## Why Stage one removed final-answer fields from Executor, stage two added deterministic Gatekeeper checks, and stage three made Verifier claim-oriented. The remaining gap is final answer rendering: ChatService can still rely on temporary V2 rendering paths instead of a dedicated expression layer, which risks letting unverified Executor material shape user-facing answers. This phase introduces a Composer expression layer so final Chat answers are generated only from Verifier-allowed material. ## What Changes - Add a `chat_composer` final-answer generation step after Verifier. - Add a strict Composer prompt and JSON output contract with `answer_summary`, `recommended_actions`, and `user_facing_answer`. - Build Composer input in `ChatService` from filtered Verifier results: - `allowed_claims` - `allowed_hypotheses` - `missing_info` - `recommended_actions` - `rationale` - Ensure PASS, LOW_CONFID, and REJECT final answers no longer read Executor `user_facing_answer` or raw Executor JSON. - Persist Composer output in `diagnosis_session.self_evaluation.verifier_evaluation.composer_output`. - Add safe fallback templates for malformed Composer output that never expose raw Executor JSON or raw Composer JSON. ## Capabilities ### New Capabilities - `chat-composer-agent`: Final expression layer that turns Verifier-allowed structured material into a readable Chinese user answer without introducing new facts. ### Modified Capabilities - `chat-verifier-agent`: ChatService final routing changes so Verifier verdicts feed Composer or safe fixed templates instead of direct Executor answer paths. ## Impact - Affected prompt: add `src/main/resources/prompts/chat-composer-prompt.md`. - Affected service: `ChatService` final rendering after Verifier, Composer input assembly, Composer output parsing, malformed-output fallback. - Affected audit: `diagnosis_session.self_evaluation.verifier_evaluation` gains `composer_output`. - Affected tests: `ChatServiceSequentialAgentTest` and focused tests around Composer input filtering, final answer routing, and malformed Composer fallback. - Database schema: no table or column change. - External API: no endpoint contract change; final answer text semantics become stricter because unverified Executor material is no longer a source for user-visible answers. ## Non-Goals - No Planner changes. - No Gatekeeper rule expansion. - No Verifier classification changes. - No Executor retry behavior change. - No database migration. - No stage-five eval fixture expansion in this phase.