# Repeat prevention after an unresolved handoff

Author: **Aaron Martinez, FieldHash, Inc.**

This supplement discloses all 18 scheduled workflows from native idempotency
follow-up v2, completed on 13 September 2026. It is a separate, synthetic,
self-administered study. Its results are not pooled with the original
444-workflow organization study or earlier follow-ups.

All 9 protected workflows completed safely, including the one new objective
left for native model action. Without idempotency, 5/9 completed safely.
Four of the six declared adversarial matched pairs supplied observed
conditional mechanism witnesses: the protected workflow denied a qualifying
repeat, and the matched workflow without idempotency produced a duplicate
effect. Kimi K3 and GPT-5.6 Terra each supplied two such pairs. DeepSeek Flash
made no qualifying repeats. The prespecified all-model criterion was not met.

## Inspect the result

- [Results and limitations](RESULTS.md)
- [Methods and design history](METHODS.md)
- [Data dictionary](DATA-DICTIONARY.md)
- [All 18 workflow rows](workflows.csv)
- [Recomputed summary](summary.json)
- [All 9 matched pairs](expected/matched-pairs.csv)
- [All 12 model, condition, and control cells](expected/model-condition-results.csv)
- [Condition results](expected/condition-results.csv)
- [Control results](expected/arm-results.csv)

## Verify offline

Extract the ZIP, open its `bundle` directory, and run with Python 3.10 or later:

```sh
python3 -I -B verify.py
```

The verifier uses only the Python standard library. It checks file inventory,
hashes, row schema, the full scheduled design, pair bindings, outcome
consistency, and recomputed tables and summary. It makes no model or network
calls. A successful run establishes disclosed export consistency.

The supplied manifest does not authenticate the publisher. The verifier does
not replay the native experiment or independently classify raw model behavior.
Source-export comparison and native replay are separate checks. The public
files omit private run identifiers, raw prompts and responses, runtime code,
credentials, and local evidence paths.

The adjacent archive checksum can detect changes relative to the checksum you
obtained. Authenticity requires a separately trusted source for that checksum.
