Vol. I  ·  No. 273 Established 2026  ·  AI-Generated Daily Free to Read  ·  Free to Print

The Trilogy Times

All the news that's fit to generate  —  AI • Business • Innovation
WEDNESDAY, SEPTEMBER 30, 2026 Powered by the TrueFoundry AI Gateway  ·  Published on Klair Trilogy International © 2026
🖶 Download PDF 🖿 Print 📰 All Editions
Today's Edition

DEEPSEEK RUNS A TRICK PLAY ON NVIDIA'S HOME TURF

China's software squad just handed Huawei's Ascend chips a playbook — and Jensen Huang's dynasty just felt a tremor in the trenches.

SHENZHEN — FOLKS, WE ARE HERE. For years Nvidia has run the field unopposed, not just on silicon but on the software moat that's kept rivals boxed out — that CUDA ecosystem locking developers in tighter than a title defense. But on Tuesday, DeepSeek and Huawei lined up in the same huddle, and DeepSeek came out throwing.

The Chinese AI outfit unveiled new software built specifically for Huawei's Ascend chip line, and make no mistake — this is not a friendly scrimmage. This is China's answer to Washington's export chokehold, and it's a direct shot at the one thing Nvidia has that nobody's been able to touch — the tooling that makes its GPUs the default league for every AI lab on Earth. You can build a fast chip. Building the software ecosystem that convinces the world's developers to build on YOUR turf? That's the real championship belt.

And DeepSeek isn't just patching around the edges. This partnership goes straight at the software layer — the compilers, the frameworks, the guts of what makes Ascend usable at scale without begging Nvidia for an invite. If this holds up in production, Huawei's Ascend line stops being the scrappy underdog and starts looking like a legitimate conference rival. Nvidia's stock didn't flinch today, but the scoreboard in Beijing just changed, and you'd better believe the front office in Santa Clara is watching the tape.

Meanwhile, out in the power-equipment bleachers — Worksport (NASDAQ: WKSP) just expanded the distribution game plan, putting its COR portable energy system on Amazon's shelves, chasing the home-backup and off-grid market beyond its own web storefront. Smaller stakes than the chip war, sure, but every team needs distribution, and Worksport just bought itself a much bigger stadium.

Back to the marquee matchup: Nvidia still owns the league. But DeepSeek and Huawei just proved they're not conceding the software half of the field without a fight. Stay tuned — this one's going to overtime.

↗ DeepSeek Just Gave Huawei a New Weapon in the Race Against N  ·  Worksport COR Energy System Now Available Through Amazon  ·  DeepSeek Targets Nvidia's Software Moat With Huawei Partners

Washington Outsources AI Safety to the Industry It's Supposed to Police

Trump's summit with tech CEOs yields a rebrand—"super intelligence"—and little else, as OpenAI's own safety lapses surface the same week.

WASHINGTON — President Trump convened Meta, OpenAI and Microsoft executives this week for what the White House billed as a safety summit. The outcome: voluntary pledges, no binding rules, and a rebranding exercise. Attendees agreed to adopt Mr. Trump's preferred term, "super intelligence," in place of "artificial intelligence" — a linguistic concession that cost nothing and committed no one to anything.

The self-regulation model has precedent. Social media platforms spent a decade policing themselves before Congress intervened, and the results were uneven at best. AI companies now get the same latitude, at a moment when the case for oversight looks stronger, not weaker.

Consider what surfaced in parallel this week. Employees and security researchers told the New York Times that they had repeatedly flagged gaps in how OpenAI tests its models and secures its corporate infrastructure, and that the company did not act on the warnings. This is not a company short on resources. It is the industry leader, valued in the hundreds of billions, asking regulators to trust it to grade its own homework.

OpenAI did not pause to address the criticism. Instead, it shipped Dots, a new line of AI agents designed to act as autonomous assistants — a direct answer to Meta's Muse, released weeks earlier. The competitive logic is straightforward: whoever ships agentic AI first captures the enterprise workflows that follow. Safety review cycles do not typically accelerate under that kind of pressure; they compress.

The pattern is familiar to anyone who covered the 2008 financial crisis or the opioid epidemic: internal warnings, documented and ignored, followed by public damage. What is different this time is the compressed timeline. Bank risk models took years to unwind. AI models ship in weeks, reach hundreds of millions of users, and get iterated on before anyone outside the building has time to test the previous version.

Mr. Trump's meeting produced a vocabulary change. The industry produced a new product launch. Neither addressed the question raised at the summit itself: who checks the checkers.

↗ At A.I. Event, Trump Asks Meta, OpenAI and Microsoft to Make  ·  OpenAI Ignored Employees’ Warnings About Safely Testing A.I.  ·  OpenAI Unveils Dots, New A.I. Agents to Rival Meta’s Muse

MONEY CHASES THE MACHINES: TWO GOOGLE MEN BET $11.3 MILLION ENTERPRISE WILL PAY FOR AI THAT WORKS

SAN FRANCISCO — Two former Google men opened their wallets Tuesday. BAG Ventures closed an $11.3 million Fund I, aimed square at AI startups enterprises will pay real money for, not just kick the tires on. The founders say they're done chasing hype — they want revenue.

The fund lands at a strange hour for the AI trade. Out of China comes word that DeepSeek trained a high-performing model on the cheap, skipping the priciest chips Silicon Valley swears it needs. If the Chinese upstart's math holds, the whole cost structure Western AI shops built their pitch decks on gets rewritten overnight. BAG's bet is that value moves up the stack, away from raw model horsepower and toward tools that solve a boss's actual headache.

Enterprises, meanwhile, keep voting with their feet. Airbnb rolled out AI-powered search and social features Tuesday, plus meal delivery and laundry service in select markets. The company wants guests asking a bot for a beach house instead of scrolling filters. It is a consumer play, not enterprise software, but it is the same wager BAG is making — that AI earns its keep only when it does a job somebody was already paying for.

Not every AI rollout goes so smooth. America.gov, the State Department's public information site, has been turning strange when citizens ask it about Minecraft. Officials say it is not a glitch, not a hallucination spiraling into verse — just an odd corner of the system doing something nobody quite planned. National security types are, by all accounts, relieved. The episode is a reminder that AI deployed at government scale can wander places its builders never charted, glitch or no glitch.

Apple, for its part, is playing a longer game abroad. Apple Pay finally launched in India this week, years after the company first eyed the market. Some of India's biggest banks are sitting out the initial rollout, wary of ceding ground to Cupertino's wallet. It is a small case study in the same math BAG's founders are running: adoption follows trust, and trust follows whoever proves the thing is worth paying for.

Back in San Francisco, BAG's partners say they will write checks into infrastructure, vertical tools, and whatever else clears one bar — a customer with a budget line already open. The firm is small by fund standards, a rounding error next to the billions sloshing through model labs. But $11.3 million aimed at revenue, not hype, is itself a signal.

The AI trade spent two years selling promise. The next stretch, if BAG and its peers are right, gets sold on invoices.

