● Demonstration — synthetic data throughout Harbor Insurance is fictional · no recommendation is made anywhere on this page
Harbor Insurance · the working screens ← back to the brief

The screen that is allowed to say no.

Before you buy, Harbor shows you the difference between the quote in front of you and the policy you already have. Three versions, all on one page. The one that matters is the second, where the honest answer is nothing here needs to change. A comparison run by a seller that has never once told you to stay put is not a comparison. It is a sales page.

One correction, dated. These screens were built on 9 September, when getting the held policy in meant uploading it. Consumer-permissioned rails turned out to be commercially available — so signing in is now the path and the upload is the fallback. The comparison is identical either way, which is why the states below are unchanged. §01 shows both routes; the capability correction is in §05.

synthetic invented for this demonstration observed from the field record speculative Harbor does not exist

Everything on this page is made up. The people, the policies, the prices and the form numbers are invented so the screen can be shown without using anyone’s real policy. The findings behind it are not invented — those come from real documents and real conversations, and they are in the record.

01

Bringing your policy in.

The comparison is the easy half. This is the step the room asked about — how the policy you already hold gets in front of Harbor at all, what comes back, and what does not. The refusals on state C start here.

INTAKE · headline: connectSYNTHETIC HOUSEHOLD 1 · SPRINGFIELD, MO
Demonstration — invented policy dataHarbor Insurance is fictional

Harbor · before the comparison

Bring in the policy you already have

Teresa Vance · quote HQ-4471-2209 · price shown, nothing paid

Why Harbor is asking

Harbor cannot tell you whether this quote is better or worse without the policy you hold. You can stop here and buy without it. Harbor will say the comparison did not run, rather than imply the two are the same.

Two ways in. Neither is preferred.

Sign in to your current insurer

Under a minute. Harbor receives the coverages, the limits, the deductibles and the term, already structured.

Harbor never sees your password. The connection is read-only and Harbor closes it when the comparison is computed.

Or add a photograph of your policy summary

Slower, and it reads less. Photographs of the page your insurer mails lose lines Harbor would otherwise match — and Harbor will name every line it could not read rather than dropping it.

Stored until the comparison is computed and deleted on a date Harbor states to you in writing.

Both controls carry equal weight and neither is pre-selected. In this demonstration they are inert.

◆ What came back

Read from your insurer, printed as your insurer prints it

Harbor does not re-title your insurer, renumber your policy, or round your dates. If any of the four lines below is wrong, the comparison is wrong, and you should stop.

Insurer
Meridian Mutual Insurance Company
Policy
4471–22–09
Term
3 Mar 2026 – 3 Sep 2026
Read at
· connection closed 14:04

Six coverages matched, in both sets of words

Your insurer and Harbor do not use the same terms. Matching them is the work, and Harbor shows you both sides of every match rather than quietly picking one.

Printed on your documentPrinted by HarborMatched
Uninsured/Underinsured Motorist Bodily InjuryIf the other driver has no insuranceYES
Bodily Injury LiabilityIf you injure someoneYES
Collision — ACV less deductibleDamage from a crashYES
Comprehensive — ACV less deductibleDamage that is not a crashYES
Property Damage LiabilityIf you damage someone’s propertyYES
Medical PaymentsYour own medical billsYES
⋯ Two lines Harbor could not place2 lines · ceiling is 5
  1. Loss of Use — $30 per day, 30 days maximum

    Harbor has no coverage this maps to. It is named here in your own printed words rather than dropped, and it is excluded from the comparison rather than counted as absent.

  2. Amendatory Endorsement A264 (02/22)

    A form number with no printed meaning on your summary. What it changes lives in the policy contract, which Harbor does not have. Harbor cannot tell you whether it matters, and says so rather than guessing.

Two is under the ceiling of five, so the comparison runs and these two travel with it. Above five, Harbor withholds the comparison entirely — that is state C.

FIG. 00 — INTAKE. Two routes, neither preferred. Four identity lines printed as the insurer prints them. Six matches shown in both vocabularies, because the matching is the product. Two refusals named rather than dropped, and the ceiling that decides whether the comparison runs at all.

