{# CUI // SP-CTI — Delta Review: side-by-side HITL delta panel (trust-hitl-02) #} {% extends "base.html" %} {% block title %}{{ app_name }} — Delta Review{% endblock %} {% block content %}
A force_* override records that a human overrode, never what changed.
Each row below is one claim-anchored diff: what the draft said, what it says now, and — for every
sentence — whether the revision actually resolved the finding that blocked it, or merely reworded it.
The diff is append-only evidence in trust_deltas; your decision moves the matching
approval_items ask and is written permanently to agent_approval_log with the
rationale you give.
trust_deltas table is unreachable on this
database, so this is not an empty review queue — it is an unmeasured one. Run
python tools/db/migrate.py --up (migration 20260815063941_trust_hitl_deltas).
{{ not_found }}. It may be on another tenant, or the link
is stale. The queue below is unaffected.
Deltas whose approval item is still pending, and which no later correction supersedes. Select one to open its side-by-side panel.
| Artifact | Stage | Findings | Claims Changed | Recorded By | Created | Action |
|---|---|---|---|---|---|---|
|
{{ d.artifact_id }}
{% if d.is_no_op %} no-op{% endif %} {% if d.review.no_ask %} no ask{% endif %} |
{{ d.stage_label }} | {{ d.findings_before_n }} → {{ d.findings_after_n }} {% if d.net_findings < 0 %} {{ d.net_findings }} {% elif d.net_findings > 0 %} +{{ d.net_findings }} {% endif %} | {{ d.changed_span_count }} | {{ d.actor or '—' }} | {{ d.created_at }} | Review |
| {% if telemetry_available %} No deltas awaiting review. {% else %} Queue not readable — see the notice above. {% endif %} | ||||||
{{ selected.stage_label }}
— recorded by {{ selected.actor or '(unattributed)' }}
— delta {{ selected.delta_id }}
{% if selected.supersedes_delta_id %}
— corrects {{ selected.supersedes_delta_id }}
{% endif %}
Stated reason for the change: {{ selected.rationale }}
{% endif %} {% if selected.is_no_op %}{{ selected.before_hash[:16] }}). A human was shown findings, cleared the gate, and the
text went out exactly as it was — which is the one thing today's audit line cannot say.
These anchor to no single claim — placeholder_guard and
citation_guard report at document level. A panel showing only claim-anchored
findings would render a blocked draft with nothing wrong with it.
{{ f.issue }}{% if f.detail %} — {{ f.detail }}{% endif %}{{ f.issue }}{% if f.detail %} — {{ f.detail }}{% endif %}
Aligned on anchored_claims offsets — the same decomposition every TRUST guard
numbers its findings against — so each row is a claim and its verdict, not a line of text.
{{ s.before_verdict }}{{ f.issue }}{% if f.detail %} — {{ f.detail }}{% endif %}{{ s.after_verdict }}{{ f.issue }}{% if f.detail %} — {{ f.detail }}{% endif %}This delta decomposed into no claims.
{% endfor %}
A rationale is mandatory (minimum {{ min_rationale_chars }} characters). An
unexplained decision is unauditable after the fact and indistinguishable from a bug. Your answer
moves this delta's approval item — the diff above is never rewritten — and appends a
permanent agent_approval_log record carrying what you write here.
This delta is pending, but it has no readable approval item, so there is nothing for a decision to move. That means the ask failed to queue when the delta was recorded, or the mutable row has been pruned. It is reported pending rather than settled deliberately: a failed enqueue must not read as a silent approval.
{{ selected.review.badge.label }} by {{ selected.review.item.resolved_by or '(unattributed)' }} {% if selected.review.item.resolved_at %}on {{ selected.review.item.resolved_at }}{% endif %}
Approval item {{ selected.review.item.item_id }}, state
{{ selected.review.item.state }}. The rationale lives in the append-only
agent_approval_log record this decision wrote — query it with the
delta_review.decisions collection above. The diff stays on screen because it is
evidence, not a receipt.
A later correction replaced this delta, so it is no longer the thing to review. Its evidence stands; find the correction in the timeline below.
This delta's own corrections, walked through supersedes_delta_id. Not the
artifact's history — that is below.
| Delta | Stage | Findings | Reason | When |
|---|---|---|---|---|
{{ c.delta_id[:12] }} |
{{ c.stage_label }} | {{ c.findings_before_n }} → {{ c.findings_after_n }} | {{ c.rationale or '—' }} | {{ c.created_at }} |
| Delta | Stage | Findings | State | Recorded By | When |
|---|---|---|---|---|---|
{{ h.delta_id[:12] }} |
{{ h.stage_label }} | {{ h.findings_before_n }} → {{ h.findings_after_n }} | {{ h.review.badge.label }} | {{ h.actor or '—' }} | {{ h.created_at }} |