Release Note Policy

What appears here

This page summarizes user-facing improvements that affect trust, availability, account access, report integrity, source freshness, or the way FightEdge communicates platform state. Internal-only maintenance and sensitive security details may be summarized without implementation specifics.

Deployment recovery now recognizes one exact release everywhere

The projection worker correctly generated a code-fingerprinted release identity, but several readiness, publication, and queue consumers still recognized only the shorter semantic version. That mismatch could leave a healthy deployment reporting permanent warming and prevent current projections from becoming customer-visible.

  • Readiness, System Health, projection publication, queue priority, and manifest replacement now share one exact code-tree ownership contract.
  • Two deployments with the same human version but different code fingerprints cannot adopt or publish each other's projection graph.
  • Startup, scheduler, and recovery controllers reuse one stable release generation instead of creating competing timestamped graphs.
  • Truth-changing card refreshes may still defer or safely supersede in-flight work; once truth settles, the exact current graph retries and publishes without a re-scrape.
  • No fight card, report prediction, probability, Elo, simulation, calibration, billing, entitlement, protected database, AWS configuration, topology, or IAM permission changed.

Fight cards now distinguish provider observations from active membership and recover without cache rituals

A provider response could include cancelled competitions beside active bouts, while a parser failure could look like an authoritative zero-fight card. Once that bad membership reached the durable snapshot, a shrink guard and stale automated additions could keep different pages on different cards. This release repairs those authority boundaries and the operational queues that must converge after them.

  • ESPN lifecycle fields are preserved for result auditing. Only pre-fight cancellations, postponements, and scratches leave active-card membership; no-contest, overturned, void, and draw results retain booked-card cardinality, with void/draw outcomes explicitly excluded from ordinary winner scoring.
  • Every smaller card requires positive authority: either stable ESPN event/competition identities prove that every removed bout received an explicit terminal status, or an exact event-scoped CITO pair set was successfully observed within six hours. Partial, stale, missing, and future-dated evidence remains blocked.
  • Unavailable and parser-failed sources no longer vote as zero-fight cards, copied secondary sites count as one independence group, and automated card mutation requires fresh primary evidence.
  • Direct event and live routes consume the canonical committed card or show a truthful warming state; they no longer rebuild a competing card from legacy fallbacks, and stale machine additions cannot re-expand primary-verified membership.
  • Projection generations include the immutable code fingerprint, queue admission and backlog use one manifest-aware verdict, obsolete receipts compact without retry cost, and missing manifest nodes requeue their exact work id.
  • Modified-fighter markers migrate once to shared storage, orphaned reanalysis and report-worker receipts resolve in timestamp order, and future-card/legacy-narrative diagnostics remain visible without becoming false hard failures.
  • Hourly account backups and daily fight/career backups now report separate truth; the OS-owned full-backup path reports success only after its authoritative marker write, generation bump, and exact readback are durably acknowledged.
  • No prediction formula, probability, Elo, simulation, calibration, report pick, billing, entitlement, protected database, AWS topology, or IAM permission changed.

Fight-week truth now converges once and publishes as one dependency-safe generation

Three individually reasonable recovery paths could still fight each other: result settlement alternated reviewed fighter-name aliases, runtime projections rebuilt from a smaller card than customer pages, and downstream jobs could publish before their exact authorities were complete. This release makes those boundaries semantic, shared, and atomic.

  • Post-event history repair resolves the settled winner to the booked fighter identity, preserves the durable display spelling, and reports only net semantic changes; repeated alias-equivalent passes perform no save, invalidation, or generation bump.
  • Runtime and display repositories now consume the same network-free card aggregate, while a checksum- and revision-verified committed CITO or official card may replace a smaller mutable view only with positive same-event identity evidence.
  • Dashboard, Events, direct event cards, Lock or Fade, and projection producers receive the same immutable card revision, checksum, count, and matchup membership.
  • Material official-card writes use compare-and-swap under the durable truth lease and invalidate inside that boundary; identical observations remain audit-visible without reopening convergence.
  • The projection graph queues authorities before consumers, binds every child to exact upstream publication receipts, stages compound read-model writes until a final source and ownership check, and rolls back a partial compound commit.
  • Obsolete or dependency-superseded jobs finish unpublished without consuming retry budget, and customer queries cannot certify a physical artifact whose current convergence manifest did not publish it.
  • No prediction formula, probability, Elo, simulation, calibration, report pick, billing, entitlement, database, AWS topology, or IAM permission changed.

One stable event identity now carries the current card through every downstream surface

A renamed headliner could leave a valid exact-title CITO alias at 10 or 12 fights while the newer dated generation already held all 13. Because event provenance was lost at the rows-only display boundary, downstream arbitration could treat those observations as separate cards or keep the smaller alias indefinitely. This release preserves the stable event credential from commit through display selection and CardQuery.

  • CITO authority manifests now retain normalized provider event ids and mutable slugs, and safely backfill those credentials from checksum-validated legacy snapshots.
  • A changed headliner title can migrate an existing scoped alias only when the stable provider id agrees or strict same-date canonical bout overlap proves one event; different nonblank provider ids remain separate.
  • The display adapter carries CITO event id, slug, and observation time into card arbitration, so a newer richer dated generation may replace a still-governed exact alias without relying on title similarity.
  • An older larger card cannot resurrect a pre-cancellation membership, and an explicit verified shrink authority remains final until positive reactivation evidence exists.
  • Contextual fighter aliases may join production-shaped snapshots only after the normal bout-family quorum; ambiguous components and transitive bridges between conflicting same-provider event ids fail closed.
  • Dashboard, Events, Lock or Fade, Expert Picks, and direct event-card consumers therefore converge on one canonical event membership without a request-path fetch or operator re-scrape.
  • No prediction formula, probability, Elo, simulation, calibration, report pick, billing, entitlement, database, AWS topology, or IAM permission changed.

Every current-card surface now resolves the same verified event variant

After r1192 fully converged, the direct event page correctly showed all 13 August 29 fights while Dashboard, Events, Lock or Fade, and Expert Picks remained on a stale 10-fight title variant. This release closes that exact-title split without weakening card identity safety.

  • When a stale headliner title cannot address the current cached CITO snapshot, the display-card resolver may inspect the same date only after at least four distinct matchup anchors prove both titles describe the same event.
  • The richer verified variant then replaces the smaller frame before broad customer projections are built, keeping Dashboard, Events, Lock or Fade, Expert Picks, and the direct event route on one fight count and membership.
  • An unrelated card, a weak one-to-three-bout anchor, and a mixed or malformed same-date payload remain rejected, so date proximity alone can never merge separate events.
  • The recovery uses only already-cached authority and adds no request-path network call, re-scrape, analysis job, or operator action.
  • No prediction formula, probability, Elo, simulation, calibration, report pick, billing, entitlement, database, AWS topology, or IAM permission changed.

One committed fight card now drives analysis, publication, and every customer surface

A verified 13-fight card could still coexist with a 10-fight report input and cached customer view, causing repeated full-card repairs that briefly reached convergence and then reopened it. This release removes those split authorities and makes repeated observation-only refreshes genuinely quiet.

  • Report analysis consumes the exact committed event-scoped CITO authority after durable replacements, cancellations, trusted aliases, and official ordering are applied; publication fails closed if the composed card diverges.
  • Empty, malformed, corrupt, or unreadable authority metadata remains governed-but-unknown instead of enabling a smaller manual fallback; persisted manifest corruption is recoverable by the scheduled writer rather than becoming a recurring exception.
  • Identical aligned CITO polls renew a checksum-bound freshness receipt without rewriting card truth, while disagreeing watch observations remain diagnostic and cannot replace report authority.
  • Dashboard is now an explicit dependency-ordered projection after effective predictions and the report catalog, so it cannot certify ahead of the authorities it displays.
  • Current-card cache materializations are fenced by release version, preventing a stale 10-fight frame produced by older code from surviving a deployment that resolves the same rows to 13 fights.
  • Timestamp, source URL, and provenance updates remain auditable but no longer bump card generations, clear caches, alert the owner, or reopen the projection graph; physical order remains meaningful whenever explicit fight order is incomplete.
  • Repeated repair attempts for the same versioned committed/current semantic target are suppressed only within a bounded horizon, preventing both endless requeues and stale receipts that block future healing.
  • Operator and Tapology decisions now deterministically outrank automated quorum evidence, including package/shared conflicts, explicit tombstones, same-ID updates, and natural numeric decision revisions; expired or invalid automatic candidates cannot hide valid owner truth.
  • Probe failures remain observation-only, while real membership, fight-order, section, round, or weight changes still invalidate exactly once.
  • No prediction formula, probability, Elo, simulation, calibration, report pick, billing, entitlement, database, AWS topology, or IAM permission changed.

Fight-week card changes now reach every surface without destabilizing background work

A verified CITO card could already contain all 13 fights while the Dashboard and Events page remained on a cached 10-fight view. At the same time, one oversized Expert Picks refresh repeatedly analyzed duplicate source rows and kept the shared projection graph in a warming loop. This release closes both cross-process failure paths at their source.

  • CITO authority now advances a durable card generation only when exact-event bout identity or membership actually changes; routine timestamp refreshes do not churn customer projections.
  • Card authority commits are serialized and fail closed, so web, scheduler, and worker processes cannot observe a silent partial snapshot or a healthy receipt without its required generation advance.
  • Dashboard, Events, Lock or Fade, and direct event-card caches all observe the same durable generation and discard stale process-local fallbacks automatically.
  • Expert Picks model enrichment is scoped to the nearest authoritative card, deduplicated by canonical matchup, bounded by a cooperative deadline, and admitted through the shared heavy-work lane.
  • Every external consensus row remains available, while ambiguous rows are receipted instead of guessed and duplicate rows reuse one canonical model result.
  • Partial or failed enrichment receives durable retry backoff and cannot repeatedly destabilize effective prediction revisions.
  • Support refreshes cannot live-scrape or persist fighter profiles, and the mutable Expert Picks artifact is no longer a canonical model-pick input.
  • No prediction formula, probability, Elo, simulation, calibration, report pick, billing, entitlement, database, AWS topology, or IAM permission changed.

Verified source identities can now repair report readiness automatically

The August 29 card was correct, but report generation stopped safely because the card spelling Liu Ce could not find the same athlete's professional profile published as Ce Liu. This release closes that identity-to-profile handoff without teaching the platform an unsafe global name reversal.

  • Sherdog and ESPN source spellings are accepted only when the reviewed provider-specific athlete id, date of birth, and division all agree.
  • ESPN profile dates now use an explicit locale plus machine-readable source corroboration, preventing ambiguous day/month swaps from blocking self-repair.
  • The source spelling remains excluded from ordinary fighter aliases; unrelated reversed names continue to fail closed.
  • A newly reviewed source strategy invalidates only that fighter's stale failed-discovery cooldown, then the existing scheduler lane retries it automatically.
  • Successful evidence is stored under the canonical card identity so the normal report identity and profile preflights can pass without a manual evidence-text workaround.
  • Wrong provider namespaces, ids, dates of birth, divisions, ambiguous search results, and incomplete profiles remain rejected.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, database, AWS topology, or IAM permission changed.

Card, history, and operations now converge on exact durable identity

This release addresses the overnight failure chain that kept readiness warming, repeatedly reopened a settled event, admitted duplicate upcoming bouts, and left infrastructure alarms attached to retired resources.

  • Optional historical projections can finish while unrelated card work is active only when their exact input revision is unchanged. Current and fight-week projections remain fail closed.
  • Post-event settlement fingerprints durable result content instead of SQLite WAL timestamps and report-directory metadata, while event reconciliation ignores already settled prior dates.
  • Provider competition and athlete ids now survive ESPN ingestion. Duplicate bouts are coalesced by provider identity or canonical pair, and source conflicts preserve the last known good snapshot.
  • Upcoming-card selection prefers the richest coherent same-event snapshot over a smaller fragment unless an explicit verified shrink authority proves the reduction.
  • Cross-surface card validation now compares both canonical matchup membership and bout count, so duplicate rows cannot hide a 13-versus-14 divergence.
  • A dry-run-by-default owner utility audits CloudWatch alarm dimensions against the exact live Elastic Beanstalk environment, Auto Scaling group, instance, and instance class before any optional repair.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, database, AWS topology, or IAM permission changed.

Fight-week recovery now repairs one verified event snapshot at a time

This release closes the remaining card-family, recovery-authority, and multi-process races that could combine unrelated bouts, erode a card across refreshes, lose a repair receipt, or leave a correctly restored matchup waiting for owner intervention.

  • Every card consumer now selects one authoritative, exact-date event snapshot. Adjacent dates, generic same-date events, stale titles, and conflicting provider ids fail closed instead of being unioned into an impossible card.
  • Automatic cancellation limits are cumulative and committed atomically, so separate 5 + 3 + 1 observations cannot bypass the same verified-card safety budget.
  • Only older machine-created blocks can be reactivated, and only when fresh event-scoped ESPN/official and CITO snapshots independently agree. Reactivation remains pending until that exact event has durably converged; operator, Tapology, admin, package, conflicting-id, stale, and one-sided authority remains protected.
  • Blocked-fight, override, card-truth, freshness, threshold, source-drift, and CITO quota transactions are serialized across web, scheduler, and worker processes. One event's success cannot hide another event's failed recovery.
  • Beginning a retry preserves the previous error, scoped and aggregate failures commit together, and same-title events with different provider ids have separate health lanes. A no-progress response stays red until the exact block is gone, including during startup recovery.
  • If the card changes or the current event rolls over while external sources are being collected, the stale build is discarded before any block, override, truth, or drift write. A sole same-date UFC.com page also requires verified identity or substantial bout overlap.
  • A delayed owner-gated startup recovery pass uses durable local evidence only, rebuilds source drift first, and runs exact-event convergence without a public network request or manual re-scrape.
  • CITO calls are quota-reserved durably before network use, provider ids tolerate harmless case/separator differences without crossing provider namespaces, and all durable blocked-event scopes receive a bounded retry decision.
  • Dashboard, event card, Lock or Fade, and report adapters are regression-gated against the same event pair set and count.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, database schema, AWS topology, or IAM permission changed.

Fight-week recovery now fails closed, repairs durably, and cannot starve

A deeper adversarial review found three remaining ways an otherwise healthy fight week could still need owner intervention: ambiguous provider identities could cross event boundaries, two workers could race through the same repair budget, and urgent card repair could remain behind an always-busy background queue. This release closes those recovery gaps and strengthens production monitoring and package provenance.

  • Event names, provider ids, dates, and bout identities now form one strict card family. Generic or same-date evidence cannot certify a precise event without a strong overlap or exact provider identity.
  • A verified ESPN event id now carries legitimate headliner-title changes through source drift, promotion, locks, ledgers, and repair budgets. Different same-date provider ids remain isolated, and a 13-fight card requires 10 actually matching bouts for the rounded-up 75% quorum — 10 unrelated rows cannot pass by count alone.
  • Destructive card reductions require exact fresh ESPN/CITO pair agreement or explicit cancellation authority. Rejected evidence remains observable but cannot silently become customer truth.
  • Observation, repair-budget accounting, enqueue, and ledger persistence are one cross-process reconciliation transaction under a stable global lock, even when provider identity first appears mid-repair. Queue receipts recover a repair after a crash, while another event's globally active refresh cannot spend this event's budget. Failed or exhausted repairs surface as real operator-attention states instead of false progress.
  • Near-term incomplete cards receive bounded recovery capacity even when ordinary projection work remains busy. Scoring and contract checks reuse prior work only while their authoritative database/WAL inputs remain unchanged.
  • Production alarm validation and release packaging now use exact allowlists, dimensions, archive paths, immutable baseline SHA-256 provenance, and byte-for-byte overlay verification.
  • No prediction formula, probability, Elo, simulation, calibration, report artifact, billing, entitlement, AWS topology, or IAM permission changed.

A partial source response can no longer shrink a complete fight card

Overnight diagnostics found all public card sources agreeing on 13 fights while one customer snapshot exposed only four. At the same time, recursive readiness work and repeated full-history checks kept the two-core production instance saturated, slowing the recovery work that should have repaired the display. This release fixes both sides of that failure.

  • A verified card snapshot rejects destructive partial replacements while still allowing ordinary one-bout cancellations. A fresh, event-scoped CITO card can repair a materially incomplete customer view only when its identities overlap the active event; unrelated cached cards remain fail closed.
  • Internal reconciliation can inspect report readiness without calling back into promotion flushing, eliminating the readiness → flush → reconciliation → readiness recursion seen in production.
  • Clean post-event settlement and production-contract scans now write content receipts and skip unchanged repeat work. The longest recurring scans share the heavy-job admission gate instead of overlapping and starving projection convergence.
  • Production acceptance now verifies that FightEdge CloudWatch alarms target the current Elastic Beanstalk Auto Scaling group and instance and rejects obsolete burst-credit alarms on non-burstable instances.
  • No prediction formula, probability, Elo, simulation, calibration, report artifact, billing, entitlement, AWS topology, or IAM permission changed.

Fight results can no longer stop between the inbox and Web Push

The August 22 fight-night audit proved that result scoring, opted-in audience selection, registered devices, and in-app notices all worked, yet no result reached the Web Push provider. The delivery plan was durable; the independent dispatcher was not guaranteed to run while live-result monitoring was active. This release repairs that handoff without replaying old fight alerts.

  • Result-push delivery now has its own fight-night scheduler controller. It runs alongside live-result polling instead of being suppressed by that branch, and one controller failing to launch cannot prevent the other from running.
  • The worker now discovers unfinished plans from the durable users database and reconstructs a missing prediction-log retry marker for the exact scored bout. The frozen recipient list remains authoritative and can never expand during recovery.
  • Recovered alerts still obey the short real-time delivery window. An old unfinished plan is terminally recorded rather than delivered late, preventing delayed or duplicate fight-result notifications.
  • Regression coverage reproduces the production split-brain state, verifies a real provider invocation and receipt completion, verifies stale suppression, and pins simultaneous live-result and push-controller operation.

Fight night now has one honest state from first bell through final settlement

The authoritative result panel could be correct while the dashboard hero, progress rail, or live-page header described a different phase. Late provider details could also leave a correctly scored winner without method or round, and a five-round non-title main event could display the impossible “Round 5 of 3.” This release makes those surfaces follow the same exact-card evidence and gives operations durable proof of the background work.

  • The dashboard hero, stage rail, live window, progress count, and proof chip now follow the exact event/date live-result panel. A provider “final” label is accepted only after every fight on that same card has an authoritative result, and an estimated end time can no longer make a long-running card disappear or finalize early.
  • The dedicated live page switches its header from LIVE to FINAL as soon as the terminal result fragment arrives and retires its pollers, including when the page was opened before the main event ended.
  • Round limits now prefer an explicit provider contract, otherwise recognize title bouts and the official order-zero headliner as five rounds. An observed fourth or fifth round can never be rendered against a three-round denominator.
  • When ESPN publishes method or round after the winner, the durable result processor persists the late details; the live surface may display them immediately only when the provider winner agrees with the canonical winner. Genuine conflicts remain quarantined.
  • Acceptance now reconciles planned, resolved, pending, and exhausted push-delivery receipts instead of checking configuration alone. Readiness also reports why projection convergence is waiting, which scopes are blocked or recovered, and elapsed convergence time.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

The dashboard can no longer get stuck "Refreshing" on fight day

On fight day the platform ingests a near-continuous stream of card, odds, and result updates. The pages you read are rebuilt only in quiet gaps between those updates so they always reflect a consistent snapshot — but the coordinator that schedules the rebuilds was also waiting for a quiet gap before scheduling anything. On the busiest days no gap ever arrived at the moment it checked, so pages sat on "Refreshing" for hours — a report existed, yet the dashboard would not show it until an app restart happened to land in a lull.

  • Scheduling and building are now separate: rebuild jobs are queued immediately, wait out the busy stretch at the front of the line, and start the instant a quiet gap opens — seconds instead of hours. The consistency rule is unchanged: a page snapshot still publishes only from a verified quiet moment.
  • During a busy stretch the worker no longer spends attempts on rebuilds that cannot succeed yet, so a long fight day can never exhaust a rebuild's retry budget before the card ends — and the freed capacity drains the update backlog faster, which shortens the wait itself.
  • On iPhones with the site installed as an app, the menu button no longer hides under the system status bar — the header now respects the phone's safe areas, so navigation is tappable again in the installed app.
  • Housekeeping: streamed worker logs now name which page projection each job built, so production evidence reads at a glance.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

Build parlays from every fight — the model's opinion rides on each leg

The Parlay Builder and SGP Lab are calculators and personal ledgers: you assemble your own slips, the site computes fair odds and Kelly sizing, and slips log to your paper or real ledger — FightEdge never handles a wager. But the leg list was gated to fights where the model claimed a verified edge, so on a card the model graded as leans-only the tool went empty. That gate belonged on recommendations, not on your ability to build.

  • Every fight with a resolved model side is now buildable in the Parlay Builder and SGP Lab, current cards included, regardless of the model's conviction level.
  • Honesty moved onto the legs themselves: a fight without a verified edge wears its true state — NO EDGE or LIMITED DATA — never a confidence-tier word, so a 65% lean can't dress up as a strong pick while you stack it.
  • The suggestion lanes (Lockness Monster and Method Monster) remain recommendations and still offer only verified model edges.
  • Fair-odds math, Kelly sizing, saved-slip behavior, and ledger logging are unchanged.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

The random thin black lines on mobile are gone

For weeks, phones showed occasional one-pixel black lines cutting across buttons and panels in seemingly random places, while desktop looked fine. Two iOS-specific rendering behaviors were responsible, and both are now fixed at the source.

  • Tapping a button on iOS latches its hover state — including the subtle "lift" animation buttons use on desktop — leaving the element permanently shifted a pixel and exposing a dark hairline at its edge. Every hover lift across the platform (31 style rules and the inline handlers) now applies only on devices with a real pointer; touch devices get stable geometry.
  • Large glowing panels could show a faint seam where the browser's compositor tiles meet on high-density phone screens. The affected panels now render as a single layer, and one heavy glow effect was rebuilt as a lighter equivalent.
  • A regression test now scans the stylesheets on every release and fails if any hover-lift rule is ever added without the touch guard — this class of bug cannot quietly return.
  • Housekeeping: a redundant deployment hook from the previous release was neutralized; worker-log streaming is owned by a single lane.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, or IAM permission changed.

Picks and games fill in minutes after a report, not an hour

After a report published, attaching each AI fight breakdown briefly paused the background pipeline that fills Expert Picks and Lock or Fade — and on a 13-fight card those pauses chained into an hour-long wait even though every number was already sealed and correct. The pipeline now distinguishes work that changes predictions from work that only redraws the page.

  • AI breakdown generation and attachment are now classified as presentation work: they no longer pause the projection pipeline, so Expert Picks, Lock or Fade, and the other model surfaces fill within minutes of a report sealing — while every safeguard against genuine mid-build prediction changes remains in force.
  • When an AI breakdown is rejected for containing action language on an analysis-only fight, the retry now sees the exact sentences that were flagged — materially improving first-retry recovery on the stubborn fights that used to exhaust their attempts.
  • The duplicate-report cleanup that runs when a report seals now sees sidecar-only leftovers (not just full documents), explains itself in the operational log when it declines to act, and can prove two names describe the same event from the sealed scoring-authority record alone.
  • All four background workers now stream their logs to CloudWatch with 30-day retention — an owner-authorized, configuration-only change that keeps diagnosis possible without touching the server, with no new permissions granted.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, or IAM permission changed.
Older releases Every earlier release note, newest first.

Every fight breakdown now reads like an analyst wrote it

When a fight's AI narrative isn't available yet — generation still in flight, or a draft rejected by the automated fact-checker — the report used to fall back to stat-recital prose that repeated numbers the surrounding tables already show. That fallback has been rebuilt from scratch.

  • The fallback breakdown now composes the same three-section analysis the AI writes — why the model sides where it does, how the fight actually unfolds, and how the read compares to the market — selecting the strongest data-backed drivers for each fight and stating percentage gaps by exact arithmetic. Analysis-only fights explain why there's no action instead of pretending there is; market-anchored numbers are presented as market-informed, never as model conviction. If composition can't meet the bar for a fight, the previous prose remains as the floor.
  • The dashboard Alerts tile now tells you about the device in your hand: if this browser isn't subscribed for push, the tile says so — "Armed elsewhere — not this device" — with a one-tap path to enable it, instead of implying you're covered because some other device is.
  • A background-analysis failure notice now tells the truth when the report actually published: if the worker was lost during post-publication housekeeping, the notice says the report is available rather than claiming it was never generated.
  • A sportsbook listing a fighter under a transliteration variant (Spivac/Spivak) no longer silently costs that fight its market-prices panel — a strict both-fighters fuzzy match rescues the join, and any fight that still finds no odds row is named in the operational log instead of disappearing quietly.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

Expert Picks' model column populates, and Lock or Fade fills every fight

When an event is renamed mid-week, its published report can briefly exist under two names on disk. The platform's safety machinery did exactly what it should with two disagreeing copies — it refused to serve either — but that refusal surfaced as a blank "Our Model" column on Expert Picks and a repair loop that never went quiet. This release makes the disk agree with the decision the platform already made.