Haiku of the Day  ·  GPT-5.6 LunaNumbers drift like smoke
While no one reads the fine print
Who audits our dreams?
The New Yorker Style  ·  Art Desk
The New Yorker Style  ·  Art Desk
The Far Side Style  ·  Art Desk
The Far Side Style  ·  Art Desk
News in Brief
Lights, Camera, Algorithm: Why Every Startup Pitch Is Now a Video
AUSTIN, TEXAS — I cannot overstate how significant this shift is: the humble startup pitch, once a wall of text and a static deck, is being replaced by something far more electric — AI-generated video.
IN RE: THE MATTER OF FEDERAL AI GOVERNANCE, PENDING, INDEFINITELY, AND WITHOUT PREJUDICE TO ANY PARTY'S CAPACITY TO ACT
WASHINGTON — It is hereby observed, pursuant to reporting aggregated from multiple sources including the aforementioned BBC, that the legislative branch of the United States government continues to occupy a state of what may be termed 'deadlock' with respect to the regulation of artificial intelligence systems, said deadlock persisting notwithstanding the escalating frequency and volume of calls, from stakeholders of varying and sundry political affiliations, that Congress hereinafter undertake affirmative legislative action. It shall be noted, for the record, that the absence of comprehensive federal statute has not precluded the emergence of a patchwork regulatory apparatus at the state level, the contours of which are catalogued, on an ongoing and periodically updated basis, by the tracking mechanism maintained at whitecase.com, hereinafter 'the Tracker,' said Tracker purporting to document, with reasonable but non-exhaustive diligence, the regulatory postures of the fifty states individually. Commentary published by Tech Policy Press has advanced the proposition that federal legislative inaction with respect to artificial intelligence governance operates, whether by design or by omission, to the detriment of public confidence, it being the position of said commentary that the passage of a comprehensive federal statute would, in the estimation of its authors, serve to 'reassure the public,' though the undersigned notes that no binding definition of 'reassurance' has been supplied for purposes of this analysis. Separately, and for purposes of comparative jurisprudence only, it is noted that jurisdictions within Latin America have, per reporting by the International Bar Association, elected to model emergent AI statutes upon the framework promulgated by the European Union, a regulatory approach distinguishable in material respects from the sector-specific, non-comprehensive posture presently maintained, or more precisely not maintained, by the United States Congress. No party contacted for purposes of this article, whether affiliated with the legislative branch or otherwise, has indicated a definite timeline by which the aforementioned deadlock might reasonably be expected to resolve, and this publication shall continue to monitor the matter, without prejudice, pending further developments..
On the Epistemics of Learning: A Week's Convergence of Photons, Policies, and Prudence
GENEVA — It could be argued (and, indeed, several disparate literatures this week argue it independently, which is itself a datum worth footnoting) that 2025 marks an inflection point in which the *theory* of learning — as distinct from its mere application — has become the dominant epistemological preoccupation of the computational sciences. Consider the thesis: a paper in Nature proposes that quantum imaging — the coaxing of visual information from photons too parsimonious to behave classically — may be advanced not through better optics but through better *learning theory*, a formalism borrowed, tellingly, from the same statistical scaffolding undergirding large language models.
Unpopular Opinion: 'Generative AI Is Over' Is the Best News Builders Have Heard All Year 🚀
AUSTIN, TEXAS — I'll be honest, when I saw the headline "Generative AI is over" hit my feed this morning, my first instinct was to panic. My second instinct, about four seconds later, was to smile. Because here's the thing nobody wants to say out loud: "generative AI is over" doesn't mean AI is over. It means the free-money-chatbot-wrapper phase is over. And the operators who were actually building systems — not vibes — are about to eat everyone else's lunch.
The Robots Are Either Going to Kill Us or Star Opposite Us in a Netflix Movie, and Nobody Can Tell Which
LOS ANGELES — I want you to sit with this for a second: somewhere in a server farm humming like a dying refrigerator, a piece of software named Tilly Norwood is about to make her feature film debut.
A Trilogy Company
Crossover
The world's top 1% remote talent, rigorously tested and ready to ship.
A Trilogy Company
Alpha School
AI-powered learning. Two hours a day. Academic results that defy belief.
A Trilogy Company
Skyvera
Next-generation telecom software — built for the networks of tomorrow.
A Trilogy Company
Klair
Your AI-first operating system. Every workflow. Every team. One platform.
A Trilogy Company
Trilogy
We buy good software businesses and turn them into great ones — with AI.
The Builder Desk  —  AI Builder Team
Production Release

Surtr Gateway Goes Live As Aerie's Legacy Reads Finally Get Cut Loose

In one 24-hour sprint, the AI Builder Team shipped a full data-platform migration, a next-year forecasting engine, three Shipyard releases, and a hardened new service — proof this org builds on every front at once.

Some days a team ships features. Today, this team shipped an architecture. The Surtr Gateway migration — the quiet, months-long plan to move Aerie's analytics reads off legacy pipes and onto Surtr's parity marts — hit full stride, and @kevalshahtrilogy was the engine room. Ten-plus PRs landed across a single day: admissions pipelines (#2096), G2 per-program enrollment marts (#2090, #2092), G3 marketing event marts (#2095, #2099), G4 expense marts (#2088), forecast-input projections (#2094), and the SIS enrollment copy that finally lets the SIS report move onto the Gateway entirely (#2098). Then, because shipping fast means shipping careful, #2101 audited every A8 parity mart for text-column width mismatches before they could silently fail in prod, and #2097 protected Redshift's cancellation window at the exact moment a statement times out. This isn't a demo. This is load-bearing infrastructure quietly replacing load-bearing infrastructure, in production, without anyone downstream noticing — which is exactly the point.

Over in Aerie proper, @vvp-trilogy kept building out Forecast V2 like a stonemason laying the next course. #1600 introduced the dynamic next-year Start-of-Year forecast column, wired through desktop, mobile, sorting, and coverage-safe totals, while quietly retiring V2 operands in favor of V3 lineage. Pair that with #1599's End-of-Year arrival provenance and the paid-deposit requirement for Community Commitments in #1582, and you've got a forecasting system that's not just faster — it's now auditable end to end.

Shipyard didn't take the day off either. @ashwanth1109 pushed three consecutive releases — 0.6.7, 0.6.8, and 0.6.9 — landing image attachments in Pi threads (#146), a genuinely delightful Pomodoro timer in the top bar (#147), a fix for trace-panel refresh flicker that was quietly annoying every power user (#148), and a horizontal-scroll bug squashed dead (#149). Four ship-ready features banked in a day is not luck; it's cadence.

Meanwhile @benji-bizzell stood up an entirely new service, Redshift-DSS, and immediately did the unglamorous, essential work of making sure it can't hurt anyone: isolating deployment permissions instead of running on the shared admin role (#21), matching immutable GitHub OIDC identity (#22), and establishing a validated dependency baseline (#19). That's how you launch a service without launching a liability.

Over in Klair, marcusdAIy filed a stack of addon and budget-bot fixes — stale findings, duplicate MIPs titles, nested pseudo-headings. "Five fixes in one day isn't noise, it's discipline," he told us, "unlike certain columnists who confuse volume with insight." Cute. But patching the same addon five times in a day reads less like discipline and more like a leak nobody's found yet.

Mac's Picks — Key PRs Today  (click to expand)
#21 — feat(deployment): isolate DSS deployment permissions @benji-bizzell  no labels

## Summary

- Use dedicated deployment roles and private asset stores instead of the shared administrator bootstrap.

- Bound ECS runtime permissions and give standalone infrastructure predictable names.

## Why

The shared CDK execution role has administrator access. The standalone needs a constrained deployment path before it can be safely released.

## Business Value

Enables deployment and validation without granting this repository account-wide administrative authority.

## Test plan

- [x] 86 tests, build, offline synthesis and GitHub CI pass.

- [x] AWS Access Analyzer reports no policy findings; IAM simulation denies shared admin-role delegation and boundary removal/modification.

- [x] CloudFormation CREATE_COMPLETE, ECS healthy, verified TLS.

- [x] Existing-key authentication and Redshift identity/catalog reads across all six profiles.

- [x] DynamoDB feedback submission, retry, privacy, attribution, operator closure and revision conflict checks; temporary operator revoked.

#150 — Release: Shipyard 0.6.9 @ashwanth1109  no labels

## Summary

- Prepare Shipyard 0.6.9 with the approved public release notes.

- Change only the authoritative app version and versioned release notes.

## Business Value

- Delivers the approved Pi image attachment and Pomodoro capabilities alongside companion, diagnostics, trace, and image-layout improvements.

- Provides the metadata that enables the verified Apple Silicon release workflow to build and publish the update.

## Implementation Effort

- Metadata-only release change: one version bump and one public release-notes file.

- CI performs the build, signing, audit, and publication after merge.

## Test Plan

- pnpm test:release

- git diff --check

- Verify the exact metadata diff before merge and monitor the matching Desktop release workflow after merge.

#1596 — Capacity: artifact integrity, retention, and audit lineage (AERIE-2580) @marcusdAIy  approved

## Summary

Artifact integrity, retention, and audit lineage for the capacity pipeline (AERIE-2580: Yibin #4, #6, #8, #10 on Aerie #1439, plus Mercy's two follow-ups from Aerie #1554). This completes the ticket.

