{
  "artifact_id": "neurobrick-system-review-2026-10-01",
  "observed_at": "2026-10-01T10:14:14+09:00",
  "inspection_window": "1 October 2026 · 10:13–10:14 KST",
  "scope": "Read-only inspection of the known operating fleet. Point-in-time internal disclosure, not live telemetry or independent attestation.",
  "inventory": {
    "compute_hosts": 7,
    "storage_appliances": 1,
    "execution_systems": 3,
    "mesh_registered": 9,
    "mesh_online": 9,
    "control_plane_containers": 7,
    "apple_silicon_installed_memory_gib": 224,
    "ci_vms_running": 3
  },
  "counting_boundary": "Seven compute hosts were accessed: the control host locally and the others over SSH. One NAS was observed through shares mounted on both Apple Silicon hosts. The mesh count is network identities: nine registered, nine online. It includes client devices and machines that are not part of the operating fleet. The seven containers are the running database, cache, metrics and log services of the control stack on one host; the control-plane service answered its health endpoint and is not one of them, and a separate second container stack on that host is not counted. Three running Linux CI guests were observed; other running Linux guests were not established as CI runners and are not counted. Containers, VMs and logical execution systems are not additional physical boxes. This is the known inspected fleet, not a discovery proof for every device.",
  "hosts": [
    {
      "role": "Control & development",
      "count": 1,
      "evidence": "The comparison that produced this review ran on this host and reached all seven compute hosts.",
      "boundary": "Reachability is not health. The local container engine was not inspected in this window."
    },
    {
      "role": "Research & primary execution",
      "count": 1,
      "evidence": "Remote runtime inspection found two primary trader, one extended-hours trader and one order-enforcer processes running. The decision lineage index was built at 07:11 KST on 30 September; separately, the latest readiness run finished its data-panel lineage check at 09:57 KST on 1 October.",
      "boundary": "Process presence does not prove every strategy is armed or orders have filled."
    },
    {
      "role": "Local inference & Linux CI",
      "count": 1,
      "evidence": "Remote inspection: the two Apple Silicon hosts carry 224 GiB of installed memory together, and the Linux CI guest on this host was running.",
      "boundary": "Inference generation, model residency and distributed inference were not tested in this window."
    },
    {
      "role": "Domestic rotation execution",
      "count": 1,
      "evidence": "Scheduled rotation task: last run 09:05 KST on 1 October, result 0. The seven support containers of the control stack were running on this host.",
      "boundary": "Scheduled-task completion is not broker reconciliation and does not establish that the rotation lane is placing live orders."
    },
    {
      "role": "Multi-account execution",
      "count": 1,
      "evidence": "Scheduled account worker: last run 10:12 KST on 1 October, result 0.",
      "boundary": "A worker result does not establish every account or strategy is eligible."
    },
    {
      "role": "Fleet observation",
      "count": 1,
      "evidence": "Deadman watch: last run 09:00 KST on 1 October, result 0. Daily scan: last started 08:00 KST on 1 October; the task was Ready at inspection.",
      "boundary": "Scheduler records do not independently validate report contents or full fleet coverage."
    },
    {
      "role": "Windows / WSL CI",
      "count": 1,
      "evidence": "Remote host reachable; three self-hosted runner services were running.",
      "boundary": "Running runner services do not establish job success."
    }
  ],
  "systems": [
    {
      "name": "NeuroPublic",
      "role": "Research, market data and primary execution",
      "detail": "A research and execution environment with domestic and US trader processes and separate order enforcement. Data readiness and strategy promotion are separate gates."
    },
    {
      "name": "KR Rotation",
      "role": "Independent domestic execution",
      "detail": "A dedicated scheduled domestic rotation engine with its own execution and account boundary."
    },
    {
      "name": "NeuroForAll",
      "role": "Multi-account execution",
      "detail": "An account-scoped execution platform with scheduled workers and separate account contexts."
    },
    {
      "name": "Control Plane",
      "role": "Control and evidence integration",
      "detail": "A separate coordination layer supplying state, release controls and evidence services. It is not counted as a fourth independent execution system."
    }
  ],
  "capabilities": [
    {
      "title": "Operate separate execution paths",
      "evidence": "Three execution systems across separate hosts",
      "detail": "Primary research and execution, domestic rotation and multi-account workers are distinct systems on separate hosts.",
      "boundary": "An operating process or successful scheduled task does not prove a filled order or current strategy eligibility."
