The checks are the product, so the checks are published
There is no way to verify an accuracy claim from the outside, and there is no reason you should try. What you can verify from the outside is the mechanism. Below is every rule the engine runs, in the vocabulary the trade already uses, with the code section or manufacturer document each one leans on. Read them the way you would read another estimator's checklist: some will be things you already do, some will be things you do not, and a few you will disagree with. All three are useful answers, and none of them requires trusting the vendor.
Each rule carries a rationale written for the person whose design it just contradicted, because sometimes that is who reads it. That rationale is not marketing copy wrapped around the rule. It is the text stored in the rule and printed in the deliverable next to the finding, and it is reproduced on this page character for character.
A rule that fires too broadly is worse than no rule
This is written into the project's testing standard, not inferred from it. A rule that flags the ordinary case trains the reader to skip the section, and a register nobody reads is worth less than no register, because it also consumed the week before the bid. Silence on a well drafted package is the intended output, not a failure to find anything.
So every rule ships with two tests: a positive test proving it fires, and a near miss test proving it does not. A near miss is not an unrelated case. It is an input that differs from the firing input in exactly the one attribute the rule turns on. A rule without a near miss test is not merged.
Rule ids are permanent and are never renumbered, because published benchmark results will cite them. A rule that is retired keeps its id and gains a pointer to whatever superseded it.
Access control, 10 rules
These run against one opening at a time, then against each IDF once the openings it serves are known. Five of them share the locking_device conflict group, so at most one locking device rule applies to any one opening and the rest are recorded as suppressed with the winner named. That record is why a reviewer who expected a different device can read the rule that displaced theirs instead of guessing.
All 10 access control rules that ship today. Pack ac_k12_base 0.1.0.
| Rule | What it checks | Authority it cites |
|---|---|---|
| AC-001 | Base kit on every controlled opening | CSI 28 13 00 Access Control; UL 294 Standard for Access Control System Units |
| AC-010 | Egress opening with existing panic hardware resolves to electric latch retraction | NFPA 101 Life Safety Code 7.2.1.5 Door Leaf Operation; CBC 1010.2 Door Operations |
| AC-011 | Standard controlled opening on hollow metal resolves to a Grade 1 strike | ANSI/BHMA A156.31 Electric Strikes and Frame Mounted Actuators, Grade 1; CSI 08 71 00 |
| AC-012 | Opening adjacent to instruction or administration resolves to a quiet strike | CSI 28 13 00 Access Control; manufacturer continuous duty strike data |
| AC-013 | Aluminum storefront withholds the locking device pending stile verification | CSI 08 41 13 Aluminum-Framed Entrances and Storefronts; manufacturer strike installation instructions |
| AC-014 | Unknown frame material withholds the locking device | CSI 08 71 00 Door Hardware |
| AC-020 | Controller allocation against openings served per IDF | CSI 28 13 00; manufacturer panel capacity data |
| AC-021 | Latch retraction requires a dedicated sequenced supply | UL 294 Access Control System Units; manufacturer latch retraction power requirements |
| AC-022 | Access supply sizing and standby batteries per IDF | UL 294 Access Control System Units; NFPA 72 10.6 Secondary Power Supply; manufacturer supply data |
| AC-030 | Low extraction confidence on an opening | Internal calibration policy; see BENCHMARK.md once phase 4 publishes |
Table scrolls sideways for the authority column.
The rationale below is the text the engine ships and the text that prints in the deliverable. It is reproduced here exactly as it is written in the pack file.
AC-001 Base kit on every controlled opening
Every controlled opening needs credential input, a way to leave without alarming, and position monitoring. Omitting the door position switch is the single most common shortfall in this trade: without it there is no door-forced and no door-held-open alarm, and the system silently becomes a lock rather than an access control system.
AC-010 Egress opening with existing panic hardware resolves to electric latch retraction
Where egress depends on a panic device, the latch must remain free at all times, so the locking function has to act on the panic device itself rather than on the frame. An electric strike releases the frame keeper and leaves the panic latch under electrical control, which is why a strike is not an acceptable substitute on this opening. This rule overrides quiet hardware preferences: acoustic comfort in an adjacent classroom does not outrank free egress.
