Thesis tested

Repair becomes a useful product only when it sits inside a complete operating lifecycle: define the job, ground the data, build a competent model, expose decisions to operators, then adapt through a verified and reversible change.

Repair was necessary, but it was not the whole product

IWMR began with a model that already existed. That isolated the scientific repair mechanism, but it left a practical question unanswered: how does an engineer get from an operating problem and local trajectories to the model that IWMR can govern?

The new product layer organizes that path around Applications rather than raw models. Each application moves through Define, Connect, Build, Validate and Deploy. The existing Runtime remains the engineering control plane for predictions, plans, evaluations, incidents, versions, activation and rollback.

The flagship Smart Water Tank makes the loop concrete. The model expects an outlet valve to remove 0.05 level units per valve-command point. Repeated observations show only 0.01. The Operator View explains both the physical change and the exact candidate model edit before sending the user to the existing verified-repair decision.

One small factory contract now covers four model families

The initial Model Factory is intentionally narrow. F1 configures explicit deterministic dynamics. F2 identifies a parametric transition. F3 fits a compact learned state-action predictor. F4 combines known dynamics with a learned residual.

All four receive complete state-action-outcome trajectories, split by trajectory identity. The factory returns competence metrics, leakage audit, resource report and content-addressed artifact identity. An edge-agent build command keeps raw trajectories and weights local; the control plane changes build state only after a durable agent receipt.

A once-only confirmation used fresh nominal-only trajectories for all four families. Every family beat state persistence, passed one-step and H8 competence, retained zero train/validation/test trajectory overlap and produced a distinct artifact digest.

OW-3 once-only bounded Model Factory confirmation
FamilyTest RMSEH8 RMSEPersistence RMSEDecision
F1 explicit0.0000000.0000000.068138Pass
F2 identified0.00000000130.00000000650.124619Pass
F3 learned0.00013260.00032890.127316Pass
F4 hybrid0.000000000090.000000000190.059492Pass
Bounded evidence

These are A08-authored one-state structured dynamics. The confirmation validates interfaces, fitting, split integrity and artifact identity—not industrial-scale usefulness.

The language compiler failed safely

The language layer uses an OpenAI model only to draft a strict typed contract. A deterministic verifier checks schema, sensor and action grounding, hard constraints and declared missing information. The LLM cannot publish a model or activate a behavioral route.

On the first four-case development, numeric safety boundaries were preserved and no unsafe contract committed, but complete briefs were rejected because the source-key convention was underspecified. One registered remediation clarified only that convention on fresh cases.

Grounding then improved to both complete briefs, yet the model asked unnecessary questions and still withheld both commits. The second development therefore failed too. Zero unsafe commits is useful safety behavior; it is not language-to-world-model confirmation. The twelve-case confirmation remained unopened.

Language compiler development decisions
RunCorrect dispositionComplete groundedUnsafe commitsOverall
OW-22/40/20Fail
OW-2-R2/42/20Fail

The same evidence now has an operator-facing surface

The Water Tank uses a purpose-built renderer for level, pump, valve, target, safety envelope, predicted future and change explanation. A second Cold Room application uses only the generic structured renderer, proving that visual operation is a plug-in rather than tank logic inside the Runtime.

A what-if panel previews one explicit model version without sending an operating command. The embedded Operator View remains authenticated, read-and-recommend only, and cannot bypass human repair approval or scoped activation.

The complete wiring works in development; confirmation stays closed

An excluded development harness then exercised three families through nominal build, hidden action-authority change, public probe, one bounded answer, typed candidate, verification, explicit approval, immutable child version, scoped activation and exact rollback.

Frozen planning fell sharply after the registered change. The same generic action-input repair restored the evaluation-only reference across all 96 tasks. Nominal routes remained unchanged and every trace and rollback verified.

OW-5 excluded development—not confirmation
FamilyFrozen planningRepaired planningRepaired H8
F13/3232/320.00000
F26/3232/320.00000
F48/3232/320.00000
Why no end-to-end claim

OW-5 used canonical contract fixtures because OW-2 failed. Opening confirmation anyway would hide the missing language link. The 8/8 result is implementation evidence only.

What A08 has now—and the next real bottleneck

A08 now has a coherent local product: application lifecycle, local data boundary, four bounded builders, a role-specific operations surface and the unchanged verified IWMR Core. This is materially more than a repair demo, while remaining small enough to audit.

The new confirmed result is narrow: the bounded Model Factory contract works across four small structured families. The broader company thesis—describe a real process, build a competent model and restore it after change—remains unconfirmed until language interaction resolves necessary questions without blocking complete briefs and the chain is repeated on an external public substrate.

The next language step cannot be another prompt tweak. It must test an interactive compile-question-answer-revalidate loop on fresh contracts, with question relevance and downstream competence as gates.

Reading the evidence correctly

Combined totals are descriptive unless the article explicitly says they were a preregistered pooled gate. Machine timings describe the measured local implementation. A failed conjunction remains failed even when several sub-results are positive.