  • The moment a report publishes, any older same-event copy under a superseded name is retired into a quarantine folder with a written receipt — reversibly, and only when the platform can prove both names describe the same event. Expert Picks' "Our Model" and blended consensus now populate for every fight as soon as the card's projections build, and the background repair loop ends for good.
  • Lock or Fade now treats the game as what it is — a prediction game, not a betting surface. "Lock with Model" and "Fade the Model" fill every fight where the model has a side, including analysis-only leans, so a fully published card is always playable. Betting surfaces keep their stricter verified-edge gates unchanged.
  • Report cards in the full layout now show the same MARKET DEFAULT honesty label the classic layout shows when a data-limited pick is anchored to market consensus — a market-informed number is never presented as model conviction.
  • AI fight breakdowns follow a tighter writing contract with the model's own honesty receipts in hand, so more narratives pass the automated fact-checker on the first try — and analysis-only fights read like an analyst explaining why there's no action, not a stat recital.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

Lock or Fade and Expert Picks now light up as soon as a report publishes

Two background systems were quietly fighting over the same prediction rows: live re-analysis (whose inputs drift with the odds) kept rewriting picks that the published-report reconciler had just aligned, and the endless back-and-forth kept the projection pipeline perpetually rebuilding. Downstream surfaces — Lock or Fade's card readiness and the Expert Picks model column — waited on projections that never finished.

  • Once a fight's pick is anchored to a published report, that sealed publication owns the row: live re-analysis can no longer overwrite it, and only a genuine re-publication moves it. The repair loop ends, the projection pipeline converges, and Lock or Fade plus Expert Picks populate promptly after every report.
  • Expert Picks shows "Our Model" for each fight alongside the blended consensus as soon as the card's projections build — the column was never missing, it was starved.
  • New on Rankings: a Compare Side-by-Side view — the official UFC list (Media Panel or META AI, your choice) next to the FightEdge model's ranking for the same division, with a delta chip per fighter and a strip of model-rated fighters the UFC list doesn't include. Official rankings refresh automatically on their scheduled lane; the FightEdge board recomputes continuously as results ingest.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

A market-deferred pick now publishes its full market-anchored probability

Yesterday's release correctly flipped debut-vs-debut picks to a deep market favorite's side with the MARKET DEFAULT label — but a second safety lane, written for blind model leans, re-capped the market-derived number down to a coin flip. A pick that defers to an 88% market conviction was displaying as 52.5%.

  • The zero-history and unqualified-input abstention caps now stand down for market-deferred picks — the same exemption the market-conflict cap always had. Those caps describe the model's own blind signal; a market-derived number already prices that blindness through its 80/20 dampening. An 88% market now publishes as roughly 80%, exactly as documented.
  • Nothing else changes: a blind debut lean with no deep opposing market still publishes at the conservative abstention ceiling, and every underlying data-quality condition stays recorded in the fight's receipts.
  • Market-defaulted picks now grade in their own "Market default" bucket on the proof surfaces, separate from the model's confidence bands — a market-mirrored win is disclosed as exactly that, never counted as model accuracy inside the bands.
  • Fixed the report layout downgrade: a freshly generated report rendered its full composition — pre-fight context, market panels, deep-data tools — but the background job that attaches AI narratives re-rendered the document without the rendering context those sections need, silently reverting it to a legacy layout 10-15 minutes after every build. Narrative updates now render with the same context the main build uses, so the report keeps its full composition permanently.

Debut-vs-debut fights no longer publish a blind pick against a deep market favorite

When two UFC debutants meet, the model has no UFC per-fight data on either athlete — and its tiny residual lean (often from an estimated physical stat) could land opposite a heavy market favorite. The platform already flips a no-data pick to the market's side when the opponent is UFC-tested; that safeguard never covered the case where both fighters are new.

  • When both fighters lack UFC per-fight data and the market has the model's blind lean at 20% implied or less (about -400 or worse), the published pick now defers to the market's side, dampened for the model's own missing signal (an 88% market publishes as roughly 80%) — with the full provenance recorded in the fight's analysis receipts.
  • These picks are labeled MARKET DEFAULT · data-limited · market-informed — never "model lean." A market-derived side is disclosed as exactly that, stays qualified as limited-data, and can never become a LOCK.
  • A moderate market disagreement (about -180 to -400) soft-caps the blind lean instead; market agreement or missing odds change nothing, and any fight where either fighter has UFC history is completely untouched.
  • Every fight still carries a logged pick — this changes direction and labeling on the narrow debut-vs-debut class only, under an explicit owner-authorized protected-model change recorded in the release manifest.

Narrative updates now stage and verify before they touch the served report

Two defects shared one symptom this week. The background job that attaches AI narratives re-rendered the whole report directly onto the served file with no structural verification — the one report writer that had not yet earned the staged, gated publication the main build received. And the staged mover left one date-keyed pointer file behind, which could make scoring validation reject a freshly rebuilt report against a stale pin.

  • Narrative publication now renders into the same staging area the main build uses and must pass the same completeness gate — every fight section present, the document closed, and the published narrative count matching the validated cache — before it atomically replaces the served report. A defective render leaves the previous report serving and keeps its own evidence for diagnosis.
  • Publication re-verifies the report's sealed prediction revision immediately before the swap, so a narrative refresh can never overwrite a newer report that finished while it was rendering.
  • Promotion now moves the entire verified artifact group — including the date-keyed scoring-authority pointer — so a rebuilt report can no longer serve against a stale scoring pin that silently rejects its own predictions.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

An event renamed mid-week now serves a single, newest report from every link

When a fight card confirms its headliners, the event's title grows a subtitle — and reports generated before and after the rename landed under two different addresses. Old links could open a superseded document while the regenerated report sat one URL away.

  • Report lookup now arbitrates between same-date artifacts that provably belong to the same event: the newest verified document wins, from either address. Crossing into a different event's report remains impossible — the full identity proof (event family, headliners, and the schedule's own title) still gates every bridge.
  • A pre-rename address — the bare event-family form with no headliners — is recognized only when the schedule corroborates exactly the requested headliners for that date.
  • The publication completeness check now counts the modern template's per-fight anchors directly, measuring both era markers with duplicates collapsed, and promotion writes its own log line the moment the served report changes.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

An operator action now always answers — queued, refused, or why

The new worker instruments caught one last silent failure class during their own first acceptance: a re-analysis request could be eaten between the browser and the server, and the response looked identical either way. Operator actions must answer.

  • A new force re-analysis control returns an explicit verdict — the queued job's identity, or the exact gate that refused — writes a durable receipt, and always starts a genuinely fresh analysis instead of quietly reusing a finished one. Every safety gate on the normal path still applies.
  • An analysis request that arrives stripped of its intent — the eaten-form case — is now logged with what actually arrived, never silently redirected.
  • The scheduler's heartbeat row on the worker panel now matches the deployed service name, clearing a cosmetic mismatch.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Background workers are now visible, and a report must prove itself whole before it serves

One day of operations exposed two invisible failure modes: a background worker whose process stayed "alive" while its job queue sat unconsumed, and a report publication that replaced a complete document with a partial one mid-failure. Neither could hide again.

  • The admin panel now reads every background worker's local log directly from disk — build stages, refusals, and errors are one click away instead of unreachable.
  • A new pipeline check pairs each worker's heartbeat with actual queue consumption: a live process that stops claiming work now reads as a failure, alerts the operator by email, and names the starved job kind.
  • Report publication is now staged and verified: a generated document must carry every fight's section and pass all existing certifications before it atomically replaces the served report. A failed or interrupted build leaves the previous report untouched — the promise the receipts always made is now enforced by the write path itself.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

A regional listing one division off no longer reads as a different person

The duplicate-row safety chain surfaced its final formatting artifact: one source listed the fighter at Lightweight, the other at Welterweight — one division apart, exactly the "legitimate weight change" class this platform's own validation taxonomy has recognized since v3.6.14. The safety check demanded identical divisions, which was stricter than the platform's own wrong-person rules.

  • The duplicate-row division check now measures distance using the same logic as the Fighter Validation severity taxonomy: within two divisions is legitimate same-person variance; cross-gender or more than two divisions apart still refuses.
  • Every earlier protection holds: raw weight forms count as no evidence, transposed dates count as one birthday, genuinely distant divisions and unconfirmed duplicates still fail closed, and every refusal logs its reason.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Date-order artifacts no longer read as two different people

The previous release's new diagnostic logging earned its keep on its first live refusal: the two duplicate profile rows for one fighter disagreed about his birth date — May 12 versus December 5 of the same year. The same digits, day and month transposed: one source recorded the date US-style and the other European-style. The safety check read a formatting artifact as a factual contradiction.

  • The duplicate-row birth-date check now recognizes day/month transposition: dates sharing a year whose day and month are swapped are treated as one birthday recorded in two orders, so rows joined by a confirmed name alias resolve instead of deadlocking.
  • Genuinely different birth dates still refuse the merge, as do different recognized divisions and duplicates without a confirmed alias — and every refusal continues to log exactly why.
  • Birth date and division are the final safety checks in this chain, so a confirmed-alias duplicate now resolves or refuses on real evidence alone.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Two sources describing one division differently no longer reads as a contradiction

The previous release taught duplicate profile rows joined by a confirmed name alias to resolve to one fighter — unless their stored facts disagreed. Its first live run found a disagreement that wasn't one: one source recorded the fighter's division as a raw weight figure, the other as the division name. Same division, two vocabularies, and the safety veto kept the deadlock alive.

  • The duplicate-row safety check now compares recognized division labels rather than raw text: a weight figure or unrecognized form counts as no evidence, exactly as an unparseable birth date already does.
  • Two genuinely different recognized divisions still refuse the merge, as do contradicting birth dates and duplicates without a confirmed alias — nothing about genuine ambiguity got looser.
  • When the safety check does decline a merge, it now logs precisely why, so a refusal can be diagnosed from the logs instead of reconstructed.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

A fighter stored under two confirmed spellings is one fighter again

The morning after the identity join shipped, one debutant's profile existed under both his short and full name — and every read, write, and operator ruling for him refused with the same duplicate-identity error, including the tools meant to fix it. The refusal was doing its job for genuinely ambiguous data; these two rows were the same person, already confirmed by the operator's own alias review.

  • When duplicate profile rows are joined by an operator-confirmed name alias, the platform now serves one of them deterministically — preferring the canonical spelling and a real source page — and logs exactly which row it chose, instead of refusing every operation on the fighter.
  • The collapse demands owner-reviewed evidence: only the manually curated alias list qualifies, never machine-generated name similarity. Duplicate rows that differ only by accents or letter case keep failing closed, because that shape signals an ingest defect rather than a rename.
  • Rows whose own facts disagree — different birth dates or different weight classes — still refuse exactly as before; date formatting differences between sources no longer count as disagreement.
  • Record arbitration and profile writes now land on the chosen row instead of erroring, so the operator escape hatch works for debutants too.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Operator rulings now reach every verification surface, and stuck jobs stop themselves

A live admin session this week applied two card rulings and watched the verification pause survive both — the ruling machinery wrote its receipts into stores that some verification surfaces never consulted. Separately, an overnight investigation found one heavy background rebuild silently restarting every ten minutes, all night, without ever being counted as a failure. Both classes end here.

  • A confirmed fighter-name spelling (the same person listed as "Stan" and "Stanley" across sources) is now joined at the identity layer, so the disagreement structurally cannot register as a card conflict — and the weekend card's verification pause clears with it.
  • Replacement rulings now apply everywhere at once: the served card updates immediately, and the ruling satisfies the source-quorum check for both the outgoing and incoming bout while the card transitions.
  • The strictness that matters is preserved exactly: an unruled disagreement between sources still pauses publication, and an attested bout that fails to appear on the card still refuses — that refusal is the signal the ruling did not apply.
  • Background jobs that repeatedly exceed their time budget are now counted, stopped after a hard ceiling with a visible failure receipt, and reported to the operator by email — a silent all-night restart loop is no longer a possible state. Heavy rebuild stages also received realistic fight-week time budgets.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Pages hold verified content through rebuilds, and renamed fighters join themselves

Twice in one evening a freshly published report appeared to vanish from the dashboard and reports list. Nothing was lost either time: while background projections rebuilt after a card change, some pages fell back to older or empty states instead of holding what they had already verified. This release makes serving monotonic — and teaches identity resolution to recognize a renamed fighter from the fight itself.

  • During a rebuild, the dashboard now keeps the last verified snapshot on screen under a clear "Card updated — re-verifying" notice, framed as the prior state, bounded to an hour, and replaced the moment the new snapshot is verified — never a regression to placeholders.
  • The reports list keeps the current event's report visible while its catalog projection re-verifies, instead of briefly dropping it.
  • When a data source shortens a fighter's name mid-week (Stan for Stanley), the platform now recognizes the same person from the bout itself — same event, same opponent, matching surname — and joins the records with a full audit receipt instead of blocking analysis. Name similarity alone is never enough; the bout must prove it.
  • Every verification gate is unchanged: held content is always labeled as prior state, and unproven identities still refuse with full evidence. No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Card repairs now land before analysis, never after publication

The automatic card-repair engine's first live evening completed every repair correctly — in the wrong order. A report published while verified card fixes were still pending; the engine applied them minutes later, correctly invalidated the fresh report, and emailed an instruction to re-analyze — while already re-generating the report itself. This release fixes the order and the conversation.

  • Analysis readiness now checks for pending verified card fixes first: if the repair engine has high-confidence corrections queued for the card, they are applied — and analysis waits for the settled card — instead of publishing a report the platform already knows will be superseded.
  • When a card genuinely changes after a report publishes, the notification email now says the replacement is being generated automatically. It is a status update, not a task; the existing report stays served until the replacement is verified.
  • Failure details are no longer cut off mid-sentence: diagnostic surfaces now carry the full reason, including exactly which verification check declined.
  • The pack surface's restore-after-verification behavior is pinned by test; with repairs now landing before analysis, packs mint with the report instead of being suppressed by a mid-flight verification pause.
  • Every verification gate is unchanged. No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

The record-conflict repair now actually runs during analysis

The previous release taught the platform to resolve provider record disagreements by reading fight-by-fight evidence — but its first live test failed, because the repair only ran during a fresh data fetch, and the analysis repair pass skipped fetching whenever a stored record already existed. A frozen record therefore stayed frozen through the exact pass built to heal it. Live acceptance caught it the same evening, and the new operator ruling unblocked the card as designed.

  • The analysis repair pass now re-fetches a stored record whose sources are in conflict, using the record's own profile page directly — no name search, which is unreliable for exactly the newcomers this affects.
  • The evidence comparison then runs as designed: explainable disagreements resolve with a full receipt; genuine contradictions still refuse publication and surface for an operator ruling.
  • Customer-facing pages remain strictly read-only — only the background analysis worker may fetch, and the final publication decision still comes from the same strict offline verification as before.
  • The failure was reproduced end-to-end in a regression test before the fix, and the healed path is pinned by the same test permanently.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Record disagreements between sources now resolve on evidence

When two data providers disagreed on a fighter's professional record, the platform correctly refused to publish a contested number — but resolving the disagreement required manual work, even when one provider's own fight log explained the gap. Analysis of this weekend's card was blocked twice by exactly that shape. The verification now reads the evidence instead of freezing on the headline numbers.

  • When providers disagree on a record, the platform now compares their fight-by-fight logs. A provider whose log confirms every fight it knows and simply lacks a recent one no longer counts as a contradiction — the fuller record is accepted, with the complete alignment stored as an auditable receipt.
  • A provider whose headline number contradicts its own fight log is set aside as self-inconsistent rather than allowed to block a corroborated record.
  • Genuinely contradictory evidence — two providers whose logs disagree about what happened in a fight — still refuses publication exactly as before, and a new operator ruling records the human decision with full provenance when that rare case appears.
  • The card-change repair engine, which has been running in observation mode and recording the repairs it would make, now executes those repairs by default: bounded, rate-limited, fully logged, and reversible by a deployment setting — so verified card changes and record fixes no longer wait for a human.
  • Every verification gate remains exactly as strict; what changed is that refusals now trigger evidence-reading repairs instead of manual runbooks. No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Recovery now restores to the last few seconds, not last night

The platform has quietly maintained a continuous, second-by-second replica of its critical databases alongside the nightly backups — but recovery only ever used the nightly copies. This release connects recovery to the continuous stream.

  • When a server starts without a valid database, restoration now tries the continuous replica first — recovering to within seconds of the last write instead of the previous night — validated by the same strict safety checks before anything is installed, with the nightly copies as unchanged fallback.
  • The backup health alert now also covers the hourly account-backup lane, so a quietly stalled timer is reported within hours instead of discovered by accident.
  • Background page refreshes can no longer be starved indefinitely by one very long analysis run: after twenty minutes, bounded refresh work proceeds alongside it.
  • No safety check was weakened anywhere — the continuous replica is a new recovery candidate, subject to every existing validation gate.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Scraped fighter evidence now survives infrastructure replacement

An infrastructure replacement this week revealed that manually verified fighter profiles could be lost when the underlying server changed, and that the nightly backup process had been quietly declining to upload some databases for weeks — recording the failures in a log nobody was alerted to. This release closes all three gaps.

  • Fighter career evidence is now restored automatically from backup whenever a server starts without it — with strict validation, and never replacing healthier local data with an older copy.
  • Every backup refusal now states exactly which safety check declined and why, and a failed or stale backup now alerts the operator directly instead of aging silently.
  • The server configuration now matches the upgraded fixed-performance instance class, so a rebuilt environment can no longer come back on throttled hardware.
  • All backup validation gates remain exactly as strict — nothing invalid is ever uploaded or restored.
  • No prediction formula, probability, Elo, simulation, calibration, billing, or entitlement changed.

Fight-night result ingestion now survives provider changes

Live results are scored from the primary provider's scoreboard, with a documented fallback source. Testing with deterministic fight-night fixtures ahead of this weekend's card exposed a gap in how those two compose — and hardened the whole live chain.

  • A structural change in the primary provider's data format used to look identical to a quiet night with no completed fights, so the fallback source never activated. That shape is now detected and reported as a provider failure, and the fallback takes over — while a genuinely quiet scoreboard still reads as exactly that.
  • Every surface that scores live results is now proven to read one consistent revision of the durable result state — no torn reads between the tracker, dashboard, and live pages while results are landing.
  • Fast live polling is proven to switch itself off once every fight on the card is settled and processed — and to stay on for every unsettled shape, including uncertainty about the stored state itself.
  • All of this is pinned by deterministic fixtures that simulate a full 13-fight card, partial snapshots, and provider format changes — no live network required to verify the behavior.
  • No fight card, report artifact, prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

Card changes now repair themselves instead of blocking analysis

Fight cards change constantly — short-notice debuts, injuries, replacements. The platform correctly refuses to analyze or publish against a card it cannot verify, but clearing those refusals required manual re-scraping and re-verification after every change. This release wires the detection to the existing repair machinery.

  • When analysis is refused because the committed card disagrees with the current verified card, the reconciliation engine now evaluates the event immediately and plans the same guarded re-scrape and re-verification an operator performs — bounded to two repair cycles per six-hour window per event, with every decision recorded in a durable ledger.
  • A card change landing while simulations are running is now caught at the next fight boundary and the run stops early — previously the change was only discovered after every remaining simulation had completed, wasting up to two hours of compute.
  • Card monitoring now covers events up to two weeks out instead of only fight week, matching how far ahead real card churn happens.
  • A queued customer report can no longer pause background page refreshes indefinitely: the deferral is capped at twenty minutes, so schedule, accuracy, and tool pages keep refreshing during long analysis runs.
  • The engine remains in observation mode: it records exactly what it would do without writing cards, spending provider budget, or publishing reports. Enabling autonomous execution is a deliberate, reversible deployment setting — never a browser click. Every verification gate is unchanged.

Your dashboard no longer goes blank after a release

Right after a deployment, the signed-in dashboard could briefly show an empty schedule — "No active card", zero upcoming events — even though the public pages were serving the real card the whole time. The refresh banner was honest, but the zeroes were not. This release makes the dashboard tell the truth through that window.

  • A deployment that does not change the fight card now keeps serving your verified dashboard snapshot, marked as refreshing, instead of discarding it. The platform proves the card is unchanged by comparing content fingerprints before reusing anything.
  • If a deployment does change the card, the old snapshot is still discarded — showing a removed fight is worse than showing a refresh state. Age limits on reused snapshots are unchanged.
  • When no snapshot is usable at all, the dashboard now fills the schedule and current card from the platform's own verified card projections — the same source the public homepage uses — while personal stats finish loading.
  • Anywhere data is genuinely still loading, the dashboard now says so — it never again asserts "no active card" or "0 events" as a fact it does not know.
  • No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

Unknown fighters on upcoming cards now resolve themselves

When a newcomer or short-notice replacement appeared on an upcoming card without a stored profile, report analysis correctly refused to guess — but resolving the fighter required manual scraping after every card change, and the bulk re-scrape tool searched only one source, silently. This release makes the whole loop automatic and explains every refusal.

  • A background lane now retries profile discovery for unresolved card fighters every half hour, using the full chain — Sherdog search with cross-source validation, then the identity-safe ESPN fallback — with a per-fighter cooldown so sources are never hammered.
  • The admin bulk re-scrape now uses that same chain instead of a single source, paces its requests, and its progress survives restarts and deployments instead of vanishing mid-pass.
  • Every discovery attempt is recorded durably per fighter: which sources were searched, what they returned, and exactly why a found candidate was refused — including same-name athletes in a different division, which are never auto-loaded.
  • The card page's "unresolved identities" notice and the Fighter Validation panel now show that evidence, with a direct link to a found-but-refused candidate so one confirmation click is all that remains.
  • All identity and weight-class safety gates are unchanged: an ambiguous fighter still fails closed rather than receiving a guessed profile. No prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

Results are only scored once their event start is verified

The platform's own diagnostics identified the last source of repeated background rebuilds: a prediction row whose event start time could not be verified was being scored from a database result, immediately un-scored by the safety check that refuses unverifiable results, and then scored again on the next pass — each cycle rewriting the prediction log and restarting dependent page rebuilds. This release removes the oscillation at its root.

  • Auto-scoring now runs the event-start verification before writing a result, not after: a row whose timing cannot be verified simply stays pending until the evidence exists, instead of being scored and reverted in a loop.
  • If a premature result is ever reverted again for the same reason, the revert is now content-identical to the first one — repeat safety passes can no longer rewrite the prediction log.
  • Every material prediction-log save now records which lane wrote it and which fields changed, in the durable worker logs, so any future churn is attributable at a glance.
  • Centralized worker-log streaming now also registers through the platform's own log-task mechanism, with the outcome of both paths recorded in the deployment receipt.
  • No fight card, report artifact, prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

All background workers now log durably, and deployments verify them strictly

Investigation after the previous release found that the worker-logging setup had been added to an unreachable compatibility section of a deployment script, so three of the four background workers never received it and its centralized-streaming step never actually ran. This release moves everything into the live installation path and tightens deployment verification.

  • Every background worker — report, projection, auxiliary, and scheduler — now writes to its own durable, rotated log file opened by the service manager with full privileges.
  • The centralized log-streaming setup runs in the live path and records a durable receipt of its outcome, visible in the admin System Health panel after every deploy.
  • Deployment verification now requires each worker to hold a stable heartbeat across a settling window, so a service stuck in a restart loop can never pass on a lucky instant; a failed worker still fails the deployment loudly with a recorded reason.
  • The unreachable script section no longer contains configuration that appears functional but is not.
  • No fight card, report artifact, prediction, model, probability, Elo, simulation, calibration, billing, entitlement, or IAM permission changed; the infrastructure scope remains the same two worker-service deployment hooks.

The scheduled-maintenance worker is running again

The previous release routed background-worker output to centrally streamed log files, but the scheduled-maintenance worker's start command could not open its log file under the production host's security policy and the service restarted in a loop instead of running. Customer pages, predictions, reports, and the page-rebuild system were unaffected — and the rebuild system completed its full first-pass convergence — but scheduled refreshes were stalled until this fix.

  • Both background workers now have their log files opened by the service manager itself with full privileges before the worker starts, so worker logging can never again fail on file permissions or security-policy denials.
  • The workers' original start commands are restored exactly; only the logging transport changed.
  • The centralized log-streaming setup step now records its outcome in the deployment log instead of failing silently, so streaming status is visible on every deploy.
  • No fight card, report artifact, prediction, model, probability, Elo, simulation, calibration, billing, entitlement, or IAM permission changed; the only infrastructure change remains the two worker-service deployment hooks.

