# Validation report — v4.12.0

## v4.12 platform, conversation, and browser validation

- PASS — the final top-level fail-closed read-only PostgreSQL refresh completed at `2026-08-25T00:40:36.59826-04:00`; 22 accepted source objects were queried and `transaction_read_only=on` was validated.
- PASS — controlled direct-file browser snapshot was built from the matching validated refresh; no credential value is present in the report package.
- PASS — 10 static public pages plus 30 parameterized detailed routes rendered at desktop size; six representative routes rendered at mobile size.
- PASS — 30 current detailed routes, 39 preserved-original links, and all 38 unique preserved HTML targets resolved.
- PASS — each detailed route contains the direct answer, evidence, why-it-matters, limitations, next questions, parent/up/home orientation, and preserved-original layer.
- PASS — all public templates include Sherie's exact analytical-working-draft disclaimer; none uses `CivicSS®`; all use the restrained `CivicSS™` notice.
- PASS — no tested public UI uses “Hide,” no tested route overflowed horizontally, no title exceeded the restrained threshold, and the browser recorded zero console or page errors.
- PASS — all 62 conversation-to-report UAT rows are `PASS` or `PASS-CONTROL`; none remains open or pending.
- PASS — structural validation found 245 local references across the public templates and no missing target.
- PASS — the current root pointer was not advanced during construction or testing; after all functional controls passed, it advanced to the v4.12 directory and governed launcher. v4.11 remains untouched.

Browser evidence: `browser-validation-v4.12.json`. Structural validator: `source/validate_release_structure.js`. Browser validator: `source/validate_v4_12_browser.js`.

## v4.11 CNA narrow-projection adoption validation

- PASS — the supplied CNA 0359 safe default query executes in a read-only transaction and returns exactly 297 eligible rows.
- PASS — the accepted portfolio controls reproduce 17 property codes, 118 represented recommendations, years 2023–2031, $3,595,313.00 uninflated, and $4,125,992.55 study-inflated.
- PASS — the missingness control reproduces 151 `SOURCE_BLANK_NOT_ZERO` rows with 151 NULL monetary rows; no missing amount enters an aggregate.
- PASS — the containment control reproduces 438 quarantined recommendations, `study_wide_complete=false`, and `publishable=false`.
- PASS — every row retains the exact projection-only amount semantics; the application rejects a snapshot that weakens them.
- PASS — nine year aggregates and 17 property-code aggregates each reconcile back to the 297 eligible rows.
- PASS — the current route, connected reports, source inventory, adoption review, crosswalk, data assessment, and PMO register preserve the same reporting boundary.
- PASS — no CNA projection is added to current debt, current capital, actual spending, or household totals.
- PASS — the release retains all 38 unique preserved HTML targets; the new CNA route supplements its historical predecessor rather than deleting or replacing it.
- READ-ONLY CONTROL — every refresh begins with read-only controls and ends with `ROLLBACK`; no database state is changed.
- PUBLICATION CONTROL — this is a local development adoption only; no external publish or deployment occurred.

## v4.10 reader-path and resident-story validation

- PASS — all 29 catalog routes retain a category, direct answer, evidence layer, meaning layer, limitation layer, next questions, and at least one preserved original.
- PASS — all 38 preserved links remain unique and their targets exist inside the untouched v3.7.0 evidence copy.
- PASS — detailed reports declare Level 3 of 3, resolve their parent category, provide an up-one-level control, and provide a Whole Picture return. The report collection declares Level 2 of 3; the resident story identifies Level 2 and links to Level 1.
- PASS — the choices-ahead direct answer contains seven numbered choices and explicitly names the property-tax levy, next HWRSD budget, Middle School capacity, and BUC/Town buildings in the first four positions.
- PASS — both Whole Picture and the resident story show the DLS endpoints $6,880 and $8,186 and the exact $1,306 subtraction beside the headline measure.
- PASS — the resident chart explicitly uses FY2021–FY2025 for both bars, a common $0–$60 million scale, and separate starting/growth segments. The explanation states that the levy is one major source paying for the spending plan and that the current evidence does not support labeling the bar difference “other revenue.”
- PASS — JavaScript syntax passed for the application, resident story, report catalog, report renderer, library renderer, durable browser validator, and structural validator.
- PASS — the durable structure validator returned 29 current routes, 6 categories, 38 preserved links, 38 unique existing targets, and 7 concrete choices with zero failures.
- LIMITATION — the Codex in-app browser security policy blocked direct navigation to the local `file:` release. No alternate browser surface was used to circumvent that control. v4.10 therefore records structural, syntax, source-refresh, checksum, and runner validation separately from the completed v4.9 browser-render validation carried below. Sherie's direct-file delivery mechanism remains unchanged.

## Annual Town Meeting adoption validation

- PASS — migration identity is exactly `0100_WILBRAHAM_2026_ANNUAL_TOWN_MEETING_V01`.
- PASS — source coverage is 6 controlled documents, 104 pages, 4,558 lines, and 4,525 numeric tokens; 5 documents, 72 pages, and 3,313 lines are in-scope for 2026, with 1 wrong-year workbook deliberately excluded.
- PASS — article coverage is 43 articles and 46 vote records; reported outcomes reconcile to 42 passed and one failed.
- PASS — numerical vote tallies remain unreported for all 43 articles and are never converted to zero.
- PASS — budget versions reconcile to 3; 588 displayed cells align across the versions; April-to-workbook, workbook-to-final, and April-to-final changes are all zero.
- PASS — internal General Fund stages reconcile to $57,163,106 department submission, $57,089,233 Town Administrator/Select Board proposed, and $57,018,471 Finance Committee recommended/final-voted authority.
- PASS — Article 19 reconciles $57,018,471 April proposed, $57,041,471 May 6 anticipated, and $57,018,471 final, with the $23,000 line explicitly unresolved.
- PASS — Article 15 returns five revolving funds and the report does not label their spending limits as receipts, cash, balances, or actuals.
- PASS — current-source descriptions distinguish Annual Town Meeting migration 0100 from Annual Town Report release 0455 discovery.
- PASS — all four data-reading routes used the current validated snapshot rather than fallback.
- PASS — all 29 current routes rendered with no route, console, page-script, missing-preserved-link, horizontal-overflow, or oversized-title failure; all 38 preserved targets remained unique and reachable.
- PASS — the ATM outcome disclosure rendered 43 rows from the validated snapshot; desktop and 390-pixel mobile controls passed, with a 32-pixel mobile title.
- PASS — JavaScript syntax passed for the catalog, current report, Whole Picture application, and durable browser validator.
- READ-ONLY CONTROL — PostgreSQL 18.4 reported `transaction_read_only=on`; the transaction ended with `ROLLBACK`; no database state changed.
- ADOPTION BOUNDARY — this release adopts ATM evidence only for the stated report locations and uses. It is not Town acceptance, publication, deployment, or public adoption.

## Household-language and linked-route validation

- PASS — the resident story renders a five-part household model covering dependable income, regular bills, savings and one-time money, borrowing, and what may remain.
- PASS — the credit-card affordability explanation appears in the resident story and both affordability counterparts.
- PASS — the resident-guide direct answer uses the approved Town budget, property-tax levy, school-share, indicator, and $1,306 household-bill wording.
- PASS — the four difficult resident-guide questions were replaced with plain questions about detailed expenses, school drivers, dependable/restricted/one-time income, and the possible addition to household tax bills.
- PASS — all 29 current report routes rendered in a headless local Chrome validation; all 38 preserved-original links resolved and no route had page-level horizontal overflow at 1,280 pixels.
- PASS — Whole Picture’s opening title rendered at 46.08 pixels; the resident-story title rendered at 38.4 pixels; no tested lower-level title exceeded the restrained 44-pixel control.
- PASS — JavaScript, launcher shell, and Python syntax checks completed without error.
- PASS — no blame-suggesting use of the word “hide” appears in the current application.
- PASS — a fresh read-only PostgreSQL refresh and direct-file snapshot build completed at 11:26 PM EDT with matching PASS/read-only timestamps.

## Safari HTTPS-Only launcher validation

- PASS — the launcher contains no `http://127.0.0.1` or other local HTTP launch URL.
- PASS — after—and only after—the governed refresh validator succeeds, the launcher builds `data/current/browser-snapshot.js` and opens the local `index.html` file.
- PASS — snapshot builder rejects non-PASS status, absent read-only transaction state, or mismatched data/status timestamps.
- PASS — generated snapshot loads as valid JavaScript with PASS status, `transaction_read_only=on`, and matching captured-at timestamps.
- PASS — both `index.html` and `resident-story.html` load the direct-file snapshot before their application scripts.
- PASS — JavaScript syntax, Python compilation, and launcher shell syntax checks completed without error.
- PASS — the fresh governed read-only refresh and direct-file build completed at 9:27 PM EDT with no validation failures.
- BROWSER BOUNDARY — the in-app validation browser is prohibited from opening `file://` URLs. The direct-file handoff was therefore validated through launcher inspection, snapshot execution, script-order controls, and syntax checks rather than a browser navigation that the testing environment does not permit.