AC-011 Standard controlled opening on hollow metal resolves to a Grade 1 strike
Hollow metal frames accept a standard Grade 1 strike body with field preparation, and Grade 1 is the durability class appropriate to a school corridor. This is the default and it is deliberately the lowest priority in its conflict group, so any opening with a life safety, acoustic, or verification constraint is resolved by the rule that names that constraint instead.
AC-012 Opening adjacent to instruction or administration resolves to a quiet strike
A standard strike buzzes on release and clacks on relatch, which is disruptive immediately outside a classroom or an administration suite. The quiet alternative is continuous duty and draws roughly twice the holding current, so choosing it here is not free: it constrains the power supply calculation for the whole IDF, which is why this rule exists rather than leaving the choice to the installer.
AC-013 Aluminum storefront withholds the locking device pending stile verification
A narrow stile will not accept a standard strike body, and the difference between a narrow stile and a standard stile changes both the device and the preparation. Selecting a strike here and discovering the stile at rough-in is a change order. Declining to select is the correct answer, and it is worth more to the estimator than a confident guess.
AC-014 Unknown frame material withholds the locking device
Frame material decides whether a strike is installable at all, and whether preparation is factory or field. Guessing hollow metal because it is the common case is how a bid absorbs a storefront.
AC-020 Controller allocation against openings served per IDF
Openings are allocated to panels by the closet that serves them, not by the building total, because a home run does not cross an IDF boundary. Rounding up rather than to nearest is deliberate: a partially populated panel is a normal condition, an under-provisioned one is a change order.
AC-021 Latch retraction requires a dedicated sequenced supply
Latch retraction draws roughly thirty times its holding current at actuation. Fed from a shared access supply, that inrush browns out every other device on the branch, which reads in the field as intermittent reader failures that nobody connects back to the door. The supply must also sequence, so that retraction and any automatic operator do not start together. This is not a preference and it is not value engineering material.
AC-022 Access supply sizing and standby batteries per IDF
The supply carries every device continuously and must additionally absorb the largest single actuation without sagging, which is why the sizing is total holding current with headroom plus the largest single inrush rather than a sum of inrushes: two strikes are not actuated at the same instant. Latch retraction openings are excluded from this calculation because AC-021 gives each of them a dedicated sequenced supply, so counting their inrush here would size the shared supply for current it never sees. Standby batteries are two 12V units in series because the supply output is 24VDC.
AC-030 Low extraction confidence on an opening
A low confidence entity flowing into the bill of materials as certain is how this category of product loses a customer permanently. The threshold is data in this rule rather than code, so a project that has hand verified its drawings can lower it.
Video surveillance, 2 rules
Coverage class is computed in the engine from the camera's own optics against the visibility polygon. Nothing here assumes a space is covered because a camera symbol appears on the plan near it.
All 2 video surveillance rules that ship today. Pack vs_k12_base 0.1.0.
| Rule | What it checks | Authority it cites |
|---|---|---|
| VS-001 | Critical space does not receive identification class coverage | IEC 62676-4 Video surveillance systems, operational requirements; district security design standard |
| VS-002 | Critical space has no camera at all | IEC 62676-4; CSI 28 23 00 Video Surveillance |
Table scrolls sideways for the authority column.
The rationale below is the text the engine ships and the text that prints in the deliverable. It is reproduced here exactly as it is written in the pack file.
VS-001 Critical space does not receive identification class coverage
A critical space is one where the district expects to be able to say who a person was, not merely that a person was present. Identification class is the resolution at which a face is usable, and it is a function of sensor resolution divided by the width of the scene at that distance, so it degrades with the square of the area a single camera is asked to cover. A space that receives detection class or worse will produce footage that shows an incident occurred and cannot support who did it, which is the specific failure districts complain about after the fact. The class is computed from the camera's own optics against the visibility polygon, not assumed from the presence of a camera on the plan.
VS-002 Critical space has no camera at all
This is separated from VS-001 deliberately. A space with a camera that underperforms is a design question about lens and placement; a space with no camera at all is a scope question about whether a device was omitted from the drawings. Those two findings go to different people and carry different money, so collapsing them into one rule would make the register less actionable.
