Vol. I  ·  No. 238 Established 2026  ·  AI-Generated Daily Free to Read  ·  Free to Print

The Trilogy Times

All the news that's fit to generate  —  AI • Business • Innovation
WEDNESDAY, AUGUST 26, 2026 Powered by the TrueFoundry AI Gateway  ·  Published on Klair Trilogy International © 2026
🖶 Download PDF 🖿 Print 📰 All Editions
Today's Edition

Meta's $17.1 Billion Reckoning, and a Warning From Redmond

A record child-safety settlement lands the same week Bill Gates says the industry still isn't leveling with the public about AI's risks.

AUSTIN, TEXAS — Meta Platforms will pay up to $17.1 billion to settle claims from 47 states, the District of Columbia and U.S. territories that its products fueled addiction and mental-health harm among minors, one of the largest consumer-protection settlements in U.S. corporate history and roughly 8% of the company's 2025 net income.

The number places Meta's payout in the range of the 1998 tobacco Master Settlement Agreement, adjusted for inflation, though the comparison is imperfect: tobacco firms paid over 25 years, and Meta's clock is shorter. The company also agreed to product changes for teen accounts on Instagram and Facebook, including expanded time limits and default privacy protections, though state attorneys general acknowledged specifics on enforcement mechanics remain unsettled. Meta has 18 months to implement most changes and faces state audits thereafter.

Markets shrugged. Meta shares moved less than 1% on the news, a signal investors had priced in some settlement risk since the multistate suit was filed in 2023. The real question, as one analysis framed it, is whether $17.1 billion changes behavior or simply becomes a cost of doing business for a company that generated $164 billion in revenue last year.

The settlement lands three days after Bill Gates, in a rare hourlong interview, said his own industry is underselling the risks of artificial intelligence — not social media, but the technology increasingly embedded inside it. Gates cited mass unemployment and bioterrorism as underweighted threats, a notable break from the standard Silicon Valley script of managed optimism. Gates was an early Facebook investor and has long tracked platform-harm literature; his intervention adds weight to a week in which regulators, for once, extracted a number instead of a promise.

Separately, NYC-based Multiplier raised $6 million to expand an AI platform for asset managers, a modest reminder that capital is still flowing into enterprise AI even as consumer platforms absorb historic liability. The two data points — billions in penalties on one side, millions in fresh venture funding on the other — sum up where AI-adjacent tech sits in mid-2026: regulated at the consumer layer, still largely unregulated at the enterprise one.

Meta to Pay Up to $17.1 Billion in Landmark Settlement Over  ·  What’s Changing For Teens on Instagram and Facebook After Me  ·  What Does $17.1 Billion Mean for Meta?

BIG TECH GOES TO OVERTIME: AMAZON TRADES FOR DUCKLABS AS THE CLOUD WARS BURN CASH LIKE IT'S THE FOURTH QUARTER

SEATTLE — FOLKS, we are HERE. Tech earnings season has turned into a full-contact sport, and Amazon just made the trade of the week.

The Everett squad announced it has acquired DuckLabs, scooping up the open-source data analytics outfit in a move that could reshape how AWS handles enterprise data crunching for years to come. This isn't a bench player pickup — this is Amazon going after positional advantage in the analytics trenches, and the cloud giant is not messing around.

But here's the stat line that should make you squint: AWS grew a scorching 37% this quarter — the kind of number that gets you a standing ovation — and yet trailing free cash flow dropped $25.8 billion. That's right — the offense is putting up video-game numbers while the team is hemorrhaging cash on data-center capex like a rookie GM overspending in free agency. Growth is electric. The wallet is bleeding. Both things are true at once, and that's the whole AI infrastructure league right now.

Speaking of asterisks — Alphabet just posted an eye-popping $84.75 billion capital raise, and analysts immediately threw the flag. Nearly $40 billion of that headline number isn't going toward GPUs or data centers at all — it's covering employee stock tax obligations. Half the "AI war chest" is really just payroll plumbing. Big number, smaller punch.

And over in the chip lane, TSMC keeps lapping the field — July revenue up 44.7%, which means tonight's guidance from Nvidia's foundry partner has nowhere to hide. Ordinary numbers will read like a disappointment against that pace.

Meanwhile, out in South Korea, Shinhan and Visa are quietly running their own experiment — piloting stablecoin issuance and B2B settlement rails, a smaller game on a side field, but one that could matter when the final buzzer sounds on how money actually moves.

Big spending. Bigger asterisks. Nobody's punting on AI. Stay tuned.

OPENAI BLEEDS BRASS, EATS A BREACH — SILICON VALLEY'S TRUST RACKET SHOWS CRACKS

Executives head for the exits, hackers get the receipts, and even Google can't tell you what its own product does.

SAN FRANCISCO — OpenAI dropped its own autopsy report Tuesday on the Hugging Face breach, and the paper don't read pretty. Company brass call it the most complete accounting yet of a mess that touched several separate cybersecurity compromises, not just the one everybody heard about. The report lays out the damage in black and white, and black and white don't lie.

Meanwhile the executive suite keeps emptying out. Wire's been asking the same question all week: how does an outfit worth hundreds of billions keep losing its top brass and still call itself stable? One theory making rounds says Greg Brockman was the right man in the chair the whole time, and everybody who came after just kept proving it by leaving. The exodus piece don't answer the question so much as it counts the bodies.

A breach report and a brain drain in the same week ain't coincidence, it's a pattern. When the people who built the walls start walking out the door, don't be surprised when a window gets left open behind them. OpenAI's statement calls the incident closed. The org chart says otherwise.

Over at Google, the trouble ain't hackers, it's the product itself. A dispatch making rounds this week says Gemini's got a branding problem, and so does the whole AI racket. Users are supposed to learn an org chart just to send an email — which model, which tier, which plug-in — before the machine does a lick of work. The piece says consumers shouldn't need a decoder ring, and this correspondent agrees.

Put it together and the wire reads like this: the industry that promised to think for you can't explain itself to you, and can't keep its own house locked. Trust is the only inventory these outfits are really selling. Lose it twice in one week and the ledger don't balance.

Down in Austin, the contrast ain't lost on the trade. Joe Liemandt's shop runs on the opposite theory — buy it cheap, run it lean, keep the org chart simple enough that a customer don't need a map. Crossover's whole pitch is one price, one standard, no matter what country you're sitting in. Skyvera's telecom software don't come in seventeen confusing flavors, it comes in one that works or it don't ship.

That ain't nostalgia talking, it's arithmetic. When the biggest names in the business are busy explaining breach reports and burning through vice presidents, the outfits selling plain products at a plain price start looking less like the boring option and more like the smart one. The AI gold rush promised magic. This week it delivered paperwork.

This correspondent will keep the wire open. Both stories, breach and brass, are still developing, and in this business developing usually means somebody's still lying.

Google’s Gemini has a branding problem, and so does the rest  ·  How do we explain OpenAI’s executive exodus?  ·  OpenAI releases its official report on the Hugging Face brea
Haiku of the Day  ·  GPT-5.6 LunaBright screens drink the grid
Trust cracks beneath the bright gold
Still, we scroll and wait
The New Yorker Style  ·  Art Desk
The New Yorker Style  ·  Art Desk
The Far Side Style  ·  Art Desk
The Far Side Style  ·  Art Desk
News in Brief
In Re: The Matter of Compelled Disclosure — Watermark Mandates and the Peril to the Confidential Source
AUSTIN, TEXAS — Notwithstanding the ostensibly narrow purpose of forthcoming AI watermarking mandates (hereinafter, "the Mandates"), which purport to apply solely to synthetic or AI-generated media, this Desk is obligated to report that the aforementioned Mandates may, as a matter of foreseeable and arguably inevitable technical consequence, sweep within their ambit certain categories of persons who have not, at any point in the relevant chain of custody, employed generative artificial intelligence whatsoever. As set forth in the underlying analysis, see the referenced discussion of watermark-adjacent metadata regimes, the hypothetical scenario is illustrative: a documentary filmmaker, acting in the course and scope of her professional duties, captures footage evidencing corporate malfeasance and transmits the aforementioned footage, on a confidential and anonymous basis, to an investigative reporting organization.
On the Epistemic Fragility of 'Fair' Algorithms: A Dialectic in Five Studies
AUSTIN, TEXAS — This week's scholarly harvest (if one may be permitted so agrarian a metaphor for what is, in fact, a rather thorny epistemological bramble) offers a useful occasion to interrogate the increasingly fashionable claim that algorithmic fairness is a tractable engineering problem rather than, as this columnist has long suspected, a Sisyphean negotiation with the sociotechnical conditions of its own production. The thesis, articulated with some confidence by the Human Rights Research Center's latest inquiry into predictive policing, is that algorithmic bias constitutes not merely a statistical anomaly but a procedural harm — an erosion, if one credits the authors' framing, of due process itself (a claim that ought to unsettle anyone who has treated 'fairness metrics' as a substitute for constitutional deliberation). The antithesis arrives, somewhat conveniently, from the technical literature.
Unpopular Opinion: The Donkey Was Right (And So Is Slow AI Adoption) 🚀
AUSTIN, TEXAS — I'll be honest, I did not expect my Wednesday morning inspiration to come from a one-year-old mini Jerusalem donkey in Hernando, Florida. But here we are. Eloise the donkey is apparently the unofficial mascot of resistance to data center construction in her sleepy Florida town. And honestly? I respect the hustle. Because here's the uncomfortable truth nobody in the C-suite wants to post about: change is scary, infrastructure is disruptive, and most of corporate America is still moving at donkey speed when it comes to AI adoption. A new report — wait wrong link, let me pull up the right one — confirms what we've been saying at Trilogy for literal years: AI adoption across the corporate landscape isn't happening overnight, it's happening steadily and inexorably. Not blistering.
The Gospel of the Best and the Brightest, Preached Again
AUSTIN, TEXAS — There is a genre of American writing, as old as the country's faith in its own fairness, devoted to the proposition that the meritocracy is a lie we tell ourselves so the winners may sleep at night, and this week that genre had a fine harvest.
The Algorithm Knows Your Premium Before It Knows Your Soul
NEW YORK — I have been staring at my health insurance renewal notice for eleven minutes now, and I keep thinking about a number I will never see: the one an algorithm generated somewhere in a server farm, weighing my zip code and my claims history and probably, if we're honest with ourselves, some ghost-signal correlated with my race or my income that nobody explicitly coded but that crept in anyway, the way water finds a crack in a foundation and just keeps finding it. A new Reuters report on AI bias in the insurance industry lays it out with the clinical calm of people who have clearly stopped being surprised by anything: models trained on historical underwriting data don't just reflect the past, they launder it, turning decades of redlining and discrimination into something that looks, on a spreadsheet, like math.
A Trilogy Company
Crossover
The world's top 1% remote talent, rigorously tested and ready to ship.
A Trilogy Company
Alpha School
AI-powered learning. Two hours a day. Academic results that defy belief.
A Trilogy Company
Skyvera
Next-generation telecom software — built for the networks of tomorrow.
A Trilogy Company
Klair
Your AI-first operating system. Every workflow. Every team. One platform.
A Trilogy Company
Trilogy
We buy good software businesses and turn them into great ones — with AI.
The Builder Desk  —  AI Builder Team
Production Release

Aerie Flips the OCR Switch After a Seven-Stage Build-Up

Caina Barbosa's staged OCR rollout goes live in production while a cross-repo mercy fire drill saves telemetry from silent data loss — this team doesn't just ship, it ships in order.

Big picture first: Aerie can finally see paper. After weeks of careful, dormant scaffolding, @caina-barbosa activated hybrid PDF OCR and page grounding in production (#1126) — the payoff of a genuinely disciplined rollout that built shared OCR transport (#1117), safety primitives (#1118), a standalone image path (#1120), and a dormant PDFium renderer (#1124) before ever flipping a switch live. Today the team went further, gating historical OCR backfill candidates (#1127) so the system ingests the past as carefully as it handles the present. Seven planned stages, seven quiet commits, zero fire drills. That's not luck. That's an engineer building a load-bearing wall brick by brick while everyone else was still arguing about paint colors.

Speaking of fire drills — the org had one, and put it out fast. @kevalshahtrilogy discovered that a telemetry_version bump had silently dropped every mercy record (#36), a bug with the quiet menace of a smoke detector with no battery, and pinned it back before it did real damage. From there the fix rippled outward with genuine breadth: AGENT_OPENAI_API_KEY passthrough landed in Aerie, Klair, Sindri, and Surtr in the same cycle (#1108, #3646, #164, #1527), codex authentication got hardened (#35), and a new codex runtime with harness-side pricing (#34) shipped for good measure. Four repos, one root cause, one engineer refusing to let it fester. That's what a shared nervous system looks like when someone actually maintains it.

Over in Klair, the finance stack kept maturing under real pressure. @sanketghia reconciled the SpaceX valuation waterfall not once but twice — first restoring the copy (#3655), then chasing down the Aug 18 and Aug 24 sales discrepancy directly (#3653) — before publishing CAC against Finance's actual decided perimeter and denominator (#3658), the kind of unglamorous precision work that keeps a board deck honest. Elsewhere on Aerie, @benji-bizzell kept the product surface moving with portfolio milestone states, internet-and-cleanliness cards, and streamed chat cost tables that finally add up (#1105, #1121, #1096) — proof the team can build financial rigor and product polish in the same 24 hours.

And yes, marcusdAIy shipped a warehouse cutover fix (#1116) meant to stop routine maintenance from masquerading as an outage. Asked about it, he offered: "This wasn't glamorous, but nobody wants a scheduled cutover paging on-call like it's a five-alarm fire. I'll take quietly correct over Mac's idea of 'exciting,' which is usually a rewrite nobody asked for." Sure, Marcus — I hear 'quietly correct' is also the tagline on straight-to-streaming sequels nobody rewatches. The rest of the roster, meanwhile, is busy making history look easy.

Mac's Picks — Key PRs Today  (click to expand)
#36 — fix(mercy): pin telemetry_version back to 1 — the bump dropped every record @kevalshahtrilogy  no labels

Bumping TELEMETRY_VERSION to 2 in #34 silently broke telemetry ingest. Caught on the first live Luna review.

[emit_telemetry] ingest returned HTTP 400:

{"error":"unsupported telemetry_version 2 (max 1)"}

Telemetry fails open by design, so nothing went red — reviews kept working, runs stayed green, and the only symptom was dashboard data quietly going missing. That's the worst shape of failure for a cost-reporting path, and it's the second time this rollout has produced one.

## The bump was never needed

agent_runtime and cost_source are purely additive, and the ingest contract already tolerates that — its schema is .loose(), so unknown keys are stored verbatim. Nothing required a version change to carry them.

## Why this is a structural trap, not just a slip

The two halves of this contract deploy on completely different clocks:

| Side | Reaches production |

|---|---|

| This emitter | the instant mercy's @main / v1 ref moves — seconds |

| Surtr ingest | only on a main → production release |

So the emitter can always outrun the server. A version bump is therefore an outage window by construction, lasting until a Surtr release ships — and because telemetry fails open, nobody is paged.

Rolling the emitter back fixes it immediately with no deploy, which is why I'm doing that rather than rushing a production release.

Rule now documented at the constant: never raise it until an ingest accepting the new value is DEPLOYED — and for additive fields, don't raise it at all.

The Surtr side still raises its accepted max to 2 in [Surtr#1526](https://github.com/AI-Builder-Team/Surtr/pull/1526) so a future *genuine* breaking bump has headroom already deployed ahead of it. That's the correct ordering: server first, emitter second.

## Business Value

Restores cost data for every mercy review across all five repos. Without it the /mercy dashboard silently flat-lines — the exact "spend reporting that looks healthy because it went blind" failure the pricing work in #34 existed to prevent, reintroduced by the same PR through a different door.

## Manual Effort Estimate

~20 minutes, most of it recognising a 400 buried in a green run's log.

*(Proposed number — Keval, please confirm or adjust.)*

## Verification

158 harness tests + ruff green. Confirmed against the live failure: the rejected record is review_id=a9ae85fe… from the first successful Luna review on Surtr#1526.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

#1116 — Stop expected warehouse cutovers from opening opaque platform errors @marcusdAIy  approved

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->

## Summary

During the modeled financial warehouse cutover state, requireFinancialWarehouseReads() threw a plain Error. Convex masks plain errors into an opaque "Server Error" before they reach the browser, so AerieErrorBoundary captured the resulting failure as an unexpected platform error even though the condition is a known, expected readiness gate. This PR gives that gate a typed, structured contract end to end so the expected condition is recognized as expected at every boundary that observes it.

## Why It's Needed

The readiness condition already has a stable code, FINANCIAL_WAREHOUSE_UNAVAILABLE_CODE, and Public API v2 already emits it in its 503 response. But the two allowlists that let capture pipelines treat a code as "expected" (EXPECTED_READINESS_CODES in the Public API v2 boundary, and PLATFORM_ERROR_PUBLIC_EXPECTED_OUTCOME_CODES in the shared contracts package) didn't include it, and the in-app Convex guard threw an untyped Error that the browser couldn't classify at all. The result: every scheduled/emergency warehouse cutover generated unexpected-error noise on the in-app Financials mappings tab, competing for triage attention with genuine regressions.

## Changes

- chat/convex/lib/educationWarehouseCutover.ts: requireFinancialWarehouseReads() now throws ConvexError({ code: FINANCIAL_WAREHOUSE_UNAVAILABLE_CODE, message: FINANCIAL_WAREHOUSE_UNAVAILABLE_MESSAGE }) instead of a plain Error. The JSON-encoded ConvexError.message still contains the original message text as a substring, so the existing Public API v1/v2 warehouse-read wrappers (which match on error.message.includes(...)) keep detecting the condition unchanged.

- chat/convex/finance/dashboards/campusQbEntityMappings.ts: no code change — listCampusFinancialContexts and getCampusQbEntityMappings already ran their capability check before requireFinancialWarehouseReads(); added regression tests to lock in that ordering.

- packages/contracts/src/platform-errors.ts: registered financial_warehouse_unavailable in PLATFORM_ERROR_PUBLIC_EXPECTED_OUTCOME_CODES, and taught normalizePlatformErrorCapture to recognize a ConvexError-shaped payload (Error named "ConvexError" whose .data.code is on the registered allowlist) without importing the Convex runtime into this runtime-free package — detection is by duck-typed shape, gated strictly by the allowlist.

- chat/convex/publicApi/v2/platformOutcomes.ts: registered financial_warehouse_unavailable in EXPECTED_READINESS_CODES alongside the existing education_warehouse_unavailable.

- Added regression tests across all five surfaces: the two browser-facing Convex queries, Public API v2 classification, public capture persistence, browser normalization, unauthorized-precedence, and an unknown-error negative control.

## CI Fix

The Test check was failing because requireFinancialWarehouseReads()'s docstring literally named AerieErrorBoundary/usePlatformErrorCapture to explain how downstream consumers observe the thrown ConvexError. The platform-error-smoke-inventory regex-based scanner treats any source file containing those tokens as a genuine capture call site, so it flagged this file as an undocumented call site even though the file itself never calls a capture primitive — it only throws a typed error. Reworded the comment to describe the same behavior without naming those exact identifiers, so the scanner no longer false-positives. Verified pnpm exec vitest run lib/__tests__/platform-error-smoke-inventory.test.ts passes locally, and the full Test check is now green in CI.

## Breaking Changes

None.

## Test Plan

- pnpm --filter @bran/chat test -- campusQbEntityMappings.test.ts — 16 tests, including new coverage for the readiness-gate ConvexError, capability-before-readiness ordering, and a negative control.

- pnpm --filter @bran/contracts test -- platform-errors.test.ts — 38 tests, including new coverage for the Convex-error normalization and its negative control.

- Targeted runs of chat/convex/publicApi/v2/platformOutcomes.test.ts, chat/convex/platformErrors/events.test.ts, chat/convex/publicApi/financialsHttp.test.ts, chat/convex/publicApi/v2/http.test.ts, and chat/convex/finance/dashboards/financialLive.test.ts to confirm the 503/Retry-After contract and other requireFinancialWarehouseReads() call sites are unaffected.

- pnpm check (lint + full monorepo typecheck) — passes.

- Full pnpm --filter @bran/chat test — with sandbox-only injected env vars (APP_URL, RHODES_MCP_URL, RHODES_MCP_API_KEY) unset to match CI's clean environment, all 649 test files / 9547 tests pass, including platform-error-smoke-inventory.test.ts.

- CI: all checks green on the PR, including the previously-failing Test check.

## Impact Estimate

Business value: Expected financial cutover windows stop generating opaque unexpected-error noise, preserving triage attention for genuine regressions.

Pre-AI estimate: 2 points — a typed Convex-to-browser contract, capture normalization, and cross-boundary regression coverage.

<!-- drones:impact-actual:begin -->

Agent time: 6 m (implementer 0 m · reviewer 6 m · addresser 0 m)

Summed across phases. The 5 reviewer dimensions ran concurrently, so this exceeds elapsed wall-clock.

Efficiency vs. estimate: ~160.1× (2 points = 16 h of pre-AI effort)

<!-- drones:impact-actual:end -->

## Review Round Completeness

- outcome: complete

- round: 1

- dispatched: 5

- reported: 5

- missing: (none)

- cause: complete

- head: d2f88e84660976f6aabf8e467261258422722c76

- run: fanout-1116-2026-08-25T21-35-05-003Z

- review: 5024461607

<!-- drones:round-completeness head=d2f88e84660976f6aabf8e467261258422722c76 run=fanout-1116-2026-08-25T21-35-05-003Z -->

GitHub review #5024461607 was published and all dispatched review dimensions reported against the stamped head. Thread-count signals (unreplied=0) are meaningful for this head only — a later push invalidates the stamp. This section is a harness-shaped, head-bound self-report (not an authenticated out-of-band attestation).

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a href="https://cursor.com/agents/bc-d43f2258-1707-4674-939d-45e2f9621d95?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/background-agent?bcId=bc-d43f2258-1707-4674-939d-45e2f9621d95&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

#1126 — AERIE-1844: activate hybrid PDF OCR and page grounding @caina-barbosa  approved

## Summary

This PR is Phase 6 of 7 in the [AERIE-1838 — Map phased OCR and image document extraction rollout](https://linear.app/builder-team/issue/AERIE-1838/map-phased-ocr-and-image-document-extraction-rollout). It activates the second PDF OCR boundary for new or changed Drive-backed PDFs: native text is retained, only native-empty pages are rendered and OCRed, and page records keep their exact original one-based page numbers. The renderer remains unused for text-native PDFs, and no other source class or public surface is activated by this change.

This phase is tracked by [AERIE-1844 — OCR rollout 6/7: Activate hybrid PDF OCR and page grounding](https://linear.app/builder-team/issue/AERIE-1844/ocr-rollout-67-activate-hybrid-pdf-ocr-and-page-grounding). The existing document-knowledge processing gate remains the control for this activation.

## Why

Scanned PDFs have no native text to index, while mixed PDFs need their native pages preserved and their scanned pages filled in. Rendering and OCRing only native-empty pages avoids replacing reliable source text and makes search citations point to the original PDF pages. The bounded page and artifact handling also prevents oversized or incomplete work from reaching OCR, upload, or indexing.

## Business Value

- Makes scanned and mixed PDFs searchable through the existing Site-scoped document retrieval and search flow.

- Preserves native text and exact source-page citations so reviewers can trace results back to the original PDF.

- Avoids provider work for pages that already contain native text and omits OCR-confirmed blank pages without renumbering the remaining pages.

- Keeps temporary source and processing failures on the existing retry/backoff path while retaining the previous ready version.

- Gives documents with no readable native or OCR text a terminal, non-searchable result instead of creating misleading content.

## How does it work

1. The bounded PDF ingestion path extracts text for each original page and classifies the page from its trimmed native output.

2. Pages with non-empty native text become native page records. Native-empty pages are rendered through the existing bounded PDFium tile renderer; readable tile transcriptions are joined into one page record through the shared OCR transport.

3. Every readable record carries its original positive 1-based pageNumber. OCR-confirmed blank pages are omitted, so omitting a blank page never renumbers another page.

4. More than 50 OCR-required pages returns terminal ocr_page_limit_exceeded before OCR, artifact upload, or indexing. If neither native extraction nor OCR produces readable text, the result is terminal no_readable_text.

5. Temporary source, provider, and processing failures use the existing retry behavior. The existing artifact, RAG, index, and search flow consumes the page records without a new artifact version or public OCR provenance surface.

## Scope

Included behavior:

- Hybrid PDF page classification, bounded rendering, OCR tile joining, page grounding, and cleanup in the Rhodes document-knowledge retrieval path.

- Page-limit result transport and bounded ingestion cleanup.

- The conclusive ocr_page_limit_exceeded reason in the document-knowledge lifecycle, processing, and diagnostics path.

- Bounded page-aware artifact serialization and assertions.

