LEF Ai.E — Federal ISB — Changelog
What's changed in the engine's structural read — what it reasons about and what it says — in reverse chronological order. (Platform changes — access, infrastructure, page copy — live in the internal platform log, not here.)
LEF Ai.E — Federal ISB points the LEF Ai Engine at the federal mission: a structural read over multi-source, unclassified records — the landscape, the structural voids (combinations that never occur), each void falsified against reality and refuted before it surfaces, and, across sources, where a structure lived in one corpus but never another. Built on the same engine substrate as DCFN-Patents, DCFN-Research, and DCFN-Bio.
2026-06-24 — Confidence label matches the verdict for non-gap voids
A void with no proposed outcome — a re-encoding artifact or an exclusion rule — still printed its probability under “Outcome confidence,” the same label a fillable gap uses for confidence in its proposed fill. For a non-gap there is no outcome; the number is the engine’s confidence in its structural verdict. The line now reads “Verdict confidence” for those voids, so a high number no longer reads as confidence in an outcome the engine just said doesn’t exist.
2026-06-24 — Re-encoding voids no longer prescribe a collection in the next-move
A void reclassified as functional dependence (the two columns are the same field — Crm Cd / Crm Cd 1, or a · populated / · multiplicity facet pair) reported “do not task a collection,” yet the next-move still read “collect the record carrying both …,” because the analyst-#3 next-move had no re_encoding branch and fell through to the occupancy default. It now omits the collection prescription entirely — the structural read and the next-move agree.
2026-06-24 — Civil-liberties gate extended to the next-move and the precondition
A protected-attribute void already withheld its authored outcome and suppressed its collection task; the gate now also neutralizes the two places that still prescribed collecting the protected join.
- The next-move no longer prescribes collecting a protected-class join. Where a void touches a protected attribute (race/ethnicity, sex/gender, religion, national origin, age, disability, sexual orientation), the next-move reads “no collection tasked — reportable only with an independent criminal predicate and civil-liberties review (28 CFR Part 23); not a collection target,” instead of “collect the record carrying both …”.
- The precondition reads as a reportable potential, not a collection mandate. The named condition and survivability for a protected-class void no longer frame closing it as a collection target.
The structural fact (the two values never co-occur) still surfaces as a reportable potential — reported, never prescribed against a protected class. Surfaced by running real protected-attribute data (LA crime: Vict Descent × Vict Sex).
2026-06-24 — Five seam fixes after the live-artifact critique
The fed143/fed144 read held up under review; this pass closes the localized seams it surfaced.
- Single-source runs no longer point at an “inter-agency join named above” that isn’t there. The bridgeable-gap survivability names the inter-agency join only when the void actually crosses two authorities; a single-source run reads “a record carrying both values would close it.”
- Same-field aliases and facets no longer surface as collectable gaps. Two facets of one column — a numbered alias (
Crm Cd / Crm Cd 1) or a structural facet (X · populated / X · multiplicity) — now classify as functional dependence (re-encoding) at detection time, matching the authoring guard, so they no longer appear as fillable gaps carrying a collection mandate and an inflated probability. They read as “the two columns are one field,” not a gap to collect.
- A genuine single-source gap reads honestly. When two distinct columns of one source have a value pairing that is simply absent, the precondition says both values are already co-recorded and names the real alternatives (a sparse slice, or a coding rule that excludes the pairing) — no false “collect the joined record.” (Codebook corpora like crime classifications.)
- Candidate-exclusion voids say why no collection is tasked. The DO block now closes with “No collection is tasked — absent a schema change that lets one record carry both, no record can occupy this cell,” so an empty task reads as intentional, not omitted.
- Multi-corpus convergence shows the boundary spread. When voids cross several source-authority pairs, the convergence block names the secondary pairs by count (e.g. “fdic x usgs 23; nih x fdic 9; …”), not only the dominant one.
- The moving-gaps lead separates a temporal lead from a worklist finding. A bridging line explains the trajectory pairs are drawn from the full record population (they co-occur in some snapshots), while the worklist carries only the pairs absent across every snapshot that cleared the power floor.
2026-06-23 — Three deepenings: cross-corpus institutional read, engine-side divergence, moving gaps
- No-shared-key cross-corpus runs now read as an institutional separation. When two sources share no join key, the engine builds a union graph; its dimensions are now source-prefixed (e.g.
nih:activity_code × usgs:review_status), so a cross-agency void is recognized as an institutional separation — the precondition names the inter-agency join, and the institutional-boundary convergence reads N such voids as one boundary, not a scatter of unexplained gaps. The adjudication stays honestly unvalidated (no joined corpus exists to test co-occurrence), but the structural read is surfaced rather than buried under a generic "no live source."
- The divergence read is now the engine's, not the page's. Where the deterministic verdict and the authored landing disagree, the detection is computed and stored on the finding (joining the artifact + the ledger) instead of re-derived at render time.
- Moving gaps over time. The engine now detects pairs whose co-occurrence is OPENING (emerging) or CLOSING (decaying) across the periods — gaps a whole-dataset scan misses because they co-occur in some years. A "Read across time" section surfaces them with their per-year trajectory.
2026-06-23 — The void anatomy: every finding now reads its own interior
A structural-void detector tells you where the wall is; the engine now tells you what the wall is made of. Each void carries two faces — the outward face (what surrounds it: the covering path, the record that would bridge it, the survival test) and a new inward face that reads the void's interior.
- The precondition profile (the inward edge). Each void names the real-world condition that would have to exist for the missing record to form — a collection mandate, a coding-rule change, a definitional change, or — when a cross-corpus void spans two authorities maintained apart — an institutional separation that no single-agency pull can close, only a data-sharing arrangement (or a common entity identifier) between them. It states the co-fire set the record requires and whether the absence is bridgeable or structurally mandated.
- The typed verdict, surfaced. The engine's read of why a void exists (bridgeable gap / candidate rule / structural rule / definitional exclusion / re-encoding) now leads the inward face by name, not just by implication. The institutional-separation read also corrects the next move: not "pull from cross-corpus," but establish the inter-agency join.
- Adversarial defensibility on the page (Mechanism 2). Each void now carries how well it holds under adversarial-traversal pressure, distinct from the skeptic-panel verdict — two integrity reads, two questions answered.
- The trajectory leads. Where a corpus carries a time axis, each void leads with its kinetic state — a durable wall, an emerging gap, a closing one — read across the snapshots.
- One institutional boundary, not N findings. When many cross-corpus voids cross the same pair of source authorities, the run reads them as one institutional separation observed many times, not a scatter of independent gaps.
- Where the engine's two tiers disagree, it says so. When the deterministic structural verdict and the domain-grounded authored read diverge, the engine states the case for and against each and hands adjudication to its own survival test — the deterministic verdict is the floor, the deep read the working hypothesis.
2026-06-20 — The membrane reads real columns before it transforms them
The ingestion membrane now runs semantic-first: it reads and understands the real columns of an uploaded dataset before the mechanical step translates high-cardinality fields into structure. Concretely, the engine now carries a per-column meaning (geographic, temporal, currency, person-attribute, identifier, classification-code, …), not just a data type, and that understanding reaches the output.
- A sanity gate resolves ambiguous columns. A column the first pass can't place — say a report number that looks like a plain category — is held, then resolved by deeper evidence (a near-unique column is an identifier, a multi-word near-unique column is free text). Resolved with a stated diagnosis rather than guessed.
- The membrane remembers. A learning profile library accumulates column-meanings across runs and recalls them — recognized once, recognized faster and more confidently every run after. Shared across the substrate, so every run teaches the same library.
- Ambiguous columns with no signal yet are left explicitly unresolved (awaiting a deeper pass) rather than mislabeled.
2026-06-19 — Source-record provenance: every validated finding traces to real rows
A confirmed void now carries exemplar source records — actual rows behind each side of the claim ("value A appears in records like {…}, M in all; value B in {…}, N in all; 0 records carry both") — plus an explicit invitation to recount them in your own upload. A finding is no longer a tag; it's a traceable claim you can verify to the row.
2026-06-19 — Population-complete cross-corpus findings
When a cross-corpus read covers the full population of its join key (e.g. all 50 states), the engine no longer mislabels a clean absence as an "underpowered lead." The absence is the realized population truth: it's reframed as a structural fact, and confirmed when the overlap was expected yet never occurs across the whole population — while genuinely modest gaps stay honestly modest. No manufactured confidence.
2026-06-19 — The association read stops surfacing missing-data artifacts
The Intelligence (association) section now demotes shared-missingness co-movements — two fields that are empty in the same records (unknown codes, or a column the membrane marked empty-here) travel together as an artifact, not a real linkage. The strongest real linkage now leads the section instead.
2026-06-18 — Honest validation, made legible
- Two-corpus provenance. Each run states plainly that the graph maps a bounded sample and every surviving void is then validated against the full uploaded corpus, with the per-pair counts shown — so the validation reads as real, because it is.
- The validation arm only counts what's present. A void is confirmed only when both its values actually appear in the validated corpus; a value that isn't there leaves the void untested, not vacuously "confirmed."
- Memory is context, not a vote. A prior run surfacing the same void is flagged for context but never counts as independent corroboration — the confirmed verdict rests on the live full-corpus check alone.
Foundation — the structural-void engine
- Seven analyst lenses. Every run is read through Intelligence, Investigation, Program Assessment, Policy/SOP, Compliance/Audit, Adjudication, and CQI — the engine surfaces only the lenses that find structure in your data.
- The adjudication panel. Every void is a hypothesis attacked by a panel of skeptics before it surfaces; what remains has already survived that challenge. Re-encoding and coverage-gap artifacts are refuted and sunk off the worklist.
- Full-corpus validation. The live skeptic checks each surviving void against the full uploaded corpus (well beyond the detection sample), so a sampling artifact is caught and a real absence is confirmed by counted fact.
- Convergence anchor. When most voids route through one axis or entity, the engine foregrounds the single boundary seen many times rather than reporting many separate findings (protected under U.S. Provisional 64/043,294).
- Cross-corpus weave. Select two or more sources and the engine folds them on their shared axis, surfacing where one source carries a structure the other never does — the gap that would have to be collected to close it.
- Corpus-regime honesty. A run with no live source to validate against says so up front — "structural candidates, not validated findings" — so untested is never read as rejected.