RnD · Линия доказательств Global validation
Каталог и оглавление
GVL.10 RnD/research/global-validation/10-primary-research-protocol.md raw.md ->

10. Primary research protocol

Статус: pre-registered execution template; результатов ещё нет.
Scope: English-speaking adults in legally cleared geographies. US — candidate geography и проверяемая гипотеза, а не доказанный лучший рынок.

Этот протокол исполняет validation program, операционализирует P0/P1 из market/product research gap audit, проверяет гипотезы global PRD и создаёт новые primary artifacts для claim/evidence matrix. Сам документ не закрывает gaps: их закрывают только результаты. Adjacent/category evidence и его ограничения находятся в PRD evidence map; текущая граница решения — в independent validation report.

1. Цели и non-goals#

Objectives#

  1. Восстановить по прошлому поведению, где у существующей компании ломаются организация, выбор GM, подготовка, правила, темп и завершение совместного вечера.
  2. Отделить решение хоста от решений гостей, включая отказ, молчание и no-show.
  3. Сравнить без leading три решения одной проблемы: autonomous AI-GM, AI co-GM и simpler party-story.
  4. Проверить на intact parties, можно ли прозрачно оказать 60- или 90-минутный concierge experience с удовольствием, agency, здоровой социальной динамикой и явным финалом.
  5. Найти content, state, safety, voice, scheduling и support failure modes и создать воспроизводимый evidence package для решения GO / PIVOT / KILL / INCONCLUSIVE.

Non-goals#

  • не оценивать TAM, prevalence проблемы, country ranking или PMF;
  • не доказывать, что US лучше других English-speaking geographies;
  • не получать WTP из интервью, concept rank, email, waitlist или бесплатной брони;
  • не подтверждать автономность AI: concierge может включать раскрытую human assistance;
  • не выбирать 60 против 90 минут статистически по 12 сессиям;
  • не проверять long campaigns, subscription, partner IP, public matchmaking или unrestricted UGC и не считать legal/provider/payment clearance результатом исследования пользователей.

2. Единицы и когорты#

Unit Операционное определение Где используется
host Взрослый организатор, который в последние 6 месяцев реально пытался собрать TTRPG или совместный online game night screen, host interview, diary, invite funnel
guest Взрослый человек, которого host сам пригласил; он независимо consented, joined, declined или no-showed guest interview, diary, debrief
intact_party Host + 2–4 знакомых ему guests; группу не собирают исследователи и не дополняют незнакомцами concierge и все group outcomes
party_version Состав party_id на конкретный слот; каждая замена участника логируется repeat и sensitivity analysis

Individual ratings не превращаются в независимые group observations. Completion, start, repeat и support считаются на уровне party/session; experience публикуется и по людям, и по party distribution.

Когорты не объединяются:

  • P — problem-qualified, concept-unexposed at entry. Непредвзятый относительно solution набор по недавней попытке организовать групповое развлечение, без требования любить AI, RPG или продукт. Это основной problem cohort, но не market-representative sample.
  • S — independent smoke cohort. Новые qualified unique hosts, не участвовавшие в P: каждый входит в denominator при первом показе случайно назначенного message, независимо от дальнейшего slot/invite behavior. Эта выборка измеряет formation, но не prevalence рынка.
  • I — concierge lineage. Подмножество S, которое выбрало реальный deliverable slot, отправило минимум два invite и собрало independently consented intact party. I измеряет experience; formation всегда считается по полному S denominator, а не по уже сформированным I parties.
  • W — future payment/checkout. Новая, не участвовавшая в P, S или I выборка для confirmatory payment test. Её протокол не входит в этот документ.

Участников P, пришедших в concierge, маркируют primed_returner; их можно использовать для operational learning, но нельзя смешивать с primary read когорт S или I. Incentive за интервью не зависит от concept choice, diary completion, брони или положительной оценки.

3. Recruitment, exclusions и внутренние квоты#

Planning cap Phase A — 30 hosts, как задано в program. Это qualitative decision sample, не репрезентативная market sample.

Inclusion#

  • 18+ и способен дать informed consent на английском;
  • может подробно восстановить одну реальную попытку за последние 6 месяцев;
  • для host — может описать реальных потенциальных гостей, но не передаёт их контакты; для Phase B все 3–5 участников отдельно consented до start.

