# Coverage Completion Plan

**UNOFFICIAL/EXPERIMENTAL.** Generated by
`scripts/generate-coverage-completion-plan.mjs`. Do not hand-edit. Regenerate with
`npm run coverage-completion-plan`.

The path to **100% verified disposition** of the master matrix — *not* 100% green.
A correct `watch` / `blocked` / `refused` / `n-a` with evidence and a named next
action is a valid product answer. This collapses the 657 non-green cells from the
[matrix-completion-audit](../matrix-completion-audit/summary.md) into
**20 action families**, ranked by cells-cleared-per-action, so a large
matrix becomes a short punch-list.

Predictions (expected status after a run/fix/stage) are marked `prediction`;
recorded dispositions (`record-decision` / `refuse-or-scope`) are not predictions.

## Top 10 actions by cells cleared

| # | Action | Family | Cells | Owner lane | Command / prerequisite |
| --- | --- | --- | ---: | --- | --- |
| CCP-01 | run-promotion | promotion-rerun-after-server-fix | 389 | Codex-live | rerun old fallback receipts on the fixed server |
| CCP-02 | refresh-image | remote-image-refresh | 74 | Claude-non-live | a pullable image or retained digest |
| CCP-03 | record-decision | verified-watch | 67 | product-decision | — |
| CCP-04 | record-decision | lifecycle-not-applicable | 44 | product-decision | — |
| CCP-05 | stage-prereq | operator-review | 20 | product-decision | runtime review or target-specific support decision |
| CCP-06 | stage-prereq | stage-secret | 10 | Claude-non-live | required Secret/ConfigMap/mount target fact |
| CCP-07 | fix-model | model-gap | 6 | Claude-non-live | — |
| CCP-08 | stage-prereq | create-namespace | 6 | Claude-non-live | see target-prerequisite-actions |
| CCP-09 | stage-prereq | install-crds | 6 | Claude-non-live | cert-manager CRDs |
| CCP-10 | fix-model | base-design | 5 | Claude-non-live | — |

## Cells by action type

| Action type | Cells |
| --- | ---: |
| `run-promotion` | 389 |
| `record-decision` | 111 |
| `refresh-image` | 74 |
| `stage-prereq` | 54 |
| `fix-model` | 25 |
| `lifecycle-observe` | 4 |

## Cells by owner lane

| Owner lane | Cells |
| --- | ---: |
| `Codex-live` | 393 |
| `product-decision` | 139 |
| `Claude-non-live` | 125 |

## Variant promotion (first-class family)

The promotion (V) lane is the loudest hole: **167 proven / 29 watch / 1 todo / 2 blocked / 0 n/a**.
- `CCP-01` **run-promotion** - 389 old fallback receipts to rerun on ConfigHub v0.1.80+.

## All action families

| # | Action | Family | Cells | Lanes | Owner | Expected (pred?) | Evidence surface | Issues |
| --- | --- | --- | ---: | --- | --- | --- | --- | --- |
| CCP-01 | run-promotion | promotion-rerun-after-server-fix | 389 | promotion | Codex-live | pass after rerun on ConfigHub v0.1.80+ (prediction) | variant-promotion-closeout | #682; #948 |
| CCP-02 | refresh-image | remote-image-refresh | 74 | G/K/L/P | Claude-non-live | pass after the image is pullable (refresh tag / pin digest / mirror) (prediction) | remote-image-runtime-workdown | #753 |
| CCP-03 | record-decision | verified-watch | 67 | G/K/P | product-decision | watch (verified disposition; recorded with evidence) | (already recorded) | #753 |
| CCP-04 | record-decision | lifecycle-not-applicable | 44 | lifecycle | product-decision | n/a (no routed lifecycle to observe) | master-catalog-matrix | #753 |
| CCP-05 | stage-prereq | operator-review | 20 | K/L | product-decision | pass after the runtime residue is reviewed or a better base is selected (prediction) | local-live-triage; target-prerequisite-workdown | #248; #753 |
| CCP-06 | stage-prereq | stage-secret | 10 | K/L | Claude-non-live | pass after the prerequisite is staged (prediction) | local-live-triage; target-prerequisite-workdown | #248; #753 |
| CCP-07 | fix-model | model-gap | 6 | K/L | Claude-non-live | pass after the model/recipe change (prediction) | model-gap-workdown | #248; #753 |
| CCP-08 | stage-prereq | create-namespace | 6 | G/K/P | Claude-non-live | pass after the prerequisite is staged (prediction) | target-prerequisite-workdown | #248; #753 |
| CCP-09 | stage-prereq | install-crds | 6 | G/K/L/P | Claude-non-live | pass after the prerequisite is staged (prediction) | target-prerequisite-workdown | #248; #753 |
| CCP-10 | fix-model | base-design | 5 | G/K/P | Claude-non-live | pass after the model/recipe change (prediction) | model-gap-workdown | #248; #753 |
| CCP-11 | fix-model | crd-lifecycle | 5 | K | Claude-non-live | pass after the model/recipe change (prediction) | model-gap-workdown | #248; #753 |
| CCP-12 | stage-prereq | provide-external-service | 5 | K/L | product-decision | pass after the provider prerequisite is modeled and staged (prediction) | local-live-triage; target-prerequisite-workdown | #248; #753 |
| CCP-13 | fix-model | semantic-normalization | 4 | G/P | Claude-non-live | pass after the model/recipe change (prediction) | model-gap-workdown | #248; #753 |
| CCP-14 | lifecycle-observe | lifecycle-route | 4 | L/lifecycle | Codex-live | observed (prediction) | lifecycle-route-actions; local-live-triage | #248; #753 |
| CCP-15 | stage-prereq | webhook-cert-lifecycle | 4 | L | Claude-non-live | pass after the certificate lifecycle is modeled and observed (prediction) | local-live-triage | #248; #753 |
| CCP-16 | fix-model | object-set-shape | 2 | K | Claude-non-live | pass after the model/recipe change (prediction) | model-gap-workdown | #248; #753 |
| CCP-17 | fix-model | unknown | 2 | G/P | Claude-non-live | pass after the model/recipe change (prediction) | model-gap-workdown | #248; #753 |
| CCP-18 | stage-prereq | admission-or-rbac | 2 | L | product-decision | pass after a target policy decision or base change (prediction) | local-live-triage | #248; #753 |
| CCP-19 | fix-model | generated-fact | 1 | K | Claude-non-live | pass after the model/recipe change (prediction) | model-gap-workdown | #248; #753 |
| CCP-20 | stage-prereq | stage-prereq-other | 1 | K | product-decision | pass after the prerequisite is staged (prediction) | target-prerequisite-workdown | #248; #753 |

## Boundaries

- Read-only projection over committed surfaces. No live run, no `runs/` edit, no
  status changed; the underlying decisions live in the surfaces this projects.
- `expected_status` for run/fix/stage families is a **prediction**, not a claim;
  the cell stays at its current disposition until a fresh receipt proves otherwise.
- Owner lanes: `Codex-live` runs the serial live/promotion lane; `Claude-non-live`
  is catalog/recipe/decision PR work; `product-decision` needs a scope/refuse call;
  `upstream-implementation` needs the ConfigHub server changeset fix.