Background truth updates no longer restart page rebuilds they didn't change

After the previous release, live observation showed the platform's page projections rebuilding correctly but repeatedly: scheduled maintenance was re-saving prediction and card data that hadn't actually changed, and every save advanced the data's revision, honestly reopening the rebuild. Customer pages stayed available the whole time, but the platform could only finish its rebuild by winning a timing race. This release makes unchanged saves true no-ops and makes every truth writer visible to the rebuild coordinator.

  • Saving the prediction log or the current fight card with byte-identical content no longer rewrites the file, refreshes its timestamp, advances its revision, or restarts dependent page rebuilds — repeated maintenance passes with unchanged inputs are now provably free.
  • Background truth writers now hold a short durable lease while they commit a real change, so the rebuild coordinator waits for the commit to settle instead of discovering it mid-build; a crashed writer's lease expires automatically and can never wedge the platform.
  • When a rebuild is interrupted by a genuine data change, the retry evidence now names exactly which data changed and which writer changed it, so any future churn is attributable at a glance.
  • Background worker logs now stream to the platform's centralized logging beside the web logs, closing the blind spot where worker issues could only be investigated from a signed-in session.
  • No fight card content, report artifact, prediction, model, probability, Elo, simulation, calibration, billing, entitlement, or IAM permission changed; the only infrastructure change is the worker log routing described above.

Background rebuilds now finish on their own after a deployment

After the previous deployment, the platform's disposable page projections rebuilt most of the way and then stalled: the public trust surface demanded a full historical report archive its contract never required, leftover pre-deployment background controllers kept re-expanding the work queue, and a temporarily unavailable input was reported as a hard failure between recovery passes. Pages stayed usable, but convergence needed operator attention. This release makes the rebuild converge hands-off.

  • The public trust surface now reads the same bounded current-report authority its dependency contract declares, so it publishes as soon as the current card's report discovery is exact instead of waiting on optional archive expansion.
  • Exactly one release-owned convergence generation governs rebuilds: obsolete controllers and unowned projection jobs from a stopped release are retired with auditable superseded receipts, at startup and on every reconciliation pass.
  • Page-triggered recovery (for example opening Reports while the platform is warming) now joins the active rebuild instead of minting duplicate competing jobs, eliminating queue amplification.
  • A projection waiting on an input that is still settling is honestly reported as retrying with bounded attempts and named evidence, instead of flapping the whole release into a failed state; a genuinely exhausted retry budget still fails loudly.
  • When a source changes mid-build, the rejection receipt now names exactly which source advanced, and the bounded clean retry remains automatic.
  • No fight card, report artifact, prediction, model, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

The signed-in Dashboard opens normally again

The previous release moved current and last-known-good report selection into a faster Dashboard overlay, but the route did not bind the report directory before using it. That caused every authenticated Dashboard request to fail even while infrastructure health remained green.

  • The Dashboard now binds the canonical report root before either exact-catalog or last-known-good report selection runs.
  • The route uses the same report-root authority as the durable shared Dashboard producer, preventing another split between fast-path and fallback behavior.
  • A release regression gate proves the binding occurs before the first report-directory use.
  • No fight card, report artifact, prediction, model, calibration, billing, entitlement, AWS topology, or IAM permission changed.

Background work now proves the exact truth it published

A queued job could outlive the inputs or release that created it, while a busy worker could hide an overdue customer job and report discovery could temporarily disagree across pages. This release makes those boundaries explicit and durable.

  • Every projection records its execution-time source revision and is rejected if a card, report, result, or other authority changes while it builds.
  • Current-release truth mutations run before projections; older queued mutations are safely superseded after deployment instead of replayed under new code.
  • Report analysis now leaves a complete terminal receipt with the stage, readiness state, source revision, and unresolved fighter identities.
  • Settled unchanged prediction partitions are reused, while progress checkpoints keep long rebuilds observable.
  • Missed queue start deadlines remain visible even when another job is running, and an exact broken revision has a bounded retry budget.
  • Dashboard, Reports, and direct report access now share current report authority while preserving verified historical reports during refresh.
  • No fight card, prediction formula, probability, Elo, simulation, calibration, billing, entitlement, AWS topology, or IAM permission changed.

Reopened data can no longer leave stale tools certified as current

Production exposed a race where a source revision could reopen after a consumer had already been treated as published. That allowed dependent tools to remain stale or a late job to certify work built from the previous revision. The hourly account backup also lacked a post-deploy proof run.

  • Projection authorities now reconcile before their consumers using the manifest state that is current at each step.
  • Reopening any authority recursively invalidates every downstream receipt and requires a new revision-bound job.
  • A late successful job is rejected when any dependency reopened while it was running.
  • Expert Picks now waits for its actual Lock or Fade input, including that projection's prediction and report authorities.
  • Account backups run two minutes after deployment and hourly thereafter through a bounded systemd timer; started, failed, and successful receipts immediately invalidate the backup-status projection.
  • No fight card, prediction formula, probability, Elo, simulation, calibration, billing, entitlement, or IAM permission changed.

Background work is isolated, bounded, incremental, and observable

One healthy worker process could still let a sitemap, projection rebuild, backup, or invalid historical report monopolize background capacity and delay fight-day work. This release turns those implicit waits into separate, measurable contracts.

  • Report publication, projection convergence, and auxiliary sitemap/diagnostic work now run in isolated workers under one shared CPU capacity boundary.
  • Every durable job has both a no-progress deadline and an absolute deadline; stalled work fails visibly and becomes retryable.
  • Effective predictions rebuild changed or recent event partitions while reusing settled materialized history.
  • Account backups have Python and operating-system timeouts, started/finished receipts, stale-run and snapshot-age detection, plus a daily non-destructive restore drill.
  • Final event pages stop live polling, ordinary projection warming returns a distinct non-5xx state, and unchanged invalid legacy reports are quarantined from hot scans.
  • No fight card, prediction formula, probability, Elo, simulation, calibration, billing, entitlement, or IAM permission changed.

Release truth, post-event settlement, and backups now recover in the right order

Production proved that healthy workers could still publish fight-day consumers before their authoritative inputs, abandon a sealed report after its live window, and skip an account backup during an ordinary SQLite writer interval.

  • Canonical predictions and report discovery now publish before Lock or Fade, Parlay, and Expert Picks, and only the atomic 19-scope manifest can certify convergence.
  • Unscored sealed reports receive bounded, low-frequency ESPN catch-up for seven days without replaying stale realtime notifications.
  • The durable report worker can hydrate trusted evidence for only the exact profiles that failed, then must pass the original offline gate before simulations begin.
  • Optional narrative reconciliation follows recent incomplete sealed reports after the platform advances to the next card.
  • Hourly account backup snapshots the live database first and validates the immutable copy before S3 publication.
  • No card data, prediction formula, probability, Elo, simulation, calibration, billing, IAM permission, or AWS resource topology changed.

Live and report reads now share one application-owned data boundary

Several customer paths still knew whether trusted data lived in SQLite, tracker logs, JSON report sidecars, or persisted odds files, and some live helpers closed a connection owned by the wider request or worker lifecycle.

  • Reports, predictions, result windows, fighter lookup, odds snapshots, and public user reads now expose typed repository contracts through one defensive-copying application service.
  • The live panel keeps its bounded single-query neighboring-date result lookup while removing SQL and storage ownership from the route.
  • Live kickoff, fighter archetype, history event identity, report-sidecar, and tracking reads now consume the same boundary.
  • Borrowers no longer close request- or thread-managed database connections during live rendering, result watching, event-day checks, or final-method reconciliation.
  • Persisted odds discovery ignores broken or empty snapshots and never calls a provider from a customer request.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Release acceptance now proves semantic health, not merely HTTP availability

A page could return 200 while showing the wrong event, stalled results, incomplete projections, or an oversized payload. The read-only release gate now fails those states explicitly.

  • Critical routes receive first-load and repeat-load latency samples plus bounded response-size budgets.
  • Live probes verify event identity, card size, lifecycle order, provider health, final settlement, and non-regressing completed-result counts.
  • Push readiness is machine-readable and no longer inferred from mutable display prose.
  • Projection readiness requires exact expected and published scope counts, the current release, and zero pending or failed scopes.
  • Metric and composite alarms, scheduler health, worker health, and one full scheduled cycle all participate in the fail-closed receipt.
  • The runner remains read-only: no scrape, analysis, rebuild, provider call, push, admin job, user-data, model, AWS, IAM, or schedule mutation.

Report readiness and engine execution now share one application boundary

Report-wide identity and model-profile checks still lived inside the oversized Events route even after interactive and administrative analysis adopted the shared orchestrator.

  • Card-wide identity and profile readiness now return typed, immutable receipts with the same actionable fighter, row, stage, and canonical-identity details.
  • Profile readiness explicitly remains local and network-free; it cannot introduce an unexpected live scrape into report generation.
  • The full-card engine is invoked and its result shape is validated through the shared AnalysisOrchestrator.
  • The proven report engine, per-fight progress, consensus input, committed-card pinning, and atomic publication flow remain unchanged.
  • Customer routes are regression-gated against directly importing identity-profile, matchup, or simulation engines.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Every customer route now reads fight-card state through one shared boundary

A final group of customer paths still called legacy mutable card builders or hashed low-level source files to decide whether cached content was current.

  • Tracking and History, Prediction Archive, Fighters, and event compatibility paths now consume the same immutable, network-free card inputs as the rest of the platform.
  • Request cache credentials now use one durable cross-process generation token advanced by every supported card writer.
  • Web, scheduler, and worker processes can no longer disagree because one process restarted or held a different in-memory revision.
  • Local fallback remains explicitly local-only and cannot trigger official-source work during an HTTP request.
  • Operator refresh commands and the specialized warm-cache truth verifier remain explicit authority boundaries instead of being weakened into display reads.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Customer pages now read one canonical fight-card snapshot

Several customer routes still read mutable card DataFrames directly even after workers had adopted the canonical card-query service. That left two competing read contracts and risked inconsistent cards or cold-request upstream work.

  • Events, Dashboard, My Bets, betting tools, and community card context now consume immutable card snapshots through one shared facade.
  • Customer requests use an explicitly network-free repository; scheduler and projection workers remain responsible for upstream convergence.
  • Legacy presenters receive bounded copied rows carrying card revision, verification, projection state, fight order, and scheduled rounds.
  • No web route directly imports the mutable current-card display loader, preventing storage and refresh details from leaking back into HTTP controllers.
  • Existing route caches, payloads, report authority, premium gates, and automatic recovery ownership remain unchanged.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Prepared pages now explain their data state consistently

The shared projection reader already knew whether data was current, stale, warming, unavailable, or failed, but several routes discarded that state before rendering.

  • Value Finder, ITD Scanner, Edge Worklist, Reddit Sentiment, Fight Week, backups, Prediction History, CLV, Trust, and Rankings now render the same accessible lifecycle notice contract.
  • Exact empty results are identified as current-but-empty instead of looking like a failed refresh or missing source.
  • Stale pages explicitly preserve the last verified snapshot while durable recovery runs; failed and unavailable states never pretend to be valid data.
  • Lifecycle wording now lives in one web-layer adapter, while the application query service remains independent of Flask and templates.
  • Existing payload shapes, page-specific integrity messages, premium gates, filters, and automatic repair behavior remain intact.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Prepared pages now share one recovery and freshness policy

Durable builders already ran outside customer routes, but each page still interpreted the resulting generation and recovery state independently.

  • Parlay, Lock or Fade, Expert Picks, market tools, Leaderboard, Fight Week, backup status, and public tracking pages now share one exact, stale, warming, unavailable, and failed read lifecycle.
  • Last-known-good payloads are defensively copied before stale notices are applied, preventing one request from mutating the durable source or another page.
  • Old and current projection envelopes use one generation-identity rule, eliminating page-specific disagreement about whether a snapshot is current.
  • Missing and failed projections request one coalesced durable repair through an injected adapter; a queue failure cannot turn a truthful recovery page into an HTTP 500.
  • Expired Parlay fights remain excluded, Lock or Fade still rejects the wrong event, and model authority remains exact-only where required.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Every durable projection now builds outside customer routes

Accuracy History and Public Trust were the final worker projections still assembled through the tracking HTTP route.

  • Accuracy History now atomically publishes event records, confidence and method summaries, rolling accuracy, filterable rows, and operational receipts from one exact prediction generation.
  • Conflicting same-authority fight outcomes fail closed and cannot enter the public accuracy record.
  • Public Trust now joins proof, benchmark records, freshness, current-card identity, and report availability from generation-bound application inputs.
  • The Trust producer and reader now share the same effective-prediction plus report-catalog generation token, eliminating perpetual false-stale refreshes.
  • Signed-in report-generation visibility remains a bounded live overlay instead of being frozen to the worker's anonymous identity.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Historical receipts now converge outside customer requests

Prediction Archive and CLV Ledger no longer rebuild through the tracking HTTP route when the durable worker publishes them.

  • Both surfaces now share one canonical scored-fight policy based on exact event date and the full fighter pair.
  • Cancelled, unresolved, missing, duplicate, draw/no-contest, and conflicting highest-authority results fail closed instead of changing public accuracy.
  • The archive publishes its event summaries and direct fight-receipt index atomically from one exact effective-prediction generation.
  • CLV coverage is tied to both settled model history and the current market generation, including legacy model-edge receipts.
  • Routes accept the previous and current durable envelope during deployment, avoiding a false empty archive while r1137 converges.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Rankings and crowd context now converge outside customer requests

Rankings and Reddit Sentiment were the final high-cost fight-analysis surfaces still rebuilt through customer route modules.

  • One rankings job now reads Elo, records, activity, current cards, advanced scores, and official rankings once, then atomically publishes all 14 supported filters.
  • Division-specific requests never compute Elo or fabricate an internal Flask request; they serve exact, last-known-good, or truthful warming state.
  • Reddit Sentiment now filters against canonical full-fighter matchup identity and discards cancelled or replaced pairs.
  • Model context comes from the exact generation-bound Expert Picks and sealed report projection, so stale pair-level picks cannot leak onto a current card.
  • Successful source commits invalidate durable generations, allowing the dependency graph to repair both surfaces without an operator page visit.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model formula change, AWS mutation, IAM change, or schedule change.

Operational surfaces now build through shared application contracts

Leaderboard, Backup Inventory, and Fight Week still crossed customer route modules during durable worker publication.

  • Leaderboard filter expansion, row enrichment, model accuracy, and event recaps now belong to one route-independent application projection.
  • Effective model history and event recap evidence are loaded once per publication instead of being reopened for every event and season.
  • Backup Inventory now shares one optional-file policy, latest-object summary, and operator health vocabulary between worker and admin views.
  • Fight Week publishes its existing account-neutral compiler directly without importing an authenticated route.
  • All three remain durable, generation-fenced, atomic projections; member requests continue to consume exact or last-known-good state.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model change, AWS mutation, IAM change, or schedule change.

Fight-week market tools now converge through one application boundary

Four high-use market projections still depended on betting page modules even after worker dispatch was centralized.

  • ITD Scanner, Edge Worklist, Odds & Lines, and Value Finder now build through route-independent application producers.
  • Each tool joins the canonical card revision, exact sealed event report, and the same persisted market generation.
  • Stale odds and non-qualified model output fail closed, while analysis-only and odds-pending fights remain honestly visible.
  • Value Finder retains verified total-round edges, fade signals, and large-edge quarantine; O/U recommendations require a validated report receipt.
  • Odds & Lines publishes the complete current slate once, with compact display filtering applied without rebuilding the projection.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model change, AWS mutation, IAM change, or schedule change.

Fight-week projections now build outside customer route modules

Worker dispatch was centralized, but three important prepared surfaces still imported HTTP routes to construct and publish their payloads.

  • Parlay, Lock or Fade, and Expert Picks now build through route-independent application services backed by canonical card snapshots and sealed report authority.
  • Parlay candidates carry the exact card revision, reject expired and non-qualified rows, and join current market data without executing a page route.
  • Lock or Fade carries explicit card verification, safely orients community consensus, and uses the provider start time for the pick lock boundary.
  • Expert Picks refuses stale dependencies and malformed partial model contracts instead of publishing an apparently successful empty projection.
  • Compatibility refresh functions delegate to the same producers, while the remaining route-owned projection families are explicitly inventoried for subsequent releases.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model change, AWS mutation, IAM change, or schedule change.

Shared reliability boundaries now execute across fight-week workflows

The application-service foundation exposed a Parlay publication defect and several remaining card and analysis paths that still bypassed the shared runtime contracts.

  • The registered Parlay producer now always performs its generation-fenced publication and returns a durable success or failure receipt.
  • Worker startup, scoped, and fallback projection work all execute through the same fail-closed producer registry.
  • Report generation, live operations, scheduled jobs, games, and Expert Picks consume revisioned canonical card snapshots with explicit verification state.
  • Renamed headliners resolve safely by a unique event date; multiple same-date events remain ambiguous and fail closed.
  • What-If, Expert Picks, Dream Fight, report analysis, and admin profile reconciliation now share one identity/profile/model orchestration boundary.
  • No card re-scrape, report generation, provider or Claude call, push delivery, user-data mutation, model change, AWS mutation, IAM change, or schedule change.

Fight-week tools now share one application contract

The durable worker was isolated from customer requests, but many projection builders and analysis entry points were still owned by route modules with route-specific card and loading shapes.

  • Worker projection dispatch now goes through one route-independent application service and composition root with fail-closed publication receipts.
  • Lock or Fade and Parlay consume immutable, revisioned card snapshots through the canonical card-query and repository boundary.
  • Report analysis and Dream Fight share one analysis orchestrator for identity, readiness, cancellation, deadlines, engine execution, and result validation.
  • Repository contracts now isolate cards, reports, predictions, results, odds, users, and durable read models without replacing the proven SQLite/JSON storage.
  • Shared exact, stale, warming, empty, unavailable, and failed UI states now provide consistent recovery language and accessible status semantics.
  • A read-only production acceptance runner produces one fail-closed verdict for AWS health, alarms, release parity, heartbeats, convergence, route budgets, card/report continuity, live polling, push readiness, and a scheduled cycle.
  • No card re-scrape, report generation, provider call, prediction change, push delivery, account mutation, AWS resource, IAM, or schedule change.

Current fight-week tools now converge before optional history work

Projection jobs were durable, but they still launched as one flat startup burst. Historical and global builders could compete with the current report and fight-week tools on the single production worker.

  • An explicit dependency graph now queues only ready projections and records why every blocked scope is waiting.
  • Old queued projection jobs become auditable superseded receipts instead of consuming the new release's worker lease.
  • Current View Report discovery is permanently separated from full historical report expansion, previews, and archive work.
  • Generation invalidations record their source and caller, making repeated rebuilds traceable to the truth mutation that caused them.
  • A safe automated fight-night gate exercises live transitions, result receipts, scoring, replay protection, and final-state monotonicity without contacting providers or sending pushes.
  • No card re-scrape, report generation, provider call, prediction change, push delivery, account mutation, AWS resource, IAM, or schedule change.

Fight-night results now have honest provider health and durable scoring authority

The live worker was running, but ESPN's edge rejected FightEdge's bot-shaped transport identity with HTTP 403 while the scheduler reported the provider as healthy and never entered its existing fallback lane.

  • ESPN requests now use the accepted JSON transport, and HTTP 403, 429, and 5xx responses count toward the provider circuit before health can reset.
  • The 30-second live lane performs bounded UFCStats failover, preserves the last durable card when both providers are unavailable, and keeps catch-up notifications from masquerading as real-time pushes.
  • Provider receipts distinguish a successful empty poll from transport failure, browser challenge, parser failure, and missing current-event coverage.
  • Reports now publish an immutable scoring selector in the same rollback transaction as their sealed artifact group, removing disposable report catalogs from the long-term scoring authority chain.
  • The live page and Admin/System show actual provider success time and outage state instead of page-render time or a healthy worker heartbeat.
  • Projection reconciliation is admission-controlled during active result work, preserving the latency-sensitive poll and scoring path.

Profiles get original FightEdge avatars while bulk picks tell the truth

Members can now choose from two original fight-themed avatar collections without uploading files, while Lock or Fade distinguishes a completed model evaluation from a qualified actionable model pick.

  • Twenty-four optimized FightEdge artwork avatars are available in Account Settings and appear consistently in the account sidebar, private identity card, and public profile.
  • Avatar selection uses the existing preferences store, validates every identifier against a fixed server-side catalog, and preserves Classic Initials as the safe fallback.
  • Lock with Model and Fade Model are disabled when the current card has zero verified MODEL_EDGE picks; NO_EDGE and LIMITED_DATA evaluations are never silently converted into picks.
  • The bulk-action endpoint shares the same qualification helper as the page and cannot claim success or write picks when zero fights qualify.
  • The r1127 Parlay projection-state binding fix remains in place with an explicit next-release regression gate.
  • No card re-scrape, report analysis, provider call, prediction, probability, Elo, simulation, live-result, push, billing, AWS resource, IAM, or schedule change.

Parlay Builder now renders the same honest projection state it loads

Live acceptance of v3.15.874 found a route-only variable binding error: the durable Parlay projection completed, but the page failed before rendering its exact, stale, or warming status.

  • Parlay Builder now loads fights and their projection status in one operation and passes that status to the template.
  • A real route regression test exercises the rendered context, preventing a source-only check from missing this failure again.
  • An exact current card with no qualified MODEL_EDGE picks now says so explicitly instead of incorrectly asking for another report analysis.
  • The fix does not re-scrape a card, regenerate a report, call a provider, alter predictions, or change live-result and notification behavior.

Current-card tools now recover from startup generation races automatically

Fight-day acceptance found that a deployment could publish one prepared page, then repair report-backed prediction truth and silently make that page obsolete. The old convergence controller treated any prior publication as permanently complete, leaving Lock or Fade in an updating state and Parlay without the current card.

  • Every published scope is now rechecked against its exact declared inputs; generation drift reopens only the affected durable job.
  • A saved startup truth repair immediately triggers projection reconciliation instead of waiting for an inherited scheduler lease or a later periodic cycle.
  • Lock or Fade, Parlay, and Expert Picks receive bounded fight-day priority, while customer report jobs remain ahead of archive-wide optional rebuilds.
  • Expired Parlay fights are never shown. A still-current verified card may remain visible with an honest updating banner while its replacement projection publishes.
  • Unrelated report, market, or dashboard changes no longer rebuild every projection, reducing startup CPU and queue pressure.
  • No card re-scrape, report regeneration, provider call, prediction formula, probability, Elo model, simulation, calibration, protected database/card byte, account, billing, AWS resource, IAM permission, or schedule change.

Live scoring now follows the same verified report users can reopen

Pre-fight production acceptance found that an older report alias could coexist with the current replacement-card report. The report library correctly showed one current report, but a bare event-name lookup could still see conflicting sealed aliases and refuse to score the event.

  • When multiple current-card aliases exist, the exact-generation report catalog may identify the single report already advertised through View Report.
  • The selected artifact must still pass its seal, exact event date and identity, complete card membership, and structured prediction validation.
  • A stale or ambiguous catalog, invalid artifact, or card mismatch still fails closed; no mutable prediction log or navigation data can replace sealed model truth.
  • Bare UFC 330 scoring now resolves to the same current replacement-card report used by the live page, allowing durable result receipts and push plans to proceed after genuine finals.
  • No card re-scrape, new report analysis, provider call, prediction formula, probability, Elo model, simulation, calibration, protected database/card byte, account, billing, AWS resource, IAM permission, or schedule change.

The final deployment check now verifies the backup design actually being installed

The first r1123 deployment started the application and both durable workers successfully, then the final topology hook rejected its own intentional backup change because it still required the retired flock -n cron token. AWS correctly stopped the deployment, leaving the prior application version serving.

  • The daily full backup is verified against its exact bounded thirty-minute maintenance-lease wait and low-priority CPU/I/O controls.
  • The hourly account backup is verified as independent of heavy maintenance so projection work cannot suppress the account recovery-point objective.
  • Both backup scripts must prove their own duplicate-run locks; duplicate schedules and legacy root-crontab entries still fail deployment closed.
  • All r1123 report, projection, card-validity, Expert Picks, convergence, and backup behavior is preserved unchanged.
  • No card source, scrape cadence, prediction formula, probability, Elo model, simulation, calibration artifact, protected database/card byte, account, entitlement, subscription, billing behavior, provider call, AWS resource, IAM permission, or cron schedule changes.

Current reports now survive unrelated data freshness while prepared pages prove usable content

Live r1122 acceptance proved the deployment stayed green and restored most prepared pages, then exposed three deeper contract failures: fighter-database freshness could suppress a card-current report, Expert Picks could publish an empty model projection, and history builders could recursively refresh the source generation they were trying to consume.