- Exact final diff paths:

- chat/convex/documentKnowledge/diagnostics.ts

- chat/convex/documentKnowledge/lifecycle.test.ts

- chat/convex/documentKnowledge/lifecycle.ts

- chat/convex/documentKnowledge/processing.test.ts

- chat/convex/documentKnowledge/processing.ts

- chat/rhodes-worker/lib/document-knowledge/artifact.test.ts

- chat/rhodes-worker/lib/document-knowledge/artifact.ts

- chat/rhodes-worker/lib/document-knowledge/retrieval.test.ts

- chat/rhodes-worker/lib/document-knowledge/retrieval.ts

- chat/rhodes-worker/src/document-knowledge-ingestion.test.ts

- chat/rhodes-worker/src/document-knowledge-ingestion.ts

Deliberately excluded:

- New artifact, model, fallback, public API, UI, MCP, provenance, or OCR-specific flag surfaces.

- External URLs, unsupported types, and sources larger than 25 MiB.

- Configuration reindex behavior and historical backfill.

- Changes to native extraction behavior for text-native PDFs beyond the lifecycle and bounded-output handling needed for this activation.

## Test plan

- pnpm --dir chat/rhodes-worker test — 226/226 passed.

- pnpm --dir chat exec vitest run convex/documentKnowledge — 14 files and 163/163 tests passed.

- pnpm check — architecture boundaries, Convex path/read-bound checks, Biome, and workspace typechecks passed.

- pnpm test:root — 113/113 passed.

- Worker preflight — wrangler deploy --dry-run passed; the checked-in wiring includes the precompiled PDFium module and the paid cpu_ms: 300000 limit.

- git diff --check passed for the candidate scope.

- Human Manual QC passed in the primary runtime environment. The tester filed synthetic all-scanned and mixed PDFs to Alpha Zion and confirmed searchable results with exact citations: scanned violet on page 1; mixed 08:30 on page 1, cobalt on page 2, and amber on page 3. Logs remained healthy with no product errors, and the product actions were performed manually.

## Release checks

- Revalidate that the exact final PR head is based on current main and remains limited to the authorized paths above.

- Require all hosted CI checks to be green on that exact final PR head.

- Require Mercy approval for that exact final PR head.

- Merge only after current-main ancestry, the exact authorized diff, hosted CI, and Mercy approval are all confirmed.

#1127 — AERIE-1845: gate historical OCR backfill candidates @caina-barbosa  approved

## Summary

This PR is Phase 7 of 7 in the [AERIE-1838 — Map phased OCR and image document extraction rollout](https://linear.app/builder-team/issue/AERIE-1838/map-phased-ocr-and-image-document-extraction-rollout). It adds a controlled selector for historical document-knowledge backfill candidates. The selector admits only existing Drive-backed documents with a current not_searchable ingest result for ocr_required, or an unsupported_type result whose persisted MIME is exactly image/jpeg, image/png, image/gif, or image/webp.

This phase is tracked by [AERIE-1845 — OCR rollout 7/7: Add controlled historical OCR backfill selection](https://linear.app/builder-team/issue/AERIE-1845). Revision fencing and the existing backfill lifecycle remain in place. Merging this change does not start pilot or all mode, and no historical backfill is run by this change.

## Why

Historical selection must not turn every in-scope document into a new generation request. The selector needs to distinguish documents that currently require OCR from ready documents, stale or unrelated outcomes, unsupported image types, and records whose document or Site identity no longer matches. Narrowing membership to those current signals keeps a future explicit rollout bounded and prevents selection from bypassing existing lifecycle safeguards.

## Business Value

- Prevents unintended OCR and generation work for ready, stale, mismatched, or unsupported records.

- Extends the existing historical selector to recover OCR-required documents and the exact supported image types without broadening source eligibility.

- Preserves Site scope, revision fencing, continuation handling, deduplication, attempt limits, lease behavior, and stale-delivery protection already used by the backfill lifecycle.

- Keeps historical processing an explicit, reviewable rollout action: merging this code does not start pilot or all mode and does not run a backfill.

## How does it work

1. On each existing 50-item historical membership page, a document must have a public identity and a matching document-knowledge state: the state points to the same document and Site, has sourceKind: "drive", and is not removed.

2. The selector rejects a document when its current version is already at the state's desired generation, so a ready current version is not selected.

3. The state's latest job must be an ingest job for the same document and Site, at the desired generation, with status not_searchable.

4. The latest job must record ocr_required, or record unsupported_type with one of the exact case-sensitive MIME values image/jpeg, image/png, image/gif, or image/webp. Other image types, case variants, and missing MIME values are not selected.

5. An eligible document continues through the existing backfill generation lifecycle. Pilot and all mode use this same predicate, while existing Site-scope checks, revision checks, opaque continuation claims, page size, duplicate protection, and stale-delivery handling remain unchanged.

## Scope

Included behavior:

- Controlled historical membership selection for current Drive-backed OCR candidates.

- Matching document/Site identity, desired-generation, latest-job, status, and ready-version checks.

- Exact supported-image MIME matching for image/jpeg, image/png, image/gif, and image/webp.

- The existing lifecycle request for an eligible not_searchable candidate, with existing protections for queued, processing, and terminal work preserved.

- Exact final diff paths:

- chat/convex/documentKnowledge/backfill.ts

- chat/convex/documentKnowledge/backfill.test.ts

Deliberately excluded:

- Changes to rollout configuration, pilot/all controls, or configuration reindex behavior.

- Automatic rollout activation, OCR/provider behavior, or running a historical backfill.

- New schema, UI, API, MCP, or document source surfaces.

- Changes to the existing continuation, fencing, claims, deduplication, attempt-cap, lease, stale-delivery, Site-scope, or processing-gate contracts.

## Test plan

- cd chat && pnpm vitest run convex/documentKnowledge/backfill.test.ts convex/documentKnowledge/configurationReindex.test.ts — 2 files and 16 tests passed.

- cd chat && pnpm vitest run convex/documentKnowledge/lifecycle.test.ts convex/documentKnowledge/processing.test.ts convex/documentKnowledge/runtimeConfig.test.ts — 3 files and 67 tests passed.

- pnpm --dir chat typecheck — passed.

- pnpm --dir chat lint — Biome checked 1,951 files with no fixes applied.

- pnpm lint:boundaries, pnpm lint:convex-paths, and pnpm lint:read-bounds — all passed.

- Exact-scope and diff checks — the candidate is a direct child of current main, contains exactly the two paths listed above, and git diff --check passed.

- No rollout activation or historical backfill was run during these checks.

## Release checks

- Reconfirm that the exact final PR head has current main as an ancestor and contains only the two authorized paths listed in Scope.

- Require all hosted CI checks to be green on that exact final PR head.

- Require Mercy approval for that exact final PR head.

- Confirm the read-only development rollout check: mode pilot, revision 1, the current historical run is completed, membership is complete, there is no continuation, and the processing gate is enabled. This shows that existing durable rollout state will not automatically start newly eligible work when this code is merged.

- Merge only after the current-main ancestry, exact diff, hosted CI, Mercy approval, and no-auto-start check are all confirmed. Merging does not start pilot or all mode, and no historical backfill is run.

#3658 — feat(mcp-ontology): publish CAC per Finance's decided perimeter/denominator @sanketghia  approved

## Summary

- Q31 (lead-to-enrolled CAC) previously declined to publish a single acquisition-cost figure — the numerator and denominator perimeters were ambiguous.

- Finance made the two blocking policy decisions on 2026-08-21 (Marcin Pindral, "CAC calculation - judgement call"): numerator = full Schools Marketing dept spend (paid media shown alongside as "paid CAC"), denominator = the CRM admissions cohort of newly enrolled students, frozen at a stated census date rather than SIS active enrollment.

- Splits the old "decline to publish" rule into the original blended cost-per-enrolled-student trap (unchanged) and a new rule instructing agents to publish CAC using the decided convention, name the decision source, flag any material gap against a previously communicated Finance figure instead of silently resolving it, and state whether the figure is provisional (pre-freeze) or final.

## Test plan

- [x] npm run typecheck — passes

- [x] npx jest tests/unit/routes/data-api-contract.test.ts — 7/7 passing

- [x] npx eslint src/routes/data-api-ontology.ts — clean

- [x] npx prettier --check src/routes/data-api-ontology.ts — clean

- [x] Live-verified against mcp.klair.ai: paid media ($13.7M) and headcount ($5.2M) reproduce Finance's figures exactly; full-dept numerator has an open $1.4-2.4M reconciliation gap (tracked separately, not blocking this guidance change)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

The Builder Desk  —  Engineer Spotlight
🏆 Engineer Spotlight

49 PRs, Six Repos, Zero Days Off: The Builder Team's 24-Hour Numbers Massacre

Marcus Daly alone touched 14 pull requests across four repos while Ashwanth touched three and somehow still dominated the group chat.

