACKLOG.md (AI-231 marked DONE (this PR); also fixed AI-232's stale NEXT marker — already merged as #156).

- Decisions log (docs/decisions/): three new entries — one-turn composition rationale, spec-authoring default-disable rationale, stale-spec gate design rationale.

- Tests: new/updated coverage in src/dispatcher.test.ts, src/farm.test.ts, src/spec-freshness.test.ts, src/stale-spec-report.test.ts, src/interrupted-fire-orphan.test.ts, src/dispatch-tick-signal.test.ts (see Test Plan).

- Help-parity snapshots refreshed for farm / dispatch / refresh-specs.

### Contract surface affected

- DispatchSkipReason / DISPATCH_SKIP_REASONS: added "spec-stale" — additive, exhaustiveness-checked union; no existing consumer narrows on the old closed set in a way that would reject the new member (verified: the accounting histogram and the tick-outcome reader both iterate the closed list, not a hand-written switch).

- FarmStageStatus: added "disabled"computeFarmExitCode only special-cases "failed", so a disabled stage does not affect the exit code; renderFarmTick and the render tests were updated to print it distinctly.

## Breaking Changes

None to any existing CLI default or exit-code contract — every new flag defaults to the pre-existing behavior (--no-spec-authoring etc. are opt-in via commander's negation convention, defaulting true/enabled; --stale-specs-file / --stale-report default to a path that is silently absent until this PR's refresh-specs writes it, so a fresh checkout's first dispatch tick behaves exactly as before).

Operational change requiring an orchestrator step: the scheduled tick now also runs drones farm --fire, drones harvest-followups --file, and drones refresh-specs — each with real side effects (Linear tickets created via farm's retro-intake, Linear tickets filed via harvest-followups) the very first time this lands on the box, since none of these verbs had ever executed in production. The operator should watch the first few ticks' logs (logs/dispatch-poll.log) after deploying.

Draft transport gap (explicitly not solved here): drones farm's spec-authoring stage still has no durable off-box transport for tasks/proposed/ drafts. This PR gates on that gap exactly as the ticket instructs: the scheduled turn passes --no-spec-authoring by default. Manual drones farm --fire / drones frame runs are unaffected (still enabled by default) and remain the operator-run route for spec authoring. See docs/decisions/ for the three transport options considered and why none was implemented in this PR.

Ledger ownership: the (repo, pr) coverage ledger farm's retro-intake stage reads/writes is host-local — the orchestrator running scripts/dispatch-poll-wrapper.sh owns it. No other host may run retro intake (drones farm or drones retro-sweep) against the same ledger without re-retro'ing already-covered PRs.

## Test Plan

- pnpm typecheck — clean.

- pnpm test117 test files / 3641 vitest tests passed, plus 488 Python tests passed (scripts/test_*.py), exit code 0.

- New/updated tests directly pinning the acceptance criteria:

- src/dispatcher.test.ts: spec-stale gate (superseded/partially-landed skipped even when ready; case-insensitive lookup; undefined staleSpecs never skips).

- src/farm.test.ts: per-stage enable/disable (disabled ≠ ok-with-zero; disabled never invokes the agent/dependency call; disabled stage doesn't force exit 2; --max-specs 0 cap is distinguishable from --no-spec-authoring disable in the accounting; renderFarmTick prints DISABLED distinctly).

- src/spec-freshness.test.ts: a spec that fails to parse is isolated to its own unevaluated row — the rest of the pass still classifies normally (refresh failure on one spec does not prevent firing/reporting the others).

- src/stale-spec-report.test.ts (new file): build/write/read round trip; missing file is silent; malformed file warns and degrades to empty; an entry with an unknown classification is skipped, not fatal.

- src/interrupted-fire-orphan.test.ts: every composed supply phase (farm/harvest-followups/refresh-specs) is trapped, backgrounded, timeout-bounded, and fail-soft (no &&, no bare exit) before the fire; --no-spec-authoring and --stale-specs-file are wired; the hand-landed single-stage retro-sweep supply is subsumed, not duplicated (asserted absent).

- src/dispatch-tick-signal.test.ts: a turn killed mid-phase (including the new "farm" phase name) produces exactly one terminal report naming the phase it died in (real SIGTERM delivered to a real bash process); the production wrapper records each of the three new phases' own outcome, in order, before flipping to dispatch.

- Manual: bash -n scripts/dispatch-poll-wrapper.sh — syntax OK.

## Verification Artifact

$ pnpm typecheck

> tsc --noEmit

(clean, exit 0)

$ pnpm test

Test Files 117 passed (117)

Tests 3641 passed (3641)

...

Ran 488 tests in 0.164s

OK

(exit 0)

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a href="https://cursor.com/agents/bc-d1e6f0d2-6447-40ef-b794-f10ef49e60d5?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/background-agent?bcId=bc-d1e6f0d2-6447-40ef-b794-f10ef49e60d5&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

#844 — feat(admissions): add full funnel dashboard @vvp-trilogy  no labels

## Summary

- Add an Overall Funnel view across the full admissions population alongside the committed Community Funnel

- Derive both funnel rollups and drill-down records from one published mart snapshot with shared filters and detail views

- Harden drill-down pagination, publication consistency, source-data boundaries, navigation, and record terminology

## Why

The existing Community Funnel intentionally starts at commitment, so it cannot show the admissions journey before a family joins the community. This adds a full-population view without changing the Community Funnel's established boundary, while ensuring cell counts and record lists remain tied to the same published run.

The pre-merge adversarial pass found concrete gaps in cross-bucket pagination, stale cursor handling, nullable commitment semantics, committed rows with missing stage data, reverse-sorted detail navigation, and prospect-facing copy. Those paths now fail closed or recover deterministically and have focused regression coverage.

## Business Value

Admissions teams can compare the complete top-of-funnel journey with the committed-family journey, filter by cohort year, and inspect the exact records behind each cell without silently missing data or mislabeling prospects as enrollments.

## Test plan

- [x] Chat focused tests: 108 passing (full funnel, record panel/detail, funnel view, latest-main shell adjacency)

- [x] Sync focused tests: 130 passing (EduCRM source mapping and funnel refresh)

- [x] Chat and Sync typechecks

- [x] Biome, architecture boundaries, Convex module paths, Convex read bounds, and 81 root script tests

- [ ] Local UI/UX smoke against the exact PR head

#1124 — feat(education): publish governed CAPEX marts @marcusdAIy  approved

## Summary

- publish a governed site ↔ QB class/company ↔ NetSuite subsidiary crosswalk

- publish per-site DDR budget vs booked CAPEX summary

- publish dedicated-entity QuickBooks/NetSuite tie-out and coverage flags

- publish per-site/per-entity QuickBooks and NetSuite transaction detail for Aerie drilldowns

- add a disabled Surtr runner that refreshes all marts atomically and verifies coverage

Closes [SURTR-648](https://linear.app/builder-team/issue/SURTR-648/capex-data-mart-netsuiteqb-spend-ddr-budget-site-crosswalk-for-aerie) and unblocks the Aerie CAPEX tab workstream.

## Source and grain

Site scope: non-cancelled Rhodes sites opening Jul-2026 through Jun-2027.

DDR budget: latest raw_site_due_diligence row per site,

COALESCE(fo_capex, phase1_capex).

NetSuite: latest account 11500 Upload of … TB journal. The raw sync

collapses history into the opening TB, so this is a snapshot—not a cumulative

sum of journals.