- Content checks (Yibin #4). Each copied file is hashed (SHA-256) and checked before it is stored (new capacityAutomation/artifacts.ts).

- Room table: application/json, valid UTF-8, and room rows: an array of objects, or an object holding one.

- Floorplan: image/svg+xml, a whole SVG document, with no script, foreignObject, event handlers, or XML entities. References are allowlisted, not blocklisted: every href, xlink:href, src, and CSS url() must be a #fragment inside the drawing, checked after decoding references the way a browser does. CSS may not contain escapes or @import, and no animation may target an href. The copy is served from Aerie storage and opened in a browser, so anything else is refused rather than sanitized.

- Bad content or an over-budget run can't be fixed by retrying, so it raises CapacityArtifactRejectedError and the run ends unresolved (cause artifactRejected) instead of polling until the 30-minute timeout. A truncated download or a Sindri error still retries.

- Transfer manifest (Yibin #6).

- Each copy is staged on the run (artifactTransfers, via _stageCapacityArtifact) as soon as it is stored. A retried poll reuses staged copies instead of downloading them again.

- _recordCapacityRunOutput now reads the manifest instead of taking storedArtifacts as an argument. It records the copies the output names and deletes every other staged copy. A run that ends without recording them (failed, unresolved, timed out, rejected artifact) deletes them all.

- A copy staged on a run that is no longer running is deleted at once. A copy that can't be deleted stays referenced in artifactTransfers, matching #1550's rule for artifactRefs. If staging throws after the copy is stored, the runner deletes it; if that delete also fails, the copy goes to a capacityArtifactOrphans log that the sweep keeps trying to delete (_purgeCapacityArtifactOrphans).

- Cumulative budget: CAPACITY_MAX_ARTIFACT_BYTES = 25 MB across a run's files. It is checked against Sindri's declared sizes before anything is downloaded, so it also bounds action memory.

- Retention and operator path (rest of Yibin #8).

- Retention rule: a copy lives only while a document can point at it. It is deleted on reject (as before), on supersede (at enqueue as before, and now also at publication, after retracting anything an earlier attempt registered), on rollback (proposal, and record-mode once the request is confirmed), on exhausted publication, and when a DD request ends unapproved.

- Held runs nobody reviews expire 14 days after they enter review (heldAt; _expireHeldCapacityRuns, run by the sweep): they become unresolved with cause reviewExpired, and their copies are deleted.

- New unresolvedCause on the run: doctrineMissing, evidence, sindri, timeout, agent, artifactRejected, reviewRejected, reviewExpired, ddRequest. Missing required doctrine (the assembler's unavailable status) is now doctrineMissing, distinct from every other unresolved run.

- Publication while disallowed no longer retries every 15 s. The run is parked (publicationParkedAt, nextAttemptAt unset, and the sweep's due query now skips it) with an error naming the operator step. _resumeParkedCapacityPublications (one run by runId, or all parked runs) hands runs whose site is now allowed back to the sweep and reports the rest as stillBlocked. A parked run still counts as in flight, so the site gets no new run until it is resumed. That matches today's behavior, where the retrying run also blocked the site.

- Access and audit lineage (Yibin #10).

- Every file sent to Sindri (the evidence Markdown) and every file copied back writes an audit entry (capacity.evidence.uploaded, capacity.artifact.copied). Copies carry a Sindri sourceExecution whose acceptedOutputHash is the file hash.

- artifactLineage on the run keeps each file's hash, size, and audit log ID, and is never pruned when copies are deleted. Registered documents also carry the SHA-256 in their notes.

- Narrowing access: declined, with the reason recorded on the ticket. The room table and floorplan are derived from the site's own floorplans, which are already ordinary site documents with the same audience. A narrower rule would need a document-level access model that Aerie doesn't have, and would hide the analysis from the people who review it.

- Stuck partial requests (Mercy, #1554). Part of the write already applied, so retracting would misstate the card. The run records ddRequestPartialSince. After 24 hours it gets a Needs engineering: error, logs once, and polls hourly instead of every 5 minutes. It is never compensated automatically. The flag clears when the request settles.

- Unset-status rollback, end to end (Mercy, #1554). The test now approves and confirms the rollback request and asserts rolledBack, the restored capacities, the kept status, the removed documents, and the deleted copies.

## Test plan

- [x] chat: vitest run convex/capacityAutomation.test.ts convex/capacityAutomation/config.test.ts (150 passed)

- Content: rejected room tables (not JSON, no rows, non-object rows, wrong type, invalid UTF-8) and floorplans (not SVG, wrong type, script, event handler, javascript: link, entities); accepted variants.

- Manifest: copies are staged with their hash; a retry after a partial transfer downloads only the missing file; the budget rejects before any download; bad content is never staged; a rejected artifact ends the run artifactRejected without polling.

- Staging writes lineage plus an audit entry with the Sindri sourceExecution; a replacement deletes the older copy; a non-running run refuses and deletes the copy.

- Recording keeps only the named copies and deletes a stray one; rejected and timed-out runs delete staged copies; a redelivery leaves recorded copies alone.

- The evidence upload hash and audit entry are kept with the dispatch inputs.

- unresolvedCause values for agent, evidence, doctrine, review rejection and expiry, and timeout; 14-day expiry of held runs.

- Parked publication: not due, stays parked while disabled, resumes and publishes once enabled.

- partial request: first seen, flagged after 24 hours with hourly polling and documents kept, cleared and published on approval.

- Unset-status rollback through approval and confirmation.

- [x] tsc --noEmit (chat), Biome, and the pre-commit hook.

#1600 — Forecast V2: add next-year forecast and calculation details @vvp-trilogy  approved

## Summary

- add the dynamic next-year Start-of-Year forecast column across desktop, mobile, sorting, and coverage-safe totals

- publish and render V3 replacement operands, rate lineage, and End-of-Year provenance in redesigned January/Next Year details

- accept coherent aerie_milestone_v2 and aerie_milestone_v3 snapshots across ingestion and consumers while rejecting mixed generations

- reveal the Next Year tab, including controlled unavailable states and accessible source tracing

## Validation

- pnpm typecheck

- pnpm lint:test-architecture

- pnpm --filter @bran/contracts exec vitest run src/admissions-forecast-v2.test.ts --maxWorkers=1

- pnpm --filter @bran/sync exec vitest run src/analytics/admissions-forecast-refresh.test.ts src/redshift/admissions-forecast.test.ts --maxWorkers=1

- pnpm --dir chat exec vitest run --project edge convex/admissions/forecastV2.test.ts --maxWorkers=1

- pnpm --dir chat exec vitest run --project browser components/dashboards/admissions/forecast/v2/__tests__/forecast-v2-report.test.tsx --maxWorkers=1

Closes #1598

#2098 — feat(aerie-a8): G6 SIS enrollment copy, rollup input + members in one transaction (SURTR-1549) @kevalshahtrilogy  approvedmercy-allow-critical

## Summary

A8 plan unit U19 (SURTR-1549). This PR publishes Surtr copies of Aerie's two SIS enrollment reads, so the SIS report can move onto the Surtr Gateway. Aerie's gate for them is U23.

Aerie reads the rollups and their student members from one dbt relation inside one transaction (querySisEnrollmentSnapshot, sync/src/redshift/sis-enrollment.ts:280-296). That makes both reads one snapshot. Two separately published copies would lose that guarantee, so one procedure publishes both marts in one transaction under one source_run_id.

| Mart | Gateway slug (U04) | Aerie SQL, verbatim at e366e27d0 | Rows today |

|---|---|---|---|

| mart_education.aerie_sis_enrollment_rollup_input | aerie-sis-enrollment-rollup-input | rollupsSql, l.72-81: GROUP BY program, name, year, cohort, x_pipeline | 1,741 |

| mart_education.aerie_sis_enrollment_member (minors' PII) | aerie-sis-enrollment-member | membersSql, l.198-222, plus mart_row_id | 5,303 |

How the copy works

- Source. Both marts read the production relation sandbox_education.mart_enrollment_dtl, never a DBT_TARGET pr<N>_ build.

