You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f assigns validity studies, exact decision/evidence/outcome linkage, subgroup diagnostics, drift monitoring, selection utility and scientific adapters to workforce_validation. PRD P0 includes a validity-study registry and FR-007 requires registration linked to predictors, criteria, samples and decision-policy versions.
Protected truth still lacks the complete executable owner path: no integrated workforce-validation-api, validity-study application tables remain in the legacy foundation schema, no protected owner read/registration API exists, and the study header does not yet model explicit predictor/sample/decision-policy/analysis-protocol versions. This is a buyer-visible DDD/scientific gap, not permission to normalize direct public-schema SQL.
#235 starts directly from protected develop and consumes no mutable #63/#64/#65 source. Current exact head is dd95dd7256f37aab2c4f26aa1fb43e8c867f4e4d, open · Draft · mechanically mergeable.
The slice establishes services/workforce-validation-api, purpose-bound ValidityStudyReadPort ownership, structurally immutable persisted study/principal evidence, canonical Foundation 100% coverage admission, and a bounded-context-local migration history. #238 separates NOLOGIN schema ownership from runtime-role isolation. #239 reconstructs principal evidence before authorization. #240/#249 bind the exact validated repository capability across authorization. #241/#242/#245 make the minimized view immutable/data-only and remove ordinary unconditional issuance. #243/#244 remove retained UUID aliases and validate exact internal integer payloads. #253 rejects an inherited Protocol declaration as a non-concrete repository dependency. #254 admits the owner-schema PostgreSQL contract to both canonical Foundation inventories and the deterministic manifest. #255 closes the final exact-policy-field coverage branch on the current head.
A ValidityStudyView remains data, not a credential or cryptographic capability. Consequential downstream actions must re-authorize and re-resolve authoritative state; Python runtime construction is never authorization provenance.
Hosted evidence and current #255 acceptance — 2026-09-06
Predecessor 72ec2296... exposed #254: the owner-schema PostgreSQL contract was already executed by Foundation but absent from both canonical required-file inventories and therefore from the exact manifest path set. Ordinary repair 195ffef... → c91df237... → e87d28a32683c6e6f115b3d13645b7d263451795 admitted it to Node REQUIRED_FILES, Python REQUIRED, and resealed manifest.json without weakening workflow execution, schema behavior, coverage or exact-set validation.
Foundation 33981328157, Repository quality 101346954404, then actually ran exact e87d28a.... Exact-head proof, compile, runner validation, Foundation validation, dependency hygiene and #254 provenance checks passed. Candidate-evidence, HRIS-kernel, Keyverse, migration, Naruon, offer, requisition, selection, Job Analysis and People suites reached their required 100% statement/branch coverage. Workforce Validation executed 25/25 passing tests but failed at 99.04% because registry.py retained one uncovered fail-closed _detach_policy(...) branch: a permitted_fields frozenset containing a caller-defined string subtype must be rejected before authorization. PostgreSQL contracts were correctly skipped after that RED.
Issue #255 preserves this real hosted finding. Minimum ordinary successor dd95dd725... changes only test_policy_runtime_integrity.py: it makes the hostile string subtype hashable with ordinary str.__hash__ so it can inhabit the immutable field set, then proves the Workforce boundary rejects that non-exact field value before caller-defined equality/inequality behavior or persistence. Production authorization behavior, SQL, migrations, workflow, provenance inventories, manifest, PostgreSQL contracts and the 100% threshold remain unchanged.
Current exact-head Foundation 33986151272 is now terminal SUCCESS on dd95dd725...: exact checkout, compile, Foundation validation, dependency hygiene, all owned unit/service contracts, isolated PostgreSQL contracts and read-only repository validation passed. SAST Semgrep 33986151255 is also terminal SUCCESS. Security Scan 33986151270 is terminal FAILURE only at the shared Dependency Review support probe after exact-head verification; the pinned Dependency Review action is skipped while the public dependency comparison remains unavailable. CodeQL PR 33986151302 is terminal FAILURE only after both current-head compatibility jobs successfully request the central scan dispatch and fail at Release runner or enforce current-head CodeQL verdict. These are shared control-plane owner paths, not evidence of an Orgmetra source/SARIF defect, and must not be converted into leaf no-op churn or synthetic GREEN.
All currently returned #235 review threads are resolved, but submitted reviews remain COMMENTED-only with no qualifying independent non-author APPROVED review. #235 therefore remains Draft despite current owner-code/Foundation/PostgreSQL GREEN.