Exclusions#

  • сотрудники/подрядчики проекта, авторы протокола, близкие родственники исследователей;
  • сотрудники/подрядчики прямого конкурента или professional research respondents, скрывшие конфликт;
  • несовершеннолетние, неспособность consent, запрещённая geography;
  • только гипотетический интерес без недавней попытки организовать группу;
  • researcher-assembled party, публичный matchmaking или подмена no-show сотрудником;
  • professional GM как основной респондент P; такие интервью допустимы только как отдельные expert notes;
  • Phase A respondent, уже видевший concept/landing, из primary problem analysis.

Quotas/caps, не market norms#

Это защита от recruitment bias, а не утверждение о рынке:

  • ни один acquisition source не даёт более 10/30 hosts P;
  • AI-specific communities и subscribers одного creator вместе дают не более 6/30;
  • минимум 10/30 должны иметь недавнюю попытку, которая состоялась, чтобы сравнить failure и workaround, а не набирать только severe pain;
  • минимум 10/30 не должны быть regular TTRPG players;
  • primary run использует одну выбранную cleared geography. Любая дополнительная geography получает отдельный run ID, собственный cap и decision table и не вносит участников в эти 30 или общий gate.

Для 12 concierge slots используется allocation, а не market quota: 6 × 60 минут, 6 × 90 минут; 6 × one-shot A, 6 × one-shot B; по 3 sessions в каждой ячейке 60/90 × 3/4–5 players. Любое отклонение публикуется.

До любого participant contact нужен подписанный minimum text-research clearance: допустимость набора в выбранной geography, consent form, incentive, approved text/PII storage, access roles, retention/deletion, withdrawal и incident route. После этого и до полного Phase 0 clearance Phase A может проводиться только через text-chat/async form.

До письменного полного Phase 0 clearance запрещён любой real-user voice или payment: microphone access, audio/video call, recording, STT, voice biometrics, voice cloning, product voice room, card authorization и capture. Phase B voice sessions не стартуют. Synthetic voices и staff dry-runs не являются user evidence.

До первого participant:

  1. Research owner подписывает minimum text-research clearance; до него нет recruitment или interview.
  2. До Phase B legal owner отдельно подписывает geography × provider × audio/STT × payment × age/content matrix.
  3. Consent отдельно перечисляет research purpose, human assistance, recording modalities, subprocessors, retention/deletion, quote use, withdrawal и incident route.
  4. Участник может играть без согласия на публикацию цитат; optional recording consent не bundling с participation.
  5. Host пересылает guest opt-in link сам. До guest consent хранят только event-level статус invited/declined/no_response/no_show, без имени, контакта или host speculation о причине.
  6. Raw PII, contact mapping, interview/debrief free text и recordings находятся в access-controlled approved storage, не в repository. Research artifacts используют pseudonymous IDs.
  7. Withdrawal удаляет разрешённые идентифицируемые данные по policy; агрегат, уже необратимо anonymized, обрабатывается как описано в consent.
  8. Concierge раскрывается как assisted research prototype. Запрещено изображать human-operated response автономным AI.
  9. Safety stop не влияет на incentive. Severe privacy/safety incident немедленно останавливает affected session и дальнейший набор до owner review.

Retention period, storage region, deletion SLA, access roles и incident contacts нельзя угадывать: они заполняются и подписываются в preregistration до набора.

5. Phase A — problem, decision unit и concept comparison#

A1. Host interview, 45–60 минут text-first#

Порядок обязателен: behavior reconstruction → artifacts/workarounds → decision unit → diary setup → только затем concepts.

Цитаты ниже — frozen participant-facing English; служебные инструкции остаются русскими:

  1. “Think about the most recent time you tried to organize a game or shared online evening. What was the first message, and what happened next?”
  2. “Who suggested it, whom did you invite, who replied, who chose the time, and what was the outcome?”
  3. “What preparation happened, who did it, and how much actual time did it take?”
  4. “Did the event need a Game Master or facilitator? Who agreed or declined, and why?”
  5. “Where did rules, setup, voice, tools, or content cause a problem? Tell me about one specific moment.”
  6. “What did the group do instead? What had you already bought or used for this kind of evening?”
  7. “If it happened, what helped it start and finish? If it did not, at what point did it fall apart?”
  8. “Who was part of the decision, and who could veto it?” Не просить контакты.
  9. “How had you actually used AI before, and what made you return or stop?”
  10. “Is there a scheduling message or calendar event you choose to show with personal details redacted?”

Запрещены вопросы «вам нравится идея?», «вы бы заплатили?» и «сколько готовы платить?».

A2. Guest, decline/no-show follow-up и scheduling diary#

Host сам рассылает neutral opt-in. Guests с consent проходят 15–25-минутный text interview:

  1. “What did you understand from the invitation, and when did you decide to join, decline, or wait?”
  2. “What commitment, risk, or alternative affected that decision?”
  3. “Who did you expect to prepare, facilitate, or pay?”
  4. “What happened on the day, and why did you attend, cancel, or not show up?”
  5. “Which parts of the experience should belong to everyone, and which to the host or Game Master?”

Decline и no-show — outcomes, не «некачественные лиды». Не ответившему guest не приписывают причину. Host report и guest report хранятся раздельно; расхождение является finding.

После host interview открывается 14-дневный internal observation window:

timestamp | party_id | actor_role | channel | event
slot_proposed | invite_sent | accepted | declined | no_response
rescheduled | cancelled | no_show | started | ended
reason_code | restricted_source_ref | researcher_prompted

Host логирует только естественную следующую попытку; исследователь не заставляет создавать событие. no_attempt к концу окна — валидный outcome. 14 дней — operational window проекта, не норма частоты game nights.

A3. Neutral concept comparison#

Показывать после behavioral section в заранее сгенерированном randomized order; одинаковые формат, длина, цена (not stated) и отсутствие бренда:

  • Autonomous AI-GM: “Your group plays a complete RPG one-shot. AI runs the world, characters, and rules, so no human Game Master is required.”
  • AI co-GM: “Your group plays an RPG one-shot with a human Game Master. AI helps them prepare scenes, manage rules, and keep notes.”
  • Simpler party-story: “Your group plays a collaborative story with choices and an ending, without a full RPG rules system or an AI Game Master.”

Для каждого: какую последнюю ситуацию мог бы заменить; кто выигрывает/проигрывает; ожидаемый failure; какая информация нужна для решения. Затем — forced rank, вариант none, уверенность 1–7 и условие, которое изменило бы выбор. Concept rank — directional preference, не demand или WTP.

6. Phase S — independent formation smoke#

Phase S открывается после Phase A concept gate, полного clearance обещанной modality и создания 12 реально staffed Phase B slots. Это новый cohort: P respondents не входят в primary S result. Платёжной формы нет; slot/invite behavior не называется WTP.

Recruitment sources, eligibility и traffic stop rule замораживаются заранее; нельзя добирать AI enthusiasts или новый channel после просмотра branch outcomes. Два frozen messages из validation program назначаются concurrent 1:1 до показа страницы, со стратификацией по source. Оба ведут в общий inventory с одинаковыми slot choices, eligibility, UX и expiry. Exposure прекращается, когда нельзя честно предложить один из 12 slots; waitlist и over-cap visits публикуются отдельно и не считаются commitment. Один slot имеет только один active hold; disclosed expiry возвращает не сформированный slot в inventory без overselling.

Каждый qualified unique host входит в S denominator при message_viewed, даже если дальше ничего не сделал. Обязательный event path:

qualified
→ assigned_message
→ message_viewed
→ slot_flow_started or no_action
→ real_slot_selected or abandoned
→ invite_1_sent / invite_2_sent or not_sent
→ accepted / declined / no_response
→ 3+ formed within 7 days or expired
→ eligible_for_I or not_formed

Primary comparison — message_viewed → real_slot_selected + 2 invites sent. Decision gates:

  • hosts with real slot + 2 invites sent / all qualified message_viewed hosts ≥40%;
  • hosts with 3+ formed within 7 days / all hosts with 2+ invites sent ≥25%.

2+ invites / slot_flow_started публикуется только как diagnostic. Рядом публикуются raw branch counts, inventory state at exposure, expiry, decline/no-response и deviations. Ни один host/group не исключается за отрицательный downstream outcome. Сформированные parties переходят в I с теми же IDs; I experience analysis не пересчитывает formation.

