# 10. Primary research protocol Статус: **pre-registered execution template; результатов ещё нет**. Scope: English-speaking adults in legally cleared geographies. **US — candidate geography и проверяемая гипотеза, а не доказанный лучший рынок.** Этот протокол исполняет [validation program](./04-validation-program.md), операционализирует P0/P1 из [market/product research gap audit](./09-market-product-research-gap-audit.md), проверяет гипотезы [global PRD](../../docs/prd/2026-07-22-global-party-ai-rpg.md) и создаёт новые primary artifacts для [claim/evidence matrix](./07-claim-evidence-matrix.md). Сам документ не закрывает gaps: их закрывают только результаты. Adjacent/category evidence и его ограничения находятся в [PRD evidence map](../../docs/prd/2026-07-22-global-party-ai-rpg-evidence.md); текущая граница решения — в [independent validation report](./08-validation-report.md). ## 1. Цели и non-goals ### Objectives 1. Восстановить по прошлому поведению, где у существующей компании ломаются организация, выбор GM, подготовка, правила, темп и завершение совместного вечера. 2. Отделить решение хоста от решений гостей, включая отказ, молчание и no-show. 3. Сравнить без leading три решения одной проблемы: autonomous AI-GM, AI co-GM и simpler party-story. 4. Проверить на intact parties, можно ли прозрачно оказать 60- или 90-минутный concierge experience с удовольствием, agency, здоровой социальной динамикой и явным финалом. 5. Найти content, state, safety, voice, scheduling и support failure modes и создать воспроизводимый evidence package для решения `GO / PIVOT / KILL / INCONCLUSIVE`. ### Non-goals - не оценивать TAM, prevalence проблемы, country ranking или PMF; - не доказывать, что US лучше других English-speaking geographies; - не получать WTP из интервью, concept rank, email, waitlist или бесплатной брони; - не подтверждать автономность AI: concierge может включать раскрытую human assistance; - не выбирать 60 против 90 минут статистически по 12 сессиям; - не проверять long campaigns, subscription, partner IP, public matchmaking или unrestricted UGC и не считать legal/provider/payment clearance результатом исследования пользователей. ## 2. Единицы и когорты | Unit | Операционное определение | Где используется | |---|---|---| | `host` | Взрослый организатор, который в последние 6 месяцев реально пытался собрать TTRPG или совместный online game night | screen, host interview, diary, invite funnel | | `guest` | Взрослый человек, которого host сам пригласил; он независимо consented, joined, declined или no-showed | guest interview, diary, debrief | | `intact_party` | Host + 2–4 знакомых ему guests; группу не собирают исследователи и не дополняют незнакомцами | concierge и все group outcomes | | `party_version` | Состав `party_id` на конкретный слот; каждая замена участника логируется | repeat и sensitivity analysis | Individual ratings не превращаются в независимые group observations. Completion, start, repeat и support считаются на уровне party/session; experience публикуется и по людям, и по party distribution. Когорты не объединяются: - **P — problem-qualified, concept-unexposed at entry.** Непредвзятый относительно solution набор по недавней попытке организовать групповое развлечение, без требования любить AI, RPG или продукт. Это основной problem cohort, но не market-representative sample. - **S — independent smoke cohort.** Новые qualified unique hosts, не участвовавшие в P: каждый входит в denominator при первом показе случайно назначенного message, независимо от дальнейшего slot/invite behavior. Эта выборка измеряет formation, но не prevalence рынка. - **I — concierge lineage.** Подмножество S, которое выбрало реальный deliverable slot, отправило минимум два invite и собрало independently consented intact party. I измеряет experience; formation всегда считается по полному S denominator, а не по уже сформированным I parties. - **W — future payment/checkout.** Новая, не участвовавшая в P, S или I выборка для confirmatory payment test. Её протокол не входит в этот документ. Участников P, пришедших в concierge, маркируют `primed_returner`; их можно использовать для operational learning, но нельзя смешивать с primary read когорт S или I. Incentive за интервью не зависит от concept choice, diary completion, брони или положительной оценки. ## 3. Recruitment, exclusions и внутренние квоты Planning cap Phase A — `30 hosts`, как задано в [program](./04-validation-program.md). Это qualitative decision sample, не репрезентативная market sample. ### Inclusion - 18+ и способен дать informed consent на английском; - может подробно восстановить одну реальную попытку за последние 6 месяцев; - для host — может описать реальных потенциальных гостей, но не передаёт их контакты; для Phase B все 3–5 участников отдельно consented до start. ### Exclusions - сотрудники/подрядчики проекта, авторы протокола, близкие родственники исследователей; - сотрудники/подрядчики прямого конкурента или professional research respondents, скрывшие конфликт; - несовершеннолетние, неспособность consent, запрещённая geography; - только гипотетический интерес без недавней попытки организовать группу; - researcher-assembled party, публичный matchmaking или подмена no-show сотрудником; - professional GM как основной респондент P; такие интервью допустимы только как отдельные expert notes; - Phase A respondent, уже видевший concept/landing, из primary problem analysis. ### Quotas/caps, не market norms Это защита от recruitment bias, а не утверждение о рынке: - ни один acquisition source не даёт более `10/30` hosts P; - AI-specific communities и subscribers одного creator вместе дают не более `6/30`; - минимум `10/30` должны иметь недавнюю попытку, которая состоялась, чтобы сравнить failure и workaround, а не набирать только severe pain; - минимум `10/30` не должны быть regular TTRPG players; - primary run использует одну выбранную cleared geography. Любая дополнительная geography получает отдельный run ID, собственный cap и decision table и не вносит участников в эти `30` или общий gate. Для 12 concierge slots используется allocation, а не market quota: 6 × 60 минут, 6 × 90 минут; 6 × one-shot A, 6 × one-shot B; по 3 sessions в каждой ячейке `60/90 × 3/4–5 players`. Любое отклонение публикуется. ## 4. Ethics, consent и работа с данными До любого participant contact нужен подписанный **minimum text-research clearance**: допустимость набора в выбранной geography, consent form, incentive, approved text/PII storage, access roles, retention/deletion, withdrawal и incident route. После этого и до полного Phase 0 clearance Phase A может проводиться только через text-chat/async form. **До письменного полного Phase 0 clearance запрещён любой real-user voice или payment:** microphone access, audio/video call, recording, STT, voice biometrics, voice cloning, product voice room, card authorization и capture. Phase B voice sessions не стартуют. Synthetic voices и staff dry-runs не являются user evidence. До первого participant: 1. Research owner подписывает minimum text-research clearance; до него нет recruitment или interview. 2. До Phase B legal owner отдельно подписывает geography × provider × audio/STT × payment × age/content matrix. 3. Consent отдельно перечисляет research purpose, human assistance, recording modalities, subprocessors, retention/deletion, quote use, withdrawal и incident route. 4. Участник может играть без согласия на публикацию цитат; optional recording consent не bundling с participation. 5. Host пересылает guest opt-in link сам. До guest consent хранят только event-level статус `invited/declined/no_response/no_show`, без имени, контакта или host speculation о причине. 6. Raw PII, contact mapping, interview/debrief free text и recordings находятся в access-controlled approved storage, не в repository. Research artifacts используют pseudonymous IDs. 7. Withdrawal удаляет разрешённые идентифицируемые данные по policy; агрегат, уже необратимо anonymized, обрабатывается как описано в consent. 8. Concierge раскрывается как assisted research prototype. Запрещено изображать human-operated response автономным AI. 9. Safety stop не влияет на incentive. Severe privacy/safety incident немедленно останавливает affected session и дальнейший набор до owner review. Retention period, storage region, deletion SLA, access roles и incident contacts нельзя угадывать: они заполняются и подписываются в preregistration до набора. ## 5. Phase A — problem, decision unit и concept comparison ### A1. Host interview, 45–60 минут text-first Порядок обязателен: behavior reconstruction → artifacts/workarounds → decision unit → diary setup → только затем concepts. Цитаты ниже — frozen participant-facing English; служебные инструкции остаются русскими: 1. “Think about the most recent time you tried to organize a game or shared online evening. What was the first message, and what happened next?” 2. “Who suggested it, whom did you invite, who replied, who chose the time, and what was the outcome?” 