AIM Cortex Programme Board

Live · 2026-09-17 07:41 · main ab668db3

One platform, two ways in. The science lives in the engine and library; shared product logic lives once in services; Fox (people) and Machines (AI agents) are thin surfaces on top. The work is nine numbered workstreams; each item is a ticket in the Cortex Delivery board. The goal running through all of it: thinner surfaces, a fatter shared middle, every capability built once.

Waiting on you live · labelled needs:david

Decide9.14 Enable the 'PR merged' + 'PR linked to issue' Project workflows #710. Belt-and-braces on the mechanical board: turn on the built-in Project #2 workflows so merged/linked PRs move tickets automatically.
StandingMerges stay your word, one lane at a time. Tickets are the source of truth — update the ticket, not this page. Archived sessions are reopenable from the Archived list — that is the rollback. S1 security (9.2) has your go; the async seam is live with the old engine warm as the parachute.

Sequence & dependencies

The serial spine — each step needs the one before it
1

Foundations

3/3 done

3

Surveys

16/18 done

7

Feature slices

28/43 done

Branches off the spine
4 · Machines POC

starts once Surveys reaches its executor (3.5)

Parallel tracks — own gates
2 · Data platform6 · Services

Build alongside the spine; only the job-store swap (2.3) waits (for 1.3 + 3.5).

No gate — run anytime
5 · Fox hygiene9 · Security8 · Engine & science · 8.1 urgent

Nothing blocks these; they run whenever there is a slot.

Ready / in flight now live
2.103.73.95.106.86.277.57.238.99.59.189.249.259.269.27

Computed from the tickets this run — every item currently Ready, In Progress or In Review.

Waits on Matt
7.38.28.68.7

7.3 analysis blocks · 8.2 v6.1 · 8.6/8.7 drivers + Likert — need Matt's rulings (8.4).

