# Portfolio III system contract — learner template

Status: NOT STARTED. This is a document task, not runnable Python or approval.
Replace examples with your own scope and measurable criteria before building.

## User and problem

- Intended classroom user:
- Decision they need to make:
- Current failure/cost and why a tool helps:
- Explicit non-goals (real authentication, public uploads, autonomous judgment,
  paid providers and production deployment are not supplied by these fixtures):

## Scope and evidence layers

| Layer | Input/source | Actual observation | Authority it does NOT establish |
| --- | --- | --- | --- |
| Acquisition | Owned invented WAV/MP4 | Retained bytes/hash, container kind/duration | Rights/privacy/full decode/publication |
| Machine signal | Supplied dimensions/frames | Declared threshold result | Measured pixels/creative quality |
| Finding | Invented authored evidence | Stored rating and evidence | Verified human identity or true judgment |
| Review | Distinct fixture actor | Permitted revision/state transition | Real person or dataset approval |
| Readiness | Actual DB/tool probes | Current dependency statuses | Production safety or durable monitoring |

## Acceptance criteria — author your own

Example, not an observed result:
"Given a submitted finding at revision 2, when the distinct configured reviewer
approves expected_revision=2, GET returns approved/revision3 with unchanged
evidence and exactly one new audit event. Retrying revision2 returns409 and
changes neither stored finding nor audit."

For each criterion record precondition, changed input, action, expected result,
actual evidence locator, failure observation and limitation. Required cases:

- Supplied valid input and strict invalid input:
- Partial/failed machine signal retained without a fabricated human verdict:
- Draft/submit/distinct review and refused self/stale/terminal action:
- Actual quarantine acceptance/refusal and no automatic publication:
- Current not-ready and safe programming fault, not static health success:
- Owned output collision/partial failure and no claimed cross-system rollback:
- Stopped/restarted process and actual persisted read/audit:
- Fresh installation from declared kit versions, with actual tool versions:

## Architecture and tradeoffs

Draw the actual boundary sequence: invented media → local quarantine/inspection;
supplied metadata → service → SQLite; authored finding → review → current read;
actual dependency probes → bounded events; exported evidence → human defense.
Do not draw a connection that does not exist, such as automatic video judgment.

Record three decisions with alternatives, cost, failure sign and reversible step.
Example: reuse a validated local transport rather than build another HTTP client;
cost is disclosed assistance and narrow loopback scope, not independent socket work.

## Trust and release scope

Who owns directories/binaries? Where are secrets prohibited? Which helper is
reused? What is measured versus declared? What still requires rights/privacy/
security review? Name unresolved risks and an owner/next action. This contract
cannot authorize deployment merely because a checklist is filled in.