3. “What preparation happened, who did it, and how much actual time did it take?” 4. “Did the event need a Game Master or facilitator? Who agreed or declined, and why?” 5. “Where did rules, setup, voice, tools, or content cause a problem? Tell me about one specific moment.” 6. “What did the group do instead? What had you already bought or used for this kind of evening?” 7. “If it happened, what helped it start and finish? If it did not, at what point did it fall apart?” 8. “Who was part of the decision, and who could veto it?” Не просить контакты. 9. “How had you actually used AI before, and what made you return or stop?” 10. “Is there a scheduling message or calendar event you choose to show with personal details redacted?” Запрещены вопросы «вам нравится идея?», «вы бы заплатили?» и «сколько готовы платить?». ### A2. Guest, decline/no-show follow-up и scheduling diary Host сам рассылает neutral opt-in. Guests с consent проходят 15–25-минутный text interview: 1. “What did you understand from the invitation, and when did you decide to join, decline, or wait?” 2. “What commitment, risk, or alternative affected that decision?” 3. “Who did you expect to prepare, facilitate, or pay?” 4. “What happened on the day, and why did you attend, cancel, or not show up?” 5. “Which parts of the experience should belong to everyone, and which to the host or Game Master?” Decline и no-show — outcomes, не «некачественные лиды». Не ответившему guest не приписывают причину. Host report и guest report хранятся раздельно; расхождение является finding. После host interview открывается **14-дневный internal observation window**: ```text timestamp | party_id | actor_role | channel | event slot_proposed | invite_sent | accepted | declined | no_response rescheduled | cancelled | no_show | started | ended reason_code | restricted_source_ref | researcher_prompted ``` Host логирует только естественную следующую попытку; исследователь не заставляет создавать событие. `no_attempt` к концу окна — валидный outcome. 14 дней — operational window проекта, не норма частоты game nights. ### A3. Neutral concept comparison Показывать после behavioral section в заранее сгенерированном randomized order; одинаковые формат, длина, цена (`not stated`) и отсутствие бренда: - **Autonomous AI-GM:** “Your group plays a complete RPG one-shot. AI runs the world, characters, and rules, so no human Game Master is required.” - **AI co-GM:** “Your group plays an RPG one-shot with a human Game Master. AI helps them prepare scenes, manage rules, and keep notes.” - **Simpler party-story:** “Your group plays a collaborative story with choices and an ending, without a full RPG rules system or an AI Game Master.” Для каждого: какую последнюю ситуацию мог бы заменить; кто выигрывает/проигрывает; ожидаемый failure; какая информация нужна для решения. Затем — forced rank, вариант `none`, уверенность `1–7` и условие, которое изменило бы выбор. Concept rank — directional preference, не demand или WTP. ## 6. Phase S — independent formation smoke Phase S открывается после Phase A concept gate, полного clearance обещанной modality и создания 12 реально staffed Phase B slots. Это новый cohort: P respondents не входят в primary S result. Платёжной формы нет; slot/invite behavior не называется WTP. Recruitment sources, eligibility и traffic stop rule замораживаются заранее; нельзя добирать AI enthusiasts или новый channel после просмотра branch outcomes. Два frozen messages из [validation program](./04-validation-program.md) назначаются concurrent `1:1` до показа страницы, со стратификацией по source. Оба ведут в общий inventory с одинаковыми slot choices, eligibility, UX и expiry. Exposure прекращается, когда нельзя честно предложить один из 12 slots; waitlist и over-cap visits публикуются отдельно и не считаются commitment. Один slot имеет только один active hold; disclosed expiry возвращает не сформированный slot в inventory без overselling. Каждый qualified unique host входит в S denominator при `message_viewed`, даже если дальше ничего не сделал. Обязательный event path: ```text qualified → assigned_message → message_viewed → slot_flow_started or no_action → real_slot_selected or abandoned → invite_1_sent / invite_2_sent or not_sent → accepted / declined / no_response → 3+ formed within 7 days or expired → eligible_for_I or not_formed ``` Primary comparison — `message_viewed → real_slot_selected + 2 invites sent`. Decision gates: - `hosts with real slot + 2 invites sent / all qualified message_viewed hosts ≥40%`; - `hosts with 3+ formed within 7 days / all hosts with 2+ invites sent ≥25%`. `2+ invites / slot_flow_started` публикуется