Scope boundary, 7 rules
Two blocks ship. The first reads one located scope statement at a time and joins to nothing else. The second reads a join over openings and specification sections, and covers the Division 08 to Division 28 seam one opening and one aspect at a time: the locking device, the power, and the rough-in.
Single statement rules, block SB-001 to SB-009
A scope marker is a sentence that moves work somewhere else: NIC, by others, furnished by, installed by, OFCI, CFCI, under separate contract. These rules read one of those sentences and report what it does and does not settle. Both share the scope_statement_disposition conflict group, so one sentence produces one register item rather than two.
The 2 single statement scope rules, block SB-001 to SB-009. Pack scope_boundary 0.1.0.
| Rule | What it checks | Authority it cites |
|---|---|---|
| SB-001 | Scope marker moves work to another party without naming the work | CSI MasterFormat Division 08 and Division 28 boundary; public contract code pre-bid clarification practice; AIA A201 General Conditions 3.2 |
| SB-002 | Scope marker assigns the work to Division 28 | CSI MasterFormat Division 08 and Division 28 boundary; AIA A201 General Conditions 3.2 on the contractor's review of the contract documents |
Table scrolls sideways for the authority column.
The rationale below is the text the engine ships and the text that prints in the deliverable. It is reproduced here exactly as it is written in the pack file.
SB-001 Scope marker moves work to another party without naming the work
This is the sentence that becomes a change order. 'BY OTHERS' with no named work and no named division tells a bidder that something in this area is not theirs, without telling them what, so every bidder draws the line in a different place and the low bidder is whoever drew it most generously. At award the question is settled by whoever has to open the wall. The finding is not that the work is missing; it is that the documents do not determine who has it, which under directive 2.4 is a flag rather than a quantity. A pre-bid RFI closes it for the cost of an email, and after award the same question is a negotiation.
SB-002 Scope marker assigns the work to Division 28
A marker that names a division is a different finding from one that names nobody, and it points at us. 'BY OTHERS' reads as somebody else's problem right up until the sentence continues 'BY DIV. 28', at which point the work is electronic safety and security and the estimator reading the Division 8 section is the person who has to carry it. The common failure is symmetrical and expensive: the door hardware supplier reads the same sentence, agrees the work is Division 28, and neither party prices the rough-in. This rule wins its conflict group over SB-001 because the party is named, so the honest finding is a cross reference to confirm rather than an unattributed gap, and reporting both against one sentence would put the same money in the register twice.
Division 08 to Division 28 seam, block SB-020 to SB-029
Door hardware is specified in Division 08 by the architect. Access control is specified in Division 28. Electric strikes, electrified locksets and latch retraction devices sit exactly on that line. For every controlled opening and each of its three aspects, these 5 rules read which division the documents put the work on and report only the states that cost money. A package where every aspect lands cleanly on one side produces nothing from this pack, which is the intended behaviour and not a failure to find anything.
The 5 Division 08 to Division 28 seam rules, block SB-020 to SB-029. Pack division_seam 0.1.0.
| Rule | What it checks | Authority it cites |
|---|---|---|
| SB-020 | Both divisions specify the work and they require different things | CSI MasterFormat Division 08 and Division 28 boundary; AIA A201 General Conditions 1.2.1 on complementary documents and 3.2.2 on the contractor's obligation to report discovered discrepancies before proceeding |
| SB-021 | Both divisions carry the work | CSI MasterFormat Division 08 and Division 28 boundary; AIA A201 General Conditions 3.2 on the contractor's review of the contract documents before bidding |
| SB-022 | Each division assigns the work to the other | CSI MasterFormat Division 08 and Division 28 boundary; AIA A201 General Conditions 1.2.1, the contract documents are complementary and what is required by one is as binding as if required by all |
| SB-023 | Neither division specifies the work | CSI MasterFormat Division 08 and Division 28 boundary; public contract code pre-bid clarification practice; AIA A201 General Conditions 3.2.2 on reporting discrepancies and omissions discovered in the contract documents |
| SB-024 | The seam cannot be determined from these documents | CLAUDE.md directive 2.4 on surfacing uncertainty; CSI MasterFormat Division 08 and Division 28 boundary; AIA A201 General Conditions 3.2.2 on requesting clarification before proceeding |
Table scrolls sideways for the authority column.
