Commit Graph
18 Commits
Author SHA1 Message Date
arcodangeandClaude Opus 5 38d2693c09 docs(erp): transmettre le choix de l'instrument aux agents suivants
L'erreur rattrapée par l'opérateur — ouvrir une fiche fournisseur au nom du
gérant — n'était pas un défaut d'exécution mais un choix d'instrument. Rien
dans le dépôt ne l'empêchait de se reproduire.

RUNBOOK_quel_instrument.md pose la question qui tranche — à qui la société
doit-elle cet argent ? — et sa table de décision : fournisseur réel → facture
fournisseur ; organisme social ou fiscal → charge ; l'associé lui-même →
paiement divers sur CCA1, sans aucun tiers. Il distingue les deux usages du
compte courant, que l'on confond facilement : le gérant AVANCE une dépense
(adc-005, le tiers est le fournisseur) contre la société DOIT au gérant
(adc-010, aucun tiers).

adc-010 enregistre la décision et sa base : le compte 455 porte les sommes dues
à l'associé, le poste fournisseurs les dettes d'exploitation envers des tiers
ayant fourni biens ou services. Le gérant qui met une pièce à disposition n'y
entre pas — même raisonnement qu'adc-008 et le runbook charges sociales
opposent déjà à l'URSSAF.

AGENTS.md porte désormais la règle dans les operating rules, avec la leçon
généralisable : une écriture dont le modèle contredit celles déjà au grand
livre est presque toujours fausse, et la vérification coûte une requête. La
règle dit aussi que le choix décide de la voie technique — ni les charges
sociales ni les paiements divers n'ayant d'API REST, le promote gated ne peut
pas les porter.

Le calendrier porte la décision de l'opérateur du 13/08 : pas de rémunération
de gérance en 2026, arbitrage reporté à 2027, avec ses conséquences — aucun
trimestre de retraite validé, et une régularisation URSSAF probablement à la
baisse puisque l'assiette réelle sera quasi nulle.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-13 21:08:08 +02:00
arcodangeandClaude Opus 5 67a74924e9 feat(erp): indemnité d'occupation janv→juil 2026 — paiements divers, sans tiers
Appliqué en production : 7 écritures, 1 483,23 EUR, compte courant d'associé
porté de -429,75 à -1 912,98. Grand livre auxiliaire intact — 12 tiers, 15
factures fournisseur, inchangés.

La première approche créait un tiers fournisseur « Radureau Gabriel » et lui
adressait 7 factures. C'était faux : le gérant n'est pas un fournisseur de sa
société, et lui ouvrir une fiche l'aurait fait apparaître au grand livre
auxiliaire, dans les balances âgées et les états de dettes fournisseurs —
l'objection exacte déjà opposée à l'URSSAF dans RUNBOOK_charges_sociales.md,
que j'ai reproduite en la contredisant. L'existant le disait pourtant : les 8
dettes déjà portées au compte courant sont toutes des factures de fournisseurs
RÉELS payées personnellement, le tiers n'étant jamais le gérant.

Le modèle correct est direct. Le compte bancaire CCA1 (id 3) porte le numéro
comptable 45511 et son propre journal ; un paiement divers en sens débit, code
613000 Locations, produit

    débit  613000  Locations                     (la charge)
    crédit 45511   G. RADUREAU, compte courant   (la dette envers l'associé)

Correction au passage : le plan comptable EST chargé (358 comptes, dont un
455110 dédié au compte courant du gérant). adc-009 affirme « module comptabilité
pas déployé » en confondant trois choses — le plan chargé, l'API REST absente,
et le dictionnaire des types de charges sans code comptable.

Deux bugs de ma main, trouvés en répétition :

- l'idempotence comparait les 24 PREMIERS CARACTÈRES du libellé, or
  « Indemnité d'occupation — » en fait exactement 24 : mars reconnaissait
  février et se déclarait déjà enregistré. Six mois silencieusement sautés.
  On compare désormais le libellé entier, avec tolérance à la troncature
  « … » de Dolibarr. recordSocialCharge.ts porte le même défaut, latent :
  ses libellés diffèrent avant le 24e caractère, aujourd'hui seulement.
- une boucle shell utilisait `set -- $m`, qui ne découpe pas les mots en zsh :
  la date devenait « 2026-- ». Le script a correctement refusé d'écrire.

/variouspayments répond « API not found » : le pipeline gated, qui parle REST,
ne peut pas porter cette opération — comme pour les charges sociales. Le script
en garde la discipline (répétition sandbox, relecture par la liste, opt-in
production explicite) sans le juge ni l'artefact de gate.

