2026-08-17 Owner Decision Intake
Historical record — 2026-08-17
Preserved as observed.
UX-ANS-01, the 14th intake row and not one of the 13 launch blockers, was answered on 2026-08-19 as D005 — answer visibility policy. Open rows are tracked in the open-work ledger. Current truth: Program Masterplan.
Release boundary:
releaseEligible: false. This is a WRDP bench-only decision intake, not a release artifact, not a distribution candidate, and not a policy claim. It records only local proofs and unresolved owner/canonical-release inputs.
Summary for owner
- Bench evidence and automated harness checks from WRDP are the current source of truth for what is already proven (
releaseEligible: false, loopback-bound ingress, health, backup/restore drill evidence, and probe truth). PW-02is closed by rendered Chromium proof and source-preservation context on 2026-08-17;PW-01remains owner-blocked until one ofsubscriber_self_serviceoradmin_onlyis chosen.- All remaining launch blockers are policy or release-engineering inputs that this host cannot infer.
- This document is for owner reply only; it deliberately does not include secrets. For any sensitive value, this page requires a secret location reference (e.g., vault path / secret manager key), never inline secret bytes.
What is already complete (autonomous)
| Fact | Current evidence | Consequence for this intake |
|---|---|---|
| Debug posture on WRDP bench is fixed and verified | docker-compose.yml:33-37; q5vault/audits/qwizz/2026-08-17-launch-readiness.md | Owner does not need to answer runtime defaults; only whether this same posture is acceptable for public launch. |
| Runtime image definitions are non-digest-pinned moving tags | docker-compose.yml:3,21,50; q5vault/audits/qwizz/2026-08-17-launch-readiness.md | Owner must answer image maintenance policy (pinning/rollback/maintenance), not the current file readout. |
| Access-log governance placeholders are currently unresolved | q5vault/operations.md:32-35; readiness rows covering OPS-LOG-01 | Needs explicit owner input values. |
| Off-host backup policy is currently unresolved placeholders | q5vault/operations.md:54-60; readiness rows covering OPS-BACKUP-01 | Needs explicit owner input values and one successful remote-copy restore proof. |
| Alerting is unresolved placeholders | q5vault/operations.md:76-80; readiness rows covering OPS-ALERT-01 | Needs explicit owner input values and one forced non-production delivery proof. |
| Canonical release inputs are absent from SSOT and bench | SOURCE-PROVENANCE.md:3-27, BUILDING.md:7-12,64-91,106-117, q5vault/audits/qwizz/2026-08-17-current-source-preservation.md, q5vault/audits/qwizz/2026-08-17-launch-readiness.md | Canonical release cannot be authorized by WRDP evidence alone. |
Owner decision intake (answerable rows)
| Decision ID | Owner input required | Accepted value shape (template) | Downstream implementation / evidence effect | If missing, blocking consequence | Responsible role | Verification action |
|---|---|---|---|---|---|---|
| PW-01 | Subscriber quiz publication lifecycle policy (mutually exclusive) | subscriber_self_service or admin_only | subscriber_self_service creates a scoped owner-control implementation/evidence lane; admin_only preserves denial and requires explicit user-facing explanation. Detailed effects are in the PW-01 choice matrix below. | Without decision, PW-01 remains open and PL-05 launch readiness remains blocked. | Product owner + UI owner | Re-run PL-05 subscriber mutation path, update probes.md, and update frontier.md row PW-01. |
| LEGAL-01 | Operator legal identity bundle (site operator identity + website URL) | JSON object: {operator_name, operator_address, operator_url, governing_jurisdiction} | Needed to remove remaining placeholder values from public legal docs and finalize Terms/Privacy/Operator draft readiness rows. | Launch row remains blocked-owner until explicit values are supplied and legal copies updated. | Legal owner | Update /?page_id=3, /?page_id=1057, /?page_id=1058; re-run legal page capture and evidence rows in 2026-08-17-launch-readiness.md (public-legal rows). |
| LEGAL-02 | Operator contact and support routes | JSON object: {contact_email, contact_url, contact_phone?, incident_contact_url?} | Required for Terms/Operator draft completeness and legal review trail. | Launch blocked for legal operator contact completeness. | Legal owner | Publish in pages and verify no placeholder remains at pages above; record in 2026-08-17-launch-readiness.md. |
| LEGAL-03 | Operator data-retention policy | JSON object: {retention_owner, retention_statement_url, data_subject_request_process} | Needed to close legal/operator placeholder rows and keep retention claims truthful. | Legal readiness stays blocked; public legal draft remains placeholder-marked. | Legal/compliance owner | Verify Terms/Privacy statements include definitive retention and owner process; add evidence lines to readiness packet. |
| DEBUG-01 | Public-launch debug posture | keep_bench_debug_logging or disable_wp_debug_logging; if kept, include {review_owner, review_cadence, redaction_policy} | Closes the owner choice after implementation evidence matches the chosen posture. | Bench posture is proven, but launch posture remains blocked-owner. | Operator / SRE owner | Re-read docker-compose.yml:33-37, verify public debug.log remains denied, and record selected posture in launch readiness evidence. |
| OPS-LOG-01 | Access-log review governance | JSON object: {cadence_cron, review_owner, escalation_destination, minimization_review_proc, evidence_dest} | Closes q5vault/operations.md:32-35 and launch-readiness rows when implemented and evidenced. | Blocked-owner for operations readiness until provided. | Operator / SRE owner | Publish runbook evidence (schedule, ownership, destination, minimization output); cite operations file and readiness evidence. |
| OPS-ALERT-01 | Alerting posture and credentials reference | JSON object: {provider, destination, transport, route, credential_ref, severity_matrix, test_recipient, test_result} | Enables concrete incident response; replaces placeholders in readiness and operations rows. | Blocked-owner for external alerting; no launch claim. | SRE owner | Send forced test incident and attach proof of reception; evidence q5vault/audits/qwizz/2026-08-17-launch-readiness.md. |
| OPS-BACKUP-01 | Off-host backup policy and operation | JSON object: {destination_uri, credential_ref, transfer_encryption, retention_immutability, transfer_schedule, restore_owner, last_remote_restore_proof} | Adds an operated off-host backup tier; required before launch readiness can move from blocked-owner. | Host stays on-host-only; launch-readiness row remains blocked-owner. | SRE/Infra owner | Add proof run: schedule execution, copied manifest verify, scratch restore proof for remote copy. |
| IMG-01 | Image pinning + rollback policy (for wordpress/wordpress:cli/mariadb) | JSON object: {wordpress_tag_or_digest, cli_tag_or_digest, mariadb_tag_or_digest, pinning_policy, pre_update_backup_rule, rollback_targets, rollback_age_limit, review_cadence, maintenance_window, approver, operator} | Enables deterministic image maintenance and rollback policy evidence for operational resilience and maintenance operations. | Launch-readiness stays blocked-owner until policy, schedule, and approver/operator assignment are supplied. | SRE / platform owner | Add policy document, pre/post digest evidence, health check evidence, and rollback drill evidence against each planned image target. |
| REL-01 | Canonical repository identity | JSON object: {canonical_repo_url, immutable_commit_sha, protected_ci_workflow_url} | Replaces absence from SSOT and allows canonical build handoff. | releaseEligible cannot be considered complete for source provenance. | Canonical release owner | Validate commit SHA against immutable history and link CI proof to release packet. |
| REL-02 | Locked release-toolchain declaration | JSON object: {toolchain_json_path, package_lock_checksum, composer_lock_checksum, node_bin_ref, npm_ref} | Required before attempting BUILDING.md locked toolchain path and reproducible build evidence. | Canonical release gate remains blocked for quality/build prerequisites. | Build/release owner | Verify file set and checksums exist and match lockfiles in canonical source tree. |
| REL-03 | Quality/compatibility/provenance gate proofs | JSON object: {ci_results, compatibility_matrix, sbom_ref, provenance_ref} | Replaces releaseEligible blockers in BUILDING.md:64-91 and source provenance requirements. | Canonical release packet incomplete; public launch remains blocked on release side. | Build/release + QA owner | Link to green CI artifact and proven SBOM/provenance attestations. |
| REL-04 | Signing and release comparison authority | JSON object: {signing_public_key_ref, sign_and_verify_command, release_compare_ref} | Required to clear protected signing/comparison gate (BUILDING.md:106-117) and confirm deterministic signed release artifacts. | releaseEligible cannot be closed. | Release/security owner | Produce signed dist and successful tools/compare-releases.py/verify-release evidence. |
| UX-ANS-01 | May a Forced site policy honour a per-quiz answer-sheet off? | honour_per_quiz_off or forced_wins | honour_per_quiz_off keeps today’s measured REST/player behaviour and changes the PDF path to match it; forced_wins makes both payload and PDF sheet unconditional under a Forced site key and the per-quiz sheet control must render disabled with an explanatory title. Current measured behaviour: REST/player honours off, PDF clamps on. | The new PDF answer-sheet control ships with split Off semantics, so the Answers UI split cannot claim a truthful Off state until the owner chooses which path wins. | Product owner + UI owner | Re-read includes/Rest/QuizController.php:174-177, includes/ExposureSettings.php:350-353,581-582, and includes/Pdf/PdfGenerator.php:225; re-run /tmp/qw-forced-matrix.php; update q5vault/audits/qwizz/play-and-print-answers.md. Status: open. |
UX-ANS-01 status quo, measured 2026-08-19
Measured on the deployed bench source, not inferred:
includes/Rest/QuizController.php:174-177:$key_meta = get_post_meta($id,'qw_include_answers',true); $site_key_allowed = ExposureSettings::effective_bool('key',$settings); $sheet_allowed = $site_key_allowed && ('' === (string)$key_meta || '1' === (string)$key_meta);— so today a per-quizqw_include_answers='0'already suppresses the REST/player sheet flag even when the site key policy isforced.- The player key is the clamped one:
includes/ExposureSettings.php:581-582(if ( 'forced' === $row['st'] ) { return true; }) feeds$key_allowed = $site_key_allowed && ! empty($experience['include_answers'])atincludes/Rest/QuizController.php:177, andincludes/QuizService.php:682-687defaultsinclude_answerstotruewhen the meta is absent.
This refines the earlier claim that “forced wins unconditionally”: it holds for the player key and the direct PDF builder path, but not for the REST/player sheet flag. The remaining decision is therefore whether the REST/player suppression is the intended contract to extend to PDF (honour_per_quiz_off) or a gap to close by making forced win everywhere (forced_wins).
PW-01 choice matrix (mutually exclusive)
- Option A —
subscriber_self_service- Scope: minimum front-end controls that let a quiz owner manage their own quizzes (unpublish/re-publish/delete) through authenticated user surfaces.
- Implementation effect: probes and docs shift from hard-fail ownership checks to policy-permitted positive paths for subscriber-owned quizzes.
- Evidence effect:
q5vault/audits/qwizz/2026-08-16-pl05-sweep.mdrequired behavior moves from blocked mutation to allowed mutation path;q5vault/audits/qwizz/frontier.mdrowPW-01changes from policy-choice open to implementation-expected.
- Option B —
admin_only- Scope: subscriber lifecycle control remains denied; explicit UI copy explains admin-only lifecycle.
- Implementation effect: current negative ownership checks remain contractually valid in user surface REST (
/quizwizz/v1/user/quizzes/...). - Evidence effect:
q5vault/audits/qwizz/probes.mdandfrontier.mdshould explicitly encode rationale and expectation; launch remains gated by policy placeholders plus independent canonical-release gatesREL-01throughREL-04, not PW-01 alone.
