# Facility Plan Auditor: local browser release

9 October 2026. [Open the auditor](https://mathideas.stera.ventures/facility/). This interface makes the first product hypothesis usable without Python installation. Select the six files, inspect exact costs and constraint failures, and export a review. The browser processes study files locally; there is no upload endpoint or hosted solver.

## What works

The interface checks weighted rectangular costs, client/site identities, exactly-k or at-most-k selection, required sites, complete whole-client assignments and capacity loads. Exact BigInt fractions avoid floating coercion. It reviews the submitted plan and a nearest-site reassignment. The latter is rejected if it overloads a facility. The independent lower bound relaxes opening, mandatory-site and capacity restrictions. Equality with a checked feasible cost proves optimality for this frozen model; otherwise the optimum remains unknown.

The generated capacity example checks submitted cost 12 and lower bound 4, rejecting the overloaded nearest-site alternative. Its bound on suboptimality is 8. The local Python tool's optional solver can separately propose the cost-10 alternative shown in earlier examples; that solver does not run in the browser. The fractional example reproduces cost 11/30 and lower bound 1/10 exactly.

Changing selected files cancels an active worker, invalidates earlier results and removes stale export links. Missing, duplicate or extra filenames and excessive sizes are refused. Unsupported model features receive explicit outcomes. User titles, provenance and errors are inserted as text; standalone HTML escapes supplied content.

## Files, exports and limits

[Six-file input contract](../facility-assignment-review-2026-10-09-v2/report.md): study.json, clients.csv, sites.csv, costs.csv, selected.csv and assignments.csv. One client must go wholly to one open site; required sites need not be filled. Fixed costs, minimum utilization, fairness, time windows, splitting and uncertain/geographic data require separate models. A user-supplied provenance statement is not authenticated.

The browser uses the same 512-client/128-site, eight-MiB-per-file, sixteen-MiB-total and 128-bit input-rational limits. It additionally refuses JSON nesting beyond 32, exact arithmetic beyond 131,072 bits per rational component, and computations still active after a 15-second worker limit. No conclusion is accepted on exhaustion. File reading, module loading, rendering and the main thread's scheduling are outside that worker limit; it is not a total-runtime or memory guarantee.

Exports contain a standalone HTML report and a JSON bundle with normalized data, original files encoded in base64, input SHA-256 hashes, engine/build identity and the HTML hash. Hashes bind bytes, not authenticity. The bundle contains the study's data; share it deliberately. No browser storage, analytics, remote font, external library or study-data request is part of this implementation. The page fetches its same-origin application assets and public generated examples. The production route adds a restrictive content policy and disables form submission.

## Validation and actual browser observations

[119 passing automated controls](../../snapshots/2026-10-08-baseline/facility-browser-validation-2026-10-09-v1.json) include 65 original-byte comparisons with the current Python no-solver checker. A separate integer oracle checks 7,776 tiny models and 93,312 submitted plans; that grid is one grouped control, not 7,776 additional component-check counts. Other controls exercise exact fractions and wide intermediate values, duplicate JSON keys, malformed CSV/UTF-8, byte/bit/depth limits, identity handling, escaped HTML and original-byte worker-bundle round trips. [Parity inputs and expected results](python-parity-inputs.json), [worker-produced report](worker-report.html), [worker-produced evidence](worker-evidence.json).

The actual local browser was used to load the capacity example, select all six fractional-study files, obtain 11/30, inspect the complete visible JSON export, and replace the selection with one file. The incomplete selection disabled review and cleared the prior result/export view. The visible bundle contained all six original files, the expected capacity assignments, cost 12 and lower bound 4. Local server logs showed application/example GETs, with no study upload request during these observations.

Native download completion is **unverified in the Codex in-app browser**: both its download event and download-link helper timed out. The files are generated and ordinary download links are present, but those observations do not prove an OS file was saved. A text-export fallback is available. Its copy button reported success, while the automation clipboard reader returned empty, so an OS clipboard round trip is also not claimed. The complete export text was directly inspected in the visible field and can be selected manually. No browser, clipboard or download permissions were weakened to bypass this limitation. Other browsers and mobile layouts were not exercised here.

## Commercial and research interpretation

This is the interface for the existing facility-review product, not another independent utility or customer. The repository now has 38 research utilities and 29,924 passing checks in 61 component reports. The [first-product plan](../../plans/optimization-assurance-first-product-2026-10-09-v5.md) retains an unvalidated assisted-review price hypothesis of AUD 5,000-10,000. Actual studies, material errors found, review-time benefit and willingness to pay remain unmeasured.

No mathematical source theorem was extended to weighted/capacitated inputs. No new manuscript reading or source proof acceptance occurred. [Archived source and evidence hashes](../facility-browser-artifact-manifest-2026-10-09-v1.json) preserve the exact release code as inert files. Next independent work includes further manuscript review and stronger exact capacity bounds; a permissioned study is needed to evaluate commercial usefulness.