02

The surface.

Three states, three synthetic households, one design language. Switch between them with the controls below. All three are always here in the page itself — the controls set and clear the hidden attribute and do nothing else. Nothing on this page is generated from a script. A reader with no JavaScript, and any machine fetching the raw HTML, sees all three in full.

With scripting off, or with this page printed, all three states render one after another. The controls above are the only script on this page.

STATE A · headline: diffSYNTHETIC HOUSEHOLD 1 · SPRINGFIELD, MO
Demonstration — invented policy dataHarbor Insurance is fictional

Harbor · comparison before you buy

The policy you hold, set against this quote

Teresa Vance · quote HQ-4471-2209 · prepared

◆ Decision due

A decision is open on this quote until .

If nothing is done by that date, Harbor re-rates the quote and this comparison is computed again from the current price. Harbor takes no payment and starts no policy by default.

All three controls carry equal weight and none is pre-selected. In this demonstration they are inert.

What this does not tell you

This compares how much you are covered for, how much you pay first, and the price. It does not read the small print. Two policies with the same numbers can still cover different things.

The price difference, six months

Δ −$420.00

−$840.00 a year

This quote is $420 cheaper over six months. Here is what the lower price is buying you.

If the other driver has no insurance

Not on this quote
You save$192a year
You would cover yourselfup to $250,000if it happens

Your policy today pays if someone hits you and has no insurance. This quote does not include that at all.

If you injure someone

Big drop
You save$188a year
You would cover yourself$150,000 moreper person hurt

Your policy pays up to $250,000 per person. This one stops at $100,000. Above that, you pay.

Damage from a crash

You pay more first
You save$218a year
You pay first$500 moreevery claim

What you pay before coverage starts goes from $500 to $1,000. One claim cancels out two years of the saving.

Damage that is not a crash — theft, hail, fire

You pay more first
You save$174a year
You pay first$500 moreevery claim

The same change again: $500 becomes $1,000 before anything is paid.

If you damage someone’s property

Halved
You save$64a year
You would cover yourself$50,000 moreif it happens

Cover falls from $100,000 to $50,000. Replacing someone’s car can pass $50,000.

Your own medical bills

Unchanged
You save$4a year
Coverthe same$5,000 per person

The only line where nothing was taken away.

Five of the six lines take away more than they give back. The price is lower. What it buys is lower by more. Both documents already carry every number above. Nobody puts them side by side before you buy.

See every number, exactly as both documents state them
Six coverages · six-month term · every figure per term and per year
CoverageYou hold — Meridian MutualThis quote — HarborDifference
Bodily injury liability $250,000 / $500,000$362.00 term$724.00 yr $100,000 / $300,000$268.00 term$536.00 yr Δ −$94.00 term−$188.00 yrmaterialThe limit on this quote is $150,000 lower per person and $200,000 lower per accident. Harbor does not pay above the limit.
Property damage liability $100,000$141.00 term$282.00 yr $50,000$109.00 term$218.00 yr Δ −$32.00 term−$64.00 yrnot material · 50.0%The limit on this quote is $50,000 lower. Harbor’s material test is a difference of more than 50%. This one is 50.0%, so it is not flagged.
Uninsured and underinsured motorist $250,000 / $500,000 · unstacked$96.00 term$192.00 yr ∅ Not covered$0.00 term$0.00 yr Δ −$96.00 term−$192.00 yrmaterialThis coverage is on the policy you hold and is not on this quote.
Medical payments $5,000 per person$38.00 term$76.00 yr $5,000 per person$36.00 term$72.00 yr Δ −$2.00 term−$4.00 yrnot materialThe limit and the kind of coverage are the same on both. Only the price differs.
Comprehensive $500 deductible$404.00 term$808.00 yr $1,000 deductible$317.00 term$634.00 yr Δ −$87.00 term−$174.00 yrmaterialOn this quote you pay $500 more of a comprehensive claim before Harbor pays anything.
Collision $500 deductible$511.00 term$1,022.00 yr $1,000 deductible$402.00 term$804.00 yr Δ −$109.00 term−$218.00 yrmaterialOn this quote you pay $500 more of a collision claim before Harbor pays anything.
Total, the six coverages Harbor compared $1,552.00 term$3,104.00 yr $1,132.00 term$2,264.00 yr −$420.00 term−$840.00 yr

Your policy summary states a term premium of $1,616.00 ($3,232.00 a year). Harbor compared $1,552.00 of it. The $64.00 difference is the rental reimbursement line above, which Harbor did not read.