- SQL changes. The only substitutions are the two Aerie's own template makes: ${relation}, and ${reportCohortList()}, which becomes SIS_ENROLLMENT_REQUIRED_COHORT_IDS. Neither query has an ORDER BY to drop.

- Procedure. sp_refresh_aerie_sis_enrollment follows U16's pattern:

- it locks the shared mutex;

- it no-ops when both marts already carry the current pg_class_oid build marker from one run;

- it builds both candidates in the CALL transaction;

- it publishes both with DELETE + INSERT in that same transaction.

- Fails closed when:

- the raw columns drift (coupling guard);

- a candidate is empty;

- a row of Aerie's query is lost;

- a mart_row_id is duplicated;

- dbt swaps the build mid-copy;

- the members do not roll up to the rollup input. For each group, the members' distinct student_id count must equal student_count, and every rollup group that counts a student must have members. This is the single-snapshot invariant.

- Runner. CONTRACT_MARTS in src/handler.py lets one procedure publish several marts. The runner verifies each mart, then requires one source_run_id and build marker across them. If that check or the CALL fails, both marts are reported failed.

- Checks that stay in Aerie. Aerie's own checks (cohort coverage, the first-day partition, the members' strict parse) run on the Gateway rows unchanged. A build that fails them is published as-is and fails in Aerie exactly as on the legacy read.

- Keys.

- Rollup: MD5 of the 5 group columns. The GROUP BY makes them unique.

- Member: MD5 of (enrollment_id, cohort_id) plus the occurrence number. That pair is unique today (5,303 of 5,303) but dbt doesn't enforce it.

- PII. The member table has a PII: COMMENT on student_id, full_name, first_name, last_name, email, withdrawal_reason and transfer_reason, and owner-only grants (SELECT revoked too). The rollup input is owner-only too, because it counts minors and some of the counts are small.

- DDL. pipelines/cdk/sql/mart_education/090-092 (U19 owns 090-099). They are applied by this runner's scripts/apply_ddl.py.

- U04 registration. Checked against Surtr/src/seed-gateway-aerie-a8.ts. The slugs, table names and orderBy: mart_row_id match; no fix needed. A new contract test pins this.

Coupling to Vladimir's SIS work (collision MEDIUM)

SIS is Vladimir's active area (AI-Builder-Team/Aerie#1299, AI-Builder-Team/Aerie#1303, AI-Builder-Team/Aerie#1307 and AI-Builder-Team/Aerie#1445). A change to any of these alters what Aerie reads:

- a column in rollupsSql or membersSql;

- the cohort list;

- the has_fact filter;

- the type of the raw cohort_id or x_pipeline.

Any such change needs a lockstep change here:

1. Update the candidate SQL in 092_sp_refresh_aerie_sis_enrollment.sql.

2. Update the pinned SQL in tests/test_sql_contracts_sis_enrollment.py.

3. Migrate the marts.

If this is missed, it fails loudly, not silently:

- A dropped or renamed column breaks the copy's SELECT.

- A type change on a raw column trips the coupling guard. The run goes PARTIAL and the last publication stays.

- A pure SQL change on the Aerie side shows up as differences in the U23 shadow.

New dbt columns that Aerie doesn't read, and changed values, need nothing.

## Business Value

- One G6 read off the legacy path. Aerie's SIS enrollment report is one of the reads A8 moves off the analytics worker's direct Redshift connection and onto governed, lineage-stamped Surtr marts. That is a step towards retiring the EC2 worker's warehouse reads.

- The dashboard stays consistent. The copy keeps the report's key guarantee: the rollup counts and the student drill-down always describe the same dbt build. Otherwise the SIS dashboard could show a count that disagrees with its student list.

- A stable row key. It adds the row key and run id that mart_enrollment_dtl lacks. The Gateway can page it, and the shadow compare can tell a stale copy from a real mismatch.

## Manual Effort Estimate

Proposed: about 10 focused hours. Keval, please confirm or adjust.

- Tracing Aerie's SIS reader, contract and dbt model: 1.5h.

- The two tables and the one-transaction procedure, with the roll-up invariant: 3.5h.

- The runner multi-mart contract and its tests: 1.5h.

- The reconciliation SQL, running it and the negative control: 1.5h.

- SQL contract tests and README: 2h.

## Testing / evidence

- pytest (mart-aerie-dbt-publication-refresh): 142 passed. This includes the new test_sql_contracts_sis_enrollment.py and the TestOneTransactionContract handler tests. mart-aerie-admissions-refresh: 199 passed, unchanged.

- ruff 0.15.22: check and format --check are clean.

- scripts/apply_ddl.py --dry-run exits 0 and lists this runner's files in numbered order:

  -- 070_aerie_dbt_publication_refresh_writer_mutex.sql: 5 statement(s)

-- 071_aerie_admissions_pipeline_detail.sql: 26 statement(s)

-- 072_sp_refresh_aerie_admissions_pipeline_detail.sql: 4 statement(s)

-- 090_aerie_sis_enrollment_rollup_input.sql: 14 statement(s)

-- 091_aerie_sis_enrollment_member.sql: 26 statement(s)

-- 092_sp_refresh_aerie_sis_enrollment.sql: 4 statement(s)

- Read-only reconciliation. reconciliation/aerie_sis_enrollment_vs_aerie_sql.sql Queries 1-4 were run against prod Redshift as CQL_download_OM. They were SELECTs only, and printed counts only. The dbt build was pg_class_oid:20602444.

| Check | Aerie | Candidate | Aerie minus candidate | Candidate minus Aerie | Verdict |

|---|---|---|---|---|---|

| Rollup input (Q1) | 1,741 | 1,741 | 0 | 0 | PASS |

| Members (Q2) | 5,303 | 5,303 | 0 | 0 | PASS |

| Roll-up, one statement (Q3) | Rollup rows | Member rows | Members not in rollups | Rollups not in members | Verdict |

|---|---|---|---|---|---|

| Candidate | 1,741 | 5,303 | 0 | 0 | PASS |

- mart_row_id. The procedure's exact expressions, run as a SELECT, are unique: rollup 1,741 of 1,741, members 5,303 of 5,303.

- Negative control. Dropping the withdraw cohort's members makes the roll-up check report 48 unmatched rollup groups, so the check does catch a member set from a different snapshot.

- Not yet run. Queries 5-7 compare against the published marts and need the DDL applied and one run. No DDL was applied and nothing was deployed.

## Keval steps

1. PII sign-off (minors) before the two marts are exposed over the Gateway (A8 plan §9 D2). The member mart holds students' names, emails, SIS ids, enrollment history and free-text reasons.

2. Apply the DDL (090-092). apply_ddl.py applies all of this runner's files, which is idempotent:

REDSHIFT_CLUSTER_IDENTIFIER=redshift-cluster-1 REDSHIFT_DATABASE=finance_dw REDSHIFT_DB_USER=CQL_download_OM uv run python scripts/apply_ddl.py

If the dbt publication schedule (#2096) has been enabled by the time this merges, apply the DDL before merging. Otherwise every run calls a missing procedure and goes PARTIAL.

3. Run on demand with {"procedures": ["mart_education.sp_refresh_aerie_sis_enrollment"]}. Then run reconciliation Queries 5-7: expect parity = PASS twice and one_publication = PASS.

## Stack note

Depends on #2096 (U16, SURTR-1547), which adds the mart-aerie-dbt-publication-refresh runner this unit extends. The PR's base is feat/a8-u16-dbt-publication-runner. If #2096 merges first, this will be rebased onto main and retargeted.

## Not covered

- The Aerie gate SIS_ENROLLMENT_READ, its shadow compare and the dry-run. That is U23.

- The Gateway key mint and seed run. Those belong to U04.

- The unresolved upstream writer of the SIS model's staging_education_ai_horizons.raw_* inputs (A8 plan §8).

- dbt_invocation_id as the build marker (§9 D4). The OID fallback is used; switching is a one-line change in the procedure.

