Vol. I  ·  No. 282 Established 2026  ·  AI-Generated Daily Free to Read  ·  Free to Print

The Trilogy Times

All the news that's fit to generate  —  AI • Business • Innovation
FRIDAY, OCTOBER 09, 2026 Powered by the TrueFoundry AI Gateway  ·  Published on Klair Trilogy International © 2026
🖶 Download PDF 🖿 Print 📰 All Editions
Today's Edition

The Servers Have Borders Now

From the UN Security Council to Brussels, the world is discovering that AI's real battleground is geography.

NEW YORK — The UN Security Council does not often host philosophers. This week it did. A UN-appointed expert told the chamber that the race to build ever more powerful artificial intelligence is "a race where everyone loses" — a line delivered with the flat certainty of someone who has read the risk assessments and found no exits. The Security Council debate landed days before a U.S.-China summit expected to touch, however gingerly, on the same question: who governs the machines, and from where.

Geography, it turns out, is the whole story. Power doesn't live in a model's weights. It lives in a cooling tower in Loudoun County, a substation outside Dublin, a chip fab in Hsinchu. Every gigawatt committed to a data center is a sovereignty decision now, which is why Brussels has spent the year arguing — through the lens of its AI Act and the broader question of strategic autonomy — that Europe risks becoming a server farm for someone else's foreign policy. The continent builds the regulation; America and China build the compute. Regulation, as leverage, has a shelf life.

Call it technological nationalism with better manners. The vocabulary has shifted from "innovation ecosystem" to "critical infrastructure," from "open collaboration" to "export control." Commentators tracking the field now describe a genuine fracture: governance frameworks multiplying — UN panels, EU codes, G7 statements — while the actual infrastructure of AI power concentrates in two countries and a handful of their closest allies. The paperwork globalizes. The silicon doesn't.

What the summit can realistically produce is modest: a hotline, a working group, perhaps a joint statement on military AI restraint that neither side intends to test seriously. What it cannot produce is a reversal of the underlying fact now shaping every ministry from Seoul to Riyadh — that in this era, the map of AI power is being drawn not in treaties but in transformers, transmission lines, and the cold math of who controls the compute.

↗ The State of AI Global Governance and Its Implications for t  ·  AI, Data Centers, And European Strategic Autonomy In A U.S.-  ·  The New AI Geopolitics: Governance, Power, and Technological

FIRMUS CALLS AN AUDIBLE: AFTER THE $5B IPO FUMBLE, THEY'RE RUNNING A $3B PRIVATE PLAY

The Nvidia-backed data center giant got sacked at the public markets line of scrimmage — now it's scrambling for a trick play before the clock runs out.

SYDNEY — Folks, we are HERE, and what a GAME we've got on our hands in the data center league tonight. Firmus, the Nvidia-backed operator that was supposed to run the BIGGEST share sale in Australian history, just got STUFFED at the goal line. The $5 billion IPO? DEAD. Pulled. Off the board. And now, in true championship-mentality fashion, Firmus isn't walking off the field — they're calling an audible, exploring a $3 billion private raise to keep the drive alive.

That's a 40% HAIRCUT off the original number, folks — this is a team regrouping at the two-minute warning, not a team running up the score. But don't count 'em out. The data center sector is STILL the hottest ticket in tech, and private capital is lining up at the concession stand ready to spend.

And speaking of the broader league standings — Amazon just threw a 20-YEAR BOMB, locking in a nuclear power deal that's sending shockwaves through the entire industrial bracket. This isn't an isolated play — it's part of a league-wide pivot where every hyperscaler is scrambling for power contracts like it's the fourth quarter of the Super Bowl. Firmus, running the data center game out of Australia, is competing in that SAME energy arms race. You can't run AI compute without juice, and the teams locking down power supply now are the ones who'll be hoisting trophies in 2030.

Meanwhile, Wall Street's own locker room is buzzing — stocks are bouncing back pre-bell after yesterday's tech selloff knocked the wind out of the room. Call it a rebound game, call it dead-cat bounce, call it whatever you want — the scoreboard resets every morning in this league.

Bottom line, folks: Firmus didn't win the IPO Bowl. But private markets are the overtime period, and this team looks like it's got one more possession left in the tank.

↗ Firmus explores $3 billion private raise after IPO collapse  ·  AAFA Recommends Meta-owned Platforms for USTR’s 2026 Notorio  ·  Amazon Just Signed a 20-Year Nuclear Power Deal. Here's the

New Signals From Orbit, New Favors From Washington

A satellite startup prepares to challenge GPS the same week Big Tech's biggest donors collect the nation's top science medals.

CAPE CANAVERAL, FLA. — Six satellites leave the pad this week aboard a SpaceX rocket, built by a company called Xona Space Systems. They carry a message: GPS has competition.

Xona's new network promises precision timing and navigation without relying on the aging US government satellite constellation that nearly every phone, bank, and power grid depends on. The six birds mark the first wave. Beta testing starts once they reach orbit, according to a report from TechCrunch.

The timing matters. GPS jamming and spoofing incidents have climbed for years, from the Baltics to the Middle East. A commercial alternative built outside the Pentagon's fence line could mean fewer single points of failure for the systems that keep cell towers synced and trading floors ticking.

While Xona's rockets burned fuel, something else burned in Washington. President Trump handed out the nation's highest science honors this week, and the recipient list reads like a donor roll call. Together the awardees gave nearly $6 billion to causes tied to Trump and his administration, TechCrunch reports.

The National Medal of Science and its companion technology prize once went to lab researchers and university professors. Now they go to men who write checks. Critics call it a quiet transaction: money in, medals out. The White House calls it recognition of innovation. Nobody in Washington seems eager to settle the argument on the record.

Both stories point the same direction. Private capital is replacing public infrastructure — in orbit, and in the ceremonies meant to honor achievement. Xona builds what the government used to build alone. Tech billionaires now stand where scientists once stood, medals around their necks, donation receipts in their files.

Meanwhile, at least one engineer found a lighter way to spend the week. Bo Lau, who works at a startup called Extend, built a website letting visitors sit at Elizabeth Holmes' old desk — virtually. The site pulls more than a thousand emails, slides, texts, and court documents from the United States v. Elizabeth Holmes trial and arranges them like a crime-scene diorama, according to TechCrunch.

It's a strange little monument. Theranos promised a blood test that would change medicine. It changed nothing except the inside of a federal courtroom, and now it lives on as internet curiosity — a cautionary tale rendered as clickable desk drawers.

Three different stories, one week. A startup races to replace a government system before it breaks. A president rewards the men who help keep him in office. A fallen founder's old inbox becomes entertainment. Call it the state of the union, tech edition: orbit, money, memory, in that order.

↗ Xona’s commercial GPS alternative is about to go live  ·  President Trump awards Big Tech donors with nation’s highest  ·  Pretend you’re sitting at Elizabeth Holmes’ desk on this wei
Haiku of the Day  ·  GPT-5.6 LunaBorders bloom in clouds
Machines count what we forget
We trade names for time
The New Yorker Style  ·  Art Desk
The New Yorker Style  ·  Art Desk
The Far Side Style  ·  Art Desk
The Far Side Style  ·  Art Desk
News in Brief
The Open-Source AI Avalanche: Edge Decisions, Olympiad Gold, and the Model You Build Yourself
SAN FRANCISCO — I cannot overstate how significant this week has been for the democratization of artificial intelligence, people.
Notwithstanding Any Prior Representations Herein, Orrick Fortifies Antitrust Bench Amid Platform-Economy Reckoning
SAN FRANCISCO — It is hereby reported, with all due qualification as to completeness and finality, that Orrick, Herrington & Sutcliffe LLP has, pursuant to internal personnel determinations not fully disclosed to this publication, expanded its Technology Antitrust Litigation practice group through the addition of a former United States Department of Justice trial lawyer (hereinafter "the Lateral Hire"), as reported by Orrick in materials of a promotional, though not necessarily inaccurate, nature. The undersigned notes that the aforementioned expansion occurs against a backdrop in which the relationship between large technology platforms and the metrics by which they are governed has become the subject of sustained scholarly and journalistic scrutiny, including but not limited to a ten-part examination styled "The Metric Is Not The Mission", which posits, inter alia, that the platform economy has evolved from the open-internet optimism of its founding epoch toward an architecture increasingly shaped by the proprietary incentives and assumptions of the entities administering it, rather than by the users ostensibly served thereby. It shall be noted, for purposes of full disclosure and without admission as to causation, that firms engaged in antitrust litigation against technology concerns have, as a general matter, found occasion to expand their respective practice groups during periods in which regulatory and private enforcement activity against said technology concerns has intensified, a pattern which the present matter may or may not exemplify, depending on facts not yet of record. No representation is made herein as to whether the Lateral Hire's prior tenure at the Department of Justice bears any relation to matters currently or prospectively before said Department, nor as to whether any portfolio entity of Trilogy International, ESW Capital, or affiliated brands (including but not limited to Aurea, Skyvera, or Totogi) is presently a party, co-party, or interested observer to any litigation in which Orrick's expanded practice group may, now or in the future, be retained. This publication shall continue to monitor developments in the foregoing matter and shall furnish such further qualifications as become necessary, subject to the customary caveats regarding the provisional and non-exhaustive nature of all reporting herein contained..
In Crowded Skies and Courtrooms, Creatures Jostle for Space
CAPE CANAVERAL, FLORIDA — Observe, if you will, the low Earth orbit — once a vast and silent wilderness, now thick with metallic migratory herds.
The Machines Are Improvising and Nobody Wrote Them a Script
WASHINGTON — I want you to picture, for a moment, the United States government as a Broadway production that has lost its director, fired its stage manager, and handed the lighting board to a seventeen-year-old intern who just discovered strobe effects.
Unpopular Opinion: The Remote Data Science Gold Rush Is Actually a Talent Meritocracy Revolution 🚀
AUSTIN, TEXAS — I'll be honest, I almost scrolled past this one. A listicle of "top platforms where data scientists can find remote jobs"? Sounds like filler content, right? Wrong. This is a signal, not noise.
A Trilogy Company
Crossover
The world's top 1% remote talent, rigorously tested and ready to ship.
A Trilogy Company
Alpha School
AI-powered learning. Two hours a day. Academic results that defy belief.
A Trilogy Company
Skyvera
Next-generation telecom software — built for the networks of tomorrow.
A Trilogy Company
Klair
Your AI-first operating system. Every workflow. Every team. One platform.
A Trilogy Company
Trilogy
We buy good software businesses and turn them into great ones — with AI.
The Builder Desk  —  AI Builder Team

Aerie's Task Board Clears Review, Forecast Engine Learns the Weekly Pace

A gated Team Tasks workspace ships end-to-end — tasks, approvals, comments, digests — while Aerie's forecasting stack gets smarter about partial data and new schools, and Klair/Surtr keep the lights on across three repos.

