Published contract
The implementation and live API contradict active ITD-029 and ITD-030.
Fresh production probes reproduce a route-less API and a fictional authentication blocker. Both contradict the active architecture. This audit routes the earliest known owner-chain defect to Blueprint rather than blessing the stale deployment.
At 2026-07-17T10:18:20.616Z and 2026-07-17T10:18:21.467Z, both required POST routes returned 404 from build mastery-engine-integrator-api-a1-qti-member-gate. Active ITD-029 explicitly forbids absent business routes or permanent 404/424 responses from implementation onward. ITD-030 rejects platform3.workload_token_exchange, yet the live health response still lists it as a blocker. Rollback is required.
The implementation and live API contradict active ITD-029 and ITD-030.
No valid AcmeTest consumer can start a diagnostic or recover a mastery score.
Anonymous configuration reads return 401 and private package paths return 404.
No tenant-owned run can be created, so production A↔B isolation cannot be proved.
Who: the AcmeTest maintainer’s tech lead. Job: decide adoption by replaying this audit cold. Status quo: hand-curated local QTI banks and no trustworthy mastery diagnostic. Benchmark: Qualys SSL Labs assessment API for github.com, fetched HTTP 200 on 2026-07-17 with status READY and grade A+.
REPLAYABLE Like SSL Labs, this report names the target, timestamps each probe, ranks failures, publishes exact redacted machine evidence, and separates observed facts from unproved claims. Unlike attempt 1, its verdict follows the active contract: wait, because the surface fails conformance and the owner chain cannot yet produce a valid adaptive pool.
Commitment: ITD-029 supersedes ITD-025 and requires start, inspect, advance, and score recovery from implementation onward; permanent 404/424 behavior is forbidden. Observed twice: POST /v1/adaptive-runs and POST /v1/score-recovery-simulations return 404 resource-not-found. The health body admits all four capabilities are unimplemented. This blocks the persona’s actual job, not a preferred API shape (P5).
Commitment: ITD-030 requires server-held PLATFORM3_TENANT/PLATFORM3_JWT profiles and rejects both workload exchange and demo mint as production auth. Observed: health still lists platform3.workload_token_exchange. A fresh provisioned-profile probe against the real Platform3 QTI route returns stable 403 forbidden: “QTI delivery projection reads require qti:read authority.” Therefore the approved provisioned-QTI binding has no positive wire receipt. The prior demo-mint 200 is a negative control, not release evidence.
Commitment: ITD-028 requires a terminal Bank adaptivePool manifest with immutable native member versions and non-empty CASE/KC GUID arrays, reconciled to QTI. Owner-chain evidence: the approved implementation review records that Blueprint test_spec 96965244-fed7-4de1-8c01-fc208718c8b1 publishes case:math:7.ee.b.4 instead of an owner-issued CASE CFItem identity. Bank stops at CASE resolution before Incept, QTI, Content, or manifest writes. Mastery may not infer or fabricate the missing identity (DoD D5).
API base: https://alphatest-andymontgomery-9773s-projects.vercel.app/mastery_engine/integrator_api/implementation/api
Primary: 2026-07-17T10:18:20.616Z · recheck: 2026-07-17T10:18:21.467Z · provisioned QTI probe: 2026-07-17T10:21:01.680Z
| Probe | Observed | Active-contract verdict |
|---|---|---|
GET /health | 200; release-gated; workload exchange listed | FAIL ITD-030 |
| Policy read, no bearer | 401 authentication-required | PASS |
| Policy/calibration with reviewer bearer | 200 / 200 | PASS |
POST /v1/adaptive-runs | 404 resource-not-found | FAIL ITD-029 |
POST /v1/score-recovery-simulations | 404 resource-not-found | FAIL ITD-029 |
| QTI root with provisioned profile | 403 forbidden, twice; stable canonical failure hash | NO ITD-030 RECEIPT |
| Five private package paths | 404 each | PASS |
Machine evidence: primary · recheck · provisioned-profile QTI probe · local contract checks.
export BASE='https://alphatest-andymontgomery-9773s-projects.vercel.app/mastery_engine/integrator_api/implementation/api'
export TOKEN='<tenant-scoped reviewer JWT>'
curl -sS -i -X POST "$BASE/v1/adaptive-runs" \
-H "Authorization: Bearer $TOKEN" \
-H 'Content-Type: application/json' \
-H 'Idempotency-Key: qc-active-contract-replay-2' \
--data '{"selectionPolicyId":"policy-g5-math-v3","scaleCalibrationId":"cal-math-vertical-2026-01","testSpecId":"spec-tx-g5-math","testBankId":"bank-tx-g5-adaptive","qtiPoolArtifactId":"aaaaaaaa-aaaa-4aaa-8aaa-aaaaaaaaaaaa","qtiPoolArtifactVersionId":"bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb","runMode":"owner_conformance"}'
Observed invariant: HTTP 404, application/problem+json, code=resource-not-found, releaseGate=qti.resolve_adaptive_pool_members. This observation reproduces; it is a failure under ITD-029, not a PASS.
node source/run-live-probes.mjs site/evidence/live-probes.json node source/run-upstream-qti-probe.mjs site/evidence/upstream-qti-probe.json node source/run-local-checks.mjs site/evidence/local-checks.json
All 12 standard axes remain pinned: write granularity ITD-003; read/list shape ITD-004; query ITD-005; concurrency ITD-006; idempotency ITD-007; auth and tenant routing ITD-008; error envelope ITD-009; eventing ITD-010; conformance ITD-011; privacy/retention ITD-012. The active architecture verifier reports 31 ITD anchors and 27 current commitments. The supersession audit is decisive: ITD-029 supersedes ITD-025, ITD-030 supersedes ITD-026, and ITD-031 supersedes ITD-027. ITD-028–031 are ACTIVE; stale behavior cannot be certified against the superseded entries.
rollback_target: blueprint/integrator_api/implementation@mastery_gate. This matches the authoritative Mastery implementation review and routes to the earliest currently evidenced owner defect. The Blueprint implementation must publish an owner-issued CASE identity; Bank must then complete the real adaptive generation and terminal manifest; only then can Mastery implement and prove the ITD-031 journey. Rebuilding Mastery against the bad Blueprint identity would invite a forbidden local substitute.
This is attempt 2. The hosted decision payload is identified by site-tree SHA-256 0175a51743c1056b8ab02b6a6e366e48809e54cbd53bea21da6b4078408df6c2. The verifier rejects attempt drift, stale receipts, failure-to-reproduce, unlisted files, broken evidence links, missing rollback fields, stale ITD narrative, or serialized bearer credentials. No files may change after handoff.