#248 remains stacked on mutable #235 at child exact d54d44d795444df572efbb301a667d74ac574d58 and recorded parent snapshot 656a0c41.... It moves the existing registry relation into workforce_validation with ALTER TABLE ... SET SCHEMA, preserves relation identity/FKs/forced RLS/bitemporal guard, introduces a distinct deny-default read runtime role, repairs the pre-existing case-validation trigger function in place so it no longer names stale public.validity_study, and adds a schema-qualified tenant-bound PostgreSQL read adapter. #250 structurally owns the accepted connection dependency, #251 repairs schema-qualified executable SQL embedded in the old trigger function, and #252 makes execution consume the exact tuple-stored connection capability rather than a subclass-overridable property.
#235 must integrate normally first. #248 then non-force adopts protected parent truth—including #249/#253/#254/#255—retargets to develop, preserves its own migration/adapter/#250/#251/#252 delta and reacquires exact-head 100% coverage, isolated PostgreSQL, security and independent review evidence. Mutable #235 source is not a valid dependency merely because GitHub's mechanical mergeability changes.
Add idempotent registration with actor/purpose/resource/provenance after owner persistence is protected truth.
Extend the aggregate for explicit predictor version, sampling design/frame, decision-policy version, analysis-plan/protocol provenance and immutable specialist-result references before predictive-validity/fairness claims.
Consume Psychometrics Commons / fast-mlsirm / TEPP only through released/versioned snapshot-analysis contracts.
Add versioned OpenAPI/gateway paths and realistic PostgreSQL-backed p95 ≤20 ms evidence only after the durable owner path exists.
Scientific authority and acceptance
ISO 10667-1:2020 remains the recorded client-side work-assessment service-delivery authority for this issue, with its next revision under ISO/AWI 10667-1. The registry therefore needs reconstructable rationale/use conditions, implementation/evaluation context, result access/use/storage governance, and validity/reliability/fairness/standardization evidence rather than a correlation-only dashboard.
Acceptance requires the canonical owner package; immutable/nested-alias-safe identity, persistence and output evidence; exact built-in policy/identity values before executable behavior; purpose-bound authorization; exact repository-capability identity; Protocol-stub rejection; exact-head 100% statement/branch coverage; executed owner-schema/ACL evidence; dual Node/Python provenance inventory plus deterministic manifest sealing for every executable Foundation PostgreSQL contract; idempotent registration with actor/purpose/resource/provenance; explicit predictor/criterion/sample/decision-policy/analysis protocol; versioned API/gateway; realistic p95 evidence; and code-current PRD/TRD/ARCHITECTURE/ERD/UML/TRACEABILITY/TEST_STRATEGY/baseline updates when those contracts become real.
Keep #234 open until the executable owner API, durable owner-schema/adoption path, registration path and scientific study-design contract are protected truth. Do not close it merely because source or acceptance-test code exists.
Live gap
Protected
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4fassigns validity studies, exact decision/evidence/outcome linkage, subgroup diagnostics, drift monitoring, selection utility and scientific adapters toworkforce_validation. PRD P0 includes a validity-study registry and FR-007 requires registration linked to predictors, criteria, samples and decision-policy versions.Protected truth still lacks the complete executable owner path: no integrated
workforce-validation-api, validity-study application tables remain in the legacy foundation schema, no protected owner read/registration API exists, and the study header does not yet model explicit predictor/sample/decision-policy/analysis-protocol versions. This is a buyer-visible DDD/scientific gap, not permission to normalize directpublic-schema SQL.Current owner slice — Draft #235
#235 starts directly from protected
developand consumes no mutable #63/#64/#65 source. Current exact head isdd95dd7256f37aab2c4f26aa1fb43e8c867f4e4d, open · Draft · mechanically mergeable.The slice establishes
services/workforce-validation-api, purpose-boundValidityStudyReadPortownership, structurally immutable persisted study/principal evidence, canonical Foundation 100% coverage admission, and a bounded-context-local migration history. #238 separates NOLOGIN schema ownership from runtime-role isolation. #239 reconstructs principal evidence before authorization. #240/#249 bind the exact validated repository capability across authorization. #241/#242/#245 make the minimized view immutable/data-only and remove ordinary unconditional issuance. #243/#244 remove retained UUID aliases and validate exact internal integer payloads. #253 rejects an inherited Protocol declaration as a non-concrete repository dependency. #254 admits the owner-schema PostgreSQL contract to both canonical Foundation inventories and the deterministic manifest. #255 closes the final exact-policy-field coverage branch on the current head.A
ValidityStudyViewremains data, not a credential or cryptographic capability. Consequential downstream actions must re-authorize and re-resolve authoritative state; Python runtime construction is never authorization provenance.Hosted evidence and current #255 acceptance — 2026-09-06
Predecessor