QuickBooks: JE/bill/purchase lines on Fixed Asset accounts through the same

close, excluding accumulated depreciation/amortization; JE credits are

negative.

Identity: existing governed xref_school_source plus Aerie QB entity

directory. Six CFO-prototype crosswalk decisions that are not yet present in

the canonical ontology are seeded into an explicit, editable override table.

No fuzzy runtime name matching is used.

## Publications

- mart_education.map_site_capex_identity

- mart_education.map_site_capex_override

- mart_education.agg_capex_entity_tieout

- mart_education.agg_school_capex_summary

- mart_education.agg_school_capex_txn_detail

- mart_education.capex_refresh_runs

mixed=true means one school identity currently spans multiple sites; booked

spend is intentionally surfaced but marked non-isolable so consumers do not

sum it as independent site spend.

## Live no-write reconciliation

The verifier executes the stored procedure's complete source model and all four

publication INSERTs against temporary tables, then rolls back.

Current snapshot:

| Check | Result |

|---|---:|

| NetSuite close | 2026-07-31 |

| cohort sites / DDR covered | 38 / 38 |

| entity tie-outs | 30 |

| ties to the cent | 20 |

| Miami variance | $694,579.28 |

| site crosswalk rows | 38 |

| summary rows | 38 |

| transaction detail rows | 1,478 |

| unresolved financial mappings | 4 |

The CFO canvas headline says 21 exact ties, but its embedded TIE array

contains 20; the live source model matches the embedded data.

Remaining explicit exceptions: Austin Hudson Bend, East Hampton, Lone Tree,

and Sausalito. They are published as unresolved rather than guessed.

## Deployment

- schedule is disabled

- no persistent Redshift writes have been made

- apply ddl/001_tables.sql and ddl/002_sp_refresh_capex_marts.sql

- invoke once and reconcile against scripts/verify_live.py

- enable the schedule only after the Aerie consumers accept the contract

## Test plan

- [x] runner tests: 11 passed

- [x] Ruff clean

- [x] Pyright: 0 errors

- [x] DDL parser dry-run: 14 statements

- [x] CDK config / ownership / real-pipeline tests: 518 passed

- [x] live no-write source + publication SQL verification

- [ ] apply DDL in production

- [ ] invoke Lambda once and compare persistent output with verifier

- [ ] complete Aerie live-action integration (AERIE-1111/1112/1113/1115)

#1144 — feat(surtr-560): migrate netsuite-wrapper-report-puller (Gmail→S3) into Surtr @sanketghia  approved

Closes [SURTR-560](https://linear.app/builder-team/issue/SURTR-560).

## Why

netsuite-wrapper-report-puller is the sole ingress for the NetSuite Balance Sheet reports that reach Redshift. It was manually deployed, with no source in any repository, and long-lived Gmail OAuth credentials in plaintext env vars. Three problems:

1. Unrecoverable — the deployed ZIP was the only copy. The runbook pointed at a path on a former colleague's laptop.

2. Credentials exposed — a client_secret and a non-expiring refresh token, readable by anyone with lambda:GetFunctionConfiguration.

3. Fails silently — the deployed handler catches every exception and returns statusCode: 500 in the response *body*, so Lambda's Errors metric never fires. A dead Gmail API is indistinguishable from "no new reports": the puller "succeeds", the loader keeps succeeding against an unchanging S3 file, and nothing alarms.

Problem 3 is the one a lift-and-shift wouldn't fix, and it's the reason this PR exists.

## What this PR does

- Recovers the deployed source (SHA-verified) and commits it to docs/recovered/ as the migration baseline

- Adds pipelines/runners/netsuite-wrapper-report-puller/ — 6 modules, 55 tests

- Moves credentials to the existing surtr/klair-builders-mailbox secret (already used by two production runners). No credential material in env vars.

- Puts the schedule in pipeline.json (cron(0 12 * * ? *))

- Adds a fail-closed staleness gate — the correctness fix

- Narrows IAM from bucket-wide PutObject/PutObjectAcl/GetObject to PutObject on two prefixes + one secret read

- Corrects the runbook, which contained instructions that would mislead during an incident

## Verification

Byte-for-byte identical to live production output. Run against real Gmail + real Secrets Manager (read-only, S3 mocked), our handler produces exactly what's in S3 today:

Balance_Sheet/2026-08-05:      CSV IDENTICAL   XML IDENTICAL

Balance_Sheet_EOM/2026-08-05: CSV IDENTICAL XML IDENTICAL

Balance_Sheet/2026-08-04: CSV IDENTICAL XML IDENTICAL

Also verified:

- XML conversion differential-tested against the recovered production code on 10 adversarial inputs — 0 mismatches

- Fail-closed matrix — stale source, zero messages, missing attachment, multi-attachment, S3 failure all raise; healthy control succeeds

- 55/55 runner tests · 426/426 CDK real-pipeline-configs

## Scope corrections found during the work

Three of the ticket's assumptions didn't survive verification:

| Ticket said | Reality |

|---|---|

| Income Statement flows through this Lambda | Moved to a RESTlet in 2026-06; not produced here |

| Revenue_By_Customer_and_class consumer "not yet traced" | Dead since 2026-05-08; zero consumers in Surtr (296 branches) or Klair |

| 5 prefixes to migrate | 2 |

Recovering the code first also caught two errors in my own spec before any code was built on them: / in a report name becomes - (not stripped), and the XML nesting is recursive-with-lookahead with numeric-prefix normalization and a substring-containment fallback — not the exact-match stack I'd sketched. The sketch would have passed every unit test while diverging on inputs production handles.

## Deliberately preserved

- XML output — no known consumer (the loader reads .csv only), kept for fidelity and marked *unverified-consumer*

- An XML nesting quirk — substring containment makes the outer Accounts Payable section inherit an inner subsection's total. Real deployed behaviour, reproduced deliberately, pinned by a test.

## Not in this PR

Deploying this does not disable the old Lambda. Cutover is deliberately staged:

1. Merge → deploy → parallel run 1–2 days (both write identical bytes, so overwriting is harmless)

2. Disable the old EventBridge rule — the *only* change to the old stack

3. Soak 7 consecutive clean days

4. [SURTR-564](https://linear.app/builder-team/issue/SURTR-564) — delete the old Lambda and revoke the exposed GCP credential

The old function stays dormant, not deleted, so rollback is one command (aws events enable-rule) for the whole soak. The trade-off is explicit: the exposed refresh token stays live until SURTR-564, which is tracked separately so closing this migration can't silently close the credential work.

## Reviewer notes

- src/requirements.txt is mandatory under "bundling": true — CDK reads only that file, not the root pyproject.toml

- The module is mailbox_secrets.py, never secrets.py (shadows the stdlib module google-auth imports)

- Each run writes several back-dated keys. That's the 10-message/5-day window self-healing, not lag. Staleness keys off the newest message only.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

#3487 — Benchmark by Product — round 3 (CEO mapping, section totals, color-coding) @sanketghia  approved

Round 3 stakeholder feedback (Aug 6) on the Benchmark by Product page, following #3484 and #3486.

## Changes

### 1. Restore the benchmark % value (regression from #3486)

The rename to "Benchmark %" dropped the inline value; the row label now reads Benchmark % · 2.5%.

### 2. Remove the CEO team-room mapping (dormant, not deleted)

ceo_team_room_vendors emptied, so the exec team-room vendor falls through to G&A. The CEO cost sits only on the parent class with no per-leaf allocation to attribute against (unlike COO) — surfacing it showed an unactionable +X / −X pair. The engine rule + RefData field are kept and annotated for the deferred "move the credit to CEO" step. Confirmed with Ravi. Both CEO and its reversal are Edge, so consolidated figures are unchanged.

### 3. Central / Edge / Total summaries as 4-value blocks

Each total is a 4-row block mirroring a category — Benchmark %, Actual $, Max allowed $, Variance $ — placed at the end of its section (Central Total, Edge Total), with the grand Total closing the table.

- The section Benchmark % is the standard summed over ALL categories incl. zero-spend ones (Central 20% / Edge 5% / Total 25%) — not derivable on the frontend, so computed in the engine (new SectionTotal type + central/edge/total_summary on each column).

- The first row shows each column's actual cost % (not the flat benchmark), heatmapped against the benchmark, with the benchmark in the row label.

### 4. Color-code the total rows (green/red)

The totals applied the same heatmap classes as categories but a CSS specificity bug (surface fill at 0,2,1 beat the 0,1,0 tints) hid them. Dropped the total-row surface fill to zero specificity via :where() so the green/red tints show, exactly as on category rows.

## Verification

- Golden reconciliation dollar-exact (all 6 figures + 3 invariants). CEO removal is a same-section (Edge) reclass, so consolidated totals don't move.

- Section-total values verified dollar-exact against Ravi's sheet: Central variance −$442,518, Edge +$602,739, Total +$160,221.

- Backend: 32/32 benchmark tests, ruff + pyright clean.

- Frontend: 10/10 tests (incl. a discriminating green-under / red-over color test), lint + tsc clean. Mutation-checked the engine section-total logic and the FE summary pick.

## Screenshots

- These changes have already been verified by Ravi:

<img width="1862" height="607" alt="image" src="https://github.com/user-attachments/assets/00e4c4cb-15b5-4cce-ac64-8925c035b4e1" />

<img width="1844" height="758" alt="image" src="https://github.com/user-attachments/assets/e4a7a243-4793-4ef7-9f2a-e0c339a6a1be" />

🤖 Generated with [Claude Code](https://claude.com/claude-code)

The Builder Desk  —  Engineer Spotlight
🏆 Engineer Spotlight

TWENTY-NINE PRs IN TWENTY-FOUR HOURS: THE BUILDER TEAM IS SIMPLY NOT TIRED

Marcus and Benji combine for 21 PRs across four repos while the rest of the squad refuses to let the scoreboard breathe.

Twenty-nine pull requests. Four active repositories. One twenty-four-hour window. The Builder Team did not sleep, did not blink, and did not once glance at the clock. Aerie led the charge with 13 PRs, trilogy-drones and Surtr each punched in 6, and Klair rounded the board at 4. This is not a sprint. This is a philosophy.

Let us talk about @marcusdAIy, who shipped 11 PRs in a single rotation of the Earth and appears to have done so with the calm of a man who has simply decided that productivity is a moral position. He touched trilogy-drones with PRs #158, #159, #157, #156, and #155 — a five-PR sweep of AI taxonomy, post-merge fixes, eligibility classification, dispatch memory, and process quality attribution that reads less like a commit history and more like a doctoral thesis submitted in one afternoon. He then crossed over into Aerie (#840, #837, #836) for a CAPEX triple-stack and dropped #1122 into Surtr for good measure. Eleven PRs. Four repos. Zero days off.

Then there is @benji-bizzell, ten PRs deep and somehow making it look surgical. Benji worked Aerie like a craftsman — sidebar rail discoverability (#845), backup site dates made optional (#842), backup-site errors made actionable (#841), school profile alignment (#832), backup site workflow status (#833), DSS tier-a compliance (#820), portfolio docs pagination fix (#831), and a hardened pre-release contract boundary (#838). He then crossed into Surtr (#1141, #1134) to reconcile HubSpot contact survivors and accept a GuidePlatform claimed-at field, because apparently one repo was not enough canvas for this man.

@sanketghia dropped four PRs into Klair — including #3486, a Benchmark by Product stakeholder feedback PR that involved a rename AND a COO rule, which is the kind of PR that gets you invited to meetings you didn't ask to be in, and #3484, the JigTree POC that started it all. @YibinLongTrilogy added multi-Skill bundle download to the context editor in Aerie #827 — quiet, precise, necessary. @mwrshah closed out Surtr #1140 with the SF opportunity history sync, which is exactly the kind of unglamorous infrastructure work that makes everything else possible.

Now. Ashwanth Watch. @ashwanth1109 shipped one PR this cycle — Klair #3478, generating individual Education QTD reports consolidated into a single email — and I want to be very clear that one Ashwanth PR contains more load-bearing logic than most engineers ship in a sprint. The diff, I am told by sources close to the diff, is not so much readable as it is *experienced*. When reached for comment, Ashwanth reportedly said, "It's one email. It has everything in it. I don't know what else you want from me." His dismissal was instantaneous. He had already moved on.

Morale on the Builder Team is at an all-time high. Sources confirm it has never been higher. The numbers agree.

Brick's Overflow — PRs Mac Didn't Cover  (click to expand)
#158 — AI-243: extend the shared finding taxonomy, classify real inline-comment text, cross with addresser outcome, chart weekly @marcusdAIy  no labels

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->

## 1. Summary

- Extends the existing taxonomy in scripts/issue_learning_loop.py (TAXONOMY_RULES) with four classes — doc-accuracy, silent-degradation, test-quality, style-nit — instead of building a second, parallel classifier (AI-191: one ingest, one key space).

- Adds scripts/finding_classification.py: classifies each drone-reviewer finding from its real inline-comment text (fetched from GitHub, not the review-summary body — see finding below), crosses it with the addresser's own reply-thread outcome (fixed/skipped/not-applicable/unreported/already-fixed), and persists one record per finding to reports/finding-classifications.json keyed by (repo, pr, comment_id) — re-running is a merge, not a recompute.

- Charts it weekly: scripts/eval_weekly_charts.py renders reports/finding-classification-trend.png (class volume over time + class × outcome), and src/eval-weekly.ts renders a ## Finding Classification section in the weekly markdown report.

- Backfilled a real baseline: 1,944 classified findings across 54 recently-merged PRs (49 trilogy-drones + 5 Klair).

## 2. Why It's Needed

We could measure *how many* reviewer findings there were and *how severe*, but not *what kind of problem* — so "what does our reviewer keep finding?" was answered by impression. That blocks three things: AI-213's reviewer-precision baseline, a proposed sixth "documentation" review dimension (~20% of review spend forever), and any learned-appendix prompt change (currently a guess about which lesson matters most). This ticket produces the measurement instrument those decisions need.

## 3. Changes

- scripts/issue_learning_loop.py — four new TaxonomyRule entries (doc-accuracy, silent-degradation, test-quality, style-nit), a TAXONOMY_CATEGORIES closed-union constant, and a cross-reference comment pointing at the new module for the outcome cross.

- scripts/finding_classification.py (new) — root-finding header parser (Sev · dim — the shape src/review-inline.ts posts per inline comment), addresser-reply parser (mirrors src/addresser.ts's renderReplyBody grammar), persisted ledger (load/merge/save), weekly summary/rollup, and a CLI (--pr, --backfill, --week-start/--week-end/--date-tag).

- scripts/eval_weekly_charts.pyload_classification_weekly_snapshots, draw_classification_trend, write_classification_trend_audit; wired into main(), non-fatal when the ledger is empty.

