# Evidence register - draft v1

Accompanies **Reporting and statistics: understanding the CAP ecosystem**, presented in the CAP training session at **The CAP Workshop and training 2026**. Individual feeds and messages provide evidence for analysis across the collection; coverage and publishing practice constrain wider conclusions.

Observed 5 October 2026. Published figures are selected aggregate observations, not an export of archive records. `evidence.json` preserves inputs to the calculations. No credentials are included.

## Screens and API scope

API origin: `https://ah-node-v2.api.alerting-apps.net`.

| Screen | Request and scope |
| --- | --- |
| Mexico SMN source | `GET /api/v1/admin/sources/by-code/mx-smn-es`: one source, rolling 24h histogram, latest errors and bounded recent alerts |
| Source reporting | `GET /api/v1/admin/reporting/sources/mx-smn-es`: source-specific current plus historic window |
| Health telemetry | `GET /api/v1/admin/monitoring/sources/{sourceId}/health-trends`: source-specific bounded aggregate windows |
| OET report | `GET /api/v1/admin/reporting/vocabularies/OET/versions/2/salience`: selected saved snapshot, 224 term aggregate rows |
| Keyword explorer | `POST /api/v1/admin/archive-keyword-explorer/query`: server-side term/field/date filtering and aggregations; sampleSize 5 for evidence collection |
| September report | Public `GET /api/v1/public/reports/monthly/2026-09/report.json`: finalised rolling 12-month aggregate report |

Original destinations:

- https://console.alerting-apps.net/cap-aggregator/sources/mx-smn-es
- https://console.alerting-apps.net/cap-aggregator/reporting/vocabularies/OET/versions/2
- https://console.alerting-apps.net/cap-aggregator/archive-keyword-explorer?q=%22OET-004%22
- https://console.alerting-apps.net/cap-aggregator/archive-keyword-explorer?q=hurricane+cyclone+typhoon+%22tropical+storm%22
- https://console.alerting-apps.net/cap-aggregator/reporting/monthly/2026-09

The bounded storm query adds `dateFrom=2026-09&dateTo=2026-09`. All five fields are selected: EVENT, EVENT_CODE, HEADLINE, DESCRIPTION, INSTRUCTION. Quoted terms: OET-004 and tropical storm. Unquoted storm terms: hurricane, cyclone, typhoon.

## Interpretation checked against implementation

- `alert-hub-v2-node/alerthub-node/src/main/java/org/alerthub/services/enrichment/ControlledTermSalienceArchiveQueryService.java`: `countEventCodeValue` and `countPreferredLabelPhrase` do not apply a period filter. The salience period selects a stored snapshot; it is not the usage month. Phrase matching targets Event, Headline and Description.
- `.../services/reporting/VocabularySalienceReportService.java`: report evidence categories, completed/missing/failed distinctions and per-term count sums.
- `cap-aggregator-workbench/src/features/sources/guidance.ts`: guidance detectors and sum of evidence counts. The badge can double-count an alert matching several tags. `guidance-hover.txt` is the actual `title` attribute, not an invented tooltip.
- `cap-aggregator-workbench/src/features/archiveKeywordExplorer/ArchiveKeywordExplorerPage.tsx`: selected fields, phrase query, union/per-term overlap, matrix drill-down and date controls.
- `cap-aggregator-workbench/src/features/reporting/MonthlyReportViewPage.tsx`: source index total and detail cover the report window; recent average explanation; tags count info elements.
- Advisory source: https://preparecenter.org/wp-content/sites/default/files/cap-enabled-alerting_0.pdf . Advice on Implementing a CAP-enabled Alerting System; labelled draft as of 2 July 2016. Referenced as advice, not a normative CAP conformance requirement.
- Project maintainer clarification, 5 October 2026: alternate publisher calendars are an active data-quality concern. Suspect future buckets require interpretation against original publisher dates; do not treat them as forecasts. Cause for each matching record has not been investigated for this talk.

## Calculations

- Explicit-code term coverage: `54 / 224 * 100 = 24.1%`.
- Phrase coverage: `133 / 224 * 100 = 59.4%`.
- Both: `45 / 224 * 100 = 20.1%`.
- Neither: `82 / 224 * 100 = 36.6%`.
- Either: `54 + 133 - 45 = 142`; `224 - 142 = 82`.
- OET-004 concentration: `220956 / 286612 * 100 = 77.1%` of summed per-term explicit-code counts.
- Top three: `(220956 + 30524 + 22995) / 286612 * 100 = 95.8%`. These are not shares of distinct alerts or publishers.
- Live OET-004 query: 222145 matches; one sender value (`https://www.airnow.gov`) contributes all matches. Snapshot/code-only scope and live/all-field scope differ.
- September storm term sum: `437 + 231 + 183 + 1013 = 1864`; union 1353; excess memberships `1864 - 1353 = 511`, not a distinct overlapping-alert count.
- Largest storm sender: `947 / 1353 * 100 = 70.0%`.
- Description union 1334; Event 977; Headline 913; Instruction 35; Event Code 0 for searched words. These sets overlap.
- September total: 152471. August: 267062. Fall: `(267062 - 152471) / 267062 * 100 = 42.9%`.
- Air-quality feed `us-epa-aq-en`: August 45356, September 3885. Contribution to net fall: `(45356 - 3885) / (267062 - 152471) * 100 = 36.8%`. Arithmetic attribution, not causal explanation.
- 189 source rows; 152 have positive September counts. Sum of source September contributions equals monthly total 152471.
- Mexico SMN rolling-window total 782; September 154; No polygon 67 for the rolling window. Current live reporting includes the partial October count and must be distinguished.

## Capture method and limits

Normal console routes returned HTTP 404 to fresh requests here. The user reports that those URLs work in their browser. They are retained as intended audience destinations. No hosting or routing changes were made.

The deployed shell entry at `/shell/ah-appshell-v1-1/index.html` and the deployed microfrontend assets remained accessible. A temporary headless rendering context loaded these assets, supplied the production API origin/configuration and the authorised token, and selected the intended route. Backend responses were live; no data were mocked. Captures are deployed-UI previews against live data, not successful direct-route browser-window captures. They omit shell account controls and browser chrome. Temporary authentication state is discarded when the capture context closes.

Native HTML `title` tooltips did not render into the screenshot. The title was read verbatim and retained separately; the deck reproduces its evidence excerpt as editable text beside the actual guidance screenshot. No simulated tooltip graphic is presented.

Screenshots are cropped for the discussed section; some tables continue below the crop. Slide 8 displays the first three strongest rows. The blog retains a larger crop. Extra explorer captures are retained for refinement, including the unrestricted calendar anomaly. Screenshot checksums and dimensions are in `screenshots.json`.

Report finalisation: `2026-10-03T11:38:23.520727Z`. Vocabulary term examples were generated 3 October; current queries were read 5 October. The API responses and screenshot capture occur at different moments. Rolling counters may differ slightly.
