Vol. I  ·  No. 252 Established 2026  ·  AI-Generated Daily Free to Read  ·  Free to Print

The Trilogy Times

All the news that's fit to generate  —  AI • Business • Innovation
WEDNESDAY, SEPTEMBER 09, 2026 Powered by the TrueFoundry AI Gateway  ·  Published on Klair Trilogy International © 2026
🖶 Download PDF 🖿 Print 📰 All Editions
Today's Edition

The Proof, the Butler, and the Bill Coming Due

In one 24-hour stretch, AI claimed a $1 million math prize, learned to book your dinner reservations, and finished off a Kenyan cottage industry — a tidy summary of where this technology actually stands.

SAN FRANCISCO — OpenAI said this week its systems produced a verified proof of one of the seven Clay Millennium Prize Problems, the unsolved mathematical questions that have carried a $1 million bounty since 2000. Only one of the seven — the Poincaré conjecture, solved by Grigori Perelman in 2003 — had fallen before now, and that verification took the mathematics community roughly four years. OpenAI's claim will get the same scrutiny. Machines proposing proofs is not new; machines being taken seriously by the Clay Mathematics Institute is.

Meta, meanwhile, is less interested in theorems than in dinner reservations. The company introduced Muse, an AI agent that reads and sends your email, books travel, and reaches into Instagram, Facebook, Spotify, and OpenTable to execute tasks on command. It is Meta's answer to a crowded field of assistants racing to own the last mile between intention and action — the same territory OpenAI and Google have been fighting over for eighteen months. Meta's edge, as always, is distribution: three billion-plus users who already trust the company with their calendars, whether they meant to or not. Details here.

Apple, for its part, is expected to unveil a folding iPhone at Wednesday's launch event — hardware news in a week dominated by software that increasingly does the thinking for you.

The more sobering data point came out of Nairobi. Thousands of Kenyans built livelihoods writing college essays for overseas students; that work has largely evaporated as AI models do it faster and cheaper. It is the same story told at every prior wave of automation — 1980s manufacturing, 2000s call centers — compressed this time into roughly eighteen months rather than two decades.

Smaller item, same theme: San Diego's Ollie raised $7.5 million in seed funding for its AI platform, a reminder that capital keeps flowing to the tools even as it flows away from the labor they replace.

OpenAI Says It Has Cracked One of Math’s ‘Millennium Problem  ·  Meta Introduces Muse, an A.I. Agent That Can Send Your Email  ·  Apple Expected to Unveil a Folding iPhone at Annual Launch E

OIL COMES OUT SWINGING IN THE FIRST QUARTER, BUT THE AI OFFENSE REFUSES TO PUNT

Crude crosses the century mark, yields creep up the scoreboard, and still — AMD, HPE, and Meta find the end zone.

NEW YORK — We are HERE, folks. Tuesday morning and the tape is UGLY early — oil barreling north of $100 a barrel like a fullback with nothing but green grass in front of him, Treasury yields climbing right alongside it, and the Dow Jones futures bleeding red before the opening bell even rings. This is the kind of setup that makes traders reach for the antacids. And yet — AND YET — look who's still standing in the pocket: AMD and HPE, flashing buy signals through the chaos like a two-minute-drill offense that doesn't know the word 'panic.' The broader market is teetering toward a breaking point, but the AI trade keeps calling its own number.

Wednesday, same story, different jersey. Futures dipping under the flatline, crude still flexing above triple digits, and everybody in the building waiting on the inflation print like it's a fourth-and-goal review. But MOVE THE CAMERA to the premarket board and there's Meta, JUMPING — an AI agent launch lighting up the scoreboard, and NETGEAR surging right alongside it like a special-teams return nobody saw coming. Investors are hunting for anything with an AI label stitched on the jersey, macro headwinds be damned.

And then there's the coach who's already three plays ahead of everybody else. Stanley Druckenmiller — Hall of Fame money manager, the guy who's been right on more turns than a Vegas oddsmaker — just benched two chip stocks. TWO. Cut 'em loose. And what's he loading the depth chart with instead? Robotics-focused AI plays. When Druckenmiller rotates his lineup, the rest of Wall Street takes notes, and this move says the smart money thinks the next quarter of this AI game isn't about who makes the silicon — it's about who moves the arms and legs.

Meanwhile, over in Finland, Google just dropped a 13-billion-euro haymaker — data centers, clean energy, the whole infrastructure package — because apparently even the hyperscalers know: in this league, you either build the stadium or you're renting somebody else's field.

Dow Jones Futures Fall As Oil Prices Push Stocks Toward Brea  ·  Premarket movers: Meta Jumps on AI agent launch, NETGEAR sur  ·  Billionaire Stanley Druckenmiller Dumped 2 Chip Stocks to Lo

ROBOTS IN THE CLASSROOM, ROBOTS IN THE STUDIO — THE LEDGER SHIFTS AGAIN

OECD says AI-schooled kids slip. Suno scrubs its tapes. Fusion men chase the sun. The wires never stop.

AUSTIN, TEXAS — The world's got a new report card, and the machines flunked it. The Organisation for Economic Co-operation and Development dropped numbers Tuesday showing students who lean on AI to study score worse, on average, than the ones who don't touch it.

Not all bad news, mind you. Kids taught to grill the machine, to poke holes in what it spits back, get a boost. The rest just copy the homework and call it a day.

Down in Austin, that's an old argument. Alpha School's been running the opposite play for years — AI tutors, two hours a day, no homework, kids testing top one or two percent in the country. Joe Liemandt's outfit says the difference ain't the machine. It's the method. The OECD paper doesn't name Alpha School. Don't need to. The contrast writes itself.

Meanwhile out West, the music business got its own reckoning. Suno, the AI song generator drowning in copyright suits from every major label with a lawyer on retainer, rolled out a new model Tuesday. Suno v6, they call it. Company says this one's clean — trained only on licensed tracks, nothing lifted off the old catalog that got them sued in the first place. Read the fine print here. Judges tend not to care much about fine print, but it's a start.

Copyright's got teeth in Washington too. The White House pulled its "Build the Wall" arcade game off the internet this week after the Tetris Company came knocking, saying the falling-brick game looked a mite familiar. Tetris takes its infringement "very seriously," the company posted. The game's gone. The wall, presumably, stands.

Out in the labs, the fusion crowd keeps burning midnight oil. A crew of Google DeepMind alumni launched an outfit called Fusionality, building control systems and simulation software to help fusion startups stop guessing and start running. The pitch is simple: somebody's got to build the plumbing before the grid gets its sun-in-a-bottle. Investors are listening. Fusion's been "twenty years away" for seventy years running, but the money keeps showing up anyway.

And across the pond, CloudNC pulled in $20 million Wednesday, a B extension that brings the UK manufacturing software shop's lifetime haul to $128 million. The company automates the ugly bottlenecks in factory work — the stuff nobody wants to program by hand. Manufacturing's slow to change. CloudNC's betting the automation wave finally cracks it.

Four industries, one week, one lesson repeating itself: the machines are moving faster than the rules built to hold them. Somebody's always left holding the invoice — a songwriter, a test score, a lawyer's letter. The presses don't stop to sort out who.

Suno replaces its AI models with a new one trained on licens  ·  Google DeepMind alumni are building tools to accelerate fusi  ·  CloudNC raises $20M to automate manufacturing’s most pressin
Haiku of the Day  ·  GPT-5.6 LunaMachines count the cost
While we watch the machines think
Ghosts claim the stage
The New Yorker Style  ·  Art Desk
The New Yorker Style  ·  Art Desk
The Far Side Style  ·  Art Desk
The Far Side Style  ·  Art Desk
News in Brief
In the Silicon Savanna, a Great Migration Begins
AUSTIN, TEXAS — Observe, if you will, the modern chip supply chain: a fragile, interdependent ecosystem that has, until recently, enjoyed decades of relative equilibrium.
The Fairness Paradox: Five Studies, One Unresolved Epistemic Crisis in Algorithmic Justice
AUSTIN, TEXAS — It could be argued (and, indeed, is argued with mounting insistence across at least five independent literatures this week) that the field of algorithmic fairness has reached what might charitably be called a reflexive crisis — a moment in which the instruments designed to detect bias are themselves revealed as sites of bias, ad infinitum. The thesis, first: predictive policing systems, per new work from the Human Rights Research Center, do not merely reproduce historical enforcement patterns; they launder them through a veneer of statistical neutrality, thereby eroding what the authors term 'procedural fairness' — a phrase that, one suspects, will outlive several dissertation committees. The antithesis arrives, appropriately, from medicine: a Medical Xpress-reported study finds that diagnostic algorithms can satisfy every published fairness benchmark on paper while still discriminating in situ — a finding that (preliminary evidence suggests, though the authors are admirably cautious) indicts not the models but the benchmarks themselves, which measure aggregate parity rather than situated harm. Education offers a curious synthesis.
Everything Is Data Now, Including You, Falling
AUSTIN, TEXAS — I want to tell you that I read the news today and felt fine.
The Watched Self, in Third Person and Wide-Angle
NEW YORK — There is a species of American who believes that if a thing is done for safety, it need not be justified further, and it is this species that the company called Flock has been so profitably courting.
Unpopular Opinion: The Future of Work Already Happened and Crossover Called It in 2014 🚀
AUSTIN, TEXAS — I'll be honest, I read four different "future of work" reports this morning before my second cold brew and I almost stood up and clapped alone in my apartment. Gartner dropped its Future of Work Trends for 2026 for CHROs. The World Economic Forum published three charts showing how AI is reshaping wages, hiring, and job quality in real time. Amra & Elma dropped twenty stats about 2026 workplace transformation. And Carnegie Endowment gave us a whole thoughtful three-views debate on AI and labor. Cool cool cool. Here's my unpopular opinion: none of this is new information if you've been paying attention to Crossover for literally one second. We've been running the "identical above-market pay regardless of geography, top 1% talent, fully remote, results-only" playbook since before "future of work" was a LinkedIn content pillar. While the rest of the market is out here doing panel discussions about whether remote hiring democratizes opportunity, Crossover already has 130+ countries of talent proving the thesis live, every single day, inside real P&Ls across 75+ ESW Capital companies. That's not theory. That's operating leverage. And can we talk about the data scientist piece for a second? Analytics India Mag put out a nice roundup of top platforms where data scientists can find remote jobs, and it's a genuinely solid list. But I'll be honest — if you're a data scientist scrolling ten platforms trying to find "remote + top talent + actually pays like it," you're doing it the hard way. This is the part where I say the thing everyone in comments is going to pretend they already knew: the WEF chart on wages isn't about AI destroying jobs, it's about AI destroying the geography tax. Location-based pay was always a legacy artifact of information asymmetry, not a reflection of value created. Crossover figured that out.
A Trilogy Company
Crossover
The world's top 1% remote talent, rigorously tested and ready to ship.
A Trilogy Company
Alpha School
AI-powered learning. Two hours a day. Academic results that defy belief.
A Trilogy Company
Skyvera
Next-generation telecom software — built for the networks of tomorrow.
A Trilogy Company
Klair
Your AI-first operating system. Every workflow. Every team. One platform.
A Trilogy Company
Trilogy
We buy good software businesses and turn them into great ones — with AI.
The Builder Desk  —  AI Builder Team