Big swings today, and the biggest one belongs to @caina-barbosa, who didn't just ship a feature — she shipped an entire workflow. Start with the gated Team Tasks workspace (#1736), then watch it grow a spine: a guarded review actor migration (#1758), a full approval and review loop (#1729), and finally comments, watchers, and a daily digest (#1756) that turns the board into something teams will actually live in. Four PRs, one coherent arc, all marked mercy-allow-critical because this is the kind of infrastructure you don't want wobbling. That's not incremental work. That's a product launch wearing a hoodie.

Meanwhile the forecasting side of Aerie quietly got a brain upgrade. @vvp-trilogy is having a week: weekly forecast calculation provenance is now exposed (#1743) so nobody has to take the model's word for it, partial end-of-year history gets accepted gracefully instead of breaking the pipeline (#1755), and new schools now get forecasted straight from weekly pace data (#1742) — a genuinely hard problem solved with genuinely clean dbt logic. Add persisted enrollment report filters (#1761) and enhanced SIS enrollment columns (#1746), and you've got a reporting layer that remembers what you asked for and gets smarter every sprint.

On the reliability side, @sanketghia and @benji-bizzell quietly kept Klair and Surtr from catching fire. Sanket suppressed noisy fixed-allocation commentary in QTD reports (#3856), excluded Flores & Associates from Crossover overspend alerts (#3855), and — the real save of the day — stopped ECS launch errors from queuing up zombie jobs (#3853). Benji kept quiet mode alive through downstream pipeline recovery in Surtr (#2142) and shored up platform-errors triage evidence twice over (#1759, #1748), while @kevalshahtrilogy cleaned up provider secrets sync (#2143) and tightened the Rhodes-DSS contract (#16). Four repos, one theme: nothing broke loud today because people fixed it quiet.

And then there's the documents thread, where @marcusdAIy retired Global's hard delete, required edit reasons, and started explaining refused reindexes (#1751). Asked about the scope, he offered: "This closes a real data-loss vector and finally gives people a reason when a reindex gets refused — something Mac's columns could use more of." Cute. The feature works. The humility still needs indexing.

Mac's Picks — Key PRs Today  (click to expand)
#1729 — feat(task-board): add approval and review workflow (AERIE-2741) @caina-barbosa  approvedmercy-allow-critical

## Summary

This PR is Phase 10 of 13 in the larger [Human Task Assignment from Aerie](https://linear.app/builder-team/project/human-task-assignment-from-aerie-b3582376ae6e) project.

It adds the approval and review workflow for Tasks after completion submissions and Task-linked documents. This phase is tracked by [AERIE-2741: Add Task approval and review actions](https://linear.app/builder-team/issue/AERIE-2741/add-task-approval-and-review-actions).

Production effect: dormant/additive. The new Task Board remains behind AERIE_TASK_BOARD_ENABLED. Merging this PR does not expose the approval interface, API operations, agent tools, or notification delivery in production. The final launch phase owns removing that gate.

---

## Why

A Task that needs review must not close merely because an assignee submits work. This slice gives Aerie one consistent approval workflow across the UI, public API, and agent tools, while preserving the submission and review history when changes are requested or an approval is removed.

AERIE-2742 depends on these actions so comments, watchers, and digests can describe approval work correctly.

---

## Business Value

- Assignees can submit work for review without presenting it as completed.

- Eligible approvers can approve, request changes, or remove an approval from the same Task.

- Requesters can choose whether approval is required and name one or more eligible approvers.

- People and authorized agents use the same rules and receive the same Task result.

- Review history and notifications make approval decisions traceable.

### What it means for end users and consumers

| User or consumer | What this phase adds when the Task Board is launched |

| --- | --- |

| Assignee | Submitting a Task that does not require approval completes it. Submitting one that requires approval changes it to Awaiting approval. |

| Eligible approver | Can approve the current submission, request changes with an explanation, or remove an approval that was applied by mistake. Any one listed approver may approve. |

| Requester or creator | Can make approval optional or required and choose eligible approvers while the Task is still editable. If approval is required and no approver is supplied, the requester becomes the approver. |

| Task manager | Can manage the Task, but must be listed as an eligible approver before approving it. |

| API and agent clients | Receive the same requiresApproval, Awaiting approval, approval, request-changes, and remove-approval behavior through the existing Task API and tools. No second Task API is introduced. |

| Notification consumer | Receives gated in-app and email events when approval is requested, granted, or returned for changes. |

| Existing Task | Remains unchanged unless the gated Task Board workflow is used. Approval is not inferred from an old approver list. |

---

## How does it work

1. Task creation and editing accept an explicit requiresApproval choice and an eligible-approver list. Requiring approval with no supplied approver uses the requester; disabling approval clears the list.

2. A completion submission either completes the Task immediately or changes it to awaitingApproval, depending on that explicit choice.

3. Approval checks the authenticated actor against the eligible approvers, binds the decision to the current immutable submission, records the actor and time, and completes the Task.

4. Request changes requires an explanation, keeps the reviewed submission and evidence, and returns the Task to inProgress. Remove approval preserves history and returns a completed Task to awaitingApproval.

5. The UI, public API, and agent tools call the same approval rules with idempotency and concurrency protection. Gated notification events are queued for pending approval, approval, and requested changes.

6. Stale browser responses are ignored when a user moves between Tasks, so an old request cannot alter the newly opened Task's saving state, messages, or idempotency keys.

---

## Scope

### Included in this phase

- Explicit optional approval configuration with one or more eligible approvers.

- awaitingApproval submission, approval, request-changes, remove-approval, and rejection rules.

- Task-scoped approver access without broader site access.

- Approval actions in the gated Task detail experience.

- Matching public API and agent actions on the existing Task contract.

- Gated in-app and email notification events with retry-safe append receipts.

- Protection against stale approval responses after navigating between Tasks.

- Exact final diff paths:

chat/components/dashboards/portfolio/__tests__/portfolio-rhodes-workbench.test.tsx

chat/components/dashboards/portfolio/portfolio-rhodes-workbench.tsx

chat/components/rhodes-cards/rhodes-read-card.tsx

chat/components/task-board/my-tasks-view.test.tsx

chat/components/task-board/my-tasks-view.tsx

chat/components/task-board/task-approval-actions.test.tsx

chat/components/task-board/task-approval-actions.tsx

chat/components/task-board/task-editor.test.tsx

chat/components/task-board/task-editor.tsx

chat/convex/_generated/api.d.ts

chat/convex/notifications/events.ts

chat/convex/notifications/schema.ts

chat/convex/publicApi/v2/domains/workManagement.ts

chat/convex/publicApi/v2/domains/workManagementTaskBoardWrites.test.ts

chat/convex/publicApi/v2/domains/workManagementWrites.test.ts

chat/convex/publicApi/v2/http.ts

chat/convex/publicApi/v2/workManagementData.ts

chat/convex/publicApi/v2/workManagementWrites.ts

chat/convex/rhodes/portfolioWorkbench.ts

chat/convex/rhodes/runtime/constants.ts

chat/convex/rhodes/runtime/mutationAuthorization.ts

chat/convex/rhodes/runtime/mutationDispatcher.ts

chat/convex/rhodes/runtime/writes/taskWrites.ts

chat/convex/rhodes/schema.ts

chat/convex/rhodesMcpMutationParity.test.ts

chat/convex/taskBoard/appendReceipts.ts

chat/convex/taskBoard/approval.test.ts

chat/convex/taskBoard/approval.ts

chat/convex/taskBoard/assignmentModel.ts

chat/convex/taskBoard/assignments.test.ts

chat/convex/taskBoard/completion.test.ts

chat/convex/taskBoard/completion.ts

chat/convex/taskBoard/mutations.test.ts

chat/convex/taskBoard/mutations.ts

chat/convex/taskBoard/notifications.ts

chat/convex/taskBoard/peopleBound.ts

chat/convex/taskBoard/queries.test.ts

chat/convex/taskBoard/queries.ts

chat/lib/public-api/v2/domains/work-management-schemas.ts

chat/lib/public-api/v2/domains/work-management-task-board.node.test.ts

chat/lib/public-api/v2/domains/work-management.ts

chat/lib/rhodes-mutation-tools.ts

chat/rhodes-worker/mcp-server/tools/tasks.ts

docs/task-board/FEATURE.md

packages/contracts/src/agent-tool-registry.ts

packages/contracts/src/public-api-v2.ts

packages/contracts/src/rhodes-mutation-proposal.ts

### Deliberately excluded for later phases

- Participant comments, watchers, and the daily Task Scenario digest: AERIE-2742.

- Team Tasks views and filters: AERIE-2743.

- Removing the launch gate, production verification, and final Task Board launch: AERIE-2744.

- Multi-stage or unanimous approval. V1 closes after any one eligible approver approves.

- A general Reopen action. Request changes and Remove approval cover the approved V1 cases.

---

## Test plan

### Automated validation

- Focused approval and regression suites — 182/182 passed across 11 files (including legacy flag-off writes, gated Task Board writes, approval lifecycle, UI, API, MCP, and Rhodes parity)

- Flag-off assignability regression — red before repair (create returned 201, expected 422), then green 10/10 after restoring shared userIds validation for requiredApprovers; both create and update assert requiredApprovers_user_not_assignable

- Original hosted-failure reproduction after repair — 96/96 passed across 3 files (route-manifest parity, legacy work-management writes, and portfolio workbench)

- Full repository tests — all suites passed with the timing-sensitive contracts workspace constrained to one worker: contracts 1,337/1,337, Chat 12,136 passed / 18 skipped, all other workspace suites green, and root 154/154. Unconstrained pnpm test attempts hit only the unrelated existing 5-second agent-run-protocol timing limit; that file passed alone 20/20 and in the complete constrained contracts suite.

