Metadata-Version: 2.4
Name: avow-verify
Version: 0.1.0
Summary: An autonomous build-and-verify loop that reports calibrated confidence in AI-generated code
Author: qatcod
License:                                  Apache License
                                   Version 2.0, January 2004
                                http://www.apache.org/licenses/
        
           TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
        
           1. Definitions.
        
              "License" shall mean the terms and conditions for use, reproduction,
              and distribution as defined by Sections 1 through 9 of this document.
        
              "Licensor" shall mean the copyright owner or entity authorized by
              the copyright owner that is granting the License.
        
              "Legal Entity" shall mean the union of the acting entity and all
              other entities that control, are controlled by, or are under common
              control with that entity. For the purposes of this definition,
              "control" means (i) the power, direct or indirect, to cause the
              direction or management of such entity, whether by contract or
              otherwise, or (ii) ownership of fifty percent (50%) or more of the
              outstanding shares, or (iii) beneficial ownership of such entity.
        
              "You" (or "Your") shall mean an individual or Legal Entity
              exercising permissions granted by this License.
        
              "Source" form shall mean the preferred form for making modifications,
              including but not limited to software source code, documentation
              source, and configuration files.
        
              "Object" form shall mean any form resulting from mechanical
              transformation or translation of a Source form, including but
              not limited to compiled object code, generated documentation,
              and conversions to other media types.
        
              "Work" shall mean the work of authorship, whether in Source or
              Object form, made available under the License, as indicated by a
              copyright notice that is included in or attached to the work
              (an example is provided in the Appendix below).
        
              "Derivative Works" shall mean any work, whether in Source or Object
              form, that is based on (or derived from) the Work and for which the
              editorial revisions, annotations, elaborations, or other modifications
              represent, as a whole, an original work of authorship. For the purposes
              of this License, Derivative Works shall not include works that remain
              separable from, or merely link (or bind by name) to the interfaces of,
              the Work and Derivative Works thereof.
        
              "Contribution" shall mean any work of authorship, including
              the original version of the Work and any modifications or additions
              to that Work or Derivative Works thereof, that is intentionally
              submitted to Licensor for inclusion in the Work by the copyright owner
              or by an individual or Legal Entity authorized to submit on behalf of
              the copyright owner. For the purposes of this definition, "submitted"
              means any form of electronic, verbal, or written communication sent
              to the Licensor or its representatives, including but not limited to
              communication on electronic mailing lists, source code control systems,
              and issue tracking systems that are managed by, or on behalf of, the
              Licensor for the purpose of discussing and improving the Work, but
              excluding communication that is conspicuously marked or otherwise
              designated in writing by the copyright owner as "Not a Contribution."
        
              "Contributor" shall mean Licensor and any individual or Legal Entity
              on behalf of whom a Contribution has been received by Licensor and
              subsequently incorporated within the Work.
        
           2. Grant of Copyright License. Subject to the terms and conditions of
              this License, each Contributor hereby grants to You a perpetual,
              worldwide, non-exclusive, no-charge, royalty-free, irrevocable
              copyright license to reproduce, prepare Derivative Works of,
              publicly display, publicly perform, sublicense, and distribute the
              Work and such Derivative Works in Source or Object form.
        
           3. Grant of Patent License. Subject to the terms and conditions of
              this License, each Contributor hereby grants to You a perpetual,
              worldwide, non-exclusive, no-charge, royalty-free, irrevocable
              (except as stated in this section) patent license to make, have made,
              use, offer to sell, sell, import, and otherwise transfer the Work,
              where such license applies only to those patent claims licensable
              by such Contributor that are necessarily infringed by their
              Contribution(s) alone or by combination of their Contribution(s)
              with the Work to which such Contribution(s) was submitted. If You
              institute patent litigation against any entity (including a
              cross-claim or counterclaim in a lawsuit) alleging that the Work
              or a Contribution incorporated within the Work constitutes direct
              or contributory patent infringement, then any patent licenses
              granted to You under this License for that Work shall terminate
              as of the date such litigation is filed.
        
