Skip to content

Open decision: how DeltaTrack reaches staffers (delivery channel), waiting on Hill IT, workflow and packaging signals #112

Description

@willhea

What needs deciding

DeltaTrack hasn't decided how it will reach its main users, congressional staffers: as a web page, a browser extension, a desktop install, or something else. The decision is waiting on information from outside the project, not on engineering work. This issue keeps the options, the settled constraints and the evidence in one place, so the question isn't re-argued from scratch. The outcome becomes a new ADR (architecture decision record, in docs/decisions/).

Some background, for anyone new to this:

  • Delivery channel. How a user runs the tool. The comparison engine is Python. Its output is canonical JSON (a fixed data format, ADR 0006) turned into an HTML report by a single renderer (ADR 0007).
  • Local-only rule. ADR 0011 says a user's bill content never leaves their machine, even to a server that stores nothing. Drafts can be confidential. Any channel that uploads bills to a server breaks the rule.
  • Install gate. Staffers use locked-down computers. In the Senate, software is installed centrally by the Sergeant at Arms (SAA) from an approved list. In the House, the Chief Administrative Officer (CAO) approves it. An arbitrary executable is hardest to get through; something that needs no install is easiest (ADR 0011, "Context").

Where things stand (develop 5ef9a5e, checked 2026-10-05)

  • A hosted web app exists and breaks the local-only rule, on purpose and for now. https://deltatrack.agoradmv.org/ takes two uploaded PDFs or XML files and compares them on the project's server. The upload page says so and asks users not to upload drafts (web/webapp/compare.html:29-33). docs/PRODUCT.md:123 records this as a known, deliberate interim state tracked here. Its "browser-only" option is marked "Coming soon" (docs/web-compare.md).
  • The hosted app now has a deploy pipeline. .github/workflows/deploy.yml builds an image and deploys it to a Dokku server (Dokku is a self-hosted platform for running apps). It was added 2026-09-13 and set to deploy from main on 2026-10-03. main was last updated 2026-08-11 and doesn't have the workflow yet, so the next production deploy waits on Epic: promote develop to main so the demo and hosted app show current code #555 (the open epic to promote develop to main). See docs/deployment.md. This is new investment in the upload channel that ADR 0011 rules out. It doesn't change that ruling, but it raises the question of how long "interim" lasts.
  • The in-browser route has evidence behind it. The PDF backend study (wrapped up by Close out the PDF study with a one-page summary #740, the PR that wrote its summary; its files were removed from the tree by Remove the closed PDF backend study #783, a PR merged 2026-10-05) moved its conclusions into the ADRs:
    • ADR 0003: the Python engine runs inside a web page under Pyodide (Python compiled for the browser) and produces byte-identical XML comparison output, checked by scripts/pyodide_parity.py. The PDF path hasn't run end to end in a browser.
    • The XML comparison cannot load in a browser because it imports a PDF library it never uses #751 (open): the XML comparison imports a PDF library it never uses, which stops it loading in a browser without a workaround. It matters only for an in-browser channel.
    • ADR 0011: a page's Content Security Policy alone can't guarantee no network traffic, because window.open and WebRTC are outside it. A browser channel's no-egress claim needs a browser- or device-level control and a network-level check.

Already decided (not reopened here)

  • No uploads to a server for the real product (ADR 0011). A server can serve the interface, or work on bills that are already public when the user sends no bill content.
  • PDF input is required, because drafts exist only as PDF (ADR 0010).
  • The engine keeps no state and writes nothing the user didn't ask for (ADR 0005).
  • Rewriting the engine in JavaScript is not free. Its correctness is validated independently (ADR 0009), and a rewrite starts that over.

The options

Channel Local-only Install gate Engine
Fully in-browser page, no server yes none Python under Pyodide, or a rewrite
Browser extension yes extension approval as above
Desktop app or packaged executable yes install approval (hardest in the Senate) Python
Locally generated static HTML report yes needs Python to run Python
Hosted app, public bills only, fetched by bill number (no upload) yes none Python
Hosted app with uploads (today) no none Python

More than one can win. The public-bills-only hosted row is allowed by ADR 0011's "Consequences" section but hasn't been discussed here before.

What would unblock it

  • Hill IT specifics: what staffers in each chamber can actually install or run. This isn't public, so it needs a contact in SAA or CAO.
  • Workflow shape: how a real staffer wants to use it: drop in two PDFs, paste text, from inside a browser?
  • Packaging direction: whether BillTrax, a sibling project that carries a vendored copy of DeltaTrack's engine, converges with this one. It's listed as open in docs/research/naming-architecture/README.md.

Done when

  • The three signals above are in, or the maintainer decides to go ahead without one of them and says why.
  • A new ADR records the channel(s), the engine runtime that follows, and what happens to the hosted upload path.
  • docs/PRODUCT.md:123 and docs/web-compare.md are updated to match.

Scope

History

Unverified

  • That the hosted app is up today; it couldn't be reached from the sandbox used for this check.
  • Who controls the Dokku host. docs/deployment.md says to "ask the host maintainer", and the naming research lists ownership of the domain as open. The maintainer reports that civictechdc holds access.
  • Whether any of the three signals has moved since 2026-09-22.

Activity

  1. added
    questionFurther information is requested
    blockedBlocked on an external dependency
    on Jun 28, 2026
  2. willhea commented on Jul 28, 2026

    @willhea
    CollaboratorAuthor

    Status update for this decision, from a full-repo evaluation (2026-07-27) plus the maintainer's confirmation of direction:

    Current state: the only working web channel is the one ADR 0011 (local-only processing: user-provided bill content "must never leave the user's machine … regardless of whether that server would store anything") forbids. The hosted upload page at deltatrack.agoradmv.org processes uploaded PDFs server-side (docs/web-compare.md marks it "Available now"), while the compliant browser-side card is marked "Coming soon." The upload path accepts any PDF, including pre-publication drafts — the exact content class 0011 exists to protect.

    Confirmed direction: the hosted version is transitional and acknowledged as a 0011 breach. The target end-state is something local with a light install — preferably a browser extension or similar — consistent with the PDF.js client-side viability spike (ADR 0003, which showed published-bill extraction can run fully in the browser; draft/pre-introduction PDFs remain the untested risk on that path).

    Interim proposal, so the breach stays visible and bounded while the transition is worked: (1) a line on the upload page telling users their PDFs are processed on the project's server and advising against uploading non-public drafts there; (2) a note in ADR 0011 (or cross-referenced from it to this issue) recording that the hosted channel is a known, deliberate, interim exception with this issue as its retirement tracker. Without those, the record reads as if the project doesn't know it's out of compliance with its own safety contract.

  3. willhea commented on Sep 22, 2026

    @willhea
    CollaboratorAuthor

    PDF bake-off external-validity arm: closed, void

    Recording this here because RESULTS.md names this issue as its consumer. Short version: it does not move any row in the channel table, and it was never one of the gating signals above. Flagging it so nobody waits on evidence that is not coming.

    The external-validity run — testing whether the bake-off's findings generalise to unseen legislative PDFs — failed its own pre-registered controls and is void. Closeout and artifacts in #728.

    What voided it. The N-B control (unambiguous, XML-corroborated headings must agree) failed, and §5.6's consequence for that is "run void": the adjudicator is unreliable independently of any architecture. Every N-B failure and five of six N-A failures were on the human adjudication route, with two systematic failure modes — spacing defects normalised away (WELD 0/3, SPLIT 0/2) and RESCISSION read as RECISSION. Weld and split are precisely the defect classes the bake-off exists to detect, so the ground truth was repairing the thing being measured.

    What this does and does not change for the channel decision:

    • No comparative architecture result. Nothing here favours or disfavours hybrid vs corrected extended glyph, so no row in the candidate-channel table moves.
    • Nothing is refuted. RESULTS.md and RESULTS-CONFIRMATORY.md stand exactly where they were. This run was designed to test whether they generalise and did not succeed in testing them — that is different from finding against them.
    • ADR 0003 is untouched. Client-side PDF.js viability was not what this run measured.
    • One genuine caution. The run established that extraction correctness at the character level is hard to validate, because human transcription — the obvious ground truth — silently normalises exactly the defects in question. Any future claim that a given PDF path is "accurate enough" for pre-publication drafts (the ADR 0010 row) needs a validation method that accounts for this. An AI image-adjudicator outperformed the human route on this study's own controls, which is a usable lead for how to do that.

    Gating signals unchanged. Hill IT specifics, workflow shape, and DeltaTrack/BillTrax packaging direction are all still outstanding, and none of them depended on this arm. This issue stays blocked for the same reasons as before.

    🤖 Generated with Claude Code

    https://claude.ai/code/session_01XmeDh5BVXMBkwZ7zCX1oca

  4. changed the title [-]Open decision: DeltaTrack delivery channel(s)[/-] [+]Open decision: how DeltaTrack reaches staffers (delivery channel), waiting on Hill IT, workflow and packaging signals[/+] on Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    blockedBlocked on an external dependencyquestionFurther information is requested

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions