From eb1391f56265938e2d1775d2609612149bbec934 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 23 Aug 2026 06:35:04 -0700 Subject: [PATCH 001/201] docs: add product-technical gap baseline with current PR heads --- docs/product-technical-gap-baseline.md | 84 ++++++++++++++++++++++++++ 1 file changed, 84 insertions(+) create mode 100644 docs/product-technical-gap-baseline.md diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md new file mode 100644 index 000000000..687218284 --- /dev/null +++ b/docs/product-technical-gap-baseline.md @@ -0,0 +1,84 @@ +# Product and technical gap baseline + +Inventory date: 2026-08-23 (Asia/Seoul). Protected `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. + +Orgmetra owns employment truth (`organization_unit`, `assignment_record`, `person_record` bound to a Keyverse subject). IdP/SCIM issuance is Keyverse. Orgmetra pins `X-CWL-Tenant-Reference` to `tenant_record` and does not issue the header. Journal truth is AIS. Commercial collection is Billing. Measurement and delivery are Psychometrics. + +Next operator action: do not self-approve as `seonghobae`. Merge a Ready PR only when a non-author OpenCode APPROVE sits on that exact SHA and product/security checks on that SHA are terminal green. Treat 5-6s OpenCode/Noema jobs as stubs, not receipts. + +## What is already on protected develop + +| Merged PR | Capability | +|---|---| +| #26 | `validity_study_case_record` integrity (migration 0010) | +| #28 | Performance-criterion job-scope guard (migration 0011) | +| #31 | Governed People mutation API | +| #38 | Governed job-analysis snapshot persist/read | + +Do not revive those heads. + +## Open PRs included in this baseline + +All listed PRs are authored by `seonghobae`. Independent OpenCode APPROVE was not present on sampled Ready heads at inventory time. + +### Draft + +| PR | Head SHA | Branch | Intent | +|---|---|---|---| +| [#99](https://github.com/ContextualWisdomLab/Orgmetra/pull/99) | `09dc3135606669cdd60778db531cd3f6af34e171` | `feat/employment-compensation-core` | Employment-scoped bitemporal base compensation | +| [#82](https://github.com/ContextualWisdomLab/Orgmetra/pull/82) | `0c3a776f2e2c6f93c25e11c5c3ce3fa66a10b5c9` | `feat/outbox-retry-policy` | Outbox retry (base is not develop) | +| [#77](https://github.com/ContextualWisdomLab/Orgmetra/pull/77) | `9b02cb911377a5beb9f541e9acf2eb51ff065ee9` | `feat/hr-data-disposition-request` | HR data disposition (stacked on #76) | + +Keep Draft until product, Strix, CodeQL, and Semgrep are green on the exact SHA. + +### Ready on develop (factory queue) + +| Order | PR | Head SHA | Title | +|---:|---|---|---| +| 1 | [#97](https://github.com/ContextualWisdomLab/Orgmetra/pull/97) | `9715b06d0a459aed7f29293e02de8c2a452e2b87` | Bitemporal Position vacancy evidence | +| 2 | [#98](https://github.com/ContextualWisdomLab/Orgmetra/pull/98) | `9aeeb204acce429f85b028029c9531a5b05f37e1` | Governed HR document evidence | +| 3 | [#80](https://github.com/ContextualWisdomLab/Orgmetra/pull/80) | `2300c0a0605d89e58aa70ac04b0dee9a7d516882` | Candidate offer response evidence | +| 4 | [#81](https://github.com/ContextualWisdomLab/Orgmetra/pull/81) | `78a9cb1e047db5c79ca855b992d44749b9214992` | contextual-orchestrator draft evidence | +| 5 | [#94](https://github.com/ContextualWisdomLab/Orgmetra/pull/94) | `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc` | Bitemporal position reporting hierarchy | +| 6 | [#95](https://github.com/ContextualWisdomLab/Orgmetra/pull/95) | `adf055d79d188ba18d06ecf80dc1117858c987f4` | Position reporting-change review | +| 7 | [#96](https://github.com/ContextualWisdomLab/Orgmetra/pull/96) | `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd` | Organization hierarchy-change review | +| 8 | [#45](https://github.com/ContextualWisdomLab/Orgmetra/pull/45) | `e0af2501d540de48f7c0e0e3d09ac3e2e5417d2b` | Assignment change review packet | +| 9 | [#46](https://github.com/ContextualWisdomLab/Orgmetra/pull/46) | `595c190e30e499abea1284c7307ea0783ada1efd` | Employment separation review packet | +| 10 | [#44](https://github.com/ContextualWisdomLab/Orgmetra/pull/44) | `482d2970cf872cb6f0b4e15fb8805f8bbfd990ff` | Performance review packet | +| 11 | [#42](https://github.com/ContextualWisdomLab/Orgmetra/pull/42) | `9b871a3245671f0d14ea56e103ac0d9b91482d43` | Selection outcome monitoring plan | + +Also open on develop (re-verify head before acting): #93, #92, #91, #90, #53, #88, #87, #83, #86, #84, #85, #79, #78, #76, #75, #74, #73, #65, #56, #48, #47, #54. + +Sampled reviews: #97 and #98 have Devin COMMENT only. Combined status on #97 `9715b06` was success (CodeRabbit rate-limited). That is not an OpenCode receipt. + +## Buyer-facing gaps after the open queue + +Do not open withholding, payroll-pay, or year-end settlement tables or UI. + +1. Job-grade design screen against a persisted job-analysis snapshot (`job_grade_structure`, `job_grade_band`, Storybooked). +2. Job-analysis LLM draft assist via contextual-orchestrator and NVIDIA NIM. Human confirm before snapshot persist. +3. Offer-to-hire close: #80 response plus #31 mutation as one operator path. +4. Vacancy-to-assignment: #97 seat can be opened, filled, or frozen against `assignment_record`. +5. Purpose-bound document retrieve/export for #98 (audit, no PII masking). +6. Storybook, design tokens, and a Figma file id in an ADR for any new screen. +7. Ecosystem only: consume Keyverse subject; emit assignment keys to Psychometrics; emit compensation proposals to AIS after a portal role code exists. Do not own statutory accounts. + +## Technical non-negotiables + +- 100% docstring and coverage on new modules; realistic cases (round-trip persist, not status 200 only). +- Database objects: two-or-more-word snake_case, 3NF, tenant plus recorded-time keys against hot partitions. +- Purpose-bound authorization, encryption, retention, audit. +- CSAP and SOC 2 on every write path. +- Modular MSA. Split the repo if it becomes a monolith. +- Failed Checks: fix on the failing SHA. Review wait is not a stop. + +## Loop + +Hourly: inventory open PRs, review, fix real defects, re-verify exact-head checks, merge only with non-author OpenCode APPROVE, then the next gap from this file. Refresh this document when a listed SHA moves or a PR merges. + +## Doctoring (APA 7th) + +Equal Employment Opportunity Commission. (1978). Uniform guidelines on employee selection procedures (29 C.F.R. Part 1607). +Society for Industrial and Organizational Psychology. (2018). Principles for the validation and use of personnel selection procedures (5th ed.). +International Organization for Standardization. (2018). ISO 30414: Human resource management — Guidelines for internal and external human capital reporting. +American Educational Research Association, American Psychological Association, and National Council on Measurement in Education. (2014). Standards for educational and psychological testing. From d1ae16efcfa03c1a21c0ca9d0a91dcfdfa456a89 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 23 Aug 2026 08:02:55 -0700 Subject: [PATCH 002/201] fix(docs): align product gap baseline with protected truth --- docs/product-technical-gap-baseline.md | 126 ++++++++++++++----------- 1 file changed, 71 insertions(+), 55 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 687218284..2714edb78 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,83 +2,99 @@ Inventory date: 2026-08-23 (Asia/Seoul). Protected `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -Orgmetra owns employment truth (`organization_unit`, `assignment_record`, `person_record` bound to a Keyverse subject). IdP/SCIM issuance is Keyverse. Orgmetra pins `X-CWL-Tenant-Reference` to `tenant_record` and does not issue the header. Journal truth is AIS. Commercial collection is Billing. Measurement and delivery are Psychometrics. +This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, branch-protection truth, or a substitute for fresh GitHub state. Every execution loop must refetch all open PRs/issues, exact heads and bases, stacks, reviews/threads, applicable exact-head workflows, and effective repository rules before acting. -Next operator action: do not self-approve as `seonghobae`. Merge a Ready PR only when a non-author OpenCode APPROVE sits on that exact SHA and product/security checks on that SHA are terminal green. Treat 5-6s OpenCode/Noema jobs as stubs, not receipts. +Orgmetra owns authoritative HRIS employment truth inside its published boundaries. Keyverse remains the read-only identity owner through its published OIDC/SCIM contracts. For the currently published People mutation API, the tenant header is `X-Tenant-Reference`; the ASGI