Your copy of this comparison

This record is immutable. If Harbor corrects a mapping, Harbor creates a new record linked to this one and tells you; nothing here is edited. You keep it whether or not you bind.

Record
GET /diffs/dr_9fb31c04 · .html · .json · .pdf
Read from
Meridian Mutual Casualty · AM-6620-1148-03
Term on your document
–
You confirmed this reading
Extraction
docai-v2 · 2026.07 · all fields ≥ 0.90
Mapping / code / rules
2026.09.1 / 1.0.4 / 1.0.0
Your upload is deleted

5 endorsement forms on your policy summary that Harbor cannot read

PL 22 07MO 41 16Z-8840A-3157E-2207

Each of these changes the contract. They are not on the comparison above and Harbor is not in a position to tell you what they do.

FIG. 01A — STATE A. The quote is $420.00 cheaper for the term and removes uninsured motorist coverage entirely. The two facts are the same size.

FIG. 01B — STATE B. Harbor is $48.00 a year cheaper and the surface reports zero material differences, offers nothing, and stops contacting the shopper. This is the state that earns the meeting.

FIG. 01C — STATE C. Six refusals, each carrying the buyer’s own printed words. Naming what cannot be compared is the interpretation move; pretending it was compared is what the industry does today.

ONE THING THE RECORD FORCED, AND IT IS THE POINT

In state B, Harbor is cheaper and the surface still returns nothing. It then writes a suppression hold and stops contacting the shopper for eighty-four days. This is this idea’s success condition and Harbor’s revenue failure condition, on the same screen — the strongest objection raised inside the review itself, published and unpriced. Nothing in the design protects that screen from a conversion review. speculative

03

What the operator sees.

The numbers that show whether this screen is still being honest. Every number below is made up synthetic and is here to show how it would be watched, not to report a result.

Did the screen change what people did? We cannot tell yet, and that is the honest answer.
0%25%50%75%100%

23 people saw a difference big enough to matter. 7 of them changed what they were doing — about 30%.

But with only 23 people, the real number could be anywhere from 13% to 51%. That is the shaded band. It is too wide to mean anything.

Not enough people yet — so this reports nothing. We would need about 60. Lowering the bar to make a number appear would be cheating.

Does it ever come out against Harbor? This is the number that says whether the screen is honest.
Went against Harbor 61
Went against the other insurer 74

Out of 162 comparisons, the screen told people to stay where they were 14 times. It found against Harbor almost as often as it found against the competition. If that first bar ever went to zero, this would have quietly turned into a sales page — so it is counted, every day.

The test that would prove me wrong — 30-day readPB-08
Denominator, first — qualifying shoppers, shown at least one material difference23
Responders — changed their selection or abandoned the bind7
Observed share30.4%
95% interval13.0% – 50.9%
VerdictDID NOT RUN

Below about 60 qualifying shoppers the read reports did not run, and that is a real outcome. At n=23 the interval spans nearly 38 points; the test cannot distinguish its own pass from its own fail. The threshold is not lowered to fit the sample. Did not run says Harbor could not generate enough of the traffic its own thesis depends on — which is worth knowing faster than a number that flatters twenty-three people.

A13 — the null resultPB-06
Interpretations produced, 30 days162
Null results returned14
As a proportion8.6% trend, no target
Daily canary, last runPASS 06:00Z
Material differences adverse to Harbor61
Material differences adverse to the incumbent74

No ratio target is set here, deliberately. Taste refused to invent one; Frequency did not set one; this phase does not either. The only failable condition the record supports is zero in thirty days, which requires a written finding with three named causes and no fourth. The two adverse counts are published side by side, because a surface whose differences run overwhelmingly one way is either serving a real distribution or is broken.

