Wave 2 shipped objective.incumbent_cache_pricing and
objective.incumbent_challenger_cache_rate with no admin control. Nobody
decided they should not have one; it never came up, and the plan had no
step that would have made it come up. That matters most for a dial whose
rationale is tuning from neutral to full penalty WITHOUT reverting code:
if turning it means hand-editing a tracked file and restarting, the
tuning loop is too slow to walk.
Two halves, both small.
plans/token-waste-waves.md gains a standing per-wave acceptance gate,
placed ahead of Wave 1 so it is read before executing and checked before
a wave is called done. The escape clause is load-bearing, not hedging --
objective.credit_attenuation.enabled is deliberately off the allowlist
and off provider edits, because enabling it must be a config edit plus a
restart. The rule is that the ABSENCE of a control is a decision someone
made, not an oversight nobody noticed.
tests/test_admin_knob_coverage.py enforces it, in the shape
test_tui_schema_drift and test_tui_warnings already set here: covered is
DERIVED from admin._CONFIG_ALLOWLIST and admin._BOOL_KNOBS rather than
hand-copied, DELIBERATELY_NOT_IN_ADMIN carries reason strings rather than
bare names, and every failure names the knob. Exactness is asserted in
both directions, so the excuse list cannot rot into a rubber stamp as
knobs quietly gain controls.
Scope is the judgement call. RouterConfig has ~130 scalar leaves, and
demanding a decision on all of them produces a baseline nobody reads --
which is the rubber stamp being guarded against. Two clauses cut it to
58: a section is in scope iff the portal already reaches it (where it
reaches, it must reach completely), and deployment wiring -- endpoints,
model ids, credentials, paths, devices -- is out, being configuration of
where the router points rather than of how it behaves. 15 are covered
today, 43 excused with reasons. The docstring draws the line and
justifies it, including the classifier section, which is out because it
has its own dedicated admin card rather than a generic allowlist entry.
Two entries are marked PENDING feat/admin-incumbent-knobs: that branch is
adding controls for exactly those two knobs, and this branch is based on
origin/main where they do not exist yet. When it merges, the exactness
test FAILS on both until the entries are deleted. That is deliberate --
the test announcing its own cleanup beats a stale excuse sitting here
silently.
No config knob added, removed or changed; src/admin.py untouched.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VRQXz5SYZYVWscxS1QqF6U