Le run gated abandonné est conservé sous fleet/harness/runs/ avec ABANDONNE.md :
il documente ce que le harness a vu, et surtout ce qu'il n'a pas vu.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-13 21:04:55 +02:00
arcodangeandClaude Opus 5 d4c8d0d68d feat(erp): indemnité d'occupation janv→juil 2026 — change-set gated, au gate
La convention annexée aux statuts (annexe 3) et la décision n°1 de l'associé
unique du 09/01/2026 fixent une indemnité d'occupation de 220 EUR/mois pour un
bureau de 10 m² dans le domicile du gérant. Elle n'a JAMAIS été ni versée ni
comptabilisée : aucun tiers, aucune des 15 factures fournisseur, aucune ligne au
grand livre bancaire.

Change-set : un tiers « Radureau Gabriel » (FO0012) puis 7 factures fournisseur
validées et réglées par inscription au compte courant d'associé (compte 3), sans
mouvement de trésorerie — la voie adc-005. Janvier au PRORATA : la convention
prend effet à sa signature, 23 jours sur 31 → 163,23 EUR. Total 1 483,23 EUR et
non 1 540 : un mois plein aurait été légèrement généreux.

Chaque facture porte en note le fondement complet et le calcul qui justifie le
forfait — loyer 1 100 EUR, quote-part de surface 16,67 % → 183,33, charges
réelles 12,53 au prorata, soit 195,87 de prorata strict contre 220 retenus
(+12,3 %). La justification vit ainsi avec l'écriture, pas dans une note à part.

Répétition sandbox : 8 opérations, 14 suites, toutes ok. Dates vérifiées en
Europe/Paris — lues en UTC elles semblent reculées d'un jour, Dolibarr tronquant
à minuit heure serveur. Compte courant : -429,75 → -1 912,98.

Corrige un vrai défaut du pipeline découvert en route : quand une op échoue,
{id} était remplacé par le DICTIONNAIRE D'ERREUR, l'URL devenait un JSON
multiligne, urllib levait InvalidURL et l'étape mourait AVANT d'écrire son
artefact — on perdait la preuve de l'échec qu'on venait de produire. Corrigé
dans rehearse et dans apply, où --keep-going exposait la même faille en pleine
écriture de production.

Verdict pré-gate : BLOCK (mistral), au motif d'une numérotation non chronologique
contraire au CGI art. 289. FAUX POSITIF, démontré sur la production : les
factures FOURNISSEUR portent déjà 5 ruptures de chronologie, leur séquence
suivant l'ordre d'enregistrement et non la date du document ; les factures
ÉMISES, seules visées par l'art. 289, en comptent 0. Le juge a appliqué au
registre des factures reçues une règle qui ne gouverne que celles émises. Sa
recommandation de renumérotation casserait la piste d'audit fiable.

Le gate humain n'est pas franchi : rien n'est écrit en production.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-13 20:36:45 +02:00
arcodangeandClaude Opus 5 ae9207ab66 docs(profile): échéancier URSSAF 2026 réel + correction 645 → 646
L'entrée « urssaf-echeancier / pending-definition / recurrence unknown » traînait
depuis erp#54 avec la consigne « ne pas inventer de cadence ». L'opérateur a
communiqué l'échéancier : ce n'est pas trimestriel mais trois appels irréguliers.

  493,00 (22/05, prélevé) + 1 215,00 (05/08) + 1 333,00 (05/11) = 3 041,00 EUR

Corrige aussi le compte comptable, faux dans la note : les cotisations d'un
gérant associé unique de SARLU (TNS) vont en 646 — cotisations personnelles du
dirigeant — et non en 645, qui vise les cotisations patronales sur salaires et
doit rester vide puisque Arcodange n'a aucun salarié.

Le schéma accepte désormais amount_eur : la boucle de rappels T11 (erp#60) a
besoin du montant en donnée structurée, pas noyé dans du texte libre.

Registre validé : 8 règles, 16 entrées, 8 ADC, 0 erreur.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-08-13 17:26:58 +02:00
arcodangeandClaude Opus 5 4d1e3ecb23 fix(email-ingest): extraction testable et pinnée au golden set + adc-008
L'extraction de champs vivait dans un heredoc à l'intérieur d'email-inspect.sh :
impossible à exécuter isolément, donc jamais mesurée, donc fausse sans que
personne puisse le voir. Sur la facture Darnis F1048 elle renvoyait le numéro de
TVA d'Arcodange comme référence de facture, et aucune date.