Answer packet template
Owner replies should be one object per row below. Do not paste secrets; use a secret reference for sensitive material. Durable answers only: repository paths or stable URLs. For REL-03 and REL-04, transient harness URIs, including artifact://..., are unacceptable durable references.
- id: PW-01
answer: "subscriber_self_service" | "admin_only"
rationale: "<short rationale>"
- id: UX-ANS-01
answer: "honour_per_quiz_off" | "forced_wins"
rationale: "<short rationale>"
- id: LEGAL-01
answer:
operator_name: "..."
operator_address: "..."
operator_url: "..."
governing_jurisdiction: "..."
evidence_hint: "source file + line anchors"
- id: LEGAL-02
answer:
contact_email: "..."
contact_url: "..."
contact_phone: "..." # optional
incident_contact_url: "..."
evidence_hint: "public legal pages"
- id: LEGAL-03
answer:
retention_owner: "..."
retention_statement_url: "..."
data_subject_request_process: "..."
- id: OPS-LOG-01
answer:
cadence_cron: "..."
review_owner: "..."
escalation_destination: "..."
minimization_review_proc: "..."
evidence_dest: "..."
- id: OPS-ALERT-01
answer:
provider: "..."
destination: "..."
transport: "..."
route: "..."
credential_ref: "vault://..."
severity_matrix: "..."
test_recipient: "..."
test_result: "..."
- id: OPS-BACKUP-01
answer:
destination_uri: "..."
credential_ref: "vault://..."
transfer_encryption: "..."
retention_immutability: "..."
transfer_schedule: "..."
restore_owner: "..."
last_remote_restore_proof: "https://..."
- id: DEBUG-01
answer: "keep_bench_debug_logging" | "disable_wp_debug_logging"
if_keep_enabled:
review_owner: "..."
review_cadence: "..."
redaction_policy: "..."
- id: IMG-01
answer:
wordpress_tag_or_digest: "..."
cli_tag_or_digest: "..."
mariadb_tag_or_digest: "..."
pinning_policy: "..."
pre_update_backup_rule: "..."
rollback_targets: ["..."]
rollback_age_limit: "..."
review_cadence: "..."
maintenance_window: "..."
approver: "..."
operator: "..."
- id: REL-01
answer:
canonical_repo_url: "..."
immutable_commit_sha: "..."
protected_ci_workflow_url: "..."
- id: REL-02
answer:
toolchain_json_path: "..."
package_lock_checksum: "..."
composer_lock_checksum: "..."
node_bin_ref: "..."
npm_ref: "..."
- id: REL-03
answer:
ci_results: "https://..."
compatibility_matrix: "path/to/compatibility-matrix.json"
sbom_ref: "path/to/sbom.json"
provenance_ref: "path/to/provenance.json"
- id: REL-04
answer:
signing_public_key_ref: "vault://..."
sign_and_verify_command: "..."
release_compare_ref: "https://.../compare/<from>-<to>"Sources and current references
- Owner policy frontier:
q5vault/audits/qwizz/frontier.md:61(existingPW-01),q5vault/audits/qwizz/2026-08-16-pl05-sweep.md:47-53. - Readiness owner-gate rows:
q5vault/audits/qwizz/2026-08-17-launch-readiness.md. - Operational placeholders for source-backed values:
q5vault/operations.md:32-35,54-60,76-80,92-97. - Release input requirements:
BUILDING.md:7-12,64-117,SOURCE-PROVENANCE.md:3-27. - Runtime anchor for debug posture and image fields:
docker-compose.yml:3,21,26-27,33-37,q5vault/audits/qwizz/2026-08-17-launch-readiness.md.
Boundary notes
- This page only records missing decisions and the next evidence gate for each.
- No release claim is made here.
- No build, probe, or wiki check/build is run by this document itself.