"The numbers are math anyone could re-run. The words are Pippa's. Keep them in that order and the analysis never lies to make a point."
The Boundary Is the Design
Analysis has two layers, and the line between them is the whole safety story. The lower layer is deterministic aggregation — pure engine math over the folded crumbs and their latest interpretations, with no model anywhere in the path. The upper layer is narration — Pippa reading those aggregates and the raw crumbs, and writing the human summary. This is the Lantern precedent applied to health: deterministic before judgment. The numbers must be reproducible without a model; the one model-touched thing beneath them is the interpretation layer, which is explicitly versioned.
What the Aggregates Compute
The aggregate pass produces reproducible structure: coverage with the empty ranges named, readings by type, symptom sites with their severity spread and first/last dates, workout activities and the gap ranges between them, the reconstructed medication trail, measurement points, which interpreter generations are present, and the list of still-uninterpreted crumbs. Every group carries its crumb IDs. And crucially, the grouping is case-folded exact strings only. The engine will not decide that "ball of foot" and "right forefoot" are the same place — that judgment is real, and real judgment lives upstairs in the narration, never smuggled into the math.
Narration Reads, It Does Not Recompute
Narration takes the aggregates JSON plus the window's raw crumbs through the utility lane, under an instruction that carries the three rules of the next lessons as a binding contract. It reads the reproducible numbers and speaks about them; it never invents a figure the aggregates do not contain. So the split also protects against a subtle failure: a model that both computes and narrates can round a number toward the story it is telling. Here it cannot — the story is written over numbers it was handed and is not allowed to change.