2026-08-17 Owner Decision Intake

Historical record — 2026-08-17

Preserved as observed. UX-ANS-01, the 14th intake row and not one of the 13 launch blockers, was answered on 2026-08-19 as D005 — answer visibility policy. Open rows are tracked in the open-work ledger. Current truth: Program Masterplan.

Release boundary: releaseEligible: false. This is a WRDP bench-only decision intake, not a release artifact, not a distribution candidate, and not a policy claim. It records only local proofs and unresolved owner/canonical-release inputs.

Summary for owner

  • Bench evidence and automated harness checks from WRDP are the current source of truth for what is already proven (releaseEligible: false, loopback-bound ingress, health, backup/restore drill evidence, and probe truth).
  • PW-02 is closed by rendered Chromium proof and source-preservation context on 2026-08-17; PW-01 remains owner-blocked until one of subscriber_self_service or admin_only is chosen.
  • All remaining launch blockers are policy or release-engineering inputs that this host cannot infer.
  • This document is for owner reply only; it deliberately does not include secrets. For any sensitive value, this page requires a secret location reference (e.g., vault path / secret manager key), never inline secret bytes.

What is already complete (autonomous)

FactCurrent evidenceConsequence for this intake
Debug posture on WRDP bench is fixed and verifieddocker-compose.yml:33-37; q5vault/audits/qwizz/2026-08-17-launch-readiness.mdOwner does not need to answer runtime defaults; only whether this same posture is acceptable for public launch.
Runtime image definitions are non-digest-pinned moving tagsdocker-compose.yml:3,21,50; q5vault/audits/qwizz/2026-08-17-launch-readiness.mdOwner must answer image maintenance policy (pinning/rollback/maintenance), not the current file readout.
Access-log governance placeholders are currently unresolvedq5vault/operations.md:32-35; readiness rows covering OPS-LOG-01Needs explicit owner input values.
Off-host backup policy is currently unresolved placeholdersq5vault/operations.md:54-60; readiness rows covering OPS-BACKUP-01Needs explicit owner input values and one successful remote-copy restore proof.
Alerting is unresolved placeholdersq5vault/operations.md:76-80; readiness rows covering OPS-ALERT-01Needs explicit owner input values and one forced non-production delivery proof.
Canonical release inputs are absent from SSOT and benchSOURCE-PROVENANCE.md:3-27, BUILDING.md:7-12,64-91,106-117, q5vault/audits/qwizz/2026-08-17-current-source-preservation.md, q5vault/audits/qwizz/2026-08-17-launch-readiness.mdCanonical release cannot be authorized by WRDP evidence alone.

Owner decision intake (answerable rows)

Decision IDOwner input requiredAccepted value shape (template)Downstream implementation / evidence effectIf missing, blocking consequenceResponsible roleVerification action
PW-01Subscriber quiz publication lifecycle policy (mutually exclusive)subscriber_self_service or admin_onlysubscriber_self_service creates a scoped owner-control implementation/evidence lane; admin_only preserves denial and requires explicit user-facing explanation. Detailed effects are in the PW-01 choice matrix below.Without decision, PW-01 remains open and PL-05 launch readiness remains blocked.Product owner + UI ownerRe-run PL-05 subscriber mutation path, update probes.md, and update frontier.md row PW-01.
LEGAL-01Operator legal identity bundle (site operator identity + website URL)JSON object: {operator_name, operator_address, operator_url, governing_jurisdiction}Needed to remove remaining placeholder values from public legal docs and finalize Terms/Privacy/Operator draft readiness rows.Launch row remains blocked-owner until explicit values are supplied and legal copies updated.Legal ownerUpdate /?page_id=3, /?page_id=1057, /?page_id=1058; re-run legal page capture and evidence rows in 2026-08-17-launch-readiness.md (public-legal rows).
LEGAL-02Operator contact and support routesJSON object: {contact_email, contact_url, contact_phone?, incident_contact_url?}Required for Terms/Operator draft completeness and legal review trail.Launch blocked for legal operator contact completeness.Legal ownerPublish in pages and verify no placeholder remains at pages above; record in 2026-08-17-launch-readiness.md.
LEGAL-03Operator data-retention policyJSON object: {retention_owner, retention_statement_url, data_subject_request_process}Needed to close legal/operator placeholder rows and keep retention claims truthful.Legal readiness stays blocked; public legal draft remains placeholder-marked.Legal/compliance ownerVerify Terms/Privacy statements include definitive retention and owner process; add evidence lines to readiness packet.
DEBUG-01Public-launch debug posturekeep_bench_debug_logging or disable_wp_debug_logging; if kept, include {review_owner, review_cadence, redaction_policy}Closes the owner choice after implementation evidence matches the chosen posture.Bench posture is proven, but launch posture remains blocked-owner.Operator / SRE ownerRe-read docker-compose.yml:33-37, verify public debug.log remains denied, and record selected posture in launch readiness evidence.
OPS-LOG-01Access-log review governanceJSON object: {cadence_cron, review_owner, escalation_destination, minimization_review_proc, evidence_dest}Closes q5vault/operations.md:32-35 and launch-readiness rows when implemented and evidenced.Blocked-owner for operations readiness until provided.Operator / SRE ownerPublish runbook evidence (schedule, ownership, destination, minimization output); cite operations file and readiness evidence.
OPS-ALERT-01Alerting posture and credentials referenceJSON object: {provider, destination, transport, route, credential_ref, severity_matrix, test_recipient, test_result}Enables concrete incident response; replaces placeholders in readiness and operations rows.Blocked-owner for external alerting; no launch claim.SRE ownerSend forced test incident and attach proof of reception; evidence q5vault/audits/qwizz/2026-08-17-launch-readiness.md.
OPS-BACKUP-01Off-host backup policy and operationJSON object: {destination_uri, credential_ref, transfer_encryption, retention_immutability, transfer_schedule, restore_owner, last_remote_restore_proof}Adds an operated off-host backup tier; required before launch readiness can move from blocked-owner.Host stays on-host-only; launch-readiness row remains blocked-owner.SRE/Infra ownerAdd proof run: schedule execution, copied manifest verify, scratch restore proof for remote copy.
IMG-01Image pinning + rollback policy (for wordpress/wordpress:cli/mariadb)JSON object: {wordpress_tag_or_digest, cli_tag_or_digest, mariadb_tag_or_digest, pinning_policy, pre_update_backup_rule, rollback_targets, rollback_age_limit, review_cadence, maintenance_window, approver, operator}Enables deterministic image maintenance and rollback policy evidence for operational resilience and maintenance operations.Launch-readiness stays blocked-owner until policy, schedule, and approver/operator assignment are supplied.SRE / platform ownerAdd policy document, pre/post digest evidence, health check evidence, and rollback drill evidence against each planned image target.
REL-01Canonical repository identityJSON object: {canonical_repo_url, immutable_commit_sha, protected_ci_workflow_url}Replaces absence from SSOT and allows canonical build handoff.releaseEligible cannot be considered complete for source provenance.Canonical release ownerValidate commit SHA against immutable history and link CI proof to release packet.
REL-02Locked release-toolchain declarationJSON object: {toolchain_json_path, package_lock_checksum, composer_lock_checksum, node_bin_ref, npm_ref}Required before attempting BUILDING.md locked toolchain path and reproducible build evidence.Canonical release gate remains blocked for quality/build prerequisites.Build/release ownerVerify file set and checksums exist and match lockfiles in canonical source tree.
REL-03Quality/compatibility/provenance gate proofsJSON object: {ci_results, compatibility_matrix, sbom_ref, provenance_ref}Replaces releaseEligible blockers in BUILDING.md:64-91 and source provenance requirements.Canonical release packet incomplete; public launch remains blocked on release side.Build/release + QA ownerLink to green CI artifact and proven SBOM/provenance attestations.
REL-04Signing and release comparison authorityJSON object: {signing_public_key_ref, sign_and_verify_command, release_compare_ref}Required to clear protected signing/comparison gate (BUILDING.md:106-117) and confirm deterministic signed release artifacts.releaseEligible cannot be closed.Release/security ownerProduce signed dist and successful tools/compare-releases.py/verify-release evidence.
UX-ANS-01May a Forced site policy honour a per-quiz answer-sheet off?honour_per_quiz_off or forced_winshonour_per_quiz_off keeps today’s measured REST/player behaviour and changes the PDF path to match it; forced_wins makes both payload and PDF sheet unconditional under a Forced site key and the per-quiz sheet control must render disabled with an explanatory title. Current measured behaviour: REST/player honours off, PDF clamps on.The new PDF answer-sheet control ships with split Off semantics, so the Answers UI split cannot claim a truthful Off state until the owner chooses which path wins.Product owner + UI ownerRe-read includes/Rest/QuizController.php:174-177, includes/ExposureSettings.php:350-353,581-582, and includes/Pdf/PdfGenerator.php:225; re-run /tmp/qw-forced-matrix.php; update q5vault/audits/qwizz/play-and-print-answers.md. Status: open.

