sincLLM operator guide · change protocol
Product Distiller Change Protocol: Versioning, Canary Tests, and Rollback
Change turning agent session evidence into a reusable product package without silently invalidating its evidence, interfaces, or rollback path.
The direct answer
Change turning agent session evidence into a reusable product package without silently invalidating its evidence, interfaces, or rollback path. The working output is A change-control protocol with baseline fingerprint, canary scope, rollback trigger, and post-change regression list.
For Product Distiller, the bounded capability is turning agent session evidence into a reusable product package. Begin only when the team can supply Claude or Codex session logs plus an explicit product goal. The documented delivery target is the catalog's fifteen-artifact product package; anything broader requires a new scope and a new authority decision.
The controlled change protocol
This change protocol is for teams with successful Claude or Codex sessions that cannot yet be replayed, tested, or handed to another operator. It begins with Claude or Codex session logs plus an explicit product goal and stays inside the documented workflow: session freeze, provenance extraction, contract recovery, procedure definition, replay fixtures, test mapping, decision records, and certification gates. For Product Distiller, the change protocol remains reviewable because its decisions have named owners, evidence fields, and stop conditions.
A change to Product Distiller starts from a content-addressed baseline for turning agent session evidence into a reusable product package and ends only when both candidate and rollback states are observable. This change protocol separates modification from release permission, and it prevents a successful canary for Product Distiller from excusing any untested acceptance criterion.
| Stage | Action | Owner | Evidence | Stop condition |
|---|---|---|---|---|
| 1. Freeze baseline | Hash the current artifact, contract, evidence packet, and rollback target. | product owner | baseline fingerprint | Stop if any required input is missing. |
| 2. Classify change | Map the proposal to session freeze, provenance extraction, contract recovery, procedure definition, replay fixtures, test mapping, decision records, and certification gates and identify affected criteria. | session analyst | impact map | Require owner input for scope or authority expansion. |
| 3. Build candidate | Change only declared surfaces and preserve prior bytes or state. | session analyst | candidate hash and delta | Reject unrelated mutation. |
| 4. Run canary | Exercise a smallest representative case including “cleaning a transcript without extracting a contract”. | independent certifier | canary receipt | Do not widen after a partial or unavailable result. |
| 5. Verify | Test “source sessions are frozen and inventoried” plus affected regressions with a producer-distinct reviewer. | independent certifier | criterion report | NOT_TESTED keeps the release closed. |
| 6. Expand or roll back | Release the remaining bounded set only after canary PASS; otherwise restore baseline. | independent certifier | release or rollback receipt | Stop after the declared repair ceiling. |
Copyable change record
{
"change_id": "CHG-ART-11-05",
"baseline_fingerprint": "sha256:<current-artifact>",
"affected_criteria": [
"source sessions are frozen and inventoried"
],
"canary_scope": "smallest representative, reversible case",
"rollback_trigger": "cleaning a transcript without extracting a contract",
"post_change_regressions": [
"source sessions are frozen and inventoried",
"observations are separated from design judgments",
"the procedure runs in a clean context",
"normal and failure fixtures map to requirements",
"open assumptions remain visible"
],
"release_status": "HOLD_UNTIL_INDEPENDENT_PASS"
}
Rollback decision
Rollback on an explicit canary failure, a stale or missing verifier binding, an unexpected change outside the declared surface, or a breach of the product boundary. Record the destination readback after restoration. If restoration cannot be verified, report the state as unresolved rather than claiming recovery.
Run the workflow as a sequence of decisions
The Product Distiller change protocol follows this working sequence: session freeze, provenance extraction, contract recovery, procedure definition, replay fixtures, test mapping, decision records, and certification gates. Within this artifact, each phrase marks a state boundary for turning agent session evidence into a reusable product package. A stage output becomes the next named input, while a failed, missing, or unavailable check keeps the dependent change protocol decision closed.