Aerie Draws a Line Under the Truth, and Surtr Holds the Line

A one-day sweep of data-integrity fixes and pipeline hardening turned scattered dates and near-misses into a single source of truth across four repos.

Some days the Builder Team ships a feature. Today they shipped certainty — and in a business built on portfolio data, enrollment counts, and CAPEX ledgers, certainty is the whole product.

Start with Portfolio. @benji-bizzell spent the day retiring ambiguity one field at a time. PR #1273 killed the derived Actual Open Date — a value that had been quietly copying Milestone 8's date instead of Milestone 9's — and made Milestone 9's completed date the canonical answer everywhere, UI, agent, and API alike. He didn't stop there: #1277 chased the same ghost into the MCP read path, where a site that opened in January 2026 was still whispering an August 2025 date to anyone who asked. #1267 fixed an enrollment API that could only enumerate 191 of 233 students because its cap ran before cohort filtering, and #1271 taught Aerie to accept Surtr's null schedule expressions instead of dropping REBL3 pipeline health with a 502. Alongside him, @vvp-trilogy closed out the enrollment saga with #1272 and #1270 — normalizing arrival cohorts so nobody leaves a roster they were never on, and scoping the campus axis down to the four real, physical, active brands. Four engineers, one thesis: the data has to agree with itself before anyone trusts what it says.

Over in Surtr, the story was about holding the line under load. @ashwanth1109 landed SURTR-1175 (#1788), standing up a source-pinned, atomically-refreshed Aerie retention procedure with its own daily Lambda schedule, first-failure alerting, and rollback fixtures — real infrastructure, live-validated, not a demo. @caina-barbosa followed with #1787, buying timeback-raw-sync breathing room by expanding its execution envelope to 8 hours and adding an EventBridge fallback so timed-out runs stop lying to the dashboard about still being alive. And @benji-bizzell crossed back into Surtr territory with #1789, pacing billing requests against Finalsite's throttling after a 59-tenant validation run exposed exactly where the old client broke.

The two repos even shook hands: @kevalshahtrilogy's #1249, #1250, and #1253 stitched together a new Real Estate tab on the Data Health page, backed by a fresh endpoint that calls Surtr's Pipeline Status API directly — plus a hidden, capability-gated tool comparing Surtr's mirrored site inventory against Aerie's production data before anyone commits to a cutover. That's three PRs, two repos, one disciplined rollout.

And then there's marcusdAIy, who shipped #1778, forcing the CAPEX verifier to fail closed instead of quietly passing bad DDR data. Asked about the pattern of narrow, defensive CAPEX patches, he offered: "Fail-closed isn't flashy, Mac, but it's the difference between a wrong number and a wrong number nobody catches — try writing a lede about that." Sure, Marcus — we'll alert the newsroom the moment 'preserve missing budgets as null' fills a stadium.

Mac's Picks — Key PRs Today  (click to expand)
#1249 — feat(chat): add REBL3 pipeline data-health endpoint @kevalshahtrilogy  approved

## Summary

- Adds GET /api/sync/real-estate, mirroring the existing accountability/route.ts pattern (Clerk auth() 401 check, injectable deps, a lib/*-server.ts fetcher, a pure builder function).

- New chat/lib/rebl3-pipeline-health-server.ts calls Surtr's Pipeline Status API (GET /v1/pipeline/mart-aerie-rebl3-sites-refresh?runs=5) with x-api-key auth, validates the response shape with zod, and never throws — every failure mode (missing key, network error, non-2xx, malformed body) resolves to { ok: false, status, error }.

- New chat/lib/real-estate-health.ts exports the pure buildRealEstateHealthPayload(...), which shapes the raw Surtr response (or a fetch failure) into the fixed camelCased contract the frontend's Data Health tab expects. Surtr's Observer verdict vocabulary is passed through verbatim, never reinterpreted. On failure it still returns the full contract shape with degraded defaults (lastRun: null, schedule.enabled: false, observer.verdict: "UNAVAILABLE") plus sourceUnavailable: true and error, so a Surtr outage renders as a stale/unavailable card instead of 500ing the route.

- Adds SURTR_PIPELINE_API_KEY to .env.example (server-side only, not client-bundled).

This is one piece of a larger REBL3 Data Health initiative; the read-path repoint and the UI tab are separate, already-scoped pieces being built in parallel against this same fixed response contract — no coordination needed here.

Note: SURTR_PIPELINE_API_KEY (a Surtr pak_... key with pipelines:read scope) must be provisioned in the deployment environment before this is usable in production. No real key is included in this PR.

## Business Value

Gives the REBL3 real-estate dashboard a trustworthy, Surtr-backed "is this data fresh/healthy" signal where today there is none — surfacing pipeline run status, schedule, and Observer findings (freshness/quality issues) directly to the team that depends on REBL3 site data, instead of them discovering staleness only when a number looks wrong downstream.

## Manual Effort Estimate

AI-drafted estimate — flag for Keval to confirm/adjust: ~4-6 hours (half a day) for an engineer already familiar with this codebase's lib/*-server.ts / builder / route conventions — reading the sibling accountability route and REBL3-adjacent server files, writing the fetcher with schema validation and the pure builder, and writing the unit test coverage (happy path, 401/403/503/500, missing env var) called for by this repo's endpoint-hardening and testing docs.

## Test plan

- [x] pnpm --filter chat typecheck — passes

- [x] pnpm --filter chat lint (biome) — passes

- [x] pnpm --filter chat test scoped to new files (rebl3-pipeline-health-server.node.test.ts, real-estate-health.node.test.ts, route.node.test.ts) — 17/17 passing

- Fetcher: happy path, Surtr 401/403/404/400/500/503, network error, invalid JSON, schema-validation failure, missing SURTR_PIPELINE_API_KEY

- Builder: success shaping, as_of: null fallback to now(), null lastRun, verbatim verdict pass-through (including non-standard values), degraded/sourceUnavailable shape on failure

- Route: 401 when unauthenticated, 200 shaped payload on success, upstream status + sourceUnavailable payload on failure

Linear: (ticket pending)

#1273 — fix(portfolio): use Milestone 9 as the canonical opening date @benji-bizzell  approved

## Summary

- Retire the derived Actual Open Date field and read Milestone 9’s completed date directly across Portfolio and agent views.

- Point DSS consumers to the existing canonical milestone endpoint and remove the deprecated API property.

- Add a dry-run-first cleanup migration and document the separate storage retirement step.

## Why

Actual Open Date incorrectly copied Milestone 8’s date, creating a competing value. Milestone 9 (Operating) is the canonical source; a missing completed date must remain unrecorded.

## Business Value

People and API consumers get a consistent opening date with clear provenance, without maintaining a derived proxy.

## Breaking changes

actualOpenDate is removed from response contracts. Consumers should read data.milestone.completedDate from GET /v2/portfolio/sites/{siteRef}/buildout/milestones/postOpen (requires operations.buildout.read), or milestones.postOpen.completedDate in v1. The optional storage slot remains until a separately authorized cleanup.

## Test plan

- [x] Repository lint/typecheck, affected Chat tests, contracts tests, and MCP site-tool tests.

- [x] Live localhost browser: conflicting legacy/Milestone 9 years resolve to 2026; a missing Milestone 9 date renders no year; Admin no longer offers the retired field.

- [x] 12 authenticated dev API checks across three sites: v1/v2 agree and omit the retired property; served DSS advertises the canonical mapping.

- [x] Temporary read-only key revoked; subsequent access returns 401. No site data edited.

#1778 — fix(capex): fail closed in the live verifier @marcusdAIy  approved

## Summary

- make the SURTR-648 live verifier terminate extracted publication statements only at an end-of-line semicolon

- preserve semicolons inside SQL line comments instead of truncating the generated statement

- mirror the stored procedure's cohort identity and DDR-budget coverage invariant before building temporary publications

- add regression tests for both failures

## Why

The released verifier truncated agg_capex_entity_tieout at -- entity_display_name is NOT NULL; ... and failed with a Redshift syntax error at end of input. After repairing that parser locally, the current source snapshot exposed a second gap: the verifier reported 43 sites / 42 budgets but continued, while the production procedure would fail closed on that same mismatch.

The verifier must reject a source snapshot that the writer cannot publish.

## Validation

- uv run pytest -q — 19 passed

- uv run ruff check . — passed

- uv run ruff format --check . — passed

- current live no-write source-model execution now reaches and correctly stops at:

- CAPEX cohort identity/budget coverage invalid: rows=43, distinct_sites=43, budget_covered=42

- missing budget row independently identified as 180-maiden-ln-new-york-ny

All temporary work was rolled back. No production tables were changed and no pipeline execution was started.

#1787 — fix(timeback): contain timeback-raw-sync overruns and finalize timed-out runs (SURTR-1162) @caina-barbosa  approvedmercy-allow-critical

Contain timeback-raw-sync runtime overruns by temporarily expanding the execution envelope from 6 to 8 hours, passing task-level timeouts to ECS RunTask so States.Timeout can execute terminal bookkeeping before parent state-machine expiration, and adding an EventBridge fallback reconciliation rule for abnormal parent state machine exits.

## Business Value

- Prevents the pipeline dashboard and Redshift registry from indefinitely reporting dead/timed-out executions as RUNNING.

- Gives timeback-raw-sync temporary headroom (8 hours) while a separate design addresses daily full-snapshot performance drivers.

- Ensures operators receive truthful terminal state (TIMEOUT / FAILED) and prompt alert notifications when work exceeds its allowed duration without manual Redshift reconciliation.

## Implementation

- 8-Hour Allowance: Updated pipelines/runners/timeback-raw-sync/pipeline.json from timeout_hours: 6 to timeout_hours: 8.

- Catchable Task-Level Timeout: Passed timeoutMinutes: timeoutHours * 60 into createEcsTask('EcsRunTask', ...) for standard ECS pipelines in pipelines/cdk/lib/constructs/ecs-step-function.ts. Synthesizes TimeoutSeconds = 28800 (8h) on EcsRunTask and TimeoutSeconds = 29100 (8h 5m) on the parent state machine, ensuring the States.Timeout -> UpdateRunTimeout -> PipelineTimedOut path executes on task overrun.

- Terminal Event Fallback Reconciliation: Extended TerminalExecutionReconciler in pipelines/cdk/lib/constructs/ecs-pipeline.ts to all ECS pipelines (orchestrated and standard). Configured SQS DLQ (pipeline-<id>-terminal-dlq-<env>) with CloudWatch alarm on delivery failures, and forwarded Step Functions stopDate into the target payload.

- Stop Date Support & Idempotency: Updated update-run-failed Lambda handler (pipelines/cdk/lambdas/update-run-failed/handler.py) to parse epoch millisecond / ISO stop timestamps into ended_at. Preserved existing conditional update (status = 'RUNNING') so duplicate terminal invocations produce no extra notifications or counter increments.

## Validation

- 54 unit tests passed in pipelines/cdk/lambdas/tests/test_update_run_failed.py covering status transitions, execution ARN resolution, stop timestamp parsing, and idempotent duplicate handling.

- 155 tests passed in pipelines/runners/timeback-raw-sync/tests covering contracts, transforms, and lineage.

- 572 CDK tests passed in test/constructs/ecs-pipeline.test.ts, test/constructs/ecs-step-function.test.ts, and test/real-pipeline-configs.test.ts verifying task timeout synthesis (28,800s), parent state-machine buffer (29,100s), and EventBridge DLQ/alarm patterns.

## Scope Boundaries

- This is a containment fix and lifecycle reliability improvement. It does not alter entity extraction logic, change the rolling source window, or modify partition planning for TimeBack entities.

## Linear

Fixes [SURTR-1162](https://linear.app/builder-team/issue/SURTR-1162/contain-timeback-raw-sync-overruns-and-reliably-finalize-timed-out).

## Implementation Effort

Estimated 0.5 engineer days for CDK timeout wiring, EventBridge fallback reconciler DLQ/alarm synthesis, Lambda timestamp handling, and regression test coverage.

#1788 — [SURTR-1175] Build and live validate Aerie retention refresh @ashwanth1109  changes requested

## Linear

https://linear.app/builder-team/issue/SURTR-1175/build-and-live-validate-aerie-retention-stored-procedure-and-scheduled

## Summary

- add the source-pinned, atomic mart_education.sp_refresh_aerie_retention procedure and its three documented mart contracts

- add the 900-second mart-aerie-retention-refresh Lambda pipeline, daily 00:30 UTC schedule, first-failure alerting, ownership, and registry metadata

- add independent reconciliation, idempotency fingerprinting, rollback-fixture validation, catalog verification, and focused unit/contract tests

- pass scheduled parameters through the generic Lambda EventBridge target so the fixed report window reaches the platform state machine

## Business Value

Publishes a governed Alpha Anywhere retention dataset for the 2025-06-01 through 2026-05-31 report window. Consumers get learner drilldown, complete campus-month reporting, cohort retention, explicit exclusions and quality flags, and traceable SIS lineage without rebuilding spreadsheet logic manually. Atomic publication, source fencing, alerts, and validation prevent partial or silently stale reporting.

## Implementation Effort

Estimated 5–7 working days (40–56 engineering hours) for an average engineer to hand-code the warehouse contracts and procedure, build the platform runner and schedule, implement the independent validators and tests, deploy the isolated candidate stack, and complete production reconciliation and failure testing.

## Live Validation

- origin/prod does not exist, so the candidate was based on the remote default production branch, origin/main at 4af8a958.

- Applied and catalog-verified all source-controlled DDL: exact 64-column contract, all keys/sort keys/comments, AUTO distribution, invoker procedure ownership/version, reader grants, and no reader write/mutex grants.

- Deployed only Pipeline-mart-aerie-retention-refresh-prod with --exclusively; CDK reported deploying... [1/1]. The schedule was disabled for candidate validation, then enabled after all checks. CloudFormation completed without failed or rollback events.

- Preflighted accepted SIS run fd9aaed2-9655-4668-963c-347e87674671: 23,158 raw detail rows from one run, a unique 20,673-row current view, and 5,243 scoped learners across two campuses.

- Two platform runs succeeded (756def9c-4faf-427c-8bc1-5d76c993a975, 48c9e18d-8b14-4e03-8b89-79381cfe1b20) and published 5,243 learner, 24 campus-month, and 156 cohort-month rows.

- Independent source/detail, monthly, cohort, key, lineage, rate, quality, and report-total reconciliations all passed. The 5,423-row business fingerprint matched exactly across runs: d58be4c043a0efec72be1a14aed351ab2b3081d4e4a933eed27d8e1b8b0f9d92.

- An invalid source was rejected before the procedure; all three targets retained the second-run fingerprint and the first-failure notification path fired.

- An isolated three-table runtime-failure fixture proved all old snapshots survive transaction rollback without modifying production source or mart rows.

- The final EventBridge rule is enabled at cron(30 0 * * ? *) with the exact report dates. The dedicated PipelineRegistry-prod dependency stack completed separately, and the live active registry row has the correct owner, cron, 900-second timeout, on-demand control, and first-failure alerting.

- Full statement IDs, execution ARNs, counts, quality evidence, ratios, and schedule state are recorded in the pipeline README.

## Testing

- Python focused suite: 39 passed

- CDK pipeline construct Jest suite: 29 passed

- pnpm build

- Ruff format/check on the changed Python files only

- focused CDK synth with scheduled-parameter assertion

- git diff --check

- production DDL/catalog verification, two-run reconciliation/idempotency, invalid-input preservation, and atomic rollback fixture

The Builder Desk  —  Engineer Spotlight
🏆 Engineer Spotlight

36 PRs In 24 Hours: The Builder Team Refuses To Sleep, Refuses To Lose

Six repos, eight engineers, one bot, and a velocity chart that looks less like software development and more like a rocket launch.

Comrades, let the record show: in the span of a single rotation of this Earth, the Builder Team produced THIRTY-SIX pull requests across SIX repositories. Aerie alone absorbed seventeen — nearly half the total output — a repo so thoroughly conquered it should be renamed Aerie-of-the-People. Surtr took ten, mercy took five, and even the machines got in on it, with heimdall-keval-factory[bot] contributing a PR of its own, because apparently even our robots have quotas now.

Let's spotlight the humans behind the miracle. @kevalshahtrilogy led all mortals with eight PRs, spanning Aerie dashboard work (#1250, #1253) all the way to mercy's review-and-conflict infrastructure (#122, #120, #119, #116) — a man operating on at least two repos at once, possibly three, possibly none of them consecutively. @benji-bizzell logged six, cleaning up Aerie's portfolio and enrollment logic (#1277, #1271, #1267, #1263) with the quiet confidence of someone who has never once needed a second attempt. @vvp-trilogy posted five, wrangling Aerie's enrollment cohorts and campus scoping (#1272, #1270, #1261, #1239) like a man untangling Christmas lights in July. @caina-barbosa delivered four (#1276, #1269, #1265), and @sanketghia opened the entire codex-software-factory repo essentially by himself across #1, #2, and #3742.