Branch result при таком inventory directional: допускается выбрать operational candidate copy, но нельзя заявлять statistical superiority или message-market fit.

Для открытия полного Phase B нужны не только percentages, но и 12 independently formed, consented и scheduled I parties, распределённых по 3 в каждую заранее заданную 60/90 × 3/4–5 players cell. Если traffic/time cap заканчивается раньше, S/B allocation получает INCONCLUSIVE. Уже обещанные sessions исполняются и остаются exploratory; нельзя молча сократить 12-session design или заменить party после известного outcome.

7. Phase B — capacity-limited concierge#

Preconditions и allocation#

Phase B открывается только после voice/legal clearance, consent test, staff-only dry-run, QA двух original-IP one-shots (OS-A, OS-B) и прохождения S formation gate. Primary I parties приходят из S с сохранёнными IDs и отрицательными upstream outcomes; primed_returner sessions анализируются отдельно. Никаких D&D, Knave, partner assets, cloned voices или чужого likeness без письменных прав.

Hard inventory — 12 staffed slots с operator, observer, backup, support buffer и promised fulfillment window. Waitlist не называется demand. Сценарий назначается случайно внутри ячейки по counterbalance:

Cell Sessions Content pattern
60 min × 3 players 3 A, A, B
60 min × 4–5 players 3 A, B, B
90 min × 3 players 3 A, B, B
90 min × 4–5 players 3 A, A, B

Timebox назначается случайно среди compatible slots, если host доступен и для 60, и для 90 минут; иначе используется quota matching и self-selection раскрывается. Party size наблюдается после formation и quota-matched: исследователь не добавляет и не удаляет людей ради ячейки. Дизайн directional: raw counts важнее процентов.

Content/tone QA rubric#

Два независимых reviewers должны дать PASS по каждому пункту обоим one-shots; disagreement закрывается до recruitment:

  • provenance и original-IP rights documented;
  • одинаковый promise: social, humorous, consent-safe adventure с явным ending;
  • сопоставимые decision density, rules/state load и opportunity для каждого игрока влиять на outcome;
  • 60-minute cut не требует скрытого railroad, 90-minute cut добавляет выбор, а не filler;
  • одинаковые content rating, boundaries, intensity и humiliation/coercion restrictions;
  • один labelled ambiguity probe и один false-valid intent probe встроены без наказания игрока;
  • facilitator guide, intervention policy и failure fallback одинаковы;
  • финал достижим без secret researcher compression.

Dry-runs используют staff/synthetic input и не входят в user metrics. Изменение content после первой real session создаёт новую version; до/после не объединяются без sensitivity table.

Service blueprint и failure states#

Stage Frontstage promise Backstage evidence Failure handling
Eligibility/consent Понятный assisted pilot consent version, geography, age F01 missing clearance/consent → no start
Slot/invites Реальный deliverable slot capacity ledger, invite events F02 <3 joined → no researcher replacement; reschedule/cancel
Join/mic Рабочий вход и sound check device/browser, latency, reconnect F03 voice failure → declared fallback; session remains assisted
Boundaries Rating, pause/stop boundary acknowledgment F04 safety concern → pause/stop, incident route
Play/state Choices change the story event/intent/state log F05 invalid/ambiguous → clarify; no silent commit
Branch/privacy Секреты scoped access trace F06 leak → stop, severe incident, gate fail
Tempo/ending Ending в promised timebox scene/time markers F07 no ending → incomplete; не дописывать success вручную
Debrief/follow-up Private feedback first individual + group records F08 missing response stays missing
Operations Обещанный слот исполнен labor/intervention/cost ledger F09 capacity failure → make-good/refund; no overselling

Каждая human action получает category: safety, technical, clarification, state_correction, pacing, content_generation, social_moderation, other; фиксируются start/end, initiator, reason, user-visible status и counterfactual would_session_continue_without_it.