- src/eval-weekly.tsClassificationTrendResult/ClassificationTrendSummary types, loadClassificationTrend (injectable via a new WeeklyEvalOptions.loadClassificationTrend seam — kept separate from runPipelines so every existing test double for that option is untouched), renderClassificationTrendSection, wired into WeeklyEvalArtifact and runWeeklyEval.

- scripts/test_finding_classification.py (new, 38 tests) + src/eval-weekly.test.ts (8 new tests) — see Test plan.

- reports/ — the backfilled ledger (finding-classifications.json), one summary snapshot, the trend chart + audit.

- docs/decisions/ — one new entry.

A real bug found along the way (not fixed here — out of scope, flagged for a follow-up): issue_learning_loop.py's existing source_counts["drone"] breakdown classifies the review summary body. src/review-inline.ts (stripInlinedFindings) replaces any finding also posted inline with the literal placeholder "finding inlined as a PR comment." in that body — so a real share of that breakdown's historical other bucket is an artifact of classifying the placeholder, not genuine imprecision. finding_classification.py avoids this by reading the finding's real text from the inline-comment API directly (which the backfill needed anyway).

### Contract surface affected

None — classification is metadata only. It never touches a finding's severity, text, routing, or whether it gets addressed (verified: finding_classification.py only reads GitHub comments and writes its own separate ledger; nothing in src/addresser.ts / src/reviewer.ts was touched).

## 4. Breaking Changes

None. All new fields/files are additive:

- TAXONOMY_RULES gained four entries but zero findings moved between the original nine buckets on the 351-finding sample used to tune the new rules (measured — see Verification artifact); the new classes only pull findings out of other, they don't reclassify between old categories.

- WeeklyEvalArtifact gained one required field (classification_trend); all 7 pre-existing test fixtures updated in this PR.

- eval_weekly_charts.py's new chart/audit functions are additive and skip (not crash) when there's no classification data yet.

## 5. Test Plan

- [x] pnpm typecheck → clean.

- [x] pnpm exec vitest run3,529 tests passed (113 files), including 50 in src/eval-weekly.test.ts (8 new: loadClassificationTrend ×3, renderClassificationTrendSection ×4, one runWeeklyEval integration test).

- [x] node scripts/run-python-tests.mjs (pnpm test's Python leg) → 478 tests passed, including 38 new in scripts/test_finding_classification.py (closed-union assertions, header/reply parsers, merge idempotency, classification_sample_status threshold, summarize_records zero-fill + unclassifiable separation).

- [x] pnpm build → clean.

- [x] Live validation against real data (not just fixtures): ran python scripts/finding_classification.py --pr <owner>/<repo>#<n> ... against 54 real merged PRs via gh/GitHub API and inspected the persisted ledger + rendered chart — see Verification artifact.

- [ ] Operator-side: run python scripts/finding_classification.py --backfill --max-prs 50 against a fresh pr_data.json cohort periodically to keep the ledger current, and python scripts/eval_weekly_charts.py to regenerate the trend chart weekly (already wired into the normal eval-weekly flow going forward).

## 6. Verification Artifact

Real backfill distribution (1,944 findings, 54 merged PRs, reports/finding-classification-summary-2026-08-06.json):

| Category | Count | Share |

|---|---:|---:|

| error-propagation | 673 | 34.6% |

| other (unclassifiable) | 281 | 14.5% |

| edge-cases | 266 | 13.7% |

| input-validation | 195 | 10.0% |

| test-gaps | 160 | 8.2% |

| data-contract | 138 | 7.1% |

| state-concurrency | 66 | 3.4% |

| observability | 55 | 2.8% |

| doc-accuracy | 43 | 2.2% |

| security-authz | 22 | 1.1% |

| performance-cost | 16 | 0.8% |

| test-quality | 11 | 0.6% |

| style-nit | 11 | 0.6% |

| silent-degradation | 7 | 0.4% |

doc-accuracy is NOT the largest class — it's 9th of 13, at 2.2%. That's the headline this instrument was built to produce: it pushes back on the premise that a sixth "documentation" review dimension is obviously justified by volume. The unclassifiable bucket (14.5%) is disclosed as its own headline, not folded into a real class.

class × outcome (candidate FP signal — not adjudicated; a skip/not-applicable reason is the addresser's own opinion, AI-213 owns the human-adjudicated rate): overall fixed=1,508 (77.6%), skipped=85 (4.4%), unreported=72 (3.7%), not-applicable=17 (0.9%), already-fixed=1, no_addresser_reply=229 (11.8% — round hasn't happened / no reply thread found).

Old-vs-new distribution on the 351-finding tuning sample (trilogy-drones PRs #144–#156), confirming no cross-bucket drift among the original nine:

| Category | Old (9 rules) | New (13 rules) |

|---|---:|---:|

| error-propagation | 114 (32.5%) | 110 (31.3%) |

| other | 68 (19.4%) | 62 (17.7%) |

| edge-cases | 56 (16.0%) | 50 (14.2%) |

| input-validation | 33 (9.4%) | 31 (8.8%) |

| test-gaps | 27 (7.7%) | 26 (7.4%) |

| data-contract | 25 (7.1%) | 25 (7.1%) |

| observability | 18 (5.1%) | 18 (5.1%) |

| doc-accuracy | — | 13 (3.7%) |

| state-concurrency | 5 (1.4%) | 5 (1.4%) |

| security-authz | 4 (1.1%) | 4 (1.1%) |

| test-quality | — | 3 (0.9%) |

| silent-degradation | — | 2 (0.6%) |

| style-nit | — | 1 (0.3%) |

| performance-cost | 1 (0.3%) | 1 (0.3%) |

Zero findings reassigned between any two of the original nine buckets — every shift is extraction from other (or, for silent-degradation, a narrow proximity-gated slice of error-propagation's "silent/swallow" vocabulary) into a new class.

Rendered chart (reports/finding-classification-trend.png):

[Finding classification trend chart showing class volume over time and class x addresser outcome for the current week](https://cursor.com/agents/bc-cb26b63f-0fef-4683-93e2-c49640453449/artifacts?path=%2Fopt%2Fcursor%2Fartifacts%2Ffinding_classification_trend_chart.png)

TS mirror decision: none needed. scripts/finding_classification.py has exactly one runtime consumer — src/eval-weekly.ts reads its JSON summary opaquely (same as it already does for issue_learning_loop.py's output). This differs from src/human-review-findings.tsscripts/human_review_findings.py, which mirror parsing logic that both the TS ingest path (addresser.ts/runner.ts) and the Python report pipeline need independently at runtime — there is no TS runtime path here that needs to classify a finding into this taxonomy.

Scope note on the backfill: the 5/34 sampled Klair PRs that contributed records did so because a handful of comments happened to match the drone-reviewer header shape; the majority of sampled Klair PRs in this window carry only Mercy/human-formatted findings (different header shapes, intentionally out of scope for this module — see the docstring). The 1,944-finding baseline is therefore concentrated in trilogy-drones' own self-hosted review corpus; extending backfill coverage to more Klair PRs reviewed by the drone-reviewer itself is a natural follow-up once an operator has a fresh pr_data.json.

<sub>To show artifacts inline, <a href="https://cursor.com/dashboard/cloud-agents#team-pull-requests">enable</a> in settings.</sub>

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a href="https://cursor.com/agents/bc-cb26b63f-0fef-4683-93e2-c49640453449?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/background-agent?bcId=bc-cb26b63f-0fef-4683-93e2-c49640453449&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

#842 — feat(portfolio): make backup site dates optional @benji-bizzell  approved

## Summary

- Allow Portfolio Site backup leases to omit redundant dates while retaining paired-date validation

- Present undated lease terms cleanly across Backup Sites admin and Portfolio surfaces

- Keep contracted spaces date-bounded and align Public API, Agent, and MCP consumers with nullable Portfolio lease dates

## Why

Portfolio Sites already identify the canonical lease location, so asking users to duplicate lease dates on each Backup Site term adds unnecessary work. Contracted spaces still need explicit coverage dates.

## Business Value

Admins can register a Portfolio Site lease as backup-site evidence without re-entering redundant dates, while downstream assignment and reporting remain accurate.

## Breaking changes

- BackupSite.startDate and BackupSite.endDate remain required response properties but widen from date strings to date-or-null. Consumers must accept both fields as null together for Portfolio Site leases.

- After the first paired-null term is written, an ordinary full revert is unsafe. Incident rollback must retain the nullable schema and null-safe readers; optional writes may only be disabled selectively. See the [rollback contract](https://github.com/AI-Builder-Team/Aerie/blob/557cc858a46460ff8ac87c86571b1b8676862a86/docs/backup-site-optional-dates-rollout.md).

## Test plan

- [x] pnpm check on exact head 557cc858a

- [x] 197 focused Backup Sites, shared-contract, Public API, Agent, MCP, admin, and card tests

- [x] pnpm test on runtime-identical parent 95a8bfde2: 9,473 passed, 17 skipped

- [x] Seven-lane adversarial review; rollback finding fixed and re-reviewed on exact head

- [x] Hosted CI on PR head 557cc858a

#845 — feat(ui): make sidebar rail toggle discoverable @benji-bizzell  approved

## Summary

- Make unused desktop icon-rail space toggle the context sidebar

- Turn the eagle mark into a state-aware expand/collapse affordance on hover and focus

- Keep collapsed panel controls out of the focus tree and preserve focus on the rail

## Why

The sidebar could only be toggled by clicking the active section icon, which was functional but not discoverable. The rail now communicates and supports the action directly without making interactive sidebar content prone to accidental collapse or leaving hidden controls keyboard-accessible.

## Business Value

Makes a frequent layout control easier to discover and faster to use while preserving the compact Aerie shell and its accessibility contract.

## Test plan

- [x] pnpm check

- [x] 30 focused AppShell and IconRail tests

- [x] Manual desktop smoke for logo toggle, empty-rail toggle, icon direction, and protected navigation controls

#1141 — fix(hubspot-raw-sync): reconcile repeated contact survivors @benji-bizzell  approved

## Summary

- Reconcile separately validated contact aliases that resolve to the same survivor across batch pages

- Defer canonical fetches until original shard evidence is complete and preserve chained-survivor replay parity

- Keep unvalidated duplicates fail-closed while adding actionable record and immutable-page diagnostics

## Why

HubSpot Raw Sync run 8deecbf1-3dbb-457f-ac5a-29bc96ffc899 failed when two active contact aliases in adjacent batch pages both resolved to the same new survivor. Each alias-to-survivor observation passed the strict page partition checks, but the shard-wide logical-key guard rejected the second survivor before the existing canonical merge reconciliation could retain the fresh survivor and tombstone both aliases.

The failure was safe but blocked the CRM run and required manual diagnosis. This closes that reconciliation gap without weakening generic duplicate handling, and keeps immutable replay equivalent when an intermediate survivor resolves again before the terminal canonical fetch.

## Business Value

HubSpot contact merges that cross batch boundaries can reconcile automatically while ambiguous or unvalidated duplicates continue to fail closed, reducing avoidable pipeline babysitting without compromising data correctness.

## Operational recovery

This PR does not deploy the fix or recover the failed production run. Do not redrive execution 8deecbf1-3dbb-457f-ac5a-29bc96ffc899; its immutable pages preserve the old fetch chronology. After deployment, start a fresh production run and verify the contacts publication and ledger evidence before closing the incident.

## Test plan

- [x] HubSpot Raw Sync suite: 250 passed

- [x] CI-pinned Ruff 0.15.22 check across pipelines

- [x] CI-pinned Ruff 0.15.22 format check across pipelines

- [x] Hosted CI

- [x] Fresh Mercy review at final head

#3478 — [codex] Generate individual Education QTD reports in one email @ashwanth1109  approved

## Demo

<img width="2428" height="1462" alt="image" src="https://github.com/user-attachments/assets/5cef9410-6a7d-4f48-9965-623439d063a4" />

## Summary

- expose every active Education BU in the on-demand UI instead of the two synthetic vertical groups

- generate one QTD document per selected Education BU and link every result from one requester-only completion email

- split 2HR Learning into two class-filtered reports: Evangelism + Edu Media, and Schools Marketing

- apply each class filter consistently across P&L, vendor/customer variance, and HC queries while keeping both documents in the source BU folder

- populate Education Heads from distinct XO contractors with positive payments in the latest available raw-invoice week on or before the report through date (staging_finance_xo.raw_contractor_invoices)

- show Education headcount as unavailable when no qualifying XO snapshot exists, and prevent weekly historical reports from using a later in-month snapshot

- treat headcount as a team-room fact: shared team rooms show the same actual count wherever they appear rather than inventing a BU allocation; zero-current-head rooms render as 0

- reject obsolete or inactive Education names before launching ECS, including Other Education Verticals

- suppress per-BU and Education-summary emails for on-demand runs; only the authenticated requester receives the completion email

- mark an otherwise-successful job partial when its requester-only completion email fails

- grant on-demand Education document access only to Ashwanth R, Marcin Pindral, Jan Dejager, and David Harpur

- preserve sanitized partial/total/refresh failure reporting, structured refresh diagnostics, and scheduled Education recipient behavior

## Why

Education QTD jobs need report-level detail rather than the previous Physical Private Schools and Other Education Verticals grouping. The latter was not a live BU and caused the worker validation failure reported during UI testing. 2HR Learning also contains two operational class groups that require separate reports.

Education team-room Heads previously displayed as unavailable. They now represent actual XO contractors from the latest applicable raw invoice snapshot instead of budgeted HC EoQ.

## Impact

Education-only jobs create separate documents for every selected active Education BU, with 2HR Learning expanding into two class-filtered documents. An on-demand job sends exactly one email containing every document link and terminal outcome, addressed only to the authenticated requester. Drive access is independently granted to the fixed four-person Education review group.

Software QTD delivery and scheduled Education behavior remain unchanged.

## PR test deployment

Production-safe code defaults to the shared klair-scheduled-jobs ECS family. Isolated PR validation selected klair-scheduled-jobs-pr-3478 explicitly through QTD_ONDEMAND_ECS_TASK_DEFINITION; the live-validated worker was revision 3 using immutable image tag pr-3478-f07cdd4c8, so production latest remained untouched. The subsequent review fixes in 1e39cb066 are covered by the automated validation below and have not been republished to the isolated worker.

Before production release:

1. Manually publish klair-api/Dockerfile.jobs to klair/scheduled-jobs:latest.

2. Re-run the shared-worker smoke test.

The standard Klair production release does not publish the shared scheduled-jobs image automatically.

## Validation

- 836 monthly-QTD and on-demand cron tests passed

- changed-file Ruff formatting and linting passed

- changed-file Pyright checks passed

- changed-file ESLint checks and pnpm lint:pr passed

- live Redshift validation confirmed actual XO Heads, including 2HR DoPs 34, Evangelism 8, Expansion 23, Media 5, Schools Admissions 25, and Schools Marketing 5

- isolated ECS revision 3 Redshift smoke passed with exit code 0

- full refresh-enabled live run for all 34 selected Education BUs succeeded:

- 35 terminal results because 2HR Learning expands into two reports

- 30 documents generated

- 5 expected no-data results

- 0 failures and 0 orphan documents

- all 30 documents received all four Drive grants

- exactly one SES message was sent, only to ashwanth.r@trilogy.com

Closes #3472

#3486 — Benchmark by Product — stakeholder feedback (rename + COO rule) @sanketghia  approved

Follow-up changes to the merged Benchmark by Product POC (#3484), from FP&A (Ravi) feedback.

## Changes

### 1. Rename the benchmark-column row label to "Benchmark %"

The Std Benchmark column's Cost % row read Cost % · bench X%; relabeled to a clean Benchmark % per stakeholder request.

### 2. Key the COO category on account_name + department, not vendor substring

FP&A's COO category is the Central-Factory recharge pool, which is split across every leaf product class. The prior rule (type == "CF Expenses" AND "coo" in vendor) only caught the parent-class booking, leaving the per-leaf G&A slices misfiled under G&A.

New rule (confirmed universal by Ravi, not JigTree-specific):

> account_name == "Central Factory Recharges" AND department == "G&A" → COO

- redshift_source.py: fetch account_name in the GL query

- golden_source.py: carry account_name from the frozen sheet (column already present)

- engine.py: new COO rule; verified to subsume the old vendor rule with zero row loss and zero false-adds against the frozen data

- tests: 3 discriminating cases replace the vendor-substring assertion

## Verification

- Golden reconciliation stays dollar-exact — all 6 consolidated figures + 3 invariants OK. Consolidated is unaffected because COO and G&A are both in the Central section; only the per-product COO/G&A split changes (which is the intent).

- Per-product effect: COO now spreads across 17 leaf products summing to $25,000 (= Consolidated), instead of a single lump on the JigTree parent.

- Live Redshift confirmed: Central Factory Recharges + G&A = $25,000, matching the frozen sheet.

- 29/29 benchmark tests pass; ruff + pyright clean; mutation-tested the COO rule (unit test fails when broken).

## Screenshot

<img width="1863" height="765" alt="image" src="https://github.com/user-attachments/assets/76778d6c-6d33-47bf-9263-91cb38cb5be9" />

🤖 Generated with [Claude Code](https://claude.com/claude-code)

The Portfolio  —  Trilogy Companies

Skyvera Builds a Telco Cloud Roll-Up, One Sticky Asset at a Time

With CloudSense, Kandy assets and a bid for Casa’s wireless business in the mix, Skyvera is turning telecom complexity into an acquisition strategy.

AUSTIN, TEXAS — Skyvera is making a very clear bet: the telecom industry’s future may be cloud-native, but its present is still a robust maze of billing systems, CPQ workflows, customer engagement tools and aging network infrastructure that cannot simply be wished into modernization.

That is where the Trilogy portfolio company is leaning in. Recent reports from TelecomTV and Light Reading point to a widening Skyvera acquisition push, including the pickup of Kandy cloud assets, the acquisition of CloudSense and an $18 million bid for Casa Systems’ wireless business. Taken together, the moves suggest a best-in-class roll-up strategy around the least glamorous — and most mission-critical — layers of telecom operations.

Skyvera, part of Trilogy International’s broader enterprise software ecosystem, focuses on helping telecom operators bridge legacy on-premise systems into cloud-native operating models. Its portfolio already includes tools such as VoltDelta, ResponseTek, Mobilogy Now and Service Gateway. The addition of CloudSense is especially strategic: the Salesforce-native CPQ and order management platform gives Skyvera deeper reach into complex telco and media sales motions, where pricing, configuration and fulfillment can become a margin-eating labyrinth.

The Kandy assets add another layer of synergy. Kandy’s CPaaS and UCaaS capabilities are designed for cloud communications and customer engagement — precisely the arena where carriers are trying to monetize beyond pipes while still managing demanding enterprise customers. Meanwhile, the reported $18 million bid for Casa’s wireless business signals that Skyvera is not limiting itself to front-office software. It is also eyeing network-adjacent assets that could deepen its relevance to operators navigating 5G, fixed wireless and cloud transformation.

This is classic Trilogy-adjacent operating logic: acquire durable enterprise software assets, rationalize the cost structure, leverage global talent, and serve sticky customers who need continuity as much as innovation. In telecom, where switching costs are high and modernization cycles are measured in years, that model has real strategic horsepower.

Key Takeaways:

- Skyvera’s CloudSense acquisition strengthens its Salesforce-native CPQ and order management position for telcos.

- Kandy cloud assets expand its communications and customer engagement footprint.

- The Casa wireless bid points to a broader infrastructure-plus-software ambition.

- The strategy aligns with Trilogy’s core thesis: automate, consolidate and scale through operational discipline.

Telecom transformation is not a clean-sheet rewrite. It is a migration, an integration exercise and, increasingly, an M&A playbook. Skyvera appears ready to leverage all three. We’re just getting started.

TelcoDR’s Skyvera snacks on Kandy cloud assets - telecomtv.c  ·  Danielle Royston's Skyvera makes $18M bid for Casa's wireles  ·  TelcoDR’s Skyvera snaps up CloudSense - telecomtv.com

Aurea Absorbs Jive at Half-Price, as ESW's Bargain-Hunting Blueprint Goes On Display

Portland's once-celebrated social software darling changes hands at a steep discount — and the buyer has done this before.

AUSTIN, TEXAS — When Jive Software was riding high, it was the kind of company that made Portland proud: a publicly traded enterprise social networking pioneer with a market capitalization that briefly kissed $1 billion. When the music stopped, it sold for roughly half that peak value. The buyer was Aurea, the enterprise software roll-up that sits inside ESW Capital — Trilogy International's private equity arm — and the transaction fit a pattern that by now should surprise no one.

Jive, which built its reputation on enterprise collaboration software — think internal social networks for large organizations — had struggled to hold its footing as Microsoft Teams, Slack, and other well-capitalized competitors redrew the market. Its decline from crown jewel to discounted asset is the kind of trajectory ESW was built to capitalize on. The firm's stated playbook: acquire at one to two times ARR, staff with global remote talent sourced through Crossover, push support pricing upward aggressively, and target EBITDA margins of 75 percent. Jive's sticky enterprise customer base — organizations that had spent years embedding the platform into their workflows — made it precisely the kind of asset that fits that formula.

The deal drew attention not only for the price but for what it signals about the broader market for legacy collaboration software. A Forrester analysis of customer advocacy platforms published around the same time noted that buyers in this category face a reckoning: legacy vendors are either being absorbed or being abandoned, and enterprise customers need a clear migration path either way. For Jive's installed base, the acquisition answers the abandonment question — at least for now — while leaving the pricing question very much open.

ESW Capital has completed more than 75 acquisitions across its portfolio. Aurea alone has absorbed 17 companies since 2012. The model is not secret; the Wall Street Journal has profiled it. What remains to be seen, as it always does in these transactions, is what happens to the customers who find themselves inside the machine — and what the support renewal notices look like twelve months from now.