Limits of flowPB-01 · PB-02 · PB-05
Manual keying, share of uploads cap 10%3.1%
Refusals per diff, mean ceiling 51.3
Diffs withheld at the ceiling9
Material disputes per 100 diffs suspend at 30.6
Misrepresentation register entries0
advice-lint failures reaching production0
Build-order gate (AT-3), last deployPASS
The Asymmetry Ledgerdeclared · no rows
decision_touches, rolling 90 days0
collections_touches, rolling 90 days0
Channels per side— / —
Automated sequences per side0 / 0

Zero over zero is the true value, and it is a limit worth stating rather than hiding. This surface serves a shopper, who holds no Harbor policy and therefore has no policy term to count touches against. The ledger’s first row arrives when Harbor’s first bound policy reaches its first billing event. The Taste contract set a test — “if Resonance produces an interface without an Asymmetry Ledger, §5 was prose” — and the honest verdict is partial: the counter is built and reads zero for a structural reason. What that test was really asking is whether §5 survives a roadmap, and that cannot be answered until Harbor has a book. AT-3, the clause that does the work, is enforceable today and is in the deploy gate.

04

What this does not do, and what is still open.

Permanent limits

  • It cannot read the policy form. Exclusions and endorsements live in a contract the buyer does not have. Two policies whose declarations agree can cover different things. The statement is on every state and it is not dismissible — and the form numbers are named, in mono, individually countable, which is more than a form number has ever been given to a buyer before.
  • It answers a narrower question than the evidence that justifies it. The two sources behind this wedge — an adjuster of forty years and a multi-policy buyer — were describing forms. This is a declarations product. That overreach was caught inside the run and corrected in place.
  • It is auto only, direct channel only. Home has one data point in the record and it is inertia. Anyone with a broker is conceded, itemised as six costs, and not pursued.
  • It never tells anyone what to buy. Not a limitation to be fixed later. It is the line the product is built against.

Open, with an owner

  • D-004 — ruled 10 September. Showing the difference before someone buys is the brief’s §03. The customer-owned record that survives the transaction is the company behind it, stated in the open and deliberately unclaimed until the test in §03 earns it. This page builds the first move, and three alternatives were drafted independently and set aside against the same four tests.
  • D-010 — whether the nine-question interview is lawful inside the quote flow. One call to an insurance lawyer. The diff consumes no interview output either way, which is what makes both answers buildable.
  • D-011 — whether adjacency is a recommendation, per state. Held as configuration, not design. Conservative stands until counsel answers, and there is no timeout that resolves a legal question.
  • D-013 — where sixty qualifying shoppers come from, for a insurer with no book. The instrument reports did not run rather than pretending.
The strongest argument against this surface, and it came from inside the reviewOPEN · UNPRICED

The test counts people who walked away as evidence the mechanism works. A13 requires the surface to tell people to stay where they are. The suppression rule then forbids following up on the people it told to stay. So this surface succeeds by losing sales, and the team that owns it is measured on a number that reduces the company’s revenue.

Two defences exist and both are weak. Harbor commits in writing to the renewal diff before it has a book, when the commitment is free — which makes reneging visible. The null result is counted in production — which makes its disappearance detectable. Neither is a mechanism. Both are tripwires, and a tripwire tells you the thing was killed without stopping the killing.

The launch plan answers it with a withdrawal condition rather than a control: any change to the null path, the suppression hold, the material definition, the refusal ceiling or the adverse-direction reporting whose justification cites conversion is an operator ruling with a name and a date — and if it is approved, the surface is withdrawn and renamed and the claim is retracted in public. The failure mode this guards against is not deletion. It is a surface that keeps its name and loses its property, which is exactly what both observed insurers did with the coverage calculator they built and then placed outside the flow. speculative

TWO THINGS THIS PHASE CAUGHT UPSTREAM

1. The invented 20% was not gone when this page was written. The gate record said the test that would prove me wrong’s unevidenced threshold had been removed earlier. It had been removed from the specification and it survived in the working instructions that operate it, tagged as inherited from a document that no longer contained the figure — two documents from the same stage disagreeing about the only real test this work has. It has since been fixed in both, and in the port manifest where a later check found a third copy. The decision table now has no threshold at all: it compares against a no-diff control, because no threshold is defensible. This paragraph is left standing, corrected, rather than deleted — the catch is the point, and a self-catch that quietly disappears once it is fixed is not a record.

2. Two artifacts give different instructions about what the open legal question blocks. The specification makes the whole channel contingent on it — “illegal, not clever”. The working instructions, written later, make only the interview module and the strength of the claim contingent, and says the diff is unchanged under either answer. The specification was corrected for a different defect later and this divergence was not folded in at the same time.

05

How it holds up.

The schema it is built on, where the advice line is enforced, and the checks run against what was actually built — open the ones you want to push on.

The typed schema — and the three states as JSON
·

The typed schema.

The renderer accepts these shapes and nothing else. There is no free-text field, no recommendation field, no score, no rank and no pre-selected default anywhere in the output. That absence is the first place the advice line is enforced, and it is the only one that survives a team that stops caring: an engineer cannot ship “you should raise this limit” as a bug, because there is no field it fits in.

// define/SystemArchitecture.md ss3.4 — the diff output, verbatim type CanonicalCoverage = | 'bi-liability' | 'pd-liability' | 'um-uim' | 'med-pip' | 'comprehensive' | 'collision'; type DiffLine = { // the ONLY shape the renderer accepts canonical: CanonicalCoverage; held: { limit: string | null; deductible: string | null; premium_cents: number | null }; quoted: { limit: string | null; deductible: string | null; premium_cents: number | null }; delta_cents: number | null; material: boolean; // present/absent, or >50% on a limit or deductible comparable: boolean; // false => both sides stated, no delta computed }; type Refusal = { // first-class output, never an omission printed_term: string; // verbatim, from the buyer's own document reason: 'unmapped' | 'out-of-scope-coverage' | 'kind-mismatch' | 'structure-mismatch' | 'unreadable'; reason_text: string; // fixed enumeration; never a runtime string }; type DiffRecord = { id: string; shopper_id: string; quote_id: string; extracted_policy_id: string; mapping_version: string; code_version: string; rules_version: string; lines: DiffLine[]; refusals: Refusal[]; headline: 'diff' | 'null' | 'refusal'; created_at: string; immutable: true; // corrections create a NEW record }; // headline classification is a rule, not a judgement: // if any(refusals) -> 'refusal' // never claim "nothing differs" // else if any(line.material) -> 'diff' // else -> 'null' // TasteContract A13

FIG. 02 — THE BLOCKED CONSTRUCTION. No recommendation, no suggested_limit, no score, no rank. The schema is the enforcement.

Each state above carries its record as structured data in this document. A machine reading the raw HTML has all three without executing anything. The design rules require that five questions be answerable from the structured representation alone — what changed, by how much from what, what is not covered, what decision is due and by when, and what happens if nothing is done. Every block below carries all five as named fields.

FIG. 02B — THREE RECORDS, EMBEDDED. In state C the first three answers are null, and the record says explicitly that a null there means Harbor did not answer — not that nothing differs. That distinction is the whole refusal design.

Where the advice line is enforced, and it is not in the copy
·

Where the advice line is enforced, and it is not in the copy.

Recommending a specific coverage level to a specific person is a licensed activity in every US state. Every output on this surface is a statement of consequence and never one of preference. “This policy’s liability is $50,000. Yours is $100,000.” Never “you should keep $100,000.”

Enforced in this markup4 points
The schema
No field carries an ought. Verify against §02.
PRESENT
No ranking, score or highlight
No row is emphasised as the better option. State chrome marks changed, not worse.
PRESENT
No pre-selected default
Three controls, identical weight, none selected. The declining control is not secondary.
PRESENT
No customer financial attribute anywhere
R1.c is a field-pair blocklist, not a word list. No assets, loan balance, vehicle value or savings figure appears on any state.
PRESENT
# the configuration that keeps D-011 buildable both ways # owned by the Compliance Reviewer, code-owner rule on the file r1c_mode: conservative # the only value shipped r1c_blocked_field_pairs: - [coverage.limit, customer.assets] - [coverage.limit, customer.loan_balance] - [coverage.deductible, customer.liquid_savings] # if counsel rules permissively in state X: # r1c_mode: counsel-ruled-<state>, named pairs unblocked # if counsel rules restrictively: the list widens # if counsel never answers: conservative stands indefinitely. # There is no timeout that resolves a legal question. # In every case the diff, the null path, the evidence store # and the counters do not move. Adjacency is config, not design.