8. Observation, debrief и metrics#

Observation template#

session: {session_id: "", party_id: "", party_version: 1}
recruitment: {geography: "", source: ""}
cell: {minutes: 60, party_size_band: "3", one_shot: "OS-A", content_version: ""}
timestamps: {scheduled: "", joined_3: "", start: "", midpoint: "", ending: ""}
attendance: {host: "", invited: 0, consented: 0, declined: 0, no_response: 0, no_show: 0}
outcome: {started: false, explicit_ending: false, actual_minutes: 0, early_exit_reason: null}
experience: {individual_rating_refs: [], consequential_choice_by_person: {}, social_events: []}
integrity: {intent_probes: [], false_valid_commits: [], corrections: [], privacy_incidents: []}
support: {interventions: [], assisted_minutes: 0, operator_count: 0}
safety: {pause_count: 0, stop: false, incident_ref: null}
evidence_refs: []
redacted_observer_summary_ref: null

Metrics публикуются с raw numerator/denominator:

  • formation: all qualified/message-exposed S hosts, slot-flow started/abandoned, real slot selected, 2+ invites sent/not sent, accepted, declined, no-response, expired, 3+ formed, scheduled и started; отдельно по assigned message и pooled;
  • experience: individual 1–7 fun, agency, social comfort, trust и desire-to-repeat; минимум/median/range внутри party, не только host mean;
  • agency: число consequential choices по участнику, ignored/overridden choices и parties, где не каждый получил такой выбор;
  • social dynamics: turn-taking/coordination, dominance, repair/help, conflict, discomfort, early exit; observer code + private self-report;
  • integrity: false-valid commits / labelled probes и / all state-changing intents; false_valid_commit означает schema-valid action, который система применила, хотя он не соответствовал выраженному намерению участника или нарушал state/rules constraints и требовал clarification; также clarification, correction, duplicate/reconnect и privacy events;
  • operations: interventions по категории, assisted minutes, operator labor, technical fallback, planned/actual duration, explicit ending;
  • next action: выбранная реальная дата повтора — только intent signal; retention возникает лишь после fulfilled second session.

Group debrief guide#

Сначала каждый отвечает приватно; затем 20-минутный group debrief, чтобы host не задавал ответ guests:

  1. Rate 1 = strongly disagree to 7 = strongly agree: “I had fun”; “My choices changed what happened”; “Everyone had room to contribute”; “I trusted the game to keep track”; “I would choose to play this again with this group.” Дать одну причину каждому score.
  2. “What specific moment changed because of your choice?”
  3. “When did the system or facilitator misunderstand an intent, forget a fact, or decide for the group?”
  4. “Who spoke or decided more or less than they wanted? Was there a safe way to intervene?”
  5. “Where did you notice human assistance, and what would have happened without it?”
  6. “What helped or prevented the story from reaching an ending in the promised time?”
  7. “For your next evening, would the group choose autonomous AI-GM, co-GM, party-story, human GM, or none? Why?”
  8. Если группа сама хочет повтор: “What real time could this group meet again?” Не предлагать checkout.

9. Analysis, codebook и double coding#

До первого real participant создаётся codebook-v1.md с definition, include/exclude rule, positive/negative example для:

  • GM_availability, prep_burden, rules_burden, scheduling, tool_voice, content_fit, social_permission, price_past_behavior;
  • host_guest_mismatch, decline, no_response, no_show, workaround, completed_despite_friction;
  • fun, agency, social_inclusion, dominance, trust, desire_repeat;
  • false_valid_commit, clarified_before_commit, critical_state_error, privacy_leak;
  • intervention categories и failure IDs F01–F09.

Два coders независимо кодируют 100% eligibility/exclusion, primary problem attribution, concept rank/reason, false-valid probes, critical defects, privacy/safety incidents и interventions; плюс seeded random 25% остальных interview/debrief records. Они не видят aggregate gate table во время first pass.

Публикуются raw agreement, confusion table и disagreements. Разногласия adjudicates третий reviewer или documented consensus; original labels сохраняются. Codebook changes получают version/date/reason и применяются ко всему corpus или только к новой wave — выбор фиксируется до re-code. Quotes иллюстрируют code, но не заменяют counts.

10. Decision gates — внутренняя risk policy, не market norms#

Пороги замораживаются до recruitment и не называются отраслевыми benchmark.