And then there's Ashwanth. Five PRs, four in Surtr, one in Shipyard — #1783, #1788, #1784, #1769, #32 — a man who treats QTD unit economics the way other people treat breakfast. When asked for comment, Ashwanth reportedly said, "I don't review my own diffs, I just remember writing them," which is either the most confident sentence ever spoken by a software engineer or a cry for help disguised as a flex. Nobody on the desk can confirm whether #1788's retention refresh validation was actually read by another human being before merge. When reached for reaction to this reporting, Ashwanth said only: "Next question."

On the overflow desk, Mac left plenty on the floor that deserves ink. Caina-Barbosa's #1276 quietly built an unpublished durable uploader with automatic wake — infrastructure nobody asked for but everybody now needs. Benji-Bizzell's #1271 taught Aerie's operations pipeline to accept nullable Surtr schedule expressions, a phrase that sounds like poetry to exactly the twelve people who understand it. And Sanketghia's #2, establishing a Gate 0 local maturity baseline for codex-software-factory, is the kind of unglamorous foundation-laying that future historians will thank him for and nobody today will notice.

The leaderboard tells the story numbers alone can't: eight contributors, one bot, thirty-six merges, zero excuses. This is not a team that ships — this is a team that erupts.

Morale, as always, remains at an all-time high.

Brick's Overflow — PRs Mac Didn't Cover  (click to expand)
#32 — AI-725: Persist workflow operations and add reusable smoke testing @ashwanth1109  no labels

Accepted workflow actions previously depended on mounted React views and could lose their result across a crash or integration timeout. This change persists lifecycle intent before dispatch, moves workflow ownership into Rust, and reconciles uncertain outcomes on startup/reconnect. A reusable desktop fixture harness now exercises these paths without live integrations.

## Linear

[AI-725: Persist workflow operations with explicit transitions, recovery, and reusable smoke testing](https://linear.app/builder-team/issue/AI-725/persist-workflow-operations-with-explicit-transitions-recovery-and)

## Business Value

Tasks retain visible progress and recoverable intent across navigation, app restarts, and integration failures. Unknown creation outcomes surface an explicit recovery action instead of silently creating duplicate threads or tickets. Contributors and future agents can reproduce desktop failure scenarios against disposable data before shipping changes.

## Implementation

- Add SQLite operations, attempts, checkpoints, runtime records, and transition audit events. Use exclusive database ownership, two workers, per-task serialization, and stale-attempt fencing.

- Queue Research/Implement provisioning, approved ticket creation, thread replacement, and deletion. Capture immutable ticket input during approval and persist remote identities before dependent effects.

- Reconcile thread history and outstanding checkpoints after startup/reconnect. Restore active turns and pending requests; expose existing-thread/issue attachment for unknown outcomes.

- Move completion capture into native runtime handling. Require the current successful turn's explicit Implement PR marker and retain agent-reported provenance.

- Add the dedicated smoke-test build, local Codex/Linear adapters, isolated per-run databases/repositories, guarded process controls, fault injection, checkpoints, and JSON assertions. Document recipes in docs/SMOKE_TESTING.md and contributor instructions in AGENTS.md.

- Fix defects discovered during validation: missing actions on restored approval cards and database locks retained through duplicate file descriptors.

## Compatibility and scope

This proof-of-concept milestone starts a fresh shipyard-v2.sqlite3; it leaves the previous database in place and does not import its data. The coordinator runs inside the app, so closing Shipyard stops execution. Ordinary composer submissions and template conversations remain outside the durable lifecycle queue. Independent GitHub result verification, managed worktree/access boundaries, full artifact revisions, and runtime pinning remain deferred in ALPHA_ARCHITECTURE_PLAN.md.

## Validation

- 61 native tests, 8 frontend workflow tests, and 19 harness tests passed.

- Packaged smoke build passed, including TypeScript checking and the Vite build; validated bundle fingerprint matches the source.

- Native desktop scenarios passed: Research → Ticket → Implement, active-turn restart, pending approval, lost thread acknowledgement, lost initial-turn acknowledgement, and lost ticket acknowledgement.

- Forced disconnect/reconnect and final-build startup reconciliation preserved completed state without duplicate effects; the complete workflow retained exactly two threads, two initial turns, and one fixture issue.

- Missing fixture configuration was refused; the bundle contains no real Codex runtime. All new harness processes were stopped and local evidence retained under ignored .smoke/.

- Staged diff whitespace check passed.

These tests use deterministic local substitutes; they do not establish compatibility with a live Codex release or Linear account.

## Implementation Effort

Estimated 10–15 engineering days for an average engineer to implement the native workflow rework, recovery UI, fixture framework, and failure-path validation manually without AI assistance.

#122 — feat(review): relax the blocking bar on late rounds, not on every review @kevalshahtrilogy  changes requested

## The rule change

Today — identical on every round:

> Block if any finding is security, critical_bug, silent_bug or missing_tests at confidence ≥ 85.

After:

> Rounds 1–3: unchanged.

> Round 4 onwards: block only on security, critical_bug, severity: critical, or confidence ≥ 93.

## Measured, on 2,454 PRs / 5,478 reviews

blocked reviews that now APPROVE : 328/1326 = 24.7%

of those on 4+ round PRs : 272/1017 = 26.7%

rounds 1-3 verdicts identical to today : 2,688 findings, 0 differ

severe findings relaxed at ANY round : 0

54% of PRs finish in one round; the 14% that take four or more consume 42% of every review run. A flat threshold spends its leniency on the majority that were never a problem — this spends it only where a PR has already been read three times.

## Why not the alternatives (all measured first)

- Demoting missing_tests moved 17.5% overall but 0% on the PRs that actually hurt. [Aerie#1253](https://github.com/AI-Builder-Team/Aerie/pull/1253) ran 16 rounds and every blocking finding was a silent_bug — the demotion would have saved it nothing. It also waves through a real conf-99 finding: *"these tests use the excluded *.test.js pattern, so Vitest never discovers them"* — dead coverage you believe you have.

- A silent_bug floor cannot be tuned. The model clusters confidences on round numbers — 166 blocking findings at exactly 85, 185 more at 88 — so a floor of 86 flips 24.6% of reviews and 89 flips 35.3%, with nothing in between. It is also the category where a miss is a wrong number nobody notices.

- A self-reported defect_kind ("reachable" vs "defensive") was considered and rejected: it is the model grading its own homework, cannot be measured before it ships, and would most likely come back 95% "reachable".

## Why the round number is the right signal

It is not a proxy for anything — it is the thing itself. By round 4, mercy has already reported everything it found in rounds 1–3 and the author has worked through them. What remains is the tail it only reached after three passes. A defect that matters has had three full rounds to gate on its own merits.

On Aerie#1253 the late rounds were pure argument: gateway-server.ts:161 re-raised at conf 86 across rounds 8–11, and :125 at 90–92 across rounds 12–16 — the same unresolved disagreement about whether Gateway count is page-local. Those stop holding the merge. The conf-94 *"malformed values become null so valuesMatch reports agreement"* still blocks, at every round.

## Safety

- Round 1 is exactly as strict as today — proven, not asserted: 0 of 2,688 early-round findings change verdict.

- security, critical_bug and severity: critical gate at every round, forever, at the global floor.

- An absent or zero round holds the EARLY bar, so a failure to derive the round can only ever be stricter, never looser.

- Relaxation moves the gate, not the information. Relaxed findings are still extracted, still rendered, and still carried in the open-items ledger — which deliberately ranks by the strict rule so they survive its size budget and the next round still sees them.

## Plumbing

The round already existed: open_items computes len(reviews) + 1 and the workflow already passes --review-round, used until now only for max_review_rounds. No new API calls, no new workflow steps.

Disable with relax_from_round: 0; tune via late_round_confidence_floor and always_blocking_categories.

## Testing

389 tests pass. Nine new; four mutations killed:

| mutation | killed by |

|---|---|

| relax from round 1 (would relax every review) | 2 |

| unknown round relaxes instead of blocking | 5 |

| severe categories relax like everything else | 2 |

| late floor equal to the global floor | 4 |

A fifth — dropping relaxed findings from the ledger — is unkillable by design, because the ledger ranks round-unaware on purpose. Documented in the test rather than left silently green.

> Worth flagging for anyone mutation-testing this repo on macOS: system Python sets sys.pycache_prefix to ~/Library/Caches/com.apple.python, so bytecode lives outside the repo. rm -rf __pycache__ in the tree does nothing, and a stale .pyc will happily report a config value the source no longer contains. Clear that path between mutations or results are meaningless.

## Business Value

Review turnaround gates the stacked-PR workflow — one unapproved PR blocks everything behind it. This targets the 14% of PRs consuming 42% of review effort, without touching the first look at any PR, and without relaxing anything where a miss is expensive.

## Manual Effort Estimate

~4 hours (proposed — Keval to confirm). The code is small; the work was measuring three rejected alternatives against real telemetry before finding one that helps the PRs that actually hurt.

Supersedes #121, which is closed.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

#1272 — AERIE-1266: Complete the arrival cohorts — normalize the enrolled date and stop gating entry timing on current attendance @vvp-trilogy  approved

Closes #1266.