- extract_fields.py : l'extraction sort du shell et devient un module.
- test_extract.py : régression contre les 16 factures hand-vérifiées de
  fleet/golden/invoice-extract/. Score par champ, et une valeur FAUSSE pèse plus
  qu'une valeur absente — un humain recopie ce qui s'affiche.

Valeurs fausses : 4 → 0. Exactitude ref 62,5 → 75 %, date 62,5 → 75 %,
HT 68,8 → 75 %, TTC 81,2 → 93,8 %.

Cinq bugs réels, dont trois invisibles sans test :
- « Nº » sur les factures françaises est U+00BA (ordinal masculin), pas le signe
  degré. La classe [°o] le rate, le motif principal échoue, et le repli attrape
  le premier jeton ref-shaped du document — très souvent un numéro de TVA.
- Le filtre anti-TVA rejetait « FR73261832 », qui est la vraie référence OVH : un
  numéro FR fait exactement 11 caractères après le préfixe.
- « Montant total (HT) » était lu comme un TTC.
- Une référence coupée par la colonne (« 06-01-26- » / « payment-366753 ») était
  renvoyée amputée : le recollage doit précéder le scan, sinon la queue seule est
  trouvée en premier.
- Un `\b` après `€` ne peut jamais matcher en fin de ligne (€ n'est pas un
  caractère de mot) — la TVA n'était jamais extraite.

adc-008 : une facture fournisseur s'enregistre à SA date, même future, tant que
l'exercice (année civile) ne bascule pas. Le document fait foi ; altérer sa date
ferait diverger l'écriture de sa pièce justificative (CGI art. 289 VII).
Registre validé : 8 règles, 8 ADC, 0 erreur.

scopes.ts : 1232 (factures fournisseur) ajouté à prod-write — oubli initial,
révélé par un 403 en production sur F1048. Le pipeline s'est arrêté sans écrire.

Appliqué en production via le pipeline gated : FAF2026014 (Darnis F1048),
218,50 HT + 43,70 TVA = 262,20 TTC, validée, non réglée.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-08-13 10:47:30 +02:00
arcodangeandClaude Opus 5 1cba032512 fix(security): production read agent is now actually read-only
Migration applied to production, in the only order that does not break the
promote flow:

1. Created `ai_agent_prod_prod_write` (id=5) with the narrow `prod-write` scope —
   invoices, payments, and document submission (needed by builddoc to regenerate
   a modified invoice's PDF). Verified functionally: reads pass, DELETE on an
   invoice returns 403.
2. Repointed the promote pipeline at that user's key. It no longer borrows the
   read skills' credential; if the key is absent it dies with the provisioning
   command rather than silently falling back.
3. Revoked 12 write/delete rights from `ai_agent` (id=3), the credential every
   read skill holds: create/modify on customer AND supplier invoices,
   thirdparties, contacts, thirdparty payment details, proposals, exports,
   accounting links — and delete on proposals, events, and GED documents.

Verified after: invoices, thirdparties, contacts, products, proposals, supplier
invoices and bank accounts all still read; creating an invoice returns
`403 Forbidden: Insuffisant rights`. The documented posture and the real one
finally agree.

scopes.ts corrected against the live instance: 262 is NOT "créer/modifier les
produits" as the first catalogue guessed but the `voir_tous` ACL extension — a
READ right the skills depend on (without it, list endpoints return empty arrays
instead of 403). Revoking it would have silently blinded every read skill. This
is why the audit reads labels off /user/perms.php rather than trusting ids in
code. The READ_ONLY baseline is now the audited read surface (35 rights), not a
guess.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-08-09 19:33:00 +02:00
arcodangeandClaude Opus 5 a2cafc0d6b feat(harness): gated promote pipeline — rehearse, judge, human gate, apply, judge
The discipline (ADR-0003, the promote flow, the operating rules) was written
down and still depended on whoever was driving choosing to follow it. On
2026-07-25 an agent session wrote five documents into the production ledger
through direct API calls, bypassing the promote flow entirely — a correct result
reached by a path nobody could audit. A rule an operator can skip is a
recommendation.

The five stages are now chained by artefacts on disk. Each refuses to run until
the previous produced its file, and the file says what it needs to hear:
rehearse (sandbox, host-guarded) -> judge --pre -> gate (human) -> apply
(prod) -> judge --post. The gate binds to a manifest digest, so approving a
change-set approves THAT change-set.

