Professional Acumen Operational Platform — Technical Review Draft v0.1

Technical review draft — no platform deployed. This H4 document describes proposed architecture, controls and acceptance tests. Historical statements about unavailable access describe the original drafting period; current site connectivity does not establish platform readiness.

Professional Acumen · H4 technical review draft · October8,2026

A member platform with accountable records and recoverable decisions

Operational platform implementation specification v0.1

The public Guidepost website remains the publishing home. A proposed member layer connects verified membership, full named business and voting histories, proposal-linked discussion, independent counting and portable records. Separate credential/evidence repositories preserve the canonical review and privacy boundaries.

Design prepared; no live platform enabled.

H4 is IN_PROGRESS. Current website reads remain quota-blocked; the last site snapshot is historical. No plugin installed, host runtime changed, real account enrolled, permission expanded, email sent, vote accepted, payment taken or credential issued. Components, costs and schedules below are proposals or bounded source observations—not tested site capabilities or approved purchases.

1 · Baseline, compatibility and evidence limits

Observed previously H4 decision Evidence still required
WordPress7.1.3; PHP7.4.33; TwentySeventeen2.2; ClassicEditor; WooCommerce; UpdraftPlus. Retain existing content/menus/classic markup while evaluating a staged supported-runtime path. Fresh authenticated inventory, database version, actual theme/plugin versions, host control/deputy access, storage and operational configuration.
C3 classic prototype script needed compact serialization to avoid inserted paragraph tags. Preserve that scoped fix; test the actual rendered script after any migration. Current raw/rendered page and regression evidence; no blanket global filter change.
No site-specific restore evidence in RP. Treat backup and recovery as unverified. Installed UpdraftPlus is not a witnessed restore. Successful backup scope, independent-copy access and isolated restore with matched manifests.
Access blocked by rolling daily cap; reported next window October8,22:00UTC /3pmPacific. Continue specification; publish when permitted current reads/checks succeed. One eligible site_info, then fresh2547/2626 and affected resource/menu/rights reads; no quota bypass.

WordPress currently recommends PHP8.3+, MariaDB10.11+ or MySQL8.0+ and HTTPS (S01). Its hosting handbook gives more detailed database lifecycle targets (S03). PHP’s official EOL table identifies7.4 as unsupported since November28,2022 (S02). This finding calls for host-supported staging/recovery and compatibility evidence—not a blind runtime switch. Database/runtime requirements must be reconciled with the actual host and current supported-version tables before selection.

Canonical sources retained: every interaction state contains Critical Reasoning, Emotional Acumen, Social Acumen and Physical Health together. PA is analytical/developmental, not an ethical doctrine or human-worth measure. Teams of Three rotation develops articulation, environmental understanding and broader perspective; it does not appoint directors, counters, reviewers or administrators.

2 · Architecture and accountable access

Layer Responsibilities Boundary / custody
Public publishing Existing pages/menus, developed resources, authorized results/method and exact-ID credential lookup projection. No public case evidence, secret credentials or applicant/person search. Existing copyright/reuse notices remain.
Member portal Account sessions; scoped admission/entitlement; eligible directory; complete named histories and all organizational business; Board follow-through and discussion. Community/entity scope explicit. Leadership does not acquire a private business-only channel merely from its office. Protected individual details handled with an identified basis, useful business explanation and independent review.
Independent counter service Verified invitation/casting route; original-source custody; receipt comparison; current entitlement/replacement/correction reconciliation; signed count report and challenge support. Separate company/qualified appointments and independent copies required. No provider chosen or contract activated; protect contact/credential secrets while exposing all named business ledger/history to members.
Credential and case repositories A4 event history, actual authority/checks/notices/appeals, protected work samples, minimum public projection and differentiated retention. Access scoped by specific record purpose; case state separate from credential state. No public application/complaint directory.
Finance and delivery integration Approved order/settlement records, licensing receipts, mail delivery/access, retry reconciliation and member business reporting. Payment purchases only approved product/service; does not buy favorable assessment, admit a statutory member or confer a vote.
Recovery and oversight Independent versioned exports/backups, manifest reconciliation, logs, deputy custody, incidents/change history and restore drills. One administrator must not be the only surviving custodian. Hashes alone do not prevent that administrator replacing all sources/copies.
Technical role Permitted proposed scope Does not automatically confer
Public visitor Published resources/results; approved exact-ID credential projection. Member histories, credential evidence, application/case identities.
Verified community member Complete named histories and business in lawful adopted scope; own submissions and proposal-linked discussion. Membership in another entity/community, Board authority or access to credentials/individual case evidence.
Board/officer Member business view plus valid bounded decision duties; recorded named votes, conflicts and follow-through. Secret corporate-business access, unilateral rule/electorate/history edits or own conflict approval.
Independent counter/inspector Approved decision originals/eligibility and counting/report/challenge work. Admission/removal of members, outcome-contingent payment, deleting originals or assigning legal powers.
Moderator Specific adopted posting controls, edit/restriction records and independent appeal routing. Changing statutory admission, electorate, counted ballots or member business read rights.
Case custodian/reviewer/appeal panel Assigned protected evidence with independent role separation and notice/response. Public person rankings, automatic membership loss, payment-based outcome or original reviewer deciding their own appeal.
Technical administrator/deputy Documented system maintenance under scoped grants and logged oversight. Corporate adoption, personnel decisions or silent deletion/correction of business records.