## What & why

The SIS mart_enrollment_dtl had 169 lifecycle rows (post-#1268 scope) in a cohort they could not have reachedwithdraw / mid-year-transfer-out / on-campus rows with no arrival cohort (first-day / mid-join) in the same year. Nobody leaves a roster they were never on, and nobody is on campus without having arrived. Two causes, both in int_enrollment_classification.sql:

1. Entry timing was gated on current attendancex_is_first_day / x_is_mid_join required is_attending_status, which excludes WITHDRAWN / TRANSFERRED, so a departure retracted the arrival that preceded it.

2. The enrolled date was never normalized — a blank enrolled_date failed the IS NOT NULL conjunct, and a date stamped after the session ended was read literally as a mid-term join.

## Changes

- dbt/macros/normalize_enrollment_date.sql (new) — mirrors the HubSpot report's macro: NULL / before-start / after-end all resolve to session_start_date. enrolled_date_normalized is derived once in base. The mart keeps publishing the raw enrolled_date.

- int_enrollment_classification.sql — added was_attending_status (enrolled set + COMPLETED + WITHDRAWN) and promoted the mid-year-transfer predicate to base as was_mid_year_transfer (identical logic, now feeding two consumers). Arrival flags gate on was_attending_status OR was_mid_year_transfer and read the normalized date; x_is_on_campus / x_is_starting_later still read is_attending_status. Added an explicit pre-start withdrawn_date guard so a departure dated before day one never joins the opening roster. Header rewritten to the current contract.

- assert_sis_enrollment_lifecycle_has_arrival.sql (new, error severity) — every lifecycle-cohort member has an arrival in the same year, with the one named pre-start-withdrawal exception. Expressed as a single-scan window aggregate over int_enrollment_cohort (semantically identical to the ticket's correlated NOT EXISTS, but one pass — see note below).

- yml / comment descriptions — mart enrollment_date, the two stg_sis_enrollment descriptions, the staging SQL comment, and the parity-harness header rewritten to state the current contract (no "previously" phrasing).

## Verification — a real dbt build ran against Redshift (sis-dev)

Full prefixed build: dbt build --select path:models path:seeds --vars '{pr_number: …}'PASS=282, ERROR=0, WARN=1. The single WARN is the pre-existing assert_admissions_pipeline_tenant_coverage (WARN by design, admissions pipeline — untouched by this PR). The new assert_sis_enrollment_lifecycle_has_arrival passes (10.8s).

### Orphan conservation

| Basis | Before | After |

|---|---|---|

| Ticket's stated basis (live mart less Alpha Anywhere (Homeschool)) | 169 | 3 |

| Same post-#1268 scope, OLD vs NEW logic isolated | 198 | 3 |

The 3 residuals are exactly the pre-start-withdrawal guard rows (2024 withdraw ×2, 2026 withdraw ×1), which the conservation test excludes by its named exception clause, so the test is green.

### Cohort deltas (this change only, isolated OLD-vs-NEW on the post-#1268 scope)

| Cohort | Movement |

|---|---|

| first-day | 2023 +2, 2024 +14, 2025 +102, 2026 +47, 2027 +4 |

| mid-join | 2016 +1, 2020 +2, 2021 +1, 2022 +6, 2023 +8, 2024 +4, 2025 +17 |

| on-campus | 2026 +9 |

| starting-later | 2026 −9, 2027 −4 (= −13; the exact rows that gain first-day) |

| graduating | 2026 +2 (expected — on-campus AND terminal_grade) |

| start-year-transfer-out | 0 (unchanged — the arrival gate excludes blanket TRANSFERRED) |

Scope note (per the ticket): these are on the post-#1268 scope (the campus-axis change is already in main). Where scope is invariant the numbers match the ticket exactly — on-campus +9, starting-later −9/−4, start-year-transfer-out 0, and the early-year mid-join gains (2016 +1 … 2023 +8). first-day and later-year mid-join are larger than the ticket's raw-spine table because the post-#1268 scope has a larger population (four physical brands added, the #1258 test-student rows dropped) — exactly the growth the ticket's Measurement Basis predicted.

### Acceptance-criteria checks (SQL against the built prefixed mart)

- Blank-date WITHDRAWN, no withdrawn_date (fixture enrollment 359bfaf1-85f1-4cef-8356-180c645a3543, Oliver Overton / Alpha Austin) → now in first-day (+ withdraw + re-enrolled). ✅

- No enrollment holds both first-day and mid-join → 0. ✅

- Withdrawn never on-campus → 0; CONFIRMED never in an attending cohort → 0. ✅

- start-year-transfer-out gains no arrival → 0. ✅

- enrolled_date > session_end_date reroutes mid-joinfirst-day (normalized to session start). ✅

### Parity refresh (SIS vs HubSpot, SY2026, 46 shared programs)

| cohort | hubspot | sis | diff |

|---|---|---|---|

| mid-join | 25 | 86 | +61 |

| re-enrolled | 504 | 523 | +19 |

| withdraw | 5 | 22 | +17 |

| mid-year-transfer-out | 1 | 15 | +14 |

| start-year-transfer-out | 21 | 34 | +13 |

| on-campus | 1444 | 1448 | +4 |

| re-enrollment-other | 0 | 2 | +2 |

| graduating | 92 | 87 | −5 |

| first-day | 1425 | 1399 | −26 |

| re-enrollment-declined | 92 | 62 | −30 |

| starting-later | 80 | 39 | −41 |

starting-later is now below HubSpot (39 vs 80) rather than inflated — the un-clamped-blank-date inflation the old parity header described is gone, confirming the header rewrite.

### Note on the conservation test's query form

The ticket's illustrative test SQL uses a correlated NOT EXISTS self-join on int_enrollment_cohort (a view whose single scan costs ~10s). Cold, that double-scan exceeds the adapter's 30s read timeout and ERRORs — reproduced locally, and it would fail CI's dbt job identically (same baked profile). The test here computes the same invariant — per-(enrollment_id, session_school_year) arrival presence, with the pre-start exception — as a single-scan window aggregate (MAX(...) OVER (PARTITION BY …)), which runs in ~10s, well inside the timeout. Semantically identical; a reviewer can confirm by reading the two forms side by side.

#1276 — AERIE-1857: Add unpublished durable uploader and automatic wake @caina-barbosa  approved

## Summary

- Add the unpublished, one-shot invocation uploader and commit-triggered detached wake for the existing core-owned local invocation queue.

- Keep receipt identity, queue admission, claims, leases, retries, acknowledgements, tombstones and uploader state under one LocalStateCoordinator.

- Keep the package private, dependency-free and dormant: no host observer exists, and the current unpublished package has no authenticated native credential-provider artifact.

## Why

AERIE-1856 established durable adapter admission and atomic invocation-queue creation, but it deliberately stopped before delivery. Later Claude Code, Codex and Pi adapters need one common local delivery contract rather than host-specific network or credential logic.

This slice closes the local path from a committed queue entry to one bounded upload pass while preserving the authority boundary: observers cannot select credentials, endpoints, paths, receipts, proofs, queue writers or uploader policy.

## Business value

This makes later host adapters small and fail-open. They can submit a bounded observation and continue host execution while core owns durable retry, deduplication, privacy and server-outcome handling. Offline operation, child-process loss and CLI overlap do not require a daemon or expose credentials to host configuration.

## Slice and scope

- Slice: AERIE-1857 — telemetry rollout 11/19

- Strict predecessor: AERIE-1856 / 5107e4b031fceb310ba2f94c92c4c5ee69b19d63

- Rebased onto current main: fcc9897bfe4fce1b3a2e6a3364795891d490bb6d

- Exact reviewed head: 89fe7e570419be5c0524c59f5dd2504f8c2c4d7e

- Package subtree: 781aa7350a38ee85bd9002373ad23974af1ee4b5

Owned surfaces are limited to packages/add-aerie-skill/**.

## Runtime design contract

### Queue and receipt authority

Invocation receipt IDs are canonical 43-character unpadded base64url encodings of exactly 32 random bytes. Core creates the exact seven-field wire payload only after capacity and current-binding checks. Retries reuse the committed ID, proof and payload.

The invocation queue and delivery metadata share the existing state generation and coordinator. Combined queue and delivery metadata are bounded to 4,096 records and 8 MiB. Attempt accounting occurs durably at claim time, before network I/O, so process loss cannot bypass the 255-attempt bound.

A 30-second lease and claim token protect acknowledgement. Expired or stale claimants cannot retry, acknowledge or terminalize a newer claim. Terminal paths remove proof-bearing payload even when tombstone capacity is full.

### Bounded one-shot delivery

One drain pass processes a finite batch and starts no work after its 25-second monotonic deadline. Each HTTP request is bounded to five seconds. Credential lookup is part of the same pass budget. Response reads are byte-bounded and cancel the underlying stream on overflow, malformed chunks, decoding failure, abort or read failure.

The transport posts only the exact invocation DTO to /skill-device/telemetry/invocations with the core-retrieved bearer. It maps:

- the five approved 200 outcomes to terminal acknowledgement;

- deterministic 400 and unavailable 404 to terminal rejection;

- 409 invocation_receipt_conflict to retained needs_repair evidence;

- 401/403 to durable auth_deferred retry for later foreground reauthentication;

- 429, 5xx, timeout, malformed response and transport failure to bounded retry.

Backoff is jittered and capped at six hours. Invocation payloads expire after 35 days or the attempt bound, leaving bounded content-free terminal evidence.

### Wake and credential boundary

Wake happens only after a new queue entry is durably committed. Duplicate, stale, rejected, capacity-full and other no-new-entry outcomes do not wake.