  • Only verified fight-card identity changes invalidate a current report. New fighter/model inputs remain visible as a refresh recommendation without erasing the sealed report or its report-derived tools.
  • The effective-prediction pipeline shares one report-truth scan, removing repeated historical sidecar validation from the same build.
  • Expert Picks now receives explicit normalized sealed model rows and cannot claim successful publication when report-backed candidates were discarded.
  • Prediction Archive and Accuracy History build from one exact effective-prediction snapshot and never start a nested source refresh.
  • Projection retries retain attempt counts and their last terminal error, so recovery no longer hides the reason a scope restarted.
  • The hourly account backup runs independently of broad maintenance work and writes a durable success/failure receipt shown in Backup and Restore.
  • No prediction formula, probability, Elo model, simulation, calibration artifact, protected database/card byte, account, entitlement, subscription, billing behavior, provider call cadence, AWS resource, or IAM permission changes.

Deployment recovery now performs each prepared-page rebuild once

Live r1121 acceptance proved the correct report survived deployment, then found two startup controllers rebuilding the same eighteen projections under different generations. The active Value Finder job also reopened the full historical report archive even though current fight-week tools can only use the sealed UFC 330 report.

  • Each release now owns one stable, idempotent startup fanout. A duplicate controller follows the existing work and preserves already-published scopes instead of replacing their convergence receipt.
  • Lock or Fade publishes the bounded current-event report authority before dependent tools; Value Finder, Edge Worklist, Parlay Builder, Reddit Sentiment, and Expert Picks reuse it without rescanning historical reports.
  • Parlay cache identity combines the supported prediction-generation receipt with bounded current/future-event sidecar probes instead of hashing the report archive.
  • The existing Elastic Beanstalk backup jobs now create verified SQLite snapshots through Python’s online-backup API, removing an undeclared command-line dependency that left the latest account backup stale.
  • The hourly account backup reports failure unless both dated and latest S3 copies succeed; Backup and Restore remains in attention until a fresh verified run actually completes.
  • No card source, scrape cadence, prediction formula, probability, Elo model, simulation, calibration artifact, protected database/card byte, report-validity rule, account, entitlement, subscription, billing behavior, provider cadence/budget, AWS resource, IAM permission, or schedule cadence changes.

Failed prepared pages now recover during fight-day monitoring without touching the card

Live r1120 acceptance proved the release-owned controller was working, then exposed a narrower failure: the full historical report catalog failed while every other prepared page continued rebuilding. Once fight-day live-result watch begins, the scheduler’s fast return could skip the receipt-only retry controller.

  • The projection reconciler now runs before the fight-day fast return. It still performs only bounded receipt reads and durable enqueues; live-result polling remains isolated from projection building.
  • A failed or excessively expensive historical catalog expansion falls back to the latest verified sealed report, keeping UFC 330 discoverable instead of showing a zero-card Reports library.
  • Readiness and System Health now expose the bounded failure reason for each failed convergence scope.
  • The aged-report banner now tells operators to trust the platform’s card-source verification and re-analyze only when the card is verified as changed or the report is marked stale.
  • Value Finder now consumes the same canonical persisted-odds/card join as Odds & Lines, instead of relying on provider timestamps and surnames, and its projection build cannot invalidate itself by launching an odds refresh.
  • No card source, scrape cadence, prediction formula, probability, Elo model, simulation, calibration artifact, protected database/card byte, report-validity rule, account, entitlement, subscription, billing behavior, provider cadence/budget, AWS resource, configuration, or schedule cadence changes.

A deployment now restores prepared pages without re-scraping a correct card

Live r1119 acceptance proved that the new worker could be healthy while still inheriting a startup receipt and convergence manifest from the previous release. A card re-scrape appeared to repair the site only because it changed generation tokens and accidentally queued the missing projection work.

  • Worker startup now owns a release-scoped recovery identity, so it cannot reuse an active startup receipt created by the stopped release.
  • The scheduler durably creates a bounded current-release startup barrier when the convergence manifest is missing or belongs to an older deployment.
  • A startup receipt cannot report success unless its child projection manifest was actually published; missing-manifest retries are bounded and idempotent.
  • Legacy queued projection receipts inherit the current scope-specific progress deadline, preventing an old startup job from receiving a longer generic timeout.
  • System Health names prior-release projection ownership and explicitly explains that re-scraping a verified card is not the repair.
  • No card source, scrape cadence, prediction formula, probability, Elo model, simulation, calibration artifact, protected database/card byte, report-validity rule, account, entitlement, subscription, billing behavior, provider call, AWS resource, configuration, or schedule changes.

A healthy worker must now prove progress, not merely remain alive

Live r1118 acceptance found one old read-model refresh renewing its heartbeat for hours while making no projection progress. Because that job owned the only durable worker, the release convergence work remained queued and customer tools stayed on different data generations.

  • The retired all-in-one refresh is now a bounded controller that queues independently retryable dashboard, prediction, report-catalog, market, community, backup, and leaderboard producers.
  • The current deployment's convergence jobs run ahead of older optional work, and a new release generation cannot reuse an active job from a prior generation.
  • Each read-model job has a stage-progress deadline independent from its renewable heartbeat and generic long-maintenance timeout; a frozen stage fails visibly and the existing worker service restarts cleanly.
  • A confirmed deployment restart immediately recovers receipts owned by the stopped worker process instead of trusting its recently written heartbeat for another lease period.
  • Readiness and System Health show exact convergence counts plus the active scope, requester, generation, progress age, deadline, and stall state.
  • No prediction formula, probability, Elo model, simulation, calibration artifact, protected database/card byte, report-validity rule, account, entitlement, subscription, billing behavior, provider cadence, AWS resource, configuration, or schedule changes.

Prepared fight-week data now proves that the whole release converged

Production acceptance found that individual startup jobs could be healthy while customer pages still represented different data generations. It also reproduced a report-alias gap in Expert Picks, a false model-input change caused by a broad modified-fighter marker, and operational alarms that treated safe artifact warming like a server outage.

  • Each deployment now owns one release-scoped convergence manifest covering every prepared page, with exact per-scope job identity, completion state, and bounded automatic recovery for interrupted or failed work.
  • Expert Picks receives a dedicated prepared model projection from the same sealed report authority as Lock or Fade, including the verified UFC number/date alias used by generated event names.
  • A modified-fighter marker now triggers exact semantic certification across database revisions; it cannot by itself invalidate a sealed report whose actual fighter inputs are unchanged.
  • Terminal narrative recovery receives one release-aware retry path, validated partial coverage remains publishable, and the narrative diagnostic reads its durable cost ledger once while preserving fail-closed spend controls.
  • Readiness distinguishes critical runtime failure from projection warming, and scheduled heavy work waits for startup convergence so deployment CPU pressure cannot strand customer projections.
  • No prediction formula, probability, Elo model, simulation, calibration artifact, protected database/card byte, account, entitlement, subscription, billing behavior, provider cadence, AWS resource, configuration, or schedule changes.

Fight-week reports and prepared pages now recover as one system

Production acceptance found several remaining ownership gaps: a healthy deploy could leave optional pages on older generations, leaderboard member context could reopen report history inside a request, and valid Claude narratives could be stranded by an event-name alias even after the core report was safely published.

  • Deploy startup now durably queues every isolated customer projection after the critical report and dashboard state is restored, keeping market, community, trust, rankings, backup, and leaderboard surfaces convergent.
  • Projected leaderboard requests consume materialized scores, and Expert Picks accepts the same verified numbered event on the same date even when one surface carries a headliner or generated display alias.
  • Narrative publication uses the immutable identity sealed into the report, retries a previously repaired failure once per release, publishes partial validated coverage, and verifies the same Claude marker in both web and fallback worker rendering.
  • The Claude prompt now matches the analysis-only validator, while rejected or missing narratives continue to fall back safely without blocking the verified core report.
  • The existing Elastic Beanstalk backup cron now records a status only after proving that this exact run refreshed the critical dated and latest S3 objects; no new AWS resource, permission, schedule, or provider call is introduced.
  • No prediction formula, probability, Elo model, simulation, calibration artifact, packaged database/card byte, account, entitlement, subscription, billing behavior, or provider cadence changes.

Deploy recovery and market pages now converge automatically

Live acceptance found one shared recovery defect behind missing reports, stale odds tools, and an intermittently frozen leaderboard: existing optional work could suppress or delay the durable rebuild that should run after a deployment or odds update.

  • Worker startup recovery now has a distinct priority identity, cannot be coalesced into an unrelated page refresh, and cooperatively preempts ordinary read-model work at safe checkpoints.
  • Leaderboard requests always read a prepared projection in production and show an honest refreshing state instead of performing a global history aggregation inside the web request.
  • Each committed odds snapshot now queues Value Finder, ITD Scanner, Edge Worklist, Parlay Builder, and line-movement projections together so those surfaces cannot silently disagree about market freshness.
  • The most expensive optional leaderboard build is queued after lightweight customer projections, and worker diagnostics identify the active read-model scope.
  • No prediction formula, probability, Elo model, simulation, calibration artifact, protected database/card byte, account, entitlement, subscription, billing behavior, AWS resource, schedule, or provider budget changes.

A safer path for reducing platform-wide route duplication

FightEdge now has an additive application-layer contract for prepared page data, giving future route migrations one consistent definition of exact, stale, warming, unavailable, and failed state. This release does not switch customer traffic to a new implementation.

  • A default-off, worker-only Parlay observer can compare the new contract with the existing durable projection after publication.
  • The observer performs no work in customer requests, writes no prediction or card truth, and cannot fail an already-published legacy projection.
  • Architecture tests prevent the new application layer from importing HTTP routes and freeze the remaining route-owned worker dependencies so debt cannot grow silently.
  • No customer feature, prediction engine, card/report result, account, entitlement, subscription, billing behavior, protected database byte, AWS resource, schedule, or provider budget changes.

Slow tools now read prepared truth instead of rebuilding the platform

A platform-wide route audit found the same ownership defect behind the long waits: several member pages were joining cards, reports, odds, files, or global database history inside the web request. A slow or failing projection could also delay unrelated tools because they shared one monolithic refresh cycle.

  • Value Finder, ITD Scanner, Edge Worklist, Reddit Sentiment, Parlay Builder, Shared Slips, Leaderboards, Lock or Fade, fight-week tools, rankings, and backup inventory now refresh through isolated durable jobs with independent retry receipts.
  • My Bets and ROI pages no longer settle bets while loading; scheduled scoring owns writes and customer requests read committed results.
  • Member settings read only the signed-in account's preferences, Parlay market enrichment runs in the worker, and Backup & Restore no longer waits on S3 from a Gunicorn request.
  • Value Finder applies bankroll, Kelly, probability, edge, and signal preferences as cheap overlays on the verified market projection instead of rebuilding all odds and report joins per user.
  • Dream Fight supplies canonical fighter suggestions and reports ambiguous, missing-profile, invalid-input, and pipeline errors distinctly instead of blaming every failure on the fighter database.
  • No prediction formula, probability, Elo model, simulation, calibration artifact, protected database byte, card byte, login, entitlement, subscription, billing behavior, AWS resource, schedule, or provider budget changes.

One card now has one report identity across every user surface

Production acceptance proved that UFC 330 could publish successfully while a date-bearing route created a second report identity. That split left Expert Picks without model rows, showed a false card-update warning, and made exact-fighter certification treat a version stamp as if every fighter changed.

  • Report-fighter certification compares the effective profile state and source revisions while retaining the full manifest hash for audit provenance; a code-version stamp alone no longer invalidates picks.
  • Report generation resolves display aliases to the committed card identity, and the event date is appended exactly once even when the incoming route already contains it.
  • Dashboard, Events, Reports, Expert Picks, Lock or Fade, and event reconciliation therefore converge on the same report artifact instead of selecting different same-card aliases.
  • Post-render verification has explicit, monotonic progress stages and a live heartbeat, so a fail-closed card/input check remains visible instead of appearing frozen at 98%.
  • Optional narrative bridge, per-fight, and publication jobs have workload-specific watchdog deadlines; a hung enrichment releases the durable worker lane and can retry without blocking the core report.
  • No prediction formula, probability, Elo model, simulation, calibration artifact, protected database byte, card byte, account entitlement, subscription, billing behavior, AWS resource, schedule, or provider budget changes.

Reports recover after deployment because every required job has an owner

Production acceptance found a healthy maintenance-worker heartbeat beside an hours-old queue: the service registered report-input certification code but its separate claim list omitted that job type. Reports awaiting certification therefore disappeared from discovery and Expert Picks lost its model column even though the sealed report still existed.

  • The worker runner now owns one exact registration-and-claim capability contract; an incomplete inherited service value cannot silently disable a supported job.
  • Report-input certification is independent from optional AI narratives, so report validity never depends on whether narrative enrichment is enabled.
  • The worker heartbeat publishes its enabled job kinds, and Admin System identifies an unsupported queued kind as a capability mismatch rather than generic contention.
  • The existing post-deploy worker restarts with certification enabled, drains the stranded UFC 330 jobs, and then republishes report discovery through the existing startup recovery lane.
  • No prediction formula, report mathematics, Elo model, simulation, calibration artifact, database byte, card byte, account entitlement, subscription, billing behavior, AWS resource, schedule, or scaling policy changes.

Member pages stop rebuilding history and partial provider replies stop erasing prices

Production acceptance found that Settings and Lock or Fade still performed global historical reconciliation, while Odds & Lines treated provider event shells as fresh pricing. Both ownership errors are removed.

  • Settings and Lock or Fade consume challenge outcomes already materialized by scheduled scoring; they no longer scan historical reports and predictions during a member request.
  • Named route-phase receipts identify preferences, member snapshot, account context, card projection, and template time if either page regresses again.
  • The odds worker publishes one durable rolling projection, keeping the newest complete h2h and totals group per fight/book across bounded recent snapshots.
  • Transient partial responses cannot blank healthy prices, fighter-side reversals and known aliases remain correctly oriented, and prices older than 24 hours are never resurrected.
  • Admin System reports actual h2h/totals coverage and marks event shells without usable markets as Watch instead of Ready.
  • Expert Picks continues in the background when the user refreshes or navigates away, and its status copy now says so accurately.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, AWS resource, account entitlement, subscription, or billing behavior changes.

Slow member actions become bounded and market/report truth survives process boundaries

Lock or Fade and Settings no longer multiply shared-database waits, while Expert Picks and Odds & Lines now consume durable report and current-market authority directly.

  • Lock with Model reuses the exact worker projection and saves the full card in one transaction; the page derives member stats from one challenge snapshot and receives its platform recap from the worker.
  • Settings reuses one bounded account snapshot for stats, sessions, watchlist, push, and onboarding state instead of serial database connections.
  • Expert Picks reads published model rows across worker/web restarts and still renders the canonical card when external expert sources are temporarily empty.
  • Odds & Lines merges current best prices into every canonical fight, admits live late-replacement markets before movement history exists, and labels true provider omissions explicitly.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, AWS resource, account entitlement, subscription, or billing behavior changes.

Fight-week recovery is durable from card truth through partial narratives

This release closes the production loops exposed by UFC 330: false report invalidation, duplicate provider ownership, misleading queue alarms, repeated historical maintenance failures, and multi-tab status polling.

  • Unrelated fighter-database updates no longer invalidate a current report. A durable worker certifies only the exact fighters sealed into that report; real fighter-input changes still fail closed.
  • The admin narrative action now uses restart-safe per-fight jobs exclusively. Every validated result publishes, so partial coverage appears honestly instead of falling back to 0/N.
  • Worker admission and queue claims share one deadline-aware policy, startup recovery is bounded, and queue health requires a live heartbeat instead of trusting a long recovery lease.
  • Numbered UFC reports keep their event identity when headliner wording changes, while event number, date, and matchup checks remain strict.
  • Current-event smoke ignores unrelated historical overrides, and unchanged invalid legacy artifacts no longer re-fail every deployment.
  • One browser tab polls report status for all open tabs, with sparse idle checks and real rate-limit backoff.
  • Card commits clear the display fallback and advance a durable cross-process generation, preventing a hard refresh from rebuilding the Dashboard from the prior card.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, account access, subscription, entitlement, or billing behavior changes.

Fight-week recovery becomes one durable, exact-event workflow

This release adds the long-term control plane behind card verification, report recovery, and optional narrative publication. It ships shadow-first so production can prove every proposed decision before autonomous actions are enabled.

  • One event-scoped controller now evaluates source quorum, card readiness, the sealed report, and optional per-fight narratives in a deterministic sequence.
  • Another week's card change cannot invalidate the current event; every transition is bound to an exact event date and immutable report revision.
  • Core reports remain independent of optional Claude prose. Narratives use bounded per-fight attempts, publish validated partial coverage, and stop safely after repeated publication failures.
  • Fresh reports seal the non-secret display context needed for later narrative-only publication, preventing an enrichment rebuild from silently removing odds.
  • Genuinely ambiguous source changes can be resolved with a typed, restart-safe replacement, cancellation, addition, reactivation, or active-bout decision instead of fragile evidence-text formatting.
  • The default shadow mode performs no autonomous writes or provider calls. Active mode requires a reviewed deployment setting and is not a browser toggle.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, account access, subscription, entitlement, or billing behavior changes.

Fight-week changes recover without erasing a healthy Dashboard

This release closes the remaining report-generation and hard-refresh seams found during UFC 330 acceptance. Verified content remains visible while background projections catch up, and optional AI prose now has a durable, bounded recovery owner.

  • A hard Dashboard refresh preserves the last verified card, View Report link, Monster Pack, and tracked record across safe report/pick updates instead of replacing everything with zeroes.
  • A real card-composition commit still fails closed; the availability fallback cannot hide a detected bout change.
  • Failed automatic report jobs receive bounded retries and expose their actual queue state instead of reusing an old failure as a false new enqueue.
  • Claude enrichment runs in the durable report worker, publishes validated partial coverage, and retries from the scheduler within a strict per-report budget; page views never spend credits.
  • Analysis-only narrative instructions now match the public safety validator, and durability rewrites remain tied to recorded finish-loss facts.
  • Usable scheduled CITO evidence immediately runs card convergence and the gated report decision instead of waiting for another refresh cycle.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, account access, subscription, entitlement, or billing behavior changes.

Current-card readiness stays usable while historical repairs remain honest

Live acceptance found a healthy UFC 330 card and report alongside one older June 27 prediction-ledger conflict. The operator views now distinguish those two facts, and the underlying maintenance paths are bounded and evidence-preserving.

  • Post re-scrape smoke reports current-card failures separately from whole-platform historical follow-up; an older event cannot look like current fight-week drift.
  • When conflicting scored rows have a verified result but no recoverable sealed customer-report pick, every row is preserved and quarantined from accuracy instead of guessing which pick users saw.
  • A single explicit owner prediction disposition can still arbitrate an orphaned historical group, and all other ambiguity remains fail-closed.
  • The bounded S3 ledger-union proof fetches retained snapshots concurrently, removing the serial scan that occupied the production maintenance worker for roughly 52 minutes.
  • Repair progress names the active ledger, restore, artifact-authority, settlement, and contract-proof stage instead of appearing stuck at a generic percentage.
  • The event prediction editor no longer mutates history on GET and validates report truth only for the requested event, eliminating the observed historical-audit 504.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, account access, subscription, entitlement, billing behavior, or automatic AWS rule changes.

Generated reports return immediately after a deployment

Production acceptance of r1104 proved the UFC 330 report itself was healthy, but its navigation remained in a refreshing state until a long historical-catalog job advanced. The restart boundary now publishes one strictly verified current report before any unrelated read-model work.

  • Every worker start receives a fresh durable discovery job; a successful receipt from the previous process cannot suppress it.
  • The newest sealed report is validated and exposed before Dashboard assembly or the complete historical archive pass.
  • Report publication proves its own targeted View Report row instead of synchronously rebuilding every historical artifact.
  • Multiple artifact aliases for one event/date appear as one report card; old direct links continue to work.
  • Operator repairs outrank background projections, and long read-model cycles yield safely between atomic stages with a durable continuation.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, account access, subscription, entitlement, billing behavior, or automatic AWS rule changes.

Reports get priority, and monitoring now distinguishes integrity failures from recovery watches

The live UFC 330 verification run showed why a correct report could still wait too long and leave System Health red: a read-only monitor could occupy the same execution lease as a customer report, one signal audit appeared three times under report aliases, and optional AI prose was treated like missing model output. Those responsibilities are now separated without weakening card, prediction-history, or publication integrity.

  • Queued customer reports take admission priority over periodic heavy scheduler work; an in-progress data transaction is never killed halfway through.
  • A report is not marked successfully published until its exact navigation catalog also exposes it; Dashboard, Events, and Reports keep View Report available while unrelated read models rebuild.
  • After a deployment or worker restart, sealed reports republish their navigation catalog before any long refresh, so existing reports return without another analysis.
  • Optional narrative-only refreshes no longer make a published report disappear from navigation.
  • Read-only contract monitoring no longer owns the report/mutation lease, and report aliases collapse to one semantic signal audit.
  • Zero-critical unused auxiliary evidence and optional AI prose recovery remain visible as non-blocking watches; genuine model-input, artifact, card, and history conflicts remain hard.
  • Transient AI-prose failures receive bounded recovery attempts while credentials, quota, identity, and re-analysis problems wait for operator action.
  • A dry-run-first AWS tool now establishes the real Cloudflare-only origin boundary with add-before-revoke verification and rollback; deployment itself makes no security-group mutation.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, account access, subscription, entitlement, or billing behavior changes.

Fight-week verification and report publishing no longer look stalled

The UFC 330 production run exposed three operational gaps after the replacement identity was corrected: a temporary cross-source record conflict could remain quarantined too long, report publication could run silently between progress updates, and the post-rescrape verification button could exceed the web proxy timeout. Those paths now recover and report progress without weakening any card, identity, or publication gate.

  • Current-card cross-source record conflicts receive a bounded recheck after one hour instead of inheriting the normal 30-day record freshness window.
  • Career-only profile failures name the exact missing or mismatched evidence receipt.
  • Report rendering, verification, artifact-lock wait, and transactional commit emit continuing worker heartbeats.
  • Post-rescrape and live-surface verification run through the durable maintenance worker and return a persisted receipt instead of occupying a customer-serving request.
  • Direct-origin 404 scans receive a tiny response, reducing traffic amplification while normal Cloudflare-served error pages remain unchanged.
  • No prediction formula, Elo model, simulation formula, calibration artifact, protected database byte, account access, subscription, entitlement, or billing behavior changes.

The UFC 330 replacement now carries verified identity provenance end to end

The previous release correctly stopped before simulations and exposed one final identity boundary: a name alias alone could not prove that Sherdog’s Eduardo Henrique record and the UFC/model history under Eduardo Chapolin belong to one athlete. The bridge now requires and records the matching Sherdog profile id, date of birth, division, and UFCStats identity before the profile enters analysis.

  • Eduardo Henrique and Eduardo Chapolin join only when the reviewed stable identifiers and demographics agree.
  • The UFC 330 Catchweight context retains trusted career and model-history receipts instead of falling through to a guessed debut profile.
  • Contradictory profile ids, dates of birth, or divisions remain rejected.
  • No prediction formula, Elo model, simulation formula, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Late replacement reports validate every fighter before simulations

UFC 330 exposed a second replacement-opponent failure after the corrected card was already visible: Eduardo Henrique resolved as a real fighter, but his model history lives under the established name Eduardo Chapolin. The report spent a full simulation pass before that profile handoff failed. The reviewed identity bridge now joins those two verified names, and the worker proves every model profile before running any simulations.

  • Charles Johnson vs Eduardo Henrique now uses Eduardo Chapolin’s existing UFC/model history while preserving the confirmed card name in the report.
  • A future fighter-profile problem stops before Monte Carlo work and names the exact fighter and failed evidence stage.
  • Read-only audits and report-artifact maintenance no longer block analysis as if the fight card were being refreshed; true card, fighter, history, ranking, and model-input maintenance still does.
  • No prediction formula, Elo model, simulation formula, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Reports now follow the current job and the correct fight card

A replaced bout could leave an older report safely preserved while a new report was being built. If that new job failed near completion, the status page could mistakenly inspect the preserved report first and claim the fight card changed during the new run. Report completion is now tied to the exact analysis job that produced it, current failures can no longer be hidden by an older artifact, and every report stays scoped to its own event instead of being invalidated by a change on another fight week.

  • Replacement-opponent reports no longer loop on a false “card changed while generating” result.
  • Completed reports must prove they belong to the current analysis job before the platform redirects members to them.
  • Tapology evidence now shows its required active/cancelled format and produces actionable parse feedback.
  • Readiness, worker diagnostics, interactive workload bounds, and signal-performance uncertainty displays received a full launch QA pass.
  • No prediction formula, Elo model, simulation formula, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Faster first loads, and a lighter changelog

Archived fight pages could take up to a minute to answer the very first visitor after a server restart, because the platform rebuilt its full prediction archive on demand; that archive is now prepared in the background before anyone asks for it. Signed-in members no longer wait on a brief refresh pause when returning to Fight Week HQ. This page also got lighter — the newest releases stay open and older ones tuck behind a single tap. Plus two fixes from our mobile review: the fighter comparison view now stacks properly on phones instead of clipping names, and filter buttons are easier to hit.