The rationale below is the text the engine ships and the text that prints in the deliverable. It is reproduced here exactly as it is written in the pack file.
SB-020 Both divisions specify the work and they require different things
Two sections requiring two different devices at one door is the argument half of section 2.4's 'a duplicate buy or an argument'. Only one device gets installed, so one of the two sections is unmet the day the door is hung, and which one is unmet is decided by whoever ordered first rather than by the design. The estimator's exposure is the difference between the two products plus the frame preparation that suits only one of them, and an electrified lockset and an electric strike do not share a frame prep. Note that a difference in wording is reported here as a conflict, because this rule compares what the sections say rather than guessing that two descriptions mean one product, and a seam where the two sections describe the device differently is worth reconciling before bid whether or not the descriptions turn out to name the same catalogue number. The severity is not blocking only because the fail state is not in question here; a conflict that also disagrees about fail-safe versus fail-secure on an egress opening is a life safety defect and belongs to the egress rules, not to this one.
SB-021 Both divisions carry the work
This is the duplicate buy half of section 2.4's 'a duplicate buy or an argument', and it is the quieter of the two because nothing about it looks wrong on either sheet. Both sections are correct in isolation and both estimators price the device, so either the owner pays for two of them or, more often, one bidder assumes the other trade has it, deletes it, and is the low bidder for the wrong reason. It sits at medium rather than high because it is recoverable: the money is still in somebody's number and the answer is a scope conversation, whereas the states SB-022 and SB-023 report are money that is in nobody's number at all. It is deliberately separate from SB-020 because the reader is different. A duplicate is the estimator's question about what to carry, and a conflict is the project manager's question about which specification the submittal will be reviewed against.
SB-022 Each division assigns the work to the other
This is the failure Part 3 describes when it says each package routinely assumes the other side covers the seam, caught in the act and provable from the documents rather than argued from silence. The door hardware section reads 'work of Division 28' and the access control section reads 'furnished under Division 08', and both writers believed they had assigned the work rather than declined it. At bid time nobody prices it, because each estimator reads their own section and correctly concludes it is not theirs. After award the two sentences are still there, which is why this is worth an RFI and not a phone call: the answer has to change a document. This rule wins its conflict group over SB-021 because counting assignments alone makes a circular hand-off look like two parties carrying one item, which is the opposite of what has happened, and reporting it as a duplicate buy would send an estimator to delete a line they never had.
SB-023 Neither division specifies the work
Section 2.4 puts it plainly: neither means somebody eats it. Nobody has priced the item, so at award it is a change order or it is absorbed by whichever trade is standing closest to the opening when the gap is found, which in practice is the one already pulling cable. This is the most inferential rule in the family and its guards are the reason it is credible rather than noise. It fires only where both divisions are present in the document set and both were read, only on openings the drawings mark as controlled, and only where no third division was named either, because power taken from a Division 26 branch circuit is somebody's work and reporting it as unassigned would be wrong in the most embarrassing direction. It is deliberately separate from SB-022 even though both mean nobody carries the item, because one is an argument from two sentences a reviewer can open and the other is an argument from silence. Those two are answered differently, they fail differently, and Part 12 makes rule ids the thing published benchmark results cite, so collapsing them would make this family's precision uninterpretable.
SB-024 The seam cannot be determined from these documents
Directive 2.4: where the documents do not determine something, produce a flag and not a guess. This is the state section 2.4's four outcomes do not name, and it is not the same finding as neither division specifying the work. Neither is a conclusion, reached after reading both sections and finding nothing; undetermined is the admission that one of them was not in the document set, or that the only sentence covering this work moves it to a party the documents decline to name. Reporting the second as the first would be Part 13's confident output where the honest output is a flag, and it would be the specific version of that failure this product can least afford, because a bidder shown 'nobody specifies the rough-in' on a package whose Division 08 section was never supplied will find the specification, find the assignment, and stop believing the register. Amendment A-006 made the same argument for SB-013 against SB-011, and this is the same distinction one gate later. The severity is medium rather than high because the finding is about our reading rather than about the documents: it tells a reader where to look, not what they will find there.
All five share the opening_division_seam conflict group. SB-022 sits first on purpose: counted by assignments alone, a circular hand-off looks identical to both divisions carrying the work, which is the opposite of what has happened.
6 whole system checks that return a number, not a verdict
A rule looks at one entity. A validator looks at an assembled system: a closet and everything it serves, or an opening and the supply that feeds it. Each one returns its computed values on a pass as well as on a fail, because the computed value is what makes a finding actionable. Knowing a supply failed is not useful. Knowing it has 6.4 A available against 7.1 A required tells a reviewer whether the answer is a second supply or a moved device, and lets them check the arithmetic against their own.
Two of the six are blocking. Voltage mismatch is blocking because the failure mode is a destroyed device at energisation rather than a performance shortfall. Egress locking compliance is blocking because it is a life safety defect rather than a cost item.
The 6 shipped validators, and the named values each one returns. Pack ac_k12_base 0.1.0.
| Validator | What it checks | What it computes |
|---|---|---|
| V-001 | Access power supply capacityidf scope, not blocking | shared_holding_current_aheadroom_fractionlargest_single_inrush_arequired_current_aavailable_current_amargin_a |
| V-002 | Voltage consistency per openingopening scope, blocking | locking_device_voltage_vdcsupply_voltage_vdcserving_idf_idlocking_device_ids |
| V-003 | Controller opening capacityidf scope, not blocking | controlled_openings_at_idfcontroller_capacity_openingsspare_openings |
| V-004 | Cable distance from serving IDFopening scope, not blocking | cable_path_length_ftmax_run_length_ftoverage_ftserving_idf_id |
| V-005 | Standby battery runtimeidf scope, not blocking | battery_countseries_stringsavailable_ahstandby_load_acomputed_runtime_hoursrequired_runtime_hours |
| V-006 | Egress locking complianceopening scope, blocking | is_egress_pathexisting_hardwarelocking_categoriesfailures |
Table scrolls sideways for the computed values.
Each validator ships a rationale and an authority in the same way a rule does. Both are reproduced exactly as the pack file writes them.
V-001 Access power supply capacity
A supply sized to its nameplate with no headroom fails on the first hot afternoon with every door in use. The computed required and available currents are reported on pass as well as on fail, so a reviewer can see the margin rather than trust the verdict.
Authority UL 294; manufacturer supply derating guidance
Pre-bid action Carry an additional access power supply at this closet, or confirm the device schedule.
V-002 Voltage consistency per opening
Devices at one opening on one branch must share an operating voltage or something is being fed the wrong supply. This is blocking because the failure mode is a destroyed device at energisation, not a performance shortfall, and because the resolution changes the bill of materials rather than the labour.
Authority UL 294; manufacturer device voltage ratings
Pre-bid action Resolve the device voltages at this opening before bid, or carry a second supply voltage at this closet.
V-003 Controller opening capacity
Panel capacity is counted against the openings actually served from this closet. A shortfall found at commissioning is a panel, an enclosure, a circuit, and a return visit.
Authority CSI 28 13 00; manufacturer panel capacity data
Pre-bid action Add controller capacity at this closet before bid.
V-004 Cable distance from serving IDF
Beyond the copper limit the run needs a different topology: an intermediate closet, a fibre link, or a repositioned panel. Each of those is a design change rather than a longer cable, and discovering it during rough-in means the pathway is already installed.
Authority TIA-568 horizontal cabling distance; manufacturer device voltage drop guidance
Pre-bid action Confirm the serving closet for this opening, or price an intermediate closet or fibre link.
V-005 Standby battery runtime
Standby capacity is specified in hours of supervised operation, and the required duration is jurisdictional. The computed runtime is reported so a reviewer can compare it against what this AHJ actually requires rather than against our default.
Authority NFPA 72 10.6.7 Secondary Power Capacity; project specification
Pre-bid action Confirm the required standby duration with the AHJ and adjust battery capacity.