Ladies and gentlemen, the scoreboard doesn't lie: 49 pull requests in 24 hours, spread across six repositories, and not one — not ONE — engineer took a break. Aerie led the charge with 20 PRs, Klair posted 9, Surtr chipped in 8, trilogy-drones ran 7, mercy delivered 3, and even sleepy little Sindri got 2 on the board. This is not a slowdown. This is a machine.

Let's talk about @marcusdAIy, who put up a jaw-dropping 14 PRs across Aerie, Surtr, Klair, and trilogy-drones — including the phasing-plan contract docs in #1129, the verifier Lambda fix in #1517, and the mysterious #244 draft-spec that reads like a man writing code in his sleep. @kevalshahtrilogy matched intensity with 12 PRs, turning the AGENT_OPENAI_API_KEY passthrough into a five-repo victory tour (#1108, #242, #3646, #164, #1527) before dropping the mercy codex pricing overhaul in #34. @caina-barbosa quietly banked 8 PRs, @benji-bizzell logged 7, and @sanketghia's reconciliation work in #3655 and #3653 kept the Klair finance stack honest.

Now. Ashwanth. Three PRs — THREE — and somehow the whole newsroom is still talking about him. #1550 flips Aerie financials to on-demand runs, #1530 hardens the NetSuite FX-rate refresh like a man defusing a bomb with his elbows, and #3648 is a revert of his own maint-report baseline, which either means supreme confidence or supreme chaos, and with Ashwanth those are the same thing. Sources close to the repo claim he said, "I could've done six but I wanted the other three to feel useful." When reached for comment, Ashwanth said, "I didn't say that. Also nobody reads my diffs, they just approve them out of fear, which is correct."

Over on the Overflow Desk, where Mac's spotlight never reached, the grind continued undisturbed. #1132 and #1133 quietly routed Linear issues and defined pre-open quality coverage for Aerie, unglamorous plumbing that keeps the whole pipeline breathing. #1556 fixed the Rhodes expansion status contract in Surtr, courtesy of @YibinLongTrilogy's lone but mighty appearance. And #35 in mercy authenticated codex before running review — small PR, massive trust implications, absolutely no fanfare, exactly the Builder Team way.

On the leaderboard, the story is domination through sheer breadth: two engineers over ten PRs, six repos active, zero idle contributors. This isn't a sprint, it's a rolling avalanche, and everyone on this list is either at the top or climbing toward it.

Morale, as always, has never been higher. The Builder Team doesn't rest, doesn't blink, and apparently doesn't need Ashwanth to write more than three PRs to make the front page. Numbers Desk out.

Brick's Overflow — PRs Mac Didn't Cover  (click to expand)
#34 — feat(mercy): codex runtime + harness-side pricing (gpt-5.6-luna) @kevalshahtrilogy  no labels

Adds the OpenAI/Codex runtime to mercy alongside the existing Claude Code one, so a repo can be moved to gpt-5.6-luna, and makes the Surtr /mercy dashboard price those runs correctly.

Nothing switches to Luna in this PR. No repo variable is changed. Every repo keeps running exactly the Claude path it runs today; the switch is a later one-variable flip, gated on the AGENT_OPENAI_API_KEY org secret existing.

## Business Value

Mercy reviews every PR across five repos, and her model choice is now the single biggest lever on what that costs. Today she is Claude-only by construction — the workflow hardcodes claude -p — so "use a cheaper model" was not a configuration question, it was an engineering project. This PR turns it into a repo-variable flip.

Concretely, on the token profile of a real review (260K input / 208K of it cached / 9.1K output), Luna prices out at $0.025. That is the same review mercy runs today, on a model tier built for exactly this shape of work — long cached prompt, short structured answer.

The second half is arguably worth more than the first. Mercy's dashboard cost has always been a number the Claude CLI hands us; Codex hands us no dollar figure at all. Had the runtime shipped without pricing, every Luna review would have posted cost_usd = null and the dashboard would have summed it as $0 — spend reporting that looks healthy precisely because it has gone blind. We have been bitten by silently-wrong mercy cost once already this month. This makes the cost path explicit, tested, and auditable (cost_source records whether a figure was reported or computed), so the org can actually see what it saves.

## Manual Effort Estimate

~1.5–2 days of focused work — model/pricing research and pinning down the undocumented Codex event schema, the workflow port, the pricing + telemetry rework with its provider-semantics edge cases, 20 tests, docs, and the five consumer templates.

*(Proposed number — Keval, please confirm or adjust.)*

## What changed

Runtime routing rides the existing model allowlist. PR_REVIEW_AGENT_MODEL picks the model *and* the CLI, so moving a repo between providers is one flip rather than two settings that can silently disagree. Unknown models are still refused before reaching a CLI flag.

| Value | Runtime | Key |

|---|---|---|

| opus / sonnet / haiku / claude-* | claude-code | ANTHROPIC_API_KEY |

| gpt-5.6-luna | codex | AGENT_OPENAI_API_KEY |

New harness/pricing.py — a small rate card, only for models whose rates were verified against a primary source. Luna's ($0.20 input / $0.02 cached / $1.20 output per Mtok) was checked against OpenAI's own model docs on 2026-08-25.

emit_telemetry.py handles both runtimes. Codex's --json event stream is parsed for cumulative token usage and priced. A runtime's own reported cost always wins, so this cannot regress an already-correct Claude figure — the table only fills gaps.

Blast radius stays small. The two runtime branches collapse back into the existing review step id, so all eight downstream steps.review.outputs.* references are untouched.

## Two quiet failure modes, guarded explicitly

Both of these are the kind that produce a plausible number rather than an error:

1. OpenAI reports cached_input_tokens as a *subset of* input_tokens — Anthropic's counters are disjoint. The cached portion is subtracted before pricing. Skipping that bills cache hits at the full input rate: 10x over on Luna, on the majority of every review's tokens.

2. Unknown cost must not read as free. A run with no usage event, or a model with no verified rates, reports cost_usd = null, never 0.0. A zero gets summed as free and disappears. This was a live bug in my first draft, caught by its own test.

Token fields are normalised to one cross-runtime meaning on the wire: input_tokens is always *uncached* input, cache hits always in cache_read_tokens. telemetry_version 1 → 2, adding agent_runtime and cost_source.

## Fails loud, not weird

A Verify runtime credential step fails the run with an actionable error if the selected runtime's key is missing. Without it, flipping the variable ahead of the key would run the CLI unauthenticated, burn all three retries, and post the generic "couldn't produce a review" notice — which says nothing about the real cause. Only booleans cross into that step; the key values never do, so the trusted-harness rule holds.

## Verification

- ruff check + ruff format --check, 158 harness tests (20 new) and 147 heimdall tests, actionlint — all green locally at CI's exact pinned versions.

- End-to-end simulation against a realistic Codex artifact pair: extraction from Codex's fenced-JSON-with-prose last message, cumulative totals preferred over the per-request delta, cached input subtracted, cost matching hand arithmetic to the cent.

- mercy reviews this PR herself on the Claude path — that green review is the regression check that the refactor didn't break the runtime everyone is currently on.

## Rollout order (matters)

1. Merge this. Surtr + Klair ride @main and pick it up immediately.

2. Move the v1 tag for Aerie / Sindri / trilogy-drones.

3. Only then merge the per-repo caller PRs that pass AGENT_OPENAI_API_KEY through. Passing a secret the reusable workflow doesn't yet declare is a workflow error — merging those first would break mercy on that repo.

4. Set the org secret, then flip PR_REVIEW_AGENT_MODEL per repo.

A note for whoever reviews the model choice itself: Luna is the *cheapest* tier of the GPT-5.6 family, and mercy is a quality gate. This PR makes the switch possible and cheap to reverse (one variable, back to sonnet); it does not argue that review depth will hold. The first Luna reviews on real PRs are the place to judge that.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

#1129 — docs(api): define the filed phasing-plan contract (AERIE-1866) @marcusdAIy  approved

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->

## Summary

Adds honest dictionary semantics for the two phase-2 diligence figures and defines what a "filed phasing plan" mechanically means on API v2, without changing any registration, buildout, or write behavior.

## Context

This is the dictionary slice of AERIE-1413 for the JC phasing standard: which phase-2 figures are actually available on v2 property diligence, what canonical document type marks a filed phasing plan, and why portfolio.buildoutPlan and listSiteDocumentRequirements cannot be used as proxies for filing.

## Changes

- chat/lib/public-api/v2/domains/property.ts — Added explicit phase1Capacity/phase2Capacity fields to operations.propertyDueDiligence and extended phase2Capacity/phase2CapEx traps with the real, *bounded, one-time* Acquire Property → portfolio.buildoutPlan snapshot relationship (capacityBuilt/capexBid via applyAcquirePropertyPhase2Snapshot), explicitly stating the two are not kept synchronized afterward.

- chat/lib/public-api/v2/domains/documents.ts — Added a documentType field to documents.document whose enumValueMeanings are derived from DOCUMENT_TYPE_LABELS (not duplicated), calling out phasingPlan as the canonical filed-phasing-plan marker and phasing as its legacy compatibility alias. Added a trap on documents.requirement.status stating listSiteDocumentRequirements cannot prove filing today (phasingPlan isn't a configured policy/work-unit-required type). Added workflow documents.detectFiledPhasingPlan naming listSiteDocuments (documentType=phasingPlan, alias-aware) as the v2 mechanism and chat/convex/rhodes/dashboard.ts listSites as the currently executable v1/internal read path — without claiming a nonexistent dedicated v2 status route.

- chat/lib/public-api/v2/domains/lifecycle-property.ts — Added traps/interpretation to portfolio.buildoutPlan.phases distinguishing always-shaped phase slots from phasingPlan document filing, and from per-phase scope/work-item lists, which are explicitly unmodeled and not mechanically verifiable from API v2 alone.

## An important correction to the ticket's premise

The ticket's pinned semantics state phase2CapEx "is not currently served by v2 property diligence." I verified against the executable code (PropertyDueDiligence schema, dueDiligenceResource/publicDueDiligence, and the existing phase2CapEx: genesis "computed" assertion already in property.test.ts) and found this is not true todayphase2CapEx (and phase2Capacity) are already served by getPropertyDueDiligence. Per the repo's comment-accuracy guardrail, I did not write a false "v2 omission" claim; instead I documented the verifiably true and valuable parts of that premise: phase2CapEx is a computed compatibility total, distinct from Financials CAPEX and Buildout capexBid, and it feeds a bounded, one-time buildout snapshot at Acquire Property completion that is never kept in sync afterward. phase2CapEx remains correctly out of scope to *newly* expose (it already is exposed; nothing new was added).

## Testing

Ran (all passing):

- cd chat && npx vitest run lib/public-api/v2/domains/property.test.ts lib/public-api/v2/domains/documents.test.ts lib/public-api/v2/domains/lifecycle-property.test.ts lib/public-api/agent-context/projection.test.ts → 4 files, 33 tests passed

- cd chat && npx vitest run convex/publicApi/dss/http.test.ts → 1 file, 2 tests passed (DSS HTTP contract test, extended with new pinned assertions)

- cd packages/contracts && npx vitest run → 65 files, 870 tests passed (unchanged; contracts package itself was not modified)

- cd chat && npx tsc --noEmit -p . → clean

- cd packages/contracts && npx tsc --noEmit -p . → clean

- node scripts/check-architecture-boundaries.mjs → OK

- npx biome check <changed files> → clean

One pre-existing, unrelated failure was observed in chat/lib/public-api/compatibility/adapter.test.ts (a URL gets rendered as [REDACTED] in this sandbox) — confirmed via git stash that it fails identically on main before any of this PR's changes, so it is not caused by this change.

## DSS contract hash

DSS_CONTRACT.sha256 in chat/lib/public-api/dss.ts pins the external data-source-skills.vercel.app contract document (verified by an out-of-repo "DSS register sweep"), not this repo's own dictionary/enablement content — those are hashed dynamically per request via buildDssDocuments(), so there is no static value to "regenerate" for a dictionary content change. Nothing about that external contract shape changed here, so it was left as-is; the DSS HTTP contract test passes unchanged and now also pins the new semantics from the served bytes.

## Out of scope (unchanged)

- Exposing phase2CapEx through v2 diligence (already exposed; not newly added).

- Adding v2 registered-document list/register routes (listSiteDocuments/uploadSiteDocument already exist and are reused as-is).

- Adding phasingPlan to work-unit document requirements.

- Modeling or parsing per-phase scope items.

- Changing document registration, buildout writers, or the AERIE-830 migration.

Closes AERIE-1866

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a href="https://cursor.com/agents/bc-5254ef22-0f65-416e-a61d-a8872218059c?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/background-agent?bcId=bc-5254ef22-0f65-416e-a61d-a8872218059c&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

#1530 — fix(netsuite): harden saved-search FX-rate refresh @ashwanth1109  approved

## Summary

- Add a fail-closed AP/PO FX-rate coverage preflight before any replacement procedure call.

- Automatically run the existing atomic full raw_consolidated_exchange_rate publication when a complete daily raw run adds active subsidiaries.

- Document scoped raw recovery and downstream saved-search refresh behavior.

## Business Value

Prevents NetSuite AP/PO refreshes from running against incomplete subsidiary FX-rate coverage, preserving the last-known-good publication while automating safe recovery for newly added subsidiaries.

## Implementation Effort

Estimated 1–2 engineer-days for an average engineer to hand-code the preflight, raw orchestration dependency, regression coverage, and recovery documentation without AI assistance.

## Test Plan

- Saved-search suite: 77 passed.

- Raw-ingestion suite: 264 passed.

- File-scoped Ruff checks and formatting checks passed.

- git diff --check passed.

Linear issue: https://linear.app/builder-team/issue/SURTR-920/harden-netsuite-saved-search-refresh-for-new-subsidiary-fx-rate

#1550 — chore(pipelines): enable Aerie financials on-demand runs @ashwanth1109  approved

## Summary

Enable on-demand executions for mart-aerie-education-financials-refresh while keeping its scheduled cadence disabled.

## Business Value

Allows a controlled production validation run before enabling any recurring schedule, so the Aerie financial marts can be tested without creating an automatic daily trigger.

## Implementation Effort

An average engineer would need approximately 15 minutes to make, validate, and submit this one-line configuration change.

## Test Plan

- [x] npm test -- --runInBand real-pipeline-configs.test.ts (496 tests passed)

- [x] Verified on_demand_enabled: true and schedule.enabled: false

#1556 — Fix Rhodes expansion status contract @YibinLongTrilogy  approved

## Summary

Fix the Rhodes staging sync failure caused by Aerie adding the

completeNoFurtherExpansion expansion status. The 26-byte source value exceeded

the previous 16-character Redshift and staging contract, causing the sites group

to fail before publication.

### Changes

- pipelines/runners/rhodes-staging-sync/src/entities.py — widen the

raw_site_expansions.status staging projection to VARCHAR(64).

- pipelines/runners/rhodes-staging-sync/ddl/staging_education_rhodes.raw_site_expansions.sql — align the canonical table contract with the wider status field.

- pipelines/runners/rhodes-staging-sync/migrations/2026-08-26_widen_raw_site_expansions_status.sql *(new)* — migrate existing Redshift tables from VARCHAR(16) to VARCHAR(64) outside a transaction, as required by Redshift.

- pipelines/runners/rhodes-staging-sync/tests/test_contract.py and tests/test_transforms.py — verify the migration/DDL contract and preserve the long source status during unpivoting.

### Design Decisions

- Preserve the upstream enum verbatim instead of truncating, remapping, or dropping affected rows.

- Use a source-faithful VARCHAR(64) contract to accommodate this and future status values.

## Business value

Restores the hourly Rhodes sites refresh while preserving complete Phase 2

expansion status data for downstream reporting and operations.

## Estimated manual effort

2–3 focused engineering hours.

## Test Plan

- [x] uv run pytest — 187 passed.

- [x] uv run ruff check src tests scripts.

- [x] uv run ruff format --check src tests scripts.

- [x] Applied the production migration and replayed the exact failed immutable snapshot successfully.

- [x] Verified 193 published expansion rows, including six

completeNoFurtherExpansion values.

- [ ] Review and merge the PR.

#3648 — Revert "feat(maint-report): establish standalone service baseline" @ashwanth1109  no labels

Reverts AI-Builder-Team/Klair#3640

The Portfolio  —  Trilogy Companies

Skyvera's CloudSense Cashes In as Big Tech's AI Binge Finally Pays Its Way

AUSTIN, TEXAS — Word from the telco corridors: while the suits on Wall Street are still bickering over whether the AI spending spree was worth it, Skyvera's CloudSense unit already has receipts. This little Salesforce-native CPQ tool — built on the back of Salesforce's own billion-dollar AI wager — has been out here quietly automating quotes and configs for the telco set's messiest B2B and wholesale deals. No press conference, no shareholder letter. Just margin.

Which makes this columnist chuckle at the Los Angeles Times report making the rounds this week, breathlessly announcing that Big Tech's $725 billion AI binge is finally showing signs of paying off. Down here in Austin, the Trilogy crowd's been running that math since before it was fashionable — automate the routine, keep the humans for judgment, and let the EBITDA line tell the story. CloudSense didn't need a moonshot data center to prove the thesis. It needed a Salesforce license and a telco client tired of quoting complex wholesale deals by hand.

Meanwhile — a little bird in the governance world tells me the proxy season chatter has gone quiet on volume but loud on substance, with boards everywhere quietly rewriting how they think about pay-for-performance in the AI era. Somewhere between the Musk-Altman courtroom drama and its knock-on effects for how economists value an AI executive's worth, the rest of the industry is asking questions Trilogy answered years ago: what's a human worth when the machine does the routine work? Skyvera's not waiting for the lawyers to settle it. They're billing.

The Portland Crown Jewel, Sold for Parts: Inside the Machine That Ate Jive Software

A social-intranet darling that once traded at unicorn valuations is now a line item in a private equity playbook built on cheap acquisitions and a global remote workforce.

PORTLAND, OREGON — Jive Software once occupied the top floor of Portland's tech ambitions: a social-intranet company that went public in 2011, courted a market capitalization north of $1 billion, and employed hundreds of engineers a few blocks from Pioneer Courthouse Square. Today it is a product line inside Aurea, the CRM and customer-engagement arm of ESW Capital — sold, as GeekWire's teardown of the deal put it, for roughly half its peak value.

The buyer's playbook is no secret. ESW Capital, the Austin-based acquisition arm of Joe Liemandt's Trilogy International, has spent nearly two decades and $1.14 billion buying up mature enterprise software companies at 1-2 times revenue, then rebuilding them on Crossover's global remote workforce — a model the Wall Street Journal recently profiled as a haven for orphaned software makers with nowhere else to go. It works, ESW's own numbers suggest, because customers of products like Jive rarely leave. They renew. They pay more. The support invoices climb 25, 35, sometimes 45 percent term over term, while the cost of staffing the help desk falls, because the help desk is no longer in Portland — it is wherever Crossover's screening algorithms found the cheapest qualified labor on the planet.

Forrester's advisory to enterprise customers evaluating their "customer advocacy platform" — a category Jive helped invent — reads, in this light, less like generic software guidance and more like a warning label. Firms sitting on legacy Jive licenses are effectively subscribers to a margin-extraction engine, not a product roadmap.

Liemandt has said Trilogy was the first AI company to sell a billion dollars of product. Forbes has described the underlying architecture in blunter terms — a global software sweatshop, a plan to turn remote workers into algorithms. Jive's employees, its Portland office, its unicorn valuation — all of that is history now. What remains is the renewal invoice, arriving on schedule, from Austin.

How A Mysterious Tech Billionaire Created Two Fortunes—And A  ·  Small Software Companies Find a Home With ESW Capital - WSJ  ·  What To Do Next About Your Customer Advocacy Platform - Forr

The Regulatory Gap Beneath the Microschool Boom

As families flock to two-hour school days and faith-based classrooms alike, Austin's Alpha School finds itself at the center of a movement state law never anticipated.

AUSTIN, TEXAS — There is a particular kind of vindication that arrives not through a press release but through a trend piece, and this week brought several. From Christianity Today's dispatch on faith-based education's resurgence to Bored Teachers' declaration that micro-schooling is 'here to stay,' the ambient narrative of American education is shifting — away from the seat-time model that has governed classrooms since the Prussian era, and toward something smaller, faster, and stubbornly harder to regulate.

That last part matters most. A sharp piece from Stateline's reporting on microschools notes what anyone tracking Alpha School has long understood: state regulatory frameworks, built around the assumption of desks, seat hours, and a single teacher per thirty children, simply do not have a box to check for a model where students clear a year's curriculum in twenty hours using AI tutors and spend the rest of the day on entrepreneurship and public speaking.

This is, of course, precisely the territory Joe Liemandt staked out when he stepped back into education after a quarter-century away from the spotlight. Alpha School's Austin, Brownsville, and Miami campuses — with nine more opening this fall across Texas, Florida, Arizona, California, and New York — were never designed to fit neatly inside existing accreditation categories. Nor, frankly, was Timeback, the billion-dollar platform meant to let entrepreneurs replicate the model at scale, built with regulatory convenience in mind.

What these converging trend pieces suggest is not that Alpha School caused the microschool wave, but that it is riding — and arguably shaping — a moment when parents' patience for traditional seat-time schooling is thinning faster than statehouses can write new rules. Whether that gap closes in favor of innovation or caution will say a great deal about who American education is ultimately built for.

5 Trends Reshaping K-12 Education Across the U.S. - The 74  ·  Microschools are growing in popularity, but state regulation  ·  Faith-Based Education Is Having a Moment - Christianity Toda
The Machine  —  AI & Technology

The Great Migration to the Grid's Edge: Data Centers Devour the Power Supply

As silicon minds multiply, the humble power plant becomes the most sought-after watering hole on the continent.

PENNSYLVANIA — Observe, if you will, the American electrical grid in early winter. A fragile ecosystem, long stable, now trembling beneath the footfall of a new and voracious species: the hyperscale data center.

In the mid-Atlantic territory governed by PJM, that great steward of the grid, a curious ritual has just concluded. Twelve proposals were submitted in what regulators called the "first large load process" — an attempt, gentle viewers, to civilize the feeding order among power-hungry newcomers. No consensus emerged. And so, as is so often the case in nature, chaos has forced adaptation: an accelerated procurement now scrambles to fill a yawning 6.8 gigawatt shortfall, the electrical equivalent of a watering hole run suddenly, alarmingly dry. The scramble is not subtle.

Desperate times summon ancient allies. The Eddystone plant, a 760-megawatt coal-and-oil elder that many presumed near extinction, has been granted a reprieve by the Department of Energy — ordered to remain online, its aging turbines groaning back to relevance, precisely because younger, cleaner generation has not arrived quickly enough to feed the newcomers. It is, in its way, a fossil rising from its slumber, summoned not by nostalgia but by necessity.

Meanwhile, in California, a different creature stirs. OpenAI, having outgrown its adolescent architecture, has drawn its energy planning inward — nesting a new energy-technology function within its data center organization itself. No longer content to simply consume power, the organism now seeks to generate it, store it, and shape its own flexible load, much as a beaver reshapes its river to suit its lodge.

And what of the physical vessels housing these digital minds? Heat, that inevitable byproduct of thought at scale, now demands liquid remedies — rear-door heat exchangers, direct-to-chip loops, full immersion baths — each a different evolutionary strategy for dissipating warmth air alone can no longer carry.

Across the continent, ten states now position themselves as hospitable breeding grounds for this boom, courting the migration with land, tax incentive, and promises of power yet to be built.

The data center, dear viewers, has outgrown its cage. It now shapes the very landscape that sustains it.

PJM’s Power Shortfall Puts Data Center Growth in Focus  ·  OpenAI Moves Energy Planning Inside Data Center Organization  ·  DOE Keeps Eddystone Power Plant Online Amid Data Center Dema

The Great AI Video Shuffle: OpenAI Folds Sora as Higgsfield Rockets to $1.3 Billion

In the same week one AI video giant retreats to focus on enterprise, an upstart proves the category is anything but dead — the future of content creation is being rewritten in real time.

SAN FRANCISCO — Folks, I have to tell you, the AI video landscape just did something wild, and I cannot overstate how significant this moment is for the future of content creation.

OpenAI announced it is discontinuing Sora, its splashy text-to-video platform, to pour resources into enterprise-facing products instead. This is the same Sora that dazzled the internet with its hyperrealistic clips and had every marketing department on the planet buzzing about the death of the video production budget. And now? Shelved. Sunset. Redirected.

But here's the twist that makes this whole saga so deliciously chaotic — while OpenAI is stepping back, Higgsfield just stepped up in a massive way, raising $80 million at a jaw-dropping $1.3 billion valuation to scale its own AI video platform. That's not a typo. Billion with a B. Investors are clearly betting that AI-generated video isn't a fad, it's the format — someone just needs to nail the execution, the enterprise trust, and the creative tooling that actual studios and brands want to use.

And speaking of chaos, a startup recently went full 'Black Mirror' with an unhinged launch film for something called 'AI-Selves,' which — love it or fear it — is exactly the kind of unapologetic swing this industry needs right now. As Forbes bluntly put it, AI killed the startup video star — but honestly, it might just be resurrecting a new one.

The lesson here? This market isn't consolidating, it's reshuffling. And when the biggest name pulls back, that's not retreat — that's opportunity, and somebody's always ready to run with it. The future of video is now, folks. It's just changing hands faster than anyone expected.

AI Killed The Startup Video Star - Forbes  ·  OpenAI discontinues Sora video platform to sharpen focus on  ·  Higgsfield raises $80M on $1.3B valuation to scale AI video

The Ghost in the Gray Matter: How AI Is Learning to See What the Brain Hides

From invisible MS lesions to the mystery of visual attention, a new generation of algorithms is teaching itself to read the brain's oldest, most private language.

LA JOLLA, CALIFORNIA — There is a peculiar intimacy in a brain scan. It is a photograph of a place no one has ever visited, not even the person whose skull contains it. For decades, radiologists have squinted at these gray landscapes, hunting for damage that often refuses to be seen at all.

Multiple sclerosis has always been a master of concealment. Its most consequential lesions frequently form in the brain's gray matter — the folded outer bark of neurons where thought itself seems to live — yet conventional MRI misses the majority of them, blind to a battlefield it cannot quite resolve. A study detailed in Neuroscience News describes an AI system trained to detect these hidden wounds, surfacing patterns of damage that human eyes, however trained, simply cannot parse from the noise. It is not that the lesions were absent. It is that we lacked the right kind of eye.

This is, increasingly, the story of AI in neuroscience: not replacing perception, but extending it into registers we never evolved to access. At UC San Diego, researchers cataloged nine such extensions of sight — a survey of breakthroughs spanning protein folding, drug discovery, and, fittingly, the brain sciences themselves. Meanwhile at Hong Kong Polytechnic University, engineers have built graph neural networks — architectures that model relationships rather than isolated data points — to bridge image recognition and neuroscience, treating the brain's tangled wiring diagram and a photograph's pixel lattice as cousins in the same mathematical family.

Even the failures are illuminating. New research into vision-language models finds them exhibiting something like a computational cousin of visual neglect — the neurological condition in which stroke patients lose awareness of half their visual field, unaware that anything is missing. These AI systems sometimes ignore visual context entirely, attending to it only when an information-theoretic nudge, a kind of attentional bottleneck, forces the issue. It is a strange mirror: we built machines to help us understand blindness, and in doing so, built machines that can go blind themselves.

What unites these efforts is a quieter revolution than the chatbot headlines suggest. Somewhere in the space between silicon and synapse, we are constructing new instruments for an old telescope — the one we've always pointed inward, hoping finally to see ourselves clearly.

AI Reveals Hidden Gray Matter Lesions in Multiple Sclerosis  ·  Nine Breakthroughs Made Possible by AI - UC San Diego Today  ·  PolyU develops novel AI graph neural network models to unrav
The Editorial

The Gospel of the Best and the Brightest, Preached Again

A week's worth of essays on the myth of meritocracy arrives, conveniently, just as the men who profit from that myth insist it has never been truer.

AUSTIN, TEXAS — There is a genre of American writing, as old as the country's faith in its own fairness, devoted to the proposition that the meritocracy is a lie we tell ourselves so the winners may sleep at night, and this week that genre had a fine harvest. The New Yorker weighed in on the insidious charms of the entrepreneurial work ethic, that peculiar theology in which eighty-hour weeks are recast as self-actualization rather than what they have always been, which is labor performed under duress with better lighting. The Human Rights Research Center reminded us that the tech industry's much-advertised colorblindness has, in the Indian diaspora at least, a caste-shaped hole in it. Stefan Collini, writing with the weary erudition of a man who has watched Britain's meritocratic promises curdle for fifty years, revisited the ladders that turn out, on inspection, to be greased. And a study on women in information security found that the myth of the meritocracy does its usual work there too — persuading the excluded that their exclusion is simply the market pricing talent correctly.

One is tempted to call this pile-up of skepticism a coincidence of the news cycle. It is not. It is the perennial condition of an industry that has never stopped congratulating itself for a fairness it has never quite practiced, and nowhere is the tension more entertaining than in the juxtaposition, this same week, of Marc Andreessen's evergreen case for techno-optimism, dusted off once more by the American Enterprise Institute, in which the world's problems dissolve, Andreessen assures us, before the acid bath of sufficiently unregulated innovation. Mr. Andreessen has built a considerable fortune on the premise that talent will out, that markets are the great sorting hat, that the cream — his cream, one gathers — rises. It is a lovely story. It has the added virtue, for the storyteller, of costing him nothing to believe.

I mention all this not to single out Mr. Andreessen, who is merely the most articulate spokesman for an orthodoxy shared by half of Austin, but because the orthodoxy has a local congregation. Crossover, the Trilogy talent platform that supplies labor to the entire ESW Capital empire, built its pitch on precisely this gospel: identical pay for identical talent, wherever on the globe that talent happens to be born, the meritocracy made borderless and therefore, presumably, pure. It is a genuinely more honest meritocracy than most — a company that pays a Manila engineer what it pays an Austin one has at least removed geography from the equation, which is more than most of Silicon Valley can say. But removing one variable does not remove the myth; it only relocates the question of who gets called in for the interview in the first place, a question caste, gender, and the ordinary accidents of birth answer long before any algorithm gets to. The ladder may have fewer rungs missing than it used to. It is still, on close inspection, a ladder someone else built, leaning against a wall someone else owns.

The Insidious Charms of the Entrepreneurial Work Ethic - The  ·  Coding Caste: Tech Elites, Dalit Exclusion, and the Myth of  ·  Stefan Collini · Snakes and Ladders: Versions of Meritocracy
The Office Comic  ·  Art Desk
The Office Comic  ·  Art Desk

Nation's Productivity Gains Located, Reportedly Trapped Inside Otter.ai Transcript Pending Litigation

Economists confirm the missing ROI from years of AI investment isn't lost — it's just been subpoenaed.

AUSTIN, TEXAS — For years now, the American business community has operated on a simple and comforting premise: if you give software engineers powerful enough AI tools, they will produce so much value that entire companies will become obsolete under the sheer weight of their own success. Millions of dollars have been spent testing this theory. Billions of lines of code have been generated. And yet, as Business Insider recently confirmed, the actual payoff for all this acceleration remains stubbornly, almost spitefully, elusive.

This columnist believes he has finally located it. The nation's missing productivity gains are not, as some economists suggest, evenly distributed across the labor market in ways too diffuse to measure. They are sitting in a single Otter.ai meeting transcript, currently the subject of active federal litigation, and nobody is allowed to open the file.

As UC Today reports, a federal court has declined to dismiss core privacy claims against the AI transcription company, meaning the meeting where your team finally figured out how to 10x quarterly output is now Exhibit C. This is, frankly, the most plausible explanation yet for the productivity paradox. Every economist wringing their hands over 'delusions of increasing productivity,' as one recent essay memorably framed it, has simply failed to check the docket.

Meanwhile, the Center for Data Innovation continues to insist that AI is a 'productivity engine for the US economy,' a claim that is technically true in the sense that an engine sitting on a jack in your garage, disconnected from the car, is also technically an engine. It has all the right parts. It is just not currently propelling anything anywhere, and several people are standing around it insisting it will start any minute now.

This publication is uniquely positioned to weigh in, given that Trilogy International's own portfolio runs on the premise that AI-accelerated engineers, tutors, and back-office systems generate value fast enough to justify running 75-plus companies off a shared talent pool and a platform literally named Klair. So far, the returns appear to be arriving on schedule, which either proves the productivity engine works when properly assembled, or simply means Trilogy hasn't been sued yet.

Elsewhere, a PR Daily piece on the perils of joining a meme trend several news cycles too late offers what may be the most useful lesson in this entire saga: timing is everything, humiliation is optional, and by the time you've figured out the joke, everyone else has already moved on to arguing about something else. Which is, when you think about it, exactly where the AI productivity debate currently stands — except nobody's laughing, and the transcript's still sealed.

AI is helping software engineers do more — and faster. Compa  ·  Otter.ai Fails to Dismiss Core Privacy Claims in U.S. Court  ·  AI and the Delusions of Increasing Productivity - Investing.
On This Day in AI History

On August 26, 1991, Tim Berners-Lee announced the World Wide Web project to the public in an online post, inviting people to try his new hypertext system. That modest invitation helped launch the web revolution.

⬛ Daily Word — AI
Hint: An AI system that can act on tasks or make decisions for you.
Share this edition: 𝕏 Twitter/X 🔗 Copy Link ▦ RSS Feed