From 3e607222c65c5b9dbb3f8b2b44e9298e69652480 Mon Sep 17 00:00:00 2001 From: Duncan Tourolle Date: Wed, 26 Aug 2026 21:16:04 +0200 Subject: [PATCH] Record the Identity screen in the face spec Also notes what building it taught the design: a split has to reject before it confirms, or the next clustering pass undoes it. Co-Authored-By: Claude Opus 5 (1M context) --- docs/faces.md | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/docs/faces.md b/docs/faces.md index 5ed7e7f..8069c9d 100644 --- a/docs/faces.md +++ b/docs/faces.md @@ -772,7 +772,18 @@ Steps 1–5 are the spike. Steps 6–8 are the build, and they are only justifie - **6 — done for storage.** Catalog schema v8 — `people`, `faces`, `face_person`, `face_person_rejected`, `face_calibration` — with the identity operations FR-CULL-10 requires. The `DetectFaces` job kind and the debounced clustering pass are not wired yet. -- **7, 8 — not started.** The People/Identity screen, and the route-C first-run flow. +- **7 — done.** The Identity screen: a third top-level mode beside library and develop, reached from + the library header. People rail, face grid with per-face confirm/reject, rename in place, confirm + all, split off a multi-selection, regroup, and the NFR-SEC-5 delete-everything control. +- **8 — not started.** The route-C first-run flow: no model fetch, no checksum pin, no licence + notice. The screen says "No face model installed" and stops, which is honest but is not the + feature. + +The screen taught the design one thing worth recording. **Splitting has to reject before it +confirms.** Moving faces to a new person is not enough on its own: the next clustering pass sees a +face that still looks like the person it left, suggests it back, and the user's correction becomes an +argument they keep having. §9's cannot-link constraint handles co-occurrence; this is the same idea +applied to a judgement the user made by hand. Two things the build changed in this document's own design: