Attempt detail, candidate history, readiness, and materialization across three test kinds.
Only route absence was proven. This is not released-boundary tenant certification.
No successful report response made Results, Caliper, Analytics, QTI, Content, CASE, OneRoster, Administration, Blueprint, or Mastery Engine use attributable.
18/18 concurrent reads returned 404; failure envelopes were stable within each deployment.
Decision
AcmeTest cannot adopt Reports. No test kind completes the minimum report journey, no production report is available to validate Platform3-native evidence composition, and no materialization proves a Results result_record, test_result_components, or matching Caliper event.
Secure failure is necessary, not sufficient. The approved architecture correctly forbids synthetic success while gates are closed. This run does not call the parked boundary a product, and it does not convert inherited upstream probes into fresh consumer evidence.
Adoption matrix
| Test kind | Attempt | History | Readiness | Materialize | Observed runtime |
|---|---|---|---|---|---|
| mastery_gate | 404 | 404 | 404 | 404 | Generic Vercel NOT_FOUND; no typed Reports envelope. |
| adaptive_diagnostic | 404 | 404 | 404 | 404 | Formative build receipt at the adaptive origin. |
| formative | 404 | 404 | 404 | 404 | Intentionally parked, typed RFC 9457 absence boundary. |
Observed 20 July 2026 11:17:23Z with a production reviewer credential supplied out of band. The credential and response bodies were not retained.
Cross-kind deployment drift
Actionable contract divergence. ITD-029 requires one coherent runtime at one canonical origin. Instead, the adaptive customer origin answered report requests with X-AlphaTest-Build-Receipt: reports-formative-parked-a3-20260720, while mastery routes bypassed the Reports problem contract and returned Vercel's generic JSON 404. The adaptive root no longer matched its approved release-status artifact.
Rollback starts at implementation@mastery_gate, the first implementation coverage cell: establish one immutable unified Reports runtime and atomic three-kind promotion matrix, then rebuild the later kind cells against that same runtime. Keep production report routes absent until their declared upstream and two-tenant gates actually pass.
Upstream reality
| Authority | Fresh credit | What would count |
|---|---|---|
| Results + Caliper | None | Exact attempt composition, component write, matching event, settled read-back, and partial-failure replay. |
| Analytics | None | Versioned class/grade mastery and parallel-form equivalence rollups returned by a production report. |
| QTI, Content, CASE, OneRoster, Administration | None | Dereferenceable native IDs and item/standard/KC evidence from the authoritative attempt chain. |
| Mastery Engine + Blueprint | None | Adaptive scale/gap receipts and mastery-gate crosswalk/readiness evidence linked to the administered attempt. |
Approved prior receipts are SHA-256 fingerprinted in provenance.json and explicitly labeled inherited. They explain why the gates are closed; they do not prove this consumer run called those capabilities.
Security result
No tenant-data exposure observed. Anonymous probes for all three kinds returned route absence, and the public demo mint remained absent.
Cross-tenant isolation is blocking-inconclusive. There is no same-tenant successful report, second production credential, or disjoint authoritative tenant fixture. A released API must prove A/A and B/B success plus indistinguishable A/B and B/A denial before adoption.
Reproduce
Run from this artifact directory with a short-lived reviewer JWT in the environment:
REPORTS_PROD_REVIEWER_JWT=<token> npm run run:live
npm testrun:live exits 0 only for an adoptable result and 2 for the reproduced failure. The suite imports no Reports implementation code and uses only public HTTPS origins. It records status, safe headers, semantic body class, typed problem fields, and latency—never JWTs or report bodies.
Certification benchmark
The run uses the OpenID Foundation Certification bar: independently runnable conformance evidence, a named target, and no certification when a required journey fails. The benchmark fetched 200 during this run and is content-fingerprinted in the machine evidence. AlphaTest exceeds it on honest upstream attribution and privacy-safe retention, but fails its decisive pass-only outcome.