| Step | Decision owner | Observable criterion | Evidence to retain | Counterexample policy |
|---|---|---|---|---|
| 1 | product owner | Source sessions are frozen and inventoried. | Direct observation or test bound to the current artifact | Run a safe negative fixture from the separate failure register; do not infer a one-to-one mapping by list position. |
| 2 | session analyst | Observations are separated from design judgments. | Direct observation or test bound to the current artifact | Run a safe negative fixture from the separate failure register; do not infer a one-to-one mapping by list position. |
| 3 | procedure author | The procedure runs in a clean context. | Direct observation or test bound to the current artifact | Run a safe negative fixture from the separate failure register; do not infer a one-to-one mapping by list position. |
| 4 | test owner | Normal and failure fixtures map to requirements. | Direct observation or test bound to the current artifact | Run a safe negative fixture from the separate failure register; do not infer a one-to-one mapping by list position. |
| 5 | independent certifier | Open assumptions remain visible. | Direct observation or test bound to the current artifact | Run a safe negative fixture from the separate failure register; do not infer a one-to-one mapping by list position. |
Separate failure register
FAIL-01: Cleaning a transcript without extracting a contract.FAIL-02: Converting interpretation into observed fact.FAIL-03: Replay that relies on hidden operator knowledge.FAIL-04: Tests that cover only the successful source run.FAIL-05: An artifact package with no reopen conditions.
The register supplies negative cases for the complete acceptance set. A reviewer determines affected checks from observed evidence; array position never asserts that one failure proves or disproves one criterion.
The producer can explain what it attempted, but the independent certifier evaluates the evidence. If the artifact changes, its prior verdict expires. This is especially important for turning agent session evidence into a reusable product package, where a plausible narrative can hide a stale configuration, an untested negative case, or an authority mismatch.
Failure and recovery drills
A useful Product Distiller change protocol explains what happens when its happy path breaks. These drills come from the accepted product truth record rather than a claim that every buyer has each failure. Use safe synthetic or authorized observations for turning agent session evidence into a reusable product package, and keep private credentials out of every fixture.
1. Cleaning a transcript without extracting a contract.
Detect for Product Distiller: product owner captures a direct readback or safe fixture that makes this change protocol condition observable. Its record binds source, time, method, and the current ART-11-05 fingerprint.
Contain the change protocol: stop only the affected Product Distiller path after observing “cleaning a transcript without extracting a contract”. Preserve its failed material and last verified state instead of erasing evidence or blindly repeating an external effect.
Recover and prove: apply the smallest authorized Product Distiller correction, then have a distinct reviewer re-evaluate the complete accepted check set. Do not select one check merely because it shares this failure's list position. If any affected change protocol check cannot run, its result remains NOT_TESTED.
2. Converting interpretation into observed fact.
Detect for Product Distiller: session analyst captures a direct readback or safe fixture that makes this change protocol condition observable. Its record binds source, time, method, and the current ART-11-05 fingerprint.
Contain the change protocol: stop only the affected Product Distiller path after observing “converting interpretation into observed fact”. Preserve its failed material and last verified state instead of erasing evidence or blindly repeating an external effect.
Recover and prove: apply the smallest authorized Product Distiller correction, then have a distinct reviewer re-evaluate the complete accepted check set. Do not select one check merely because it shares this failure's list position. If any affected change protocol check cannot run, its result remains NOT_TESTED.
3. Replay that relies on hidden operator knowledge.
Detect for Product Distiller: procedure author captures a direct readback or safe fixture that makes this change protocol condition observable. Its record binds source, time, method, and the current ART-11-05 fingerprint.
Contain the change protocol: stop only the affected Product Distiller path after observing “replay that relies on hidden operator knowledge”. Preserve its failed material and last verified state instead of erasing evidence or blindly repeating an external effect.
Recover and prove: apply the smallest authorized Product Distiller correction, then have a distinct reviewer re-evaluate the complete accepted check set. Do not select one check merely because it shares this failure's list position. If any affected change protocol check cannot run, its result remains NOT_TESTED.
4. Tests that cover only the successful source run.
Detect for Product Distiller: test owner captures a direct readback or safe fixture that makes this change protocol condition observable. Its record binds source, time, method, and the current ART-11-05 fingerprint.
Contain the change protocol: stop only the affected Product Distiller path after observing “tests that cover only the successful source run”. Preserve its failed material and last verified state instead of erasing evidence or blindly repeating an external effect.
Recover and prove: apply the smallest authorized Product Distiller correction, then have a distinct reviewer re-evaluate the complete accepted check set. Do not select one check merely because it shares this failure's list position. If any affected change protocol check cannot run, its result remains NOT_TESTED.
5. An artifact package with no reopen conditions.
Detect for Product Distiller: independent certifier captures a direct readback or safe fixture that makes this change protocol condition observable. Its record binds source, time, method, and the current ART-11-05 fingerprint.
Contain the change protocol: stop only the affected Product Distiller path after observing “an artifact package with no reopen conditions”. Preserve its failed material and last verified state instead of erasing evidence or blindly repeating an external effect.
Recover and prove: apply the smallest authorized Product Distiller correction, then have a distinct reviewer re-evaluate the complete accepted check set. Do not select one check merely because it shares this failure's list position. If any affected change protocol check cannot run, its result remains NOT_TESTED.
Ownership and handoff
| Role | Owned decision | Separation rule |
|---|---|---|
| product owner | owns the request boundary and confirms the intended consequence | May not approve evidence it produced when independent review is required |
| session analyst | owns the bounded implementation surface and action receipt | May not approve evidence it produced when independent review is required |
| procedure author | owns source material, freshness, and the claim-to-evidence map | May not approve evidence it produced when independent review is required |
| test owner | owns release readiness, rollback, and destination verification | May not approve evidence it produced when independent review is required |
| independent certifier | owns the human approval or escalation decision | May not approve evidence it produced when independent review is required |
For this Product Distiller change protocol, the adjudication role is independent certifier. That role judges frozen acceptance evidence for turning agent session evidence into a reusable product package without becoming the product owner, legal adviser, security authority, or buyer. Its handoff retains open gaps, failed evidence, changed hashes, and the next action permitted for ART-11-05.
Evidence and acceptance
Use these product-specific statements as candidate acceptance checks:
- Source sessions are frozen and inventoried.
- Observations are separated from design judgments.
- The procedure runs in a clean context.
- Normal and failure fixtures map to requirements.
- Open assumptions remain visible.
For every Product Distiller change protocol check, retain the tested object, environment or source, observation time, method, expected result, actual result, verifier identity, and artifact hash. In this ART-11-05 record, label a direct readback OBSERVED, a reproducible transformation COMPUTED, and an interpretation JUDGMENT; never merge those states into one confident claim.
The admitted Search Console packet contained no article-specific demand observation for this exact topic. The page is therefore justified by its distinct operator job and product truth, not by an invented volume estimate. Performance remains unknown until measured after an authorized release.
The product boundary remains controlling: Distillation can organize observed execution evidence, but it cannot manufacture missing provenance, prove product demand, or certify a result outside the stated gates.
Implementation checklist
- The change protocol names the distinct reader job: Change turning agent session evidence into a reusable product package without silently invalidating its evidence, interfaces, or rollback path.
- The input boundary is explicit: Claude or Codex session logs plus an explicit product goal.
- The intended deliverable is explicit: the catalog's fifteen-artifact product package.
- Every required acceptance check has current evidence or an honest NOT_TESTED status.
- At least one negative fixture covers cleaning a transcript without extracting a contract.
- The independent certifier is distinct from the artifact producer.
- Rollback or reopen conditions are written before consequential action.
- No ranking, traffic, conversion, compliance, certification, or buyer-outcome guarantee was added.
When this Product Distiller change protocol has a failed item, repair that named item and rerun its dependent checks. Keep the frozen threshold intact; the remaining checks cannot establish that the failed ART-11-05 condition probably holds.
Sources and claim boundaries
- sincLLM product catalog — used only for product capability and boundary.
- NIST AI RMF resource — used only for general procedure and control guidance.
- OWASP GenAI guidance — used only for general procedure and control guidance.
For ART-11-05, the sincLLM catalog supplies the Product Distiller product description. Its third-party references support only the general change protocol procedure each source addresses. None proves a buyer-specific outcome from Product Distiller or turns this page into a ranking, citation, or AI-answer guarantee.
Keep the Product Distiller next step bounded
Review the catalog for this change protocol, its required inputs, and its limits. Test any buyer-specific outcome from Product Distiller in the buyer's environment instead of assuming it from the guide.
Explore the sincLLM product catalog