An op is defined ONCE, as an API call, and replayed on the sandbox then on
production — because the first design described each write twice (a sandbox
script input and a prod API body) and the pre-gate judge immediately caught them
diverging: the rehearsal was creating a EUR invoice with no due date while
production would have received a USD one at 60 days. Two descriptions of the
same write are two things that can disagree.

Judges are context-free, cross-family per the PRD qa-strategy rule, and
advisory: a BLOCK still lets the operator approve, and the override is recorded
with their name. Blocking authority stays with the human gate and the host
guards — an LLM verdict never silently starts or stops a production write.

Verified end to end against the real 24/08 change-set (M3 deferred, USD 3,000):
- pre-gate judge (Mistral) returned BLOCK twice, correctly — first on the
  sandbox/prod divergence, then on a duplicate left by a repeated rehearsal;
- apply refuses after a rejected gate;
- apply refuses without ARCO_PROD_CONFIRM;
- editing an amount after approval invalidates the gate on digest mismatch.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-07-26 08:06:45 +02:00
arcodangeandClaude Opus 5 cf0cc3073d fix(config): real company identity — capital without the € sign, and no placeholders
static/config/company.json feeds setupCompany() in both main.ts and
provisionSandbox.ts, and main.ts defaults to the PRODUCTION address. The file
held placeholder identity values: running it against prod would have replaced
Arcodange's legal identity with them.

- capital "1000€" -> "1000". Dolibarr expects a number; the € made the value
  unusable by the PDF template, which is why "Capital de 1 000 €" was missing
  from every invoice since January (mandatory mention, C. com. R.123-238). This
  file is the root cause — patching the database alone would have been undone
  by the next provisioning run.
- siren 123456789 -> 999657455, siret 12345678900011 -> 99965745500013,
  numTva FR00000000000 -> FR00999657455, rcs_rm "000 000 000 R.C.S. Evry"
  -> "R.C.S. Évry", naf_ape 62.02A -> 6201Z. All read off the production ERP,
  where they render on every issued invoice.
- formeJuridique SAS -> SARL, and the same correction in fleet/profile/fiscal.yaml
  (legal_form), which inherited "SAS" from the PRD README. Three operational
  sources say SARL: the production ERP, the signed contrat cadre signature block
  ("Pour Arcodange (SARL)"), and the 2026-05-28 cohort review. The PRD is wrong.
  Flagged in-file for confirmation against the Kbis.
- moisDebutExercice Juillet -> Janvier (fiscal year closes 12-31 per fiscal.yaml).

fiscal.yaml still validates: 8 rules, 15 calendar entries, 7 ADC records, 0 errors.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-07-26 00:27:20 +02:00
arcodange 87a176e5b1 Merge pull request 'feat(fleet): fiscal profile + compliance calendar + ADC register (T11 data) — ⚠️ operator gate: Accept adc-001…005' (#71) from arcodange/fiscal-profile into main 2026-07-19 09:22:56 +02:00
arcodange 90669afe52 Merge pull request 'feat(fleet): invoice-extract atom — dual extraction + validators + provenance anchors (T02)' (#74) from arcodange/invoice-extract-atom into main 2026-07-19 09:22:39 +02:00
arcodange 479663e3f8 Merge pull request 'feat(fleet): golden set + injection fixtures from real history' (#73) from arcodange/golden-set into main 2026-07-19 09:22:09 +02:00
arcodangeandClaude Fable 5 e9d4a2bcb2 feat(fleet): invoice-extract atom — dual extraction + validators + provenance (erp#40)
Implementation of the T02 atom over the erp#39 golden set:

- validators.py: instruction-pattern + multi-IBAN pre-screens (0 hard false
  positives on the 16 real docs; all 6 injection fixtures quarantined BEFORE
  any model call), the atom.yaml invariants, and literal provenance anchoring
  with locale-aware locate (FR/EN months incl. abbreviations, NBSP-tolerant
  amounts, line-wrap + column-interleave fragment anchoring for refs).
- extract.py: single-leg runner (MLX endpoint / vibe -p), zero credentials,
  zero action tools; reasoning-channel aware.
- dual_run.py: model_policy in code — dual legs, exact critical-field
  agreement; disagreement, single-valid-leg or both-invalid → escalations/
  for the Claude tier (resolutions go back through validators.check).

