Forensics · Verified remedies

Verify a remedy before rollout

Run six bounded validation legs against one immutable package version and keep every pass, failure, cancellation, inconclusive result, and not-run state.

For: engineers investigating AI-assisted work, reviewers deciding what the evidence establishes, and team owners checking the same record across devices

What it does, and why it helps

A prevention package is content-hashed and versioned. The local runner copies allowlisted inputs into an isolated workspace, removes operator credentials, blocks outbound connections, enforces byte and time ceilings, and seals every trial artifact. Hosted and model-backed runners remain explicitly disabled by default.

The pain. A fix that passes its own happy-path test can break legitimate controls or fail on the next session.

The point of view. Promotion needs evidence across the defect, fix, guard, controls, variants, and subsequent use.

What gets easier. Seeing which leg failed and whether infrastructure or code caused it.

When it helps. A case has a drafted prevention package ready for review.

Its limits. A local fixture cannot substitute for a production source, a second OS, or human review.

Where to find it

  • Desktop: Memory, prevention package validation and run history.
  • Hosted: /team/agent-incidents, case Prevention section.
  • API: POST /api/prevention/validate

When to use it

Validate a package candidate

Situation. An AI-assisted change needs an answer that another reviewer can reproduce.

What you do. Choose the bounded local runner and run the six-leg matrix for the current content hash.

What you see. Each leg keeps outcome, trials, digests, limits, artifacts, and actual or estimated cost separately.

What it establishes. Only the exact version with a current passing matrix can move to review.

Before you start

Supported versions
RepoOps v0.3.1, verified against the 2026-09-17 completion worktree.
Where it runs
The local view needs a tracked repository. The team view needs a bound device and an authenticated team membership.
Permissions
Local evidence follows the repository's own access. Hosted reads are tenant and repository scoped before rows, counts, filters, or exports are built.
Connections
Local inspection works offline. Team delivery needs the device binding and repoops.ai; a failed delivery keeps its cursor and reports the failure.
Plan
Local deterministic analysis is available without a paid runner. Hosted compute, private runners, and model analysis are disabled by default and never silently substituted.

Configure it

  1. Define allowlisted repository inputs and deterministic checks.

    This establishes the scope before any conclusion is computed.

  2. Run locally, inspect every leg, then request separated review.

    The receipt records the decision and the evidence ids it used.

SettingWhereA sensible choiceWhy it matters
ⓘ
To stop or undo
Cancel the run; completed trials and incurred cost remain receipted.

What you should see

A cancelled leg

Configuration. Use a tracked repository and leave every unknown or disputed input in its real state.

Expect. The leg reads cancelled with the byte, time, or caller limit named, never failed code.

Verify. The sealed artifacts for completed trials remain readable and later legs are not-run.

Data and cost

What is captured
Package hash, runner plan, trial outcomes, code and artifact digests, limits, timestamps, and priced receipts when supplied.
Who can see it
Package metadata and validation events can reach the team; raw workspace files do not.
How long it is kept
The whole package group expires after 365 days without related activity, or earlier with team/case deletion.
What leaves the machine
The local runner blocks network. Hosted execution is disabled unless a later approved capability exists.
What it costs
Local deterministic checks have no model charge; default hosted and model ceilings are USD 0.

When the result differs

SymptomLikely causeNext action
A leg reads not-run.Its runner capability, input, budget, or prior required leg was unavailable.Read the reason on that row; do not rerun under another label or count it as pass.
Disable
Stop the relevant capture or prevention toggle in Settings; already recorded evidence remains a historical record.
Roll back
Restore the earlier package version or withdraw the disputed edge. Append the correction; do not rewrite the earlier decision.
Revoke access
Revoke the device or transcript grant. Later reads become restricted while identifiers and non-secret receipts remain auditable.
Delete
Delete the owning case or team through its deletion flow. Prevention groups also expire coherently after 365 days of inactivity.

Maintenance evidence

Feature id
verified-remedies (spine leaf verified-remedies)
Owner
Forensics runtime and public-story owners (LDG-0695 through LDG-0699, LDG-0722)
Supported product version
RepoOps v0.3.1
Last verified
2026-09-17
Example fixtures
Deterministic unit and integration fixtures cited by the source modules; external acceptance gates remain named separately.
Source references
lib/remediation/runners/local-runner.mjs, lib/remediation/runners/run-validation.mjs, lib/prevention/validation-store.mjs, website/lib/ai-incident-cases/validation-runs.ts
Documentation review
Claims checked against the implementation and dated evidence. Unknown, disputed, restricted, not-run, and unavailable states are retained.
Video review
No licensed rendered story is published for this guide yet. The guide does not render a placeholder player.

Last updated