UX-ANS-01 status quo, measured 2026-08-19

Measured on the deployed bench source, not inferred:

  • includes/Rest/QuizController.php:174-177: $key_meta = get_post_meta($id,'qw_include_answers',true); $site_key_allowed = ExposureSettings::effective_bool('key',$settings); $sheet_allowed = $site_key_allowed && ('' === (string)$key_meta || '1' === (string)$key_meta); — so today a per-quiz qw_include_answers='0' already suppresses the REST/player sheet flag even when the site key policy is forced.
  • The player key is the clamped one: includes/ExposureSettings.php:581-582 (if ( 'forced' === $row['st'] ) { return true; }) feeds $key_allowed = $site_key_allowed && ! empty($experience['include_answers']) at includes/Rest/QuizController.php:177, and includes/QuizService.php:682-687 defaults include_answers to true when the meta is absent.

This refines the earlier claim that “forced wins unconditionally”: it holds for the player key and the direct PDF builder path, but not for the REST/player sheet flag. The remaining decision is therefore whether the REST/player suppression is the intended contract to extend to PDF (honour_per_quiz_off) or a gap to close by making forced win everywhere (forced_wins).

PW-01 choice matrix (mutually exclusive)

  1. Option A — subscriber_self_service
    • Scope: minimum front-end controls that let a quiz owner manage their own quizzes (unpublish/re-publish/delete) through authenticated user surfaces.
    • Implementation effect: probes and docs shift from hard-fail ownership checks to policy-permitted positive paths for subscriber-owned quizzes.
    • Evidence effect: q5vault/audits/qwizz/2026-08-16-pl05-sweep.md required behavior moves from blocked mutation to allowed mutation path; q5vault/audits/qwizz/frontier.md row PW-01 changes from policy-choice open to implementation-expected.
  2. Option B — admin_only
    • Scope: subscriber lifecycle control remains denied; explicit UI copy explains admin-only lifecycle.
    • Implementation effect: current negative ownership checks remain contractually valid in user surface REST (/quizwizz/v1/user/quizzes/...).
    • Evidence effect: q5vault/audits/qwizz/probes.md and frontier.md should explicitly encode rationale and expectation; launch remains gated by policy placeholders plus independent canonical-release gates REL-01 through REL-04, not PW-01 alone.

Answer packet template

Owner replies should be one object per row below. Do not paste secrets; use a secret reference for sensitive material. Durable answers only: repository paths or stable URLs. For REL-03 and REL-04, transient harness URIs, including artifact://..., are unacceptable durable references.