Gantt · effort & sequence T-shirt sizes · live

Each bar is a ticket; its width is the AI-execution effort (the Size field), laid end-to-end along the dependency chain. Dashed lines are dependency gates — a downstream track (e.g. 7 Feature slices, 4 Machines) can’t start until the marked spine work clears. Not a calendar — horizontal is relative AI-effort (XXS minutes · XS ½h · S 1–2h · M ½d · L 1d · XL 2–3d · XXL ~1wk).
sequence start≈31.7 AI-days →
Landed — 184 delivery ticketsclick to expand
0.1 · 0.1 PR #532 closed WITHOUT merge - confi0.2 · 0.2 PR #547 closed WITHOUT merge - confi0.3 · 0.3 Protection drift: live settings no l0.4 · 0.4 Pin the latest board artifact versio0.5 · 0.5 Resume the 4 paused build lanes 0.6 · 0.6 Add the native Roadmap view to Proje0.7 · 0.7 CI red on main - ci0.8 · 0.8 CI red on main - viz-ci0.9 · 0.9 CI red on main - service-ci0.10 · 0.10 CI red on main - secret-scan0.11 · 0.11 CI red on main - ci0.12 · 0.12 CI red on main - ci0.13 · 0.13 PR #656 closed WITHOUT merge - conf0.14 · 0.14 PR #827 closed WITHOUT merge - conf0.15 · 0.15 Parametrise the derived-profile pho0.16 · 0.16 Region acceptance gate for the next0.17 · 0.17 Resolve the three inert Geography c0.18 · 0.18 PR #945 closed WITHOUT merge - conf0.19 · 0.19 PR #864 closed WITHOUT merge - conf0.20 · 0.20 PR #858 closed WITHOUT merge - conf0.21 · 0.21 infra-cd: apply job declared 'No ch0.22 · 0.22 Fox freeze guard: relaxed attestati0.23 · 0.23 CI red on main - viz-ci0.24 · 0.24 Fix resonance-map service silent fa0.25 · 0.25 build_sha0.26 · 0.26 [Hygiene]: wire up the documented c0.27 · 0.27 CI red on main - ci0.28 · 0.28 PR #1111 closed WITHOUT merge - con0.29 · 0.29 PR #1110 closed WITHOUT merge - con0.30 · 0.30 focus_group_run async job never com0.31 · 0.31 #987 service-cd diff-gate: false-po0.32 · 0.32 TC-STUD-22: platform-divergent cate0.33 · 0.33 PR #1151 closed WITHOUT merge - con0.34 · 0.34 PR #1146 closed WITHOUT merge - con0.35 · 0.35 Real-scale parity test stale on uk_0.36 · 0.36 CI red on main - service-ci0.37 · 0.37 Service: shared selection for sensi0.38 · 0.38 Throughput step 1a: scheduled fail-0.39 · 0.39 Throughput step 1b: scripted Fox ro0.40 · 0.40 Throughput step 1c: deploy_sha inpu0.41 · 0.41 Live probe: production surface unre0.42 · 0.42 Throughput step 1 0.43 · 0.43 Throughput step 1 0.44 · 0.44 Protection drift: live settings no 0.45 · 0.45 Throughput step 2: always-post shim0.46 · 0.46 Throughput step 1 0.47 · 0.47 Live probe: production surface unre0.48 · 0.48 Fox rollback script: mktemp -t fail0.49 · 0.49 Throughput step 2: CODEOWNERS shrin0.50 · 0.50 Throughput step 2: scripts/ lint ga0.51 · 0.51 Throughput step 2: remove /scripts/0.52 · 0.52 CI red on main - secret-scan0.53 · 0.53 PR #1233 closed WITHOUT merge - con0.54 · 0.54 Protection drift: live settings no 1.1 · 1.1 Orchestration reliability + CI frict1.2 · 1.2 Generate the live-state page from th1.3 · 1.3 Truth-docs audit 2026-09-05: INDEX, 2.1 · Stand up the control-plane database2.2 · Accounts / projects / keys / budget grad2.3 · Job-store backend swap 2.4 · Asset data waves2.5 · Ledger graduation + evidence envelope2.8 · Results cache 2.11 · 2.11 2.1: migration 0001 must self-grant2.12 · 2.12 2.4.1 · Results wave — migrate stud2.13 · 2.13 2.4.2 · Audiences finalisation — pr2.14 · 2.14 2.4.3 · Fix import_studies append-o3.1 · Surveys slice spec 3.2 · Freeze the characterization corpus3.3 · Wire the 6 stranded believability specs3.4 · Demo curation 3.5 · Services survey executor 3.5 · Shared PRNG primitive 3.5 · Sampler cleanup 3.6 · Fox thin adapter + flag cutover3.8 · Sampling-quality gate 3.10 · 3.10 3.6c · Survey executor reference-lo3.11 · 3.11 [Conductor primary] Diagnose the su3.12 · 3.12 Break the survey mock coupling so t3.13 · 3.13 Move participant selection and audi3.14 · 3.14 Service: one JS-parity module with 3.15 · 3.15 Service: shared selection and prove3.16 · 3.16 Service: v2 study contracts on new 4.1 · Machines POC: real run-survey job kind4.2 · Machines POC: minimal MCP tool 4.3 · Machines POC: demo — an agent commission4.4 · 4.4 Workstream 4 · Machines5.1 · Compat calibration_status hardcoded true5.2 · verbose_errors to real config + error ca5.3 · DRIVER_BANK provenance gating5.4 · Fakery re-sweep 5.5 · Avatar quality 5.6 · V6 warm-cache staleness plan row5.7 · resonanceMap per-persona confidence ?? 05.8 · Local/IDB-mode Quadrant demos serve stal5.9 · Silent-failure / honesty register needs 5.12 · 5.12 Harness hygiene: the keyed audience5.14 · 5.14 Placement tripwire: a disposition r5.15 · 5.15 Numbers audit: a generated register5.16 · 5.16 Refresh the Fox developer kickoff f5.20 · 5.20 Trait radar's "UK baseline" is a fl5.21 · 5.21 Admin console operational metrics 5.22 · 5.22 Fox: refresh vendored oracle manife5.23 · 5.23 Creative service adapter forwards t6.2 · Accounts / identity model detail6.5 · Error-code developer + user documentatio6.7 · CF Pages deploy pipe — LFS-smudge clone 6.9 · 6.9 Service-layer CD: auto-deploy 03-bis6.10 · 6.10 Box disk hygiene: prune Docker imag6.11 · 6.11 Service loads whole populations unc6.12 · 6.12 Dockerfile digest-pin test: a FROM 6.13 · 6.13 service-cd: deploy fails on a full 6.14 · 6.14 Terraform drift: bis-service-box de6.15 · 6.15 Registry should report row count, p6.16 · 6.16 Move the sample cap and the study m6.18 · 6.18 Infra CD: Terraform validate on PR,6.19 · 6.19 service-cd applies the box's compos6.20 · 6.20 Gateway G0: policy with the feature6.21 · 6.21 Gateway G1: survey voicing and the 6.22 · 6.22 Gateway G2: the three search tasks 6.23 · 6.23 Gateway G2b: the survey and intervi6.25 · 6.25 Gateway G4: the ingestion endpoints6.26 · 6.26 Gateway G5: generate-image via the 6.28 · 6.28 Service: the call context as code6.29 · 6.29 Service: the run timeline in job_ev6.30 · 6.30 Service: one worker process on the 6.31 · 6.31 Service: the Postgres queue and N w6.33 · 6.33 Service: one policy module 6.34 · 6.34 Service: one-off tooling out of the6.35 · 6.35 Audiences: reconcile app/audiences/6.37 · 6.37 Index the known_defects entries acr7.1 · Audience creation 7.2 · Focus groups7.6 · Chat-survey fold-in7.10 · Survey question types 7.13 · 7.13 7.5.1 · Port the creative study run7.14 · 7.14 7.5.2 · Port the sensitivity study 7.15 · 7.15 7.2.0 · Golden-freeze the spec-less7.16 · 7.16 7.2.1 · Port the focus-group study 7.17 · 7.17 7.2.1 · Port the focus-group study 7.18 · 7.18 7.5.3 · Port the interview study ru7.19 · 7.19 7.5.4 · Port the resonance-map stud7.20 · 7.20 7.5.5 · Port the ddq study runner t7.21 · 7.21 Port resonance-map per-driver R 7.22 · 7.22 Feature B — engine-generate audienc7.24 · 7.24 Confirm the target account when cre7.25 · 7.25 Audience membership count — server-7.26 · 7.26 Route /v1/reactions + /v1/workflows7.27 · 7.27 Audience count: service /v1/audienc7.28 · 7.28 population_generate's n has no uppe7.29 · 7.29 Audience-count follow-ons after #907.31 · 7.31 Interview runner: write the live-st7.32 · 7.32 Region breakdowns in study results 7.33 · 7.33 Build the missing live-staged parit7.36 · 7.36 Study-maths defect register: every 7.38 · 7.38 Client-side discrepancy guard for t7.39 · 7.39 Port the audience clustering machin7.40 · 7.40 Port the competitor and positioning7.43 · 7.43 Focus Group + Interview: target_tra8.1 · Build a new 100k HSV population8.11 · 8.11 Creative voices quotes with an empt8.12 · 8.12 Interview reports a hardcoded 0.82 8.13 · 8.13 Focus-group headline quotes can sho8.14 · 8.14 applyFilter coerces missing age to 8.16 · 8.16 T3: parametrise the derived-profile8.17 · 8.17 T3: regenerate the client populatio8.18 · 8.18 T3: measure the service's resident 8.19 · 8.19 T3: Matt's inputs for the subsample8.20 · 8.20 Move the engine's narratives into t8.24 · 8.24 Service: a populations module, step8.25 · 8.25 M4 GB-lens mean_shift: dim-119 all-8.26 · 8.26 M2 declares relations_emitted=['ser9.2 · S1 security execution 9.6 · 9.6 9.2/S1 [Medium]: authenticated SSRF 9.7 · 9.7 9.2/S1 [Medium]: path traversal via 9.8 · 9.8 9.2/S1 [Medium]: indirect prompt inj9.9 · 9.9 9.2/S1 [Medium]: D1 DoS — save-state9.10 · 9.10 9.2/S1 [Medium]: D1 DoS — arbitrary9.11 · 9.11 9.2/S1 [Medium]: no CSRF defence on9.12 · 9.12 9.2/S1 [Medium/local-dev]: serve.py9.15 · 9.15 Believability harness passes secret9.16 · 9.16 Make the service check required in 9.24 · 9.24 GITHUB_TOKEN cannot write repositor9.28 · 9.28 Papercuts: stale docs-auto-land com

