10. Primary research protocol
Статус: pre-registered execution template; результатов ещё нет.
Scope: English-speaking adults in legally cleared geographies. US — candidate geography и проверяемая гипотеза, а не доказанный лучший рынок.
Этот протокол исполняет validation program, операционализирует P0/P1 из market/product research gap audit, проверяет гипотезы global PRD и создаёт новые primary artifacts для claim/evidence matrix. Сам документ не закрывает gaps: их закрывают только результаты. Adjacent/category evidence и его ограничения находятся в PRD evidence map; текущая граница решения — в independent validation report.
1. Цели и non-goals#
Objectives#
- Восстановить по прошлому поведению, где у существующей компании ломаются организация, выбор GM, подготовка, правила, темп и завершение совместного вечера.
- Отделить решение хоста от решений гостей, включая отказ, молчание и no-show.
- Сравнить без leading три решения одной проблемы: autonomous AI-GM, AI co-GM и simpler party-story.
- Проверить на intact parties, можно ли прозрачно оказать 60- или 90-минутный concierge experience с удовольствием, agency, здоровой социальной динамикой и явным финалом.
- Найти content, state, safety, voice, scheduling и support failure modes и создать воспроизводимый evidence package для решения
GO / PIVOT / KILL / INCONCLUSIVE.
Non-goals#
- не оценивать TAM, prevalence проблемы, country ranking или PMF;
- не доказывать, что US лучше других English-speaking geographies;
- не получать WTP из интервью, concept rank, email, waitlist или бесплатной брони;
- не подтверждать автономность AI: concierge может включать раскрытую human assistance;
- не выбирать 60 против 90 минут статистически по 12 сессиям;
- не проверять long campaigns, subscription, partner IP, public matchmaking или unrestricted UGC и не считать legal/provider/payment clearance результатом исследования пользователей.
2. Единицы и когорты#
| Unit | Операционное определение | Где используется |
|---|---|---|
host |
Взрослый организатор, который в последние 6 месяцев реально пытался собрать TTRPG или совместный online game night | screen, host interview, diary, invite funnel |
guest |
Взрослый человек, которого host сам пригласил; он независимо consented, joined, declined или no-showed | guest interview, diary, debrief |
intact_party |
Host + 2–4 знакомых ему guests; группу не собирают исследователи и не дополняют незнакомцами | concierge и все group outcomes |
party_version |
Состав party_id на конкретный слот; каждая замена участника логируется |
repeat и sensitivity analysis |
Individual ratings не превращаются в независимые group observations. Completion, start, repeat и support считаются на уровне party/session; experience публикуется и по людям, и по party distribution.
Когорты не объединяются:
- P — problem-qualified, concept-unexposed at entry. Непредвзятый относительно solution набор по недавней попытке организовать групповое развлечение, без требования любить AI, RPG или продукт. Это основной problem cohort, но не market-representative sample.
- S — independent smoke cohort. Новые qualified unique hosts, не участвовавшие в P: каждый входит в denominator при первом показе случайно назначенного message, независимо от дальнейшего slot/invite behavior. Эта выборка измеряет formation, но не prevalence рынка.
- I — concierge lineage. Подмножество S, которое выбрало реальный deliverable slot, отправило минимум два invite и собрало independently consented intact party. I измеряет experience; formation всегда считается по полному S denominator, а не по уже сформированным I parties.
- W — future payment/checkout. Новая, не участвовавшая в P, S или I выборка для confirmatory payment test. Её протокол не входит в этот документ.
Участников P, пришедших в concierge, маркируют primed_returner; их можно использовать для operational learning, но нельзя смешивать с primary read когорт S или I. Incentive за интервью не зависит от concept choice, diary completion, брони или положительной оценки.
3. Recruitment, exclusions и внутренние квоты#
Planning cap Phase A — 30 hosts, как задано в program. Это qualitative decision sample, не репрезентативная market sample.
Inclusion#
- 18+ и способен дать informed consent на английском;
- может подробно восстановить одну реальную попытку за последние 6 месяцев;
- для host — может описать реальных потенциальных гостей, но не передаёт их контакты; для Phase B все 3–5 участников отдельно consented до start.
Exclusions#
- сотрудники/подрядчики проекта, авторы протокола, близкие родственники исследователей;
- сотрудники/подрядчики прямого конкурента или professional research respondents, скрывшие конфликт;
- несовершеннолетние, неспособность consent, запрещённая geography;
- только гипотетический интерес без недавней попытки организовать группу;
- researcher-assembled party, публичный matchmaking или подмена no-show сотрудником;
- professional GM как основной респондент P; такие интервью допустимы только как отдельные expert notes;
- Phase A respondent, уже видевший concept/landing, из primary problem analysis.
Quotas/caps, не market norms#
Это защита от recruitment bias, а не утверждение о рынке:
- ни один acquisition source не даёт более
10/30hosts P; - AI-specific communities и subscribers одного creator вместе дают не более
6/30; - минимум
10/30должны иметь недавнюю попытку, которая состоялась, чтобы сравнить failure и workaround, а не набирать только severe pain; - минимум
10/30не должны быть regular TTRPG players; - primary run использует одну выбранную cleared geography. Любая дополнительная geography получает отдельный run ID, собственный cap и decision table и не вносит участников в эти
30или общий gate.
Для 12 concierge slots используется allocation, а не market quota: 6 × 60 минут, 6 × 90 минут; 6 × one-shot A, 6 × one-shot B; по 3 sessions в каждой ячейке 60/90 × 3/4–5 players. Любое отклонение публикуется.
4. Ethics, consent и работа с данными#
До любого participant contact нужен подписанный minimum text-research clearance: допустимость набора в выбранной geography, consent form, incentive, approved text/PII storage, access roles, retention/deletion, withdrawal и incident route. После этого и до полного Phase 0 clearance Phase A может проводиться только через text-chat/async form.
До письменного полного Phase 0 clearance запрещён любой real-user voice или payment: microphone access, audio/video call, recording, STT, voice biometrics, voice cloning, product voice room, card authorization и capture. Phase B voice sessions не стартуют. Synthetic voices и staff dry-runs не являются user evidence.
До первого participant:
- Research owner подписывает minimum text-research clearance; до него нет recruitment или interview.
- До Phase B legal owner отдельно подписывает geography × provider × audio/STT × payment × age/content matrix.
- Consent отдельно перечисляет research purpose, human assistance, recording modalities, subprocessors, retention/deletion, quote use, withdrawal и incident route.
- Участник может играть без согласия на публикацию цитат; optional recording consent не bundling с participation.
- Host пересылает guest opt-in link сам. До guest consent хранят только event-level статус
invited/declined/no_response/no_show, без имени, контакта или host speculation о причине. - Raw PII, contact mapping, interview/debrief free text и recordings находятся в access-controlled approved storage, не в repository. Research artifacts используют pseudonymous IDs.
- Withdrawal удаляет разрешённые идентифицируемые данные по policy; агрегат, уже необратимо anonymized, обрабатывается как описано в consent.
- Concierge раскрывается как assisted research prototype. Запрещено изображать human-operated response автономным AI.
- Safety stop не влияет на incentive. Severe privacy/safety incident немедленно останавливает affected session и дальнейший набор до owner review.
Retention period, storage region, deletion SLA, access roles и incident contacts нельзя угадывать: они заполняются и подписываются в preregistration до набора.
5. Phase A — problem, decision unit и concept comparison#
A1. Host interview, 45–60 минут text-first#
Порядок обязателен: behavior reconstruction → artifacts/workarounds → decision unit → diary setup → только затем concepts.
Цитаты ниже — frozen participant-facing English; служебные инструкции остаются русскими:
- “Think about the most recent time you tried to organize a game or shared online evening. What was the first message, and what happened next?”
- “Who suggested it, whom did you invite, who replied, who chose the time, and what was the outcome?”
- “What preparation happened, who did it, and how much actual time did it take?”
- “Did the event need a Game Master or facilitator? Who agreed or declined, and why?”
- “Where did rules, setup, voice, tools, or content cause a problem? Tell me about one specific moment.”
- “What did the group do instead? What had you already bought or used for this kind of evening?”
- “If it happened, what helped it start and finish? If it did not, at what point did it fall apart?”
- “Who was part of the decision, and who could veto it?” Не просить контакты.