implementation normalizes HTTP header names to lower case before parsing it and binds it to the authoritative tenant UUID. Orgmetra does not invent or issue a foreign identity-provider subject. -## What is already on protected develop +Finance/accounting journal ownership and commercial billing/collection ownership are **not accepted Orgmetra architecture in this snapshot**. Treat those integrations as planned/out-of-scope until an owner contract is published and accepted into Orgmetra's canonical architecture/traceability. Psychometrics Commons and other dedicated-writer CWL repositories remain read-only dependencies consumed only through their published contracts. + +Next operator action: do not self-approve. Process the live open-PR graph oldest/dependency-root first. Merge only an unchanged exact head after every applicable current-head gate is terminal GREEN, required conversations are resolved, qualifying independent non-author approval is present, and `develop` has actually enforceable protection. Short-lived model/status checks are not substitutes for those gates unless the live repository policy explicitly makes them qualifying evidence. + +## Merged buyer-visible anchors on protected develop + +This table is a selected set of shipped anchors relevant to the current buyer-gap analysis, not a replacement for Git history. | Merged PR | Capability | |---|---| | #26 | `validity_study_case_record` integrity (migration 0010) | -| #28 | Performance-criterion job-scope guard (migration 0011) | +| #28 | Performance-criterion Job-scope guard (migration 0011) | | #31 | Governed People mutation API | -| #38 | Governed job-analysis snapshot persist/read | +| #38 | Governed Job Analysis snapshot persist/read | +| #41 | Governed candidate evidence intake | +| #43 | Governed offer approval packet | -Do not revive those heads. +Do not revive those merged heads. Extend protected truth through a new owner-scoped change only when a fresh buyer gap still exists. -## Open PRs included in this baseline +## Open-PR snapshot -All listed PRs are authored by `seonghobae`. Independent OpenCode APPROVE was not present on sampled Ready heads at inventory time. +The entries below are useful anchors only. They are intentionally not an authoritative or exhaustive queue; live execution order comes from a fresh GitHub graph and remains oldest/dependency-root first. -### Draft +### Draft / dependency-constrained examples -| PR | Head SHA | Branch | Intent | +| PR | Head SHA | Branch | Current snapshot reason | |---|---|---|---| -| [#99](https://github.com/ContextualWisdomLab/Orgmetra/pull/99) | `09dc3135606669cdd60778db531cd3f6af34e171` | `feat/employment-compensation-core` | Employment-scoped bitemporal base compensation | -| [#82](https://github.com/ContextualWisdomLab/Orgmetra/pull/82) | `0c3a776f2e2c6f93c25e11c5c3ce3fa66a10b5c9` | `feat/outbox-retry-policy` | Outbox retry (base is not develop) | -| [#77](https://github.com/ContextualWisdomLab/Orgmetra/pull/77) | `9b02cb911377a5beb9f541e9acf2eb51ff065ee9` | `feat/hr-data-disposition-request` | HR data disposition (stacked on #76) | - -Keep Draft until product, Strix, CodeQL, and Semgrep are green on the exact SHA. - -### Ready on develop (factory queue) - -| Order | PR | Head SHA | Title | -|---:|---|---|---| -| 1 | [#97](https://github.com/ContextualWisdomLab/Orgmetra/pull/97) | `9715b06d0a459aed7f29293e02de8c2a452e2b87` | Bitemporal Position vacancy evidence | -| 2 | [#98](https://github.com/ContextualWisdomLab/Orgmetra/pull/98) | `9aeeb204acce429f85b028029c9531a5b05f37e1` | Governed HR document evidence | -| 3 | [#80](https://github.com/ContextualWisdomLab/Orgmetra/pull/80) | `2300c0a0605d89e58aa70ac04b0dee9a7d516882` | Candidate offer response evidence | -| 4 | [#81](https://github.com/ContextualWisdomLab/Orgmetra/pull/81) | `78a9cb1e047db5c79ca855b992d44749b9214992` | contextual-orchestrator draft evidence | -| 5 | [#94](https://github.com/ContextualWisdomLab/Orgmetra/pull/94) | `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc` | Bitemporal position reporting hierarchy | -| 6 | [#95](https://github.com/ContextualWisdomLab/Orgmetra/pull/95) | `adf055d79d188ba18d06ecf80dc1117858c987f4` | Position reporting-change review | -| 7 | [#96](https://github.com/ContextualWisdomLab/Orgmetra/pull/96) | `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd` | Organization