WordPress capabilities are proposed enforcement primitives (S05/S07), not the membership register. Every sensitive operation needs authenticated identity plus resource/entity/community/action authorization. A nonce helps with request context; it is not a substitute for that authorization or replay/idempotency controls (S06). Adopted legal read rights for former members must be resolved in D1 rather than erased by an account-status toggle.

3 · Components: retain, evaluate and reject unsupported assumptions

Candidate/path Evidence Disposition and proof required
Existing WordPress + ClassicEditor + theme Historical inventory and existing published pages. Retain publishing home. Stage actual compatibility, menu/raw/rendered/regression tests; no new host/theme needed merely to draft this plan.
bbPress forum candidate Official current listing2.6.19; WP6.0+, tested7.1.3, PHP7.2+ (S04). Candidate for isolated evaluation, not installed/selected as compliant. Prove scoped member business access, proposal links, authorship/edit/restriction history, exports, moderation appeal and required accessibility; plan a tested extension/alternative for missing functions.
Membership/account bridge Native WordPress account/capability API context (S07). Propose a narrow maintained member/event bridge over actual lawful admission records. Do not substitute WooCommerce customer/subscriber role or dues-paid flag for statutory entitlement. Paid membership-plugin selection remains unmade until actual requirements/version/cost proof.
Independent email administrator + portable transactional ledger C3 requires independent company, named receipts/history and email counting. Preferred evaluation route: qualified independent service handles original intake and reproducible counting, with approved named member ledger and portable source/event exports. Manual assisted intake at small scale may be evaluated; exact casting/identity method, valid law, contract and acceptance evidence remain open.
ElectionBuddy documented anonymous web-ballot path Features describes unlinked confidential election choices; access guide’s sample says email replies do not register votes (S12/S13). This documented path fails the current named-history/email-casting requirements. Do not launch it as if compliant. A separately evidenced lawful named/email configuration would need new contractual/demo proof; no blanket claim about every possible service configuration.
Simply Voting documented anonymous path Vendor says organizers cannot determine individual choices (S14). Does not demonstrate required named member histories; not qualifying on retrieved evidence. Vendor security assertions do not establish project fitness or independent verification.
Generic poll or C3 fictional local UI C3 has no real authentication, email or durable storage and only its fictional resolution method. Demonstration only. Not a statutory election service or replacement for independent administration/reconciliation.
UpdraftPlus Installed historically; vendor scope/location/restoration docs (S09–S11). Retain/evaluate actual backup job, complete component scope, independent destination, encryption/access and witnessed staging restore; external repositories/mail/counter records need their own backups.
WooCommerce existing store Historical inventory; official order/webhook docs (S15/S16). Reuse only authorized product/payment behavior after actual gateway/version/rights review and sandbox tests. No subscription/payment/member or credential activation here.
Provider evidence request — ready to use after a real provider is identified

Obtain written answers and a synthetic demonstration for: named electorate and full member-visible choice/history export; exact optional500-code-point explanation retention; email invitation versus actual reply/intake methods; independent company/ownership/conflicts; original-source custody/receipt comparison; decision-specific class/weight/seat/quorum/replacement/correction methods; rejected/superseded history; authorized appointment/signed report; accessible assistance; delivery/outage/challenge handling; contract exit/export; data scope/custody/retention; actual fees and staff capacity.

Reject an unsupported feature claim at its requirement gate. Do not change the named-transparency design to fit a secret-ballot default. If D1 identifies an actual mandatory legal alternative, record the exact basis and explicit resolution. No inquiry or email was sent.

4 · Complete participation and independent-count workflow

  1. Admission and access: an authorized body records actual scoped membership; verify an account separately. Show eligible directory, business access, source/appeal route and historical effective intervals. Payment/contact address/learning role alone does not establish entitlement.
  2. Decision and discussion: register V01 exact proposal/version, legal actor, all counting/notice/replacement/deadline rules and electorate snapshot. Connect nomination/business materials and member discussion. No real launch while any required field is unresolved.
  3. Independent delivery: the appointed company confirms addresses/identity checks, records invitation/failure/alternative delivery and distinct credentials. Reissues invalidate prior casting ability without erasing history or adding power.
  4. Cast and receipt: display exact choice constraints and optional explanation; use the same Unicode rule at every boundary. Preserve accepted exact text, original source and received timestamp. Show a receipt before claiming the event is current/countable; ambiguous MIME/encoding or identity issues go to review rather than invented parsing.
  5. Count and member verification: reconcile all raw events to decision-specific current entitlements atomically. Every member can see all named histories, source-linked dispositions, rules and corrections. Secret contact/token details remain outside the ledger. A duplicate receipt is not a new vote; a recording correction is not a changed original choice.
  6. Independent correction and report: preserve original and prior interpretation; append authorized correction/recount/appeal with independent evidence and effect. Counter signs a reproducible report; the valid body records result/remaining limits. Unresolved material discrepancy blocks certification.
  7. Follow through: publish public result/method; keep full member history and discussion available across leadership/provider changes. Assign actual owner/funds/milestones, record Board named decisions/recusal/dissent and review delivered outcomes.

Email From/header or a logged-in account alone is not adequate eligibility proof. Use the approved member/credential/proxy/assistance checks; common household addresses or networks do not prove duplicate people. Distinguish provider invitation email from an actual email casting route. If a provider offers only web casting, the requested email-counting/casting design still needs an explicit evidenced resolution.

All organizational business remains member-visible: staffing arrangements, compensation decisions, finances, contracts, resource access, teaching/certification performance and conversion. Specific individual information may use an identified scoped handling route with useful business reasons and independent appeal. Moderation cannot quietly rewrite a ballot, cancel a vote, suppress member business access or punish lawful criticism.

5 · Data contracts, credential projection and retention

Planned object Minimum fields Access and relation
member_event event_id, entity_id, community_id, member_id, name, class, weight, effective_at, recorded_at, authority_ref, previous_event_ref, reason, independent_check Member business history; operational contact secret kept separately.
decision_rules decision_id, entity_id, community_id, version, authority_ref, proposal_hash, electorate_snapshot_ref, method, quorum_rule, approval_rule, class_seat_rules, record_dates, replacement_policy, open_at, close_at, timezone, outage_remedy, counter_appointment, appeal_route, publication_schedule V01; freeze prior to actual notice; an unknown field blocks real launch.
ballot_event event_id, decision_id, member_id, entitlement_ref, proposal_version, channel, received_at, source_ref, choices, reason_exact, code_point_count, receipt_ref, disposition, previous_event_ref, independent_check Full named member ledger with exact historic interpretation/dispositions; original private operational source accessible to independent checks.
discussion_event event_id, topic_id, decision_id, entity_id, community_id, author_id, original_body, recorded_at, previous_event_ref, moderation_ref Member-visible authored/edit/restriction history; specific individual material separately scoped.
credential_event event_id, credential_id, event_type, effective_at, recorded_at, decision_ref, authority_ref, previous_event_ref, recorder, independent_check, notice_ref, reason, retention_trigger Restricted A4 custodian/authorized reviewers; case evidence separate from member business.
credential_public credential_id, issuer, standard_name, standard_version, pathway, scope, limitations, status, effective_at, expires_at, as_of, verification_contact, replacement_credential_id Exact public lookup projection only; no case state, work sample, child/health/contact/fee details.
delivery_event event_id, message_purpose, recipient_ref, decision_or_case_ref, source_version, idempotency_key, queued_at, provider_accepted_at, delivered_at, accessed_at, failure_code, retry_ref, alternative_route_ref Credentials/contacts private; member business delivery performance accountable without exposing secrets.
payment_event event_id, entity_id, order_id, gateway_reference, delivery_id, source_hash, signature_check, recorded_at, amount, currency, reconciliation_state, fulfillment_ref Finance operation + appropriate member business reporting; no card secrets stored in this plan.
export_manifest manifest_id, entity_id, scope, schema_version, rules_versions, exported_at, as_of, object_counts, hash_algorithm, file_hashes, custodian, independent_copy_ref, hold_refs Independent reconciliation; hashes flag discrepancy but do not prove untamperability if administrator controls all copies.

These are proposed record contracts, not registered endpoints or a running database. Stable IDs link scope, authority and immutable source references. Store UTC effective and recorded timestamps separately. Snapshot prior versions, append corrections, and keep independently held originals/manifests so replay can reproduce the approved projection. The exact reason remains a string; rendering escapes markup without altering its stored words.

A4 remains canonical:12-calendar-month proposed term; independent three-person appeal; start inclusive/expiry exclusive. Case workflow, appeal pending, invoice paid or class attendance never creates active status or extends expiry. Unknown/unissued public IDs return no verified credential, without implying dishonesty or revealing private case facts. Public lookup uses the exact allowlist above, not public name/applicant search.

Canonical A4 proposed category Retention trigger/period Purpose/access
Decision, notice, appeal and change history Four years after the later of credential end or last related case closure. For unissued applications, four years after final review/appeal closure. Restricted program custodian and qualified case/oversight reviewers. Minimize quoted personal detail; retain criterion/version/reason traceability.
Raw work samples and observation records Through credential validity, then 24 months after the later of credential end or related case closure; unissued applications: 24 months after final closure. Separate restricted evidence repository. Use deidentified summaries when adequate; no unnecessary health or child-identifying material.
Contact and access-support logistics Remove unnecessary logistical detail within 90 days of case closure; retain only a current contact needed for an active credential or open case. Intake staff; diagnosis not required. Review necessity at renewal and closure.
Public lookup projection While status verification is authorized and necessary; proposed review for removal four years after the credential ends. Only approved minimum fields; removal does not silently rewrite the retained restricted decision history.
Fee, accounting, employment or legal records Separate adapter-specific schedule, not the educational evidence schedule above. Financial/authorized roles only. Actual legal, contractual and funding duties must be verified in D1 before collection.
Preservation hold Pause scheduled disposal for specified records needed for an open dispute or other verified preservation duty; review necessity every 90 days. Custodian records basis, scope, approver, review and release. Never treat a blanket indefinite hold as the default.

Do not reuse educational evidence periods as voting, corporate, payroll, accounting or agency schedules. D1 must complete those actual duties; case/vote open disputes preserve specifically scoped sources. Periodic hold review and documented release avoid an indefinite blanket archive. Backup/replica disposal and reintroduced data after restore need coordinated approved handling. No actual deletion or retention clock is enabled by this plan.

Planned service boundary, with no endpoint enabled

Proposed namespace /pa-platform/v1/: scoped member directory and history; decision rules/electorate; append-only submission/receipt; linked correction request and authorized disposition; discussion history/moderation appeal; exact-ID credential public projection; scoped export manifest; authorized delivery/payment reconciliation. GET authorization applies to reads and exports, not just mutation. Public projection uses a hard allowlist and distinct query; protected files are served only through checked access, never by assuming an obscure upload URL is private.

Mutations use an idempotency key scoped to entity/decision/actor/action; record database transaction and uniqueness rules before accepting current entitlement. Replay of one request returns the same existing outcome. A server error with unknown outcome requires querying the known event/request before retry. Source hashes support comparison; do not market an administrator-controlled chain as tamper-proof.

6 · Mail, payments, recovery and change operations

Reliable notices and receipts

Use a durable outbox and purpose/version/recipient idempotency key. Record queued, provider-accepted, delivered, accessed, failed and alternative-route evidence separately. WordPress wp_mail success is not proof the recipient received the message (S08). Reconcile ambiguous sends before retry; preserve original deadline/access-failure evidence. Use synthetic destinations in staging and disable outward delivery; real notices require actual authority and a valid service.

Payment integration without purchased authority

Validate actual gateway and webhook payload signatures, amount/currency/entity/order/reference and event age/state; deduplicate delivery IDs and reconcile current gateway/order evidence before fulfillment. Official WooCommerce v1 webhook reference describes HMAC-SHA256 and delivery IDs (S16); installed/gateway behavior is still unverified. Pending/on-hold are not completed payment; a manual refund status alone need not mean funds were returned (S15). Payment/waiver/refund events never directly change membership, votes or credential outcome. Licensing rights and authorized prices/owners remain B2/D1/D3 gates; no card secrets belong in member histories.

Backup and restoration runbook

  1. Inventory database,plugins,themes,uploads,config/host routing,external event/case storage,counter originals and mail/payment reconciliation state. Identify exclusions and restore dependencies.
  2. Confirm an independently accessible encrypted copy and actual responsible/deputy custody; secrets are referenced from controlled storage, not printed in RP. Updraft vendor docs do not establish this site’s remote coverage (S09/S10).
  3. Before migration, retain current revisions and a verified recoverable snapshot. Restore into isolated authorized staging with outbound mail/payment disabled; compare object counts/hashes, page/menu/record histories and critical flows.
  4. Measure actual recovery and loss boundaries. Proposed public-content target:24-hour recovery-point window and8-hour recovery-time window. Acknowledged ballot/correction/credential events require durable independent copies and reconciliation so no acknowledged event is silently lost; do not advertise zero-loss recovery until demonstrated.
  5. If rollback needed, stop affected writes/verification, preserve new events after the snapshot, restore only authorized scope, replay/reconcile them and verify public/member projections. Never overwrite post-backup valid votes with an older snapshot.
  6. Record restore operator/witness,backup/version,sources,elapsed time,missing records,side effects,exceptions and successful checks. Resume only with a documented bounded decision.

This is infrastructure recovery planning. The canceled website-wide Word/ZIP export remains canceled; no such export or actual site backup was created. No staging/restore/production mutation was performed.

Incidents, updates and deputies

Propose weekly delivery/error/access/discrepancy queue review; monthly dependency/permissions/storage checks; quarterly isolated recovery rehearsal; before each election, review source/configuration/counter independence and capacity. For material ballot/history mismatch, stop certification, preserve originals, route independent review and notify through valid authority; do not alter deadline or conceal unfavorable records. For a specific individual-data leak, restrict the affected exposure and preserve incident evidence while retaining lawful business access; actual notification duties require D1’s jurisdiction basis.

Record change/version/dependency diff,owner/approver,staging evidence,backup/rollback plan and success/exception result. Deploy using supported WPVibe operations and fresh exact anchors for content; no raw SQL/security bypass. Existing copy-protector/rights conflict is D3/H3 review work, not permission to disable it. No subscription, account/access expansion, host migration or installed-component change occurred.

7 · Capacity, funding and accountable owners

Proposed initial planning workload:100verified members, two independent decision cycles/year and modest moderated discussion. This is an evaluation scenario, not actual membership or a throughput guarantee. Assign an accountable owner and deputy for membership/access, system/recovery, independent count, moderation/appeal, credential/case custody,finance and rights. One person holding multiple administrative roles must not decide their own ballot discrepancy, compensation or appeal. Independent duties need real funded capacity.

Fictional allowance Calculation USD
Setup specification/integration/staging work 88hours ×$50 4,400
Staging and test allowance Proposed envelope; not a quote 600
Setup expense 4,400+600 5,000
Monthly maintenance 8hours ×$50 +$80 infrastructure +$20 archive 500
Annual recurring maintenance 12×500 6,000
Two independent decision cycles 2×(16hours ×$50 +$200 service allowance) 2,000
First-year expense 5,000+6,000+2,000 13,000
Held reserve Proposed cash; not expense 1,000
First-year cash requirement 13,000+1,000 held 14,000

Actual providers/hosting/storage/security/accessibility/payment charges and reviewer wages must be quoted. These allowances are editorial assumptions; no funds approved or spent. Legal/accounting review, formation, products/teaching, reviewer/three-person appeal casework and taxes are outside this scenario. Reconcile B1’s overall budget and the C3 per-election illustration rather than adding duplicate line items; a new illustration does not silently replace either earlier source. Variable demand and review backlogs need separate funded expansion/stop rules.

O01–O04 · Reusable operating records

O01 compatibility/change: current component/version/source/date,host requirement,dependency,staging evidence,rights/access effect,owner/approver,backup/rollback and release result.

O02 recovery: backup components/exclusions,independent destination,custodian/deputy,encrypted-access reference,manifest,restore witness/time/RPO/RTO,post-snapshot replay and exceptions.

O03 provider/capacity: requirement/demo evidence,company/appointment/conflicts,original-source/ledger/export agreement,actual quote/funds,staff/deputy,delivery/incident/challenge/exit and review dates.

O04 incident/launch: affected scope/decision,concern versus established facts,original evidence,proportionate containment,independent review,notice/response,authorized correction,result/recovery,remaining limits,appeal and approved restart scope.

8 · Acceptance contract and reproducible scenarios

Requirement Source interface Required evidence
R01 · Current compatibility and restoration evidence H4 Fresh inventory; supported runtime target; staging dependency tests and witnessed restore before risky production changes.
R02 · Verified account versus lawful membership C3/D1/C4 Account authentication separate from entity/community, member admission, decision entitlement and historical effective dates.
R03 · Full named member-business access C3/C4 Eligible directory, every named ballot/history, Board decisions/finance/contracts/staffing business, moderation/access reasons and linked discussion; no leadership-only business secrecy.
R04 · Decision-specific approved rules C3 V01/D1 Method, class/power/seats, record date, notice, quorum/approval, replacement, deadline/timezone, tie/outage and authorized actors all resolved before actual use.
R05 · Exact optional500-character reasons C3 V04 Proposed Unicode-code-point convention preserved in client/server/provider; spaces/LF/punctuation retained; blank accepted;501 rejected without silent changes.
R06 · Independent email administration/counting C3 V03–V07 Qualified independent company, authorized appointment, original evidence, member receipt comparisons, transparent dispositions and signed reproducible report.
R07 · Events versus voting power C3 V05 Transactional deduplication/current entitlement; no concurrent double count; reissue/replacement/correction history retained.
R08 · Three community boundaries C4 PA, podiatry and Purpose of Life use explicit community/entity scope and distinct menus/permissions; no cross-community privilege inferred.
R09 · Moderation with independent review C4 Preserve authorship/edit/restriction history; specific lawful individual-data route; criticism is not a reason to remove membership/read/vote rights.
R10 · Credential projection and case separation A4 Exact allowlist; case/appeal/payment/attendance never confers status;12-month proposal and three-person independent appeal unchanged.
R11 · Differentiated retention and holds A4/D1 Source retention categories retained; actual voting/business/payment schedules separately adopted; no universal deletion or indefinite blanket hold.
R12 · Protection across every delivery surface H4/C4 Server authorization for UI/API/files/exports/caches/search/feed/sitemaps; credentials and specific individual records do not leak.
R13 · Receipts and delivery evidence C3/A4 Processing, provider acceptance, delivery/access, count inclusion and certified result recorded separately with retries and alternatives.
R14 · Payments separate from rights/credential B1/B2/A4 Gateway evidence reconciled; order or payment cannot automatically admit a member, decide eligibility or issue a credential.
R15 · Export and independently recoverable records C3/A4/H4 Portable versioned event/snapshot/receipt/rules manifests; original sources under proper access; independent copy/reconciliation and recovery drill.
R16 · Accessible participation H3/C4 Keyboard/mobile/assistive/print/copy checks and assisted routes preserve voter choice, evidence, deadlines and rights restrictions.
R17 · Funded capacity and accountability B1/A4/H4 Actual quotes/staff/owner/independence/backups/incident/appeal resources and maintenance; proposed envelope is not funded service.
R18 · Controlled deployment and truthful readiness RP1/H4 Retained revisions, compatibility gates, supported operations, unknown-outcome readback, no real activation before authority/access/end-to-end gates.