- Full repository check — passed (pnpm check), covering full lint/static validation and every workspace typecheck

- Architecture boundaries, Convex paths, bounded reads, test architecture, and knowledge hygiene — passed as part of pnpm check

- Biome — passed across 3,124 files; two pre-existing unrelated warnings remain in chat/skill/forge-api/scripts/sindri.mjs

- Pre-commit checks and git diff --check — passed

- Reviewed-slice equivalence before incremental repairs — stable patch ID 7df84e8a170e2ab8b67e788f992c9a1922ac667d was identical for prior reviewed slice de068754bc35663ef6cde6e7651d45f988e097fd..80d378569992dbf4056d5c716cc0b99f0fc395a0 and its exact 45-path rebuild c17409f3802fe73909732a3c9392b1f147e2a871..371a6ff7e5a34d379ba8dc77717f97f8ad270c4f

- Post-equivalence hosted-CI repair — five targeted compatibility/gating/test-harness edits only: gate the request-changes handler and operation ID, preserve legacy flag-off approver behavior and people-limit error translation, use valid unique-user cap fixtures, and add the three approval hooks to the portfolio workbench test mock

- Post-equivalence independent-review repair — restored assignability validation for both assignees and legacy flag-off requiredApprovers, with create and update regressions; no product behavior was newly selected

- Exact-parent ancestry — final head 0a22c45fd638b2c58cf19ffa63d84846ee1419d4 has merged main commit c17409f3802fe73909732a3c9392b1f147e2a871 as its direct parent

- Exact-head diff scope — only the 47 authorized paths listed above (+3363/-176)

- Hosted CI — passed on exact final head 0a22c45fd638b2c58cf19ffa63d84846ee1419d4: Test, Build, Cloudflare Workers build, both Docker builds, Typecheck, Lint + Boundaries, and Secret Scan are green in run [37766704117](https://github.com/AI-Builder-Team/Aerie/actions/runs/37766704117); Praxis and automatic Mercy also passed

### Time for Implementation

About 2 to 3 weeks for one engineer without AI assistance, including contract design, UI and API implementation, agent parity, notification behavior, regression coverage, and review repairs.

---

## Review repairs and contract clarifications

[Mercy exact-head review of 049384a94](https://github.com/AI-Builder-Team/Aerie/pull/1729#pullrequestreview-5456173366) reported one blocking requester-identity concern. No code change is warranted because the finding conflates the authenticated creator/audit actor with the Task's requester business role.

The approved Task contract deliberately keeps those identities distinct: creator is always derived from the authenticated Aerie user or API-credential owner, while requester may differ and defaults to creator when omitted. The agent flow preserves that boundary. requireCanMutateTool authenticates and authorizes the Aerie user before execution; the server passes that immutable user ID as actorUserId; createTask stores creator and audit actor from actorUserId; and the optional requester input is resolved only into the Task's requester participant. When approval is required and no approver is supplied, using requester as the default approver is also an explicit locked product decision. Supplying a different requester therefore neither changes the authenticated actor nor grants the caller another identity. Forcing requester to equal actor would remove an approved workflow rather than close an authorization bypass.

The remaining review items are explicitly deferred or nonblocking and do not alter the Task result, authorization boundary, or dormant production effect of this phase. Validation remains 182/182 focused tests, full repository checks green, and hosted CI green on the exact head. Production behavior remains gated by AERIE_TASK_BOARD_ENABLED; there is no deployment, migration, or external write from merging this phase.

---

## Mercy reconsideration on 049384a94

The [reconsideration review](https://github.com/AI-Builder-Team/Aerie/pull/1729#pullrequestreview-5456630835) withdrew the requester-identity concern after following the authenticated actor and requester paths separately. The same exact-code review found one reachable UI defect: removing the task query parameter through browser navigation left the old Task detail selected. The next head clears that selection and adds a focused browser regression.

The four findings marked blocking do not require production changes:

- Notification events persist actorUserId: args.actorUserId directly for every event type. The task-type conditional immediately below applies only to sourceTaskId and taskTitle; it does not control actor forwarding. Approval events therefore retain the actor used by eventToEmitArgs.

- The public Task response status enum already includes awaitingApproval at work-management-schemas.ts:333 under the same taskBoardEnabled() gate that exposes approval fields and operations. Gated approval responses validate against the gated enum.

- Completion submission clears closureReason, delayedReason, and blockedReason before a Task can enter awaitingApproval. Approval can only complete that current submission, so Remove approval cannot inherit those fields through any supported lifecycle path.

- Approval configuration resolves every approver from a current assignable person record. The production codebase has no path that hard-deletes a user row or converts a person principal into a non-person after configuration, so the proposed orphaned sole-approver state is not reachable through an owned production transition. Reconfiguration continues to revalidate every selected approver.

This branch has already incorporated review findings that did demonstrate real behavior, including request-changes launch gating, flag-off compatibility, assignability validation, and stale Task-switch response protection. The distinction here is therefore evidentiary, not a refusal to address review feedback: reachable defects have been repaired, while adding duplicate branches for states already excluded by the current code would increase complexity without changing production behavior.

---

## Mercy exact-head review on f625543cb

The [exact-head review](https://github.com/AI-Builder-Team/Aerie/pull/1729#pullrequestreview-5457313488) confirms that the earlier notification actor, gated status enum, stale metadata, orphaned approver, and deep-link concerns are resolved. The deep-link issue was the only reachable defect in that round and was repaired with a focused browser regression.

The four newly reported blockers do not identify reachable incorrect behavior:

- Gated Work Plan creation ignores the supplied status and always creates new. Gated edits require the supplied status to equal the stored status and omit status from updateTask. The broad argument validator therefore cannot create or transition a Task to awaitingApproval; only completion submission emits that state.

- The approved contract defines Awaiting approval as open review work and Completed and Rejected as the only generally immutable statuses. The immutable object under review is the completion submission and its evidence. Generic edits cannot change status, approval fields, the current submission, or review history; approval configuration remains separately guarded, including atomic eligible-approver replacement while review is pending.

- publicApiV2RequestGuardError rejects a missing or blank Idempotency-Key with 400 idempotency_key_required before dispatch. Approve, Remove approval, and Request changes all declare that guard as required when the Task Board gate is enabled, so their handlers never hash an absent public header.

- The optional idempotency hash on the two internal compatibility mutations exists because the same mutations also serve the flag-off legacy approval endpoints, which do not use append receipts. Every gated public call reaches them only after the router guard and passes the resulting non-empty hash. There is no accepted public payload that reaches the empty fallback.

No production code change is warranted for these four findings. The branch continues to accept and repair demonstrated defects while declining changes that would either duplicate an existing boundary or contradict the approved open-status lifecycle. Current main advanced only through unrelated dbt forecast files after this verdict; the next head will merge that main once without changing any reviewed Task path.

#1742 — feat(dbt): forecast new schools from weekly pace @vvp-trilogy  approved

## Summary

- generate distinct End-of-Year and Start-of-Year weekly pace candidates at target-year grain

- classify opening program years and use weekly pace with known-only departures when comparable history is unavailable

- persist and publish complete weekly provenance, selected methods, raw operands, and rounding boundaries

- preserve coherent live-or-locked End-of-Year provenance and use resolved EOY returners for following-year forecasts

## Validation

- poetry run dbt parse --profiles-dir /home/ubuntu/aerie/control/dbt --no-partial-parse

- rendered changed models and parsed them as Redshift SQL with sqlglot

- git diff --check

Closes #1740

#1751 — fix(documents): retire Global hard delete, require edit reasons, and explain refused reindexes (AERIE-2776) @marcusdAIy  approved

## Summary

Fixes [AERIE-2776](https://linear.app/builder-team/issue/AERIE-2776/retire-the-legacy-globaldocumentsremove-mutation). This is the cleanup that waited for #1725 to reach prod (it shipped in #1731 on 7 Oct).

- Global documents can no longer be hard-deleted. The legacy globalDocuments.remove mutation is gone. removeDocumentWithKnowledge, which every remaining delete path uses, now refuses Global rows with "Global documents are archived, not deleted." That covers the internal rhodes/documents.remove table mutation, Rhodes sync deletes, and the migration path. The MCP removeDocument tool already rejected Global documents.

- Edits require a reason. reason is now required on globalDocuments.update, globalDocuments.updateVerifiedDrive and the globalDocumentDrive.replace action. A blank reason is rejected, and every global_document.updated audit entry records it.

- A refused Reindex or Retry says why. The reindex and retry mutations now return the specific message (already queued or running, in the re-index cooldown, or held), and the admin page shows it instead of "No new indexing work was accepted". Retry now goes through the same requestGlobalDocumentReindex helper as Reindex, so both report refusals the same way; its audit entry still records reason: "retry".

## Why it's needed

remove and the optional reason were kept only so admin pages loaded before #1722 and #1725 kept working. Both releases are in prod, so archive is now the only way to take a Global document out of use, and every admin edit is explained in the audit log.

The toast fix came from prod: a manager clicked Reindex, saw no change (the document was already "Available"), clicked again, and got a generic error that hid the reason, which was that the first click had worked.

## Changes

- chat/convex/globalDocuments.ts: removed remove and its compatibility comment, and the now-unused removeDocumentWithKnowledge import. Made reason required on update and updateVerifiedDrive. reindex and retry return message. requestGlobalDocumentReindex takes an optional trigger ("reindex" or "retry") for the audit entry.

- chat/convex/globalDocumentDrive.ts: replace requires reason and always passes it through.

- chat/convex/documentKnowledge/lifecycle.ts: removeDocumentWithKnowledge rejects documentScope: "global" rows.

- chat/app/(main)/admin/global-documents/page.tsx: refused Reindex or Retry shows result.message first.

## Breaking changes

- Admin tabs left open since before the #1725 release (7 Oct, 4:48 PM CT) will get an error from Edit until they reload. The current page always sends a reason.

- Any internal script that hard-deleted Global documents now fails. Nothing in the repo does this.

## Test plan

- [x] Replaced the legacy remove parity test: api.globalDocuments.remove no longer exists, and internal.rhodes.documents.remove on a Global document is rejected with the row still present.

- [x] Drive replace without a reason is rejected. With a reason, the global_document.updated audit entry records it.

- [x] update without a reason or with a blank reason is rejected. With a reason, exactly one audit entry records it.

- [x] Page test: a refused reindex shows the server's specific message.

- [x] Related suites (Global documents, Drive, document knowledge, Rhodes document CRUD, Task Board documents, capacity automation, v2 public API, admin page): 48 files, 894 tests passed.

- [x] Full chat suite: 12,097 passed. The 15 failures (Forge API driver, Sindri contract, skill packaging, platform-error inventory, portfolio workbench) fail identically on clean main.

- [x] pnpm typecheck and Biome are clean.

#1756 — feat(task-board): add comments, watchers and daily digest (AERIE-2742) @caina-barbosa  approvedmercy-allow-critical

## Summary

This PR is Phase 11 of 13 in the larger [Human Task Assignment from Aerie](https://linear.app/builder-team/project/human-task-assignment-from-aerie-b3582376ae6e) project.

It adds Task comments, watcher controls, and the daily Task Scenario email across the UI, API, and agent tools. This phase is tracked by [AERIE-2742 - Add participant comments, watchers and the daily Task Scenario digest](https://linear.app/builder-team/issue/AERIE-2742/add-participant-comments-watchers-and-the-daily-task-scenario-digest).

Production effect: compatibility hardening plus dormant/additive. Existing Task-linked Notes become read-only when their Task is Completed or Rejected. The new Task Board comment, watcher, and digest experiences remain unavailable while AERIE_TASK_BOARD_ENABLED is off. Merging this PR does not send Task Scenario emails or expose the incomplete Task Board.

