# Project health & benefits

One Library home in **Data, evidence & assurance**, containing two explicitly independent examples:

- `#gaps`: the six-project Health Atlas capability / maturity / performance triad.
- `#benefits`: the PMO benefits and assurance rehearsal, with `#regulatory`, `#proof`, `#interfaces` and `#sources` views (`#source-lenses` and `#lenses` also work).

These are synthetic, historical prototypes made inspectable. They do not assess a real portfolio, identify causal interventions, approve regulatory decisions, establish barrier sufficiency or provide authenticated audit evidence. The six PMO benefits are not the six Health Atlas projects. There is no numerical connection between the two modes.

The reader’s shared task—asking what deserves a closer look at a project review—justifies one pictured Library home. This is a bounded worked example, not a new claim of progress on a foray’s research End. The preserved design distinctions and their limits are in [What was worth keeping](provenance/ideas-and-boundaries.md).

## Source identity and exact retention

Original public repository: [lawrencerowland/Project-web-apps](https://github.com/lawrencerowland/Project-web-apps/tree/7888f8a85aa9121e99190d392a622a4ee0cd4a7e). Migration base: **`7888f8a85aa9121e99190d392a622a4ee0cd4a7e`**. Source was read in full, including the six PMO files, the root forwarding page, Health Atlas and its supporting roadmap. No corresponding TSX implementation was found. The original source repository is CC0-1.0; the receiving implementation uses no external runtime dependencies.

| Original path | SHA-256 | Git blob |
|---|---|---|
| `web_apps/Project_Health_Atlas.html` | `6b841f99f8b834118dbc3e57940536edd815a3a1ae936fdc62a5ba62c92dfedd` | `46899a5d0c1e17bb282c4dd222b775869f58fb80` |
| `web_apps/regulatory-benefits-pmo.html` | `754b7ead6e61849e58e3c224a1871bbd5b8ae82941774c6394c32d7df1c8e34d` | `6bb4b1b5f8e5946c52cad773e84cdbcf1dda1d88` |
| `web_apps/regulatory-benefits-pmo/index.html` | `eacb5ed16a8c788c844f2dca1f0af39d02648fdac592848052d212d55bdb6688` | `0a2be7c1d0de5a59e4cfa33f1e5f165ece681175` |
| `web_apps/regulatory-benefits-pmo/README.md` | `991a00a374ad7f4a85ad2bd2fad4a915849a587686a355c5c70d62ba4831b335` | `9970382bf5097b61956d76229fbd3c7c69427d5d` |
| `web_apps/regulatory-benefits-pmo/modules/source-app-map.md` | `c295cedeff937db27f8a2e3e39316174930936e5d8b426f38ed928a84e1ec8ba` | `35a00a0709bb831940eee53ac77c700d0ffdf341` |
| `web_apps/regulatory-benefits-pmo/data/programme-model.json` | `d0769e49c97b27eb2f045f608089c81041cc6eee139014f508b0df70215b2e3c` | `5483876487a2a94786134eb795131201a00dd94a` |
| `web_apps/regulatory-benefits-pmo/data/benefits.csv` | `51f9d3b5dbdfcca032c44d30d8bf9204722b55b2e2ce6e050978a6acd4843700` | `5b79595c0b167c4618a78eb98c498643be446f02` |
| `web_apps/regulatory-benefits-pmo/data/evidence-register.csv` | `4b74e5eb6e11fa632c7005cbc99318bcbe1bc73f5f62752f2c59f289e962d97a` | `60c143cd8d475f9c10693fec4814655e5d1d19b0` |
| `docs/project-health-atlas-roadmap.md` | `1d392dbdef5c0200613baf24cc9e21ac99ead7462e2facf500a4d4c775bc96f2` | `594620aabeb94ed5f7931058030450e847400c2e` |

`data.js` retains the complete original six projects, PMO runtime model, all five presets, driver labels and six decorative SVG variants. SHA-256 of its exported data under `JSON.stringify` is **`b74fcf9414b03e84d2c66665f26b680d74eeeca255b18c16a0302c209706e29c`**. The retention test separately evaluates the original JavaScript literal when that pinned checkout is present. The three files under `data/` are byte-identical copies with the hashes above. They are reference assets: the original app never loaded them. The outline JSON lacks party/lever/weight/interface data and is deliberately rejected as a complete scenario import.

### Feature and supporting-file disposition

| Source feature or file | Receiving treatment |
|---|---|
| Six named projects, stage tags and 18 gap values | Exact original data; pictured tiles, numeric bars, detail inspection and added gap editing |
| Deforming tiles | Original neutral formula retained on the artwork; text and controls stay flat |
| Capability / maturity / performance definitions and per-tile “why” | Visible explainers, tie-aware questions and actual per-project calculated values |
| Randomise gaps | Repeatable seeded toy samples, 0–100 inclusive, seed visible and saved |
| Three stress controls | Repaired as three distinct colour-focus choices; original capability/performance buttons applied the same transform. Focus no longer implies that an assessment changed |
| Reset | Restores all original gap values, seed and focus; PMO reset restores its original model separately. Neither reset deletes snapshots |
| What / Why / How help | Retained as accessible disclosures with the claims narrowed to the actual construction |
| Three-step tour | Retained as a keyboard-accessible inline tour with focus return and Escape; no misleading modal overlay |
| Six miniature DAG variants | Exact illustrative artwork retained; highlighted curves are not claimed to be computed bottlenecks |
| Sparkline | Same synthetic idea, now seeded and stable across rendering; labelled synthetic with no observed history. SVG avoids the detached zero-size canvas issue |
| `setDAGFor(index, svgString)` programmatic hook | Not exposed: it was not a data format or user control and accepted arbitrary raw markup. Six built-in illustrations are preserved |
| Five PMO presets / six sliders / six levers | All source values, names, deltas, owners, families and descriptions retained. Slider focus survives updates. Presets replace drivers and retain selected levers; baseline reset restores both |
| Six benefit streams and heatmap | All targets, starting values and weights retained. Scores, target differences, exposure ingredients and full formula terms inspectable; every driver column remains available on small screens |
| Party / regulatory view | All six parties, thresholds, roles and eight weighted links retained. “Consent” displayed as party/composite scores; “pivotality” displayed as attention, with threshold status separately visible |
| Decision queue / obligations | Recast as questions about target gaps, party shortfalls, release evidence and ownership. Inactive-lever comparison actually recomputes each one-step score difference. No “highest leverage” or optimisation assertion |
| Evidence / proof view | All seven scenario/barrier/evidence/status/owner rows retained; score follows explicitly declared status. Added status editing. Missing descriptions and original ambiguous `r2` status remain visible |
| Interface view | Five starting values, weights, positions and illustrative proximity links retained; independent formulas explicitly distinguished from propagation |
| Source lenses / source-app map / original PMO README | All eight original runtime source descriptions retained; current canonical routes plus accurate boundaries in the Source lenses view. Useful supporting ideas consolidated into one note; redundant working copies removed, original versions recoverable in pinned Git history |
| PMO receipt commit / list / clear | Versioned snapshots with inspect and restore, individual removal, no silent 20-record truncation. At 100 records, adding fails with an explicit export/remove message. Reset preserves them |
| Export / editable JSON / local storage | Complete new-state roundtrip; original complete PMO models and exports with actual receipts supported. Atomic validation before replacement; explicit browser save/load, startup read without writes, storage errors visible; editor drafts survive other controls |
| Original PMO root forwarding HTML | Incoming source route forwards to the new independent benefits mode through the retirement integration |
| Health proof-bundle roadmap | Acceptance artifacts, rule receipts, lineage and simple-front-door ideas preserved in the compact note and evidence disclosure. Unimplemented signatures, rule engine, governance roll-ups and phased delivery aspirations remain in pinned Git history, not a new development plan |

## Calculations and corrections

`model.js` contains pure deterministic functions, with the UI displaying their results. `FORMULA = health-benefits-2026-10-v1` identifies the current arithmetic. All numbers below are authored demonstration choices, not fitted coefficients or validated metrics.

### Gap picture

For capability `c`, maturity `m`, performance `p`: `t = max(1,c+m+p)`, `x=(c-p)/t`, `y=(m-(c+p)/2)/t`, `intensity=max(c,m,p)/100`. The shape uses `tiltX=8y`, `tiltY=10x`, `skewX=6x×intensity`, `skewY=-5y×intensity` in degrees, and bulge position `(50+35x,35-25y)%`. This preserves the source's neutral formula. All tied largest positive gaps are named; the all-zero case has no dominant gap. Equal gaps yield a balanced shape even if all are large. Numeric values remain authoritative.

### PMO formulas

Let `V,R,E,I,F,A` be effective volatility, regulatory pressure, evidence confidence, interface drag, funding tension and acceleration. Active lever deltas are **summed then clipped once to [0,1]**. The original clamped after each lever, making opposite deltas order-dependent at a boundary. All original preset / active-lever combinations remain numerically equivalent within floating-point tolerance; opposed custom deltas now behave consistently.