hierarchy-change review | -| 8 | [#45](https://github.com/ContextualWisdomLab/Orgmetra/pull/45) | `e0af2501d540de48f7c0e0e3d09ac3e2e5417d2b` | Assignment change review packet | -| 9 | [#46](https://github.com/ContextualWisdomLab/Orgmetra/pull/46) | `595c190e30e499abea1284c7307ea0783ada1efd` | Employment separation review packet | -| 10 | [#44](https://github.com/ContextualWisdomLab/Orgmetra/pull/44) | `482d2970cf872cb6f0b4e15fb8805f8bbfd990ff` | Performance review packet | -| 11 | [#42](https://github.com/ContextualWisdomLab/Orgmetra/pull/42) | `9b871a3245671f0d14ea56e103ac0d9b91482d43` | Selection outcome monitoring plan | - -Also open on develop (re-verify head before acting): #93, #92, #91, #90, #53, #88, #87, #83, #86, #84, #85, #79, #78, #76, #75, #74, #73, #65, #56, #48, #47, #54. - -Sampled reviews: #97 and #98 have Devin COMMENT only. Combined status on #97 `9715b06` was success (CodeRabbit rate-limited). That is not an OpenCode receipt. +| [#99](https://github.com/ContextualWisdomLab/Orgmetra/pull/99) | `09dc3135606669cdd60778db531cd3f6af34e171` | `feat/employment-compensation-core` | Draft in fresh GitHub state; do not infer readiness from its body | +| [#82](https://github.com/ContextualWisdomLab/Orgmetra/pull/82) | `0c3a776f2e2c6f93c25e11c5c3ce3fa66a10b5c9` | `feat/outbox-retry-policy` | Stacked on #51; dependency-first | +| [#77](https://github.com/ContextualWisdomLab/Orgmetra/pull/77) | `9b02cb911377a5beb9f541e9acf2eb51ff065ee9` | `feat/hr-data-disposition-request` | Stacked on #76; dependency-first | +| [#67](https://github.com/ContextualWisdomLab/Orgmetra/pull/67) | `cf59b3001fa58e5a978099c2a5692a03f4849fdd` | `feat/candidate-withdrawal-governance` | Stacked on #66; dependency-first | +| [#58](https://github.com/ContextualWisdomLab/Orgmetra/pull/58) | `c79a6ed49627e6a47947f171aeeed2bf02a8c152` | `build/validation-analysis-reproducibility` | Stacked on #57; dependency-first | + +Keep a PR Draft whenever any applicable exact-current-head required workflow is absent, queued, pending, cancelled, skipped-required, neutral, failed, or stale; when a valid defect remains unresolved; or when its stack dependency has not integrated. Do not transfer predecessor checks or reviews. + +### Ready-for-review examples on develop + +These are snapshot examples only; re-fetch each head, base, review state, threads, workflows, and effective repository rules before acting. + +| PR | Head SHA | Capability | +|---|---|---| +| [#40](https://github.com/ContextualWisdomLab/Orgmetra/pull/40) | `8d8896b14db10a5a4981f0b9e209ea00ee3be64c` | Governed structured interview plan | +| [#42](https://github.com/ContextualWisdomLab/Orgmetra/pull/42) | `9b871a3245671f0d14ea56e103ac0d9b91482d43` | Selection outcome monitoring plan | +| [#44](https://github.com/ContextualWisdomLab/Orgmetra/pull/44) | `482d2970cf872cb6f0b4e15fb8805f8bbfd990ff` | Performance review packet | +| [#45](https://github.com/ContextualWisdomLab/Orgmetra/pull/45) | `e0af2501d540de48f7c0e0e3d09ac3e2e5417d2b` | Assignment change review packet | +| [#46](https://github.com/ContextualWisdomLab/Orgmetra/pull/46) | `595c190e30e499abea1284c7307ea0783ada1efd` | Employment separation review packet | +| [#80](https://github.com/ContextualWisdomLab/Orgmetra/pull/80) | `2300c0a0605d89e58aa70ac04b0dee9a7d516882` | Candidate offer response evidence | +| [#81](https://github.com/ContextualWisdomLab/Orgmetra/pull/81) | `78a9cb1e047db5c79ca855b992d44749b9214992` | Contextual Orchestrator draft evidence | +| [#94](https://github.com/ContextualWisdomLab/Orgmetra/pull/94) | `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc` | Bitemporal Position reporting hierarchy | +| [#95](https://github.com/ContextualWisdomLab/Orgmetra/pull/95) | `adf055d79d188ba18d06ecf80dc1117858c987f4` | Position reporting-change review | +| [#96](https://github.com/ContextualWisdomLab/Orgmetra/pull/96) | `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd` | Organization hierarchy-change review | +| [#97](https://github.com/ContextualWisdomLab/Orgmetra/pull/97) | `9715b06d0a459aed7f29293e02de8c2a452e2b87` | Bitemporal Position vacancy evidence | +| [#98](https://github.com/ContextualWisdomLab/Orgmetra/pull/98) | `9aeeb204acce429f85b028029c9531a5b05f37e1` | Governed HR document evidence | + +Many other open roots exist. Never use this table to skip an older root or an independently actionable lane. ## Buyer-facing gaps after the open queue -Do not open withholding, payroll-pay, or year-end settlement tables or UI. +Do not open withholding, payroll-pay, statutory accounting, or year-end settlement tables/UI inside Orgmetra without an accepted owner boundary. -1. Job-grade design screen against a persisted job-analysis snapshot (`job_grade_structure`, `job_grade_band`, Storybooked). -2. Job-analysis LLM draft assist via contextual-orchestrator and NVIDIA NIM. Human confirm before snapshot persist. -3. Offer-to-hire close: #80 response plus #31 mutation as one operator path. -4. Vacancy-to-assignment: #97 seat can be opened, filled, or frozen against `assignment_record`. -5. Purpose-bound document retrieve/export for #98 (audit, no PII masking). -6. Storybook, design tokens, and a Figma file id in an ADR for any new screen. -7. Ecosystem only: consume Keyverse subject; emit assignment keys to Psychometrics; emit compensation proposals to AIS after a portal role code exists. Do not own statutory accounts. +1. Job-grade design against a persisted Job Analysis snapshot, with a normalized grade/band model and accessible Storybooked interaction. +2. Job-analysis LLM draft assistance through Contextual Orchestrator/NVIDIA NIM, with semantic-unit provenance and mandatory human confirmation before snapshot persistence. +3. Offer-to-hire close: connect governed candidate offer response to the authoritative confirmed-hire mutation path without turning response evidence into hire authority. +4. Vacancy-to-assignment: let an authorized operator fill/freeze a staffable Position through authoritative Assignment truth, preserving bitemporal and audit/outbox evidence. +5. Purpose-bound document retrieve/export for governed HR document evidence with field minimization, retention/export controls, and immutable audit rather than indiscriminate masking. +6. For new buyer-visible screens, maintain Storybook, design tokens, accessibility evidence, wireframes, and a governed Figma/Product Design handoff when material. +7. External finance/accounting or billing integration remains planned until a published owner API/event contract is accepted; Orgmetra must not create statutory-account truth or direct cross-service application-table SQL. ## Technical non-negotiables -- 100% docstring and coverage on new modules; realistic cases (round-trip persist, not status 200 only). -- Database objects: two-or-more-word snake_case, 3NF, tenant plus recorded-time keys against hot partitions. -- Purpose-bound authorization, encryption, retention, audit. -- CSAP and SOC 2 on every write path. -- Modular MSA. Split the repo if it becomes a monolith. -- Failed Checks: fix on the failing SHA. Review wait is not a stop. +- Exact 100% owned production statement/branch coverage where tooling exposes it, plus beginner-readable public docs/docstrings and realistic round-trip/security/privacy/concurrency/recovery cases. +- Database objects use descriptive two-or-more-word `snake_case`, 3NF by default, tenant/context isolation, opaque public IDs, and distinct business/effective versus system-recorded time. +- Job, Position, and Assignment remain separate authoritative concepts. +- Necessary PII stays usable only through purpose-bound authorization, least privilege, field minimization, encryption, retention/export controls, and immutable audit evidence. +- High-impact employment decisions require explicit accountable human confirmation with actor/purpose/reason/evidence versioning; LLM output remains untrusted draft evidence only. +- Design write paths toward CSAP and SOC 2 evidence readiness without claiming certification. +- Preserve modular MSA extraction boundaries; do not introduce direct cross-service application-table SQL. +- Failed checks are repair triggers at the first causal owner boundary. Review wait on one lane never blocks independent Orgmetra work. -## Loop +## Execution loop -Hourly: inventory open PRs, review, fix real defects, re-verify exact-head checks, merge only with non-author OpenCode APPROVE, then the next gap from this file. Refresh this document when a listed SHA moves or a PR merges. +Each run: refetch protected `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, reviews/threads, exact-head workflows