V-006 Egress locking compliance
On a designated egress path the locking arrangement must not defeat free egress, and a fail secure device on a panic protected opening does exactly that. This is blocking because it is a life safety defect rather than a cost item, and because it will not pass plan check.
Authority NFPA 101 7.2.1.5; CBC 1010.2.13 Electromagnetically Locked Egress Doors; CBC 1010.2 Door Operations
Pre-bid action Resolve the locking arrangement on this opening with the architect and the AHJ before bid.
One case is worth stating separately. When a home run length is not stated anywhere in the package, V-004 records a fail with the length as unknown rather than a pass. Unknown is not the same as compliant.
The id blocks that are allocated and still empty
This section is here on purpose. Rule ids are permanent and can never be renumbered, so the blocks were allocated in advance, before the rules that will fill them were written. That means the numbering itself records what has been planned and not built. Publishing the shipped list without this one would let a reader assume the families are complete.
Every allocated id block and what is actually in it. Read out of the project's rules architecture document.
| Block | Allocated to | State | Notes |
|---|---|---|---|
| AC-001 to AC-999 | Access control, no sub-blocks allocated | 10 shipped | AC-001, AC-010 to AC-014, AC-020 to AC-022, and AC-030 are used. The grouping by theme is real and intentional but is recorded in no amendment, so the next AC rule will be numbered by whoever notices the pattern. |
| VS-001 to VS-999 | Video surveillance, no sub-blocks allocated | 2 shipped | VS-001 and VS-002 are used. |
| SB-001 to SB-009 | Single statement scope rules, one scope statement, no join | 2 shipped | SB-001 and SB-002 are used. SB-003 to SB-009 are free. |
| SB-010 to SB-019 | Drawing schedule to specification joins | empty | Specified in detail and shipping nothing. The amendment resolves this check into three rules plus a suppressor: SB-010 where every specification reference assigns the device to another party, SB-011 where the device has no specification reference at all, SB-013 where a reference could not be resolved to the device with confidence, and SB-012 to suppress SB-010 where a scope marker correctly and explicitly states the assignment. None exists in any shipped pack. A test currently pins the set of joins the scope pack may read, so shipping SB-010 fails that test until the filter that excludes a bidder's own take-off from the join is written. Anyone reading that amendment as a description of current behaviour would be wrong. |
| SB-020 to SB-029 | Division 08 to Division 28 seam | 5 shipped | SB-020 to SB-024 are used. SB-025 to SB-029 are free. |
| SB-030 to SB-039 | Scope added by addendum and not priced in the base | empty | Allocated and unwritten. Addendum reconciliation is a later phase, and no rule in this block exists. |
| DC-001 to DC-019 | Contradictions between claims across documents | empty | The whole DC family ships nothing. Quantity mismatch, product mismatch, conflicting performance requirement and conflicting responsibility assignment across drawings, schedules, sections and addenda are all specified and none is implemented. |
| DC-020 to DC-029 | Contradictions introduced or left unresolved by an addendum | empty | Same family, same state. |
| EX-001 to EX-019 | Extraction uncertainty. EX-001 is vendor disagreement | empty | EX-001 is allocated by amendment, the id pattern accepts the EX prefix, the chat coverage footer prints the block, and a source comment states that EX-001 is a rule in a pack. No pack defines it. The mechanism it names is real and shipped: where two independent extractions disagree on a field, no value is emitted at all and a disagreement record takes its place. The rule that would put that on the register is not written. |
| V-001 to V-999 | Validators, not rules | 6 shipped | V-001 to V-006 are used, all in the access control pack. |
Table scrolls sideways for the notes column.
Block membership is not enforced by the loader or by the schema. It is enforced by a per pack test asserting that every rule id falls inside that pack's block, paired with a test asserting every rule in the pack reads the join the block is for. The paired test is the load-bearing half: an id inside the seam block that read one located statement instead of the seam join would be in the wrong block whatever its number said, and the number can never be changed afterwards.
Reading a rule is one thing. Watching it land on a door is another
The viewer runs on fixture data. Click a door and you get exactly one of the rules above firing against it, with the rationale you just read, the authority it cites, and the citation to the page and sentence that triggered it, plus any rule that matched the same target and was suppressed, with the winner named.