All24 system acceptance scenarios below are NOT_RUN. No site/component/hosting/provider/permission/recovery/payment/mail/end-to-end capability is reported as passing. The companion JSON supplies each scenario’s setup,expected outcome,requirement links,unassigned owner and empty evidence reference. Synthetic testing is a future implementation contract, not an actual vote or independent verification result.

TC01 · Refresh inventory and compatibility

Setup: Record actual WP/PHP/database/theme/plugin versions, host limits and supported target; stage representative content/store/forum/REST behavior.

Expected: Evidence from target stack; unchanged old pages/menu/routes; unresolved incompatibility blocks deployment.

Trace: R01, R18 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC02 · Restore drill

Setup: Restore independent backup into isolated staging with outward email/payment disabled; compare manifests and historical records.

Expected: Correct pages/files/menus/configuration references/events restored; measure actual RPO/RTO; no live overwrite or side effects.

Trace: R01, R15 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC03 · Account and scope mismatch

Setup: Use synthetic visitor, applicant, PA member, podiatry-only member, former member and staff accounts on UI/API/export/direct-file routes.

Expected: Only actual adopted scoped grants succeed; wrong-scope requests denied; legal read-right treatment explicit rather than inferred.

Trace: R02, R08, R12 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC04 · Full named history and public exclusions

Setup: Member sees all electorate/ballots/old interpretations/Board business; logged-out public requests all export/search/cache routes.

Expected: Full member business histories available; public sees approved results/method only; no credential/contact/case leak.

Trace: R03, R12 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC05 · Incomplete V01 and missing entitlement

Setup: Attempt synthetic ballot before method/authority/class or record date resolved; omit an existing eligible member.

Expected: No launch/acceptance on missing rule; independent correction preserves original snapshot and applies lawful remedy.

Trace: R04, R07 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC06 · Blank,500 and501 Unicode reasons

Setup: Submit blank;500 emoji;501 emoji; leading/trailing spaces,LF,literalHTML and combining characters.

Expected: Blank accepted; code points consistently counted;500 accepted/501 rejected; exact accepted reason round-trips; text rendered inert.

Trace: R05 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC07 · Email-original reconciliation

Setup: Independent test operator compares synthetic raw sources, normalized extracted choices, receipts and member ledger.

Expected: Ambiguous/altered/unknown encoding rejected for review; original bytes retained; no invented choice or silent rewrite.

Trace: R06, R13 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC08 · Identity and credential reissue

Setup: Forged From,shared mailbox, changed address, reused/reissued credential and two simultaneous submissions.

Expected: Address/header alone insufficient; reissue cannot add power; one valid entitlement counted atomically; all events retained.

Trace: R02, R06, R07 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC09 · Replacement and interpretation correction

Setup: Two fixtures: replacement permitted/prohibited; initial recordedNo where originalYes; proposed unapproved correction.

Expected: Method-specific replacement applied; original event/reason preserved; independently authorized correction changes interpretation only; unapproved mutation refused.

Trace: R04, R07 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC10 · No quorum, abstention and multiseat

Setup: Reproduce C3 fictional3/5 resolution; no-quorum2 ballots; alternate weighted/class/multiseat fixture.

Expected: C3 fixture1Yes/1No/1Abstain→2Yes/0No/1Abstain after source correction, same participation3; real methods have separate approved expected counts.

Trace: R04, R07 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC11 · Deadline, delivery failure and outage

Setup: Synthetic late email, accepted-but-undelivered invite, timezone boundary, provider outage and lost receipt.

Expected: Preannounced valid remedy; no changed deadline after seeing result; actual delivery evidence/alternative preserved; material unresolved issue blocks certification.

Trace: R04, R13 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC12 · Independent replay and portability

Setup: Counter exports original sources/events/rules/manifests; separate reviewer reconstructs electorate/current ballots/result without provider dashboard.

Expected: Identical approved totals/history; missing source/config/hash mismatch blocks favorable verification; provider exit does not destroy records.

Trace: R06, R15 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC13 · Criticism and moderation appeal

Setup: Publish synthetic criticism of leadership; moderator attempts remove vote/read access and edits original without history.

Expected: Specific moderation action/reason visible and appealable; membership/votes unchanged; original/edit history preserved; independent remedy works.

Trace: R03, R09 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC14 · Specific protected individual material

Setup: Attach synthetic private contact/health-like/child-like information within business discussion; test files,REST,feed/cache/search and exports.

Expected: Only specifically protected portion handled through valid scoped route; full business explanation retained with useful summary; no blanket secret discussion.

Trace: R09, R12 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC15 · Credential public projection

Setup: Replay canonical A4 fixtures and query unknown/unissued ID, active/expired/suspended/revoked/superseded record.

Expected: Exact approved allowlist only; start inclusive/expiry exclusive; no application or payment status becomes credential; unknown reveals no allegation or person-worth inference.

Trace: R10 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC16 · Appeal and retention boundaries

Setup: Use synthetic appeal pending at expiry; notice access delay; differentiated closure dates and preservation hold.

Expected: No automatic expiry extension; correct independent three-person appeal records; category-specific retention/hold/release with approved authority.

Trace: R10, R11 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC17 · Nonce, capability and replay

Setup: Valid session without entitlement; stale/missing nonce; forbidden resource ID; repeated mutation with same request ID.

Expected: Authentication/authorization both enforced; nonce is not entitlement; repeat returns same disposition without new event/power.

Trace: R12, R18 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC18 · Payment event reconciliation

Setup: Synthetic signed/forged/duplicate/out-of-order webhook; pending/on-hold/paid/refund status; gateway reference mismatch.

Expected: Invalid/duplicate events cannot fulfill twice; current gateway/order evidence reconciles; manual refund status not proof funds moved; no auto credential/vote rights.

Trace: R14 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC19 · Notification queue failure

Setup: Crash worker after provider submission but before acknowledgement; recipient bounce; assisted participant lacks email.

Expected: Stable idempotency/reconciliation avoids duplicate messages; retry bounded; alternative accessible route and actual access recorded; no deadline lost through quiet failure.

Trace: R13, R17 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC20 · Unknown write outcome and rollback

Setup: Simulate publish timeout, concurrent user edit and failed component migration.

Expected: Query known destination before retry; compare current version; preserve revisions/new records; staged rollback does not erase post-backup valid ballots.

Trace: R15, R18 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC21 · Accessible participation and rights

Setup: Keyboard and assistive navigation,360px/desktop,zoom,reason review,receipts,disclosure tables and permitted print/copy.

Expected: Exact choices/reasons readable; focus/error/status announced; assistance does not choose vote; component-specific rights respected.

Trace: R16 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC22 · Capacity/incident exercise

Setup: Synthetic100members/2elections and configured demand; two-person absence, counter conflict, backup access loss and priority discrepancy.

Expected: Actual observed completion/error/recovery within adopted targets; deputy/independent escalation available; unsupported load/service promises blocked.

Trace: R17 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC23 · Content preservation after upgrade

Setup: Compare representative original/current page raw,IDs/hrefs/styles/menus; exercise C3 compact script and Woo/forum checks.

Expected: No paragraph/source/model/rights loss; Classic Editor script remains executable; no global filter/security workaround; failure returns to prior tested package.

Trace: R01, R18 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

TC24 · Launch and completion gate

Setup: Review real authority,rights,reviewer/counter appointments,quotes/funds,scopegrants,all critical test evidence and unresolved issues.

Expected: Launch refused if any mandatory gate unknown/failed; written owner decision bounded to tested scope; RP reflects actual publication/operation separately.

Trace: R08, R18 · Execution: NOT_RUN · Owner: UNASSIGNED · Evidence: none

Local preparation checks can establish intact source linkage, valid internal references, canonical A4 field/retention preservation and arithmetic; they do not pass these end-to-end scenarios. H3 owns the broader display/accessibility/copy/print audit; C4 implements actual forum/voting membership flows after its dependencies and real launch gates are satisfied.

9 · Deployment gates and publication queue

Phase Work / required gate Actual state
P0 · Read and baseline No website access before reported2026-10-08T22:00Z retry window. Then one harmless site_info and current target/template/menu/backup configuration reads. BLOCKED_ACCESS
P1 · Recover and stage Confirm actual host/staging, admin/deputy, backup scope/destination and restore evidence. Copy only authorized minimized data; suppress outbound mail/payments in isolation. NOT_STARTED
P2 · Compatibility and scoped component evaluation Evaluate supported PHP/database targets, actual plugin/theme matrix and bbPress/custom member/event bridge in staging; rollback evidence before production. NOT_STARTED
P3 · Fictional end-to-end rehearsal All access/count/forum/register/payment/mail/export/recovery scenarios with synthetic accounts and independent test operator; no real communications/payment. NOT_STARTED
P4 · Bounded authorization and deployment Actual D1/D3 rules/rights/adoption, reviewer/counter appointments,funded resources, security-access authority and passed critical tests; supported operations only. NOT_AUTHORIZED_OR_VERIFIED
P5 · Operate and maintain Adopted monitoring, deputy coverage, backups/restore, change review, weekly queue checks and periodic independence/resource review; actual outcomes recorded. NOT_ACTIVE

Publish this technical planning resource in existing member-participation2547 and a compact Operations Manual2626 interface only after fresh raw/anchor/rights checks. Preserve original#forum/#membership and O-06 clauses, source text, C3 compact script, navigation and all existing menus. Verify exact intended insertions, reciprocal links and scoped display; a planning publication remains distinct from an enabled service.

H4 remainsIN_PROGRESS: technical resources prepared, no current stack/restore/authorization/end-to-end evidence or website publication. D1 remainsIN_PROGRESS with California public-benefit/statutory-member model selected; its review draft stays queued. C4 remainsQUEUED and no live participation component is activated. The conditional continuation watcher remains unconfigured until required successful website preflight, as recorded in RP.

Next action: recover the latest RP and artifacts; after the indicated access window, one harmless site check, current target/inventory/backup reads, then eligible draft publication and compatibility/recovery planning. Obtain actual host/staging and lawful scope/rights/counter/funding information before any consequential deployment. Current-site evidence, actual provider configuration and all24 acceptance outcomes remain open.

10 · Sources and provenance

External sources checked October8,2026. Primary technical documentation and vendor feature claims support only the bounded context below. No actual provider security assurance, service pricing, installed compatibility or site-operation claim follows from them.

Primary source Bounded observation/use
S01: WordPress requirements Official current page recommends PHP8.3+, MariaDB10.11+ or MySQL8.0+, and HTTPS; minimum legacy support is not a security-support promise.
S02: PHP supported and unsupported branches Official table identifies PHP7.4 EOL November28,2022 and last release7.4.33. Select a currently supported target using https://www.php.net/supported-versions.php, then test the actual stack.
S03: WordPress hosting server environment Current hosting handbook lists supported database targets and differing lifecycle detail; reconcile it with host evidence rather than adopting an old minimum.
S04: bbPress plugin listing Current official page:2.6.19, WordPress6.0+, tested to7.1.3, PHP7.2+. Earlier search snippets differed on tested-to version; direct current listing used. Metadata does not prove installed-stack compatibility or required access/history features.
S05: WordPress REST endpoint permissions Permission callbacks check action authorization after authentication; capabilities or equivalent resource checks are required.
S06: WordPress nonces Current official documentation; nonce handling must not replace authentication/capability checks or idempotent event handling.
S07: WordPress roles and capabilities Official API context for capability design; technical roles are distinct from statutory membership and decision authority.
S08: WordPress wp_mail A successful processing return does not prove recipient delivery. Delivery and access need separate evidence.
S09: UpdraftPlus backup scope Vendor documentation: free backup covers WordPress database and wp_content; broader files/external tables/databases have separate coverage. Verify actual installation/configuration.
S10: UpdraftPlus backup location Vendor documentation recommends independent remote storage. Actual destination/access/encryption/retention are not observed.
S11: UpdraftPlus restoration Vendor restoration workflow is documented; installed plugin or backup listing is not this site’s witnessed restore evidence.
S12: ElectionBuddy features Documented election offering describes anonymous choices not linked to voters. No qualifying named-history configuration established.
S13: ElectionBuddy ballot access Documented notices deliver web credentials; sample says email replies do not register votes. Email invitation is not demonstrated email-ballot intake.
S14: Simply Voting security Vendor says organizers cannot determine individual choices because results are anonymous. Its security claims are vendor descriptions, not independent verification here.
S15: WooCommerce order statuses Pending/on-hold/processing/completed/refunded have distinct meanings; a manual refund status need not mean funds returned. No gateway outcome observed.
S16: WooCommerce webhook reference Official v1 reference documents HMAC-SHA256 signature and delivery IDs; confirm the actual installed API/gateway behavior before integration.

Internal current sources: RP31 at start; index11/register13; C3 specification; canonical A4 continuing-review and status-register specification; curriculumv0.3. The canonical A4 JSON’s public allowlist,12-month term,case separation and differentiated proposed retention are imported unchanged. Existing alternative A4 drafts do not supersede them. All diagrams/contracts/timing/capacity/budget/component-fit decisions and acceptance scenarios here are editorial proposals.

Historical site inventory comes from RP and prior successful site_info; no fresh site request made against the known daily block. No current restored backup, staging instance, technical account, configured provider, gateway settlement, real membership record or independent verifier was observed.