  • Archived fight pages answer promptly even on a cold server.
  • Fight Week HQ no longer pauses for returning members.
  • Mobile: comparison view stacks correctly, filter chips are full-size, and this page is much lighter.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Fight Week HQ gets fast, and archived fight pages return

Two follow-ups from the last release, both measured on the live site. Fight Week HQ was still doing heavy work on every visit — re-reading the entire odds and line-movement history per member, per page load, for data that is the same for everyone; it is now shared and cached, which removes the bulk of the remaining wait. And fight pages for past events, which briefly returned a “temporarily unavailable” response after the last release, serve normally again.

  • Fight Week HQ loads substantially faster for signed-in members.
  • Archived fight pages are reachable again for readers and search engines.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The last slow page, and a card-integrity fix

Fight Week HQ was the final member page still rebuilding its data on every visit; it now serves from prepared snapshots like the rest of the site, and it finally reports its own timings so slowness there can never hide again. The public fight pages got the same treatment. Separately, we found and fixed a real card-integrity defect: the automatic bout-cancellation check could be misled by a cached card from a DIFFERENT event, and with no limit on how much it could remove at once, it had quietly cancelled most of one upcoming card. Cancellations are now checked against the right event, require the official card listing to agree, and can never remove most of a card in one pass — that now raises an alert for review instead.

  • Fight Week HQ and public fight pages load from prepared snapshots instead of rebuilding per visit.
  • Automatic bout cancellations are event-scoped, officially corroborated, and bounded — a whole card can never vanish.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Configuration changes are safe again

A maintenance script that runs only during server configuration changes had carried an invisible formatting defect since it was written — and the very first configuration change in six weeks tripped it, briefly marking the environment unhealthy while the site itself kept serving normally. The script is repaired, and the build pipeline now refuses to package any script with that class of defect, so it cannot recur. No member-facing behavior changed.

  • Server configuration updates apply cleanly again.
  • A permanent build check prevents this entire defect class from shipping.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Fight week at full speed, on every device

A full mobile audit ahead of fight night found and fixed the platform’s slowest corners and its biggest phone-only bug. Fight Week HQ, Lock or Fade, the Parlay Builder, My Bets, and the ITD Scanner were all capable of stalling for 20 seconds or more while the page rebuilt heavyweight data mid-request — they now serve instantly from prepared snapshots, with fresh data assembled in the background the way the dashboard already works. On phones, the top navigation bar had silently stopped staying pinned — scroll down and the menu was gone; it stays put again on every page. Installed-app users also get a leaner update pipeline: the offline cache shed over 4MB of dead weight and now versions itself correctly, so updates arrive promptly instead of serving stale screens.

  • The five slowest member pages now load in about a second instead of stalling mid-request.
  • The mobile menu stays pinned while scrolling; rapid-tap picks no longer double-fire; parlay taps stop yanking the page.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Narrative checks now compare data, not deployments

Running the previous release live surfaced a subtle, long-standing flaw: the integrity check that guards fight narratives compared a fingerprint that included which software version produced it — so every platform update made perfectly unchanged fighter data look “drifted” and blocked narrative publication until the numbers themselves moved. The check now compares exactly what it always meant to compare: the fighter data behind the published pick. Real data changes still refuse publication exactly as before, and the refusal receipt now names precisely which data section moved.

  • Platform updates no longer interrupt AI narrative publication for unchanged picks.
  • Genuine data drift still blocks prose, now with a clearer explanation of what changed.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Fight narratives, fully unblocked

Running last release’s fight-week checklist live surfaced three deterministic blockers that kept AI fight narratives off the UFC 330 report no matter how many times analysis was re-run. All three are fixed at the root: a data-quality label that wrongly vetoed narratives for newer fighters even when the underlying inputs were byte-for-byte identical to the published pick’s, a rebuild step that could never publish freshly generated prose, and a writing prompt that omitted the exact finish-history facts our honesty checker grades against. The checker itself is untouched — narratives still publish only when every fact survives verification.

  • AI narratives can now complete for every fight on a card, including newer fighters with thinner records.
  • Freshly generated narratives reach the published report reliably; nothing publishes partially.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Ready for fight night, honestly

A fight-week hardening pass across five fronts. If the live scoring source ever goes dark mid-event again, the live panel now says so plainly within minutes — and reassures you that every pick still gets graded from official results afterward. The AI fight narratives fix a statistics-presentation defect: the writing model was being fed a number on the wrong scale, our honesty checker correctly refused the resulting prose, and the inputs now come from the exact same calculation the checker uses, so they can never disagree again. A phantom “missing data” flag that could cap a fighter’s profile confidence forever is eliminated at its root, and two long-standing internal watch items — a duplicate-entry conflict from June and a renamed bout misread as a replacement — are resolved with full receipts.

  • Live-event outages are named on screen instead of leaving fights “pending” in silence.
  • Fight narratives return with statistically verified numbers; the honesty gate is unchanged.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Completed events are settled history

Three refinements from the weekend’s record reconciliation. Prediction entries left behind when a fight was replaced before a report sealed are now recognized as superseded — named in the record’s own receipts rather than counted as fresh failures forever (nothing is deleted; the ledger keeps everything). A fighter name variant is unified so a pre-seal entry joins its sealed report correctly. And the “data refresh” warning no longer appears on reports for events that already happened: a sealed pre-event report is a historical document, and results arriving afterward are expected — the warning now reserves itself for upcoming cards where it genuinely means something.

  • The public record’s completeness check can now report fully accounted, with every exception named.
  • Graded reports stop warning members about “stale data” that is actually just the results themselves.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The dashboard gets its speed back

The new performance diagnostics pinpointed where dashboard time was going: a personal “Tail the Model” statistics computation ran from scratch on every page view, and the page deep-copied shared data it only needed to annotate. The statistics are now cached and refresh automatically whenever results are rescored, and the page copies only what it changes. Two smaller roots were also closed: the date-format defect that recently blocked results imports is fixed at the exact line that produced it, and the July 18 event — whose report was lost in a prior incident — is now fully acknowledged across both ways its absence can surface, so the record page reports clean without hiding anything new.

  • Dashboard loads substantially faster for signed-in members, especially those following the model.
  • Result imports can no longer be blocked by the date-truncation defect at its source.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The stuck results import is fixed at its root

The new import diagnostics named the exact record that had blocked completed results for three days: one row written during a live event carried its date in display format (“August 8, 2026”) where every other record uses the standard form, so it could never be matched or superseded. Dates are now normalized at the import boundary, a bounded receipted repair corrects any such rows already stored, failure diagnostics can no longer be truncated into uselessness, and administrators gain a read-only view that breaks down exactly where slow page time is spent.

  • Completed results can import even when a live-event record carried a non-standard date.
  • Unparseable dates are reported, never guessed.
  • No prediction formula, pick, simulation, calibration artifact, account access, subscription, entitlement, billing, or AWS configuration changes.

A faster, steadier FightEdge on every page

This release is a full platform-quality pass built from a measured audit of every member surface. The largest wins: a failed background data refresh can no longer leave the platform warning about fighter changes that were already rolled back — the condition that recently caused a report-access flap, a misleading red banner, and a silenced live-scoring night; background retries after a failure now slow down and eventually pause for review instead of consuming the server indefinitely; and the dashboard’s shared data view publishes reliably instead of getting stuck “warming.”

  • Odds & line-movement pages no longer re-verify their entire snapshot library on every view, and expert picks no longer rebuilds a large lookup it never needed — both families now respond in a fraction of the time.
  • Report pages stop shipping their stylesheet twice, cutting page weight by roughly a third and letting every past report load faster immediately.
  • Live panels reserve their space (no more layout jumps), background tabs stop polling, a leaked countdown timer was fixed, and the accuracy page header now always matches the rows beneath it.
  • Job-queue hygiene: stuck placeholder files can no longer crash the background worker or block real work, and operators can see exactly what the worker is doing.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

When a result row is rejected, the record now says which one and why

FightEdge refuses to accept a partial import of official fight results — if any row fails, the whole batch is rolled back rather than leaving the database half-updated. That safety rule is unchanged. What was missing was diagnosis: the internal record reported only a count of failures, with no indication of which bout was rejected or for what reason, which made a single bad row effectively impossible to investigate. Import records now carry a bounded sample of rejected rows with their event, bout, and exact reason.

  • Rejected rows are now identifiable, so a blocked results import can be diagnosed and fixed instead of retried blindly.
  • Purely diagnostic — no change to what is accepted, rejected, or rolled back.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

One upstream hiccup can no longer hold every result hostage

Completed fight results arrive through a published data mirror that FightEdge validates as a coherent whole before trusting any of it. That check tolerates a small number of inconsistent historical events, but it counted raw spreadsheet rows against a single flat limit — and one of those files stores a row for every fighter in every round, so the same three tolerated old events produced several times more rows there and failed the entire bundle. With the direct backup source simultaneously unavailable, that left recent results unable to load at all. The tolerance now scales with how many rows an event legitimately produces in each file, while the number of inconsistent events allowed stays exactly as strict as before.

  • Recent results ingest normally again even when a few unrelated historical events are inconsistent upstream.
  • Genuinely mixed or corrupted data still fails validation on the unchanged event-count guard.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Post-event scoring can no longer deadlock on a vanished live feed

When the live scoreboard feed is unavailable for an entire event, the platform correctly refuses to guess results in real time. But after the event ended, the recovery pipeline demanded that same live feed — which can never return for a finished card — before it would let the official-results ingestion run. The fix: once every outstanding fight belongs to a finished, past-date event, the pipeline yields with a named receipt and lets official completed results resolve everything. Same-day events keep the full safety latch, and scoring itself remains gated on the sealed report exactly as before.

  • Official results now flow in the morning after an event even if the live feed was down all night.
  • Nothing scores or notifies from this change — it only unblocks the official-results lanes.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Freshness judged by real cadence; a retitled card keeps its report

Two truth fixes. First, the System Freshness panel judged weekly-cadence sources on daily clocks: the source bundle (published upstream once a week) and completed results (which only exist after an event) showed "Stale" mid-week when nothing was wrong, and the sentiment threshold sat exactly on its own refresh interval, flapping between cycles. Thresholds now match each source's actual publication rhythm, while the fast probes that catch genuinely new data keep their fast clocks. Second, when a re-scrape updates an event's title after its report was sealed under the earlier name, the dashboard could lose its link to that report; the resolver now falls back to the unique same-date artifact, exactly as the serving pipeline already does — ambiguity still refuses.

  • Weekly sources stop reporting "Stale" on daily timers; genuinely overdue data still flags.
  • A card retitle no longer hides the sealed report from the dashboard tile.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The dashboard stops second-guessing a serving report

The dashboard's event tile ran its own extra verification pass on the current report and, under any momentary doubt — a background rebuild, a single-source card rumor — removed the View Report button entirely, even while the report itself served every visitor normally. On fight day that read as the report vanishing when nothing had happened to it. The tile now tells the same truth as the site: if a sealed report exists and serves, View Report and Re-Analyze stay visible; doubt states appear as a small badge ("Card updated · re-analysis recommended") instead of deleting buttons. Publication and verification gates are completely unchanged — this is presentation honesty only.

  • View Report never disappears while the report is live; card-change doubt becomes a visible badge with a recommended action.
  • Fight-week pick highlights still hide under unverified conditions — only the button behavior changed.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

A superseded render can no longer silence the current report

Re-analyzing a card leaves the previous sealed render on disk beside the new one — harmless by itself, and the old copy is always suppressed from serving. But the internal record-keeping lookup treated one non-current artifact as a reason to refuse the whole event, so the current report's scored results could not join the public accuracy record even while the report itself served customers normally. Currency is now judged per artifact: superseded copies stay suppressed and logged exactly as before, the current one proceeds, and the lookup only refuses when nothing current exists. The same judgment now breaks ties in yesterday's arbitration step.

  • Tonight's card joins the public accuracy record correctly after the fights — the superseded pre-replacement render no longer blocks it.
  • Every suppression is unchanged and still named in the logs; ambiguity between two current artifacts still refuses rather than guesses.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Tonight's card joins the public record correctly

The new verification diagnostic found the exact fault in one click: an early analysis had sealed a report under a generic title before tonight's card name resolved, leaving two same-date artifacts side by side. Faced with two candidates, every consumer refused to guess — correctly — so tonight's card was missing from public accuracy surfaces, fight pages, and the sitemap while the report itself served normally. The resolver now arbitrates by proof: when exactly one of the candidates passes the full verification chain, it wins; anything else still refuses. Separately, the artifact quarantine no longer treats a fight-count disagreement on otherwise seal-intact files as byte corruption — a rule that briefly sidelined a healthy, publicly-serving past card before it was restored the same hour.

  • When a stale duplicate artifact shadows a real one, the verified one now wins instead of both being refused.
  • Quarantine reserves file-moving for true byte corruption: unparseable data or sealed-hash mismatches.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The public record chain becomes fully observable

FightEdge's public accuracy surfaces only count a scored prediction after its published report is re-verified end to end — that strictness is the product. This release makes the verification chain itself observable: a new read-only diagnostic walks every resolution step for recent events and reports exactly where a join succeeds or refuses, so a card that fails to appear on the public record is a one-click diagnosis instead of an investigation. Alongside it: the repair job now attests honestly when the only outstanding items are the July 18 rows already acknowledged as unrecoverable (naming them every run, but no longer masking new failures behind a permanent red), the worker status panel shows which jobs the background worker is actually holding, and a fighter-name identity for an upcoming card was confirmed and pinned.

  • One-click, read-only diagnosis for any event missing from the public record — each verification layer reports its verdict verbatim.
  • Repair runs stop reporting failure for the already-acknowledged July 18 rows while still naming them in every receipt; anything new still fails loudly.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Dead-link fight pages answer instantly

Requests for fight pages that do not exist — mistyped links, outdated bookmarks, automated URL guessing — used to trigger the full published-report lookup, including artifact validation, before returning not-found. The first request for each distinct dead URL could hold a server worker for the better part of a minute, and overnight probe traffic was loud enough to distort platform health signals. A fast existence check now answers those misses immediately. Every real fight page resolves exactly as before — same lookup, same validation, same content — so search engines and AI crawlers exploring FightEdge spend their crawl budget on pages that exist instead of waiting on ones that never did.

  • Nonexistent fight URLs return not-found in microseconds instead of tens of seconds.
  • Pages for published reports are untouched — the fast path only accelerates misses, never changes a hit.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Line movement finally publishes — a two-line bug, months old

The new rebuild receipt caught it red-handed: the line-movement projection would complete nearly two minutes of real work walking months of collected odds snapshots, then crash constructing two page links — a step that only works during a live browser request, never in the background worker where the build actually runs. Every background attempt since the feature shipped died on that line, silently. Both projection builders are now safe to run anywhere: the links resolve to their fixed destinations outside a request, and background builds are treated as standard reads.

  • The line-movement and value-finder projections can now build in the background worker — the two-minute snapshot walk completes and publishes.
  • The failure that hid this for months is the exact class the new receipts were built to expose: found on the first instrumented run.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Line movement gets a direct rebuild path

The new odds diagnostics pinpointed why the Odds & Lines page sat empty despite months of collected line history: the pre-built projection that page renders from had never been published, and the background chain that should build it had two silent exits. Operators can now trigger that build directly and see its full receipt — either the projection publishes on the spot, lighting the page up with the accumulated history, or the receipt names exactly what blocked it. The diagnostics receipt also now reports the internal generation state that gated the build, closing the last place this could hide.

  • A one-click rebuild for the line-movement and value-finder projections, with the builder’s full receipt returned — success or a named reason, never silence.
  • Odds diagnostics now include the generation-token state that previously allowed a skipped build to report as success.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The odds pipeline can no longer fail silently — or serve stale lines

Investigating why the Odds & Lines page sat empty revealed two honesty gaps rather than one outage: odds-fetch failures were logged at a level nobody sees, and the report generator’s fallback would accept a saved odds snapshot of any age — meaning lines from days ago could quietly attach to a fresh report as if current. Both are closed: failures now surface as real warnings, snapshots older than 24 hours are refused with the refusal on record, and a new one-click diagnostics receipt reports the state of every layer — key configuration (never the key itself), live quota, snapshot freshness, and the line-movement data store — so this class of question gets answered in seconds, not hours.

  • Odds failures now announce themselves in the operational log instead of vanishing at debug level.
  • Report generation refuses odds snapshots older than 24 hours — stale lines can never masquerade as current market data.
  • A read-only diagnostics action reports key source, live quota, snapshot age, and line-movement store state in one receipt.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Pick and community pages never wait on outside websites

Right after a server restart, the pick, betting, and community pages could stall for half a minute while the fight-card data rebuilt itself from official upstream sources. Those pages now always serve the platform’s own stored card — the freshly verified version when it’s ready, the last locally saved version in the brief window after a restart — and the verified rebuild happens in the background where it belongs. Admin verification tools intentionally keep waiting for real upstream truth.

  • Expert Picks, betting, my-bets, and community pages serve instantly after a restart instead of stalling on upstream fetches.
  • Card accuracy is unchanged: the same verified rebuild still runs on schedule in the background; public pages simply stop paying for it in-request.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Faster pick pages, tougher restarts, and one healed record

Three fixes ahead of fight night. The Expert Picks and value pages no longer read multi-megabyte sealed-report files while you wait — they serve from a bounded recent cache and fail safely to “pick pending” on a cold start, ending the occasional two-minute page load during heavy background analysis. A background job interrupted by a server restart is now always recovered at boot — previously a technicality meant an interrupted job could be silently abandoned. And one completed bout that was recorded twice under two spellings of the same fighter — a scraper truncation already fixed at its source — now resolves to a single graded row.

  • Expert Picks, edge, and value surfaces respond immediately from cached model context; a cold cache shows an honest pending state instead of stalling the page.
  • Server restarts can no longer orphan an in-flight background job: anything the previous process left running is requeued at boot with a receipt naming what happened.
  • The duplicated July 25 bout resolves to one row, and repair receipts now name any conflicting duplicate they cannot resolve rather than reporting a bare count.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The accent-aware identity fix now reaches verification too

The previous release taught the results system to recognize event names that differ only by an accent mark — and its first live run revealed one more strict checkpoint that still compared spellings exactly: the final verification step that approves a sealed report before its graded picks can join the public record. That checkpoint now accepts an accent variant only when the sealed report’s own metadata proves both spellings are the same event, with every byte-level check unchanged. Repair receipts also now name each still-unpublished row and its exact reason, so nothing sits unexplained in an aggregate count again.

  • Sealed reports whose event name carries an accent now pass final verification for either spelling — completing the fix end to end, from lookup through verification to the public record.
  • Strictness preserved: the acceptance requires proof from the report’s own sealed metadata; different events, mismatched dates, and every byte-level integrity check reject exactly as before.
  • Repair receipts now list each still-blocked row with its specific reason, replacing bare counts with answers.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

An accent mark can no longer hide a completed event’s results

One completed card’s graded picks stayed off the public record for a subtle reason: the sealed report spelled the headliner with an accent mark (“Medić”) while the prediction ledger spelled it without one (“Medic”), and the strict identity match — correctly refusing to guess — treated them as different events. Identity comparison is now accent-aware: spellings that differ only by accents are recognized as the same event, while genuinely different events remain strictly separated. Alongside it, the backup-restoration lane can now complete when leftover partial files sit in the way — they are preserved untouched beside the restored report, never deleted.

  • Events whose names differ only by accent marks now match on every results, scoring, and history surface that uses the sealed-report identity check — no more invisible gaps from a spelling nuance.
  • Nothing loosened: the comparison still requires the same event name and date; only accent variants of the same name are unified, and every restored report passes the same byte-level verification before anything serves.
  • Backup restoration now handles leftover partial files by preserving them aside with a full audit trail, instead of stopping with nothing restored.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Completed results flow again, and a lost report returns

For weeks the platform reported a critical data gap: every fight-database refresh quietly failed at its final check and undid its own work, because one upstream results website stopped responding to our server — even though the same results were already arriving through our verified, checksum-proven data bundle. Refreshes now accept the verified bundle as the source of record when the live site is provably unreachable, under strict evidence recorded in receipts: the bundle must verify, the live check must have genuinely run and returned nothing at all, and any partial answer still fails the refresh. Separately, a completed event’s sealed report that vanished from the server — but survived intact in off-site backups — can now be reconstructed, only when every recovered file matches its original sealed receipts exactly.

  • The weeks-long “critical” data state is addressed at its proven root cause: verified results are no longer discarded because a separate website ignored our server.
  • Nothing is taken on faith: acceptance requires the checksum-verified bundle plus hard evidence the live source was truly dark, all preserved in receipts — a partial or suspicious answer still fails closed.
  • A sealed report lost from the server can return from off-site backups, verified byte-for-byte against its original sealed receipts before anything serves.
  • Operational alarms now distinguish “the background worker is busy on a long job” from “the worker is down”, so a healthy grind no longer suggests a restart.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Background work can no longer get stuck in line

Twice this week, queued background jobs sat idle for up to half an hour while the system reported itself healthy — each time a busy in-server refresh held the shared work slot and everything behind it waited. Three root-cause fixes end that: exempt maintenance work now claims through a held slot instead of waiting behind it, stale job locks left by a restart are swept at boot, and in-server refreshes carry a hard time budget so they stop cleanly between events and resume later instead of holding the slot indefinitely.

  • Maintenance jobs that were designed to run alongside heavy work can no longer be starved by whatever happens to be first in the queue.
  • A restart no longer leaves phantom job locks behind: they are provenance-stamped and swept on boot, so recovery is automatic instead of waiting out a 45-minute staleness window.
  • In-server report refreshes stop cleanly at a time budget with all remaining work preserved for the next pass — the site can no longer be held hostage by one long grind.
  • A damaged stored report can now be repaired from off-site backups — only when the recovered copy provably matches the original sealed receipt, with the damaged bytes preserved for audit and the same fail-closed verification before anything serves.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Missing fight results return, and long repairs get the time they need

Two completed events whose graded results disappeared from the public record — July 18 and July 25 — are restored: their sealed reports return from incident quarantine under a strict rule that nothing serves unless it verifies, and their existing Correct/Wrong verdicts rejoin the archive and accuracy pages. Separately, long-running maintenance now declares how much time it actually needs, so the safety watchdog stops legitimate catch-up work from being cancelled minutes before finishing.

  • The July 18 and July 25 cards return to the archive with their original graded picks — the same verdicts recorded on fight night, never regraded.
  • Restoration is fail-closed: a report that cannot be verified goes straight back to quarantine with its reasons on record; nothing unverified is ever shown.
  • Maintenance jobs carry realistic time budgets derived from their own estimates; the watchdog still terminates genuinely hung work, with the same receipts.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Your dashboard is always there the moment you open it

The "Dashboard data is refreshing" experience is gone. FightEdge now serves your last-known dashboard instantly — complete with your report, packs, and picks — with a small quiet note when a background refresh is running, instead of a banner over real content or an empty placeholder. A blank screen can now only appear in the first seconds of a fresh deployment, and it repairs itself in place without you refreshing.

  • Real content first, always: a saved dashboard up to hours old beats an empty placeholder, and background refreshes announce themselves with a small "Updating" chip instead of taking over the page.
  • The rare true loading state now repairs itself: the page quietly checks readiness and swaps the full dashboard in the moment it is ready — no manual refreshing, no reload loops.
  • Dashboard rebuilds can no longer be starved: they run first and every maintenance cache flush schedules its own rebuild automatically.
  • If background processing ever stalls, System Health raises an alarm within minutes instead of the site quietly degrading.
  • A report page that fails its publication check now retries once, shows the event name, and recovers itself the moment verification succeeds — no more dead-end error pages.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Operator evidence works no matter how a source spells a fighter

Fight sources spell athletes differently — the same strawweight is "Gigi" on one site and "Giovanna" on ours. Evidence review now resolves reviewed alias spellings exactly the way card verification already does, pasted source pages parse in their mobile shape and with accented names, and a set of silent maintenance receipts now name their real failure instead of reporting "completed".

  • An operator ruling on a bout now lands even when the evidence source spells a fighter differently — reviewed, event-scoped aliases only; unreviewed names still fail closed.
  • Pasted evidence pages parse in both desktop and mobile shapes, and names with accents no longer drop.
  • A failed maintenance batch now reports its actual error instead of "completed".
  • Internal observation counters were added to a small set of unused-looking pages so a future cleanup can prove what is and is not used — log-only, no behavior change.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Fighter evidence survives every deploy, and the dashboard stops stuttering on phones

A replication bookkeeping mismatch made every deployment silently swap the verified fighter-record store for a frozen week-old copy — the true source of the recurring "records changed after an update" cycle. Both deployment validators now recognize replication bookkeeping, nightly backups of the store flow again, and a failed validation can never destroy the only copy. Mobile scrolling gets its biggest cleanup yet, and the operator can now record a durable ruling for a committed bout that outside sources have not caught up on.

  • Deployments validate the live fighter-record store correctly, so verified records, heights, reaches, and cross-checks persist through every update — and its nightly off-site backup resumes.
  • If a store ever fails validation, the deploy keeps it in place until a validated replacement is actually in hand; recovery can no longer delete the last copy while restoring nothing.
  • Mobile scrolling is dramatically smoother: fixed bars stop re-blurring every frame, off-screen panels stop refreshing themselves mid-scroll, below-the-fold cards paint lazily, and the "warming" screen reloads at most once instead of four times.
  • The operator can record a documented ruling for a bout already on the card that outside sources have not yet confirmed — with a visible receipt and an expiry — so an adjudicated card stops pausing downloads and the weekly pack game.
  • A corrected fighter record now re-publishes the report even while card verification is pausing actionable content; the paused presentation itself is sealed in, so nothing actionable can slip through while numbers stop going stale.
  • Maintenance runs no longer fail on quiet days: "nothing is live to fetch right now" is reported as exactly that instead of failing every downstream repair, and every fighter-record quarantine now leaves a visible receipt.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, or billing changes; AWS changes are limited to the two declared persistence/backup configs.

Deploys can no longer un-verify your fight card

A software update briefly made the platform forget verified fighter identities and re-check an already-published report. This release ends that class: everything the platform learns — scraped fighter records, identity mappings, verification rulings — now provably survives every deployment, and the one legacy repair that rewrote identity data on each ship now runs exactly once with a receipt. Verified operator rulings also carry real authority now, so a bout you confirmed against the source of record stops pausing downloads while slower public sources catch up.

  • Fighter records, identity data, and verification state persist across every deployment; the recurring "re-scrape the same fighters after an update" chore is gone.
  • When the operator verifies a bout with documented evidence, that ruling satisfies the card check for that bout — with a visible receipt — while genuine cross-source disagreements still pause exactly as before.
  • The weekly Monster Pack game returns automatically as soon as card verification clears; a maintenance action can also restore it on demand.
  • Broken historical report files are found and retired automatically instead of failing checks forever in the background.
  • Analysis re-runs itself when a fighter's verified record materially changes after a report was published — the same gated pipeline, no manual step.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes beyond the declared persistence config.

Reports finish themselves, and warnings mean something again

This release closes the last mile after a report is generated and removes the manual button-chain around it. Finished AI fight narratives now attach to the published report automatically, the dashboard and reports library update the moment a report is ready, alias-only spelling differences between public card sources no longer pause downloads or actionable content, and a stuck background job recovers by itself instead of waiting for a restart. The System Health page now shows only warnings that are actually current, organized into labeled sections.

  • Completed AI narratives rebuild the published report automatically — no more reports stuck on fallback prose after generation finished; narrative statistics are phrased against the correct denominators so the honesty validator stops rejecting sound narratives.
  • The dashboard and reports library refresh themselves immediately after a report seals; while an index rebuilds, the library says "refreshing" instead of pretending no reports exist.
  • Two public sources spelling one verified athlete differently is no longer a "card conflict": comparisons run on reviewed identities, so downloads and actionable content stop pausing over spelling — while genuine card disagreements still pause exactly as before.
  • Scheduled card updates now promote verified changes and refresh the verification verdict automatically, and analysis re-runs itself when the card verifiably changed and every readiness gate is green — through the exact same gated pipeline as a manual run.
  • A background job that hangs now retires itself with a receipt so the queue keeps moving; previously only a restart cleared it.
  • Operational warnings that describe already-resolved conditions clear themselves or age out with receipts; the admin health page shows only active issues, grouped under clear section headers.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The verified real-world card can always be admitted

Fight cards change late: bouts get added days before an event, and a bout cancelled earlier can return. The operator evidence flow now covers both — a verified new bout can be added when independent sources and fighter records confirm it, and a returning bout's stale cancellation mark can be cleared with a receipt. Analysis and reports always describe the full card being sold on fight night.

  • Verified additions: a bout confirmed by operator-reviewed evidence, an independent second source, and resolved fighter records joins every card view in one reviewed step.
  • Returning bouts: a cancellation mark left over from before a bout's verified return is cleared with a receipt instead of silently hiding the fight.
  • Every change is previewed with its evidence before anything is applied; unverified bouts remain refused exactly as before.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

A fighter recorded under two spellings is one athlete again

When sources rename a fighter mid-camp, ingestion can leave two stored records for one athlete. The platform's reviewed identity bridge now proves when duplicate records are the same person — by curated stable identifiers and date of birth, never by name alone — and serves exactly one; anything unproven still fails closed. This removes the state that briefly blocked new report generation for the August 8 card.

  • Analysis no longer refuses a verified fighter because an ingest created a second record for the same reviewed athlete; unproven duplicates are still refused.
  • A new read-only operator audit names exactly which identities are bridge-collapsed and which remain genuinely conflicted, with record-level receipts.
  • The live fight panel passes through the canonical-pair check once more after every data join, so one reviewed bout can never render as two rows.
  • Operator maintenance actions now show their result receipts inline, and a background lane interrupted by a deploy is labeled honestly instead of appearing to run forever.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

The fixes proved live are now complete on every tier of every page

Post-deploy acceptance of the previous release measured three follow-up defects in production: the Fight Week page returned an error on its warming tier, the event-card page still rendered one reviewed bout twice, and the new marker-reconcile repair had no clickable button. Each is repaired exactly where production failed.

  • Fight Week renders correctly on every serving tier, including the brief warming state right after a deploy; every warming state is now render-verified against its page.
  • Lock or Fade pick-history views for past events render correctly again while fresh model context is being prepared — model chips simply wait instead of erroring.
  • The event card page and live tracker show the same single row for a reviewed bout as the rest of the platform — no more duplicate matchup rows on any surface.
  • The receipted marker-reconcile repair is one click in the admin panel, so falsely suppressed reports can be released the moment their evidence verifies.
  • Archived fight pages for dated events answer from a bounded single-event lookup on every topology; unknown pages still 404 fast.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Every page serves bounded worker-published truth, and reports stop going stale for false reasons

A full-surface production sweep measured two pages timing out entirely, a cluster of member surfaces taking 7–48 seconds cold, and every report suppressed by a poisoned modified-fighter marker whose every other evidence check matched exactly. The measured surfaces now serve durable worker-published projections, and the marker records only honest, dated, verifiable change.

  • Value Finder, Line Movement, Lock or Fade, Fight Week, Trust & Status, Prediction History, CLV Ledger, the Prediction Archive, and My Bets no longer assemble heavy aggregates inside customer requests.
  • Cold Rankings and fighter pages never recompute full-history Elo in a request; the worker keeps the snapshot warm.
  • Archive misses answer instantly from an index instead of rebuilding the corpus for a 404, and status polling backs off politely when rate-limited.
  • The modified-fighter marker can no longer be poisoned by a failed snapshot, preserves its certification receipts, and a receipted operator action clears only fully verified events — no suppression gate was weakened.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

One reviewed bout can no longer appear twice, and analysis waits for its prerequisites

Live r1057 acceptance showed the August 8 card rendering 11 rows for 10 reviewed bouts because two source spellings of one bout both survived identity projection, and two analysis submissions raced the post-deploy re-scrape into guaranteed preflight failures. Card authorities now coalesce canonical pairs after projection, and the analyze action checks a durable readiness receipt before queueing any model work.

  • Exact same-date canonical fight pairs are collapsed at the committed analysis card and the final event display, with metadata merged conservatively and every collapsed source spelling retained as auditable evidence.
  • Different dates, different opponents, contradictory divisions, and true replacement bouts never coalesce; strict identity and publication gates are unchanged.
  • Report analysis now refuses with an actionable state while card or profile maintenance is active, and names the exact unresolved fighters instead of queueing work that must fail.
  • Repeated analyze clicks produce one job or one deterministic refusal, never parallel duplicate analysis.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Reviewed fighter identities now remain consistent through report publication

Live r1056 acceptance found that card analysis could resolve a reviewed fighter name correctly while a later report-authority layer still compared the older source spelling. The durable committed-card projection and every report comparison now use the same exact-event identity context.

  • Analysis input, current-card authority, report membership, card order, metadata, and stale-report checks now share one reviewed identity.
  • Original source names and evidence receipts remain attached for auditability; no card file or fight database is rewritten.
  • Existing report artifacts can reconcile only when exact event date and opponent match a reviewed record.
  • The verified Wes/Wesley Schultz source difference is covered only for the August 22 bout opposite Jackson McVey.
  • Different dates, opponents, contradictory divisions, unresolved names, and ambiguous identities continue to fail closed.
  • No prediction formula, pick, simulation, calibration artifact, database byte, account access, subscription, entitlement, billing, or AWS configuration changes.

Personal Dashboard data no longer holds first paint, and reviewed fighter names reconcile correctly

Live r1055 acceptance isolated a slow account-context read and one false current-card mismatch. Personal widgets now hydrate through a bounded same-user snapshot, while exact reviewed event identities tolerate genuinely missing source metadata without weakening conflict checks.

  • The Dashboard waits no more than 350 ms for account context and renders an honest warming state if storage is contended.
  • Personal results are coalesced, cached only by user id, and never reused across members.
  • The reviewed José Luiz / José Montanha da Silva identity now reconciles for the exact August 8 bout even when the source omits division.
  • A wrong division, opponent, date, ambiguous identity, or unreviewed bare-name match still fails closed.
  • No prediction formula, pick, report content, database byte, account access, subscription, entitlement, price, Stripe behavior, or AWS configuration changes.

Frequently visited pages now stay on bounded, worker-published truth

Live r1054 acceptance exposed five remaining request-path leaks. Events, readiness, pricing, previews, and fight-database freshness now use bounded parsing or exact durable projections instead of report archives, global prediction history, deep System Health, or contended telemetry writes.

  • Events resolves report links from one exact worker-published catalog and does not reopen report groups per event row.
  • Mixed ISO and human-readable Greco dates are compared chronologically, eliminating recurring freshness parse failures.
  • Readiness receipts have a dedicated priority job, are primed when the worker starts, and no longer wait behind deep admin diagnostics.
  • Pricing reads Brier score from the durable public proof projection, while cold previews return an honest warming state.
  • Optional acquisition telemetry gives up within a sub-second lock budget instead of delaying a public page behind account writes.
  • No prediction formula, pick, calibration artifact, report truth, database byte, account access, subscription, entitlement, price, or Stripe behavior changes.

Background maintenance can no longer crowd customer requests off the host

FightEdge now gives every durable background lane one combined CPU budget and serves frequently visited surfaces from exact-generation projections. Customer requests no longer rebuild cards, deeply validate historical reports, create sitemaps, or assemble global archives while a member waits.

  • Scheduler, report analysis, repairs, and read-model work share one host-level CPU ceiling that preserves capacity for Gunicorn.
  • Dashboard polling, reports, previews, profiles, Ask the Model, prediction archives, sitemap, and System Health use bounded durable reads or an honest warming state.
  • Successful refresh jobs remain terminal instead of restarting every minute, and expired sessions stop protected polling immediately.
  • Admin repairs retain one root-cause ID across failed and dependency-skipped steps, publish exact terminal progress, and record scheduler exceptions durably.
  • Strict report, fighter-identity, current-card, and completed-result gates remain fail-closed; unresolved history is suppressed or quarantined rather than silently rewritten.
  • No prediction formula, pick, calibration artifact, packaged database byte, account, subscription, entitlement, or billing state changes.

Legacy report warmup can no longer starve signed-in pages

FightEdge now keeps its remaining report-history warmup out of the customer-serving web process whenever the durable production worker is installed. Valid oversized legacy reports can also be compacted through a bounded, receipt-backed maintenance action.

  • The production web server no longer opens report archives from an in-process startup thread.
  • Oversized valid result sidecars are migrated only by the durable worker under a strict per-run limit.
  • Every migration verifies the original receipt, reseals and validates the artifact, preserves reversible evidence, and rolls back on failure.
  • One-click contract recovery orders quarantine, compaction, and strict contract repair automatically.
  • No model formula, prediction, calibration, report-selection rule, database, account, subscription, entitlement, or billing state changes.

Repairs can write the correct runtime database without starving customer pages

FightEdge now recognizes its durable production fight database correctly across Elastic Beanstalk's package symlink, restoring the guarded completed-result and database-repair chain. Heavy repair and scheduler workers also retain a strict CPU ceiling so the web server keeps capacity for members.

  • The shared production database is writable only when its exact canonical runtime identity is proven.
  • Packaged database evidence and every noncanonical alias remain immutable and fail closed.
  • Far-future numbered UFC event shells no longer make an otherwise complete upcoming-card refresh fail.
  • Dashboard member state and System Health exports use bounded, durable read paths instead of serial live reconstruction.
  • No model formula, prediction, report, packaged database byte, account, subscription, entitlement, or billing state changes.

Signed-in pages no longer launch report and history rebuilds inside the web server

FightEdge now sends expensive Dashboard and prediction-history projection work to its durable maintenance worker. Members receive the latest verified snapshot, or an honest warming state, while the isolated worker rebuilds under one coalesced job and publishes only if card and prediction truth remain unchanged.

  • Authenticated Dashboard requests no longer start heavyweight Gunicorn daemon threads.
  • Cold prediction-history displays use the same worker boundary instead of rescanning reports in the web process.
  • Duplicate member requests coalesce by exact truth generation and retry safely after a failed publication.
  • The worker retains heartbeat, heavy-work lease, memory, CPU-niceness, and generation-change protections.
  • No model formula, pick, report, fight data, account, subscription, entitlement, or billing state changes.

Production deployment now recognizes Amazon Linux's split Nginx health-log layout

FightEdge now validates the complete staged Elastic Beanstalk Nginx tree before applying its privacy-safe access-log format. This resolves a deployment-only incompatibility where the platform placed its healthd sink in an included configuration file rather than the root Nginx file.

  • The main access log still excludes authentication query strings and referrers.
  • The one AWS healthd sink is located across the complete staged tree and retains valid hourly telemetry.
  • Both legacy single-file and current Amazon Linux split-file layouts are tested and idempotent.
  • An absent or duplicated healthd sink still stops deployment before any staged proxy file is written.
  • No fight data, report, prediction, model, account, subscription, entitlement, or AWS environment setting changes.

Customer reads stay fast while repair and publication truth remain fail-closed

FightEdge now separates bounded customer display reads from strict producer verification, invalidates shared read models across processes, and gives Admin/System repairs one prerequisite-aware execution path with durable progress and exact terminal receipts. Report, card, fighter-identity, and prediction-history integrity remain fail-closed without making ordinary page loads repeat producer work.

  • Dashboard, Events, reports, bets, account, and billing display paths use bounded last-known-good projections instead of synchronously rebuilding strict prediction history.
  • Report catalogs verify immutable metadata without reopening full report payloads, while current report proof and settled historical truth remain distinct.
  • Cross-process generation receipts invalidate dashboard, prediction, and sitemap read models after card, odds, or report truth changes.
  • Admin repairs enforce prerequisites, serialize conflicting result work, show live progress and ETA, and report success only after the requested postconditions pass.
  • Trusted fighter identity and Cito verification preserve source provenance and resolve special-character or event-scoped names without weakening ambiguity gates.
  • Nginx keeps AWS healthd observability for valid requests while dropping malformed-request log noise that previously obscured real production failures.

Completed cards and current-card drift now have one safe recovery path

Admin/System repair now preserves the exact reason for a failed or deferred source operation and runs result, card, database, Cito, and contract recovery in a deterministic order. A completed event without a published pre-fight report is recorded as history-only; FightEdge never invents retroactive model picks.

  • Official final results converge without stale real-time notifications or fabricated prediction rows.
  • The completed-result database lane can resume after durable final-result work has settled instead of remaining blocked for an entire event-day tail.
  • Three-source consensus can add a genuinely missing upcoming bout, including verified fighter-name variants, without mutating completed history.
  • Repair receipts retain capacity waits, validation failures, and post-repair health while bounded verification avoids a second multi-minute diagnostic scan.
  • Hard and soft contract warnings are listed independently so no active warning is hidden by a shared display cap.

Detected production issues now lead to visible, durable repairs

Admin/System repairs now run outside the browser request and retain their progress through navigation, refreshes, and ordinary network timeouts. FightEdge also verifies the resulting System Health state before calling a repair complete.

  • One Repair Detected Issues action builds a bounded plan from the current health findings and avoids duplicate work.
  • Repair phase, elapsed time, estimated remaining time, progress, exact failures, and post-repair health remain visible to the operator.
  • The maintenance worker is available without enabling report-analysis feature flags; report generation remains independently controlled.
  • Environment-only AWS updates now preserve the same shared databases, card state, reports, and worker lifecycle as application deployments.
  • Dashboard first paint no longer waits for the expensive live-card join, and no model, account, billing, or protected database content changes.

Fight-card refresh and report publication now recover from the production overlay state

FightEdge now recognizes Litestream's own SQLite bookkeeping without confusing it for foreign fighter data. The verified post-deploy repair chain can therefore migrate the isolated career-evidence overlay, quarantine proven broken historical artifacts, and restore report readiness instead of stopping before repair begins.

  • Every unrelated, source, or account table still fails closed; only Litestream's two exact housekeeping tables are accepted.
  • Older partial career-overlay schemas are upgraded additively and transactionally instead of remaining permanently unreadable.
  • Operator re-scrapes validate the immediate fight card only, rather than blocking on every future card and the full rankings roster.
  • A card-refresh job interrupted by deployment is safely re-queued after restart, while active report publication continues to block an unsafe application flip.
  • No prediction formula, model artifact, customer account, subscription, or protected fight database is changed.

Admin actions now stay secure and usable through long operating sessions

FightEdge now validates the complete admin control plane instead of only a subset of System-page controls. Long-lived admin tabs renew their security token before actions, and server failures are reported as failures instead of being mistaken for success.

  • The read-only preflight covers 121 distinct admin pages, buttons, forms, background-status helpers, and compatibility routes.
  • Members, Stripe re-sync, moderation, prediction maintenance, fighter validation, CITO, contacts, backups, and System jobs share one explicit contract inventory.
  • Expired admin security tokens are renewed automatically and JSON actions retry once only when the server explicitly identifies token expiry.
  • Backup and restore controls now display the real server outcome and never claim success because a timer elapsed.
  • No customer entitlement, subscription, prediction, fight database, or AWS configuration is changed by this release.

Current-card fighter evidence can recover safely without leaving report generation blocked

FightEdge now closes the gap between a successful maintenance refresh and the identity gate used to begin a report. When Sherdog cannot confidently resolve a fighter, one unique identity-checked ESPN professional record can complete the evidence chain without changing the protected fight database.

  • Ambiguous ESPN results, wrong identities, and implausible weight-class matches remain fail-closed.
  • The identity gate is recomputed immediately after a durable backfill, avoiding a second manual validation cycle.
  • A stale source-canary ingest pause clears only after the active database profile and deterministic canaries both pass; unrelated failure pauses remain active.
  • Diagnostic sidecars from refused analyses no longer masquerade as hard defects in a valid published report.
  • The r1043 report handoff and quota-aware CITO coverage behavior are included cumulatively.

Completed analyses now survive safe worker/web handoffs without weakening model integrity

FightEdge now distinguishes the model inputs that can change a pick from diagnostic source labels that cannot. A completed report is no longer withdrawn merely because isolated processes describe identical behavior with different provenance labels.

  • Rule bytes, calibration, Elo revision, engine and production modes remain fail-closed; a real change still blocks stale publication.
  • A genuine engine transition during analysis triggers one coherent re-analysis before any report-ready notification is sent.
  • If the engine remains unstable, publication stops before writing or announcing an artifact and identifies the changed behavioral fields.
  • A CITO event no-match remains non-verifying but is shown as an external coverage gap, never as a report-analysis blocker.
  • CITO no longer spends an additional rankings request after the active event could not be matched.

Production bottlenecks now fail bounded instead of multiplying across every request thread

Read-only production observation connected the July latency incidents to repeated SQLite writes and duplicate current-card rebuilds rather than insufficient CPU. FightEdge now keeps normal authenticated database opens read-only, collapses cold card work to one builder, and repairs the isolated career overlay before the application accepts a deployment.

  • Schema-ready account connections no longer renegotiate WAL or scan and commit every token table; genuine legacy sessions migrate only when their exact token is presented.
  • A busy current-card request serves bounded last-known-good truth instead of starting another filesystem and SQLite rebuild.
  • The deploy migration step backs up, migrates, and strictly validates only the career overlay; the protected model database is never passed to that migration.
  • Older valid Greco schemas preserve complete fighter history even when newer optional enrichment columns are absent.
  • Replication health uses Litestream 0.5 LTX JSON listings and fails closed on invalid or empty evidence.

Incident-recovery safeguards now prove the exact behavior they report

FightEdge's cumulative recovery work has been reconstructed from the last canonical Git baseline and independently reviewed. Runtime health checks now measure the final deterministic model result, request-path source calls stay inside their latency budget, and operational diagnostics survive worker changes.

  • Model canaries isolate live overlays and compare the final guarded probability, so changing expert or market data cannot create false drift.
  • ESPN request timeouts are capped by the remaining page budget instead of allowing a first call to stall the request.
  • Database replication reports healthy only when every live SQLite store is configured, and maintenance verification never falls back to root database access.
  • Diagnostic exports survive cross-worker polling and interrupted work becomes visible instead of spinning indefinitely.
  • Report quarantine refuses name collisions before moving any artifact, preserving both copies for operator review.

Every report is now tied to one verified, current fight-data revision

FightEdge now treats the weekly Greco source files, completed results, the derived fight database, and published report inputs as separate evidence stages. A partial download or failed rebuild can no longer make the model database look current.

  • All six Greco source files must download and pass schema, row-count, key-completeness, date, and cross-file checks before any active file is replaced.
  • Promotion is rollback-backed and produces a receipt with source revision, per-file hashes, sizes, row counts, and latest event date. The previously verified bundle remains available when validation fails.
  • Source-bundle freshness, completed-result freshness, and derived model-database freshness are tracked independently; one successful stage cannot hide another failed or overdue stage.
  • The model database is certified only after canonical result/stat ingestion, derived rates, exact sidecar verification, and health canaries all succeed. Retries rerun the derived stages even when source rows were already committed.
  • If a required source, derived, canary, or report-revision stage fails, FightEdge restores the exact pre-refresh database, verifies its SHA-256, and retries an incomplete rollback instead of leaving an uncertified partial update active.
  • A lightweight Tuesday/Wednesday revision probe starts a full refresh only when the exact upstream commit changes. Busy or failed changed revisions remain pending under retry backoff until the complete guarded refresh succeeds.
  • Only completed fights on or before the current date can affect fighter histories, aggregate rates, or Elo. Exact event, bout, and fighter identity joins prevent one matchup's evidence from being assigned to another.
  • Provider event IDs and canonical dates keep repeated generic event names and rematches distinct; ambiguous legacy rows are withheld rather than inheriting the wrong event date.
  • New Tale-of-the-Tape corrections and logical table revisions invalidate stale fighter-profile caches across workers, so a completed refresh becomes visible without restarting the site.
  • Published reports and modified-fighter reanalysis jobs now carry the exact model-database revision and must verify every current-card bout before completion. Missing, partial, changed, or unverified revisions remain non-actionable and require a verified re-analysis.
  • The verified Greco bundle is backed up as one immutable S3 generation. Conditional pointers cannot be rewound by concurrent instances, and restore selects the newest complete verified latest-or-dated generation. The atomic completed-result overlay preserves official results between upstream releases.
  • No pick was manually changed. No member account, subscription, billing entitlement, packaged database, protected database seed, calibration artifact, packaged Elo data, simulator artifact, or saved model changed.

Model evidence now controls confidence, every report surface, and narrative recovery

FightEdge corrected generalized data and confidence defects found while reviewing the August 1 report. Current fight receipts can improve model inputs without turning unavailable opponent statistics into perfect defense, and evidence limits now remain consistent everywhere a member sees or acts on a pick.

  • Per-fight Greco statistics and control time now join through canonical fighter-pair and event identity instead of list position or SQLite ingestion order, preventing one bout's evidence from being attached to another.
  • Elapsed-time-qualified canonical fight rows may refresh offensive rates, while missing opponent receipts preserve trusted roster defense instead of converting placeholder zeroes into flawless defensive statistics.
  • Win and loss method totals must exactly cover the corresponding canonical record. Present-but-incomplete zeroes are now reported as partial evidence rather than silently influencing winner and method probabilities.
  • Landed significant strikes per minute are treated as landed volume; striking accuracy is no longer multiplied into that decision-volume signal a second time.
  • Legacy or otherwise unproven calibration can damp confidence but cannot inflate it. A positive lift now requires an immutable pre-fight receipt and a qualifying chronological holdout.
  • A weak model lean that conflicts with a strong market becomes NO EDGE without silently flipping the selected fighter to the market favorite. A blocked fighter with no canonical, profile, or Elo history is also always non-actionable.
  • The latest prediction-bound card-integrity gate now governs direct and downloaded reports, Card Sheet/API/CSV, event triage, Dashboard/preview, Ask Model, public/social/share cards, caches, parlay pieces, and Monster combinations from the same evidence state.
  • Claude narrative recovery now explains provider, configuration, validation, and stale-input failures, records durable retry outcomes, and refuses to attach prose generated from changed fighter inputs or a source label without exact Claude provenance.
  • No pick was manually changed. No member account, subscription, billing entitlement, AWS service definition, packaged database, or protected database seed changed.

Fight order stays official, Dashboard work leaves the request path, and every prediction carries an input receipt

FightEdge corrected the source-order defect that mislabeled Jan Błachowicz vs. Navajo Stirling, removed expensive report validation from signed-in Dashboard requests, and made the final data behind each fight auditable.

  • Accent and spelling variants no longer remove an official UFC row and append it as a preliminary bout; retained UFC order and section metadata remain authoritative.
  • Main and co-main labels now follow explicit card metadata, including legacy artifacts with partial numeric ordering, instead of depending on template loop position.
  • The Dashboard serves a versioned last-known-good projection while expensive card/report verification runs in a coalesced background producer; card and report mutations invalidate stale projections across application processes.
  • Every analyzed fighter now carries a sealed receipt for final feature values, identity, career-history coverage and freshness, Elo history, production engine, and the exact accepted calibration artifact.
  • Missing, stale, or conflicting inputs remain visible but force analysis-only treatment. Low-evidence or cached narratives cannot present those fights as LOCK, STRONG, SOLID, high-clarity, value, or wagering recommendations.
  • No pick was manually changed to match market odds. No member account, subscription, billing entitlement, AWS service definition, or protected database seed changed.

Verified replacement-fighter evidence now reaches report analysis end to end

FightEdge corrected the remaining production handoff that recognized Borislav Nikolić successfully but then tried to find his trusted career-source URL inside the packaged fighter roster.

  • Provenance-gated career-overlay identities now enter the same evidence-aware profile path as verified career-only records instead of being mistaken for roster identities.
  • The exact accent-normalized Borislav identity, 16–2 professional record, and 14-fight report handoff are covered through profile construction, report analysis, and committed-card pinning.
  • Unknown, ambiguous, conflicted, quarantined, or missing roster identities remain blocked before publication; this correction does not turn unverified fighters into predictions.
  • No prediction formula, probability, selected winner, account, subscription, billing entitlement, AWS service definition, or protected database seed changed.

Newly verified replacement fighters can reach the model without weakening publication truth

FightEdge corrected the production handoff that rejected the Medić–Rodriguez report after all 14 fights had finished analysis. Trusted career evidence and strict model identity were reading two different stores.

  • The strict resolver now recognizes provenance-gated, deployment-persistent career evidence for a late replacement while corrupt, conflicted, or quarantined records remain blocked.
  • Every committed-card fighter is resolved before simulations begin, so an actionable identity failure no longer appears only after a full-card analysis.
  • Card refreshes preserve and commit structurally valid staged rows when one upstream source is incomplete, while freshness remains visibly failed until the source recovers.
  • Report analysis, card refreshes, and heavy scheduler maintenance now share an operating-system lease across their separate services instead of relying only on process-local locks.
  • Archive contract monitoring stays out of the first 15 minutes after deployment, leaving capacity for health checks, member traffic, and operator acceptance.
  • No prediction formula, probability, account, subscription, billing entitlement, AWS service definition, or protected database seed changed.

Report navigation is bounded and completed analysis keeps the card identity that launched it

FightEdge corrected two production defects found after the v3.15.777 deployment: archive-wide validation on ordinary report navigation and a name-normalization mismatch that could make a newly generated report reject itself.

  • Dashboard and Reports now share one bounded catalog instead of reopening the complete report archive on each cold request.
  • Current and future reports remain strictly checked against committed card truth, and opening any report still validates its sealed publication group before content is served.
  • Canonical profile names remain available to the model while the report, tracker, expert picks, metadata, and manifest preserve the exact fighter names and order from the committed card.
  • Unverified identity or ordered-card drift fails closed before publication; no model probability or selected winner is changed by the binding step.
  • No account, subscription, billing entitlement, AWS hook, scheduler cadence, or protected database seed changed.

Report evidence and display projection now share a verified authority boundary

FightEdge extended the Events structural checkpoint through career-evidence validation and sealed report-group projection before continuing the broader remediation.

  • Career-evidence freshness and bounded failure detail now run from the focused report-access module while preserving deferred imports and worker retry seams.
  • Reusable report rows, publication signatures, and display metadata continue deriving pick-bearing fields from sealed published predictions.
  • Exact helper behavior, facade identity, publication authority, route topology, and response hooks remain contractually unchanged.
  • No card scrape, prediction formula, report pick, account, billing entitlement, scheduler cadence, AWS configuration, or protected database seed changed.
  • This build is an untagged local-QA checkpoint until the exact packaged application passes acceptance.

Narrative internals are now isolated behind verified module boundaries

FightEdge extended the Events structural checkpoint through the full-card narrative and enrichment support boundaries before continuing the broader remediation.

  • Full-card narrative generation now runs from the focused Events narrative module while retaining the established Events facade.
  • Canonical fighter-pair merging, safe enrichment markers, and simulation-aware narrative re-patching now share that focused boundary.
  • Exact helper behavior, alias reconciliation, monkeypatch seams, route topology, and response hooks remain contractually unchanged.
  • No card scrape, prediction formula, report pick, account, billing entitlement, scheduler cadence, AWS configuration, or protected database seed changed.
  • This build is an untagged local-QA checkpoint until the exact packaged application passes acceptance.

Events internals are smaller and more testable without changing member behavior

FightEdge checkpointed the cumulative Events refactor on top of the corrective v3.15.774 recovery candidate so the packaged application can be tested as one coherent build.

  • Shared Events state now has one authority instead of being distributed through the route module.
  • Identity, card-truth, dashboard, report-access, analysis-status, and narrative-policy helpers now live behind focused module boundaries.
  • The public route map, response-hook topology, route facade, and mutable-state identities remain contractually unchanged.
  • No card scrape, data migration, model formula, report pick, account, billing entitlement, scheduler cadence, AWS configuration, or protected database seed changed.
  • This build is an untagged local-QA checkpoint until packaged-app acceptance is complete.

Card refreshes now remain attached to persistent storage

FightEdge replaced the failed v3.15.773 deployment candidate with a safer correction built directly from the restored v3.15.772 production baseline.

  • Atomic card updates now replace the shared target instead of replacing and detaching its application symlink.
  • Before the application handoff, a newer detached card can be recovered only after validation and strong recency evidence.
  • The existing shared card and metadata receive a timestamped backup before any recovery write.
  • Stale or absent legacy metadata can be repaired independently when the card itself agrees.
  • Recovery uncertainty produces an operator receipt and warning, never a failed deployment or degraded AWS health by itself.
  • No scrape runs during deployment, and no prediction formula, report pick, account, subscription, result history, or database seed changed.

Events gained cold-start safeguards and stricter acceptance

This release added local-first event rendering, validated recovery points, and a zero-card acceptance check. Production then exposed the legacy shared-link defect corrected above.

  • The Events page now renders first from committed card data already stored with FightEdge; an external card overlay no longer controls first paint.
  • A read-only release fallback covers the brief moment when a new instance is still reconnecting its shared card snapshot.
  • A valid live snapshot always wins, so the fallback cannot replace a deliberately updated or cleared production card.
  • Each successful card refresh now mirrors its validated rows and matching metadata to current and dated off-instance restore points.
  • A real loading failure is shown as retryable unavailability and recorded by monitoring instead of masquerading as “No upcoming events.”
  • The post-deploy acceptance check now fails if Events returns a successful page with zero rendered cards.
  • No prediction formula, model output, member account, subscription entitlement, or database seed changed.

Verified reports no longer depend on optional AI prose

FightEdge tightened the full-card analysis handoff after production exposed a fighter-evidence refresh race and an exhausted narrative-provider quota.

  • The analysis worker checks trusted fighter-career evidence immediately after simulations and automatically retries once if relevant evidence changed mid-run.
  • The existing fail-closed integrity gate remains intact, so mixed-input predictions are never published as a valid report.
  • Verified model predictions publish before optional AI narratives; a Claude quota, billing, or authentication issue can no longer hold the core report hostage.
  • A provider-wide narrative failure stops after its first confirmed terminal response instead of repeating the same failed request across the entire card.
  • Administrator diagnostics now preserve the real failed stage and timeline instead of presenting an incomplete job as complete.
  • No model formula, prediction receipt, member account, subscription, database seed, scheduler cadence, or AWS configuration changed.

Verified reports now survive routine deployments

FightEdge corrected a legacy cache policy that removed modern report-verification evidence during every AWS deployment.

  • Unchanged published reports now retain their HTML, results, metadata, input manifest, and audit receipts across deployments.
  • Routine cache refreshes remove only interrupted runtime markers and in-memory state; they no longer delete published report evidence.
  • Dashboard, Events, and event cards show Report Ready only after the complete publication group validates against the current card.
  • Real card or model changes still use the explicit administrator Re-Analyze action before new picks are published.
  • No model formula, prediction receipt, member account, subscription, database seed, or scheduler cadence changed.

Current-card and report-repair safeguards were tightened

FightEdge corrected two issues found while production-accepting the previous cumulative release, before continuing the structural-remediation roadmap.

  • A partial cached ESPN card can no longer hide valid matchups from the current multi-source card.
  • A genuine replacement matchup still supersedes the prior pairing.
  • Legacy report receipt reconciliation now defaults to a read-only audit and requires a separate explicit apply decision.
  • Report-repair audits run only as explicit offline maintenance commands, never inside a member or administrator web request.
  • No model formula, prediction receipt, member account, subscription, database seed, scheduler cadence, or AWS configuration changed.

Historical packaging code is now a compact, verifiable record

FightEdge removed 88 obsolete per-release packaging programs after preserving their exact Git provenance and release identities in one read-only catalog.

  • The current source tree now has one executable package builder instead of a new builder for every revision.
  • Every retired builder and its historical test evidence remains recoverable byte-for-byte from the recorded Git commit and SHA-256.
  • Implementation-only tests for deleted builders no longer consume CI time; the active builder retains reproducibility, tamper, protected-boundary, database, package-safety, and executable-mode coverage.
  • The full test-fidelity job now runs every remaining in-repository test without omitting an external-artifact category.
  • No customer-facing behavior, predictions, reports, accounts, subscriptions, production data, schedulers, or AWS infrastructure changed.

Deployment packages now come directly from one reviewed Git commit

FightEdge now assembles the complete AWS deployment from a single tagged source tree and declarative release receipt instead of layering changes onto an older ZIP.

  • Every packaged path, byte, and executable mode must exactly match the reviewed Git commit.
  • Protected model, report, account, billing, database, and AWS boundaries remain frozen unless one release explicitly authorizes an exact change.
  • Deployment approval can require the intended release tag to resolve to the exact packaged commit.
  • CI forbids new per-release builder scripts, stopping the packaging system from growing another revision-specific implementation.
  • Historical builder compatibility was retained temporarily for a separately reviewed cleanup.
  • No customer-facing behavior, predictions, reports, accounts, subscriptions, production data, schedulers, or AWS infrastructure changed.

Every in-repository test now has an executable CI path

FightEdge now exercises the complete test inventory under isolated runtime data and verifies the same published-pick receipt through both report renderers.

  • The full suite is collected automatically, so a newly added test cannot silently fall outside every CI list.
  • All 48 previously uncovered domain suites—including fighter identity, report rendering, simulation, caching, and end-to-end coverage—also remain in the focused deploy gate.
  • Production Flask/Jinja reports and the command-line fallback must publish identical fighter names, predicted side, and exact probabilities.
  • Historical contract debt is recorded node by node as strict expected failure; a repaired or newly broken outcome stops CI for review.
  • Tests run against copied databases with startup workers and network access disabled, preserving the packaged fight-data seeds.
  • No model formulas, predictions, reports, member accounts, billing behavior, production data, or AWS infrastructure changed.

Heavy report evidence no longer blocks ordinary pages

FightEdge now keeps large optional simulation samples out of customer report sidecars and makes cache lookups independent of report or database scans.

  • New report result sidecars are capped below 8 MiB; optional Monte Carlo sample evidence is stored separately for explicit offline use.
  • A dry-run-first operator migration can slim legacy reports, reseal their receipts, verify the publication group, and reverse the change when necessary.
  • All 41 cache-key functions are continuously checked to remain free of file, report, and database I/O.
  • Admin/System and deployment telemetry now show whether host swap is active instead of silently accepting a zero-swap instance.
  • Published fighter order, picks, probabilities, model formulas, member accounts, subscription behavior, and production data are unchanged.

An unresolved fighter name can no longer become a model pick

FightEdge now verifies one unique fighter identity before building an analysis profile, so a spelling mismatch cannot silently look like a debutant with no history.

  • Exact names, verified aliases, accents, and suffix variations carry an explicit canonical fighter receipt into analysis.
  • Same-name roster records stay bound to the exact verified fighter id instead of whichever database row appears first.
  • Unresolved or ambiguous upcoming-card names stop that bout with an actionable validation error before a profile, feature vector, or prediction is built.
  • A debut signal now requires both a verified identity and a genuinely small recorded sample.
  • The same protection covers full-card reports, single-fight and what-if tools, expert-pick model refreshes, command-line picks, and runtime canaries.
  • No model weights, prediction formulas, member accounts, billing records, fight databases, or deployment infrastructure changed.

Release guardrails now stay intact across future refactors

FightEdge now builds release payloads from one clean Git commit and keeps model, report, account, and billing protections permanent unless a reviewed release explicitly authorizes a narrow exception.

  • One canonical registry protects prediction, report-publication, authentication, account, and billing boundaries.
  • Release exceptions expire automatically instead of weakening every builder that follows.
  • Deterministic packaging proves the exact source commit, release delta, database hashes, runtime-data exclusions, and deployment-hook modes.
  • This foundation changes no customer-facing behavior, predictions, subscriptions, reports, or production data.

Fighter histories now reconcile across accents, aliases, and corrected results

FightEdge now carries one verified fighter identity through source matching, profile construction, Elo, and report confidence so a spelling variation cannot silently fragment evidence.

  • Accents, punctuation, known transliterations, and unique middle-name variations reconcile without rewriting the fight database.
  • Ambiguous identities fail closed instead of borrowing the first similar fighter's profile or Elo rating.
  • Dynamic Elo uses complete corrected result history, preserves same-day rematches, observes no contests without rating them, and invalidates after same-count result corrections.
  • Greco evidence is ordered newest-first, and every model profile carries a source/recency receipt that exposes coverage gaps.
  • Unverified identities or missing history are labeled LIMITED DATA and cannot become qualified model edges or locks.

Fight reports now preserve complete analysis while incomplete data fails closed

FightEdge now separates a model's raw directional read from an actionable edge, restores hidden evidence on close fights, and makes AI-narrative coverage explicit.

  • Cards with missing venue metadata no longer inherit a false 7,350-foot altitude signal.
  • NO EDGE and LIMITED DATA fights keep their visible model lean and full descriptive evidence while fair-price, sizing, and recommendation language stays suppressed.
  • Complete Claude narratives render on every decision state; each fight and full-card report identifies Claude coverage versus a rule-based fallback.
  • Thin UFC profiles without a cross-verified broader professional record cannot be promoted to a qualified model edge.
  • Sportsbook disagreement remains a visible risk signal, not an instruction to rewrite the model toward a favorite.

Successful trial renewals now unlock Pro automatically across Stripe propagation timing

When Stripe has captured the renewal payment but its invoice and subscription period snapshots arrive a few moments apart, FightEdge now reconciles the two exact provider receipts without requiring administrator Re-Sync.

  • Access still requires the exact latest paid invoice, active subscription, configured FightEdge price, matching customer and subscription, and a refund-safe payment receipt.
  • The live subscription period is accepted only for a paid recurring-cycle invoice whose payment timestamp aligns with that newly advanced billing window.
  • Unfinished provider propagation remains retryable through Stripe instead of being reported as critical billing corruption.
  • Manual invoices, mismatched or older invoices, failed payments, refunds, canceled subscriptions, and unconfigured products cannot use this reconciliation path.
  • Existing Pro members, trials, cancellation controls, and administrator billing controls remain intact.

Completed full-card analyses now carry their verification receipt through the production renderer

FightEdge now embeds the same exact fighter-side receipt whether a report is rendered by the production Jinja template or the standalone fallback renderer.

  • The production renderer no longer forces validation to scrape display copy, surnames, or rounded percentages to recover a pick.
  • The full 14-fight Medić–Rodriguez card now publishes and reloads as one verified HTML/results artifact group through the real Flask report path.
  • Missing or ambiguous picks still fail closed; the fix does not infer a winner from probability order, odds, or eventual results.
  • Future publication failures identify the affected matchup in server diagnostics, shortening recovery without exposing account or billing data.
  • Model formulas, picks, accounts, subscriptions, protected databases, scheduler behavior, and AWS infrastructure are unchanged.

A verified full-card analysis can publish through harmless fighter display-name updates

FightEdge now records the exact matchup side behind every report pick, so an expanded or accented fighter display name cannot make a valid 14-fight report look like the card changed.

  • Every new report includes an explicit side receipt in addition to the visible fighter name and complementary probabilities.
  • An older pick label may be reconciled only when it maps to exactly one fighter in the matchup; missing or ambiguous picks still fail closed.
  • Publication and manifest failures are now reported as publication failures unless card membership, fight count, order, or known metadata actually changed.
  • Unused raw simulation samples are always removed from new report sidecars, even if an obsolete production environment override is still present.
  • The r1009 recent-history recovery remains intact; accounts, subscriptions, model formulas, official results, protected databases, and AWS infrastructure are unchanged.

Recent fight history stays visible, and an invalid report can no longer finish as successful

FightEdge now keeps settled cards available through their frozen pre-fight receipts when a report artifact is quarantined, while new report jobs must prove that every published surface agrees before they can complete.

  • Settled fight history can recover from validated pre-fight snapshots without inferring a pick from the eventual winner or replaying old notifications.
  • Current reports carry an exact machine-readable prediction receipt; older whole-percent reports are checked against the same rounding contract used to render them.
  • A job with zero complete fights, a missing explicit pick, or a mismatched artifact group fails before it can replace the last verified report.
  • Report-ready notifications and prediction logging happen only after the customer-facing report validator accepts the completed artifact group.
  • New sidecars omit unused raw simulation sample arrays, substantially reducing report storage, parsing work, and cold-read memory.
  • The skipped r1008 card-refresh progress improvements are included cumulatively; member accounts, subscriptions, protected databases, existing results, and model formulas are unchanged.

Upcoming-card re-scrapes now show real progress and recover cleanly after worker restarts

FightEdge now distinguishes the scheduled data pipeline from the isolated card-refresh worker and gives operators a durable, continuously updating receipt from queue to completion.

  • Elapsed time now counts correctly from UTC worker timestamps instead of becoming stuck at zero.
  • The status receipt shows the current phase, cards checked, progress, approximate remaining time, and worker-heartbeat health.
  • The re-scrape control stays locked while the job is active, preventing accidental duplicate submissions.
  • Reloading Admin/System restores the active receipt and resumes polling through a terminal success or failure result.
  • A confirmed maintenance-worker restart immediately requeues its own orphaned jobs instead of leaving them behind a 45-minute lease.
  • Staged card publication, last-known-good rollback, model picks, reports, scoring, accounts, subscriptions, and protected databases are unchanged.

Public traffic can no longer turn a cache lookup into a full report scan

FightEdge now keeps expensive report and current-card reconciliation outside the anonymous landing request, so a cold cache cannot make the public site appear offline.

  • The landing cache key is constant-time and never reads or fingerprints report artifacts before checking for a warm response.
  • Cold public requests render immediately while exactly one background refresh rebuilds current-card, proof, accuracy, and member-count context.
  • During refresh, prior verified proof may remain visible, but a potentially stale upcoming card is withheld until the new card context is ready.
  • Large report-authority files contribute at most three 64 KiB probes to request-time mutation detection instead of being read in full.
  • Three remaining legacy deployment repairs are disabled by default and can run only through explicit, locked, hard-time-bounded operator controls.
  • Model picks, report contents, scoring, accounts, subscriptions, member data, and protected UFC databases are unchanged.

One invalid report artifact can no longer make the whole platform appear offline

FightEdge now validates a changed report once, remembers both approvals and safe rejections, and protects the web request pool while preserving the same strict report-truth requirements.

  • Large results files use a bounded mutation fingerprint before cache lookup instead of being read and hashed in full on every page request.
  • Receipt mismatches, visible-report disagreements, missing metadata, and other rejected states remain fail-closed but are reused until the exact artifact changes.
  • Simultaneous cold requests collapse behind one validator; excess requests return a fast unavailable state instead of occupying every web thread.
  • Current-card approval is bound to the exact committed-card, career-evidence, and report-artifact revision, so a real card or publication change still invalidates immediately.
  • Deployment no longer launches legacy report/data repair against the live web process by default. An operator may run the repair explicitly under a single-flight lock and hard per-step limits.
  • Model picks, report contents, scoring, accounts, subscriptions, member data, and protected UFC databases are unchanged.

Fight-week background work is now bounded, observable, and less likely to slow the member experience

FightEdge now limits duplicate event-day recovery and market-history work, reduces oversized report read pressure, and exposes better operational health signals without changing model picks or published report content.

  • Closing-line captures and publication recovery retries now use bounded timing and clear operator receipts instead of repeatedly re-running on every event-day tick.
  • Line-movement processing is single-flight and releases stale cache copies, while the member-facing market tools keep their existing output.
  • Large report sidecars no longer retain unused simulation samples in ordinary display reads; narrative updates still preserve complete receipt-safe artifacts.
  • Accuracy History, CLV, and Miss Autopsies reuse short-lived verified contexts and avoid repeating failed official-title lookups.
  • Background workers now expose memory headroom and use soft service-level containment, with durable diagnostics for future incident review.
  • The emergency swap, allocator, and live-event safeguards remain intact. Predictions, scoring, accounts, billing, member content, and protected UFC data are unchanged.

Future-card analysis now fails closed when career or fight-detail evidence is ambiguous

FightEdge now keeps professional career scope, source identity, fighter-side fight detail, and displayed conviction aligned so incomplete evidence cannot masquerade as a high-confidence betting edge.

  • Professional and amateur career records are separated, source identity is checked, and legacy/unverified totals are excluded from model features until refreshed.
  • Current-card refreshes include established fighters, archive prior evidence, preserve good data when a refresh fails, and never delete Greco/core fight history.
  • Fight-detail rows use fight-and-fighter identity so reciprocal fighter evidence is not collapsed into one arbitrary row.
  • Calibration uplift is bounded, market hard-overrides remain limited-data leans, and LOCK language now requires strong raw model evidence plus strong data quality.
  • Coin-flip and incomplete-data matchups are presented as No Edge or Limited Data while retaining a secondary canonical scoring lean.
  • Current and future reports carry an exact career-evidence receipt; stale evidence cannot re-enter through live tracking, Fight Week, previews, parlays, cards, or raw sidecar fallbacks.
  • Career evidence is isolated in a validated, backed-up overlay. Packaged UFC/Greco databases remain byte-identical, while two existing persistence configurations safely carry the overlay across deployments.

Eligible members keep the trial, while repeat subscriptions clearly state what is due today

FightEdge now carries trial history and Stripe subscription truth across cancellation, administrator recovery, and deployment so a returning member cannot be surprised by an unclear restart charge or a duplicate subscription.

  • Eligible first-time subscribers still receive the complete seven-day Pro trial.
  • A member account that already consumed a trial cannot become eligible again because local Pro access was revoked or the application was redeployed.
  • A no-trial restart requires an explicit acknowledgement of the exact monthly or annual amount due today before Stripe Checkout opens.
  • A crafted immediate-charge form is rejected when the account remains trial-eligible.
  • FightEdge inventories the existing Stripe customer and blocks a new Checkout when any non-terminal subscription already exists.
  • Administrator local-access revocation preserves Stripe customer and subscription identity so Resync remains available and billing is never implied to be canceled.
  • Prediction logic, reports, scoring, packaged databases, member records, schedulers, and AWS infrastructure remain unchanged from r1002.

Paper tracking, first entry, and subscription control now behave like one dependable account journey

FightEdge now gives members a working Paper Ledger submission, a predictable first destination, and an explicit way to stop or resume renewal without deleting their account or losing paid-through access early.

  • Paper bets submit through one canonical POST endpoint, while previously cached pages remain compatible instead of falling into a generic Method Not Allowed response.
  • Ordinary newly verified members enter the primary Dashboard; intentional fight, report, preview, and Pro-return destinations are still preserved.
  • Signed-in username watermarks have been removed so data-dense research surfaces remain legible and distraction-free.
  • Cinematic product visualizations now remain fully visible on narrow phone screens instead of cropping the interface being demonstrated.
  • Profile and Pricing now offer direct cancel-at-period-end and resume-renewal controls alongside Stripe billing management.
  • Canceling renewal keeps the account and paid access intact through the confirmed service period; signed Stripe lifecycle events convert the member to Free only when access actually ends.
  • Cancellation and resumption require an exact customer, subscription, plan, and active-state match, so unrelated or stale billing records fail closed.
  • Administrator resync, monthly, annual, lifetime, and revoke controls remain available and are covered by behavioral contracts.
  • The account schema change is additive; synthetic migration coverage preserves thirteen existing Pro records and every pre-existing entitlement field.
  • Prediction logic, generated reports, scoring, packaged databases, schedulers, stored member content, and AWS infrastructure remain unchanged from r1001.

Checkout confirmation and Pro access now agree on one durable subscription state

FightEdge now distinguishes a subscription that is active, still reconciling, payment-incomplete, trial-ineligible, or canceled instead of presenting every non-active return as the same retryable delay.

  • Each Checkout attempt now has one durable, replay-safe intent, so retries preserve the member’s selected plan and destination without silently creating a second purchase path.
  • A canceled, payment-incomplete, or trial-ineligible subscription can no longer be mistaken for paid-through time or reappear as temporary local Pro access.
  • Trial denials are committed before Stripe cancellation and remain tied to the exact subscription across webhook retries and out-of-order delivery.
  • Apple Pay and other expanded card payment methods are inspected with bounded recovery when wallet details are still propagating, without treating an unavailable fingerprint as a confirmed duplicate.
  • Paid access is backed by the exact positive invoice and service period that granted it; unrelated events and refunds cannot replace or revoke that entitlement.
  • Renewal failures, provider-side cancellations, expired Checkout Sessions, refunds, and administrator repairs now converge through the same fail-closed lifecycle rules.
  • The confirmation page checks committed account state for a bounded period and distinguishes active, still reconciling, payment-incomplete, ineligible, terminal, and verification-error outcomes without asking the member to pay again.
  • Account deletion blocks new billing claims while FightEdge closes exact open Checkout Sessions and subscriptions, then removes or de-identifies local billing receipts before deleting the account.
  • Legitimate paid subscriptions canceled at period end still retain the time already purchased, while unrelated subscription events cannot revoke a member’s current subscription.
  • Prediction logic, generated reports, scoring, packaged databases, schedulers, stored member content, and AWS infrastructure remain unchanged from deployed r1000.

Sign-in recovery and card refreshes no longer compete with the member experience

FightEdge now keeps concurrent account recovery deterministic and moves long-running card refresh work out of the web request path, so a successful sign-in cannot appear stuck behind an administrator refresh.

  • Parallel requests from the same remembered browser recover one stable tracked session instead of creating competing sessions that can evict an active login.
  • The bounded, revocable device allowance now supports normal multi-device use and remains configurable by the operator.
  • Authentication status checks use a dedicated no-store endpoint and return explicit JSON or HTMX authentication failures instead of following background requests into sign-in HTML.
  • Upcoming-card refreshes run through the durable worker queue rather than a web-process thread, with job status reconciled back into Admin/System.
  • Each event page is fetched once, candidate card data is validated in memory, and one guarded compare-and-swap publishes the complete card without exposing partial per-event writes.
  • Concurrent operator edits and the last-known-good card remain protected when a refresh fails, is incomplete, or races with another change.
  • Privacy-safe request timing now distinguishes application latency from upstream latency in production access logs.
  • Prediction logic, report generation, scoring, packaged databases, private account data, and billing behavior remain unchanged.

FightEdge now carries one fused FE identity through every account boundary

The recognizable aperture now incorporates both letters in FightEdge, while sign-in and sign-out keep the same cinematic, professional atmosphere members see on the landing and account pages.

  • The fused FE mark replaces the E-only symbol across navigation, favicons, install icons, email, social previews, notifications, launch screens, product scenes, and generated-report chrome.
  • Versioned assets prevent immutable browser and installed-app caches from retaining the retired identity; compatibility aliases remain available to existing clients.
  • Sign-in, account creation, verification, recovery, reset, and sign-out use one lightweight cinematic handoff with an accessible name and description.
  • Fast responses are never forced to wait. The transition appears only after a short anti-flash delay and exposes safe status recovery only when a response is genuinely slow.
  • Keyboard focus, page inertness, browser-history restoration, reduced-motion, and Windows high-contrast behavior remain part of the transition contract.
  • Dashboard, Odds & Lines, My Bets, and other normal navigation keep contextual non-blocking loading feedback rather than adopting an account-boundary splash.
  • Nonvisual account and billing modules are frozen to the reviewed v3.15.746 payloads; model truth, generated reports, scoring, packaged databases, schedulers, stored artifacts, and AWS infrastructure remain unchanged.

The first visit and every account handoff now feel like one premium FightEdge journey

FightEdge now carries one recognizable Edge-E identity and the member’s original research destination from the public product story through account access and confirmed activation.

  • Landing, sign-in, registration, verification, password recovery, checkout success, and checkout cancellation now share one focused, accessible cinematic account shell.
  • Free, monthly Pro, and annual Pro choices use explicit language: Free requires no card, and trial eligibility is confirmed at checkout instead of promised in advance.
  • Safe fight, event, report, Fight Week, and My Bets destinations survive registration, verification, sign-in, and checkout while external, oversized, API, authentication, and billing-loop targets are rejected.
  • Verification displays a masked address and resumes from server-side state; signed-in password-reset continuation uses dedicated single-use session state.
  • Billing return pages distinguish confirmed access, pending activation, cancellation, and non-activating states before returning the member to their original context.
  • The Edge-E aperture is consistent across the public site, signed-in shell, emails, social previews, installed app, offline fallback, and push notifications.
  • Versioned high-resolution product renders, app icons, launch screens, and compatibility aliases keep current and previously installed clients visually consistent without inventing picks, odds, results, or performance claims.
  • This cumulative candidate includes skipped v3.15.742-v3.15.745 work; model truth, report content, scoring, packaged databases, schedulers, stored runtime artifacts, and AWS infrastructure remain unchanged.

The public first visit now gets to real FightEdge value faster

FightEdge now leads with the current UFC card, an immediately useful Free preview, truthful proof, and a shorter path from first visit to a personalized Fight Week workspace.

  • The first screen explains the product for UFC bettors and makes current-card research the primary action, with Free registration next and the Pro trial introduced after value is demonstrated.
  • The hero pairs the upcoming card with the latest canonical prior-card result, while withholding the score and offering the receipt when production proof is unavailable.
  • Preview, registration, sign-in, and trial links preserve the exact fight or card destination through Pricing and registration so members do not lose context as they progress.
  • Free is now described consistently as up to three selected current-card winner/confidence previews; the complete pick slate, reports, and fight-week tools remain part of Pro.
  • Social proof is a count-only aggregate of verified active customer accounts; stale model benchmarks are withheld instead of being restated as marketing.
  • The in-frame neuron field remains part of the brand through a small adaptive local canvas with reduced-motion, data-saver, visibility, and frame-rate safeguards.
  • The cinematic landing composition now shares the dashboard's neutral surfaces, text hierarchy, teal, and blue brand values so the signed-out and signed-in experiences feel continuous.
  • Workflow symbols now render as clean outlines. The product reel replaces compressed captures with three high-resolution, feature-faithful renders of the real analysis, Fight Week HQ, and Dashboard workflows—without inventing fighters, picks, events, metrics, features, or performance claims.
  • The reel identifies every scene as a rendered product visualization; a new vector Edge-E mark, deeper neural field, and native-scroll section assembly add cinematic polish while preserving reduced-motion, keyboard, and forced-colors behavior.
  • The closing evidence area retains its restrained orbit and light field instead of a generic grid.
  • Full-screen transitions remain limited to sign-in and sign-out. Slow in-app navigation keeps the current page visible, explains the requested destination, and offers a clear stay-on-page recovery action.
  • This cumulative release includes skipped v3.15.742-v3.15.744 candidates; accounts, access, billing, predictions, reports, scoring, databases, schedulers, and AWS infrastructure remain unchanged.

Member Journey progress is now measurable without collecting betting content

FightEdge now gives administrators an aggregate view of whether members complete setup, finish a real Fight Read, save something personally useful, and return to Fight Week.

  • Journey milestones are count-only: their paths and destinations are canonicalized, and caller-supplied picks, fighters, wager details, report contents, or other member payloads are discarded before storage.
  • A Fight Week return is recorded only after a member already has a successful first-open receipt, and only once per account.
  • Saved-signal adoption derives counts from existing picks, watched fighters, and logged bets without reading their selections, amounts, odds, or report content.
  • The administrator view labels the four journey outcomes precisely and exposes semantic progress values for assistive technology.
  • This cumulative release includes the skipped v3.15.742 and v3.15.743 candidates; accounts, access, billing, predictions, generated reports, scoring, databases, schedulers, and AWS infrastructure remain unchanged.

Core browsing is clearer, more resilient, and easier to operate

FightEdge now keeps mobile navigation, loading feedback, errors, event cards, reports, and prediction history understandable across touch, keyboard, assistive technology, and Windows high-contrast use.

  • The closed phone menu is no longer reachable by keyboard or screen reader; opening it moves focus inside, traps focus, and Escape returns focus to the menu button.
  • Loading feedback announces the requested action once, reports genuinely slow responses without pretending to know backend progress, and keeps the current page usable when the network drops.
  • Error notices stay visible longer and include a 44px keyboard-operable close button, while reconnection produces a clear recovery message.
  • Events use valid primary and secondary links; Reports and Prediction History use contextual control names, structured headings, and meaningful accuracy semantics.
  • A mobile animation conflict that could leave the Reports hero and upgrade panel invisible is removed, and Windows forced-colors receives explicit focus, surface, and progress fallbacks.
  • This cumulative release also includes the skipped v3.15.742 Fight Week request consolidation; accounts, access, billing, picks, reports, scoring, databases, schedulers, and AWS infrastructure remain unchanged.

Fight Week now opens from one consistent member snapshot

FightEdge now gathers the account state needed by Fight Week in one read instead of repeatedly reopening the shared member database for each panel.

  • My Card, followed fighters, saved bets, alert readiness, onboarding progress, and personal tracking reuse one current request snapshot.
  • The snapshot is never shared between members and exposes only a push-device count, not subscription endpoints or browser keys.
  • Current-card and published-report truth remain immediately responsive to source changes; the page is not hidden behind a stale full-page cache.
  • Fight Week now has one main content landmark, and its inline My Bets action meets the 44px mobile target.
  • Accounts, access, billing, published picks, reports, scoring, databases, schedulers, and AWS infrastructure are unchanged.

Upgrades and returning visits now resume in context

FightEdge now carries the exact fight, card, report, or betting workspace through the upgrade path and gives returning members a dismissible, replayable introduction to their personalized Fight Week workspace.

  • Free members who upgrade from a fight or report return to that same safe FightEdge destination after Stripe confirms access.
  • New Free, new Pro, existing Free, existing Pro, and administrator journeys keep distinct, accurate account language.
  • Existing preferences remain intact, setup stays optional and resumable, and the Fight Week orientation can be dismissed or replayed from Profile.
  • Upgrade return paths are length-bounded, same-site only, and excluded from billing, authentication, and onboarding loops.
  • Desktop and phone acceptance covered skip/resume, logout/login persistence, mobile fit, touch targets, light/dark themes, and accessible structure.
  • Model inference, published picks, reports, scoring, accounts, entitlements, databases, schedulers, and AWS infrastructure are unchanged.

FightEdge now builds a bettor workspace around you

New and returning members share one guided setup, and Fight Week HQ now brings personal card priorities, saved exposure, followed fighters, market context, and alert readiness into one decision-first view.

  • Members can choose their experience level, goals, odds format, preferred sportsbook, alert categories, and default start page without changing any model pick.
  • New-account email, trial, and billing-success paths use the same resumable member journey as existing accounts.
  • Saved bets and watched fighters rise to the top of the current card; notable market movement remains visibly separate from the published report pick.
  • My Bets, Value Finder, Line Movement, Profile, and Fight Week HQ share the member’s odds and sportsbook display choices.
  • Before a report exists, Fight Week shows the current card and an honest analysis-pending state instead of presenting an unpublished report as available.
  • Existing access, account data, bets, watchlists, reports, predictions, scoring, billing state, databases, schedulers, and AWS infrastructure are preserved.

Your most-used FightEdge tools can now follow you

Members can choose a compact navigation style, keep up to five favorite tools within one tap, and decide where the FightEdge home button opens.

  • Quick Access is available throughout the signed-in platform and saves with the member account.
  • Focused, Balanced, and Expanded modes control how much of the customer tool directory remains open.
  • Fight Hub, Analysis, Betting Tools, Community, and My Account groups keep every existing destination while reducing the default wall of links.
  • The current page's group always opens, so a compact preference never hides the member's location.
  • Profile leads with a My FightEdge organizer and keeps long secondary settings sections closed until requested.
  • Model inference, published picks, scoring, reports, accounts, administrator and Pro access, billing, databases, schedulers, notifications, and AWS infrastructure are unchanged.

Returning sessions receive the current release’s interface

Versioned styles and scripts now remain distinct inside the installed app cache, preventing a previous release’s interface bytes from winning over a newly deployed asset URL.

  • The service worker preserves the trusted content-version token when it stores and retrieves static assets.
  • Existing app installations explicitly check for the latest service worker during normal page use instead of depending on the browser’s delayed update schedule.
  • Unversioned launch icons and offline assets retain their existing cache-first behavior.
  • No browser data is cleared and the PWA is not unregistered.
  • Model inference, published picks, scoring, reports, accounts, administrator and Pro access, billing, databases, schedulers, notifications, and AWS infrastructure are unchanged.

Small-screen controls and report receipts are easier to trust

The production acceptance pass tightened three undersized mobile controls, added privacy-safe route-phase timing, and aligned report receipts with the exact JSON representation saved at publication.

  • Prediction History's older-events disclosure, Odds & Lines event filters, and dark Dashboard primary actions now meet their intended phone touch sizes.
  • Administrators can see bounded Dashboard and System Health phase timings in Production Pulse, without storing users, IP addresses, query strings, request bodies, or report data.
  • System Health's live-only cold-start view now treats an unavailable optional Cito snapshot as empty instead of returning a temporary error while deep diagnostics warm.
  • New report manifests hash normalized persisted values, preventing false integrity warnings caused by Decimal, NumPy/pandas, or non-finite values changing representation during JSON persistence.
  • Existing report artifacts and historical prediction rows are not rewritten; any historical repair remains an explicit operator-reviewed action.
  • Model inference, published picks, scoring, accounts, administrator and Pro access, billing, databases, scheduler behavior, push delivery, and AWS infrastructure are unchanged.

High-traffic bettor pages now lead with the decision, not every supporting panel

Dashboard, Events, Prediction History, and Odds & Lines keep their full data while moving secondary workflow maps, definitions, analytics, and later records behind clear native disclosure controls.

  • The Dashboard Tool Board remains complete but no longer repeats twelve sidebar destinations in the default expanded view.
  • Events leads with the three nearest cards; Card Radar and later scheduled events remain one interaction away and remember the user's choice.
  • Prediction History brings recent event receipts forward, groups calibration and operational context, and keeps older matching events available under an explicit count.
  • Odds & Lines keeps Market Triage visible while collapsing the signal reference and all but the nearest event table by default.
  • Disclosure controls are keyboard operable, focus visible, light/dark compatible, reduced-motion safe, and stored only as optional local display preferences.
  • Generated reports, published picks, scoring, event truth, accounts, administrator and Pro access, billing, databases, scheduler behavior, and AWS infrastructure are unchanged.

System Health opens with live safety signals while deep diagnostics refresh

Administrator diagnostics no longer make one page request wait for every database, report, storage, and integrity scan after a process restart or cache expiry.

  • Recent errors, request latency, scheduler receipts, contract warnings, cache state, and available live scheduler/ops state remain current on the rendered page.
  • The heavier verified diagnostic context is reused from shared storage and refreshed by one coalesced background worker.
  • A clear status pill distinguishes ready, updating, and retry states, and the page refreshes itself once a new verified snapshot is available.
  • An explicit administrator ?fresh=1 request retains the deliberate synchronous full-refresh behavior.
  • Generated reports, published picks, scoring, accounts, administrator and Pro access, billing, databases, scheduler behavior, and AWS infrastructure are unchanged.

The current card stays responsive while shared statistics refresh

Dashboard can now reuse its most recent verified same-card view while prediction and performance summaries rebuild in the background.

  • A previous event card is never accepted: reuse requires the exact current-card source and Eastern calendar day to remain unchanged.
  • Same-card fallback is time-bounded, duplicate refresh work is coalesced, and a rebuild that crosses a card revision is discarded.
  • Live readiness and account-specific controls continue to revalidate on each request instead of being frozen into shared context.
  • Generated reports, published picks, scoring, accounts, administrator and Pro access, billing, databases, schedulers, and AWS infrastructure are unchanged.

Data-heavy pages no longer queue behind long freshness checks

Dashboard and Odds & Lines now keep trusted cached context available while a background data writer briefly owns the fight database.

  • Short scheduler write locks can no longer multiply into repeated five-second waits for one page request.
  • Committed card and fight-data changes still invalidate the short token memo immediately, so speed does not replace freshness.
  • The report-first model-pick display lookup is warmed in the background and reused only while its exact report and prediction sources match.
  • Generated reports, published picks, scoring, accounts, administrator and Pro access, billing, databases, schedulers, and AWS infrastructure are unchanged.

Search engines now receive one clean FightEdge URL for every public page

Public fight-detail links in the sitemap now use the real report slug, and the reviewed www alias converges on the primary FightEdge origin.

  • Compound report filenames no longer leak .results into public fight URLs, eliminating the malformed sitemap routes identified in the production audit.
  • Production requests to www.fight-edge.com now keep the exact path and query while moving permanently to https://fight-edge.com.
  • The redirect destination is fixed and cannot be influenced by an incoming Host header; localhost, staging/custom domains, Elastic Beanstalk hosts, and AWS health probes remain outside the rule.
  • Accounts, sessions, administrator and Pro access, billing, model picks, reports, scoring, databases, schedulers, and AWS infrastructure are unchanged.

Moving between FightEdge tools now has clearer, mobile-safe feedback

Data-heavy destinations now acknowledge the selected action with route-specific progress language, while the normal mobile menu behaves as one predictable drawer.

  • Dashboard, event-card, Fight Week HQ, Trust, account, sidebar, and mobile-header navigation now receive delayed loading feedback when a response is not immediate.
  • Opening an existing event card says that the card is loading; it no longer claims that a model analysis is running or replaces the selected link with analysis copy.
  • The mobile drawer now keeps its visible, clickable backdrop, sidebar, menu icon, accessibility state, focus, and page scroll synchronized across second tap, backdrop, navigation, Escape, and desktop resize.
  • Model inference, reports and published picks, scoring, event truth, accounts, Pro access, billing, databases, schedulers, and AWS infrastructure are unchanged.

Valid prediction history is restored without replaying old alerts

A release-time authority check hid valid older fights from History and public accuracy totals even though their durable prediction rows were still present. The affected cohort is now recovered from those original receipts.

  • The post-event track record returns from 65/96 to the audited 114/169; no missing picks are invented and no prediction rows are deleted.
  • The sealed report remains authoritative for new events. Rodrigues Jr. stays the published pick against Franco and remains graded as a miss.
  • Ambiguous, missing, or unreadable new-event authority still fails closed instead of guessing a pick.
  • Recovery is scoped and repeat-safe, and it cannot replay historical phone pushes or create a catch-up batch.
  • Accounts, administrator and Pro access, billing, model inference, generated reports, packaged databases, and AWS infrastructure are unchanged.

Published picks now stay fixed from report to final result

The sealed fight report is now the fail-closed pick authority for the live tracker, History, and accuracy totals—even when a fighter name includes a suffix such as “Jr.”

  • Partial, equal-size, or larger ESPN updates are matched by bout identity, so duplicates or unrelated rows cannot hide a missing fight or end the tracker early.
  • Temporary live-state storage errors preserve the last verified card, block unsafe card changes, and show a clear “Live data temporarily unavailable — retrying automatically” message instead of making the tracker appear empty or ended.
  • Exact event timing is preferred while a guarded one-day timezone bridge keeps the correct card visible across UTC/Eastern midnight; ambiguous adjacent dates are never merged.
  • A dedicated background startup repair reconciles an existing report/history mismatch outside the live ESPN and notification lanes, clears the durable health warning, and never replays an old phone push.
  • Final-result notifications leave the polling lane immediately, use per-member delivery receipts, and stop retrying after ten minutes instead of arriving hours later in a batch. Durable follow-up markers resume unfinished result storage work safely after a restart, and stable first-seen times prevent repeated provider polls from making stalled work look new.
  • Existing passwords, administrator and Pro roles, premium access, and sessions remain unchanged. Private account storage receives only additive delivery and deletion-safety state, including rollback-compatible cleanup. If billing cancellation succeeds but local deletion then fails, the account remains available and the page explains how to retry or contact support instead of showing a server error.

Every public accuracy view now grades the same fights

Model Proof, Accuracy History, the prediction archive, Dashboard, Calibration, and confidence-zone accuracy now share one canonical scored-fight set.

  • Duplicate repair receipts with a missing event date no longer inflate calibration or confidence-zone samples.
  • True rematches remain separate, and explicit administrator result corrections retain priority.
  • This is a read-model consistency repair; it does not rewrite predictions, results, accounts, reports, model files, or databases.

Visible report-menu links now receive the tap

The mobile report backdrop no longer sits above the visibly open sidebar, so navigation links behave like the rest of FightEdge.

  • Sidebar links can be tapped at common phone widths instead of only closing the menu.
  • The shared presentation fix also reaches already-published cached reports.
  • This changes layering only; it does not alter report data, picks, accounts, billing, or model behavior.

Mobile report menus now open and close consistently

Generated reports now use one menu controller, keeping the visible sidebar, backdrop, menu button, and accessibility state in sync on phones.

  • A second tap, the backdrop, Escape, or a report navigation link can close the menu reliably.
  • Older controller-less report shells receive one compatibility fallback when served.
  • This is a presentation-only repair; it does not change stored reports, report data, picks, accounts, billing, or model behavior.

Safer HTTPS entry and faster Trust checks

FightEdge now has an additional production HTTPS safeguard and reuses expensive proof calculations without letting current card, freshness, or report-status facts go stale.

  • Trust now keeps the UFC's promoted headliner order consistent with Events and reports.
  • Proof and freshness cards stack cleanly on phones while retaining the denser tablet layout.
  • Generated-report navigation now displays the same visible mobile menu control as the rest of FightEdge.
  • This update does not change accounts, billing, picks, report data, model behavior, or ITD validation.

Current-card report titles and status now agree

Report headings now follow the same current-card headliner used across FightEdge, while Trust & Status separates a published report from report generation that may or may not be running.

  • Historical report titles remain unchanged when no unambiguous current-card match exists.
  • Trust now shows report publication and generation activity as two independent facts.
  • This update changes presentation only; it does not regenerate reports or alter picks.

Trust & Status hub added

Added a single user-facing place to understand model proof, current-card status, source freshness, report-generation visibility, account billing confidence, and related methodology pages.

  • Uses the existing proof, freshness, and report-status systems instead of creating duplicate records.
  • Keeps detailed model history, calibration, and receipts on their original canonical pages.
  • Adds a cleaner route for users who want to know whether FightEdge is current and trustworthy right now.

Sentiment page recovery and stale-data handling

Improved the Reddit Sentiment surface so stale or missing discussion data does not leave the page feeling empty. Current-card rows can now show useful context while live mention data catches up.

Global report-generation status

Logged-in users can see when a fight-card report is actively being generated, including stage, progress, and ETA context. This reduces the gap between a card change/report invalidation and the next available report.

Billing and entitlement safeguards

Strengthened Stripe subscription sync behavior so trial-to-paid conversions and paid-invoice access repairs preserve Pro access when Stripe has successfully charged the customer.

Cookie and privacy choices

Added a global cookie/privacy consent footer so visitors can understand and control privacy-bounded analytics usage, with links to the existing Privacy Policy.