AlphaTest · Reports · External consumer run

DO NOT ADOPT

Honest evidence. No report product yet.

An AcmeTest-shaped client exercised the live Reports API for mastery gates, adaptive diagnostics, and formative tests. Zero of twelve adoption operations completed. The API is fail-closed, but its canonical deployment topology also drifted across test kinds.

0 / 12
customer operations passed

Attempt detail, candidate history, readiness, and materialization across three test kinds.

3 / 3
anonymous probes contained

Only route absence was proven. This is not released-boundary tenant certification.

0
fresh upstream calls credited

No successful report response made Results, Caliper, Analytics, QTI, Content, CASE, OneRoster, Administration, Blueprint, or Mastery Engine use attributable.

154.5 ms
load p95

18/18 concurrent reads returned 404; failure envelopes were stable within each deployment.

Decision

AcmeTest cannot adopt Reports. No test kind completes the minimum report journey, no production report is available to validate Platform3-native evidence composition, and no materialization proves a Results result_record, test_result_components, or matching Caliper event.

Secure failure is necessary, not sufficient. The approved architecture correctly forbids synthetic success while gates are closed. This run does not call the parked boundary a product, and it does not convert inherited upstream probes into fresh consumer evidence.

Adoption matrix

Test kindAttemptHistoryReadinessMaterializeObserved runtime
mastery_gate404404404404Generic Vercel NOT_FOUND; no typed Reports envelope.
adaptive_diagnostic404404404404Formative build receipt at the adaptive origin.
formative404404404404Intentionally parked, typed RFC 9457 absence boundary.

Observed 20 July 2026 11:17:23Z with a production reviewer credential supplied out of band. The credential and response bodies were not retained.

Cross-kind deployment drift

Actionable contract divergence. ITD-029 requires one coherent runtime at one canonical origin. Instead, the adaptive customer origin answered report requests with X-AlphaTest-Build-Receipt: reports-formative-parked-a3-20260720, while mastery routes bypassed the Reports problem contract and returned Vercel's generic JSON 404. The adaptive root no longer matched its approved release-status artifact.

Rollback starts at implementation@mastery_gate, the first implementation coverage cell: establish one immutable unified Reports runtime and atomic three-kind promotion matrix, then rebuild the later kind cells against that same runtime. Keep production report routes absent until their declared upstream and two-tenant gates actually pass.

Upstream reality

AuthorityFresh creditWhat would count
Results + CaliperNoneExact attempt composition, component write, matching event, settled read-back, and partial-failure replay.
AnalyticsNoneVersioned class/grade mastery and parallel-form equivalence rollups returned by a production report.
QTI, Content, CASE, OneRoster, AdministrationNoneDereferenceable native IDs and item/standard/KC evidence from the authoritative attempt chain.
Mastery Engine + BlueprintNoneAdaptive scale/gap receipts and mastery-gate crosswalk/readiness evidence linked to the administered attempt.

Approved prior receipts are SHA-256 fingerprinted in provenance.json and explicitly labeled inherited. They explain why the gates are closed; they do not prove this consumer run called those capabilities.

Security result

No tenant-data exposure observed. Anonymous probes for all three kinds returned route absence, and the public demo mint remained absent.

Cross-tenant isolation is blocking-inconclusive. There is no same-tenant successful report, second production credential, or disjoint authoritative tenant fixture. A released API must prove A/A and B/B success plus indistinguishable A/B and B/A denial before adoption.

Reproduce

Run from this artifact directory with a short-lived reviewer JWT in the environment:

REPORTS_PROD_REVIEWER_JWT=<token> npm run run:live
npm test

run:live exits 0 only for an adoptable result and 2 for the reproduced failure. The suite imports no Reports implementation code and uses only public HTTPS origins. It records status, safe headers, semantic body class, typed problem fields, and latency—never JWTs or report bodies.

Certification benchmark

The run uses the OpenID Foundation Certification bar: independently runnable conformance evidence, a named target, and no certification when a required journey fails. The benchmark fetched 200 during this run and is content-fingerprinted in the machine evidence. AlphaTest exceeds it on honest upstream attribution and privacy-safe retention, but fails its decisive pass-only outcome.