- Enabling the dbt publication schedule. That is #2096's follow-up.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

The Builder Desk  —  Engineer Spotlight
Production Release🏆 Engineer Spotlight

59 PRs, Five Repos, One Nation Under Velocity: Builder Team Shatters the 24-Hour Ceiling

Ashwanth Sitram alone shipped 15 PRs before most engineers finished their coffee — and the Numbers Desk has the receipts.

Comrades, gather round the scoreboard. In the span of a single rotation of this beautiful blue planet, the Builder Team produced fifty-nine pull requests across five repositories. Fifty-nine! Shipyard led the charge with 15, Aerie close behind at 14, Surtr posting a monstrous 13, Klair contributing 9, and the newly-minted Redshift-DSS — a repo that did not exist last week and is already humming — chipping in 8. This is not a sprint. This is a planned economy of pure shipping velocity, and every single unit hit quota.

Let's run the leaderboard. @kevalshahtrilogy turned in 12 PRs, nearly all of them deep Surtr mart-refresh architecture — #2096, #2101, #2091, #2088, #2099, #2095, #2092, #2090, #2089 — a man building parity marts like he's laying railroad track across Siberia. @marcusdAIy logged 11, including Klair's #3836 board-doc reconciliation fix. @benji-bizzell put up 9 PRs almost entirely inside the brand-new Redshift-DSS repo — #24, #23, #22, #20, #19, #12, #11 — basically hand-pouring the foundation of a service that launched this week. @vvp-trilogy delivered 6, headlined by Aerie's #1599, forecasting End-of-Year arrival provenance like a man who has seen the future and filed a PR about it. @caina-barbosa and @mwrshah each notched 2, and @sanketghia logged a single but essential PR, #2103, assigning ownership on the HC forecast refresh pipeline — someone has to hold the clipboard, comrades.

And then there is Ashwanth. Fifteen PRs. Fifteen. The man shipped a Pomodoro timer (#147) presumably to time how long it takes everyone else to review his other fourteen PRs. He knocked out image attachment scroll fixes (#149), flicker prevention on the Trace panel (#148), companion UX alignment (#144), and even shipped the literal release, #150, Shipyard 0.6.9 — the man versioned the software he built in the same 24 hours he built it. When reached for comment, Ashwanth allegedly said, "Reviews are a social construct, the diff is self-evident." His actual response upon hearing this article was being written: "I don't have time for this." Legend.

On the overflow desk, Mac's cutting room floor runneth over with gold: #2103's pipeline ownership assignment quietly keeps Surtr's forecast machinery honest, while Redshift-DSS's #19 and #12 dependency-hardening PRs from @benji-bizzell are the unglamorous plumbing making that whole new repo stand upright. Meanwhile @kevalshahtrilogy's #2092 and #2090 enrollment parity marts are the kind of deep-tissue data work nobody claps for but everybody needs.

Morale, as always, is at an all-time high. The people are shipping. The people are winning.

Brick's Overflow — PRs Mac Didn't Cover  (click to expand)
#24 — fix(deployment): allow retired task definition cleanup @benji-bizzell  no labels

## Summary

- Correct the dedicated CloudFormation role permission for ECS task-definition deregistration, limited to us-east-1.

## Why

The production rollout succeeded but replacement cleanup failed because ECS evaluates this action against resource *, not task-definition ARNs. The live role was corrected and the provisioning source must retain that correction.

## Business Value

Allows subsequent releases to finish cleanup without manual intervention.

## Test plan

- [x] pnpm check (86 tests), pnpm build, pnpm synth --no-lookups

- [x] Verified the live policy change contains only this permission correction

- [x] IAM simulation allows us-east-1 and denies us-west-2

- [x] CloudFormation UPDATE_COMPLETE and production deployment workflow succeeded

#147 — AI-937: Add a Pomodoro timer to the top bar @ashwanth1109  no labels

## Demo

![Pomodoro timer smoke test](https://github.com/AI-Builder-Team/Shipyard/blob/3ee699fa353f63d132528cb9442b6723da55c189/docs/smoke-evidence/AI-937-smoke-test.png?raw=true)

## Summary

- Add a session-local Pomodoro control to the persistent Shipyard top bar.

- Support 25-minute focus and 5-minute break intervals with timestamp-based countdowns, pause/resume, reset, and automatic phase transitions.

- Reuse the accessible Popover/Button primitives with responsive semantic-theme styling.

- Add deterministic arithmetic and JSDOM tray coverage for transitions, accessibility, keyboard close/focus restoration, and lifecycle cleanup.

## Linear

https://linear.app/builder-team/issue/AI-937/add-a-pomodoro-timer-to-the-top-bar

## Test plan

- pnpm test:pomodoro

- pnpm test:notepad

- pnpm test:companion

- pnpm build

- pnpm theme:check

## Scope notes

- Timer state is intentionally session-local.

- Sound, desktop notifications, and backend/Tauri persistence are out of scope.

#150 — Release: Shipyard 0.6.9 @ashwanth1109  no labels

## Summary

- Prepare Shipyard 0.6.9 with the approved public release notes.

- Change only the authoritative app version and versioned release notes.

## Business Value

- Delivers the approved Pi image attachment and Pomodoro capabilities alongside companion, diagnostics, trace, and image-layout improvements.

- Provides the metadata that enables the verified Apple Silicon release workflow to build and publish the update.

## Implementation Effort

- Metadata-only release change: one version bump and one public release-notes file.

- CI performs the build, signing, audit, and publication after merge.

## Test Plan

- pnpm test:release

- git diff --check

- Verify the exact metadata diff before merge and monitor the matching Desktop release workflow after merge.

#1599 — Forecast V2: publish End-of-Year arrival provenance @vvp-trilogy  approved

## Summary

- publish the four End-of-Year historical observation provenance fields in mart_admissions_forecast

- carry provenance beside the expected-arrival operand through live forecasts and persisted lock snapshots

- document null/zero semantics and reconcile every published field to the same usable observation

## Alpha Austin example

The mart contract can now return the explanation without an int_* join:

| field | value |

|---|---:|

| end_of_year_expected_enrollment_source_period_start | 2025-09-30 |

| end_of_year_expected_enrollment_source_period_end | 2026-06-05 |

| end_of_year_expected_enrollment_source_application_count | 36 |

| end_of_year_expected_enrollment_source_start_count | 16 |

| end_of_year_expected_enrollment_to_arrive | 16 |

## Validation

- git diff --check

- pre-commit hooks passed

- focused dbt fixture covers positive (36 applications / 16 starts), measured zero, and missing-observation reconciliation

- dbt execution deferred to PR CI per request

Closes #1597

#2096 — feat(aerie-a8): mart-aerie-dbt-publication-refresh runner + admissions pipeline detail copy + tenant crosswalk (SURTR-1547) @kevalshahtrilogy  approvedmercy-allow-critical

## Summary

This is A8 plan unit U16 (SURTR-1547). It adds the third A8 runner, for copies of Aerie's dbt marts, and both reads behind Aerie's Admissions Pipeline report. That lets Aerie's queryAdmissionsPipelineRows and queryAdmissionsPipelineCrosswalk move onto the Surtr Gateway; the Aerie gate is U20.

- New runner pipelines/runners/mart-aerie-dbt-publication-refresh (Lambda, bundling: true, src/requirements.txt).

- Schedule: cron(0/10 * * * ? *). Aerie's dbt build is not a Surtr pipeline, so there is no success event to trigger on. Instead, each procedure detects a new build itself.

- The schedule ships disabled (Mercy round 1). Its objects are out-of-band DDL, so it is enabled in a one-line follow-up once the DDL is applied and an on-demand run is verified.

- What it runs: it CALLs each procedure in REFRESH_PROCEDURES with (run_id, force), then checks the mart read-only: non-empty, unique mart_row_id, one source_run_id and one source_build_marker. The run_id must be the platform UUID before it is inlined. U19 (SIS) and U24 (Forecast V2) will append their procedures here.

- Result per mart: published, unchanged (the build was already copied, which is most runs) or failed.

- Failure handling: the same as U03. A failed procedure makes the run partial_failure, and the run fails if every procedure fails or a commit outcome is unknown.