and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects test-first when practicable; rerun exact-head evidence; resolve only addressed threads; and merge only with qualifying independent non-author approval plus actually enforceable protection. Refresh this document only as a snapshot after material state changes; never treat its recorded SHAs as current truth. ## Doctoring (APA 7th) -Equal Employment Opportunity Commission. (1978). Uniform guidelines on employee selection procedures (29 C.F.R. Part 1607). -Society for Industrial and Organizational Psychology. (2018). Principles for the validation and use of personnel selection procedures (5th ed.). -International Organization for Standardization. (2018). ISO 30414: Human resource management — Guidelines for internal and external human capital reporting. -American Educational Research Association, American Psychological Association, and National Council on Measurement in Education. (2014). Standards for educational and psychological testing. +Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee selection procedures* (29 C.F.R. Part 1607). + +Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). + +International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management — Requirements and recommendations for human capital reporting and disclosure*. ISO. + +American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. From 3a0fd199b1863a4fb1bf71dd6d260689e96dc653 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 00:53:04 +0900 Subject: [PATCH 003/201] docs: record 2026-08-24 loop findings and PR anchors in gap baseline --- docs/product-technical-gap-baseline.md | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2714edb78..f17d3bd4d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product and technical gap baseline -Inventory date: 2026-08-23 (Asia/Seoul). Protected `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Inventory date: 2026-08-24 (Asia/Seoul), superseding the 2026-08-23 snapshot. Protected `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, branch-protection truth, or a substitute for fresh GitHub state. Every execution loop must refetch all open PRs/issues, exact heads and bases, stacks, reviews/threads, applicable exact-head workflows, and effective repository rules before acting. @@ -10,6 +10,13 @@ Finance/accounting journal ownership and commercial billing/collection ownership Next operator action: do not self-approve. Process the live open-PR graph oldest/dependency-root first. Merge only an unchanged exact head after every applicable current-head gate is terminal GREEN, required conversations are resolved, qualifying independent non-author approval is present, and `develop` has actually enforceable protection. Short-lived model/status checks are not substitutes for those gates unless the live repository policy explicitly makes them qualifying evidence. +## 2026-08-24 execution-loop findings + +1. **Strix failures were infrastructure, not source defects.** Every `strix` check failure on open PRs traced to NVIDIA NIM `429 Too Many Requests` during the scanner's LLM connection phase (three primary-model attempts plus fallback exhausted, no report artifact, fail-closed). Local exact-head verification of #97, #98, #99, #102, #103, #104, and #95 reproduced all owned package suites green at 100% statement/branch coverage; the scan lane, not the code, was failing. Remediation: same-head re-scan dispatch plus a draft/ready toggle per affected PR to re-fire the required-workflow context without moving any head SHA. +2. **Org review-dispatch budget was zero.** The organization variable `ORG_SWEEP_REVIEW_DISPATCH_LIMIT` was set to `0`, so the hourly/quarter-hourly org queue sweep could never dispatch an OpenCode review for any repository, leaving every PR approved-blocked on "review dispatch limit reached". Fixed by restoring the limit to `2` (and `ORG_SWEEP_BRANCH_UPDATE_LIMIT` to `1`) and adding `ContextualWisdomLab/Orgmetra` to the central repository's targeted-dispatch allowlist. This is recorded so future zero-review stalls are diagnosed against this variable first. +3. **Queue congestion is real but not a defect.