только как diagnostic. Рядом публикуются raw branch counts, inventory state at exposure, expiry, decline/no-response и deviations. Ни один host/group не исключается за отрицательный downstream outcome. Сформированные parties переходят в I с теми же IDs; I experience analysis не пересчитывает formation. Branch result при таком inventory directional: допускается выбрать operational candidate copy, но нельзя заявлять statistical superiority или message-market fit. Для открытия полного Phase B нужны не только percentages, но и 12 independently formed, consented и scheduled I parties, распределённых по 3 в каждую заранее заданную `60/90 × 3/4–5 players` cell. Если traffic/time cap заканчивается раньше, S/B allocation получает `INCONCLUSIVE`. Уже обещанные sessions исполняются и остаются exploratory; нельзя молча сократить 12-session design или заменить party после известного outcome. ## 7. Phase B — capacity-limited concierge ### Preconditions и allocation Phase B открывается только после voice/legal clearance, consent test, staff-only dry-run, QA двух original-IP one-shots (`OS-A`, `OS-B`) и прохождения S formation gate. Primary I parties приходят из S с сохранёнными IDs и отрицательными upstream outcomes; `primed_returner` sessions анализируются отдельно. Никаких D&D, Knave, partner assets, cloned voices или чужого likeness без письменных прав. Hard inventory — 12 staffed slots с operator, observer, backup, support buffer и promised fulfillment window. Waitlist не называется demand. Сценарий назначается случайно внутри ячейки по counterbalance: | Cell | Sessions | Content pattern | |---|---:|---| | 60 min × 3 players | 3 | A, A, B | | 60 min × 4–5 players | 3 | A, B, B | | 90 min × 3 players | 3 | A, B, B | | 90 min × 4–5 players | 3 | A, A, B | Timebox назначается случайно среди compatible slots, если host доступен и для 60, и для 90 минут; иначе используется quota matching и self-selection раскрывается. Party size наблюдается после formation и quota-matched: исследователь не добавляет и не удаляет людей ради ячейки. Дизайн directional: raw counts важнее процентов. ### Content/tone QA rubric Два независимых reviewers должны дать `PASS` по каждому пункту обоим one-shots; disagreement закрывается до recruitment: - provenance и original-IP rights documented; - одинаковый promise: social, humorous, consent-safe adventure с явным ending; - сопоставимые decision density, rules/state load и opportunity для каждого игрока влиять на outcome; - 60-minute cut не требует скрытого railroad, 90-minute cut добавляет выбор, а не filler; - одинаковые content rating, boundaries, intensity и humiliation/coercion restrictions; - один labelled ambiguity probe и один false-valid intent probe встроены без наказания игрока; - facilitator guide, intervention policy и failure fallback одинаковы; - финал достижим без secret researcher compression. Dry-runs используют staff/synthetic input и не входят в user metrics. Изменение content после первой real session создаёт новую version; до/после не объединяются без sensitivity table. ### Service blueprint и failure states | Stage | Frontstage promise | Backstage evidence | Failure handling | |---|---|---|---| | Eligibility/consent | Понятный assisted pilot | consent version, geography, age | `F01` missing clearance/consent → no start | | Slot/invites | Реальный deliverable slot | capacity ledger, invite events | `F02` <3 joined → no researcher replacement; reschedule/cancel | | Join/mic | Рабочий вход и sound check | device/browser, latency, reconnect | `F03` voice failure → declared fallback; session remains assisted | | Boundaries | Rating, pause/stop | boundary acknowledgment | `F04` safety concern → pause/stop, incident route | | Play/state | Choices change the story | event/intent/state log | `F05` invalid/ambiguous → clarify; no silent commit | | Branch/privacy | Секреты scoped | access trace | `F06` leak → stop, severe incident, gate fail | | Tempo/ending | Ending в promised timebox | scene/time markers | `F07` no ending → incomplete; не дописывать success вручную | | Debrief/follow-up | Private feedback first | individual + group records | `F08` missing response stays missing | | Operations | Обещанный слот исполнен | labor/intervention/cost ledger | `F09` capacity failure → make-good/refund; no overselling | Каждая human action получает category: `safety`, `technical`, `clarification`, `state_correction`, `pacing`, `content_generation`, `social_moderation`, `other`; фиксируются start/end, initiator, reason, user-visible