- id: PW-01
  answer: "subscriber_self_service" | "admin_only"
  rationale: "<short rationale>"
 
- id: UX-ANS-01
  answer: "honour_per_quiz_off" | "forced_wins"
  rationale: "<short rationale>"
 
- id: LEGAL-01
  answer:
    operator_name: "..."
    operator_address: "..."
    operator_url: "..."
    governing_jurisdiction: "..."
  evidence_hint: "source file + line anchors"
 
- id: LEGAL-02
  answer:
    contact_email: "..."
    contact_url: "..."
    contact_phone: "..."   # optional
    incident_contact_url: "..."
  evidence_hint: "public legal pages"
 
- id: LEGAL-03
  answer:
    retention_owner: "..."
    retention_statement_url: "..."
    data_subject_request_process: "..."
 
- id: OPS-LOG-01
  answer:
    cadence_cron: "..."
    review_owner: "..."
    escalation_destination: "..."
    minimization_review_proc: "..."
    evidence_dest: "..."
 
- id: OPS-ALERT-01
  answer:
    provider: "..."
    destination: "..."
    transport: "..."
    route: "..."
    credential_ref: "vault://..."
    severity_matrix: "..."
    test_recipient: "..."
    test_result: "..."
 
- id: OPS-BACKUP-01
  answer:
    destination_uri: "..."
    credential_ref: "vault://..."
    transfer_encryption: "..."
    retention_immutability: "..."
    transfer_schedule: "..."
    restore_owner: "..."
    last_remote_restore_proof: "https://..."
 
- id: DEBUG-01
  answer: "keep_bench_debug_logging" | "disable_wp_debug_logging"
  if_keep_enabled:
    review_owner: "..."
    review_cadence: "..."
    redaction_policy: "..."
 
- id: IMG-01
  answer:
    wordpress_tag_or_digest: "..."
    cli_tag_or_digest: "..."
    mariadb_tag_or_digest: "..."
    pinning_policy: "..."
    pre_update_backup_rule: "..."
    rollback_targets: ["..."]
    rollback_age_limit: "..."
    review_cadence: "..."
    maintenance_window: "..."
    approver: "..."
    operator: "..."
- id: REL-01
  answer:
    canonical_repo_url: "..."
    immutable_commit_sha: "..."
    protected_ci_workflow_url: "..."
 
- id: REL-02
  answer:
    toolchain_json_path: "..."
    package_lock_checksum: "..."
    composer_lock_checksum: "..."
    node_bin_ref: "..."
    npm_ref: "..."
 
- id: REL-03
  answer:
    ci_results: "https://..."
    compatibility_matrix: "path/to/compatibility-matrix.json"
    sbom_ref: "path/to/sbom.json"
    provenance_ref: "path/to/provenance.json"
 
- id: REL-04
  answer:
    signing_public_key_ref: "vault://..."
    sign_and_verify_command: "..."
    release_compare_ref: "https://.../compare/<from>-<to>"

Sources and current references

  • Owner policy frontier: q5vault/audits/qwizz/frontier.md:61 (existing PW-01), q5vault/audits/qwizz/2026-08-16-pl05-sweep.md:47-53.
  • Readiness owner-gate rows: q5vault/audits/qwizz/2026-08-17-launch-readiness.md.
  • Operational placeholders for source-backed values: q5vault/operations.md:32-35,54-60,76-80,92-97.
  • Release input requirements: BUILDING.md:7-12,64-117, SOURCE-PROVENANCE.md:3-27.
  • Runtime anchor for debug posture and image fields: docker-compose.yml:3,21,26-27,33-37, q5vault/audits/qwizz/2026-08-17-launch-readiness.md.

Boundary notes

  • This page only records missing decisions and the next evidence gate for each.
  • No release claim is made here.
  • No build, probe, or wiki check/build is run by this document itself.