The work — by workstream active shown · done in Landed

now / in reviewdoneparkedurgentreadytriage / queued
1

Foundations

3/3

Objective: Stand up the guardrails and coordination so the build runs safely, in parallel, without rotting.

Needs: Unlocks the whole critical path. These are live lanes, not board tickets.

2

Data platform

10/15

Objective: Give the platform a real memory — one production database for accounts, keys, assets and results.

Needs: Store ruled (D-021, production). 2.3 waits on 1.3 + 3.5.

3

Surveys

16/18

Objective: Prove the build-once model — move the first real feature into shared services, thin on both surfaces.

Needs: Needs the 1.1 gate + 1.3 job seam; not the data platform. Spec 3.1 ruled.

4

Machines

4/4

Objective: Let an AI agent commission a survey end to end — the first Machines proof of concept, internal only.

Needs: Branches off the spine once Surveys reaches its executor (3.5). Delta ruled (D-022).

  • all clear — 4 landed 
5

Fox hygiene

17/24

Objective: Close the honesty and cleanup gaps in the Fox app so demos and pilots are trustworthy.

Needs: No gate — runs anytime, full-auto to verified PRs.

6

Services & platform

27/37

Objective: Build the shared plumbing both surfaces rely on — the AI gateway, accounts, a real release path.

Needs: 6.1 rides the Surveys path; 6.3 is independent and unlocks retiring the old VM.

  • DeliversThe one shared LLM gateway service — 29 registered tasks + the 4 ingestion/image endpoints, the unregistered raw-completion escape hatch closed, provider provenance stamped (closes the model_used defect) → unlocks every surface calling LLMs through one governed path instead of its own integration, with the Survey-voicing subset moving first, riding workstream 3 (Surveys).
    Services
  • DeliversA real release path for the service — Artifact Registry, scripted deploy, an acceptance probe (M4 baseline + real >30s async compute), previous-image rollback, release-identity stamp → unlocks the old-VM decommission (~65-110/mo saving).
    Services
  • 6.4#624Infra tidyqueued
    DeliversInfra tidy on the redeployed box — L1 observability re-verified (merged 08-08, never re-verified), key-rotation completed, a tunnel/DNS map drawn → unlocks a verified, documented infra baseline for the 6.3 release path and old-VM decommission to build on.
    Services
  • DeliversThe ~230 MB of static census / personality / HSV reference datasets moved from git LFS into a GCS bucket (europe-west2), with the population build + docs updated to fetch from the bucket → unlocks near-zero LFS bandwidth + storage (kills the recurring LFS overage that hit 250 GB/250 GB and ~$76 in Aug) and removes the fresh-clone / Codespace "over data quota" failure risk permanently.
  • Deliversthe remaining registered tasks moved to the gateway in four batches (subjects, audiences, studies, analysis), each with prompt photographs, one live-staged run and its own Fox flag; TASK_ENDPOINT_CLASS generated from GET /v1/llm/tasks and pinned by a test.
  • Deliversgateway.model_policy (append-only, audit row per change), PUT /v1/admin/llm-policy, and the AC admin console's LLM and costs panel showing the effective policy and its config_hash; the engine domain read-only there.
  • Deliversapi_keys.expires_at and a sweeper; a keys:mint scope that can only issue short-lived humans-surface keys; the Pages proxy mints one per workspace session bound to the Access-authenticated email and the claimed active account (recorded as a claim until memberships exist), and attaches it to every engine and study call; keyed twins on /v1 for the m2, m3 and m4 analyse routes and their async forms; a flag per route with rollback to the keyless path; a humans-surface default budget.
7

Feature slices

28/43

Objective: Grow the product by pulling each study type into shared services, reusing the Surveys machinery.

Needs: Needs the Surveys machinery (3). 7.3 also needs Matt (8.4).

8

Engine & science

13/30

Objective: Engine & science — the 100k population, the capability workshop, and Matt's handover items.

Needs: 8.1 is urgent and runs now; most rows are Matt-gated.

9

Security & governance

11/30

Objective: Security baseline, dependency debt, and pre-customer licensing validation.

Needs: 9.1 sweep can start now (Codex); 9.2 has David's go.