Skip to content

Owner-only CFG-GOV follow-ups: Atlas custody runbook, corpus purge script (dry-run default), deploy notes - #29

Merged
Gio2050 merged 1 commit into
mainfrom
docs/cfg-gov-owner-runbooks
Aug 6, 2026
Merged

Gio2050 merged 1 commit into
mainfrom
docs/cfg-gov-owner-runbooks

Conversation

@Gio2050

@Gio2050 Gio2050 commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Prepares — and does not execute — the three owner-only items that complete the CFG-GOV slot work (afi-infra#28, afi-reactor#80, afi-config#80, all merged):

  1. docs/atlas-read-only-custody-runbook.md (D-CFG-2(3)): the exact Atlas users, roles, and per-database grants — afi-evidence-writer (sole canonical writer), afi-evidence-reader (verify cron + all readout tooling), afi-analytics-writer (outcome capture, no canonical grant) — plus post-cutover verification steps. This custody separation cannot be enforced from these repos; it is Atlas console work.
  2. scripts/purge-scored-corpus.mjs: clears the pre-CFG-GOV scored corpus (canonical scored_signal_evidence + _history) while HARD-KEEPING the observations — signal_outcomes and scoring_context (which carries the raw ingest payloads, rawUss, enabling offline re-scoring). Dry-run by default with exact per-collection before/after counts; acting requires --confirm-purge-scored-corpus; unknown arguments and keep-list names are refused. It has not been run (no database URI exists on the authoring machine; refusal paths proven without a connection).
  3. docs/cfg-gov-deploy-notes.md: what a deploy changes (records seal at admission; recordHash moves prospectively per D-EV3-4(6), documented under D-CFG-6; verify-on-read + re-verification cron; composition-scoped proofs; analytics compositionRef stamp) and why the purge must run BEFORE the deploy so the store is uniformly sealed from the first record forward.

Documentation and an unexecuted script only — no runtime surface, no schema, no test change.

Made with Cursor

…g executed)

- docs/atlas-read-only-custody-runbook.md — exact Atlas users/roles/grants
  for D-CFG-2(3) custody separation, per-consumer, with verification steps.
- scripts/purge-scored-corpus.mjs — owner corpus purge: dry-run by default,
  exact per-collection before/after counts, --confirm-purge-scored-corpus
  required to act, hard-refuses the keep-list (signal_outcomes and
  scoring_context, which carries the raw ingest payloads). NOT RUN.
- docs/cfg-gov-deploy-notes.md — behavioural deploy notes: records seal at
  admission, recordHash moves prospectively, purge BEFORE deploy so the
  store is uniformly sealed from the first record forward.

Co-authored-by: Cursor <cursoragent@cursor.com>
@cursor

cursor Bot commented Aug 6, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@kilo-code-bot

kilo-code-bot Bot commented Aug 6, 2026

Copy link
Copy Markdown

Kilo Code Review could not run — your account is out of credits.

Add credits or switch to a free model to enable reviews on this change.

@Gio2050
Gio2050 merged commit cf4d709 into main Aug 6, 2026
4 of 5 checks passed
@Gio2050
Gio2050 deleted the docs/cfg-gov-owner-runbooks branch August 6, 2026 02:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant