[data-veracity] Uncalibrated deployments silently report a foreign site's exit multiplier #36
Labels
No labels
blocked
bug
enhancement
high-priority
low-priority
needs-info
needs-triage
ready-for-agent
ready-for-human
referenced
research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
gabogg/hikcentral#36
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
k = 1.1162is hardcoded as the fallback in at least four places:compute_ewma_multiplierreturnsinitial_kunchanged when there is no trusted history, so a fresh deployment — or any site that has not yet accumulated a trusted cycle — publishes calibrated occupancy figures scaled by a constant measured at a different facility.1.1162is a real empirical result for this mall's sensors. It is not a neutral default. As a fallback it means the system's least-informed state produces numbers that look calibrated and carry a ~11.6% systematic correction nobody measured.Why it is hard to notice
get_sample_maturity_infocorrectly reportsINITIAL (0/14 jornadas), but that badge lives in the admin UI, not on the deck.k = 1.1162and displayed with no indication that the multiplier is assumed rather than derived.compute_multiplier_variancereturns the default0.0002whenN < 2, so the 95% CI band renders narrow — the system is at its least certain precisely when it draws its most confident-looking band.KPIs corrupted
Calibrated Residual · Peak Occupancy · Riemann Ō · Mean Dwell · the 95% CI band width · k̂ stability tile — all of them, on any deployment before calibration matures.
Suggested fix
kto 1.0 (identity) when there is no trusted history. An uncalibrated system should report raw counts, which are honest, rather than counts scaled by a borrowed constant.occupancy_config(initial_exit_multiplier) rather than into function signatures, so it is a deployment decision with a visible value.N < 2— the CI should be at its widest when the sample is empty. Deriving the default from the guardrail range ([0.90, 1.35]) would be defensible;0.0002is not.trusted_days_count < 7, the calibrated tiles should carry anUNCALIBRATEDstate chip.RFC-ARCH-2026-004has no provision for this and should gain one.Decision needed
Whether an uncalibrated deployment should show raw numbers (recommended) or refuse to show calibrated tiles at all.
✅ Design settled (grilling session)
Note — reversed from this issue's original suggestion. The issue proposed defaulting
kto1.0(identity) for uncalibrated deployments. Decision: do not fall back to 1.0. Apply the seededkfrom day one and mark the figures explicitly unreliable until calibration matures — one consistent formula, honesty via a state chip and a wide CI.Settled spec
occupancy_config.initial_exit_multiplier(a visible per-deployment value), not from hardcoded function defaults. Remove the scattered1.1162literals (occupancy_service.py:736,778,occupancy_repository.py:1006,1065). This mall's config carries1.1162; a fresh deployment defaults to1.0and the operator sets a measured value when they have one. (Biased to this site for now — accepted.)UNCALIBRATED/SIN CALIBRARstate chip on every calibrated tile (Calibrated Residual, Peak Occupancy, Mean Dwell, k̂ stability) until 14 trusted business cycles. (RFC-ARCH-2026-004gains this state.)N < 2: derive from the guardrail — SD ≈(1.35 − 0.90) / 4 ≈ 0.11— replacing the overconfident0.0002. Widest band precisely when the sample is empty.[0.90, 1.35](occupancy_service.py:753,941); fix CONTEXT.md:88's stale[0.80, 1.30]to match. Resolves a live code/doc contradiction. Changing the live clamp is avoided so deployed calibration doesn't shift.Added to scope
Acceptance criteria (supersede "Decision needed")
kapplied from day one fromoccupancy_config.initial_exit_multiplier; no hardcoded1.1162in function signatures.1.0; this deployment's config carries1.1162.UNCALIBRATED/SIN CALIBRARchip on calibrated tiles until 14 trusted business cycles.N < 2derived from the guardrail (SD ≈ 0.11); CI renders wide.[0.90, 1.35];CONTEXT.mdupdated to match.k = 1.0, not a borrowed constant.Re-tagged
ready-for-agent.Being addressed in draft PR #70, one of four [data-veracity] drafts declared on 2026-09-23 (#68, #69, #70, #71). Each will be triaged, reviewed and implemented in order; the PR description lists the open design points to settle first.
gabogg referenced this issue2026-09-24 13:13:51 +00:00