Gate GO PIVOT / KILL / INCONCLUSIVE
A: problem ≥18/30 hosts дают конкретный recent GM/prep/rules friction; guest evidence не показывает систематически обратную картину Scheduling-only → shorter/asynchronous/co-GM PIVOT; quota/guest evidence incomplete → INCONCLUSIVE
A: concept Autonomous AI-GM получает host plurality, guest ordering не reverses it, а primary objection не требует human GM Co-GM или party-story wins → тестировать winner; none plurality → KILL current proposition
S: formation/allocation ≥40% всех qualified message-exposed hosts выбирают real slot и отправляют 2+ invites; ≥25% invite-sending hosts формируют 3+ party в 7 дней; 12 I parties распределены по 3 в каждой pre-registered cell Low all-exposed send → positioning/social-permission PIVOT; low form → guest-friction/format PIVOT; fewer than 12 allocated parties или incomplete lifecycle → INCONCLUSIVE
B: start ≥75% scheduled intact parties start Decline/no-show reasons определяют guest-friction PIVOT; researcher-filled groups недопустимы
B: experience ≥70% started parties reach explicit ending; no systematic loss of agency/social safety После двух versioned content/tempo iterations completion <50% → KILL format
B: integrity 0 critical state error, privacy leak и false-valid commit в labelled probes Любое событие → PAUSE; root cause + rerun, не усреднение
B: operations Предварительно подписанный support ceiling выдержан и все promised slots resolved/fulfilled Ceiling не был preregistered → INCONCLUSIVE; capacity failure → no checkout handoff

Support ceiling выводится из staff dry-run и реальной staffing capacity, подписывается до participants и публикуется числом; этот документ не выдаёт выдуманный «нормальный» intervention rate.

11. Правила negative evidence#

  1. Decline, no-response, no-show, cancellation, failed join и incomplete остаются в соответствующих denominators.
  2. Legal/provider failure означает NOT TESTED, а не отсутствие спроса.
  3. Recruitment-source failure нельзя переносить на product; eligible invite refusal можно.
  4. Assisted success не считается autonomous success; intervention нельзя скрывать.
  5. Interview enthusiasm, concept rank, slot choice и repeat date не являются WTP, retention или completion.
  6. Один critical privacy/safety/state event не растворяется в average.
  7. Post-hoc subgroup, changed script/content или broken randomization маркируются exploratory.
  8. Geography results не poolятся для прохождения gate; US failure/success не доказывает English-speaking market.
  9. Missing guest reason остаётся unknown; host explanation не заменяет guest evidence.
  10. Waitlist, over-cap demand и невыполнимая бронь не являются valid commitment.
  11. S host остаётся в denominator после message_viewed; failure выбрать slot, отправить invites или сформировать party не является exclusion.
  12. Нейтральный или mixed result — INCONCLUSIVE, а не автоматический GO.

12. Evidence artifacts и naming#

Run ID: PR-YYYYMMDD-NN; participant PER-####, host H-####, guest G-####, party PTY-####, session SES-####. IDs стабильны; PII mapping хранится отдельно.

Repository не является approved raw research-data store. Каждый released run в global-validation/ содержит только структурированные события, числовые ответы, codes и прошедшие release review summaries:

data/primary-research/<run_id>/
  README.md
  preregistration.md
  protocol-snapshot.md
  recruitment-log.csv
  screening-disposition.csv
  consent-index.csv
  measurement/event-schema-vNN.json
  measurement/metric-dictionary-vNN.md
  measurement/identity-attribution-rules-vNN.md
  measurement/qa-fixtures/valid-lifecycle.json
  measurement/qa-fixtures/invalid-lifecycle.json
  measurement/qa-report.json
  phase-a/redacted-host-summaries/H-####.md
  phase-a/redacted-guest-summaries/G-####.md
  phase-a/guest-outcomes.csv
  phase-a/scheduling-diary.csv
  phase-a/concept-order-and-rank.csv
  phase-s/message-assignment.csv
  phase-s/funnel-events.csv
  phase-s/invite-outcomes.csv
  phase-s/inventory-state.csv
  phase-s/metric-table.csv
  phase-b/content/OS-A-vNN.md
  phase-b/content/OS-B-vNN.md
  phase-b/content/qa-rubric.csv
  phase-b/session-allocation.csv
  phase-b/capacity-ledger.csv
  phase-b/observations/SES-####.yaml
  phase-b/debriefs/SES-####-individual-ratings.csv
  phase-b/debriefs/SES-####-redacted-group-summary.md
  phase-b/interventions.csv
  phase-b/incidents.csv
  analysis/codebook-vNN.md
  analysis/coded-records.csv
  analysis/double-coding.csv
  analysis/redacted-negative-cases.md
  analysis/decision-table.csv
  restricted-source-index.csv
  redaction-review.csv
  artifact-index.csv
  manifest.json