    },
    {
      "title": "Keep release permission explicit",
      "evidence": "Approval axis open · kill switch ARMED · release authority not read",
      "detail": "The control plane reports its approval axis as open: an approval that the live-execution safety gate requires is granted. The health endpoint does not say which approval. A flag trace on 27 September 2026 found operator approval granted and both autonomous-release opt-ins off, and the owner confirmed on 28 September 2026 that the approval is intended. The release-authority artifact sits behind an authenticated endpoint and was not read.",
      "boundary": "The approval-axis value is a summary the health endpoint derives from the control plane's approval settings; no order is admitted or refused by reading that summary. It belongs to the control plane, not to the independent engines."
    },
    {
      "title": "Reject unsuitable research inputs",
      "evidence": "1 October, 09:57 KST run · data-panel lineage check exit 2",
      "detail": "Nine of nine price prerequisites passed; 17 of 42 factor checks failed (observation contract failed 9; price-parent snapshot mismatch 6; missing point-in-time provenance 2). No research-observation start was recorded. The readiness run is scheduled; these are the figures of its latest receipt, whose event chain (each event's hash recomputed) and output hash were checked before counting. The hashes are unkeyed and written on the same host, so they detect accidental damage, not a deliberate rewrite.",
      "boundary": "This is one specified input set. It is not a fleet-wide failure rate or proof that all trading stopped."
    },
    {
      "title": "Produce operating evidence",
      "evidence": "Lineage index last built 07:11 KST on 30 September · NAV and margin state files read",
      "detail": "The latest completed build held 112,812 nodes and 34,405 links between them, totals over the ledger files the build read rather than one day's additions. The NAV state file had been rewritten within the last 30 minutes, every venue reported an empty error list, and the file did not mark its value stale. The margin state's alert flag was off; this review reads only that flag and does not confirm the margin calculation had its inputs. No balance or account identifier is read or published.",
      "boundary": "A built index is an instrument, not a linkage result. Freshness and empty error lists do not establish accounting correctness."
    },
    {
      "title": "Support research and delivery",
      "evidence": "Three running Linux CI guests · three runner services",
      "detail": "Inference, shared data, Linux CI guests, runner services and NAS-backed storage support the execution systems.",
      "boundary": "CI job acceptance, inference output quality and full clean-box recovery remain separate verification work."
    },
    {
      "title": "Carry one identifier along the decision path",
      "evidence": "Broker-accepted stock orders carrying a decision identifier 0 of 772 · gate-check lines joined to an order attempt by attempt identifier 297 (lines read; an archive copy counts again)",
      "detail": "Some stock-order producers mint a decision identifier before placement; others whose orders are among the 772 send orders without one. The executor copies any identifier it receives onto the pre-trade gate record and the order record; no gate logic reads it. None of the 772 stock orders the brokerage accepted in the ledgers read (29 May to 30 September), Korean or US listing, carries one; the index does not show how many came from a minting producer after it began minting. A separate spot accumulation job on a non-stock venue, whose orders are not among the 772, has a launch configuration that names a release dated 15 September; that release predates the change that gave the job its own decision identifier, so its orders cannot carry one until the job runs a newer release. Zero of the 34 accumulation ledger lines the index read carry one (an archive copy counts again). A fixture test writes a decision identifier by hand onto one made-up sell order and drives that sell through the realized-outcome writer and the index build: the index turns the order's identifier into a decision node linked to that order, and the order joins the realized row by its order number. The test does not exercise the step that puts the identifier on a real order.",
      "boundary": "The fixture proves the join from an order that already carries an identifier to its realized row; it does not prove that real orders get stamped, and it is not an operating result. No realized outcome of a stock order is yet linked to a decision identifier."
    }
  ],
  "authority": [
    {
      "title": "Central operating state",
      "state": "APPROVAL AXIS OPEN",
      "detail": "The control-plane health endpoint answered, reporting its approval axis open and the kill switch ARMED. Its database, cache and core probes were not read by this inspection.",
      "boundary": "HTTP availability is not business readiness. The approval-axis value is a summary the health endpoint derives from the control plane's approval settings; no order is admitted or refused by reading that summary. The kill switch is reported separately. When the approval was last granted was not observed."
    },
    {
      "title": "Central live release",
      "state": "NOT READ",
      "detail": "The release-authority artifact is served behind an authenticated endpoint and was not read in this inspection.",
      "boundary": "Absence of a reading is not a permission and not a block."
    },
    {
      "title": "Strategy promotion evidence",
      "state": "WITHHELD",
      "detail": "Zero strategies held promotion authority in the stock-strategy evidence state. The latest auto-promotion pipeline row had zero eligible candidates, and the stock promoter's apply status was disabled.",
      "boundary": "This is a specific promotion pipeline, not a verdict on every existing trading strategy."
    },
    {
      "title": "Local execution boundaries",
      "state": "PATH-SPECIFIC",
      "detail": "Independent execution engines retain their own permissions, account contexts and gates.",
      "boundary": "The inspection did not re-census all authority surfaces or prove one universal actuator gate."
    },
    {
      "title": "Inter-host access gates",
      "state": "ONE SET TO DENY · ONE SET TO OBSERVE",
      "detail": "Two of the fleet's inter-host access gates were read. One's mode was set to deny, which by design refuses requests outside its allowlist; the other's was set to observe, which by design records a verdict and blocks nothing. Only the mode settings were read, not the gates' logs or individual requests, and this is not a full count of the fleet's access controls.",
      "boundary": "These gates bound machine-to-machine access. They are not trading authority and do not describe every inbound path."
    }
  ],
  "observation": [
    {
      "title": "Control-plane availability",
      "state": "ANSWERED",
      "detail": "The HTTP health endpoint answered at inspection. Its status field, HTTP code and deeper database, cache and core probes were not read."
    },
    {
      "title": "Decision lineage index",
      "state": "LAST RUN DID NOT BUILD",
      "detail": "Latest completed build 07:11 KST on 30 September; the most recent run, at 07:10 KST on 1 October, was refused by its free-disk floor, so these counts are from the completed build. Orders accepted on all venues that the index links to a research signal: 0 of 4,466. Only the 772 stock-brokerage orders have a rule that can link them, and that rule looks a signal up only in the current signal ledger, so a reference it cannot find there is unknown, not absent. Gate-check lines, counted per line read so an archive copy counts again: 297 carry the executor's attempt identifier, all joined to an order attempt; 15,319 carry none."
    },
    {
      "title": "Research readiness",
      "state": "STOPPED AT DATA-PANEL CHECK",
      "detail": "Scheduled run, latest receipt 09:57 KST on 1 October: 17 of 42 factor checks failed."
    },
    {
      "title": "Scheduled fleet observation",
      "state": "TASK RESULTS READ",
      "detail": "Deadman watch last ran 09:00 KST on 1 October with result 0. The daily scan last started 08:00 KST on 1 October."
    },
    {
      "title": "Observer independence",
      "state": "NOT RE-ATTESTED",
      "detail": "A separate observation host was reachable. Independence, complete scan coverage and the primary/fallback receipt chain were not re-attested in this inspection."
    },
    {
      "title": "Storage and recovery",
      "state": "MOUNTS OBSERVED",
      "detail": "NAS shares were mounted on both Apple Silicon hosts. A fresh fleet-wide clean-box restore was not performed."
    },
    {
      "title": "CI execution evidence",
      "state": "GUESTS AND RUNNERS RUNNING",
      "detail": "Three Linux CI guests and three runner services were running. This does not establish that CI jobs pass."
    },
    {
      "title": "Support services",
      "state": "DEGRADED IN PART",
      "detail": "Three containers of a separate support stack were unhealthy, restarting or still starting on the host that runs the control stack. The seven control-stack containers were up."
    }
  ],
  "limits": [
    "None of the 772 broker-accepted stock orders carries a decision identifier; no accepted order on any venue is linked to a research signal (0 of 4,466; only stock-brokerage orders have a rule that can link one); and no index rule yet records the authority behind a decision, so a governed decision cannot be counted. The research-to-authorized-execution-to-accounting path is not established.",
    "The latest research readiness run stopped at its data-panel lineage check with 17 of 42 factor checks failing, so no research observation started.",
    "No strategy holds promotion authority in the stock-strategy evidence state.",
    "The release-authority artifact was not read; this review makes no claim about central live release.",
    "Authority-surface attribution, replay equivalence and remediation-effect totals were not re-measured. August figures remain historical evidence.",
    "Observer independence and complete coverage were not re-attested. Scheduled-task success alone does not establish either.",
    "NAS mounts and running services do not establish a verified fleet-wide clean-box recovery or a reconciled formal close.",
    "Durable net performance and readiness for automatic capital expansion are not established by this public disclosure."
  ],
  "next_acceptance_conditions": [
    "Execute one bounded, owner-authorized sell order that carries a decision identifier, and observe its fill and its realized row joined to that order in the index, stating whether the row's cost is modelled or broker-reported.",
    "Bring the scheduled readiness run to a pass of its data-panel lineage check, which requires all 9 price and all 42 factor checks to pass.",
    "Give authority events their own identifiers so a governed decision can be counted, and read the release-authority artifact beside the approval axis."
  ],
  "readiness_case": {
    "executed_at": "2026-10-01T09:57:23+09:00",
    "price_passed": 9,
    "price_total": 9,
    "factor_failed": 17,
    "factor_total": 42,
    "lineage_exit_code": 2,
    "observation": "No start or completion event recorded",
    "boundary": "One scheduled readiness run and its specified input set, read from its receipt. Counts are not a fleet-wide failure rate. This concerns the research observation stage and does not establish that all live trading was blocked.",
    "failure_categories": [
      {
        "reason": "observation contract failed",
        "count": 9
      },
      {
        "reason": "price-parent snapshot mismatch",
        "count": 6
      },
      {
        "reason": "missing point-in-time provenance",
        "count": 2
      }
    ]
  },
  "publication_boundary": "Capital-redacted internal inspection. Excludes balances, account identifiers, secrets, raw hostnames, addresses and private configuration. Checksums identify the public files, not independently reproduced private runs.",
  "development_scope": [
    {
      "state": "Operating",
      "title": "Execution and supporting services",
      "detail": "Existing proprietary-capital execution systems, observation and infrastructure have operating evidence. This does not establish that every strategy is active or every integration is accepted."
    },
    {
      "state": "Under validation",
      "title": "A unified research-to-evidence path",
      "detail": "A daily lineage index (latest completed build 30 September) measures the path and a scheduled readiness run gates its first stage. None of the 772 broker-accepted stock orders carries a decision identifier yet, so no stock order links a decision to its accounting. A complete repeatable path is not yet established."
    },
    {
      "state": "Not established",
      "title": "Sustained economic validation",
      "detail": "This review does not establish durable net performance, readiness for automatic capital expansion or fleet-wide recovery. These require additional operational evidence."
    }
  ],
  "supersedes": "neurobrick-system-review-2026-09-30",
  "decision_path": {
    "index_build": "2026-09-30T07:11:11+09:00",
    "nodes": 112812,
    "edges": 34405,
    "gate_rows_linked": 297,
    "executed_orders_with_decision_identifier": {
      "n": 0,
      "N": 772
    },
    "executed_orders_linked_to_research": {
      "n": 0,
      "N": 4466
    },
    "fixture_proof": "A fixture test writes a decision identifier by hand onto one made-up sell order and drives that sell through the realized-outcome writer and the index build: the index turns the order's identifier into a decision node linked to that order, and the order joins the realized row by its order number. The test does not exercise the step that puts the identifier on a real order. Code path only.",
    "boundary": "Counts come from the ledgers of one host at one build. Fields named \"executed\" count orders the venue accepted, not orders filled. Blocked, dry-run and synthetic order rows are excluded and each order is counted once. The decision-identifier count covers stock-brokerage orders only; the research-linkage count covers all venues. The gate count is per ledger line and joins a gate record to an order attempt by attempt identifier, not by decision identifier."
  },
  "observed_states": {
    "nav_artifacts_ok": true,
    "margin_alert": false,
    "promotion_authority_granted": 0,
    "promotion_candidates_eligible": 0,
    "stock_promoter_apply_status": "disabled",
    "approval_axis": "OPEN",
    "kill_switch": "ARMED"
  },
  "observed_facts": {
    "primary_engine_processes": 4,
    "primary_trader_processes": 2,
    "extended_trader_processes": 1,
    "order_enforcer_processes": 1,
    "rotation_last": "2026-10-01T09:05:01+09:00",
    "rotation_result": 0,
    "worker_last": "2026-10-01T10:12:01+09:00",
    "worker_result": 0,
    "deadman_watch_last": "2026-10-01T09:00:01+09:00",
    "deadman_watch_result": 0,
    "daily_scan_state": "Ready",
    "daily_scan_last": "2026-10-01T08:00:01+09:00",
    "runner_services_running": 3,
    "support_containers_not_healthy": 3,
    "access_gate_primary_mode": "deny",
    "access_gate_secondary_mode": "observe",
    "accumulation_release_date": "2026-09-15T00:00:00+09:00",
    "accumulation_release_without_identifier": true,
    "lineage_gate_rows_read": 15616,
    "lineage_gate_rows_without_attempt_id": 15319,
    "lineage_gate_rows_attempt_id_unjoined": 0,
    "lineage_order_window_from": "2026-05-29",
    "lineage_order_window_to": "2026-09-30",
    "lineage_research_eligible_brokerage": 772,
    "lineage_accumulation_rows": 34,
    "lineage_accumulation_rows_with_identifier": 0,
    "lineage_last_run_at": "2026-10-01T07:10:00+09:00",
    "lineage_last_run_outcome": "refused by its free-disk floor"
  }
}