           4. Redistribution. You may reproduce and distribute copies of the
              Work or Derivative Works thereof in any medium, with or without
              modifications, and in Source or Object form, provided that You
              meet the following conditions:
        
              (a) You must give any other recipients of the Work or Derivative
                  Works a copy of this License; and
        
              (b) You must cause any modified files to carry prominent notices
                  stating that You changed the files; and
        
              (c) You must retain, in the Source form of any Derivative Works
                  that You distribute, all copyright, patent, trademark, and
                  attribution notices from the Source form of the Work,
                  excluding those notices that do not pertain to any part of
                  the Derivative Works; and
        
              (d) If the Work includes a "NOTICE" text file as part of its
                  distribution, then any Derivative Works that You distribute must
                  include a readable copy of the attribution notices contained
                  within such NOTICE file, excluding those notices that do not
                  pertain to any part of the Derivative Works, in at least one
                  of the following places: within a NOTICE text file distributed
                  as part of the Derivative Works; within the Source form or
                  documentation, if provided along with the Derivative Works; or,
                  within a display generated by the Derivative Works, if and
                  wherever such third-party notices normally appear. The contents
                  of the NOTICE file are for informational purposes only and
                  do not modify the License. You may add Your own attribution
                  notices within Derivative Works that You distribute, alongside
                  or as an addendum to the NOTICE text from the Work, provided
                  that such additional attribution notices cannot be construed
                  as modifying the License.
        
              You may add Your own copyright statement to Your modifications and
              may provide additional or different license terms and conditions
              for use, reproduction, or distribution of Your modifications, or
              for any such Derivative Works as a whole, provided Your use,
              reproduction, and distribution of the Work otherwise complies with
              the conditions stated in this License.
        
           5. Submission of Contributions. Unless You explicitly state otherwise,
              any Contribution intentionally submitted for inclusion in the Work
              by You to the Licensor shall be under the terms and conditions of
              this License, without any additional terms or conditions.
              Notwithstanding the above, nothing herein shall supersede or modify
              the terms of any separate license agreement you may have executed
              with Licensor regarding such Contributions.
        
           6. Trademarks. This License does not grant permission to use the trade
              names, trademarks, service marks, or product names of the Licensor,
              except as required for reasonable and customary use in describing the
              origin of the Work and reproducing the content of the NOTICE file.
        
           7. Disclaimer of Warranty. Unless required by applicable law or
              agreed to in writing, Licensor provides the Work (and each
              Contributor provides its Contributions) on an "AS IS" BASIS,
              WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
              implied, including, without limitation, any warranties or conditions
              of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
              PARTICULAR PURPOSE. You are solely responsible for determining the
              appropriateness of using or redistributing the Work and assume any
              risks associated with Your exercise of permissions under this License.
        
           8. Limitation of Liability. In no event and under no legal theory,
              whether in tort (including negligence), contract, or otherwise,
              unless required by applicable law (such as deliberate and grossly
              negligent acts) or agreed to in writing, shall any Contributor be
              liable to You for damages, including any direct, indirect, special,
              incidental, or consequential damages of any character arising as a
              result of this License or out of the use or inability to use the
              Work (including but not limited to damages for loss of goodwill,
              work stoppage, computer failure or malfunction, or any and all
              other commercial damages or losses), even if such Contributor
              has been advised of the possibility of such damages.
        
           9. Accepting Warranty or Additional Liability. While redistributing
              the Work or Derivative Works thereof, You may choose to offer,
              and charge a fee for, acceptance of support, warranty, indemnity,
              or other liability obligations and/or rights consistent with this
              License. However, in accepting such obligations, You may act only
              on Your own behalf and on Your sole responsibility, not on behalf
              of any other Contributor, and only if You agree to indemnify,
              defend, and hold each Contributor harmless for any liability
              incurred by, or claims asserted against, such Contributor by reason
              of your accepting any such warranty or additional liability.
        
           END OF TERMS AND CONDITIONS
        
           APPENDIX: How to apply the Apache License to your work.
        
              To apply the Apache License to your work, attach the following
              boilerplate notice, with the fields enclosed by brackets "[]"
              replaced with your own identifying information. (Don't include
              the brackets!)  The text should be enclosed in the appropriate
              comment syntax for the file format. We also recommend that a
              file or class name and description of purpose be included on the
              same "printed page" as the copyright notice for easier
              identification within third-party archives.
        
           Copyright 2026 qatcod (github.com/qatcod/avow)
        
           Licensed under the Apache License, Version 2.0 (the "License");
           you may not use this file except in compliance with the License.
           You may obtain a copy of the License at
        
               http://www.apache.org/licenses/LICENSE-2.0
        
           Unless required by applicable law or agreed to in writing, software
           distributed under the License is distributed on an "AS IS" BASIS,
           WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
           See the License for the specific language governing permissions and
           limitations under the License.
        
Project-URL: Homepage, https://github.com/qatcod/avow
Project-URL: Repository, https://github.com/qatcod/avow
Project-URL: Issues, https://github.com/qatcod/avow/issues
Keywords: ai,code-generation,testing,mutation-testing,verification,llm,calibration
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Software Development :: Testing
Classifier: Topic :: Software Development :: Quality Assurance
Requires-Python: >=3.11
Description-Content-Type: text/markdown
License-File: LICENSE
License-File: NOTICE
Requires-Dist: anthropic>=0.69
Requires-Dist: httpx>=0.27
Requires-Dist: hypothesis>=6.0
Requires-Dist: pydantic>=2.6
Requires-Dist: pyyaml>=6.0
Provides-Extra: dev
Requires-Dist: pytest>=8.0; extra == "dev"
Requires-Dist: pytest-json-report>=1.5; extra == "dev"
Dynamic: license-file

# Avow

**An autonomous build-and-improve loop that knows when not to trust itself.**

[![CI](https://github.com/qatcod/avow/actions/workflows/ci.yml/badge.svg)](https://github.com/qatcod/avow/actions/workflows/ci.yml) [![PyPI](https://img.shields.io/pypi/v/avow-verify)](https://pypi.org/project/avow-verify/) [![Python](https://img.shields.io/pypi/pyversions/avow-verify)](https://pypi.org/project/avow-verify/) [![License](https://img.shields.io/badge/license-Apache--2.0-blue)](LICENSE)

You hand Avow a goal. It writes a test suite, builds code until the tests pass, then, instead of declaring victory, it interrogates its own work: are the tests actually rigorous? Do they test the *right* goal? Does the solution hold up under fuzzing? It folds those signals into a single **calibrated confidence** and *flags or escalates a green it doesn't trust*.

The bet behind Avow: self-improving loops only work when something can objectively tell a good attempt from a bad one. For software there's no physics simulator, so Avow **synthesizes a verifier** out of execution-grounded signals and reports a confidence number, not a fake guarantee.

## Why this is different

Most "autonomous coder" demos stop at *the tests pass*. That's the easy 20%. The hard, valuable part is **trusting the result**, because a weak test suite, or a suite testing the wrong thing, makes "all green" a lie. Avow's whole design is the verification layer that turns "it passed" into "here's how much you should trust it, and why."

## The verification signals

| Signal | What it answers | How |
|---|---|---|
| **Behavioral** | Does it pass the suite? | the build loop converges to green |
| **Hold-out** | Did it overfit the visible tests? | a hidden split of the suite, with a hard floor |
| **Mutation** | Are the tests rigorous enough to catch bugs? | inject mutants, measure the kill rate |
| **Intent** | Do the tests test the *right* goal? | a different model reads the suite *blind*, restates the goal, compare |
| **Property** | Do invariants hold for *all* inputs? | Hypothesis property/metamorphic tests fuzzed during the build |
| **Reference oracle** | Does it match an *independent* implementation? | generate a simplest-correct reference; differential-test the solution against it on thousands of fuzzed inputs |
| **Adversarial escalation** | Can a QA adversary break it? | the Examiner reads the passing solution and writes harder tests targeting its weak spots; the suite battle-hardens over rounds (`avow harden`) |

> Behavioral-green is the precondition (not a confidence input); property tests are folded into the frozen suite (they raise the bar for *green* and *mutation* rather than appearing as a separate number). The aggregated confidence breakdown is **hold-out + mutation + intent + reference-oracle**, each included only when it ran. Hold-out, panel-agreement, and oracle-disagreement each act as a hard floor (a breach forces `low_confidence` regardless of the average).

These combine into a **calibrated confidence** with a transparent per-signal breakdown. `done = green ∧ confidence ≥ threshold`; below it, the run is flagged `low_confidence` or escalated to a human.

## Anti-cheat & honesty (load-bearing)

- **The builder never sees the tests.** They're graded in an ephemeral copy and never enter the builder's workspace, so it can't hard-code to them.
- **Enforcement is deterministic code, never an agent.** Budget caps, the non-regression gate, the confidence floor, stop conditions, none of these are an LLM that could hallucinate. You can't fix "AIs hallucinate" by adding an AI to watch them.
- **Confidence is a calibrated signal, not certainty.** Two of its inputs are LLM-judged; the breakdown is always surfaced so the verdict is auditable. A `low_confidence` result is the system telling you it doesn't trust its own green, the most valuable thing it produces.

## Install

```bash
pip install avow-verify          # Python 3.11+, from PyPI (the CLI command is still 'avow')
```

Or from source, to hack on it:

```bash
git clone https://github.com/qatcod/avow && cd avow
pip install -e ".[dev]"
```

The builder drives the [`claude`](https://claude.com/claude-code) CLI (uses its login); the verification hooks use the `anthropic` SDK (`ANTHROPIC_API_KEY`).

Verification clients are injectable. To run a panel or other structured-output verifier across
providers, use `OpenRouterClient` with OpenRouter model IDs (the selected models must support
structured outputs):

```python
from avow.openrouter import OpenRouterClient
from avow.panel import panel_intent_check

client = OpenRouterClient()  # reads OPENROUTER_API_KEY
result = panel_intent_check(
    goal,
    tests_dir,
    client,
    ["google/gemini-2.5-flash", "anthropic/claude-sonnet-4.6"],
)
```

## CLI

```bash
avow solve <goal-dir>                       # the full loop: build → verify → confidence
avow improve <goal-dir>                     # self-improvement: converge, then propose & build the next feature, repeat
avow harden <goal-dir>                       # converge, then escalate: the Examiner writes harder tests targeting the solution, repeat
avow survive <goal-dir>                       # converge, then survive an execution gauntlet, one counterexample kills the green and it fights back
avow gauntlet <solution-dir> <goal.md>       # attack an existing solution once: K independent references vs it over a fuzzed input space
avow graveyard                               # list the global attack-pattern memory (what past deaths have taught Avow)
avow population <goal-dir> [--hybrid]        # run N candidate solutions; the verifier picks the winner (--hybrid escalates only on plateau)
avow mutate <solution-dir> <tests-dir>      # suite-strength score for any code (offline AST by default; --llm adds cross-model mutants)
avow intent-check <goal.md> <tests-dir>     # does this suite actually test this goal?
avow propertize <goal.md> <out-dir>         # generate Hypothesis property tests for a goal
avow oracle <solution-dir> <goal.md>        # differential-test a solution against an independent reference impl
avow supervise <run.jsonl> <goal.md>        # review a recorded run's trajectory; the Supervisor recommends continue/redirect/escalate
avow adjudicate <solution> <tests> <goal.md> # a stalled build: decide BY EXECUTION which failing tests are the Examiner's bug (run them vs K independent references)
avow check <solution-dir>                    # run the configured verifier checks (lint/typecheck/audit/...) on a solution
avow report <repo>                           # point-and-go: auto-detect a repo's code + tests and mutation-score its suite
avow calibrate [--llm]                       # measure whether the confidence number is trustworthy (reliability curve)
avow calibrate --gauntlet [--seed] [--llm]  # the survival-instinct proof: false-high-confidence for plain vs gauntlet-survived vs seeded-graveyard greens
avow verify <solution> <tests> <goal.md>    # one calibrated confidence number for any artifact
```

Beyond the pytest suite, a goal can require arbitrary **checks**, any command that exits 0 on pass (lint, typecheck, a security scan, a size/perf budget). Configure them in `avow.yaml`:

```yaml
checks:
  - name: lint
    command: ["ruff", "check", "."]
  - name: types
    command: ["python", "-m", "mypy", "lib.py"]
  - name: bundle-size          # a metric check: pass iff the parsed number is within bounds
    command: ["wc", "-c", "dist/app.js"]
    max: 500000
  - name: coverage
    command: ["coverage", "report", "--format=total"]
    min: 90
strip_check_config: false      # opt-in anti-cheat (see below)
```

During `avow solve`, checks fold into the grade alongside the tests: the run is green only when the suite passes **and** every check passes, and a failing check feeds the Builder exactly like a failing test, so it iterates to fix lint/type/budget errors too. More verifier *types* → more product *types* Avow can drive to perfect. `avow check` runs them standalone.

- **Exit-code checks** pass iff the command exits 0. **Metric checks** (a check carrying `max` and/or `min`) require the command to succeed, then parse a number from its **stdout**, the last numeric token by default (thousands separators and scientific notation handled), or a `pattern` regex for non-trivial output, and pass iff it's within bounds (inclusive). That covers size/coverage/latency/complexity budgets, not just pass/fail gates.
- **Anti-cheat:** checks run on the solution dir, so by default they're a weaker anti-cheat than the hidden pytest suite (visible to a reviewer, but a Builder could loosen a check's own tool-config). Set `strip_check_config: true` to run each check in an ephemeral copy with builder-authorable config (`.ruff.toml`, `mypy.ini`, `.flake8`, …) stripped, so a check can't be silenced by loosened config. (`pyproject.toml` is deliberately preserved, it can hold real dependencies.)

When a build stalls just short of green, `avow adjudicate` answers *"is this failing test the solution's bug or the Examiner's?"* by generating K independent reference implementations and **running each failing test against all of them**, if the independent correct implementations also fail it, the test contradicts correctness (a `TEST BUG`); if they pass it, the solution is the outlier. The verdict is decided by execution, not by an LLM's opinion. It's advisory (never auto-edits a test) and available in-loop via the opt-in `adjudicate_enabled`.

`avow improve` runs the two-phase loop: converge on the goal, then an **Ideator** proposes the next improvement (each with a verifier and a risk label), a **leash** auto-pursues objective low-risk ideas (and escalates the rest), the chosen idea joins the verifier, as a **test** the Examiner writes, or, when the idea is a standing quality **gate** (`kind: "check"`), as a new entry in `config.checks`, and the loop re-converges, bounded by a round cap. So Avow widens its own verifier menu as it self-improves.

`avow survive` is the survival instinct. After a green, it throws the solution into an **execution gauntlet**: K independently generated reference implementations, differential-fuzzed against it over a large input space. If a *majority* of references diverge on any input, the solution is the outlier and the green is **killed**, the winning reference's differential test is frozen into the suite, the Builder rebuilds, and it faces a fresh gauntlet. It keeps fighting until it survives a full gauntlet clean (`verified_survivor`) or dies honestly at the round cap (`died`, with the exact counterexample). The kill is decided by *execution* against a reference majority, never by opinion, and `verified_survivor` means "survived a K-reference execution gauntlet," not "provably correct." `avow gauntlet` runs one attack on an existing artifact. Ships dormant.

Avow also gets **harder to fool over time**. Every kill is sent to a **Coroner**, which abstracts the concrete counterexample into a transferable *attack pattern* (a class of tricky inputs, not the one literal case), stored in a global **Graveyard** (`~/.avow/graveyard.jsonl`, deduped). Future gauntlets are seeded from it: for a new goal, `avow survive` retrieves the patterns most *relevant* to that goal by keyword overlap (not just the most recent) and steers reference generation to probe those known-tricky input classes. The autopsy is strictly best-effort, so it can never change or crash the execution-decided verdict. `avow graveyard` lists what it has learned. This is a lexical heuristic, not semantic retrieval; it improves on recency without pretending to understand meaning.

That memory arms the *attacker*. Avow also arms the *defender*: within a single `avow survive` run, each kill's abstract lesson is accumulated into an ephemeral **lineage memory** and handed to the Builder on the rebuild, so the heir inherits *why its predecessors died* and steers away from the whole failure class, not just the one input the frozen test already blocks. The inherited lesson is abstract only (the failure class and its description, never the reference implementation or a concrete input), preserving the rule that the Builder never sees tests or references. It is guidance, not a guarantee: the frozen regression test remains the mechanical backstop.

`avow report <repo>` is the point-and-go entry point: aim it at an existing repository and it auto-detects the source modules (including code nested in packages) and the test suite, confirms the suite is green, mutation-tests the real code, and prints the suite-strength score with the surviving mutants pinned to `file:line` (the faults no test caught). No goal file, no flat-module layout, no configuration. If the suite isn't green on the unmutated repo, it reports *why* (the actual pytest failure with a hint, a missing import means `pip install -e .` first; a `src/` layout means point `--source` at the package) rather than a meaningless number. When auto-detection guesses wrong, override it: `avow report <repo> --source src/mypkg --tests tests` (both repeatable).

`avow calibrate` measures whether the confidence number can be *trusted*. It runs a labeled benchmark (goals with a correct reference, injected-bug variants, and an independent oracle for ground truth), scores every variant with the real verifier, and reports the reliability curve plus the **false-high-confidence rate**, the fraction of "trusted" solutions that are actually wrong. Run it whenever the confidence path changes. It's what proved that suite-derived signals alone (mutation + hold-out) miss green-but-wrong solutions whose bugs live in the suite's blind spots, and that folding in the suite-independent reference oracle drives false-high-confidence toward zero, which is why `avow solve` runs the oracle by default.

`avow calibrate --gauntlet` extends that into the survival-instinct proof: it scores the benchmark across three cohorts (plain green, gauntlet-survived with an empty graveyard, and survived with a graveyard **seeded** leave-one-out from *other* goals' deaths) and compares their false-high-confidence. The seeding is leave-one-out with a provenance leakage guard, so a pattern mined from the goal being scored can never inflate its own result. The report is deliberately honest: it prints raw `wrong/trusted (n=...)` counts and refuses to state an "N times less likely" multiplier unless the sample is large enough. Without `--llm` it runs a deterministic stub that demonstrates the mechanism with no API key (labeled `STUB MODE`); with `--llm` it produces real numbers from a single labeled run.

A goal directory holds a `goal.md` (and, optionally, a `avow.yaml` to tune budgets/weights). `avow solve` writes the suite, runs the loop, and reports the verdict plus the confidence breakdown.

```
$ avow solve ./my-goal
result: success=True reason=green score=1.00 iterations=1
confidence: 1.00
  holdout: 1.00
  mutation: 1.00
best solution: ./my-goal/.avow/best
```

## What it is, and isn't

Avow is a **verifiable-domain solver**: its usefulness scales with how cheaply correctness can be *checked by execution* (code with clear I/O, algorithms, transforms, parsers). It is **not** a universal agent, it can't autonomously achieve fuzzy real-world outcomes (revenue, "make it good") because those have no sandbox verifier. It earns its keep on tasks that are both verifiable and tedious enough that looping beats hand-coding.

## Configuration (`avow.yaml`)

Budgets (`max_iterations`, `max_cost_usd`, `max_wall_seconds`, timeouts), models per role, hold-out fraction and floor, confidence threshold and per-signal weights, and which verification hooks are enabled, all tunable. See `avow/config.py` for the full set and defaults.

## Design docs

Architecture and per-feature specs/plans live in `docs/specs/` and `docs/plans/`.

## Status

**All five verification layers of the design are built**: execution-grounded checks (property + reference-oracle), decorrelated judges (cross-model panel + adversarial-escalating Examiner), test-the-tests (mutation + hold-out), intent triangulation (back-translation), and calibrated confidence (aggregation + hold-out/panel/oracle floors), plus the self-improvement *expand phase* (`avow improve`) and adversarial hardening (`avow harden`). It also ships **Population / Hybrid search** (`avow population`, run N candidate solutions *concurrently* (capped by `max_parallel_candidates`), the verifier picks the winner; `--hybrid` escalates only on plateau) and the **Supervisor** (`avow supervise` / opt-in `supervisor_enabled`, an event-triggered trajectory guardian that judges a plateauing run and recommends redirect/escalate; never enforces). All four agents of the design (Builder · Examiner · Ideator · Supervisor) are built, and the **full moat is proven end-to-end against live Claude** (Examiner-written suite + property fuzzing + the 3-model intent panel + mutation + confidence). Roadmap: true cross-provider panels, learned signal weights, parallel candidate execution.