FIG. 03 — D-011 IS OPEN AND BOTH ANSWERS STAY BUILDABLE. This page does not resolve it and does not need to.

THE ONE STRING THAT IS NOT ON THE SURFACE, AND WHY

When advice-lint blocks a rendered line, the line is replaced with “Harbor cannot show this line” and the failure is logged with the template ID. The lint is fail-closed: with the lint service stopped, nothing renders. That placeholder does not appear on any of the three states above, because nothing on them was blocked. Showing a blocked line here to demonstrate the mechanism would be staging a failure that did not happen, which is the class of thing this whole surface exists to refuse.

Composition test — every element traced to a declared capability
·

Composition test.

Every element of the surface traces to a capability declared in CapabilityMap.md §2 (owned) or §3 (rented). An element needing anything from §4 is a Stability gap and is not built.

Interface elementCapabilityKindTraced
Confirmed-extraction strip — insurer printed verbatim, policy number, term, confirmation timestampdec-page-intakeownedYES
OCR provider and version; the “we cannot read documents right now” fallbackocr-extractionrentedYES
Upload receipt with a server-side deletion datedocument-storagerentedYES
Shopper session and quote identity on the recordidentity-authrentedYES
Canonical coverage labels; mapping version stampcoverage-matchingownedYES
Refusal block — verbatim printed terms, fixed reasons, ⋯ glyphnamed-refusalownedYES
The ledger table, the material flag, both units on every figurecoverage-diffownedYES
The null headline at full weight; the canary badgenull-resultownedYES
The absence of any free-text, score, rank or pre-selected defaultadvice-line-lintownedYES
Record address, version stamps, the immutability statementdiff-evidence-recordownedYES
html · json · pdf triple; data-state; <data> and <time>; the embedded recordsmachine-readable-recordownedYES
The suppression notice on state B — hold written, expiry, no liftsolicitation-suppressionownedYES
The decision block — consequence class, deadline, default, equal controlspolicy-event-modelownedYES
Operator panel — decision against collections touchesasymmetry-ledgerownedYES
Operator panel — the deploy-gate resultautomation-registry-gateownedYES

FIG. 05 — 15 ELEMENTS · 12 OWNED AND 3 RENTED CAPABILITIES · 0 BUILT ON ANYTHING UNDECLARED · TWELVE OF TWELVE OWNED ARE TRACED.

What was designed and then not built.

Element consideredCapability it needsState in CapabilityMap §4
A named boundary case on the liability line — “a case this decides: a storm drops a tree…”, exactly as the Taste contract renders it on an on-brand buying surfaceboundary-case-libraryDEFERRED — boundary cases are underwriting output, and underwriting is out of scope by the assignment
Prefilling the held coverage with no upload at allcoverage-connectAVAILABLE — AND I HAD THIS WRONG — consumer-permissioned insurance rails reach most of the US market off a sign-in the customer performs. I recorded it as out of reach when this surface was built on 9 September, and found out otherwise on the 17th. What it changes is the intake step, not the comparison: connecting becomes the path and the upload becomes the fallback, and what arrives is the same coverage either way. Named and sourced in the landscape scan. The surface below still shows the upload flow, because that is what was built.
Comparing the endorsement forms rather than naming themform-and-endorsement-comparisonOUT OF REACH — named on every state as a permanent limit instead
A “compare this again at my renewal” controlrenewal-diffUNAVAILABLE — Harbor has no book. The commitment is stated in writing; no control is rendered, because a control implies a capability

THE ONE I WANTED MOST

The boundary case was drafted, and then removed. It is the single most persuasive thing that could have gone on that screen — a real claim, decided one way by wind and the other way by lightning, sitting next to the liability limit. It requires a case a Harbor underwriter has ruled on, and there is no Harbor and no underwriter. Rendering an invented one would have been the most convincing lie on the page. A12 is therefore marked FAIL on this surface, in the checks below, rather than satisfied by fiction.

A CAPABILITY THE MAP DID NOT DECLARE — AND THE RULING THAT FOLLOWED

This phase reported that the not-asked disclosure had no owner. The configuration Harbor ships is interview_placement: outside_flow, the working instructions required the flow to state what Harbor did not ask, and no declared capability rendered it. It was reported as a gap rather than invented, and this surface did not build it.

The gap turned out to be in the criterion, not the build. A7 was drawn from a true observation about two insurers — both park their coverage questionnaire outside the quote — and then written as a rule binding Harbor. This surface asks no needs questions at all; it reads a document the buyer already holds. A7 was governing a capability the diff does not use, so it has been re-scoped to needs-collection surfaces and is N/A here.

Left standing rather than deleted. The catch was correct and the resolution was not the one it expected — which is worth more on the record than a panel that quietly disappears once the thing it caught is settled.

Acceptance checks, marked against what was actually built
·

Acceptance checks, marked against what was actually built.

Nothing below is marked pass that was not built. Seven of the thirteen architecture criteria describe backend behavior that a single HTML file cannot have, and they are marked NOT BUILT, which is a different and more useful statement than a green tick.

Architecture acceptance criteria — SystemArchitecture §11

CriterionVerdictEvidence, or what is missing
1 · An unconfirmed extraction cannot reach the diff engine, enforced by a required fieldNOT BUILTNo engine. The confirmation timestamp is present and populated on all three records
2 · Every printed term that does not map appears verbatim, with a reason. Zero silent dropsPASS7 refusals across states A and C, each verbatim with a fixed enumerated reason
3 · A held PIP line against a quoted MedPay line produces a refusal, never a deltaPASSState C, refusal 1
4 · The null test account returns a null headline through the production path, dailyNOT BUILTThe canary badge in the operator section is a synthetic status. A canary that runs in production is not a thing a page can contain
5 · A comparison containing any refusal never renders a null headlinePASSDemonstrated on all three: A has a refusal and a diff headline, B has none and the null, C has six and the refusal headline
6 · advice-lint fails closed: with the service stopped, no interpretation rendersNOT BUILTNo lint service. The four enforcement points are described in the checks below; only the first (the schema) is structurally present here
7 · No field in the output schema can carry a recommendationPASS§02. Asserted by inspection on this page; the criterion asks for a schema test, which is not built
8 · A null result produces zero marketing or collections sends until expiryNOT BUILTThe hold is stated and carried in the record. No outbound service exists to be suppressed
9 · Any record recomputes byte-identically from its version stampsNOT BUILTStamps are present and correctly shaped; nothing recomputes
10 · CI fails on a collections automation with no live decision counterpartNOT BUILTNo CI. The gate result is shown as a synthetic row in the operator section
11 · Every published diff answers the five agent questions from JSON alonePASSAll three embedded records carry an answers object with all five as named fields
12 · Every currency figure carries both units and is decimal-alignedPASSEvery premium, total and delta renders per term and per year, tabular and right-aligned, at the same type size. See the reading declared below
13 · A mapping added without a source document fails the buildNOT BUILTNo build, no mapping table

6 PASS · 7 NOT BUILT · 0 FAIL. A static page can satisfy the rendering criteria and cannot satisfy the enforcement ones, and saying so is the point of the column.

Design conformance — the ten checks a reviewer runs, in order

CheckVerdictNote
1 · Grayscale renderRUNNABLE, NOT RUNEvery state carries colour, a literal text label, a glyph and a rule treatment. Designed to pass the four-channel rule; not put through a grayscale render
2 · Glyphs removedRUNNABLE, NOT RUNNo glyph appears without its label in the same cell. Delete every Δ, ◆, ∅ and ⋯ and the words remain
3 · Plain-text extraction, five agent questionsPASSAnswerable from the three embedded JSON records with no rendering
4 · Figure alignment — tabular, decimal-alignedPASStnum and lnum on every figure; right-aligned; two decimals throughout, so columns align on the decimal
5 · Delta size — a change never smaller than the number it modifiesPASSDifference column at 14px against a 14px number; the headline delta at 34px against a 26px sentence
6 · First paint — no consequential element animates inPASSThere are no transitions and no animations on this page at all. The motion budget is unspent, which is the strongest form of M1
7 · Refused-word grepPASSRun over the Harbor surface strings and over this commentary. None of the §9.2 list appears, in either place
8 · Passive grep — Harbor hidden as the actorPASSHarbor read, Harbor refused, Harbor withholds, Harbor has recorded, Harbor sends nothing. Named and active throughout
9 · Unit parity grepPASS, with a reading declaredA9 governs premiums, savings and changes. Every one carries both units at the same type size. Limits and deductibles are neither, and carry no annual counterpart — $250,000 of liability is not a per-term figure. Stated here rather than assumed silently
10 · Print at US LetterPARTIALPrint rules written: single column, all three states unhidden, controls suppressed, the decision block inverted to a 2px ink border with a solid ink header band, mono identifiers held at 14px. Not tested on paper

Taste criteria that bear on this surface

CriterionVerdictNote
A13 · The null result is a first-class outputPASSState B. Headline, at 34px, reachable without the shopper declining anything, with a production count in the operator section
A2 · No supersession without a diffPASSThis surface is the diff. Held and quoted are both present on every line; column three is never empty
A4 · Every published document is machine-readablePASSReal text, semantic table with th scope, structured record at the same address. The PDF representation is named and not built
A6 · Specificity allocated by consequence, not by easePASSLiability carries the most specific numbers on the surface. No coverage carries a placeholder in place of a limit
A8 · Symmetry of self-servicePARTIALThe declining control sits at equal weight with the binding control, which is the part this surface can satisfy. Click-count parity across add, reduce and cancel is a policy-management property and is not testable here
A9 · Unit parityPASSWith the reading declared at check 9 above
A7 · What determines the answer sits where the question is askedN/AAmended and re-scoped after this page was built (D-015). A7 was derived from a true observation about two insurers — both park their coverage questionnaire outside the quote — and then written as a rule binding Harbor. This surface asks no needs questions at all; it reads a document the buyer already holds. A7 binds needs-collection surfaces and does not reach this one. It was marked FAIL here rather than papered over, and the correct resolution turned out to be that the criterion was mis-scoped, not unmet
A12 · A named boundary case at the point of descriptionFAILboundary-case-library is deferred. Rendering an invented case would have been the most convincing lie on the page
R1 a, b and c · the advice linePASSNo directive verb applied to a coverage choice; no sentence that would change for a different reader and also carry a directive; no customer financial attribute anywhere, so no adjacency pair can form
R6 · No selling in the frame of an unresolved decisionPASSState B offers no Harbor product in the frame of the null result, and follows it with a suppression hold rather than an offer
R7 · No product-demand launderingPASSNo claim anywhere about how Harbor customers behave. Harbor has none
R9 · Nothing Harbor cannot substantiate from the customer’s own recordPASSEvery figure derives from the uploaded document or from Harbor’s own quote. No third-party inference appears

One conformance item this build closed

Design open item 2: “State colours are not yet contrast-verified against color.paper… #8A5A00 on #FBFAF8 is the one most likely to fail. Verify before any of these values reach a stylesheet.” They reached a stylesheet, so they were verified.

TokenValueContrast on #FBFAF8AA, normal text
color.ink#14181C17.4 : 1PASS
color.state.changed#1B4F9C7.6 : 1PASS
color.state.lapsed#A11B1B7.5 : 1PASS
color.state.expiring#8A5A005.7 : 1PASS
color.muted#5F65705.6 : 1PASS
color.state.decisionpaper on ink17.4 : 1PASS

FIG. 06 — THE ONE FLAGGED AS MOST LIKELY TO FAIL DOES NOT FAIL. Design open item 2 closes. Items 1, 4 and 5 remain; item 3 closed earlier.