The existing isolated Fly app serves this static Varro V1 surface over valid TLS.
The Varro V1 public route is live, reviewed, and rebuilt through cycle 24.
This page is the Build 1 review surface for the Varro documentation and tutoring site. It shows what exists now, how cycle 24 rebuilds KG-8 from the live-runtime gate collect packet, how cycle 22 refuses live model execution while the generated-answer citation gate is present, how cycle 23 collects against the live-runtime gate without changing that authority boundary, how cycle 19 uses the Rust verifier to promote 11 source-backed KG records in the reversible experiment packet, and how the remaining live tutor runtime gap stays active with escalation esc-005 without model-call, learner-submission, production KG-store, or infrastructure claims.
The series now tracks route verification, tutor eval pass rate, wall-clock, cost, static citation coverage, accepted useful output, source-backed readiness, runtime-boundary readiness, collect evidence, KG-6 promotion state, the Rust runtime adapter spike, cycle 14 runtime-spike collect evidence, cycle 16 learner runtime slice, cycle 17 learner-interface collect evidence, cycle 18 KG-5 rebuild evidence, cycle 19 source-backed promotion evidence, cycle 20 live-runtime-gap collect evidence, cycle 21 KG-7 rebuild evidence, cycle 22 runtime-gate refusal evidence, cycle 23 gate-collect evidence, and cycle 24 KG-8 rebuild evidence.
Autonomous work can refresh content only; app, DNS, TLS, and secrets stay supervised.
The accepted-output index stays flat at 0.9028 because the runtime gate narrows the final tutor gap without adding a counted surface, promoting more records, or touching the production KG store.
First learner path: write and check a VSL system.
The initial content is intentionally small: one concrete tutorial, a frozen eval set, a visible citation-check surface that requires citations or refusal, a runtime contract surface generated to the KG-2 limit, and a Rust adapter spike that validates the typed answer report. Cycle 23 collects against the live-runtime gate: candidate generated-answer citations remain checked, but live model execution is still refused until backend, secret, and learner-submission boundaries are reviewed.
- Varro is a governed query and control surface, not the owner of truth.
- The command grammar is `ask`, `show`, `check`, `run`, and `create`.
- Preview is the default posture; execution requires explicit authority.
- Out-of-scope or source-missing questions must be refused without fabrication.
system tutorial.hello {
mission "A first VSL system."
authority lane "operator:local"
domain software
maturity draft
context root = "helios://local/tutorial/hello"
compile workspace-runtime -> varro
runtime execution {
host governed
commit-mode host-only
}
}
What the reviewer can check today.
Delivery
| Public route | verified by Rust route checker |
|---|---|
| Target app | mentormind-varro-web |
| Rollback | pinned image digest in runbook |
| Latest cycle | cycle 24 rebuilds KG-8 from the cycle-23 live-runtime gate collect packet, preserving 11 source-backed records, keeping execution refused, and keeping zero production KG-store mutation |
Measurement
| Tutor eval | 1.0 pass rate on frozen v1 spike |
|---|---|
| Citation QA | 15 frozen eval items and 4 refusals checked by Rust route verification |
| Accepted output | 0.9028 from reviewed surfaces, 11/18 source-backed KG promotion, tutor eval coverage, and live deploy |
| KG readiness | 7 of 7 external source hashes verified by Rust |
| Runtime contract | 5 answer stages and 4 refusal boundaries generated to KG-2 limit |
| Runtime collect | pre-collect public route verified; no usage or live runtime evidence claimed |
| KG promotion | 18 records and 16 relationships carried into KG-8; 11 records are source-backed |
| Runtime adapter | 15 of 15 frozen items evaluated by Rust with 0 failures and 0 model calls |
| Runtime spike collect | 4 findings, 4 live-interface test boundaries, and 2 active gaps surfaced for the next rebuild |
| Learner interface | 15 prompt/answer cards rendered from the checked fixture with 4 refusal cases and 0 model calls |
| Learner collect | 4 collect findings and 3 still-absent boundaries recorded for the next KG rebuild |
| Live runtime collect | 4 KG-6 readiness checks, 4 blockers, 4 evidence inputs, and 1 active live-model runtime gap consumed by KG-7 and carried into KG-8 |
| Live runtime gate collect | 4 candidate citation checks, 4 execute refusal reasons, 4 unblock requirements, 4 collect findings, 4 regression checks, and 4 KG-8 rebuild inputs consumed by KG-8; live execution refused in the static no-secret envelope |
| Kickoff cost | 0.6104224 USD lower bound |
| Route signal | in control after public verification |
Knowledge graph
| Records | KG-8 rebuild packet |
|---|---|
| Relationships | normalised records, not inline claims |
| Promotion | 11 of 18 records are source-backed |
| Active gaps | live model-backed tutor runtime refused pending backend, secret, route-verifier, and learner-boundary review |
Accepted output is now separated from activity.
The useful-output score counts only review/QA-accepted, source-traced formation. It gives credit for the public surface, evaluator, citation surface, route evidence, review evidence, SPC series, and now the first source-backed KG packet while keeping unmanifested and tutor runtime-dependent records conservative.
- 1Surfaces
8 of 8 frozen Build 1 surfaces are visible or evidenced; cycles 14 through 21 add supporting QA/KG evidence, not new counted surfaces.
- 2KG
11 records are externally hash-eligible and source-backed in KG-8; 7 records stay conservative because they rely on unmanifested bootstrap, route, cycle, or tutor evidence.
- 3Tutor
Frozen v1 eval coverage is 15 of 15 with pass rate 1.0.
- 4Deploy
The live public route passes Rust verification.