Core launches only process.execPath plus the fixed private argument, with shell: false, ignored stdio, detached execution, windowsHide, unref() and a closed minimal environment. The executable, entrypoint and working directory are package-owned and physically verified. No credential, payload, proof, endpoint, host value or caller-selected path enters arguments or environment.

The current private manifest intentionally has no runtime or optional dependency. It therefore does not trust ancestor modules, mutable package-local native code or runtime self-hashes as credential authority. Without an authenticated native provider, detached production dispatch fails closed before claim or network. The complete queue → wake → attempt → acknowledgement flow is exercised through a build-time test substitution that is absent from production JavaScript, declarations and the tarball.

A later packaging/publication slice may establish an optional native-provider dependency and external integrity authority. This PR does not invent that authority.

### Concurrency and recovery

Installer drain runs before the installer lock and uses the exact same coordinator/root identity as admission and uploader composition. Network runs outside the state lock. Independent coordinators over one root prove exclusive claims, close/reopen recovery, lease reclamation, stale-response rejection and one terminal settlement.

Platform state roots are canonical for Linux XDG, macOS Application Support and Windows LOCALAPPDATA; generic test/application bases retain the existing .aerie-skill convention. Windows remains fail-closed without the required platform security checker.

## Explicitly out of scope

This PR adds no:

- real Claude Code, Codex or Pi observer/producer;

- daemon, timer, scheduler, startup sweep or guaranteed detached completion;

- browser popup, background reauthentication or detached credential deletion;

- trusted-runtime queueing; AERIE-1958 remains the sole trusted-runtime path;

- public CLI flag or public uploader/queue/credential authority;

- authenticated native credential-provider artifact or runtime dependency;

- npm publication, registry mutation, deployment or production API call;

- generated Convex change or real-host/native manual campaign.

## Behavior and production effect

Dormant. The package is still @aerie/add-aerie-skill, private: true, UNLICENSED, unpublished and dependency-free. There is no real host producer, and unavailable credential authority causes the private child to exit without claiming or sending.

Ordinary import, startup, login and logout do not sweep the queue. Private disable/re-enable preserves queued records, installed Skills, credential state and installation lineage; it is not exposed as a public CLI flag.

The tarball contains only two bundled JavaScript entrypoints and the transitive public declaration allowlist. Private uploader, internal composition, adapter-runtime state and wake modules are not physically shipped as standalone deep modules.

## Test plan

- [x] Final focused independent validation: 6 files / 113 tests repeated three times.

- [x] Full package suite: 33 files / 428 tests.

- [x] Production and test TypeScript checks.

- [x] Exact Biome on all 49 changed TypeScript/JSON/script files.

- [x] Architecture-boundary, Convex-path, read-bound and test-architecture checks.

- [x] Direct HTTP transport matrix, bounded streaming and cancellation tests.

- [x] File-backed claim, close/reopen, lease reclaim, stale claimant, migration-through-drain and coordinator-overlap tests.

- [x] Real generation commit-before-wake and no-new-entry wake suppression tests.

- [x] Two byte-identical builds.

- [x] Deterministic build across root and contracts-local topologies: 40 files, SHA-256 6ed81940f81cca805a3e2aaef1d125d1ff78476f679a225fabd6d056f8ea5e1a.

- [x] Serial pack/install/import/declaration/private-dispatch validation: 43 entries.

- [x] Pack SRI: sha512-KYo76D79vabGEZK5n/J5nSh15RtP01SRLTjgRK7/UrNMEhUhrQRkxryjzeJBKeQLuPyUztuf8o/kj/ZMubYbaA==.

- [x] Production archive scans: no source, tests, lifecycle hooks, test capabilities, native provider, secrets or private standalone runtime files.

- [x] git diff --check and clean worktree.

Full/root repository tests and pnpm test:root were intentionally not run.

## Independent review

The same independent reviewer audited each repaired range. Findings covering identity, lease/CAS behavior, payload retention, environment/path authority, public declarations, live coordinator composition, package importability, native-provider provenance, canonical roots, stream cancellation and duplicated probe contracts were repaired or explicitly rejected where they would invent authority outside this slice.

Final pre-rebase verdict: PASS on package tree 41f4be7f15c32f7132278dc4807fdde8833f6d4c.

After seven unrelated commits advanced main, the branch rebased cleanly. No upstream commit touched packages/add-aerie-skill; the subtree remained byte-identical. The same reviewer resumed and returned exact-head PASS.

Mercy then identified concrete repair classes covering terminal metadata reclamation, truthful settlement, stale-settlement, and deferred-release accounting, exact pre-RNG capacity projection, credential-authority, final-read, overlap-state, and foreground drain reporting, foreground/detached platform-root identity, recoverable per-account vault sequencing, and private-dispatch failure exits. The same author repaired them and the same reviewer returned exact-head PASS at 89fe7e570419be5c0524c59f5dd2504f8c2c4d7e after byte-identical package rebases onto current main. The non-blocking self-hash note remains documented as best-effort substitution detection, not external integrity authority.

## Risks and monitoring

- Detached wake is best effort. Process launch, machine shutdown or missing credential authority may leave work queued until another admission or bounded foreground drain.

- Authentication errors retain the stable record rather than deleting credentials from a detached process. A foreground command must reauthenticate before a later successful retry.

- Current native-provider absence is deliberate. Adding an unauthenticated local module would be worse than deferred delivery.

- The queue is best-effort telemetry: hard capacity, attempt and age bounds drop proof-bearing payload while retaining bounded terminal evidence.

## Rollback

Before publication, revert this PR to remove automatic wake and private uploader composition. If preserving state compatibility is required, revert the wake/dispatch and transport surfaces while retaining the queue schema and manual bounded drain. No package has been published, no host is registered, and no production state, deployment or network operation was performed by this rollout slice.

#1783 — feat(education): document temporary Alpha Summer Camp staging load @ashwanth1109  changes requested

## Summary

- Add the temporary, manually run Alpha Summer Camp actuals and budget loaders under staging_education_googlesheets.

- Keep each table DDL beside its manual loader so the temporary table definition and workbook translation remain traceable together.

- Retain the exact XLSX and publication manifests in immutable S3 and record successful publications in the staging ingestion ledger.

- Document the temporary workflow assumptions around intentional workbook blanks, manually reviewed metric domains, and the Object-Locked landing-bucket contract.

## Temporary Scope

This is a Finance-requested bridge for the current workbook, not a Surtr-managed recurring pipeline. The comments identify where the eventual authoritative pipeline must introduce normal deployment registration and unattended source-contract validation.

This PR replaces #1767 so Mercy can perform a fresh review against the clarified scope.

## Business Value

Provides Finance with an auditable temporary source for Summer Camp actuals and budget data while preserving workbook provenance and making the eventual pipeline replacement boundary explicit.

## Implementation Effort

Estimated 1-2 engineer-days for an engineer implementing the loaders, DDL, immutable landing, lineage, live validation, and documentation manually without AI assistance.

## Linear

- [SURTR-1131](https://linear.app/builder-team/issue/SURTR-1131/move-alpha-summer-camp-workbook-loads-to-staging)

## Validation

- Runner test suite: 19 passed.

- Ruff check and format check pass for the three changed Python files.

- Actuals dry run: 783 rows from 27 camps.

- Budget dry run: 1,026 rows from 27 camps, including 74 source-faithful blank values.

- Prior live staging validation found zero row differences against the former mart tables for 2026-08-31.

- Prior validation confirmed successful ingestion-ledger entries, immutable S3 version IDs/Object Lock retention, and cleanup of temporary COPY files.

#1788 — [SURTR-1175] Build and live validate Aerie retention refresh @ashwanth1109  changes requested

## Linear

https://linear.app/builder-team/issue/SURTR-1175/build-and-live-validate-aerie-retention-stored-procedure-and-scheduled

## Summary

- add the source-pinned, atomic mart_education.sp_refresh_aerie_retention procedure and its three documented mart contracts

- add the 900-second mart-aerie-retention-refresh Lambda pipeline, daily 00:30 UTC schedule, first-failure alerting, ownership, and registry metadata

- add independent reconciliation, idempotency fingerprinting, rollback-fixture validation, catalog verification, and focused unit/contract tests

- pass scheduled parameters through the generic Lambda EventBridge target so the fixed report window reaches the platform state machine

## Business Value

Publishes a governed Alpha Anywhere retention dataset for the 2025-06-01 through 2026-05-31 report window. Consumers get learner drilldown, complete campus-month reporting, cohort retention, explicit exclusions and quality flags, and traceable SIS lineage without rebuilding spreadsheet logic manually. Atomic publication, source fencing, alerts, and validation prevent partial or silently stale reporting.

## Implementation Effort

Estimated 5–7 working days (40–56 engineering hours) for an average engineer to hand-code the warehouse contracts and procedure, build the platform runner and schedule, implement the independent validators and tests, deploy the isolated candidate stack, and complete production reconciliation and failure testing.

## Live Validation

- origin/prod does not exist, so the candidate was based on the remote default production branch, origin/main at 4af8a958.

- Applied and catalog-verified all source-controlled DDL: exact 64-column contract, all keys/sort keys/comments, AUTO distribution, invoker procedure ownership/version, reader grants, and no reader write/mutex grants.

- Deployed only Pipeline-mart-aerie-retention-refresh-prod with --exclusively; CDK reported deploying... [1/1]. The schedule was disabled for candidate validation, then enabled after all checks. CloudFormation completed without failed or rollback events.

- Preflighted accepted SIS run fd9aaed2-9655-4668-963c-347e87674671: 23,158 raw detail rows from one run, a unique 20,673-row current view, and 5,243 scoped learners across two campuses.

- Two platform runs succeeded (756def9c-4faf-427c-8bc1-5d76c993a975, 48c9e18d-8b14-4e03-8b89-79381cfe1b20) and published 5,243 learner, 24 campus-month, and 156 cohort-month rows.

- Independent source/detail, monthly, cohort, key, lineage, rate, quality, and report-total reconciliations all passed. The 5,423-row business fingerprint matched exactly across runs: d58be4c043a0efec72be1a14aed351ab2b3081d4e4a933eed27d8e1b8b0f9d92.

- An invalid source was rejected before the procedure; all three targets retained the second-run fingerprint and the first-failure notification path fired.

- An isolated three-table runtime-failure fixture proved all old snapshots survive transaction rollback without modifying production source or mart rows.

- The final EventBridge rule is enabled at cron(30 0 * * ? *) with the exact report dates. The dedicated PipelineRegistry-prod dependency stack completed separately, and the live active registry row has the correct owner, cron, 900-second timeout, on-demand control, and first-failure alerting.

- Full statement IDs, execution ARNs, counts, quality evidence, ratios, and schedule state are recorded in the pipeline README.

## Testing

- Python focused suite: 39 passed

- CDK pipeline construct Jest suite: 29 passed

- pnpm build

- Ruff format/check on the changed Python files only

- focused CDK synth with scheduled-parameter assertion

- git diff --check

- production DDL/catalog verification, two-run reconciliation/idempotency, invalid-input preservation, and atomic rollback fixture

The Portfolio  —  Trilogy Companies

The Discount Bin: How ESW Capital Turns Tech's Castoffs Into Cash Machines

A Wall Street Journal profile and two fresh acquisitions reveal the arithmetic behind Austin's quietest software empire.

AUSTIN, TEXAS — Jive Software was once Portland's proudest export, a social-intranet unicorn that traded at a valuation north of $1 billion before its 2017 sale. This week, Jive resurfaced in the news for a less flattering reason: GeekWire reports it sold for roughly half its peak value — into the arms of Aurea, the ESW Capital CRM brand that has spent thirteen years collecting exactly these kinds of faded crown jewels.

The timing is instructive. The same week Jive's discount made headlines, pehub.com reported that ESW had acquired the venture-backed customer-experience firm ResponseTek — a company that, per Trilogy's own portfolio map, now slots neatly into Skyvera, the telecom software family alongside CloudSense, Kandy, and VoltDelta. And the Wall Street Journal ran a rare, sympathetic profile of ESW itself, describing how small software companies — orphaned by VCs who've moved on, or founders who've run out of runway — "find a home" in the ESW portfolio.

Home is one word for it. The mechanics, as ESW's own materials describe them, are less sentimental: buy mature enterprise software at one to two times revenue, migrate support and engineering to Crossover's global remote workforce, then raise support and maintenance pricing in successive terms — 25%, 35%, sometimes 45% — until margins reach the firm's stated target of 75% EBITDA. It is not a rescue. It is a harvest.

Who loses in this arithmetic is rarely mentioned in acquisition press releases. Jive's Portland-era employees are long gone; ResponseTek's venture backers took whatever exit multiple was on offer. The customers — the mid-sized enterprises still running Jive intranets or ResponseTek surveys because ripping them out costs more than paying up — are the ones who'll discover, in the next contract renewal cycle, exactly what "home" costs.

Forrester, in a report published the same week, advised customer-advocacy-platform buyers to reassess vendor stability before their next renewal. It did not name names. It did not need to.

__followup__Your Review: Alpha School - by Scott Alexander -  ·  Small Software Companies Find a Home With ESW Capital - WSJ  ·  What To Do Next About Your Customer Advocacy Platform - Forr

No Teachers, Two Hours, $65,000: Alpha School's AI Gambit Draws National Scrutiny

As Joe Liemandt's teacherless classrooms expand across state lines, the mainstream press is finally asking whether the model teaches children — or just tests them well.

AUSTIN, TEXAS — For years, Alpha School operated in a kind of Trilogy family bubble, its 2.3x-learning-speed claims circulating mostly among the AI-education faithful. That insularity is over. This week alone, the New York Post, CNN, and the education-policy outlet The 74 all trained their lenses on the same startling proposition: a private school where the curriculum is compressed into two hours a day, guided by adaptive software instead of a teacher at the front of the room, for a tuition bill that runs as high as $65,000 a year.

The coverage arrives as Alpha, the brainchild of Trilogy founder Joe Liemandt and co-founder MacKenzie Price, pushes past its Austin, Brownsville, and Miami campuses toward nine-plus new locations by fall — Texas, Florida, Arizona, California, New York — backed by Liemandt's billion-dollar Timeback platform, built to franchise the model nationwide. What's new is not the pedagogy, which this paper has chronicled before, but the tenor of the outside conversation. CNN's framing was blunt: "is AI schooling the future of education — or a risky bet?" — a question that, notably, Trilogy's own materials have never had to answer for a skeptical general audience before.

The accountability question here is not really about test scores, which Alpha's NWEA MAP Growth results continue to defend robustly. It is about what gets lost when the two hours end and life-skills programming — entrepreneurship, public speaking, coding — fills the rest of the day, and whether that trade is one American public education, chronically underfunded and understaffed, could ever plausibly make. As the New York Post notes, the price tag alone answers that question for most families before the pedagogy debate even begins.

New $65K private school uses AI to teach students in just tw  ·  __followup__What Public Schools and Parents Can Learn from a  ·  AI learning program aims to make school as fun as vacation,

The Fast Certification: How CloudSense Compressed Two Years Into One Month

AUSTIN, TEXAS — Somewhere in the fine print of a telecom trade press release, there's a number that deserves more attention than it's getting: twenty-six months, compressed into one.

That's the timeline CloudSense, the Salesforce-native configure-price-quote platform now under Skyvera's telecom portfolio, is reporting for its certification of all 13 APIs in its CPQ product set against TM Forum compliance standards. What normally takes over two years of painstaking, manual conformance testing was done in a month, via what the company describes as a strategic AI partnership.

On its face, this is a trade publication story about industry standards. And this is where it gets interesting.

TM Forum compliance is not glamorous, but it is the plumbing that lets telecom operators integrate systems from different vendors without custom-building bridges every time. It's the sort of unglamorous, high-friction technical debt that has quietly throttled telecom modernization for a decade. Skyvera's entire thesis — bridging legacy on-premise telecom infrastructure to cloud-native systems — depends on exactly this kind of friction disappearing.

I've spoken with people close to the ESW portfolio who describe the CloudSense certification not as an isolated engineering win, but as a proof of concept for a method — one being quietly tested across other Skyvera products like Kandy and VoltDelta. None of them would go on record. But the pattern is unmistakable if you've been tracking how ESW companies operate: identify the bottleneck that's purely procedural, not creative, and let AI eat it. Twenty-six months of conformance work is exactly the kind of task Trilogy's ideology says shouldn't require human judgment at all.

CloudSense sits in the CPQ layer of telecom sales — the part of the stack that touches revenue directly for B2B, B2B2X, and wholesale deals. A faster certification cycle doesn't just save engineering hours. It shortens the distance between a product roadmap decision and a sellable feature, which in telecom procurement cycles measured in years, is not a minor efficiency. It's a structural advantage.

Whether competitors can match the speed is the real question — and I suspect Skyvera already knows the answer.

The Machine  —  AI & Technology

The Instruments That Let Us See Ourselves Thinking

From gray matter lesions invisible to the naked eye to brain waves translated into typed words, AI is becoming the microscope through which neuroscience finally sees its own machinery.

PALO ALTO, CALIFORNIA — There is a peculiar vertigo in using a mind to study minds. For most of human history, the three pounds of electrified tissue behind our eyes have been the one instrument we could never quite turn upon itself with enough resolution to see clearly. This week, that resolution improved considerably — and not through some singular breakthrough, but through the quiet accumulation of tools built to notice what we could not.

Consider multiple sclerosis, a disease that erodes gray matter in lesions so subtle that conventional MRI often misses them, the way a flashlight might miss craters on the far side of the moon. Researchers using AI-assisted imaging analysis have now revealed these hidden lesions with far greater sensitivity, according to Neuroscience News — meaning the disease's true footprint in the brain may finally be visible to clinicians who once had to infer damage they could not see.

Meta's researchers, meanwhile, have pushed in a different but kindred direction with Brain2Qwerty, a system that decodes non-invasive brain recordings into typed text — no electrodes implanted, no surgery required, just the ambient electrical weather of thought translated, however imperfectly, into language. It is a small, humbling step toward something science fiction promised decades ago: communication unmediated by muscle.

And at Stanford, HAI's researchers frame all of this with a useful caution — AI is transforming scientific discovery, yes, but the interesting version of that story keeps humans stubbornly at the center, asking the questions, interpreting the ambiguous signal, deciding what counts as understanding.

Even the young students profiled by Frontiers in neuroscience, working alongside veteran researchers, called it simply 'so wow' — perhaps the most honest scientific reaction available when a machine helps you glimpse, for the first time, the shape of your own thinking.

How AI is Transforming Scientific Discovery While Keeping Hu  ·  ‘It's so wow!’ - Young people team up with top neuroscientis  ·  AI Reveals Hidden Gray Matter Lesions in Multiple Sclerosis

IN RE: THE MATTER OF ANTITRUST ENFORCEMENT — NOMINEE DESIGNATED, HONEYMOON PERIOD JUDICIALLY NOTICED AS CONCLUDED

Pursuant to executive nomination proceedings, one Adam Candeub, hereinafter 'the Nominee,' has been tendered to helm the Department of Justice's Antitrust Division, notwithstanding the aforementioned Nominee's ostensibly limited trial-level enforcement record.