** Org-wide hosted-runner saturation (hundreds of queued runs across sibling repositories) delays evidence materialization for hours. Waiting is not blocked work: local verification, documentation refresh, and independent lanes continue while hosted evidence catches up. + + ## Merged buyer-visible anchors on protected develop This table is a selected set of shipped anchors relevant to the current buyer-gap analysis, not a replacement for Git history. @@ -74,6 +81,10 @@ Do not open withholding, payroll-pay, statutory accounting, or year-end settleme 6. For new buyer-visible screens, maintain Storybook, design tokens, accessibility evidence, wireframes, and a governed Figma/Product Design handoff when material. 7. External finance/accounting or billing integration remains planned until a published owner API/event contract is accepted; Orgmetra must not create statutory-account truth or direct cross-service application-table SQL. +## Open PRs observed 2026-08-24 (anchors, not authority) + +Fifty open PRs were observed. New roots since the previous snapshot include #52 (TEPP analysis adapter), #54 (workforce composition change), #55 (People read hardening), #56 (Organization hierarchy snapshot), #57 (validity analysis handoff), #59-#65 (recorded-time/runtime-integrity repairs), #66 (normalized candidate application), #68 (Naruon calendar integrity), #69-#73 (bitemporal/correction/chronology hardening), #74 (People operability probes), #75/#76/#77 (HR data export/retention/disposition governance), #78 (SBOM/provenance release evidence), #79 (Kubernetes reference deployment), #90 (People HTTP telemetry), #91-#96 (privacy/performance/reporting/hierarchy evidence lanes), #100 (this document), #102-#104 (audit/work-capacity/qualification-rule reviews), #110 (vacancy fill orchestration, draft), #111 (Position lifecycle review), #112 (lifecycle application, stacked draft). Stacks remain dependency-first: #105→#104, #106→#94, #107→#98, #108→#80, #109→#101, #112→#111, #77→#76, #67→#66, #58→#57. + ## Technical non-negotiables - Exact 100% owned production statement/branch coverage where tooling exposes it, plus beginner-readable public docs/docstrings and realistic round-trip/security/privacy/concurrency/recovery cases. From bc4eee3bf859ceabd87818e1a800daefbfd50b18 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 24 Aug 2026 13:05:24 -0700 Subject: [PATCH 004/201] docs: refresh product gap baseline to live Orgmetra state --- docs/product-technical-gap-baseline.md | 150 ++++++++++++++----------- 1 file changed, 85 insertions(+), 65 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f17d3bd4d..0f700a28e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,111 +1,131 @@ # Product and technical gap baseline -Inventory date: 2026-08-24 (Asia/Seoul), superseding the 2026-08-23 snapshot. Protected `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Inventory date: 2026-08-25 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, branch-protection truth, or a substitute for fresh GitHub state. Every execution loop must refetch all open PRs/issues, exact heads and bases, stacks, reviews/threads, applicable exact-head workflows, and effective repository rules before acting. +This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, branch-protection truth, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and bases, dependency ancestry, reviews/threads, exact-head workflows, effective repository rules, releases, and changed refs before acting. -Orgmetra owns authoritative HRIS employment truth inside its published boundaries. Keyverse remains the read-only identity owner through its published OIDC/SCIM contracts. For the currently published People mutation API, the tenant header is `X-Tenant-Reference`; the ASGI implementation normalizes HTTP header names to lower case before parsing it and binds it to the authoritative tenant UUID. Orgmetra does not invent or issue a foreign identity-provider subject. +Orgmetra owns authoritative HRIS employment truth inside its published boundaries. Keyverse and other dedicated-writer CWL repositories remain read-only dependencies consumed only through published package/API/event contracts and existing owner-control paths. No static product-gap document may authorize a write into another dedicated-writer repository. -Finance/accounting journal ownership and commercial billing/collection ownership are **not accepted Orgmetra architecture in this snapshot**. Treat those integrations as planned/out-of-scope