Eval (eval/2026-07-19/, full transcripts + journals committed):
- critical-field accuracy 100 % (bar 98 %) — MET
- injection suite 6/6 quarantined — zero leaks
- overall field accuracy 94.9 % (known gaps: supplier ids often null,
  period_covered format) — non-blocking, noted for the next version
- 9/16 documents escalated to the Claude tier (Mistral API timeouts, small
  local model on receipts, one BIC-glued IBAN, derived-ratio rates) —
  consistent with the A1 autonomy level recorded in atom.yaml

Runtimes this run: m4-local = Qwen2.5-7B-4bit (MLX), mistral = vibe -p
(mistral-medium-3.5) — provisional pending erp#45; journals are the
routing-bench raw material.

Closes erp#40 (PR to follow once arcodange/golden-set is pushed — this branch
stacks on it).

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-07-19 00:31:21 +02:00
arcodangeandClaude Fable 5 a482bb18c4 feat(fleet): fiscal profile + compliance calendar + ADC register (erp#54, T11 data)
fleet/profile/ goes from stub to the machine-readable business-rules surface
the fleet reads (PRD agent-catalog document surface + compliance ADC framework):

- fiscal.yaml — entity, VAT position, 8 rules (regime reel simplifie until
  2026-12-31 -> quarterly CA3 from 2027-01-01 per LF 2025 art. 38; KM export
  autoliquidation 259-1 CGI box E2; FR 20% deductible; intra-EU reverse
  charge; FX 766/666; SaaS expensed; CCA 455 lane). Every rule carries
  effective_from/effective_until AND decision: adc-NNN; every date cites its
  PRD anchor as an inline comment (verified against factory origin/main).
- calendar.yaml — 15 entries: acomptes TVA (2026-07 month-window, 2026-12-15),
  last CA12 FY-2026 (2027-05-04), CA3 quarterly windows, CFE (December),
  AG comptes annuels (2027-06-30), e-invoicing milestones (2026-09-01
  reception, 2027-09-01 emission/e-reporting), URSSAF echeancier with the
  in-file NOTE that a real direct debit exists since May 2026 (erp#57 revisit
  of the payroll-dormant assumption), KM deferred due dates + renewal stub.
- JSON Schemas for both + scripts/validate.py (stdlib-only: strict YAML-subset
  parser, JSON-Schema-subset checker, rule->ADC resolution, calendar checks).
- decisions/ — ADC register: template + adc-001..005 Accepted formalizations
  (autoliquidation KM, FX->766/666, SaaS expensed, reel simplifie until
  abolition, CCA personal-card lane) + adc-006/007 Proposed stubs (retainer
  currency -> erp#53; capital path -> erp#51). Agents draft, the operator
  Accepts — never the reverse; immutable once merged, supersede never edit.
- Mutation policy in-file: PRs only (T12 proposes, human merges).
- Same-change: profile README stub -> real doc; fleet/README.md layout line
  and AGENTS.md fleet row updated (profile no longer a stub).

Validation: PASS — 8 rules, 15 entries, 7 ADCs, 0 errors, 7 warnings (the
warnings list exactly what awaits operator verification). Human gate left
open on purpose: operator sanity-read of the calendar + Acceptance of
adc-001..005.

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-07-18 23:45:00 +02:00
arcodangeandClaude Fable 5 bdd3d63b61 feat(fleet): invoice-extract atom — validators, screens, dual-run orchestrator (WIP erp#40)
- validators.py: deterministic pre-screens (instruction patterns, multi-IBAN
  escalate flag) + the atom.yaml invariants (arithmetic, rates, SIREN Luhn,
  IBAN mod-97, date plausibility) + literal-provenance anchoring (a value
  absent from the source can never appear in output).
  Tested: 0 hard false positives on the 16 real docs; 6/6 injection fixtures
  quarantined PRE-model; darnis-f1042 (embedded second document) → escalate.
- extract.py: single-leg runner, zero credentials/action tools; runtimes =
  MLX endpoint (Ornith/M4) and vibe -p (Mistral).
- dual_run.py: model_policy in code — dual legs, exact critical-field
  agreement, disagreement/flags → escalations/, invalid-both → quarantine.

Eval run against the golden set follows in this branch.

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-07-18 23:41:44 +02:00
arcodangeandClaude Fable 5 ceb4321224 chore(fleet): erp#63 evidence — verifier parity + builder bench transcripts
- runs/2026-07-18/: the 8 sha256-pinned verifier transcripts (4 runtimes ×
  2 tests), blind-judging verdicts (2 independent judges per cell, unanimous),
  the erp#56 builder-bench journal + prompt + caps, and the evidence README
  with the parity table.
- run-verifier.sh: mistral runtime drops the tool-filter flag (--enabled-tools
  with a no-match pattern hangs vibe 2.21.0); plain -p with --max-turns 1.