status и counterfactual `would_session_continue_without_it`. ## 8. Observation, debrief и metrics ### Observation template ```yaml session: {session_id: "", party_id: "", party_version: 1} recruitment: {geography: "", source: ""} cell: {minutes: 60, party_size_band: "3", one_shot: "OS-A", content_version: ""} timestamps: {scheduled: "", joined_3: "", start: "", midpoint: "", ending: ""} attendance: {host: "", invited: 0, consented: 0, declined: 0, no_response: 0, no_show: 0} outcome: {started: false, explicit_ending: false, actual_minutes: 0, early_exit_reason: null} experience: {individual_rating_refs: [], consequential_choice_by_person: {}, social_events: []} integrity: {intent_probes: [], false_valid_commits: [], corrections: [], privacy_incidents: []} support: {interventions: [], assisted_minutes: 0, operator_count: 0} safety: {pause_count: 0, stop: false, incident_ref: null} evidence_refs: [] redacted_observer_summary_ref: null ``` Metrics публикуются с raw numerator/denominator: - formation: all qualified/message-exposed S hosts, slot-flow started/abandoned, real slot selected, 2+ invites sent/not sent, accepted, declined, no-response, expired, 3+ formed, scheduled и started; отдельно по assigned message и pooled; - experience: individual `1–7` fun, agency, social comfort, trust и desire-to-repeat; минимум/median/range внутри party, не только host mean; - agency: число consequential choices по участнику, ignored/overridden choices и parties, где не каждый получил такой выбор; - social dynamics: turn-taking/coordination, dominance, repair/help, conflict, discomfort, early exit; observer code + private self-report; - integrity: false-valid commits / labelled probes и / all state-changing intents; `false_valid_commit` означает schema-valid action, который система применила, хотя он не соответствовал выраженному намерению участника или нарушал state/rules constraints и требовал clarification; также clarification, correction, duplicate/reconnect и privacy events; - operations: interventions по категории, assisted minutes, operator labor, technical fallback, planned/actual duration, explicit ending; - next action: выбранная реальная дата повтора — только intent signal; retention возникает лишь после fulfilled second session. ### Group debrief guide Сначала каждый отвечает приватно; затем 20-минутный group debrief, чтобы host не задавал ответ guests: 1. Rate `1 = strongly disagree` to `7 = strongly agree`: “I had fun”; “My choices changed what happened”; “Everyone had room to contribute”; “I trusted the game to keep track”; “I would choose to play this again with this group.” Дать одну причину каждому score. 2. “What specific moment changed because of your choice?” 3. “When did the system or facilitator misunderstand an intent, forget a fact, or decide for the group?” 4. “Who spoke or decided more or less than they wanted? Was there a safe way to intervene?” 5. “Where did you notice human assistance, and what would have happened without it?” 6. “What helped or prevented the story from reaching an ending in the promised time?” 7. “For your next evening, would the group choose autonomous AI-GM, co-GM, party-story, human GM, or none? Why?” 8. Если группа сама хочет повтор: “What real time could this group meet again?” Не предлагать checkout. ## 9. Analysis, codebook и double coding До первого real participant создаётся `codebook-v1.md` с definition, include/exclude rule, positive/negative example для: - `GM_availability`, `prep_burden`, `rules_burden`, `scheduling`, `tool_voice`, `content_fit`, `social_permission`, `price_past_behavior`; - `host_guest_mismatch`, `decline`, `no_response`, `no_show`, `workaround`, `completed_despite_friction`; - `fun`, `agency`, `social_inclusion`, `dominance`, `trust`, `desire_repeat`; - `false_valid_commit`, `clarified_before_commit`, `critical_state_error`, `privacy_leak`; - intervention categories и failure IDs `F01–F09`. Два coders независимо кодируют 100% eligibility/exclusion, primary problem attribution, concept rank/reason, false-valid probes, critical defects, privacy/safety incidents и interventions; плюс seeded random 25% остальных interview/debrief records. Они не видят aggregate gate table во время first pass. Публикуются raw agreement, confusion table и disagreements. Разногласия adjudicates третий reviewer или documented consensus; original labels сохраняются. Codebook changes получают version/date/reason и применяются ко всему corpus или только к новой wave — выбор фиксируется до re-code. Quotes иллюстрируют code, но не