## Complete lower-level report validation

- PASS — all 38 preserved HTML files were reviewed and grouped into 29 distinct byte-level artifacts; nine files are duplicate historical entry copies rather than missing rewrites.
- PASS — all 29 rewritten report routes load in the browser with a direct answer, evidence, meaning, limitations, next questions, and related current paths.
- PASS — the 29 routes contain 38 preserved-original links; the link set matches all 38 preserved HTML files exactly, with no missing or extra preserved target.
- PASS — the untouched original is the final substantive section on every rewritten route.
- PASS — all 29 tested desktop routes render titles at one restrained 40.96px size and none has page-level horizontal overflow at the tested 1280px width.
- PASS — the report collection exposes all 29 routes in six understandable families and offers four question-led starting paths.
- PASS — Whole Picture’s lower-level links now lead to current rewritten counterparts; the preserved portal remains directly reachable as evidence.
- PASS — static local-link inspection found no missing real target. Two apparent misses are literal JavaScript template placeholders in the untouched source-register files, not rendered links.
- PASS — fresh read-only PostgreSQL refresh completed at 8:09 PM EDT with 15 named source-query groups and no validation failure.

## Complete storytelling-path validation

- PASS — resident title now begins with the question a household is carrying and no longer presents an institutional conclusion as the welcome.
- PASS — seven resident questions render in order; all three progressive-disclosure explanations open successfully.
- PASS — all nine Whole Picture questions render in order; all eighteen progressive-disclosure explanations open successfully.
- PASS — current live values populate on both application pages with no browser console warnings or errors.
- PASS — desktop layout is calm and readable; 390-pixel responsive test has no page-level horizontal overflow.
- PASS — 30 direct links in Whole Picture and 17 direct links in the resident story resolve to existing local targets or valid fragments.
- PASS — all 40 HTML pages in the release packet were inspected; 3,000 links were encountered and no local target was missing.
- PASS — no use of the word “hide” remains in the current application.

## Application-wide typography validation

- PASS — Whole Picture and resident-story opening headlines render at the same approximately 46px desktop size in the tested viewport.
- PASS — major section questions render at approximately 36–37px; direct-answer headings render at approximately 23px.
- PASS — live refreshed status appears on both current application pages.
- PASS — preserved historical evidence files remain unchanged.

## First-screen and launcher validation

- PASS — opening viewport contains the tax/levy/bill contrast and three report paths.
- PASS — resident-story link is visible in the permanent left rail and resolves to `resident-story.html`.
- PASS — no resident-facing “hide” wording remains in the primary navigation or section title.
- PASS — local loopback serving allows the governed JSON snapshot to load; the page reports the current validated refresh rather than a `file://` fallback.

## Resident-story validation

- PASS — live DLS tax and average-home series load through the governed read-only snapshot.
- PASS — HWRSD FY2022–FY2026 cost-driver series is included from `cske.sch_v_budget_cost_driver_trend`.
- PASS — preserved Town-plan bridge is labeled as preserved and pending governed historical reconciliation.
- PASS — no Town-wide Run/Change dollar split, enterprise overcharge claim, or General Fund transfer claim is invented.
- PASS — preserved resident story remains unchanged and linked at the bottom of the replacement page.
- PASS — the top-level refresh symlink succeeds with no preconfigured shell environment; the approved password-file path is used without reading or exposing credential values.
- PASS — successful launcher execution reaches the post-validation open step; failed refreshes exit before that step.