72ec2296...exposed #254: the owner-schema PostgreSQL contract was already executed by Foundation but absent from both canonical required-file inventories and therefore from the exact manifest path set. Ordinary repair195ffef... → c91df237... → e87d28a32683c6e6f115b3d13645b7d263451795admitted it to NodeREQUIRED_FILES, PythonREQUIRED, and resealedmanifest.jsonwithout weakening workflow execution, schema behavior, coverage or exact-set validation.Foundation
33981328157, Repository quality101346954404, then actually ran exacte87d28a.... Exact-head proof, compile, runner validation, Foundation validation, dependency hygiene and #254 provenance checks passed. Candidate-evidence, HRIS-kernel, Keyverse, migration, Naruon, offer, requisition, selection, Job Analysis and People suites reached their required 100% statement/branch coverage. Workforce Validation executed 25/25 passing tests but failed at 99.04% becauseregistry.pyretained one uncovered fail-closed_detach_policy(...)branch: apermitted_fieldsfrozenset containing a caller-defined string subtype must be rejected before authorization. PostgreSQL contracts were correctly skipped after that RED.Issue #255 preserves this real hosted finding. Minimum ordinary successor
dd95dd725...changes onlytest_policy_runtime_integrity.py: it makes the hostile string subtype hashable with ordinarystr.__hash__so it can inhabit the immutable field set, then proves the Workforce boundary rejects that non-exact field value before caller-defined equality/inequality behavior or persistence. Production authorization behavior, SQL, migrations, workflow, provenance inventories, manifest, PostgreSQL contracts and the 100% threshold remain unchanged.Current exact-head Foundation
33986151272is now terminal SUCCESS ondd95dd725...: exact checkout, compile, Foundation validation, dependency hygiene, all owned unit/service contracts, isolated PostgreSQL contracts and read-only repository validation passed. SAST Semgrep33986151255is also terminal SUCCESS. Security Scan33986151270is terminal FAILURE only at the shared Dependency Review support probe after exact-head verification; the pinned Dependency Review action is skipped while the public dependency comparison remains unavailable. CodeQL PR33986151302is terminal FAILURE only after both current-head compatibility jobs successfully request the central scan dispatch and fail atRelease runner or enforce current-head CodeQL verdict. These are shared control-plane owner paths, not evidence of an Orgmetra source/SARIF defect, and must not be converted into leaf no-op churn or synthetic GREEN.All currently returned #235 review threads are resolved, but submitted reviews remain COMMENTED-only with no qualifying independent non-author
APPROVEDreview. #235 therefore remains Draft despite current owner-code/Foundation/PostgreSQL GREEN.Durable persistence child — Draft #248
#248 remains stacked on mutable #235 at child exact
d54d44d795444df572efbb301a667d74ac574d58and recorded parent snapshot656a0c41.... It moves the existing registry relation intoworkforce_validationwithALTER TABLE ... SET SCHEMA, preserves relation identity/FKs/forced RLS/bitemporal guard, introduces a distinct deny-default read runtime role, repairs the pre-existing case-validation trigger function in place so it no longer names stalepublic.validity_study, and adds a schema-qualified tenant-bound PostgreSQL read adapter. #250 structurally owns the accepted connection dependency, #251 repairs schema-qualified executable SQL embedded in the old trigger function, and #252 makes execution consume the exact tuple-stored connection capability rather than a subclass-overridable property.#235 must integrate normally first. #248 then non-force adopts protected parent truth—including #249/#253/#254/#255—retargets to
develop, preserves its own migration/adapter/#250/#251/#252 delta and reacquires exact-head 100% coverage, isolated PostgreSQL, security and independent review evidence. Mutable #235 source is not a valid dependency merely because GitHub's mechanical mergeability changes.Canonical repair order
Scientific authority and acceptance
ISO 10667-1:2020 remains the recorded client-side work-assessment service-delivery authority for this issue, with its next revision under ISO/AWI 10667-1. The registry therefore needs reconstructable rationale/use conditions, implementation/evaluation context, result access/use/storage governance, and validity/reliability/fairness/standardization evidence rather than a correlation-only dashboard.
Acceptance requires the canonical owner package; immutable/nested-alias-safe identity, persistence and output evidence; exact built-in policy/identity values before executable behavior; purpose-bound authorization; exact repository-capability identity; Protocol-stub rejection; exact-head 100% statement/branch coverage; executed owner-schema/ACL evidence; dual Node/Python provenance inventory plus deterministic manifest sealing for every executable Foundation PostgreSQL contract; idempotent registration with actor/purpose/resource/provenance; explicit predictor/criterion/sample/decision-policy/analysis protocol; versioned API/gateway; realistic p95 evidence; and code-current PRD/TRD/ARCHITECTURE/ERD/UML/TRACEABILITY/TEST_STRATEGY/baseline updates when those contracts become real.
Keep #234 open until the executable owner API, durable owner-schema/adoption path, registration path and scientific study-design contract are protected truth. Do not close it merely because source or acceptance-test code exists.