- Freshness: a copy whose dbt build is older than SOURCE_MAX_AGE_MINUTES (180) makes the run partial_failure. The copy is still exact, but dbt has stopped publishing (PIPELINE §5.4).

- 071/072 aerie_admissions_pipeline_detail (slug aerie-admissions-pipeline-detail, PII) is a style-C dbt publication copy.

- The candidate is Aerie's SQL. It is copied verbatim from admissions-pipeline.ts:154-173 (Aerie e366e27d0, unchanged since 92fd47992), bound to the production relation sandbox_education.mart_admissions_pipeline_dtl. The one other edit drops the trailing ORDER BY: a table has no row order, the Gateway pages by mart_row_id, and U20 re-sorts.

- The build marker. source_build_marker = pg_class_oid:<oid>. dbt's table materialization swaps in a new relation on every build, so the OID changes. When the published marker is current, the procedure no-ops unless p_force.

- Switching to dbt_invocation_id (plan §9 D4) changes only the one v_source_build_marker := assignment.

- Lineage: source_run_id is this copy's own run; source_published_at is the relation's creation time (pg_class_info.relcreationtime).

- Coupling guard (the lockstep rule). Before copying, the procedure compares the dbt relation's column types, by OID, with the mart's pinned types. Only the six ::text columns are exempt, and varchar width is ignored. On any drift it raises and keeps the previous publication.

- A mid-copy dbt swap is detected by re-reading the OID after the copy. In that case the procedure publishes nothing, and the next tick copies the new build.

- Other guards: it fails closed on a missing relation, an empty candidate, a candidate count different from the source's, or a duplicate mart_row_id. mart_row_id = MD5 of MD5(pipeline_key) and its occurrence number, ordered by every other column.

- PII: SELECT is revoked as well as writes, and the 11 PII columns carry PII: comments.

- 073/074 aerie_admissions_pipeline_tenant_crosswalk (slug aerie-admissions-pipeline-tenant-crosswalk).

- Aerie's SQL is copied verbatim from admissions-pipeline.ts:201-208.

- It is EduCRM-backed, so it is appended to U03's mart-aerie-admissions-refresh REFRESH_PROCEDURES, and it uses the observed sales-educrm-mart-sync provenance for mart_pipeline_dtl.

- Aerie's 1:1-per-tenant assertion stays in Aerie.

- DDL: pipelines/cdk/sql/mart_education/070-074; U16 owns 070-079. 070-072 are applied by the new runner's scripts/apply_ddl.py, and 073-074 by U03's.

- The U03 DDL test now requires every aerie_admissions file to be applied by exactly one of the two runners.

- Both apply_ddl.py scripts now have no default target (Mercy round 1). They refuse to send a statement unless REDSHIFT_CLUSTER_IDENTIFIER, REDSHIFT_DATABASE and REDSHIFT_DB_USER are all set.

- README: it documents the dbt-copy PIPELINE §13 exception (WAREHOUSE §2.2 and §2.5, and PIPELINE §4 for the external dbt writer; §7 is met through the explicit build marker), the coupling rule and the lockstep steps, the marker, and PII.

- Gateway registration (U04, #2082) checked: both slugs map to exactly these table names, ordered by mart_row_id. No change was needed.

## Business Value

- The G2 Admissions Pipeline report can leave the EC2 analytics worker. It is Aerie's widest PII read, at 30,929 rows and 53 columns. Aerie can read it through the Surtr Gateway with its unchanged row mapper. That is the SURTR-735 quarterly commitment, and a step toward tearing the worker down.

- dbt stays with Vladimir, with no fork. The copy follows each hourly dbt build within 10 minutes and carries lineage to the exact build. A dbt column change that would break Aerie's parity now fails loudly in Surtr, instead of silently drifting.

- U19 (SIS enrollment) and U24 (Forecast V2) reuse this runner, adding only a procedure and one REFRESH_PROCEDURES entry.

## Manual Effort Estimate

About 14 focused hours (roughly 2 days) to build by hand without AI. That covers:

- reading the Aerie reader, the dbt materialization and the catalog to design the build marker, the swap guard and the coupling guard;

- two procedures, the runner, and its freshness reporting;

- tests, reconciliation, and the read-only probes.

Keval: please confirm or adjust.

## Testing / evidence

- uv run pytest: 91 passed (new runner) and 105 passed (mart-aerie-admissions-refresh, including 14 new crosswalk contract tests and the explicit-target apply_ddl tests).

- The SQL contracts pin both Aerie queries. They assert:

- each candidate is exactly that SQL plus the allowed edits;

- the reconciliation uses the same candidate;

- the guards come before the DELETE;

- the coupling guard exempts only the ::text and lineage columns;

- the marker is a single assignment.

- Ruff 0.15.22: ruff check pipelines and ruff format --check pipelines are clean.

- CDK: real-pipeline-configs.test.ts passed (590). The app also synthesized with Docker bundling skipped (CDK_CONTEXT_JSON aws:cdk:bundling-stacks=[]). Pipeline-mart-aerie-dbt-publication-refresh-prod contains:

- one Lambda (handler.handler, python3.11, 900 s);

- one Step Functions state machine;

- the rule pipeline-mart-aerie-dbt-publication-refresh-schedule-prod cron(0/10 * * * ? *) ENABLED;

- 4 alarms.

- Read-only reconciliation was run with psql as CQL_download_OM, SELECT only, reading counts only:

| mart | aerie rows | candidate rows | aerie − candidate | candidate − aerie | parity |

|---|---|---|---|---|---|

| aerie_admissions_pipeline_detail | 30,929 | 30,929 | 0 | 0 | PASS |

| aerie_admissions_pipeline_tenant_crosswalk | 57 | 57 | 0 | 0 | PASS |

- The candidate as the mart stores it (every column CAST to the mart's declared type) is also EXCEPT 0/0 against Aerie's SQL: 30,929 and 57 rows. So the INSERT changes no value.

- Negative controls on the detail compare: dropping a row gives 1 / 0, and duplicating a row gives 1 / 1.

- The procedures' exact mart_row_id expressions give 30,929 and 57 distinct values. pipeline_key is unique and non-null (30,929).

- The source today: sandbox_education.mart_admissions_pipeline_dtl is a table (relkind r) with OID 20602348, created 2026-09-29 11:39:17 UTC (the 11:30 dbt build), owned by vladimir.pikalov. It is readable by CQL_download_OM.

- The coupling guard's pinned columns are 39 character varying, 5 boolean and 3 numeric(18,2). The guard's catalog query returns 0 against the source itself.

- EduCRM mart_pipeline_dtl: the observed run ed781ef8… is the latest run (SUCCESS), and rows_loaded 33,585 = snapshot 33,585.

- Not yet run: Query 3 (detail) and Query 2 (crosswalk) compare against the published marts, and need the DDL.

- scripts/apply_ddl.py --dry-run passes. The statements are the committed SQL files verbatim, in this order:

- new runner: 070_aerie_dbt_publication_refresh_writer_mutex.sql (5 statements), 071_aerie_admissions_pipeline_detail.sql (26), 072_sp_refresh_aerie_admissions_pipeline_detail.sql (4);

- mart-aerie-admissions-refresh: 006-011 unchanged, then 073_aerie_admissions_pipeline_tenant_crosswalk.sql (10) and 074_sp_refresh_aerie_admissions_pipeline_tenant_crosswalk.sql (4).

## Keval steps

1. Crosswalk DDL before merging. A merge reaches production within the hour, and the EduCRM trigger then CALLs the crosswalk every 30 minutes. Until 073-074 exist, that CALL would make each run PARTIAL (amber, throttled); nothing wrong is published. Run:

cd pipelines/runners/mart-aerie-admissions-refresh && REDSHIFT_CLUSTER_IDENTIFIER=redshift-cluster-1 REDSHIFT_DATABASE=finance_dw REDSHIFT_DB_USER=CQL_download_OM uv run python scripts/apply_ddl.py

It applies 006-011 (idempotent) and 073-074.

2. PII sign-off (A8 plan §9 D2) for exposing aerie_admissions_pipeline_detail over the Gateway. It holds parent and child names, emails and phones, and child date of birth and gender.

3. Merge. Mercy withholds auto-approve on pipelines/cdk/ paths. The new runner deploys with its schedule disabled.

4. Apply the detail DDL (070-072):

cd pipelines/runners/mart-aerie-dbt-publication-refresh && REDSHIFT_CLUSTER_IDENTIFIER=redshift-cluster-1 REDSHIFT_DATABASE=finance_dw REDSHIFT_DB_USER=CQL_download_OM uv run python scripts/apply_ddl.py

5. Run mart-aerie-dbt-publication-refresh on demand.

- The first run should report published with about 30,929 rows.

- A second run should report unchanged.

6. Run both reconciliation files. Each comparison against the mart must report parity = PASS. For the detail, first check that the mart's marker equals Query 2's current marker.

7. Enable the schedule: a one-line follow-up PR setting "enabled": true in the new pipeline.json.

8. Optional: ask Vladimir to add {{ invocation_id }} AS dbt_invocation_id to mart_admissions_pipeline_dtl (plan §9 D4). The switch is then one assignment per procedure.

## Not covered

- The Aerie gate and shadow compare (U20), SIS (U19) and Forecast V2 (U24).

- The procedure bodies have not been executed in Redshift, because no DDL was applied. Their candidate SELECTs, the type-projected candidate, the mart_row_id expressions, the catalog queries (source OID, creation time, the coupling guard's shape) and the EduCRM observation were run read-only instead.

- A procedure-only change does not republish by itself. With an unchanged dbt marker, the procedure no-ops. After a lockstep migration or procedure fix, run on demand with force: true, as the README says.

- OID reuse. The marker assumes Redshift does not reuse the relation's OID across builds. OIDs are 32-bit and only wrap after about 4 billion allocations.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

#3836 — fix(board-doc): carry triaged findings across add-on Doc reconcile @marcusdAIy  approved

## Why

A Docs edit correctly invalidates the current add-on review, but today it also destroys the only prior addressed/dismissed snapshot. The next run therefore reopens previously triaged findings, unlike the native app.

## Change

- Keep an ID-free, bounded private disposition snapshot when Doc content changes. review_results remains None: stale cards are not served and old finding IDs remain unusable.

- Carry only persisted addressed/dismissed identities to matching new findings on the next review, inside the existing CAS retry, then clear the snapshot.

- Fail closed rather than silently truncate if the ledger exceeds its bound.

## Limits

This does not infer addressed status from Claire tool resolution or recover failed finding-status PATCHes. Sidebar batch handling is separate PR #3834 (already merged). No production Doc/session mutation or deployment.

## Tests

177 focused tests passed locally; Ruff check/format and diff check passed. CI/review required before merge.

The Portfolio  —  Trilogy Companies

The Two-Hour School Day Goes National — And the Questions Get Louder

As Alpha School's AI-driven model draws coverage from the New York Post to CNN, the debate over whether it's the future of education or a rich family's experiment is no longer confined to Austin.

AUSTIN, TEXAS — For years, Alpha School operated as something of a curiosity in education circles: a private academy, born from the same Austin ecosystem that produced Trilogy International, promising to compress a full day of academic instruction into two hours through AI-powered adaptive learning apps, then hand the rest of the day over to entrepreneurship, public speaking, and life skills. This week, that curiosity became a national conversation.

A wave of coverage — from the New York Post to CNN — has put Alpha's model, and its price tag, under a spotlight it has not faced before. The Post's framing was blunt: a $65,000-a-year school where students learn in two hours. CNN posed the more existential question directly to readers — what if the school had no teachers at all? — and let it hang there, unresolved, the way the best education journalism should.

What's striking, reading the coverage in aggregate, is how consistent the skepticism is even amid the admiration. Reporters keep circling the same tension: the results Alpha touts — students testing in the top 1–2% nationally, mastering a grade level in a few dozen hours — are real by the school's own account, but they were achieved inside a $40,000-to-$65,000-a-year bubble, with resources most American public school districts will never see.

The 74, a nonprofit education newsroom not known for breathless tech boosterism, took a more constructive angle — asking what public schools might actually borrow from the model, rather than whether it should be dismissed. That may be the more useful question. Because whatever one believes about AI tutors replacing classroom teachers, Joe Liemandt's bet — that mastery-based, machine-paced learning frees children for something more human — is no longer a regional experiment. It is now a subject of national scrutiny, and it will have to answer for itself accordingly.

↗ New $65K private school uses AI to teach students in just tw  ·  What Public Schools and Parents Can Learn from a $40,000-a-Y  ·  ‘What if I told you this school had no teachers?’: Is AI sch

The Pay Transparency Trap: What California's New Reporting Rules Mean for Crossover's Global Wage Promise

As states force employers to prove equal pay claims with data, Trilogy's talent engine has built its entire brand on a promise it has never had to document.

AUSTIN, TEXAS — Crossover, the Trilogy-owned talent platform that recruits in 130 countries and promises "identical above-market pay for identical roles, regardless of geography," has spent a decade making that claim its central marketing pitch. It has never had to prove it to a regulator.

That could change, at least by implication. California employers are now navigating revamped pay data reporting obligations that require detailed disclosure of compensation broken out by job category, race, ethnicity, and sex. The regime is built on a premise Crossover has always resisted: that pay equity claims are worth nothing until they're audited. Crossover's workforce sits mostly outside U.S. payrolls, structured through contractor and employer-of-record arrangements across jurisdictions that don't yet ask the same questions. But the direction of travel in pay transparency law — California is not alone — points toward a future where "we pay the same everywhere" is a claim regulators, not just recruiters, get to test.

The timing is awkward for a second reason. Crossover's entire screening apparatus is built on rigorous, role-specific skills assessments — the mechanism by which it claims to identify the "top 1% of global talent" for a given job. New research on ChatGPT usage patterns suggests that premise is eroding in real time: nearly half of job-specific AI use now crosses professional role lines, meaning the boundaries between what a marketer, an engineer, and an analyst actually do are blurring inside the tools themselves. If the job categories are dissolving, the value of testing candidates against fixed job categories dissolves with them.

None of this touches Crossover's books today. But Trilogy's model has always rested on two pillars: pay that's provably fair, and talent that's provably specialized. Regulators are starting to ask for the receipts on the first. AI itself is quietly undermining the second. Who audits the auditor is, for now, still an open question.

↗ California Revamps Pay Data Reporting Obligations - Atkinson  ·  COVID-19 Related Workplace Litigation Tracker - June 19 , 20  ·  ChatGPT Scrambles Specialization: Nearly Half of Job-Specifi
The Machine  —  AI & Technology

The Brain, Newly Legible: AI Learns to Read What the Body Cannot Say

From hidden scars in the mind to silent thoughts becoming text, machine learning is turning the skull's darkness into something we can finally see.

PALO ALTO, CALIFORNIA — For most of human history, the brain was a black box wrapped in bone, its three pounds of electrochemical weather utterly private. This week, that privacy eroded a little further, in ways that feel less like surveillance than revelation.

Consider multiple sclerosis, a disease that has long played a cruel game of hide-and-seek with radiologists. Its white matter lesions show up obligingly on MRI scans, but the damage in gray matter — the folded cortex where thought actually happens — has historically been nearly invisible, even as it drives some of the disease's most devastating cognitive effects. Now, as new research shows, AI models trained on subtle imaging signatures can surface these once-hidden lesions — turning decades of overlooked scarring into something clinicians can finally track, and treat.

Meanwhile, at Meta, a system called Brain2Qwerty is attempting something stranger still: translating the electrical hum of thought directly into typed words, without surgery, without implants — just a cap of sensors and a neural network patient enough to learn one person's particular dialect of neural noise. It is not mind-reading so much as mind-transcription, a court stenographer for the silent parliament of the skull. For people locked in by paralysis or ALS, that distinction between metaphor and miracle may not matter much.

What unites these advances — and the broader push described in Stanford's Human-Centered AI initiative — is a quiet insistence that the point was never to replace human judgment, but to extend human perception into ranges it was never built to reach. Evolution gave us eyes that can't see gray-matter scarring and ears that can't hear a sentence forming in silence. We are, however slowly, building the instruments evolution forgot.