- “How had you actually used AI before, and what made you return or stop?”
- “Is there a scheduling message or calendar event you choose to show with personal details redacted?”
Запрещены вопросы «вам нравится идея?», «вы бы заплатили?» и «сколько готовы платить?».
A2. Guest, decline/no-show follow-up и scheduling diary#
Host сам рассылает neutral opt-in. Guests с consent проходят 15–25-минутный text interview:
- “What did you understand from the invitation, and when did you decide to join, decline, or wait?”
- “What commitment, risk, or alternative affected that decision?”
- “Who did you expect to prepare, facilitate, or pay?”
- “What happened on the day, and why did you attend, cancel, or not show up?”
- “Which parts of the experience should belong to everyone, and which to the host or Game Master?”
Decline и no-show — outcomes, не «некачественные лиды». Не ответившему guest не приписывают причину. Host report и guest report хранятся раздельно; расхождение является finding.
После host interview открывается 14-дневный internal observation window:
timestamp | party_id | actor_role | channel | event
slot_proposed | invite_sent | accepted | declined | no_response
rescheduled | cancelled | no_show | started | ended
reason_code | restricted_source_ref | researcher_prompted
Host логирует только естественную следующую попытку; исследователь не заставляет создавать событие. no_attempt к концу окна — валидный outcome. 14 дней — operational window проекта, не норма частоты game nights.
A3. Neutral concept comparison#
Показывать после behavioral section в заранее сгенерированном randomized order; одинаковые формат, длина, цена (not stated) и отсутствие бренда:
- Autonomous AI-GM: “Your group plays a complete RPG one-shot. AI runs the world, characters, and rules, so no human Game Master is required.”
- AI co-GM: “Your group plays an RPG one-shot with a human Game Master. AI helps them prepare scenes, manage rules, and keep notes.”
- Simpler party-story: “Your group plays a collaborative story with choices and an ending, without a full RPG rules system or an AI Game Master.”
Для каждого: какую последнюю ситуацию мог бы заменить; кто выигрывает/проигрывает; ожидаемый failure; какая информация нужна для решения. Затем — forced rank, вариант none, уверенность 1–7 и условие, которое изменило бы выбор. Concept rank — directional preference, не demand или WTP.
6. Phase S — independent formation smoke#
Phase S открывается после Phase A concept gate, полного clearance обещанной modality и создания 12 реально staffed Phase B slots. Это новый cohort: P respondents не входят в primary S result. Платёжной формы нет; slot/invite behavior не называется WTP.
Recruitment sources, eligibility и traffic stop rule замораживаются заранее; нельзя добирать AI enthusiasts или новый channel после просмотра branch outcomes. Два frozen messages из validation program назначаются concurrent 1:1 до показа страницы, со стратификацией по source. Оба ведут в общий inventory с одинаковыми slot choices, eligibility, UX и expiry. Exposure прекращается, когда нельзя честно предложить один из 12 slots; waitlist и over-cap visits публикуются отдельно и не считаются commitment. Один slot имеет только один active hold; disclosed expiry возвращает не сформированный slot в inventory без overselling.
Каждый qualified unique host входит в S denominator при message_viewed, даже если дальше ничего не сделал. Обязательный event path:
qualified
→ assigned_message
→ message_viewed
→ slot_flow_started or no_action
→ real_slot_selected or abandoned
→ invite_1_sent / invite_2_sent or not_sent
→ accepted / declined / no_response
→ 3+ formed within 7 days or expired
→ eligible_for_I or not_formed
Primary comparison — message_viewed → real_slot_selected + 2 invites sent. Decision gates:
hosts with real slot + 2 invites sent / all qualified message_viewed hosts ≥40%;hosts with 3+ formed within 7 days / all hosts with 2+ invites sent ≥25%.
2+ invites / slot_flow_started публикуется только как diagnostic. Рядом публикуются raw branch counts, inventory state at exposure, expiry, decline/no-response и deviations. Ни один host/group не исключается за отрицательный downstream outcome. Сформированные parties переходят в I с теми же IDs; I experience analysis не пересчитывает formation.
Branch result при таком inventory directional: допускается выбрать operational candidate copy, но нельзя заявлять statistical superiority или message-market fit.
Для открытия полного Phase B нужны не только percentages, но и 12 independently formed, consented и scheduled I parties, распределённых по 3 в каждую заранее заданную 60/90 × 3/4–5 players cell. Если traffic/time cap заканчивается раньше, S/B allocation получает INCONCLUSIVE. Уже обещанные sessions исполняются и остаются exploratory; нельзя молча сократить 12-session design или заменить party после известного outcome.
7. Phase B — capacity-limited concierge#
Preconditions и allocation#
Phase B открывается только после voice/legal clearance, consent test, staff-only dry-run, QA двух original-IP one-shots (OS-A, OS-B) и прохождения S formation gate. Primary I parties приходят из S с сохранёнными IDs и отрицательными upstream outcomes; primed_returner sessions анализируются отдельно. Никаких D&D, Knave, partner assets, cloned voices или чужого likeness без письменных прав.
Hard inventory — 12 staffed slots с operator, observer, backup, support buffer и promised fulfillment window. Waitlist не называется demand. Сценарий назначается случайно внутри ячейки по counterbalance:
| Cell | Sessions | Content pattern |
|---|---|---|
| 60 min × 3 players | 3 | A, A, B |
| 60 min × 4–5 players | 3 | A, B, B |
| 90 min × 3 players | 3 | A, B, B |
| 90 min × 4–5 players | 3 | A, A, B |
Timebox назначается случайно среди compatible slots, если host доступен и для 60, и для 90 минут; иначе используется quota matching и self-selection раскрывается. Party size наблюдается после formation и quota-matched: исследователь не добавляет и не удаляет людей ради ячейки. Дизайн directional: raw counts важнее процентов.
Content/tone QA rubric#
Два независимых reviewers должны дать PASS по каждому пункту обоим one-shots; disagreement закрывается до recruitment:
- provenance и original-IP rights documented;
- одинаковый promise: social, humorous, consent-safe adventure с явным ending;
- сопоставимые decision density, rules/state load и opportunity для каждого игрока влиять на outcome;
- 60-minute cut не требует скрытого railroad, 90-minute cut добавляет выбор, а не filler;
- одинаковые content rating, boundaries, intensity и humiliation/coercion restrictions;
- один labelled ambiguity probe и один false-valid intent probe встроены без наказания игрока;
- facilitator guide, intervention policy и failure fallback одинаковы;
- финал достижим без secret researcher compression.
Dry-runs используют staff/synthetic input и не входят в user metrics. Изменение content после первой real session создаёт новую version; до/после не объединяются без sensitivity table.
Service blueprint и failure states#
| Stage | Frontstage promise | Backstage evidence | Failure handling |
|---|---|---|---|
| Eligibility/consent | Понятный assisted pilot | consent version, geography, age | F01 missing clearance/consent → no start |
| Slot/invites | Реальный deliverable slot | capacity ledger, invite events | F02 <3 joined → no researcher replacement; reschedule/cancel |
| Join/mic | Рабочий вход и sound check | device/browser, latency, reconnect | F03 voice failure → declared fallback; session remains assisted |
| Boundaries | Rating, pause/stop | boundary acknowledgment | F04 safety concern → pause/stop, incident route |
| Play/state | Choices change the story | event/intent/state log | F05 invalid/ambiguous → clarify; no silent commit |
| Branch/privacy | Секреты scoped | access trace | F06 leak → stop, severe incident, gate fail |
| Tempo/ending | Ending в promised timebox | scene/time markers | F07 no ending → incomplete; не дописывать success вручную |
| Debrief/follow-up | Private feedback first | individual + group records | F08 missing response stays missing |
| Operations | Обещанный слот исполнен | labor/intervention/cost ledger | F09 capacity failure → make-good/refund; no overselling |
Каждая human action получает category: safety, technical, clarification, state_correction, pacing, content_generation, social_moderation, other; фиксируются start/end, initiator, reason, user-visible status и counterfactual would_session_continue_without_it.
8. Observation, debrief и metrics#
Observation template#
session: {session_id: "", party_id: "", party_version: 1}
recruitment: {geography: "", source: ""}
cell: {minutes: 60, party_size_band: "3", one_shot: "OS-A", content_version: ""}
timestamps: {scheduled: "", joined_3: "", start: "", midpoint: "", ending: ""}
attendance: {host: "", invited: 0, consented: 0, declined: 0, no_response: 0, no_show: 0}
outcome: {started: false, explicit_ending: false, actual_minutes: 0, early_exit_reason: null}
experience: {individual_rating_refs: [], consequential_choice_by_person: {}, social_events: []}
integrity: {intent_probes: [], false_valid_commits: [], corrections: [], privacy_incidents: []}
support: {interventions: [], assisted_minutes: 0, operator_count: 0}
safety: {pause_count: 0, stop: false, incident_ref: null}
evidence_refs: []
redacted_observer_summary_ref: null
Metrics публикуются с raw numerator/denominator:
- formation: all qualified/message-exposed S hosts, slot-flow started/abandoned, real slot selected, 2+ invites sent/not sent, accepted, declined, no-response, expired, 3+ formed, scheduled и started; отдельно по assigned message и pooled;
- experience: individual
1–7fun, agency, social comfort, trust и desire-to-repeat; минимум/median/range внутри party, не только host mean; - agency: число consequential choices по участнику, ignored/overridden choices и parties, где не каждый получил такой выбор;
- social dynamics: turn-taking/coordination, dominance, repair/help, conflict, discomfort, early exit; observer code + private self-report;
- integrity: false-valid commits / labelled probes и / all state-changing intents;
false_valid_commitозначает schema-valid action, который система применила, хотя он не соответствовал выраженному намерению участника или нарушал state/rules constraints и требовал clarification; также clarification, correction, duplicate/reconnect и privacy events; - operations: interventions по категории, assisted minutes, operator labor, technical fallback, planned/actual duration, explicit ending;
- next action: выбранная реальная дата повтора — только intent signal; retention возникает лишь после fulfilled second session.
Group debrief guide#
Сначала каждый отвечает приватно; затем 20-минутный group debrief, чтобы host не задавал ответ guests:
- Rate
1 = strongly disagreeto7 = strongly agree: “I had fun”; “My choices changed what happened”; “Everyone had room to contribute”; “I trusted the game to keep track”; “I would choose to play this again with this group.” Дать одну причину каждому score. - “What specific moment changed because of your choice?”
- “When did the system or facilitator misunderstand an intent, forget a fact, or decide for the group?”
- “Who spoke or decided more or less than they wanted? Was there a safe way to intervene?”
- “Where did you notice human assistance, and what would have happened without it?”
- “What helped or prevented the story from reaching an ending in the promised time?”
- “For your next evening, would the group choose autonomous AI-GM, co-GM, party-story, human GM, or none? Why?”
- Если группа сама хочет повтор: “What real time could this group meet again?” Не предлагать checkout.
9. Analysis, codebook и double coding#
До первого real participant создаётся codebook-v1.md с definition, include/exclude rule, positive/negative example для:
GM_availability,prep_burden,rules_burden,scheduling,tool_voice,content_fit,social_permission,price_past_behavior;host_guest_mismatch,decline,no_response,no_show,workaround,completed_despite_friction;fun,agency,social_inclusion,dominance,trust,desire_repeat;false_valid_commit,clarified_before_commit,critical_state_error,privacy_leak;- intervention categories и failure IDs
F01–F09.
Два coders независимо кодируют 100% eligibility/exclusion, primary problem attribution, concept rank/reason, false-valid probes, critical defects, privacy/safety incidents и interventions; плюс seeded random 25% остальных interview/debrief records. Они не видят aggregate gate table во время first pass.
Публикуются raw agreement, confusion table и disagreements. Разногласия adjudicates третий reviewer или documented consensus; original labels сохраняются. Codebook changes получают version/date/reason и применяются ко всему corpus или только к новой wave — выбор фиксируется до re-code. Quotes иллюстрируют code, но не заменяют counts.
10. Decision gates — внутренняя risk policy, не market norms#
Пороги замораживаются до recruitment и не называются отраслевыми benchmark.
| Gate | GO | PIVOT / KILL / INCONCLUSIVE |
|---|---|---|
| A: problem | ≥18/30 hosts дают конкретный recent GM/prep/rules friction; guest evidence не показывает систематически обратную картину |
Scheduling-only → shorter/asynchronous/co-GM PIVOT; quota/guest evidence incomplete → INCONCLUSIVE |
| A: concept | Autonomous AI-GM получает host plurality, guest ordering не reverses it, а primary objection не требует human GM | Co-GM или party-story wins → тестировать winner; none plurality → KILL current proposition |
| S: formation/allocation | ≥40% всех qualified message-exposed hosts выбирают real slot и отправляют 2+ invites; ≥25% invite-sending hosts формируют 3+ party в 7 дней; 12 I parties распределены по 3 в каждой pre-registered cell |
Low all-exposed send → positioning/social-permission PIVOT; low form → guest-friction/format PIVOT; fewer than 12 allocated parties или incomplete lifecycle → INCONCLUSIVE |
| B: start | ≥75% scheduled intact parties start |
Decline/no-show reasons определяют guest-friction PIVOT; researcher-filled groups недопустимы |
| B: experience | ≥70% started parties reach explicit ending; no systematic loss of agency/social safety |
После двух versioned content/tempo iterations completion <50% → KILL format |
| B: integrity | 0 critical state error, privacy leak и false-valid commit в labelled probes |
Любое событие → PAUSE; root cause + rerun, не усреднение |
| B: operations | Предварительно подписанный support ceiling выдержан и все promised slots resolved/fulfilled | Ceiling не был preregistered → INCONCLUSIVE; capacity failure → no checkout handoff |
Support ceiling выводится из staff dry-run и реальной staffing capacity, подписывается до participants и публикуется числом; этот документ не выдаёт выдуманный «нормальный» intervention rate.
11. Правила negative evidence#
- Decline, no-response, no-show, cancellation, failed join и incomplete остаются в соответствующих denominators.
- Legal/provider failure означает
NOT TESTED, а не отсутствие спроса. - Recruitment-source failure нельзя переносить на product; eligible invite refusal можно.
- Assisted success не считается autonomous success; intervention нельзя скрывать.
- Interview enthusiasm, concept rank, slot choice и repeat date не являются WTP, retention или completion.
- Один critical privacy/safety/state event не растворяется в average.
- Post-hoc subgroup, changed script/content или broken randomization маркируются exploratory.
- Geography results не poolятся для прохождения gate; US failure/success не доказывает English-speaking market.
- Missing guest reason остаётся
unknown; host explanation не заменяет guest evidence. - Waitlist, over-cap demand и невыполнимая бронь не являются valid commitment.
- S host остаётся в denominator после
message_viewed; failure выбрать slot, отправить invites или сформировать party не является exclusion. - Нейтральный или mixed result —
INCONCLUSIVE, а не автоматический GO.
12. Evidence artifacts и naming#
Run ID: PR-YYYYMMDD-NN; participant PER-####, host H-####, guest G-####, party PTY-####, session SES-####. IDs стабильны; PII mapping хранится отдельно.
Repository не является approved raw research-data store. Каждый released run в global-validation/ содержит только структурированные события, числовые ответы, codes и прошедшие release review summaries:
data/primary-research/<run_id>/
README.md
preregistration.md
protocol-snapshot.md
recruitment-log.csv
screening-disposition.csv
consent-index.csv
measurement/event-schema-vNN.json
measurement/metric-dictionary-vNN.md
measurement/identity-attribution-rules-vNN.md
measurement/qa-fixtures/valid-lifecycle.json
measurement/qa-fixtures/invalid-lifecycle.json
measurement/qa-report.json
phase-a/redacted-host-summaries/H-####.md
phase-a/redacted-guest-summaries/G-####.md
phase-a/guest-outcomes.csv
phase-a/scheduling-diary.csv
phase-a/concept-order-and-rank.csv
phase-s/message-assignment.csv
phase-s/funnel-events.csv
phase-s/invite-outcomes.csv
phase-s/inventory-state.csv
phase-s/metric-table.csv
phase-b/content/OS-A-vNN.md
phase-b/content/OS-B-vNN.md
phase-b/content/qa-rubric.csv
phase-b/session-allocation.csv
phase-b/capacity-ledger.csv
phase-b/observations/SES-####.yaml
phase-b/debriefs/SES-####-individual-ratings.csv
phase-b/debriefs/SES-####-redacted-group-summary.md
phase-b/interventions.csv
phase-b/incidents.csv
analysis/codebook-vNN.md
analysis/coded-records.csv
analysis/double-coding.csv
analysis/redacted-negative-cases.md
analysis/decision-table.csv
restricted-source-index.csv
redaction-review.csv
artifact-index.csv
manifest.json
event-schema задаёт required fields/enums и version для event_id, event time, eligibility, source, assignment, person/host/party/party-version/session/slot IDs и lifecycle state. metric-dictionary для каждой метрики фиксирует unit, formula, numerator, denominator, exclusions, missing/censored handling, window и owner. identity-attribution-rules фиксирует deduplication, same-party, source attribution и payment lifecycle.
До release автоматический QA проверяет schema validity, unique IDs, допустимый порядок lifecycle, reconciliation funnel counts, frozen assignment, inventory at exposure, party-version consistency и отсутствие невозможных payment/session states. qa-report.json содержит test count, failures и schema/hash; любой failure блокирует decision table.
Free-text interview/debrief, signed consent forms, recordings, contacts, exact scheduling artifacts и PII остаются в approved restricted storage. Repository consent-index.csv хранит только pseudonymous unit ID, consent version, allowed scopes и status. restricted-source-index.csv содержит только opaque source reference, unit ID, consent scope, retention class и release status — без raw path, contact или narrative. Repository summary проходит:
- удаление direct identifiers и ненужных quasi-identifiers исследователем;
- независимый second-person redaction review;
- automated secret/PII scan;
- проверку quote/publication consent;
- статус
approved_for_repositoryвredaction-review.csv.
pending, restricted или rejected artifact не попадает в tree и manifest. Псевдоним сам по себе не считается anonymization. Если безопасную summary сделать нельзя, в repository остаются только code/count и opaque source reference.
artifact-index.csv содержит artifact_id,path,phase,unit_id,created_at,consent_scope,redaction_status,retention_class,sha256. manifest.json фиксирует hash каждого released artifact, schema version, generator и timestamp.
13. Handoff к checkout/powered tests#
Передача в future cohort W разрешена только когда:
- все открытые concierge promises имеют terminal status
fulfilled,participant_cancelled,researcher_cancelled_makegood_completedилиrefunded; outstanding slots =0; - capacity ledger доказывает, что следующий advertised inventory реально staffed и deliverable;
- два one-shots прошли QA, content version заморожена, support ceiling и failure policy измеримы;
- critical privacy/safety/state incidents закрыты письменно; legal/payment/refund owners дали pass;
- Phase A/S/B evidence package hashed, negative cases включены, measurement QA passed и решение подписано;
- будущий payment cohort новый, sample/power/price/refund/authorization/capture protocol зарегистрирован отдельно.
До этого допустим только честно маркированный non-transactional intent. Нельзя принимать card authorization/capture ради «проверки цены» на inventory, который команда не способна исполнить.
14. Pre-registration checklist#
- Hypotheses, non-goals, geography и US-as-hypothesis wording frozen.
- Units, same-party/party-version rule, cohort labels и non-pooling rule frozen.
- Inclusion, exclusions, sources, caps, quotas и incentive documented.
- Minimum text-research clearance подписан до recruitment; полный legal/voice/payment matrix — до S slot promise и Phase B.
- Interview guides, 14-day diary schema и guest opt-in path piloted text-only.
- Concept cards equal-format; randomized order table generated before exposure.
- S message assignment, all-exposed denominator, event path, shared inventory/expiry и formation gates frozen.
- OS-A/OS-B rights provenance, versions, content/tone QA и staff dry-runs passed.
- 12-slot allocation, hard capacity ledger и waitlist behavior frozen.
- Event schema, metric dictionary, identity/attribution rules, QA fixtures/report, observer template, failure IDs, denominators и support ceiling frozen and tested.
- Codebook v1, coder training set, random 25% double-code seed и adjudicator assigned.
- Decision gates, negative-evidence rules, missing-data handling и stop rules frozen.
- Restricted-storage boundary, two-person redaction release, PII scan, artifact tree, access и hash/manifest tested; protocol snapshot timestamped и hashed до first participant.