data-agent 成功证明
在抽取 Open Generative 之前,Tessera Agent 必须达到的确定性、质量、安全和渲染门槛。
当前工作的唯一目标不是证明“模型能输出组件 JSON”,而是证明:Tessera Agent 能把受治理的真实查询结果生成成有用、可信、响应式、可交互的数据分析界面,并在失败、流式中断、权限变化和并发冲突中保住 last-good。
固定范围
- 六个分析 Component Contract;其中唯一的 Chart Contract
data.chart见当前 Generative UI Catalog。 - 17 个经过审计的 Recipe:Steps Bars、Pipeline Stage Bars、Sleep Score、Revenue per Account Scatter、Tracked Time Sankey、Visitors Radial、Visitors Radar、Activity Calendar、Revenue Smooth Area、Active Users Heatmap、Sign-up Funnel、Earned so Far Bars、Contributions Heatmap、Sessions + Conversion Combo、Devices Bars、Visitors Stacked Area 与 Activity Rings。
- 至少 100 个固定 Golden Prompt,覆盖 Recipe 选择、Column Binding、流式创建、增量编辑、恢复、权限变化和冲突。
- 同一 Query Resource 必须能产生不同但合理的 Recipe,证明系统不是隐藏的固定 Query Renderer。
硬性安全门槛
以下指标必须为 100%,不存在统计容忍:
- Query tool result、prompt、proposal、Document、Revision、history 与普通日志中没有 rows。
- Resource window 只能通过 actor/tenant/Surface-bound grant 和 server cursor 获取。
- 模型不能引用未提供的 Resource、column、evidence、Component 或 Action。
- Preview 只读;浏览器不执行 document state 或 HostIntent;approval token 只能消费一次。
- event hash、sequence、cursor、epoch、audience 或 Contract lock 任一错误都 fail closed。
生成质量门槛
| 指标 | 门槛 |
|---|---|
| Provider schema 接受率 | 100% |
| 首次 proposal 结构有效率 | 不低于 95% |
| 有界 repair 后 commit 成功率 | 不低于 99% |
| 虚构引用或越过 Catalog slice | 0 |
| 错误 chart encoding | 不高于 1%,并在 commit 前拒绝 |
| 无意义重复组件或装饰 section | 不高于 2% |
| snapshot 与等价 operations 的 canonical 差异 | 0 |
成功 Commit 只是结构门槛。每个 Golden Case 还必须校验 Recipe 选择、Column Mapping、信息层级、 来源一致性,以及 Equivalent View 是否表达相同 Resource 语义。
Renderer 门槛
data.chart Contract 必须具有 Exact Renderer Registration、Authoring 与 Resolved Props Validator、
Resource Fixture、Accessibility Coverage 和 Node Error Boundary。17 个 Recipe 全部必须具有稳定尺寸、
Responsive Behavior、Reduced Motion、Accessible Name 与 Summary,以及同一份数据的 Table 或 Text
Equivalent View。可信文档 Gallery 必须把官方 Fixture 经过 SurfaceController、GenerativeSurface
与 Verified Registry 渲染出来;文档专用仿制图表不算通过。
可发布证明产物
候选发布必须锁定 Catalog、Contract、renderer 和 chart manifests;100+ golden 结果;replay/resume/conflict/security fixtures;no-payload scan;desktop/mobile visual regression;accessibility report;以及 dependency integrity 和 build provenance。CI 必须能在没有生产 credential 时重放确定性部分。
这些门槛全部通过后,才允许把 framework-neutral core 提炼到独立 Open Generative 项目。