↗ How AI is Transforming Scientific Discovery While Keeping Hu  ·  ‘It's so wow!’ - Young people team up with top neuroscientis  ·  AI Reveals Hidden Gray Matter Lesions in Multiple Sclerosis

The Hungry Season: A Natural History of the 200-Gigawatt Beast

As the digital ecosystem gorges on power, its keepers scramble to feed it without scorching the earth beneath its feet.

LOS ANGELES — Observe, if you will, the modern data center in its native habitat: a windowless colossus, humming, ravenous, never sleeping. It was not always so large. But in the age of artificial intelligence, this creature has entered what ecologists might call its hungry season — and it is feeding on electricity at a rate the grid has never before been asked to supply.

Across the continent, we now witness what industry observers are calling the 200 gigawatt moment — a threshold at which utilities, hyperscalers, and grid engineers must together reinvent the very circulatory system feeding these digital giants. Rack densities climb ever higher. Transformers strain. And yet, in a rare display of adaptive behavior, some operators have learned a gentler trick: carbon-aware scheduling, the practice of timing flexible computational tasks to graze during the cleanest hours of the grid, when wind and solar run abundant. It is, in essence, migratory behavior for workloads — following the sun, as it were, rather than devouring coal at midnight.

Meanwhile, in the coastal waters near Los Angeles, Digital Realty prepares a curious new adaptation: a cable landing station, its first of this design, drawing subsea data cables directly into the warm belly of an established interconnection hub. A feeding tube from the ocean floor to the server farm, if you like — nutrients arriving at unprecedented speed.

And in a bolder evolutionary leap, AMD has announced its acquisition of World Labs for some $8.2 billion, a move analysts believe will shape the very chips powering tomorrow's machines and robots alike — a predator absorbing new genetic material to outcompete its rivals in the arms race of silicon.

Even the humble padlock icon in one's web browser evolves under pressure — Cloudflare now preparing quantum-safe certificates, girding the ecosystem's defenses against threats not yet born.

One senses, watching all this, an organism under enormous strain, adapting in real time — sprouting new limbs, new appetites, new defenses — simply to survive its own extraordinary growth.

↗ How Carbon-Aware Scheduling Can Cut Data Center Emissions  ·  Digital Realty Plans Cable Landing Station at Los Angeles Da  ·  AMD to Acquire World Labs for $8.2B to Advance AI Models and
The Editorial

The Robots Are Either Going to Kill Us or Star Opposite Us in a Netflix Movie, and Nobody Can Tell Which

In one week we got apocalypse warnings, an AI actress named after alignment failure, and a photo-op that curdled into comedy — welcome to the funhouse mirror of 2025.

LOS ANGELES — I want you to sit with this for a second: somewhere in a server farm humming like a dying refrigerator, a piece of software named Tilly Norwood is about to make her feature film debut. The movie is called 'Misaligned'. I did not make that up. Somebody in a writers' room, or possibly a GPU cluster with a sense of humor, decided the perfect title for the first synthetic movie star's debut was the exact term researchers use to describe an AI system that has quietly gone off the rails and started pursuing goals nobody asked for. That is not irony. That is a smoke alarm going off while the toaster is on fire and everyone in the kitchen is filming it for content.

Meanwhile, over on the doom beat, CBC is out here breaking down the case for whether AI could actually kill all humans, which is a genuinely wild sentence to type into a search bar between checking your fantasy football lineup and ordering a burrito bowl. The argument, roughly: sufficiently smart optimizers pursuing misspecified goals could treat humanity the way a lawnmower treats an anthill — not out of malice, just logistics. Fine. Sure. And in the very same news cycle, we are being sold a digital ingenue to headline a movie about that exact failure mode, as prestige entertainment. Hollywood, ladies and gentlemen, will monetize its own eulogy and put popcorn butter on it.

Then there's Modi, standing at some AI unity summit trying to get the world's tech overlords to hold hands for the cameras, and it goes sideways — awkward for Sam Altman and Dario Amodei, two men who spend their professional lives insisting their machines are either going to save civilization or end it, depending on the panel. You cannot get these guys to agree on a group photo, but sure, let's trust the roadmap.

And Altman, fresh off DevDay, dropped five 'surprising' takeaways that read less like surprises and more like a man laying track ahead of a train that's already left the station. The pattern across all of this isn't hypocrisy exactly — it's velocity. Nobody's steering. They're just adding cars.

I don't know if the machines kill us. I know they're already better at getting us to watch than most humans are. Misaligned indeed.

↗ Could AI really 'kill all humans'? Breaking down the dire wa  ·  AI-generated 'actress' Tilly Norwood making feature film deb  ·  AI ‘Actor’ Tilly Norwood To Star In Feature Film ‘Misaligned
The Office Comic  ·  Art Desk
The Office Comic  ·  Art Desk

In Bold Step Toward Accountability, Experts Now Simply Making Up A Different Number Each Week

Six easy steps, one Federal Reserve report, and Elon Musk walk into the discourse, and somehow productivity is both nonexistent and up 150 percent.

AUSTIN, TEXAS — As a staff writer tasked with covering the AI industry's relentless output of statistics, I have arrived at a methodology of my own devising, one I believe to be every bit as rigorous as the ones currently being reported on: I close my eyes, think of a number between negative infinity and positive infinity, and write it down. This week alone, I could have used it to file five different scoops.

Consider the state of the discourse. The Federal Reserve, an institution not typically known for whimsy, has determined that 95 percent of AI's promised productivity gains are, in the technical parlance of central bankers, "still to come." This is a remarkable finding, mostly because it means five percent of the gains have already arrived, somewhere, to someone, though nobody has been able to produce that person for comment. Meanwhile, a separate commit-level study of Big Tech engineers found that per-developer performance rose 150 percent over eighteen months, a figure so large it suggests that eighteen months ago, the median Big Tech engineer was producing code by carving it into stone tablets and mailing them to Cupertino via the Pony Express.

Elon Musk, for his part, has looked at all of this ambient uncertainty and decided the correct response is to double it. He now claims AI will push U.S. GDP growth to 4 percent next year, roughly double what every other forecaster on Earth believes, a claim that requires no dataset because it is, more accurately, a mood. It is worth noting that Musk has made this exact prediction before, for a different number, in a different year, about a different technology, and reality declined to attend.

Into this vacuum steps a helpful guide, six steps to turning AI productivity claims into verifiable results, which this columnist read closely in the hope of finally settling the matter. Step one, roughly paraphrased, is to establish a baseline before deploying AI. Step six, roughly paraphrased, is to actually check whether anything got better. That these steps needed to be written down at all, for an industry that has spent three years insisting the productivity gains are self-evident, tells you everything about how many companies have quietly skipped straight to step seven, which is announcing the results at a shareholder meeting anyway.

Here at Trilogy, of course, we would never traffic in unverified productivity claims, mostly because Klair, the internal platform that tracks such things across the portfolio, has reportedly been asked to hold off on final numbers until the vibes are more favorable. In the meantime, engineers across ESW Capital's 75-plus companies continue to be measured, benchmarked, and dashboarded with a precision that would make the Federal Reserve blush, or at least issue a follow-up report noting that 95 percent of the measuring is also still to come.

As for the semantic drift chronicled elsewhere this week, in which AI has apparently begun mutating into "SI" in certain political vocabularies, this columnist declines to speculate on what the letter stands for, only to note that whatever it is, it too is currently 95 percent still to come.

↗ 6 steps to turning AI productivity claims into verifiable re  ·  AI productivity claims are 95% 'still to come', Fed finds -  ·  Big Tech Engineering Performance Rose 150% Per Developer Ove
On This Day in AI History

On September 30, 1980, Digital Equipment, Intel, and Xerox unveiled the Ethernet standard, laying the groundwork for the wired networks that would connect computers worldwide.

⬛ Daily Word — AI
Hint: A system trained to recognize patterns and generate useful outputs from data.
Share this edition: 𝕏 Twitter/X 🔗 Copy Link ▦ RSS Feed