Decision record: withdrawal of the staffing funnel from the benchmark origin
Date: September 3, 2026
Decision authority: founding steward, under the transitional rule in GOVERNANCE.md §2
Status: adopted; the correction is complete and mechanically guarded
Served at: /find-an-fde, the address the withdrawn surface occupied
1. What happened
Between August 31 and September 2, 2026, the public benchmark origin at benchmark.lockedinlabs.ai served a talent-matching prototype at /find-an-fde. It let a visitor describe an engagement, ranked a roster of invented, named, fictional candidates against it, labelled them "Best aligned", "Strong alternative" and "Adjacent fit", and ended with two links to LockedIn Labs' sales contact form: "Create a talent brief" and "Request an introduction". A persistent "Find an FDE" button placed it in the primary navigation of every page.
That surface contradicted the project's own normative text in three places. SPEC.md §4 prohibits ranking named people. The live-versus-planned register records a named-person leaderboard as "Not authorized". CONFLICT_OF_INTEREST.md §6 bars LockedIn's commercial teams from operating inside the benchmark. A staffing funnel inside the yardstick is the most direct form of the conflict the independence firewall exists to prevent.
2. What the evidence bounds, and what it does not
The project's own deployment evidence brackets the certified window.
| Record | Commit | Published | /find-an-fde |
|---|---|---|---|
deployment-evidence/benchmark-public-draft-2026-09-01.json |
b6e7ec3 |
2026-09-01T21:30:13Z | listed as a passing live route |
deployment-evidence/benchmark-public-draft-07975c9.json |
07975c9 |
2026-09-02T00:29:47Z | no longer listed; /research takes its place |
The evidence directory lives at the staging repository root, one level above this public boundary, so the records are cited by path rather than linked; the deployment runbook describes how each is produced.
So the surface was certified live, by the project's acceptance check, for at least two hours and fifty-nine minutes on the evening of September 1. The acceptance check passed because it tested the routes it was given, and the funnel was one of them: a verifier confirms what it is asked to confirm.
What the evidence does not bound is the earlier period. The recommender was built on August 31 (27f9403) and deployments before September 1 were published by hand from a workstation with no commit reference and no evidence record, so the project cannot state from its own records when the route first appeared in production. That gap is itself a finding, and it is why every deployment since September 2 runs through the commit-pinned pipeline and writes an evidence file.
3. What was done
- Unmounted in
07975c9(September 1, 20:26 local): the route, the navigation item and the lazy import were removed from the application, so the published bundle stopped carrying it. - Deleted from source in
75a69fc(September 2, 09:04):FdeRecommender.tsx,recommender-data.ts,recommender.cssand the unmountedResearchObservatory.tsxwere removed rather than left unreferenced, and the synthetic verification-record fixture stopped carrying a person's name. - Guarded in the same commit: the publication verifier now walks every source file under the public site and fails the build on the sales contact destination, the host of the linked FDE platform, the two call-to-action phrases, the withdrawn fixture name, and the retired phrase "FDE Score". A later commit added a reachability check that fails when any component stops being imported, so an unmounted surface can no longer sit in the tree unnoticed.
- Recorded here, and served at the withdrawn address, so a stale link to
/find-an-fderesolves to this explanation rather than to the homepage or to silence.
4. Why this record exists
The credibility evidence register and the publication integrity workflow require that a correction be recorded in the open, with the window it covers and the control that prevents recurrence. A project that publishes a fail-closed claims register and then corrects a contradiction quietly has not kept its own standard.
There is a second reason. The failure mode this record describes is not an accident of one prototype. LockedIn Labs founds, funds, trains, employs and staffs the population this benchmark would measure, and a procedural firewall cannot make that conflict disappear; it can only make each breach visible and correctable. This record is the first such breach, made visible. Any structural answer to the conflict, whether a separate entity, a change in what is measured, or an external majority holding the protected decisions, should be judged against whether it would have prevented this one.
5. What this record does not do
It does not claim that any real person was ranked, that any real evidence was received, or that any hiring decision was influenced. The roster was fictional and labelled as such on the page. It does not seat the commission, clear a mark, or authorize a result. It closes one contradiction and names the control.