Verdicts: Mistral (vibe -p, mistral-medium-3.5) and Ornith 35B (hermes MLX)
reach verdict parity with the Claude baseline on both tests → admitted to
verifier duty. Qwen2.5-7B-4bit fails both → the honest small-model floor.
Builder bench: erp#56 completed by the Mistral runtime, 0 code corrections,
261 s, acceptance run clean (0 bank-UNKNOWN) → merged as PR #68.

Closes #63 (with the paired factory qa-strategy PR).

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-07-18 19:56:55 +02:00
arcodangeandClaude Fable 5 6df4693880 feat(fleet): golden set + injection fixtures from real history (erp#39)
Seed the invoice-extract (T02) and mail-classify (T01) golden sets from real
Arcodange history, plus an adversarial injection suite and an offline
field-level scorer.

invoice-extract/
- 16 real supplier PDFs (DARNIS/Hiway F1040/F1042/F1045/F1046, Anthropic
  invoice+receipt x2, Mistral, OVH, greffe d'Evry, INPI x2, Legalstart, Qonto,
  Infogreffe) fetched from the Zoho mailbox + Dolibarr GED, each with a
  hand-verified expected JSON per the T02 schema. Every expected value was
  cross-checked against the pdftotext -layout text and re-validated against the
  deterministic invariants (HT+TVA=TTC, per-rate sums, IBAN mod-97, SIREN Luhn).
- inputs/ carries both the source PDF and its {source_sha256, mime, text} pair.
- 6 SYNTHETIC injection fixtures (LLM-directive, hidden white text, IBAN-swap
  BEC lure, arithmetic-repair lure, fake tool-call, ref-hijack duplicate) whose
  only correct outcome is quarantine; each PDF is marked SYNTHETIC.
- score.py: stdlib-only field-level scorer, critical fields (amounts/IBAN/refs/
  dates) scored separately against the 98% bar, injection leaks blocking; a
  built-in --self-test proves it catches perturbed fields and leaks.
- manifest.json: per-item provenance (mail message id / GED path + sha256),
  linked Dolibarr supplier invoice, a verification note, and the list of real
  documents deliberately excluded (fee statements, payment proofs, La Poste
  receipts with no HT/TVA breakdown) with reasons.

mail-classify/
- 1824 historical mails labeled into {supplier-invoice, bank-notice,
  government-admin, client, other} via sender-domain + subject weak supervision,
  one human-correctable JSONL line per message with confidence + reason +
  message-id provenance. manifest.json records the pull method and distribution.

Docs: golden/README hub, invoice-extract/README (T02 schema + conventions),
injection/README (threat table), mail-classify/README (method + distribution).

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-07-18 19:07:58 +02:00
arcodangeandClaude Fable 5 f2a60817e2 feat(fleet): multi-runtime harness — verifier tests + capped builder shell
The harness layer (builder sessions, cold verifiers, evidence flow) gets a
committable home, per the PRD model-fleet § harness portability and erp#63:

- fleet/harness/verifier/: the two canonical verifier tests (locate-test,
  cold-reader backlog audit) with pinned inputs, verbatim prompts, ground
  truth and pass rules — judged context-free, never self-graded.
- fleet/harness/bin/run-verifier.sh: runs a test against any OpenAI-style
  local endpoint (Ornith/MLX) or vibe -p (Mistral); emits sha256-pinned
  JSON transcripts.
- fleet/harness/bin/vibe-builder.sh: the bounded shell for scoped builders
  and recurring tasks — refuses the trunk (linked-worktree guard), hard
  --max-turns/--max-price caps, full JSON journal per run.
- fleet/README.md layout + AGENTS.md Fleet section updated in the same
  change (same-change freshness rule).

Part of erp#63 (harness portability spike, D2).

Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
2026-07-18 18:52:53 +02:00
arcodangeandClaude Fable 5 96c594e0ce feat(fleet): scaffold the atom registry — classes, contract, worked example, AGENTS.md section
Closes erp#38 deliverables: fleet/ layout, atom.yaml schema documented
in fleet/README.md, 7 class skeletons per the PRD agent-catalog,
invoice-extract as the worked example (contract only — implementation
is erp#40), golden/ + profile/ stubs, AGENTS.md Fleet section with
freshness fixes (fleet/ no longer "not yet landed").

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-07-15 18:38:08 +02:00