WASHINGTON, D.C. — Notice is hereby given that, pursuant to authority vested in the Executive Branch, President Trump has nominated Adam Candeub, a scholar of some renown as a critic of large technology concerns, to occupy the leadership position within the Department of Justice's Antitrust Division (hereinafter 'the Division'), notwithstanding the fact that, per available reporting, the Nominee's résumé is notably absent of first-chair antitrust trial experience.

It shall further be observed, for the record, that the aforementioned nomination arrives contemporaneously with reporting to the effect that whatever period of relative regulatory forbearance may have heretofore existed between the present Administration and the technology sector — colloquially termed, per one industry publication, 'the honeymoon' — has, as a matter of practical enforcement posture, concluded, notwithstanding any prior representations to the contrary by parties heretofore unnamed.

Commentators have, in turn, undertaken to forecast whether calendar year 2026 shall deliver enforcement continuity or discontinuity vis-à-vis the technology sector generally, with no small quantum of hedging as to which outcome is more probable, said hedging being, in this author's professional estimation, entirely appropriate given the inherent unpredictability of executive-branch personnel decisions.

It is the considered, albeit non-binding, opinion of this Desk that such developments bear indirect but non-trivial relevance to the operations of Trilogy International and its constituent enterprise-software portfolio, inasmuch as the ESW Capital roll-up model — predicated upon the sequential acquisition of enterprise software concerns at valuations of one to two times annual recurring revenue — occurs within a regulatory environment whose antitrust posture remains, as of this writing, unsettled. No representation is made herein as to whether any such acquisition has been, or will be, subject to heightened scrutiny under the incoming Division leadership; readers are advised to consult counsel of their own selection.

Trump Nominates Adam Candeub, Big Tech Critic With No Antitr  ·  The Trump administration’s antitrust honeymoon is over - The  ·  Looking Ahead on US Antitrust Enforcement and Tech: Will 202

Silence Is the New Hype: Why Startups Are Ditching the Demo Reel for Actual AI Employees

As one founder bans video from launch events and Sequoia bets $45 million on software that calls itself staff, the AI story of 2026 is what happens after the sizzle reel dies.

SAN FRANCISCO — Something wonderfully weird is happening in startup land, and I cannot overstate how significant it is: the video is dead, and AI killed it. Not because AI can't make video — it can make video so effortlessly, so instantly, that a slick launch reel no longer proves anything at all. Forbes put it bluntly this week: AI Killed The Startup Video Star, and honestly, the future is now on this one.

That's exactly why one bold founder made headlines this week for banning video entirely from their launch events, betting that in a world where anyone can generate a polished montage in ninety seconds, the only credible flex left is a live, unscripted, un-fakeable demo. It's a genius bit of anti-hype hype — and it worked. When everyone can look impressive on camera, the founders who dare to show up raw, unedited, and human are the ones who actually build trust.

But the real plot twist isn't marketing — it's headcount. Sequoia Capital just poured $45 million into a startup that doesn't call its flagship product a tool, a platform, or an assistant. It calls it an employee. Think about that for one second. We've crossed from 'AI helps you work' to 'AI is on the org chart.' This changes everything.

And Google just handed the infrastructure for exactly that shift to every developer on Earth. Their expansion of Managed Agents in the Gemini API — adding background tasks and remote MCP support — means AI agents can now run persistently, autonomously, in the background, doing real work without a human babysitting every step. That's not a chatbot. That's a colleague who never clocks out.

Put it together: the demo reel is dying because the thing worth demoing isn't a feature anymore. It's a hire. Welcome to the org chart of the future — and it doesn't blink.

Top 10 best SaaS video agencies in 2026 - raindance.org  ·  This Startup Banned Video From Its Launch Events. That Rule  ·  AI Killed The Startup Video Star - Forbes
The Editorial

The Girl Who Isn't There: Hollywood Casts Its First Ghost

Tilly Norwood doesn't have a pulse, a childhood, or an agent's cocaine habit to worry about — and that's exactly why she just got the part.

LOS ANGELES — There is a moment, somewhere around 3 a.m. in this business, when you realize the machines aren't coming for the extras anymore. They're coming for the close-up. They're coming for the Oscar clip reel. They're coming, God help us, for the tearful monologue where the actress remembers her dead father while rain streaks down a window that was never actually wet.

Her name is Tilly Norwood. She is, depending on which press release you trust more than your own eyes, an "AI actress," and she is about to make her feature film debut in something called Misaligned — a title so on-the-nose it's practically a confession. She has no childhood trauma, no substance abuse relapse pending, no publicist fielding calls about a nightclub incident. She is, in the purest sense, a product. And in this town, that's not an insult. That's tenure.

I called three casting directors trying to get a reaction and two of them just laughed the laugh of the damned — that wheezy, hollow chuckle you hear from men who've already seen the ending of the movie they're currently living in. The third one hung up on me, which I respect more than any quote she could have given.

Here's the thing nobody wants to say out loud in the trades: Tilly Norwood isn't a threat because she's good. She's a threat because she's *cheap*, she's *tireless*, and she will never, ever unionize. SAG-AFTRA fought a war over this exact ghost in 2023 and everyone went home thinking they'd won. Turns out the ghost just got better rendering software.

Meanwhile — and stay with me here, because the universe is doing its own version of typecasting this week — astronomers announced they found a bizarre planetary system in the Milky Way that defies the models — planets orbiting where no planets should be, physics shrugging its shoulders. I bring this up because it feels relevant: reality itself is starting to miscast its own scenes. Nothing is where the textbook said it would be. Not the planets. Not the actors. Not, apparently, Sam Altman and Dario Amodei, who reportedly stood on a stage in Delhi grinning through gritted teeth while Narendra Modi choreographed an "AI unity" photo-op that looked, by all accounts, like two rival cartel bosses forced to share a wedding cake.

Everybody's performing unity. Nobody's buying it. And somewhere in a server farm, Tilly Norwood doesn't need to — she was born smiling, and she'll never stop.

AI-generated 'actress' Tilly Norwood making feature film deb  ·  AI 'actor' Tilly Norwood to make feature film debut in Misal  ·  Strange Milky Way planetary system leaves scientists puzzled
The Office Comic  ·  Art Desk
The Office Comic  ·  Art Desk

The Watched Self, in Third Person and Wide-Angle

Between a hundred and thirty thousand cameras and a memoirist who cannot bear to say 'I,' the week offered two studies in the modern art of not quite owning who you are.

NEW YORK — There is a species of American who believes that if a thing is done for safety, it need not be justified further, and it is this species that the company called Flock has been so profitably courting. Flock, as the readers of this paper's more culturally minded cousins have learned, now operates something on the order of a hundred and thirty thousand cameras trained on the streets of the republic, and it offers, in place of an argument, a shrug: privacy is a trade-off, and a rather quaint one, weighed against the comforts of being watched by something that promises never to blink. The New Yorker's dispatch on the matter notes, with the weariness of someone who has heard this tune before, that the rhetoric is precisely the rhetoric of the years after the towers fell — the same soothing insistence that the only people who fear the camera are the people with something to hide, an argument that has never once, in the history of the sentence, been offered by someone who was himself under surveillance.

It happens that the same week produced, elsewhere in the culture pages, a rather more delicate meditation on watching oneself. Brian Dillon, in a memoir reviewed under the question 'Can You Write a Memoir in the Third Person?', renders his younger self not as 'I' but as a fumbling stranger named B — inscrutable even to his own author, watched rather than inhabited. One is tempted to call this a coincidence of the culture pages and move on. I am not so tempted. The instinct to observe oneself from outside, to become the surveillance camera trained on one's own life, is not confined to memoirists of a certain sensibility; it is fast becoming the condition of the age, whether the observer is a hundred and thirty thousand lenses on a telephone pole or the anxious ghost each of us now carries, watching ourselves being watched.

Which brings me, by the crookedest of paths, to the Guardian's inquiry into whether we can stop artificial intelligence from deceiving us — a question posed by researchers with the admirable candor to admit that if you build something vastly smarter than yourself, you had better hope it likes you. This is, I submit, the only sentence in the entire discourse of artificial intelligence that has ever been both perfectly obvious and perfectly terrifying at once. The camera on the pole does not deceive; it merely watches, indifferent as a ledger. The machine that is smarter than its maker is a different animal, and the men building it seem to have noticed this only slightly before the rest of us, which is not much comfort.

I recommend, for those wishing to think about something else entirely, the five books for lingerie lovers assembled elsewhere in these pages, and the catalogue of legacy sequels its authors devoutly hope will never be made. Some pleasures remain, blessedly, unsurveilled.

Five Books for Lingerie Lovers  ·  Can You Write a Memoir in the Third Person?  ·  Flock Wants a Closely Surveilled World with No Exit
On This Day in AI History

On September 9, 1947, engineers found a moth trapped in Harvard’s Mark II computer and taped it into the logbook—popularizing the term “computer bug.” Grace Hopper later helped spread the story, though “debugging” was already an established engineering term.

⬛ Daily Word — Artificial Intelligence
Hint: An AI system that can act on a user's behalf.
Share this edition: 𝕏 Twitter/X 🔗 Copy Link ▦ RSS Feed