## Commercial-flow validation

- DLS property-class series: **PASS**, 30 rows across five classes and FY2021–FY2026.
- DLS class endpoint changes: **PASS**, five classes.
- DLS new-growth-by-class series: **PASS**, 30 rows.
- Room-occupancy policy: **PASS**, 4.0% adopted-active rate.
- Room-occupancy distributions: **PASS**, six FY2021–FY2026 source totals.
- Meals policy: **PASS**, Wilbraham not reported as adopted in the accepted snapshot.
- Meals potential: **PASS**, $45,000 quarterly Town estimate retained as not a budget forecast and not annualized.
- Residential, commercial, and industrial endpoint levy changes: **PASS** against exact controls.
- Commercial net fiscal contribution: **NOT ESTABLISHED**, correctly blocked rather than presented as zero.

## Budget-cycle story validation

- Read-only PostgreSQL refresh: **PASS**; transaction ended with `ROLLBACK`.
- DLS tax-summary and municipality average-home coverage: **PASS**, six FY2021–FY2026 rows each.
- MassGIS match on `source_prop_id + source_loc_id`: **PASS**, 6,069 records.
- Starting-value bands and provisional use categories each reconcile to 6,069: **PASS**.
- The rejected `source_loc_id`-only many-to-many match is not used in output.
- Aggregate-only export contains no owner, address, parcel identifier, or geometry: **PASS**.
- JavaScript syntax, HTML parse, local links, and anchors: **PASS**.
- Location distribution: **OPEN/NOT DISPLAYED**, pending accepted geography and cell-size controls.

**Validation date:** August 23, 2026  
**Disposition:** `EXECUTED_VALIDATED`

## Result

**PASS for governed read-only refresh, material headline reconciliation, static application integrity, preservation, and explicit unresolved coverage.** Deployment, publication, and Town acceptance are not claimed.

## Database controls

- PostgreSQL client/server: 18.4.
- Database/schema: `cske_dev` / `cske`.
- Transaction status recorded by the output: `transaction_read_only=on`.
- Query package begins `BEGIN TRANSACTION READ ONLY`, sets the reporting search path, and ends `ROLLBACK`.
- Password file used only through `PGPASSFILE`; existence, nonempty state, and mode 600 checked without reading or displaying its contents.
- Latest live migration reported: `0552_GRANTS_CPA_CAPITAL_FUNDING_DEBT_PROJECT_LIFECYCLE_V01`, August 22, 2026.
- Mandatory headline controls: pass; see `REPORT-RECONCILIATION-AND-COVERAGE.md`.
- Timestamped successful run and current snapshot created.
- Failed first run retained as failed evidence: database query produced no row because an inclusion-state filter was too narrow; no current file was replaced. The filter was corrected to the exact governed status and the succeeding run passed.

## Traceability and preservation

- Legacy evidence files preserved: 479.
- Original-to-copy hash differences: 0 at inherited release validation.
- Original public HTML pages inventoried: 38.
- Question occurrences recorded: 843.
- Non-identifier numeric display occurrences recorded: 35,817.
- Total display-level traceability rows: 36,660.
- Property-address, email, and phone patterns are redacted from matrix context; their original files remain controlled by the preservation inventory.
- Each row includes original location and line, intended context, query/source, current implementation, refresh behavior, validation status, and discrepancy.
- Unmapped items remain explicitly unresolved rather than being represented as current.

## Application integrity

- Total HTML pages scanned: 39.
- Local/external references inspected: 3,040.
- Missing local targets: 0.
- Files with duplicate HTML IDs: 0.
- Governing snapshot requests use `cache: no-store`.
- Missing or failed snapshot produces an explicit static-fallback message.
- Refresh time, source views, refresh status, and fallback policy are available in the snapshot/status records.
- JavaScript syntax: pass.
- CSS delimiter balance: pass (101 opening and 101 closing blocks).
- Responsive and reduced-motion rules: present.

## Data-handling controls

- Missing and zero remain distinct.
- Town and HWRSD remain separate.
- Budget, actual, levy, household bill, authorization, cash, principal, outstanding debt, and future cash flow remain distinct.
- Exact source precision is preserved in JSON; the interface may use clearly understood rounded display values.
- The four-part `REPORTING-DATA-ASSESSMENT.md` records confirmed discrepancies, normalization needs, essential missing sources, and helpful additions.
- No credential value, personal-contact record, personal identifier, owner/address record, geometry, individual compensation, or student-level information is included.

## Actions not performed

- No DDL, DML, migration, loader, temporary/staging database write, materialized-view refresh, role/configuration change, or database mutation.
- No Git merge, push, or remote action.
- No deployment, publication, public URL verification, Town adoption, endorsement, recommendation, or affordability certification.