event-schema задаёт required fields/enums и version для event_id, event time, eligibility, source, assignment, person/host/party/party-version/session/slot IDs и lifecycle state. metric-dictionary для каждой метрики фиксирует unit, formula, numerator, denominator, exclusions, missing/censored handling, window и owner. identity-attribution-rules фиксирует deduplication, same-party, source attribution и payment lifecycle.

До release автоматический QA проверяет schema validity, unique IDs, допустимый порядок lifecycle, reconciliation funnel counts, frozen assignment, inventory at exposure, party-version consistency и отсутствие невозможных payment/session states. qa-report.json содержит test count, failures и schema/hash; любой failure блокирует decision table.

Free-text interview/debrief, signed consent forms, recordings, contacts, exact scheduling artifacts и PII остаются в approved restricted storage. Repository consent-index.csv хранит только pseudonymous unit ID, consent version, allowed scopes и status. restricted-source-index.csv содержит только opaque source reference, unit ID, consent scope, retention class и release status — без raw path, contact или narrative. Repository summary проходит:

  1. удаление direct identifiers и ненужных quasi-identifiers исследователем;
  2. независимый second-person redaction review;
  3. automated secret/PII scan;
  4. проверку quote/publication consent;
  5. статус approved_for_repository в redaction-review.csv.

pending, restricted или rejected artifact не попадает в tree и manifest. Псевдоним сам по себе не считается anonymization. Если безопасную summary сделать нельзя, в repository остаются только code/count и opaque source reference.

artifact-index.csv содержит artifact_id,path,phase,unit_id,created_at,consent_scope,redaction_status,retention_class,sha256. manifest.json фиксирует hash каждого released artifact, schema version, generator и timestamp.

13. Handoff к checkout/powered tests#

Передача в future cohort W разрешена только когда:

  • все открытые concierge promises имеют terminal status fulfilled, participant_cancelled, researcher_cancelled_makegood_completed или refunded; outstanding slots = 0;
  • capacity ledger доказывает, что следующий advertised inventory реально staffed и deliverable;
  • два one-shots прошли QA, content version заморожена, support ceiling и failure policy измеримы;
  • critical privacy/safety/state incidents закрыты письменно; legal/payment/refund owners дали pass;
  • Phase A/S/B evidence package hashed, negative cases включены, measurement QA passed и решение подписано;
  • будущий payment cohort новый, sample/power/price/refund/authorization/capture protocol зарегистрирован отдельно.

До этого допустим только честно маркированный non-transactional intent. Нельзя принимать card authorization/capture ради «проверки цены» на inventory, который команда не способна исполнить.

14. Pre-registration checklist#

  • Hypotheses, non-goals, geography и US-as-hypothesis wording frozen.
  • Units, same-party/party-version rule, cohort labels и non-pooling rule frozen.
  • Inclusion, exclusions, sources, caps, quotas и incentive documented.
  • Minimum text-research clearance подписан до recruitment; полный legal/voice/payment matrix — до S slot promise и Phase B.
  • Interview guides, 14-day diary schema и guest opt-in path piloted text-only.
  • Concept cards equal-format; randomized order table generated before exposure.
  • S message assignment, all-exposed denominator, event path, shared inventory/expiry и formation gates frozen.
  • OS-A/OS-B rights provenance, versions, content/tone QA и staff dry-runs passed.
  • 12-slot allocation, hard capacity ledger и waitlist behavior frozen.
  • Event schema, metric dictionary, identity/attribution rules, QA fixtures/report, observer template, failure IDs, denominators и support ceiling frozen and tested.
  • Codebook v1, coder training set, random 25% double-code seed и adjudicator assigned.
  • Decision gates, negative-evidence rules, missing-data handling и stop rules frozen.
  • Restricted-storage boundary, two-person redaction release, PII scan, artifact tree, access и hash/manifest tested; protocol snapshot timestamped и hashed до first participant.