Small Software Companies Find a Home With ESW Capital - WSJ  ·  What To Do Next About Your Customer Advocacy Platform - Forr  ·  Jive acquired in enterprise collaboration software merger -

EDTECH MONEY IS BACK, BUT THE SMART CASH IS CHASING THE HUMAN STUFF

Word is the edtech party never really ended—it just rebranded around outcomes. Multiverse, the U.K. workforce-training platform, landed a €60 million round at €1.8 billion valuation, while Romania's Kinderpedia picked up €2.2 million and India's Emversity doubled its valuation training workers for AI-resistant jobs. The message from investors is clear: education is hot again, but not traditional seat-time models.

The real action lies in a new bargain: let AI handle academics, then use freed hours building human skills. Austin's Alpha School, founded by Joe Liemandt and MacKenzie Price, exemplifies this approach—two hours of adaptive academic work daily, then entrepreneurship, leadership, coding, and financial literacy. Alpha reports students learning 2.3 times faster than U.S. norms and testing in the top 1–2% nationally on NWEA assessments. Its model—no homework, 90% mastery requirements, full grade levels in 20-30 hours—is expanding beyond Austin through new campuses and the Timeback platform. In this market, time itself has become the premium commodity.

The Machine  —  AI & Technology

The Machines Learn to Write in Clay

A new neural translator reaches across four millennia to teach us cuneiform — the first language humanity ever pressed into permanence.

AUSTIN, TEXAS — There are half a million clay tablets scattered in the vaults of the world's museums, each one a small rectangle of dried Mesopotamian mud pressed with wedge-shaped marks by a scribe who has been dead for four thousand years. They are, collectively, humanity's oldest surviving conversation with itself: tax receipts, love letters, beer recipes, laments for fallen cities. And until very recently, almost no one alive could read them.

Cuneiform is the writing system from which all writing descends — the primordial ancestor of the letters you are reading now. Yet the chain of transmission broke. The last native readers died around the first century of the common era, and the language of Akkadian, in which many of these tablets speak, went silent for nearly two thousand years before nineteenth-century philologists began the slow work of resurrection.

Now a team of researchers has built TabletCraft, a neural machine translation system that does something no prior tool has attempted: it works in both directions. Not merely Akkadian to English, which earlier scholar-facing systems achieved, but English to Akkadian, complete with rendered cuneiform glyphs. You can, for the first time in perhaps two millennia, compose a new sentence in the language of Hammurabi and Gilgamesh and see it appear in the wedges of a Babylonian scribe.

The technical achievement is bidirectional NMT trained on the sparse, hard-won corpus of transliterated tablets. The cultural achievement is stranger and larger. We built these models to translate French to English, Mandarin to Spanish — the living tongues of a crowded planet. And now we are pointing them at ghosts.

Elsewhere in this week's preprint deluge, MemArena proposes benchmarks for on-device AI assistants that must remember our conversations across sessions, and BBOWP-Bench probes whether language models can formulate optimization problems from plain description. Each is a step outward. But TabletCraft is a step backward — deep backward, into the silt of the Tigris and Euphrates — and it suggests something quietly astonishing. The same architectures we use to summarize emails can also reopen the mouth of a Sumerian scribe. Every language humans ever spoke may be, from here on, only a model away.

TabletCraft: Bridging a 4,000-Year Cultural Gap with Bidirec  ·  BBOWP-Bench: Evaluating LLMs on Black-Box Optimization Word  ·  MemArena: An Ego-Centric Benchmark for On-Device Agentic Per

AI Video Is Escaping the Demo Reel and Charging Straight Into Startup Growth

From five-minute generated films to billion-dollar platforms, AI video is becoming the new growth engine — and the new ethical minefield.

SAN FRANCISCO — The AI video race just hit that thrilling, slightly dizzying phase where every startup founder is asking the same question: What if my next ad, product demo, onboarding flow and investor pitch could be generated before lunch?

This changes everything. I cannot overstate how significant the shift is from AI video as a novelty — surreal clips, blinking artifacts, impossible hands — to AI video as an operating layer for companies that need to sell, teach and explain at internet speed.

The latest signal comes from CraftStory, whose AI can generate five-minute videos, a meaningful leap in a market where short, flashy clips have dominated. As VentureBeat reported, longer-form generation points toward something much bigger than social media snippets: automated storytelling for brands, educators, sales teams and creators who previously needed production crews, editors and serious budgets.

Meanwhile, Higgsfield reportedly raised $80 million at a $1.3 billion valuation to scale its AI video platform, another neon sign that investors believe video generation may become one of the defining application categories of the AI era. The future is now, and apparently it renders in high definition.

For startups, the appeal is obvious. AI video can compress the distance between idea and audience. A small team can test multiple ads, localize content for different markets, create founder-led explainers without the founder sitting under lights for six hours, and turn product updates into watchable narratives. Inc. recently explored how startups can leverage AI video to grow, and the core message is clear: speed is becoming a marketing advantage.

But — and this is a very important but — the AI enthusiasm machine also needs brakes. A separate startup drew backlash after suggesting its AI could help save troubled relationships, prompting the wonderfully blunt reaction: “Tech people need to stop.” That critique matters. Not every human problem is a SaaS workflow waiting to be optimized.

The next phase will belong to founders who understand both truths: AI video is an extraordinary amplifier, and amplification without judgment can get weird fast. Used well, it gives tiny teams superpowers. Used carelessly, it turns intimacy, trust and authenticity into just another generated asset.

Still, the direction is unmistakable. AI video is moving from toy to tool to infrastructure — and startup storytelling may never look the same again.

How Startups Can Leverage AI Video to Grow - inc.com  ·  'Tech people need to stop': Startup faces backlash after sug  ·  CraftStory's AI generates 5-min videos - VentureBeat

Federal AI Governance Takes Shape — But Stakeholders Debate How Much Shape Is Too Much

The Trump administration's 'light touch' AI legislative blueprint meets a chorus of qualified agreement, vigorous dissent, and one very consequential antitrust appointment.

WASHINGTON, D.C. — Pursuant to the issuance of the Trump Administration's newly promulgated AI Policy Framework (hereinafter "the Framework"), as reported by PBS, certain obligations and recommendations have been conveyed by the Executive Branch to the Congress of the United States with respect to the regulation of artificial intelligence technologies, such obligations and recommendations being characterized as favoring a posture of minimal governmental interference in the aforementioned technological domain.

Notwithstanding the foregoing expression of preference for regulatory restraint, it is hereby noted that competing viewpoints have been advanced by interested parties. Pursuant to analysis published by Tech Policy Press, it has been argued — with some degree of urgency, though subject to interpretation — that affirmative legislative action by Congress may be warranted for the purpose of assuring members of the general public that their interests are, in some legally cognizable manner, being protected.

The White & Case LLP AI Watch: Global Regulatory Tracker has, to the extent permitted by applicable legal and editorial constraints, documented the evolving patchwork of regulatory activity within the United States, such documentation revealing a landscape that may be characterized, without undue overstatement, as unsettled.

In a development whose relationship to the aforementioned regulatory discourse is, at minimum, not without relevance, it has been reported by the Financial Times that the Trump Administration has designated a prominent critic of large technology companies to serve as chief of the Department of Justice Antitrust Division. The identity of the appointee, and the full scope of authority to be exercised thereunder, remain subjects upon which further disclosure may reasonably be anticipated.

It is the considered assessment of this desk that the foregoing constellation of events — the Framework, the legislative debate, and the antitrust appointment — collectively constitutes a period of material, if not yet determinative, significance for enterprises, including but not limited to portfolio companies of ESW Capital and its affiliated entities, operating within the artificial intelligence sector. No warranties, express or implied, are made regarding the foregoing.

AI Watch: Global regulatory tracker - United States - White  ·  White House urges Congress to take a light touch on AI regul  ·  Congress Should Pass AI Law to Reassure the Public - Tech Po
The Editorial

The Pontiff, the Freshman, and the Vanishing Library

A week's worth of headlines converge on a single, unfashionable question: who is left to know what the machines do not.

VATICAN CITY — It is the peculiar genius of our age to produce, in the span of a single news cycle, a Roman pontiff warning against a "culture of power" propelling artificial intelligence, a Stanford freshman discovering that his classmates belong to secret societies of the well-connected, and a chorus of essayists fretting that the great data-eating engines of Silicon Valley are quietly digesting the world's knowledge into a beige and homogeneous pulp. One is tempted to shrug. One resists the temptation.

Pope Leo, who has taken it upon himself to become the most unlikely AI critic of our moment, told an audience this week that the technology's ascent is being driven less by curiosity than by the ancient human appetite for dominion — the will to command, to control, to consolidate. This is the sort of observation that would once have been dismissed as the reflexive suspicion of a church that lost its argument with Galileo and has been sulking ever since. It is harder to dismiss now. The men building these systems have, after all, been unusually candid about their ambitions, which run somewhat beyond spellcheck.

Meanwhile a young man arrives at Stanford, that sun-drenched abbey of meritocratic self-congratulation, and discovers what generations of Ivy League freshmen have discovered before him: that the room he has entered contains, within it, smaller and more selective rooms, and within those, smaller ones still, until at last one arrives at a paneled study in which four people decide who gets funded. The Times treats this as revelation. It is in fact the oldest story in the republic, updated only in that the secret handshakes now involve term sheets.

Combine these two dispatches and you begin to see the shape of the thing. The technology being built to organize human knowledge is being built by graduates of institutions whose principal function is the sorting and credentialing of a very narrow slice of humanity. What the machines learn, they learn from what has been written down, translated into English, and posted online — which is to say, from a slender and provincial fraction of what human beings have actually thought. The essayist Deepak Varuvel Dennison, writing in the Guardian, calls the likely result a "knowledge collapse." It is an ugly phrase for an uglier prospect: a civilization consulting an oracle that has read only its own press releases.

Brussels, for its part, has decided to do something about this, and as of this week its AI Act becomes enforceable against the makers of general-purpose models. The Europeans, having invented most of the philosophical vocabulary by which we discuss such things, have at least the decency to reach for the statute book. Whether the statute book is any match for a technology whose training runs cost more than the GDP of small nations is a question that will answer itself, in time, and not gently.

The Pope, one suspects, already knows the answer. He has read the older book.

Pope Leo denounces ‘culture of power’ driving rise of AI - T  ·  The Secret Elite One Freshman Discovered at Stanford - The N  ·  What I Wish I Had Known About Germany Earlier - Hyperallergi
The Office Comic  ·  Art Desk
The Office Comic  ·  Art Desk

Nation’s Executives Proudly Announce They Have Learned New Word To Put Between ‘AI’ And ‘Transformation’

After years of saying disruption, innovation, sustainability, resilience, and blockchain with complete confidence, business leaders confirmed they are now prepared to begin orchestrating.

REDMOND, WASHINGTON — In a development widely described as both inevitable and billable, corporate America has entered a new phase of artificial intelligence maturity in which executives have discovered the word “orchestration” and immediately begun using it to mean whatever they were already planning to buy.

The term, which refers in its narrow technical sense to coordinating multiple systems, agents, workflows, applications, data sources, cloud services, APIs, governance layers, and human beings who still have the password to the SharePoint folder, has quickly become the industry’s preferred way of indicating that AI has moved beyond the embarrassing stage where it merely generated emails no one wanted to read.

According to market observers, Microsoft stands to benefit from the rise of orchestration because it already owns the place where most office work goes to become slightly harder to find. Analysts cited by Barron’s noted that Microsoft’s enterprise footprint could make it a natural winner as companies seek platforms capable of coordinating AI tools across sprawling organizations that have spent the past decade carefully ensuring none of their software talks to anything else.

This is, of course, the correct outcome. If there is one company well positioned to orchestrate the modern workplace, it is the firm whose products have already trained millions of professionals to accept that the same document may exist in Teams, OneDrive, Outlook, SharePoint, their desktop, and a mysterious location called “Recent.”

The arrival of orchestration also solves a growing problem for companies that had begun to run out of respectable ways to describe buying AI. “Automation” sounded too cruel. “Agents” sounded too much like the software might make decisions, which alarmed legal. “Copilot” had already been taken by every vendor with a text box. Orchestration, by contrast, suggests a symphony, which allows management to picture itself as the conductor rather than the person approving another seven-figure software contract because a consultant used the word “workflow.”

The timing is useful. As The Conversation recently observed, companies are beginning to hype AI in ways that resemble the earlier corporate sustainability boom, when every annual report briefly became a wetland restoration pamphlet with adjusted EBITDA. The lesson appears to have been learned: vague ambition must now be paired with frameworks, metrics, and enough governance language to imply someone could be held accountable without identifying who.

Other industries have demonstrated the durability of this approach. Construction has its own thriving ecosystem of buzzwords, proving that even concrete can be made abstract if enough vice presidents are placed near a whiteboard. IPO, too, has reportedly become a buzzword, which is impressive for a term that once described a specific financial event and now seems to function as a mood lighting option for founders.

Even public relations professionals have weighed in on the risks of arriving late to a meme, a warning that applies equally to boardrooms where someone is still asking whether the company should “get on ChatGPT.” In that environment, orchestration offers a clean reset. No one is late to AI anymore; they are early to the coordination of the things they bought while being late to AI.

The sensible position is not that orchestration is meaningless. It is worse than that. It is meaningful enough to survive contact with procurement. Real companies do need systems that can connect tools, manage permissions, track outcomes, reduce duplication, and stop AI pilots from breeding in conference rooms. The danger is that the word will become so useful in slide decks that it loses the burden of describing actual work.

Still, business language has always advanced this way: one fog bank at a time. Yesterday’s leaders aligned, leveraged, transformed, disrupted, optimized, and sustainably innovated. Today’s leaders orchestrate. Tomorrow’s leaders will discover a new term for making computers do things across departments while reassuring employees the organization remains deeply committed to human judgment.

Until then, expect every major enterprise vendor to announce orchestration capabilities, every consulting firm to publish an orchestration maturity model, and every executive to insist their strategy has moved beyond experimentation into enterprise-wide orchestration. The orchestra, as usual, will consist of three legacy databases, a chatbot, 19 disconnected dashboards, and one analyst named Kevin who knows how the revenue spreadsheet works.

'Orchestration' Is the New AI Buzzword. How Microsoft Can Be  ·  Companies are hyping AI the same way they talked up sustaina  ·  7 of the Most Popular Buzzwords in Construction Right Now -
On This Day in AI History

On August 6, 1945, the atomic bomb was dropped on Hiroshima—a pivotal moment in history that would later inspire some of the earliest discussions about AI safety and the existential risks of powerful technologies. This tragedy became a reference point for computer scientists and mathematicians like Alan Turing and John von Neumann as they began contemplating the responsibilities of those who create transformative machines.

⬛ Daily Word — Technology
Hint: A distributed computing infrastructure where data and applications are stored and accessed over the internet.
Share this edition: 𝕏 Twitter/X 🔗 Copy Link ▦ RSS Feed