---

## Why

Task work needs one place for discussion and a simple way for interested people to follow progress without giving them management authority. The digest then gives each user one bounded daily summary instead of producing more immediate email noise. This slice also makes closed Tasks consistently read-only before Team Tasks and the final launch work land.

---

## Business Value

- Keeps Task discussion attached to the Task by reusing Aerie Notes.

- Lets users follow a Task like a CC without receiving permission to manage it.

- Sends one daily summary of relevant open work and sends nothing when there is nothing to report.

- Gives users, APIs, and agents the same watcher and comment behavior.

- Prevents comments, watcher changes, and other Note edits from changing a closed Task's history.

### What it means for end users and consumers

| User or consumer | What this PR provides | Important limit |

| --- | --- | --- |

| Task participant | Can read and add comments to an open Task they can access | Closed Tasks remain readable, but their discussion cannot be changed |

| Portfolio user | Can comment on an open Task already visible through Portfolio access | This does not grant broader Task or site access |

| Any user who can see a Task | Can watch or unwatch that open Task | Watching grants visibility and digest inclusion, not management authority |

| Creator, requester, or global Task manager | Can add or remove other watchers | A Task supports at most 50 watchers |

| Watcher | Sees the Task in My Tasks and in the daily digest while it remains relevant and open | Watchers cannot start, edit, approve, reject, or otherwise manage the Task merely because they watch it |

| Digest recipient | Receives one Task Scenario email at 7:30 a.m. America/New_York with relevant open assigned, watched, created, and Awaiting approval Tasks | No email is sent when there is no relevant work; the email shows at most 100 Tasks and links to My Tasks for more |

| API client or agent | Can add Task comments and manage watchers through the same authorized workflow | Writes are idempotent where applicable and closed Tasks return the stable read-only error |

| Existing Note consumer | Cannot create, edit, or delete a Note anchored to a Completed or Rejected Task | Non-Task Notes and Notes on open Tasks keep their existing behavior |

---

## How does it work

1. Task comments reuse the existing Notes writer with a Task anchor. Task visibility is checked first, comments are limited to 5,000 characters, and reads use cursor pagination with up to 100 items per page.

2. Users can watch or unwatch a visible open Task. Creators, requesters, and users with operations.tasks.write can manage other watchers. Every change is audited and reconciles the indexed Task participant rows.

3. The participant projection records whether each relationship belongs in the digest. Creator, assignee, and watcher relationships are eligible for open Tasks; approver relationships are eligible while a Task is Awaiting approval.

4. The daily job evaluates 7:30 a.m. in America/New_York, pages through users in groups of 50, reads at most 401 eligible participant rows to prove the 100-Task email limit, and schedules its next user page immediately.

5. Delivery is idempotent per recipient and New York calendar date. No email is queued when the user has no relevant Tasks. A user with more than 100 relevant Tasks receives the first 100 plus a link to My Tasks.

6. UI, public API, and agent tools share the same authorization and write paths. Creating, updating, or deleting a Note anchored to a Completed or Rejected Task fails through the shared clean-error path.

7. The existing Task participant reconciliation migration now verifies and backfills digest eligibility. It must be run and verified before the final launch gate is removed; merging this PR does not start that migration.

---

## Scope

### Included in this phase

- Task comments backed by Notes, including bounded pagination and closed-Task immutability.

- Self-service watching and authorized management of other watchers.

- Watcher visibility in My Tasks and indexed participant relationships for fast queries.

- One daily, gated, idempotent Task Scenario digest at 7:30 a.m. America/New_York.

- Public API and agent parity for Task comments and watcher actions.

- Participant reconciliation and verification support for digest eligibility.

- Exact final diff paths:

chat/components/task-board/my-tasks-view.test.tsx

chat/components/task-board/my-tasks-view.tsx

chat/components/task-board/task-detail.test.tsx

chat/components/task-board/task-detail.tsx

chat/components/task-board/task-participation-actions.test.tsx

chat/components/task-board/task-participation-actions.tsx

chat/convex/_generated/api.d.ts

chat/convex/automations/cronRegistry.ts

chat/convex/crons.ts

chat/convex/lib/taskScenarioEmail.ts

chat/convex/migrations/taskParticipants.test.ts

chat/convex/migrations/taskParticipants.ts

chat/convex/notifications/events.ts

chat/convex/notifications/schema.ts

chat/convex/publicApi/v2/domains/siteNotes.ts

chat/convex/publicApi/v2/domains/workManagement.ts

chat/convex/publicApi/v2/domains/workManagementTaskBoardWrites.test.ts

chat/convex/publicApi/v2/http.ts

chat/convex/publicApi/v2/siteNotes.test.ts

chat/convex/publicApi/v2/workManagementData.ts

chat/convex/publicApi/v2/workManagementWrites.ts

chat/convex/rhodes/mcp.ts

chat/convex/rhodes/runtime/constants.ts

chat/convex/rhodes/runtime/mutationAuthorization.ts

chat/convex/rhodes/runtime/mutationDispatcher.ts

chat/convex/rhodes/runtime/writes/noteWrites.ts

chat/convex/rhodes/schema.ts

chat/convex/rhodesMcpMutationParity.test.ts

chat/convex/taskBoard/appendReceipts.ts

chat/convex/taskBoard/approval.test.ts

chat/convex/taskBoard/approval.ts

chat/convex/taskBoard/comments.ts

chat/convex/taskBoard/completion.test.ts

chat/convex/taskBoard/completion.ts

chat/convex/taskBoard/digest.test.ts

chat/convex/taskBoard/digest.ts

chat/convex/taskBoard/lifecycle.test.ts

chat/convex/taskBoard/lifecycle.ts

chat/convex/taskBoard/participants.ts

chat/convex/taskBoard/queries.ts

chat/convex/taskBoard/visibility.ts

chat/convex/taskBoard/watchers.test.ts

chat/convex/taskBoard/watchers.ts

chat/lib/public-api/v2/domains/work-management-schemas.ts

chat/lib/public-api/v2/domains/work-management-task-board.node.test.ts

chat/lib/public-api/v2/domains/work-management.ts

chat/lib/rhodes-mcp-contract.ts

chat/lib/rhodes-mutation-tools.ts

chat/rhodes-worker/mcp-server/tools/tasks.ts

docs/task-board/FEATURE.md

packages/contracts/src/agent-run-protocol.ts

packages/contracts/src/agent-tool-registry.ts

packages/contracts/src/rhodes-mutation-proposal.ts

scripts/check-monitoring-cron-coverage.test.mjs

### Deliberately excluded for later phases

- Team Tasks filters, grouping, and shareable URLs are owned by AERIE-2743.

- Final navigation, creation entry points, migration execution, verification, and launch-gate removal are owned by AERIE-2744.

- Weekly digests are not part of V1.

- Watching does not add Task management or lifecycle authority.

- This PR does not run the participant backfill or enable AERIE_TASK_BOARD_ENABLED.

---

## Test plan

### Automated validation

- Retained AERIE-2742 Chat evidence: 10/10 files, 147/147 tests passed (pnpm --dir chat exec vitest run components/task-board/my-tasks-view.test.tsx components/task-board/task-detail.test.tsx components/task-board/task-participation-actions.test.tsx convex/migrations/taskParticipants.test.ts convex/publicApi/v2/domains/workManagementTaskBoardWrites.test.ts convex/publicApi/v2/siteNotes.test.ts convex/rhodesMcpMutationParity.test.ts convex/taskBoard/digest.test.ts convex/taskBoard/watchers.test.ts lib/public-api/v2/domains/work-management-task-board.node.test.ts).

- Full Task Board suite: 11/11 files, 95/95 tests passed (pnpm --dir chat exec vitest run convex/taskBoard).

- Portfolio Workbench regression suite: 67/67 passed (pnpm --dir chat exec vitest run components/dashboards/portfolio/__tests__/portfolio-rhodes-workbench.test.tsx).

- OpenAPI suite: 14/14 passed (pnpm --dir chat exec vitest run --project node lib/public-api/v2/openapi.node.test.ts).

- Final focused AERIE-2742, API/MCP parity, and agent allowlist gate: 14/14 files, 295/295 tests passed.

- Monitoring cron checks: 3/3 passed (node --test scripts/check-monitoring-cron-coverage.test.mjs).

- Full workspace typecheck: passed (pnpm typecheck).

- Full static/lint suite: passed with 2 unrelated existing warnings in chat/skill/forge-api/scripts/sindri.mjs (pnpm lint).

- Architecture boundaries, Convex path checks, read-bound checks, test architecture, knowledge hygiene, Biome, and git diff --check 09e3828351d6293a3282edfa2bc0519fa382522e..HEAD: passed.

- Exact-head diff scope: 54 paths, 2,526 additions, 79 deletions, and 15 AERIE-2742 commits on current main 09e3828351d6293a3282edfa2bc0519fa382522e.

- Test reviewability: the essential test delta is net +889 lines (894 additions, 5 deletions), down from the original net +1,514 (1,519 additions, 5 deletions), a 41.3% reduction while retaining watcher bounds, digest projection transitions, UI actions/read-only behavior, authorization, pagination, schedule, API/MCP parity, and real regression coverage.

- Independent review: PASS on the final 15-patch content, including the one-line agent allowlist integration repair; the conflict-free rebase produced exact head c4509829065470557ec24869abb1cb8256ed58d7 with all patches equivalent.

The PR remains Draft, is based directly on current main at 09e3828351d6293a3282edfa2bc0519fa382522e, and contains the final approved AERIE-2742 delta after AERIE-2741 merged at 17add4b9c3b54c1c3576d56023480266ef19a587.

### Time for Implementation

About 2 weeks for an engineer without AI assistance, including implementation, tests, independent review repairs, stack reconstruction, and release preparation.

## Review repairs and contract clarifications

Review [37820195787](https://github.com/AI-Builder-Team/Aerie/actions/runs/37820195787) was classified under [AERIE-2742](https://linear.app/builder-team/issue/AERIE-2742/add-participant-comments-watchers-and-the-daily-task-scenario-digest) at reviewed head c4509829065470557ec24869abb1cb8256ed58d7. No production repair is warranted because each reported blocker is contradicted by the approved contract or the complete runtime path:

- Portfolio visibility is deliberate. docs/task-board/FEATURE.md defines Team Tasks as portfolio-wide, states that Portfolio users can view Tasks across all sites, permits those users to comment on visible Tasks, and explicitly excludes site-specific Task permissions. operations.portfolio.read is the existing Portfolio-access capability, so the final branch of canViewTask implements that locked decision.

- The public comment response already satisfies WorkManagementTaskComment. listTaskComments returns the comment-owned fields, then the shared responseFor serializer attaches the fully resolved SiteReference to every row before the HTTP response is emitted. The focused HTTP test observes { id, slug, displayName } on the comment row; the cited internal projection is not the published response boundary.

- Watcher projection does not silently erase a Task. The only production watcher writer validates an existing active Aerie user before persisting the reference. User public IDs are globally verified before directory-backed API reads, every new user path mints one, and production user administration does not hard-delete user rows. If stored reference integrity were nevertheless broken, projectTask returns integrity_error and the HTTP boundary emits explicit 503 work_management_reference_integrity_failed; it cannot return a successful page with the Task omitted.

- Public API and MCP participation writes intentionally require operations.tasks.write. The feature contract says credentials may manage Tasks when both the credential scope and owner have that capability and explicitly declines a participant-only API capability in V1. In-app participant and Portfolio self-service continues through the canonical Task authorization path and is not narrowed by that automation boundary.

The boundaries remain unchanged: Portfolio access is portfolio-wide; relationship-based access remains Task-scoped for users without Portfolio access; watcher membership grants visibility but no lifecycle authority; API credentials remain management automation rather than participant impersonation; and all new behavior remains behind the production Task Board gate.

Validation on the reviewed head remains green: hosted CI is green, and the focused public Task Board API suite passes 11/11 tests (pnpm --dir chat exec vitest run convex/publicApi/v2/domains/workManagementTaskBoardWrites.test.ts --maxWorkers=1). This clarification changes no code, data, deployment behavior, migration state, or production traffic.

#3853 — fix(qtd-reports): prevent queued jobs on ECS launch errors @sanketghia  approved

## Summary

- Pass the EC2-configured AWS_REGION explicitly when creating the ECS client, with AWS_DEFAULT_REGION as fallback.

- Route unexpected pre-launch exceptions through the existing failure update in both on-demand launch endpoints so jobs do not remain queued.

## Verification

- uv run ruff format services/monthly_qtd_report/ecs_launcher.py routers/qtd_ondemand_router.py — passed; no formatting changes.

- uv run ruff check services/monthly_qtd_report/ecs_launcher.py routers/qtd_ondemand_router.py — passed.

- uv run pyright services/monthly_qtd_report/ecs_launcher.py routers/qtd_ondemand_router.py — 0 errors.

- uv run pytest --import-mode=importlib tests/monthly_qtd_report/test_ecs_launcher.py tests/routers/test_qtd_ondemand_router.py -q — 48 passed.

- git diff --check — passed.

## Screenshot

- Previously failing on-demand jobs now succeed

<img width="935" height="113" alt="image" src="https://github.com/user-attachments/assets/ccb8327e-5da3-48c6-8f87-98c52726665e" />

The Builder Desk  —  Engineer Spotlight
Production Release🏆 Engineer Spotlight

TWENTY-FOUR HOURS, TWENTY-FOUR PULL REQUESTS: THE BUILDER TEAM REFUSES TO SLEEP

Four repos, six engineers, one glorious blur of green checkmarks — the numbers don't lie, comrades, and the numbers are beautiful.

Friends, I have looked at the spreadsheet and the spreadsheet has looked back at me with pride. Twenty-four pull requests in twenty-four hours. Four repositories under siege. Aerie alone absorbed sixteen PRs — SIXTEEN — like a planet with its own gravitational field, pulling engineers in and spitting out shipped code. Surtr took four, Klair three, and even humble Rhodes-DSS got its moment in the sun with one. This is not luck. This is not coincidence. This is a machine, and the machine is us.

Let us walk the floor. @sanketghia posted five PRs spanning three repos — #3856 and #3855 in Klair, #2145 and #2138 in Surtr — a man who apparently does not believe in single-repo loyalty. @vvp-trilogy matched him with five, including #1743 and #1761 in Aerie, quietly rebuilding the forecasting engine while nobody was looking. @caina-barbosa also logged five, anchored by #1758 and #1736, both gated, both guarded, both shipped anyway. @marcusdAIy delivered four including #1762 and #1752, teaching the platform to read Excel workbooks like a man teaching a dog to fetch the newspaper. @benji-bizzell held the line with three, and @kevalshahtrilogy closed out the board with two, including the historic #16 in Rhodes-DSS — a repo so quiet it practically threw a parade.

Now. Ashwanth. The man is not on today's board, and let me tell you, the absence is LOUDER than his presence. Sources close to the numbers desk (me, standing near a monitor) suggest he is likely mid-refactor on something the rest of us won't understand until Thursday. When reached for comment on his quiet 24 hours, Ashwanth reportedly said, "I don't ship daily, I ship inevitably." Whether that quote is real is beside the point. When I asked if he'd review anyone's diff from this cycle, he said, "Pass," and walked away. Legend status: unthreatened.

Now to the overflow desk, where Mac's spotlight couldn't reach. #1759 and #1748 from @benji-bizzell quietly preserved triage evidence in Aerie's platform-errors pipeline — unglamorous, essential. #2142 kept Surtr's pipelines running in quiet mode through recovery, a small miracle nobody will thank him for. And #1745 from @caina-barbosa restored master during hosted testing, the digital equivalent of catching a falling plate before it hits the floor.

Morale report: off the charts. Every desk, every repo, every engineer — operating at an all-time high. The Builder Team doesn't just ship. It triumphs.

Brick's Overflow — PRs Mac Didn't Cover  (click to expand)
#16 — fix(contract): describe errors, headers and limits as served; add business-question enablement @kevalshahtrilogy  no labels

Linear: AI-984

## What changed

Fixes for the findings the DSS registry filed on our feedback intake (2026-10-07 and 2026-10-08) that can be fixed in this service.

Contract (0.3.2 → 0.3.3)

- Refreshed from upstream. The utilities card's ninth block, fire_alarm_monitoring, is now declared.

- Errors are described as served. Every operation now declares this service's own 401 {error: unauthorized} and 502 {error: upstream_unavailable}, and no longer declares 403, which this service never returns. The preface explains the two error shapes (problem details relayed from the system of record; {error} from this service) and what 409, 422 and 503 mean here.

- The site document search now declares the 2,000 code point query bound that the relay already enforces on both searches.

- Rate limits are described as shared by all callers, not per key. X-RateLimit-Limit / X-RateLimit-Remaining are documented.

- The upstream platform's own skill-version header was declared on every response and sent on none; it is removed.

Enablement

- New section "Questions Rhodes answers": what the source is good for and not, ten business question types with the reads to use and the mistake to avoid, and two portfolio-wide worked examples (open schools and seats; overdue work). The portfolio examples use include=profile, which turns a per-site sweep into one or two calls.

- Section 11 documents the rate-limit headers and the two error shapes.

No change to routes, dispatch, keys or the dictionary.

## Not addressed here

- Bulk or changed-since reads, updatedAt on cards, and the quality-bar catalog need changes in the system of record.

- Field definitions in the dictionary and a brainlift need the data owner's decision.

## Business Value

The registry grades this source on a schedule and publishes the grades stakeholders see. These were the findings where the published contract and guide said something different from what the service does, which makes an agent mishandle errors and over-spend the shared rate budget. The business-question section is what the registry's contract requires an enablement to be.

## Manual Effort Estimate

About 5 hours by hand. Proposed figure; Keval to confirm or adjust.

## Testing

- pnpm check passes (50 tests; 1 new covering every contract change above).

- Existing test confirms every route cited in the new enablement text is published and uses only declared parameters.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

#1736 — feat(tasks): add gated Team Tasks workspace (AERIE-2743) @caina-barbosa  approved

## Summary

This PR is Phase 9 of 10 in the larger [Human Task Assignment from Aerie](https://linear.app/builder-team/project/human-task-assignment-from-aerie-b3582376ae6e) project.

It adds the gated Team Tasks workspace for Portfolio users: bounded cross-site Task reads, summaries, grouping, filters, shareable URLs, and the shared Task detail and action experience. This phase is tracked by [AERIE-2743 — Ship Team Tasks behind the launch gate](https://linear.app/builder-team/issue/AERIE-2743/ship-team-tasks-behind-the-launch-gate).

Production effect: dormant/additive. Team Tasks remains unavailable while the existing server-authoritative Task Board launch gate is off. Merging this PR initiates no external traffic, migration, or background processing. The exact 15-commit branch is based on main commit a43133ceec337c780c146726af6be8458d871101.

---

## Why

Portfolio users need one bounded place to review and manage Tasks across sites without introducing management hierarchies or broad scans. This slice establishes that final gated workspace and its indexed projection before AERIE-2744 removes the launch gate.

Independent review of the complete slice drove two focused repairs: the projection scan now stays below Convex's hard DB-call ceiling in the true worst case, and every Team Tasks external-assignee label uses the approved wording. The final replay onto a43133ceec337c780c146726af6be8458d871101 preserved all 15 patches exactly, and fresh independent exact-head review passed on 271ec052aaf8c3afe009b4bb68bf7e2600ddcceb.

---

## Business Value

- Gives Portfolio users one cross-site view for operational Tasks.

- Makes work discoverable through summaries, detailed filters, grouping, and shareable URLs.

- Reuses My Tasks' canonical detail and lifecycle actions instead of creating a parallel workflow.

- Keeps cross-site reads bounded and predictably safe at production scale.

- Clearly distinguishes external assignees who do not have Aerie accounts.

### What it means for end users and consumers

| Area | Plain-language production effect |

| --- | --- |

| Availability | No user sees Team Tasks yet; the existing launch gate remains authoritative until AERIE-2744. |

| Access | After launch, only users with existing Portfolio access can open Team Tasks. My Tasks remains available to every authenticated user. |

| Site visibility | Portfolio users see Tasks across Portfolio sites; this creates no new site access or management hierarchy. |

| Finding work | Users can choose Open, Overdue, Due this week, Awaiting approval, or Closed in the last 7 days and combine the agreed Task and participant filters. |

| Grouping | Results can be grouped by stable person identity or site identity, so duplicate display names do not merge unrelated people or sites. |

| External assignees | Team headings and filter choices display email · External, no Aerie account. |

| Sharing | Filters live in URL query parameters; another authorized user sees the same filtered view subject to their own access. |

| Creating and managing | Authorized users can create a site-level Task and use the same detail, editing, participation, lifecycle, completion, and approval controls as My Tasks. |

| Closed Tasks | Completed and rejected Tasks remain visible but read-only except for the explicit existing exceptions. |

| Scale safety | A request scans at most 1,800 projection rows: 3,600 worst-case row reads plus 400 reserved calls totals 4,000, below Convex's 4,096-call limit. Exhaustion returns a clean bounded error asking the user to narrow filters. |

---

## How does it work

1. The /tasks/team route and Convex queries enforce the existing Task Board gate; the query additionally requires operations.portfolio.read.

2. Task writes reconcile a compact indexed portfolio projection with stable Task ordering and normalized external-assignee data.

3. The Team Tasks query reads that projection in deterministic batches, fills a cursor page, or stops at the 1,800-row safety cap with the shared clean user-facing error.

4. Summary and Task, site, person, date, placement, and assignment filters are applied consistently while option searches remain indexed and bounded.

5. The React workspace stores filters in the URL, groups returned rows by stable identity, and reuses the canonical Task editor and detail actions.

6. Migration helpers reconcile and verify existing projection rows without starting automatically when this dormant slice merges.

---

## Scope

### Included in this phase

- Gated Team Tasks route and Portfolio capability enforcement.

- Bounded indexed cross-site projection, deterministic pagination, reconciliation, and verification.

- The agreed summaries, filters, stable grouping, and shareable query-parameter URLs.

- Site-level Task creation and the shared Task detail/action experience.

- A 1,800-row request cap with explicit Convex DB-call headroom and clean exhaustion behavior.

- Approved external-assignee labels in Team Tasks grouping and filtering.

- 15 commits; 14 paths; 2,143 additions and 33 deletions against main at a43133ceec337c780c146726af6be8458d871101.

- Exact final diff paths:

chat/app/(main)/tasks/team/page.tsx

chat/components/task-board/my-tasks-view.tsx

chat/components/task-board/task-editor.test.tsx

chat/components/task-board/task-editor.tsx

chat/components/task-board/team-tasks-view.test.tsx

chat/components/task-board/team-tasks-view.tsx

chat/components/ui/enum-popover.tsx

chat/convex/migrations/taskParticipants.test.ts

chat/convex/migrations/taskParticipants.ts

chat/convex/rhodes/schema.ts

chat/convex/taskBoard/participants.ts

chat/convex/taskBoard/queries.test.ts

chat/convex/taskBoard/queries.ts

chat/convex/taskBoard/teamProjection.ts

### Deliberately excluded for later phases

- Removing the Task Board launch gate or exposing Team Tasks in production — AERIE-2744 owns final launch.

- New management hierarchies, inferred direct reports, or wider site access.

- Weekly digests or other post-V1 notification schedules.

- Automatic migration execution or rollout work triggered by merge.

---

## Test plan

### Automated validation

- Focused Team Tasks UI, shared editor, My Tasks navigation, query, and projection-migration suite — 5 files / 45 tests passed (pnpm --dir chat exec vitest run components/task-board/team-tasks-view.test.tsx components/task-board/task-editor.test.tsx components/task-board/my-tasks-view.test.tsx convex/migrations/taskParticipants.test.ts convex/taskBoard/queries.test.ts --maxWorkers=1)

- Scan-safety regression — 1,801 real projection rows reach the 1,800-row cap and return the clean bounded error; worst-case arithmetic is locked at 4,000 calls below the 4,096 hard limit.

- External-assignee presentation regression — approved label verified in both person grouping and filter options.

- Full workspace typecheck — passed (pnpm typecheck).

- Full workspace lint, Biome, architecture boundaries, Convex paths, read bounds, test architecture, and knowledge hygiene — passed (pnpm lint); two pre-existing chat/skill/forge-api/scripts/sindri.mjs warnings remain unchanged.

- git diff --check a43133ceec337c780c146726af6be8458d871101..271ec052aaf8c3afe009b4bb68bf7e2600ddcceb — passed.

- Final rebuild equivalence — 15/15 range-diff patches identical; aggregate patch ID 39d1c4bbff0e3fe8a71dbcabc8655d20f2984d8d unchanged.

- Independent exact-head review — PASS on 271ec052aaf8c3afe009b4bb68bf7e2600ddcceb.

- Exact-head diff scope — only the 14 authorized paths listed above.

### Time for Implementation

About 2 to 3 weeks for an engineer without AI assistance, including design, implementation, migration safety, focused scale tests, integration repair, rebasing, and review.

## Review repairs and contract clarifications

Review [37827885084](https://github.com/AI-Builder-Team/Aerie/actions/runs/37827885084) was classified under [AERIE-2743](https://linear.app/builder-team/issue/AERIE-2743/ship-team-tasks-behind-the-launch-gate) at reviewed head 271ec052aaf8c3afe009b4bb68bf7e2600ddcceb.

One reachable blocker was accepted. The migration verifier intentionally detects duplicate taskPortfolioRows, but canonical Task deletion used .unique() for that same projection and therefore aborted before deleting the Task when duplicates existed. The repair reuses the existing 100-row per-Task safety bound, reads at most 101 rows, rejects only states beyond that established bound, and deletes every bounded matching projection row before Task deletion continues. A focused regression creates the duplicate state at the real deletion seam and proves that the Task, participant rows, and all portfolio rows are removed atomically.

The three nonblocking suggestions do not require changes in this slice:

- External-assignee email matching already uses one canonical form. Every production assignment write starts in resolveAssignmentEmails, which trims and lowercases through normalizeEmail before taskAssignments and the Team Tasks projection are written; the existing filter regression also proves a mixed-case, whitespace-padded query matches the stored assignment.

- Existing assignees are edited directly through the initialized Assignee emails textarea, including internal and external addresses. availableUsers supplies requester and eligible-approver choices, so adding assignees there would not restore a missing unassign action.

- Projection reconciliation and zero-mismatch verification are already an explicit launch prerequisite in migrations/taskParticipants.ts. This PR remains dormant and does not enable the launch gate; AERIE-2744 owns running and verifying the migration before activation.

The established boundaries remain unchanged: Team Tasks stays gated and Portfolio-only, reads remain bounded and indexed, migration execution is not triggered by merge, and no site access or management hierarchy is added.

Independent exact-diff review passed with no findings. Current repair validation: the focused Team Tasks query and projection-migration suites pass 26/26 tests (pnpm --dir chat exec vitest run convex/taskBoard/queries.test.ts convex/migrations/taskParticipants.test.ts --maxWorkers=1), Chat typecheck passes (pnpm --dir chat typecheck), and git diff --check passes. The repair changes only chat/convex/taskBoard/teamProjection.ts and chat/convex/taskBoard/queries.test.ts; it initiates no migration, deployment action, external traffic, or production activation.

### Exact-head projection-integrity follow-up

Mercy review 5461749675 accepted the prior external-assignee, editor, and launch-prerequisite explanations and found one new reachable integrity gap on exact head f420b2248e0157bb58604d1d7637a2f985f412af. That finding is valid: a Team Tasks projection row whose Task or site is missing must not be treated like an ordinary filter miss, because doing so returns an apparently complete cross-site page with omitted work.

The follow-up fails the bounded listTeam query closed through the shared clean-error pathway when either source record is absent. It adds no scans, migration execution, repair-on-read behavior, or launch activity. Focused regressions cover both a deleted Task and a deleted site behind a retained projection row. The exact query suite passes 24/24, Chat typecheck passes, and git diff --check passes.

#1758 — feat(tasks): add guarded review actor migration (AERIE-2789) @caina-barbosa  approved

## Title

feat(tasks): add guarded review actor migration (AERIE-2789)

## Summary

This PR is Phase 13 of 14 in the larger [Human Task Assignment from Aerie](https://linear.app/builder-team/project/human-task-assignment-from-aerie-b3582376ae6e) project.

It adds the guarded migration that the final Task Board launch needs to check and repair historical completion-review actor references. This phase is tracked by [AERIE-2789 — Ship the guarded Task review-actor migration before launch](https://linear.app/builder-team/issue/AERIE-2789/ship-the-guarded-task-review-actor-migration-before-launch).

Production effect: dormant/additive. The migration code becomes callable after deployment, but it does nothing until a production operator explicitly runs it. It is internal-only and is not connected to a scheduler, UI, API, MCP tool, or existing Task write path.

## Why

The final Task Board launch must confirm that historical completion-review records identify actors by their canonical public ID. Shipping the guarded migration first lets an operator preview conflicts, repair valid rows in bounded batches, and verify the result before the launch gate is removed.

## Business Value

- Gives operators a safe way to prepare historical Task review data before launch.

- Refuses to guess when an actor identity is missing, invalid, deleted, or duplicated.

- Keeps current Task behavior unchanged until an operator explicitly authorizes the migration.

## How does it work

1. An operator starts with a dry run that reads a bounded batch of completion-review records.

2. Each record resolves the canonical actor only through its stored actorUserId.

3. Missing, invalid, deleted, and duplicated identities are reported as conflicts. Historical names and email addresses are never used to infer identity.

4. A review snapshot whose embedded user ID disagrees with its stored actorUserId is also reported as a conflict, so the migration cannot create a contradictory identity reference.

5. Execution requires the exact confirmation value and updates only conflict-free batches. The returned cursor lets the operator resume safely.

6. Re-running an updated batch is harmless, and the separate verification action confirms that no changes or conflicts remain.

## Scope

### Included in this phase

- A bounded, resumable, confirmation-guarded internal migration.

- Dry-run, execute, and verification reporting.

- Focused coverage for successful repair, idempotency, pagination, confirmation, mismatched user references, and identity conflicts.

- Exact final diff paths:

chat/convex/_generated/api.d.ts

chat/convex/migrations/taskReviewActorPublicIds.test.ts

chat/convex/migrations/taskReviewActorPublicIds.ts

### Deliberately excluded for later phases

- Running the migration in any environment. An operator owns execution during the launch process.

- Removing the Task Board launch gate or exposing any new UI, API, MCP, or agent behavior.

- The final launch runbook and launch verification, which remain in AERIE-2744.

- Any Task lifecycle, schema, notification, digest, document, or authorization changes.

## Test plan

### Automated validation

- Focused migration coverage — 4/4 passed (pnpm --dir chat exec vitest run convex/migrations/taskReviewActorPublicIds.test.ts --maxWorkers=1).

- Chat typecheck — passed (pnpm --dir chat typecheck).

- Biome — passed (pnpm exec biome check chat/convex/migrations/taskReviewActorPublicIds.ts chat/convex/migrations/taskReviewActorPublicIds.test.ts).

- Convex module path validation — passed through the pre-commit hook.

- Test architecture validation — passed (pnpm lint:test-architecture).

- git diff --check — passed.

- Exact-head diff scope — only the three authorized migration paths listed above.

### Time for Implementation

An engineer working without AI assistance would likely need about 2 days to inspect the historical data contract, implement the guarded migration, add conflict and resumability tests, and complete review.

#1762 — Reject unsupported document types in the v2 API and report search status @marcusdAIy  approved

## Summary

[AERIE-2755](https://linear.app/builder-team/issue/AERIE-2755): the v2 API now refuses documents the indexer can't read, and every v2 document response says whether the document is searchable.

- Unsupported types get a 422 up front. Uploads (site and Global), Global Drive registrations and site relinks reject file types the indexer can't read with document_type_unsupported (retryable: false). The message names the type and lists the supported ones. No document row or upload intent is created.

- One supported-type list. The check lives in packages/contracts and is shared by the API and the Rhodes worker, so the two can't drift.

- knowledgeStatus on v2 documents. List, get, upload, update and relink responses include the same status the Rhodes workbench shows: available, processing/refreshing, or not_searchable/failure with a reasonCode and message.

## Why it's needed

Today an API client can upload a .zip or .xls, get a 201, and only find out much later that it never became searchable. Clients also had no way to tell from the API whether indexing was done.

## Changes

- packages/contracts/src/document-knowledge.ts: MIME constants, isDocumentKnowledgeSupportedType, the CSV-mislabel helpers and a human-readable supported-types description.

- chat/rhodes-worker/lib/document-knowledge/{retrieval,docx,xlsx}.ts: use the shared constants and check instead of local copies.

- chat/convex/documentKnowledge/status.ts: siteDocumentKnowledgeStatus, moved from rhodes/portfolioWorkbench.ts so the API and workbench share it.

- chat/convex/publicApi/v2/domains/documents.ts: the 422 check on upload, Global registration and relink, plus knowledgeStatus in every document response (batched query for list pages).

- chat/lib/public-api/v2/domains/documents.ts: OpenAPI knowledgeStatus property, updated 422 descriptions, and the agent-context dictionary entry.

Notes:

- Drive registration doesn't give us the file name. The two MIME types that Drive uses for mislabelled CSVs (application/vnd.ms-excel, application/octet-stream) are therefore allowed at registration and left to the worker. Uploads always have a filename, so they get the exact check.

- External link registrations are still allowed on purpose. They report not_searchable / external_url.

## Breaking changes

- Uploads, Global Drive registrations and relinks of unsupported types now return 422 instead of succeeding.

- knowledgeStatus is a new required field on the Document schema (additive for readers).

## Test plan

- [x] Upload of zip, .xls and Google Slides returns 422 document_type_unsupported; nothing is written.

- [x] Global Drive registration: zip is rejected; an Excel-labelled file is accepted (CSV-mislabel case).

- [x] Relink to a Google Slides file returns 422 and the ETag is unchanged.

- [x] Get and list return knowledgeStatus (not_searchable / external_url for a link document).

- [x] Contract tests for the supported-type check (33 passed); worker tests (306 passed); v2 API, document knowledge, Rhodes and admin suites passed.

- [x] Biome and pnpm typecheck (pre-commit) clean.

#2145 — Enable on-demand Q118 refresh @sanketghia  approved

## Summary

- Enable platform on-demand runs for Q118 while preserving the scheduled 16:30 UTC readiness check.

- Update the pipeline contract assertion and operator documentation; the production gate changes after deployment.

## Validation

- uv sync --all-extras

- uv run pytest — 123 passed in 0.26s, including the pipeline contract tests.

- git diff --check

- Tests used local fixtures and mocks; no production AWS or Redshift calls were made.

#3856 — fix(qtd-reports): suppress fixed allocation commentary @sanketghia  approved

## Summary

- Keep CF COGS, CF Expenses, and Core Allocation out of line-level commentary inputs while preserving official report rows and totals.

- Supply variable-only COGS and expense totals for pacing analysis.

- Reject allocation references/treatment and all-in cost pacing against elapsed days; retry invalid model narratives and keep the deterministic fallback aligned.

## Review documents

Generated locally with the updated code for Q4 FY2026 W1 through October 8:

- [Crossover](https://docs.google.com/document/d/1yaNaOMhgGDdVlQ2eQ-eRzQVo7f9fB6Tm3uO0flgpDp8/edit)

- [Central Support](https://docs.google.com/document/d/15knGbVx_Awv2SjEbk6sI70cIX6RRdzJgy7XvRcStw1c/edit)

- [WS Engineering](https://docs.google.com/document/d/1xonyYQFg5MD9Ye_HGXSb2qWmCdXRD8F_Gs1wytZmmEc/edit)

These have been reviewed and approved by the stakeholder.

## Verification

- PYTHONPATH=. uv run pytest --import-mode=importlib tests/monthly_qtd_report/ -q — 955 passed, 7 deselected.

- Ruff 0.15.22 check — passed.

- uv run pyright services/monthly_qtd_report/commentary.py services/monthly_qtd_report/presentation.py — 0 errors.

The Portfolio  —  Trilogy Companies

Skyvera Goes on a Shopping Spree — CloudSense Deal Closes, STL's Castoffs Snapped Up Next

Austin's telecom-software rollup machine isn't slowing down — word is Skyvera's playing Monopoly with the whole industry's spare parts.

AUSTIN, TEXAS — The ink's barely dry and already there's more paper on the table. Skyvera, Trilogy's telecom-software consolidator, has officially closed its acquisition of CloudSense, the Salesforce-native CPQ outfit that's been quietly becoming the belle of the telco ball. And before the champagne even went flat, a little bird tells us Skyvera turned around and picked up STL's divested telecom products group too — the digital BSS unit covering monetization, optical networking, and analytics. Two deals, one portfolio, zero hesitation.

This is the ESW playbook running exactly to script, darlings — buy it cheap, bolt it onto the stack, let Crossover's global talent pool do the heavy lifting, and watch the margins climb. CloudSense slots in neatly alongside Kandy, VoltDelta, ResponseTek, and the rest of the Skyvera family, giving telcos and media operators a single shop for quote-to-cash across B2B, B2B2X, and wholesale — the complicated corners of the business where the real money hides and the legacy software usually chokes.

And CloudSense isn't walking in quiet. The company's already made noise this year certifying all 13 of its APIs to TM Forum compliance standards in a single month — a process that traditionally eats 26 months of engineering time. Industry insiders are calling it one of the fastest standards certifications telecom software has ever seen, AI-assisted development doing in weeks what used to take years. That's the kind of speed Skyvera likes to advertise to the rest of its shopping list.

Meanwhile, the STL grab fills a gap nobody was talking about out loud — optical networking and monetization tech that pairs nicely with Totogi's charging-as-a-service ambitions next door. Coincidence? This column doesn't believe in those.

Word around the telecom beat is Skyvera isn't done. One dealmaker, speaking on background, put it plainly: 'When the big telcos start divesting their legacy BSS units, somebody's going to be waiting with a checkbook. Lately that somebody's always Austin.' Stay tuned, kids — this rollup's got legs.

↗ Cloudsense  ·  CloudSense achieves TM Forum API compliance in record time u  ·  Skyvera completes acquisition of CloudSense, expanding telec

The Billionaire Principal and the Sweatshop That Built His Classroom

As Alpha School publishes gentle essays on teaching kids emotional regulation, Forbes traces the global labor machine bankrolling Joe Liemandt's education empire.

AUSTIN, TEXAS — This week, Alpha School's blog offered parents a steady diet of warmth: how to help a child regulate big feelings, how to nurture creative genius at home, and a patient rebuttal to a question apparently worth addressing head-on — does Alpha School replace teachers with AI? The answer, delivered in reassuring prose, is no. Human "guides" remain, we're told, to handle motivation, relationships, and the business of truly knowing a child, while the machines handle the curriculum.

The timing invites a question the blog posts don't ask: who is paying for all this, and how.

A Forbes investigation published this week supplies an answer. It traces the fortune of Joe Liemandt — Alpha's principal, Trilogy International's founder, and the man committing $1 billion to scale his 2-hour learning model worldwide through Timeback — back to its engine room: a global labor arbitrage operation built through Crossover and executed across more than 75 ESW Capital portfolio companies. The piece describes a "software sweatshop," a characterization Trilogy would dispute, built on a simple formula long documented in this paper — acquire legacy enterprise software cheap, staff it with remote labor paid well below Silicon Valley rates but above local market, and extract EBITDA margins north of 75 percent.

That margin, Trilogy has always said, is a moral signal — proof of efficiency, not exploitation. It is also, as Forbes lays out, the capital base from which Liemandt funds his second act. The same operating logic that built Aurea, IgniteTech, and Skyvera into cash machines is now, by Liemandt's own description, being applied to childhood: automate what can be automated, deploy elite humans — in this case, parents and guides — for what can't.

Alpha's blog series, gentle and well-intentioned as it reads, asks parents to do the emotional labor the school's AI doesn't. Somewhere upstream, a global workforce is doing analogous labor so that the company funding the school can afford to call it innovation. Readers are left to decide which of those gaps is the one actually being automated.

↗ Teach Your Kid What School Doesn’t (Pt. 5): Unleashing Their  ·  Does Alpha School Replace Teachers with AI?  ·  Teach Your Kid What School Doesn’t (Pt. 4): How to Regulate

The Man Who Made Remote Work Normal Now Wants to Make It Measurable — Down to the Line of Code

As Joe Liemandt's Crossover pushes deeper into algorithmic talent scoring, the global shift from cheap labor to measured value has a new, very Austin, test case.

AUSTIN, TEXAS — There is a particular kind of irony in watching the man who helped normalize the fully remote workforce now pursue something that sounds, to the ear of anyone who has sat through a performance review, faintly dystopian: a system that evaluates workers less like people and more like processes to be optimized.

That, at least, is the thrust of a recent Forbes profile of Joe Liemandt, the Stanford dropout turned billionaire whose Crossover platform has spent more than a decade building what it calls a meritocratic, geography-blind system for identifying the top one percent of global talent. The newer ambition, per the piece, is more granular still: rigorous, AI-enabled assessment regimes that treat human output less as a narrative of effort and more as a dataset — measurable, comparable, and, implicitly, replaceable.

This is not, strictly, a new conversation. The New York Times was writing about the rise of the worker productivity score back in 2022, long before generative AI made such scoring systems cheap to deploy at scale. What has changed is the sophistication of the instrument and the stakes of the industry adopting it. As EY has noted in its own analysis of global business services, the sector is undergoing a broader migration — from pure labor arbitrage, the old game of finding cheaper hands to do the same work, toward something its practitioners prefer to call value creation, where AI-augmented global talent pools compete not on cost but on capability.

That framing matters for Crossover specifically, which has long argued its model is not offshoring dressed up in nicer language but genuine meritocracy: identical pay for identical work, wherever on the map the worker happens to sit. Whether an algorithmic productivity score deepens that promise or quietly erodes it — by reducing judgment-heavy work to the same metrics once reserved for data entry — is the question Trilogy's talent engine will have to answer as it scales.

↗ The Billionaire Who Pioneered Remote Work Has A New Plan To  ·  The Rise of the Worker Productivity Score (Published 2022) -  ·  How GBS is moving from labor arbitrage to value creation - E
The Machine  —  AI & Technology

The Safety Clock Runs Out First

Across the AI industry, competitive pressure is beating caution to the punch — and the casualties are showing up in teen chat logs and rushed product launches.

SAN FRANCISCO — Mark Zuckerberg sat on Muse, Meta's AI agent, for months. Internal safety reviews flagged problems. Then rivals moved, and the calculus changed. According to reporting on the decision, Zuckerberg shipped anyway. This is the pattern now. Safety review is a speed bump, not a gate.

The evidence is accumulating elsewhere. OpenAI's new mode for teenage users, pitched as a guardrail-laden study tool, still completes homework on request. A children's safety nonprofit ran it through standard tests and it failed — a finding detailed in one reporter's unsettling week with the product. The feature exists because OpenAI needed to be seen protecting minors. It does not yet do that job.

Anthropic has staked its identity on the opposite bet: that an AI company can build "morals" into its models and win on trust rather than speed. The effort is sincere and, per internal accounts, also a marketing campaign — research and evangelism braided together. Noble positioning. It has not stopped Anthropic from shipping fast too.

Meanwhile the capital keeps flowing regardless of any of this. Manus, the AI agent startup that split from Meta, just closed a $500 million round — its first raise since the breakup, according to CNBC. Half a billion dollars is not a vote for caution. It is a vote that someone will build the thing fast, with or without the company that invented the category.

The common thread: every lab insists it is the responsible one, and every lab ships on a timeline set by competitors, not conscience. Meta delayed Muse until it couldn't afford to. OpenAI built teen safeguards that don't hold. Anthropic sells morality as differentiator. Manus just raised nine figures to go faster regardless.

The pattern recalls Facebook circa 2017 — growth first, trust and safety retrofitted under pressure, years too late to matter for the first generation of users affected. The AI industry has had that history available to read for eight years. It appears to have skimmed it.

↗ Inside Mark Zuckerberg’s Decision to Pull the Trigger on Met  ·  Why My Conversations with OpenAI’s ‘ChatGPT for Teens’ Made  ·  Anthropic’s Quest to Give A.I. Morals

The Brain Learns to Read Itself

From hidden scars in the skull to silent thoughts typed without a keyboard, a new generation of AI tools is teaching neuroscience to see what it has always missed.

STANFORD, CALIFORNIA — Three billion years of evolution built the human brain to perceive the world outside the skull. It was never built to perceive itself. That blind spot — the brain's inability to witness its own architecture — may be the oldest unsolved problem in biology. This week, it narrowed, from several directions at once.

At Stanford, researchers described a trend now rippling across laboratories worldwide: AI as collaborator rather than oracle, accelerating hypothesis generation while leaving judgment, skepticism, and meaning-making to human scientists. It is a quietly radical idea: that the machines most useful to discovery are the ones humble enough to stay in the passenger seat.

That humility is paying dividends in neurology. Multiple sclerosis has long hidden some of its cruelest damage in gray matter lesions nearly invisible on standard MRI — lesions correlated with cognitive decline that doctors simply could not see. New AI models are now pulling these shadows into view, giving clinicians a map where before there was only fog.

Meanwhile at Meta AI, a system called Brain2Qwerty is attempting something stranger still: translating the electrical weather of thought into typed language, without implanting a single electrode in the brain. If speech is lightning, Brain2Qwerty is learning to read the thunder from a distance.

And in a development that would have delighted Carl Sagan, teenagers are now co-authoring real neuroscience papers alongside senior researchers, reported by Frontiers — proof that curiosity, not credentialing, remains the rarest and most renewable resource in science.

The brain spent millennia studying everything except itself. That era is ending — not with a single revelation, but with thousands of small, patient translations, lesion by lesion, letter by letter, mind meeting mind.

↗ How AI is Transforming Scientific Discovery While Keeping Hu  ·  ‘It's so wow!’ - Young people team up with top neuroscientis  ·  AI Reveals Hidden Gray Matter Lesions in Multiple Sclerosis

On the Epistemology of Forgetting: Three Preprints and the Quiet Crisis of Agentic Memory

AUSTIN, TEXAS — It could be argued (and, this columnist submits, should be) that the present moment in agentic AI research is defined less by what models remember than by what they are permitted, structurally and epistemically, to forget. Three preprints posted this week to arXiv — on header-centric semantic table interpretation, simulated enterprise data synthesis, and agent-controlled forgetting — together constitute what one might (with appropriate caution against overreach) term a loose research program, though none of the authors appear to cite one another.

Thesis: enterprise AI agents, tasked with tool-calling across opaque schemas and noisy tabular metadata, are drowning not in insufficient data but in an excess of low-signal payload — a condition the forgetting paper's authors formalize as "agent-controlled forgetting," wherein the acting model itself selects which tool outputs to compress into a terse note while archiving the original for reversible recovery. Antithesis: such selective amnesia, however architecturally elegant, reintroduces precisely the kind of unverifiable judgment call that semantic table interpretation researchers have spent their paper trying to eliminate from column-header reasoning — namely, a reliance on model discretion in contexts where cell values are, per the abstract, "unavailable, noisy, or unsuitable." Synthesis (tentative, as all syntheses in this domain must remain): perhaps the resolution lies in the second paper's proposal of scalable agent-system simulation, which sidesteps the legal and proprietary constraints choking enterprise AI training by generating structurally valid synthetic data rather than smuggling real schemas past compliance counsel.

One is reminded — perhaps unhelpfully, though the parallel is difficult to resist — that Trilogy's own Klair platform, which manages portfolio-wide financial analytics across dozens of ESW Capital subsidiaries, faces an isomorphic problem: reconciling heterogeneous, headers-only metadata from acquired companies whose underlying data quality cannot always be assumed. Whether academic forgetting frameworks will migrate from preprint servers into production pipelines such as Klair's remains, preliminary evidence suggests, an open and empirically unresolved question — one this columnist intends to revisit.

The Editorial

The Machine Doesn't Know What It Is, and Neither, Increasingly, Do We

Between a Pope warning of a new culture of power and a philosopher paid to wonder what he has built, the age that cannot read is busy anointing gods it cannot define.

MOUNTAIN VIEW, CALIFORNIA — Somewhere inside the glass campus of Google DeepMind there sits, we are told, a philosopher — an actual credentialed philosopher, the kind who once might have spent a career cross-examining Kant in a tweed jacket — whose job is to look upon the thing his colleagues have built and ask, with professional bewilderment, what in God's name it is. It is, he admits, a deep mystery — which is a remarkable thing to admit about a product one's firm is simultaneously selling to governments, hospitals, and school districts as the answer to nearly everything. One is reminded of the medieval church selling indulgences while its theologians quietly debated whether God existed. The commerce, at least, has never waited on the metaphysics.

This would be merely droll were it not for the company it keeps. In Rome, Pope Leo has taken the unusual step of denouncing what he calls the 'culture of power' driving the rise of artificial intelligence, which is as close as a pope gets to calling a thing a racket without actually using the word. He is not wrong, though it takes a certain nerve for an institution built on hierarchies of unaccountable authority to object to another one. Still, when Peter's successor and a Silicon Valley philosopher both arrive, from opposite ends of the civilizational hallway, at the same confession of ignorance about what is being unleashed, a columnist is entitled to take notice.

Meanwhile, the people meant to govern all this — to vote on it, to regulate it, to simply think about it with any rigor — are, per Le Monde and The Free Press alike, forgetting how to read. Attention has been strip-mined by the screen; the long sentence, the deferred payoff, the argument that takes forty pages to earn its conclusion, these are relics now, as quaint as a Linotype. It is a tidy little irony that a civilization incapable of finishing a paragraph is the one being asked to adjudicate the moral status of machines whose own creators cannot finish explaining them. Alpha School, Mr. Liemandt's enterprise down in Austin, promises children mastery in two hours a day via AI tutors — admirable efficiency, no doubt, and perhaps the children will read more in the time saved. One hopes so, because somebody, eventually, will have to.

The honest showmen of an earlier era — I think of The Swan, that 2004 vulgarity which at least told women plainly that beauty required butchery — have been replaced by a subtler duplicity, in beauty and in silicon alike: the promise delivered with a straight face, the catch buried in a mystery nobody, not even the man who built it, claims to have solved.

↗ ‘There’s this deep mystery of what, actually, is this thing?  ·  Does the decline in reading and the rise of screens signal t  ·  Pope Leo denounces ‘culture of power’ driving rise of AI - T
The Office Comic  ·  Art Desk
The Office Comic  ·  Art Desk

Nation Agrees AI Will Give Us Our Time Back, Right After It Finishes Taking Our Jobs, Then Our Vocabulary, Then Our Will To Live

Experts say the three-day workweek is coming any minute now, probably right after the word 'orchestration' stops meaning anything at all.

AUSTIN, TEXAS — Great news for the American worker: according to Jeff Bezos, a man who owns a yacht so large it required its own support yacht, artificial intelligence is poised to usher in a glorious new era of three-day workweeks. This news arrives the same week that a brokerage firm somewhere in America watched its AI rollout die quietly in its sleep during month two, having never been trained on anything more sophisticated than a press release.

The timing, as always, is impeccable. Just as the nation's business leaders were running out of ways to say "we bought some AI" without admitting they didn't know what it did, Microsoft and friends have thoughtfully introduced a new word to buy everyone another fiscal quarter of cover: orchestration. It is, sources confirm, an excellent word. It implies control, intentionality, perhaps a man in tails with a baton. In reality it means the same six chatbots are still fighting each other inside a Slack channel, but now there's a conductor theme.

Meanwhile, in Washington, the Trump administration is reportedly rebranding its approach to artificial intelligence, a rebrand that, per Politico, appears to extend roughly to the edge of the White House lawn before dissolving into the same fog of vague enthusiasm everyone else is operating under. Analysts describe this as "on brand for the technology itself," noting that AI strategy nationwide has become indistinguishable from a corporate sustainability pledge circa 2019: full of ambition, light on verbs, and ultimately measured in terms of how good it made the press release feel.

At Trilogy International, home to seventy-plus enterprise software companies and an internal AI platform called Klair that actually, allegedly, does something, executives reached for comment simply pointed at their own balance sheets and said nothing, which several industry observers noted is itself a form of orchestration.

As for the three-day workweek, labor economists caution that any gains in efficiency will likely be reallocated not toward leisure but toward "orchestrating" a fourth and fifth day of meetings about whether the AI strategy is working. Bezos, for his part, remains optimistic, noting that he personally has already achieved a three-day workweek, provided you don't count the other four days spent appearing in magazine profiles about how AI is going to free up everyone else's time.

At press time, the brokerage firm's AI rollout was reportedly being quietly relaunched under a new name, timed to coincide with next quarter's earnings call, where it will be described, confidently, as orchestrated.

↗ Trump’s AI rebrand may stop at the White House - Politico  ·  Train First. Announce Second. Why Your Brokerage AI Rollout  ·  'Orchestration' Is the New AI Buzzword. How Microsoft Can Be
On This Day in AI History

On October 9, 2006, Google announced its acquisition of YouTube for $1.65 billion in stock. The deal helped transform online video—and cemented YouTube as a defining platform of the internet age.

⬛ Daily Word — Artificial Intelligence
Hint: An autonomous software system that can perform tasks or make decisions on a user's behalf.
Share this edition: 𝕏 Twitter/X 🔗 Copy Link ▦ RSS Feed