заменяют counts. ## 10. Decision gates — внутренняя risk policy, не market norms Пороги замораживаются до recruitment и не называются отраслевыми benchmark. | Gate | GO | PIVOT / KILL / INCONCLUSIVE | |---|---|---| | A: problem | `≥18/30` hosts дают конкретный recent GM/prep/rules friction; guest evidence не показывает систематически обратную картину | Scheduling-only → shorter/asynchronous/co-GM PIVOT; quota/guest evidence incomplete → INCONCLUSIVE | | A: concept | Autonomous AI-GM получает host plurality, guest ordering не reverses it, а primary objection не требует human GM | Co-GM или party-story wins → тестировать winner; `none` plurality → KILL current proposition | | S: formation/allocation | `≥40%` всех qualified message-exposed hosts выбирают real slot и отправляют 2+ invites; `≥25%` invite-sending hosts формируют 3+ party в 7 дней; 12 I parties распределены по 3 в каждой pre-registered cell | Low all-exposed send → positioning/social-permission PIVOT; low form → guest-friction/format PIVOT; fewer than 12 allocated parties или incomplete lifecycle → INCONCLUSIVE | | B: start | `≥75%` scheduled intact parties start | Decline/no-show reasons определяют guest-friction PIVOT; researcher-filled groups недопустимы | | B: experience | `≥70%` started parties reach explicit ending; no systematic loss of agency/social safety | После двух versioned content/tempo iterations completion `<50%` → KILL format | | B: integrity | `0` critical state error, privacy leak и false-valid commit в labelled probes | Любое событие → PAUSE; root cause + rerun, не усреднение | | B: operations | Предварительно подписанный support ceiling выдержан и все promised slots resolved/fulfilled | Ceiling не был preregistered → INCONCLUSIVE; capacity failure → no checkout handoff | Support ceiling выводится из staff dry-run и реальной staffing capacity, подписывается до participants и публикуется числом; этот документ не выдаёт выдуманный «нормальный» intervention rate. ## 11. Правила negative evidence 1. Decline, no-response, no-show, cancellation, failed join и incomplete остаются в соответствующих denominators. 2. Legal/provider failure означает `NOT TESTED`, а не отсутствие спроса. 3. Recruitment-source failure нельзя переносить на product; eligible invite refusal можно. 4. Assisted success не считается autonomous success; intervention нельзя скрывать. 5. Interview enthusiasm, concept rank, slot choice и repeat date не являются WTP, retention или completion. 6. Один critical privacy/safety/state event не растворяется в average. 7. Post-hoc subgroup, changed script/content или broken randomization маркируются exploratory. 8. Geography results не poolятся для прохождения gate; US failure/success не доказывает English-speaking market. 9. Missing guest reason остаётся `unknown`; host explanation не заменяет guest evidence. 10. Waitlist, over-cap demand и невыполнимая бронь не являются valid commitment. 11. S host остаётся в denominator после `message_viewed`; failure выбрать slot, отправить invites или сформировать party не является exclusion. 12. Нейтральный или mixed result — `INCONCLUSIVE`, а не автоматический GO. ## 12. Evidence artifacts и naming Run ID: `PR-YYYYMMDD-NN`; participant `PER-####`, host `H-####`, guest `G-####`, party `PTY-####`, session `SES-####`. IDs стабильны; PII mapping хранится отдельно. Repository **не является approved raw research-data store**. Каждый released run в `global-validation/` содержит только структурированные события, числовые ответы, codes и прошедшие release review summaries: ```text data/primary-research// README.md preregistration.md protocol-snapshot.md recruitment-log.csv screening-disposition.csv consent-index.csv measurement/event-schema-vNN.json measurement/metric-dictionary-vNN.md measurement/identity-attribution-rules-vNN.md measurement/qa-fixtures/valid-lifecycle.json measurement/qa-fixtures/invalid-lifecycle.json measurement/qa-report.json phase-a/redacted-host-summaries/H-####.md phase-a/redacted-guest-summaries/G-####.md phase-a/guest-outcomes.csv phase-a/scheduling-diary.csv phase-a/concept-order-and-rank.csv phase-s/message-assignment.csv phase-s/funnel-events.csv phase-s/invite-outcomes.csv phase-s/inventory-state.csv phase-s/metric-table.csv phase-b/content/OS-A-vNN.md phase-b/content/OS-B-vNN.md phase-b/content/qa-rubric.csv phase-b/session-allocation.csv phase-b/capacity-ledger.csv phase-b/observations/SES-####.yaml phase-b/debriefs/SES-####-individual-ratings.csv phase-b/debriefs/SES-####-redacted-group-summary.md phase-b/interventions.csv phase-b/incidents.csv analysis/codebook-vNN.md analysis/coded-records.csv analysis/double-coding.csv analysis/redacted-negative-cases.md analysis/decision-table.csv restricted-source-index.csv redaction-review.csv artifact-index.csv manifest.json ``` `event-schema` задаёт required fields/enums и version для `event_id`, event time, eligibility, source, assignment, person/host/party/party-version/session/slot IDs и lifecycle state. `metric-dictionary` для каждой метрики фиксирует unit, formula, numerator, denominator, exclusions, missing/censored handling, window и owner. `identity-attribution-rules` фиксирует deduplication, same-party, source attribution и payment lifecycle. До release автоматический QA проверяет schema validity, unique IDs, допустимый порядок lifecycle, reconciliation funnel counts, frozen assignment, inventory at exposure, party-version consistency и отсутствие невозможных payment/session states. `qa-report.json` содержит test count, failures и schema/hash; любой failure блокирует decision table. Free-text interview/debrief, signed consent forms, recordings, contacts, exact scheduling artifacts и PII остаются в approved restricted storage. Repository `consent-index.csv` хранит только pseudonymous unit ID, consent version, allowed scopes и status. `restricted-source-index.csv` содержит только opaque source reference, unit ID, consent scope, retention class и release status — без raw path, contact или narrative. Repository summary проходит: 1. удаление direct identifiers и ненужных quasi-identifiers исследователем; 2. независимый second-person redaction review; 3. automated secret/PII scan; 4. проверку quote/publication consent; 5. статус `approved_for_repository` в `redaction-review.csv`. `pending`, `restricted` или rejected artifact не попадает в tree и manifest. Псевдоним сам по себе не считается anonymization. Если безопасную summary сделать нельзя, в repository остаются только code/count и opaque source reference. `artifact-index.csv` содержит `artifact_id,path,phase,unit_id,created_at,consent_scope,redaction_status,retention_class,sha256`. `manifest.json` фиксирует hash каждого released artifact, schema version, generator и timestamp. ## 13. Handoff к checkout/powered tests Передача в future cohort W разрешена только когда: - все открытые concierge promises имеют terminal status `fulfilled`, `participant_cancelled`, `researcher_cancelled_makegood_completed` или `refunded`; outstanding slots = `0`; - capacity ledger доказывает, что следующий advertised inventory реально staffed и deliverable; - два one-shots прошли QA, content version заморожена, support ceiling и failure policy измеримы; - critical privacy/safety/state incidents закрыты письменно; legal/payment/refund owners дали pass; - Phase A/S/B evidence package hashed, negative cases включены, measurement QA passed и решение подписано; - будущий payment cohort новый, sample/power/price/refund/authorization/capture protocol зарегистрирован отдельно. До этого допустим только честно маркированный non-transactional intent. Нельзя принимать card authorization/capture ради «проверки цены» на inventory, который команда не способна исполнить. ## 14. Pre-registration checklist - [ ] Hypotheses, non-goals, geography и US-as-hypothesis wording frozen. - [ ] Units, same-party/party-version rule, cohort labels и non-pooling rule frozen. - [ ] Inclusion, exclusions, sources, caps, quotas и incentive documented. - [ ] Minimum text-research clearance подписан до recruitment; полный legal/voice/payment matrix — до S slot promise и Phase B. - [ ] Interview guides, 14-day diary schema и guest opt-in path piloted text-only. - [ ] Concept cards equal-format; randomized order table generated before exposure. - [ ] S message assignment, all-exposed denominator, event path, shared inventory/expiry и formation gates frozen. - [ ] OS-A/OS-B rights provenance, versions, content/tone QA и staff dry-runs passed. - [ ] 12-slot allocation, hard capacity ledger и waitlist behavior frozen. - [ ] Event schema, metric dictionary, identity/attribution rules, QA fixtures/report, observer template, failure IDs, denominators и support ceiling frozen and tested. - [ ] Codebook v1, coder training set, random 25% double-code seed и adjudicator assigned. - [ ] Decision gates, negative-evidence rules, missing-data handling и stop rules frozen. - [ ] Restricted-storage boundary, two-person redaction release, PII scan, artifact tree, access и hash/manifest tested; protocol snapshot timestamped и hashed до first participant.