- Benefit `b`: `clip(current − .30 V wV − .24 R wR + .26 E wE − .26 I wI − .18 F wF − .24 max(0,A−.48) wA + .035 min(.45,A))`. The acceleration boost is deliberately unweighted, as in the source. The target is used for the displayed gap, not the score.
- Exposure index: `(wV V + wR R + wE(1−E) + wI I + wF F + wA A)/6`. It is divided by six, not by the sum of weights. The heatmap shows these ingredients ×100. Neither is a derivative or causal sensitivity.
- Evidence status score: mean of declared status weights (`covered=1`, `no-proof=.45`, `evidence-only=.30`, `unassessed=0`). No description or artifact is validated by this formula. “Covered” is displayed as **claimed covered**.
- Party score: clipped `base + .22(mean benefit−.58) + .18(evidence score−.55) + active lever party boosts + Σ sensitivity × centred driver`. Evidence is centred as `E−.5`; other drivers as `.5−driver`.
- Party attention: clipped `1.8×max(0,own threshold−own score) + Σ linkWeight×max(0,neighbour threshold−neighbour score+.08)`. No influence propagation or marginal contribution is calculated.
- Composite party score: product of mandatory scores × `(1−product(1−optional scores))`. Thresholds do not gate it. It is not a probability; independence is not established. With no optional parties the second factor is now 1 (the source returned zero). With no mandatory parties their product is 1; at least one party is required.
- Interface score: clipped `starting maturity − .20 I + .08 E − .06 V + .09×weight` when the interface-room lever is active, plus `.03` when gate protocol is active. Each interface is independent. SVG proximity lines use drawing distance only and have no numerical effect.
- Attention indicators retain the five original formulas with accurate names: `1−mean benefit`, `.72 R + .28(1−evidence score)`, `1−mean interface`, `.78 F + .22(1−composite party score)`, and `1−community party score`. The community formula now preserves a real zero instead of the source's `|| .5` fallback; if a custom model omits the community party, this indicator is omitted. These differently constructed indicators do not establish a binding constraint. Equal values use stable ID order.

Baseline fixture: effective drivers `(0.35,0.47,0.75,0.26,0.39,0.37)`; mean benefit `0.5849723333333333`; exposure `0.0745583333333333`; evidence `4.05/7`; composite party score `0.6410363437404724`; five interface scores `(0.7035,0.6372,0.6555,0.5910,0.5602)`. Largest attention indicator is gate evidence pressure `0.4564`. These precise numbers establish reproducible arithmetic only.

## State and snapshot boundary

Export schema: `project-health-and-benefits`, version `1`, formula version `health-benefits-2026-10-v1`. It contains independent gap and PMO inputs and up to 100 snapshots. New snapshots contain full inputs and outputs. Import validates shape, finite ranges, allowed fields, array limits, unique IDs, references, URL schemes and formula version before changing live state. Stored outputs must match recomputation; object-key ordering does not matter. This catches inconsistency, not forgery: a person can edit the inputs and recompute outputs.

Original raw complete PMO models and `{model, receipts, outputs}` exports are accepted. Each legacy receipt retains its exact original object as `legacyReceipt`, including its old wording and outputs. Its formula status is `legacy-unversioned`; restoring uses validated stored inputs with the new formulas, and the UI says so. Neither legacy outputs nor new snapshots are cryptographic proof. The source seed outline is deliberately rejected as incomplete. Arbitrary prototype keys, non-finite numbers, oversized/nested payloads and unsupported URL schemes are rejected.

Only `library-project-health-and-benefits-v1` is written, when Save is pressed. Startup and Load read without overwriting malformed data. Old PMO browser keys are read only on explicit “Read old PMO browser save”; they are never written. Invalid imports leave live state and saved bytes intact. Editor drafts are independent of sliders. Resetting a mode preserves snapshots. No server, analytics request, shared workspace or external evidence store is involved.

## Verification

Run from the website repository root:

```sh
node --test library/apps/project-health-and-benefits/tests/*.test.cjs
```

The tests use the repository's existing `tools/library-apps/node_modules/jsdom`; production has no dependencies. The original-source comparisons use `git show` at the pinned revision (not the current working files), when that history is available at `/private/tmp/project-web-controls-retirement-20261002`; the retained-data and seed-file digests run everywhere.

Verified: 21 model/DOM test groups. These include source extraction parity, all 320 original preset/lever combinations, independent baseline arithmetic, driver clipping order, acceleration thresholds, gap ties/zeros, geometry-independent interface results, party-threshold independence, real zero community score, one-step lever differences, seeded samples, actual legacy receipt import, complete snapshot restore, reordered JSON keys, tampered outputs, malformed/unsafe imports, all views and controls, persistent slider focus, reset preservation, JSON draft preservation, corrupt/blocked storage and tour keyboard behavior. Browser layout and integrated navigation are checked separately by the receiving-site review; passing arithmetic/DOM tests does not establish human usefulness.

External conceptual source actually read: [W3C PROV overview](https://www.w3.org/TR/prov-overview/), 30 April 2013 note, for the limited provenance distinction in the compact note. No causal, game-theoretic, regulatory or empirical claim is being inferred from the PMO's invented formulas.
