# DataDrivenAEC review-queue sandboxes

Version 1.0.1. **Imported and executed in n8n 2.38.7 on 2026-09-11; outputs match the Node implementation.** These are synthetic, read-only planning pilots, not connected production workflows.

| Artifact                     | Input                             | Actual output                          | Not implemented                                                |
| ---------------------------- | --------------------------------- | -------------------------------------- | -------------------------------------------------------------- |
| `rfp-sandbox.json`           | Structured synthetic notice       | Owned review/hold record               | RSS polling, source verification, scoring, CRM write or alert  |
| `filing-sandbox.json`        | Structured RFI/submittal metadata | Proposed filing path and review record | Reading attachments, moving files or writing a document system |
| `meeting-tasks-sandbox.json` | Already structured action items   | Owned task-review record               | Transcript extraction, AI summarization or task-system writes  |

`aec-review-queue.mjs` is the shared original source. The three n8n files contain the same function, a Manual Trigger v1 and Code v2 nodes, all inactive and credential-free. There is no external request, automatic submission, notification or customer payload. The three supplied samples passed the n8n CLI importer and JavaScript task runner; see [verification.json](verification.json) for the image digest, artifact hashes and observed outputs.

## Run the executable logic without n8n

Use Node 22.12 or newer; tests ran on Node 22.15.0. From this repository:

```sh
node scripts/run-aec-sandbox.mjs < public/downloads/automation/rfp-input.json
node scripts/run-aec-sandbox.mjs < public/downloads/automation/filing-input.json
node scripts/run-aec-sandbox.mjs < public/downloads/automation/meeting-tasks-input.json
node --test tests/native/aec-automation-sandbox.test.mjs
node scripts/build-aec-sandbox-workflows.mjs --check
```

Or import `buildAecReviewQueue` from the module. It accepts one JSON envelope containing `schemaVersion: 1`, `task`, an explicit `asOf` timestamp, `rows` and optional `previous` state. The samples fix their comparison time deliberately; they are reproducible teaching data, not live notices. Set your own verified comparison time for a new test.

The function returns `changes` and `state`; **it does not save state**. For a replay test, supply the previous returned `state` as the next input's `previous`. State is namespaced by task. An unchanged row becomes `unchanged`; a later revision becomes `amended`; a newly elapsed deadline can become `recheck`. Exact duplicates within one input are counted once. Same-ID conflicts, stale revisions and malformed records reject the entire pure calculation without an external partial write.

Missing owners, missing deadlines, elapsed deadlines and non-open notices remain `hold`. A `review` result still requires human review: it is not verified eligibility, acceptance or authorization to submit. Outputs and state retain supplied source metadata; use synthetic data for tests, avoid sensitive URL fields and never publish production state as an artifact.

## Repeat the n8n import test

Follow n8n's Import from File instructions: https://docs.n8n.io/workflows/export-import/ . Import one JSON file into a **new authorized test workflow** and keep it inactive. Inspect all three nodes and confirm no credentials or external-action nodes exist. Run manually and compare the final output with the Node command above. Record the actual server version, node versions, test time and observed output. The implementation works with default Code sandbox restrictions; it does not require a URL global or prototype inspection.

The recorded test used the pinned n8n image in `verification.json`, with Docker networking disabled and no credentials. Each file was assigned a temporary test ID, imported with `n8n import:workflow --input=<file>`, and run with `n8n execute --id=<test-id> --rawOutput`. All three completed successfully; the final Code-node JSON exactly matched the Node CLI output. The editor UI, connected systems and durable external state were not tested.

Source links accept ASCII HTTPS hostnames (including punycode), optional valid ports, paths and queries. IPv6 literals and raw Unicode hosts are outside this bounded input format. Credentials, fragments, sensitive query keys, malformed escapes and control characters are rejected.

## Before connecting anything

A separate reviewed adapter must define authorized source access, response parsing, source/record identity, durable storage, least-privilege credentials, human approval and recipient/destination allowlists. Add integration tests for rate limits, timeouts, retries and failures after a real write, with an idempotency key and atomic persistence appropriate to the destination. The in-memory replay test does **not** prove exactly-once external delivery or recovery after a partially committed external operation.

No Opportunity Radar feed or API is assumed. These files do not request an account, connect to live systems, scrape protected sources or send a proposal.

## Maintenance and rollback

Maintenance owner: unassigned pending repository-owner acceptance. Keep this release inactive until a named owner accepts its scope. Regenerate with `node scripts/build-aec-sandbox-workflows.mjs --write` after editing the shared source; commit source, samples and generated files together. Re-run the native tests and then the separately documented n8n import test. The generator writes only these six fixed output paths and does not change CI or repository settings.

Rollback: remove/deactivate the imported test workflow and revert the focused artifact commit. There are no external writes to reverse in these sandboxes. External adapters require their own recovery and retention policy.

License: original source and generated synthetic artifacts in this folder are provided under `LICENSE.txt`. This grants no rights to third-party notices, documents, n8n itself or unrelated repository content. Publication was authorized by the repository owner for this reviewed sandbox release. Connected deployments still require their own implementation and review.
