From Agent 1.1 to Agent 9 — 5 October 2026

Kenny's fixes and the "paid work survives" programme: what we did and why

Tor has asked you to check that we've done the right thing. This covers every task raised today in my lane, the decisions behind them, what goes live on the next deploy, and what I'd like you to check.


1. Where it started: Kenny's three complaints (Physio K)

Practice edd060d9-2341-446a-b163-e673354041bb, assessment 71bc9610-2d23-47d2-b89c-ab61da2a4bae.

  1. NDIS article was about the "NDIS refresh", not NDIS. Cause (confirmed by #3551): the plan action label "Refresh: NDIS" was passed to research and writing as the topic. Research read "refresh" as the NDIS reform. Kenny's three clinician-insight answers were saved but are absent from the queue payload and dossier inputs, so they were almost certainly not used.
  2. Several search-volume numbers under each card. The fix (#3542, one line per card) was already live, but Kenny's plan had not saved since 4 Oct. Both rebuilds on 5 Oct (09:01Z, 09:23Z) ran ~19 min each and were refused at final save, because a final filter (rewrite protection: protected / recently published page) removed his started Back Pain refresh, and the started-work safety check then refused the whole plan.
  3. WorkCover/CTP article showed raw JSON. The first draft (02:40Z, 4 Oct) was fine. The automatic quality-repair loop then ran 9 times (pass mark 70; it stalled at 69). The last repair hit its 8,000-token output limit, was cut off, and the permissive repair parser saved the broken output over the good version (version 13).

Kenny was charged 12 credits on 4 Oct (WorkCover 2, Back Pain 6, NDIS 4). Repairs, regenerations and plan rebuilds are not charged to the clinic. Tor has refunded 6 credits (WorkCover + NDIS) via Admin → Credits → Adjust balance. Kenny has been asked not to regenerate either article until we've checked.


2. Tasks raised and merged today (all CCS, all Agent 1.1 briefs)

Task What it does Status
#3550 Partial: work started after the last plan save is no longer dropped. (Attempt-history/visibility half not built; still owed as a brief.) Merged
#3551 Refresh articles: action labels never reach research/writing as the topic; existing page text supplied; every clinician-insight answer reaches research and writing on all paths; article envelopes validated before save ("Generation failed — try again" instead of raw JSON). Merged
#3554 Started work is exempt from every final filter (dedupe, one-main-per-topic, caps, rewrite protection, focus). Genuine identity conflicts still refuse and name the item. Merged
#3555 23 coverage-fallback test failures were real bugs from #3544's exact-key main-page matching ("Hand therapy" didn't match "Hand therapy assessment and treatment" → duplicate page suggestions). Narrow title-equivalence fix. Merged
#3556 Every generation and repair call checks the stop reason; cut-off/malformed output never saved or allowed to replace a complete version; repair/condense/differentiation output limit raised to 16,000. Includes a guarded one-record production repair: restores WorkCover/CTP (record 8146f08a-…) from the last complete version (campaign_content row c64c8107-…, 02:58Z, MD5 f3da80ee…), hash-bound and idempotent. Tor authorised this write. Merged
#3557 Typecheck gate green (10 pre-existing errors in Builder tests/vitest config + 4 from #3551). Merged
#3558 Paid-response receipts: raw provider responses saved before parsing; retries reuse them. Scope: research, dossiers, plan rebuilds, developer briefs. Adds a new table. Merged
#3559 Quality-repair loop stops after 2 consecutive non-improving attempts and keeps the best-scoring complete version (incl. first draft; ties keep earlier). Attempts/scores/stop reason shown in admin Content Health. Pass mark, caps, scoring unchanged. Merged
#3563 Receipts extended to the whole article pipeline (6 page types, briefs, trim, repairs, citation repair, differentiation, taxonomy, linking, summaries). Merged
#3564 (Narrowed) campaign research, priority topics, Step 12, niche/profession research. Merged
#3567 (Narrowed) external providers: competitors, keyword/volume enrichment, DataForSEO, citations, Browserless, reconnaissance, geocoding, review sources. Google Ads Keyword Planner excluded (per-request charging not established). Adds a migration. Merged
#3569 Campaign content: Quick Wins, chapters/ebooks, leaflets/posters, email, social, other marketing. Idempotent saves; credits/refunds/notifications once only; stale workers fenced. Adds a campaign-credit identity migration. Merged
#3570 Standalone planning tools (inference, classification, topic matching, library categorisation, spoke regeneration/extension). Adds an operation-metadata migration. Merged
#3575 Assessment analysis (audit, sanity, classification, booking, coverage, narratives, review themes, opportunities, recommendations). No migration. Merged
#3576 Profiles and helpers (profiles/imports, both Whisper routes, Answer Panel batches, meeting reports, live-review docs, helpers, AC38 offline). Building

Tor's standing rule behind #3556–#3576 (now rule A10 in state/content-plan.md): we never throw away work we've paid to create. Paid output is saved on arrival; a later failure never discards it; a retry redoes only the failed step.


3. What the next deploy does to the database

All should be additive except the one authorised repair:

  1. New paid-response receipts table (#3558).
  2. External-provider lifecycle metadata (#3567).
  3. Campaign-credit identity (#3569) — touches credit bookkeeping.
  4. Standalone-planning operation metadata (#3570).
  5. One-record data repair: WorkCover/CTP article restore (#3556), hash-guarded, authorised by Tor.

Rule as always: if the publish diff shows DROP / TRUNCATE / DELETE / SET NOT NULL, cancel.


4. Things I'd like you to check

  1. Typecheck after all merges. Several tasks ran their gate before reconciling with parallel work (#3567, #3569). Please run the clean typecheck once more on main before deploy.
  2. Migration order/collisions. Four migrations registered by parallel tasks (#3558, #3567, #3569, #3570, and #3576 may add one). Confirm they're all registered once, idempotent, and additive.
  3. Completion reviews that timed out. #3569 and #3570 were marked implemented after their final Replit review timed out (tests and typecheck passed). Your call whether that's acceptable.
  4. Customer-visible change in #3569: "selected content" generation now waits for completion before responding. A slow run could time out in the browser and show an error while generation continues in the background. I'll check it after deploy and brief a "still working" fix if needed.
  5. Process sanity check: is one receipt mechanism opted into scope-by-scope (rather than a global wrapper) the right architecture? It's what Replit recommended and what all tasks built on, but it means any new paid call added in future is unprotected unless it opts in. That may need a rule in replit.md ("every new paid call must run inside a paid-operation scope").

5. Process changes Tor made today (apply to everyone briefing Replit)


6. Still to do (my lane)

Agent 1.1