until an owner contract is published and accepted into Orgmetra's canonical architecture/traceability. Psychometrics Commons and other dedicated-writer CWL repositories remain read-only dependencies consumed only through their published contracts. +## Repository-control truth -Next operator action: do not self-approve. Process the live open-PR graph oldest/dependency-root first. Merge only an unchanged exact head after every applicable current-head gate is terminal GREEN, required conversations are resolved, qualifying independent non-author approval is present, and `develop` has actually enforceable protection. Short-lived model/status checks are not substitutes for those gates unless the live repository policy explicitly makes them qualifying evidence. +GitHub currently reports `develop` as `protected: true`, but the effective branch-protection payload observed for the same branch has `protection.enabled=false`, required-status enforcement `off`, and no required contexts/checks. Issue #89 owns that repository-settings defect. -## 2026-08-24 execution-loop findings +Consequences: -1. **Strix failures were infrastructure, not source defects.** Every `strix` check failure on open PRs traced to NVIDIA NIM `429 Too Many Requests` during the scanner's LLM connection phase (three primary-model attempts plus fallback exhausted, no report artifact, fail-closed). Local exact-head verification of #97, #98, #99, #102, #103, #104, and #95 reproduced all owned package suites green at 100% statement/branch coverage; the scan lane, not the code, was failing. Remediation: same-head re-scan dispatch plus a draft/ready toggle per affected PR to re-fire the required-workflow context without moving any head SHA. -2. **Org review-dispatch budget was zero.** The organization variable `ORG_SWEEP_REVIEW_DISPATCH_LIMIT` was set to `0`, so the hourly/quarter-hourly org queue sweep could never dispatch an OpenCode review for any repository, leaving every PR approved-blocked on "review dispatch limit reached". Fixed by restoring the limit to `2` (and `ORG_SWEEP_BRANCH_UPDATE_LIMIT` to `1`) and adding `ContextualWisdomLab/Orgmetra` to the central repository's targeted-dispatch allowlist. This is recorded so future zero-review stalls are diagnosed against this variable first. -3. **Queue congestion is real but not a defect.** Org-wide hosted-runner saturation (hundreds of queued runs across sibling repositories) delays evidence materialization for hours. Waiting is not blocked work: local verification, documentation refresh, and independent lanes continue while hosted evidence catches up. +- a GREEN PR is not merge-authorized merely because GitHub computes it as mergeable; +- qualifying independent non-author approval is still required where the repository governance contract requires it; +- no workflow shim, author approval, predecessor check, model-only status, or manual force merge substitutes for enforceable branch protection; +- immediately before any future merge, refetch the unchanged exact head, independently resolved live base, reviews, unresolved threads, effective rules/protection, and every applicable exact-head check. +## Merged buyer-visible anchors on `develop` -## Merged buyer-visible anchors on protected develop - -This table is a selected set of shipped anchors relevant to the current buyer-gap analysis, not a replacement for Git history. +This is a selected shipped inventory, not a replacement for Git history. | Merged PR | Capability | |---|---| -| #26 | `validity_study_case_record` integrity (migration 0010) | -| #28 | Performance-criterion Job-scope guard (migration 0011) | +| #26 | `validity_study_case_record` integrity | +| #28 | Performance-criterion Job-scope guard | | #31 | Governed People mutation API | -| #38 | Governed Job Analysis snapshot persist/read | +| #38 | Governed Job Analysis snapshot persistence/read | | #41 | Governed candidate evidence intake | | #43 | Governed offer approval packet | -Do not revive those merged heads. Extend protected truth through a new owner-scoped change only when a fresh buyer gap still exists. +Do not revive these merged heads. Extend default-branch truth only through a current owner-scoped change when a fresh buyer gap remains. + +## Live open-PR control snapshot -## Open-PR snapshot +The repository currently has 68 open PRs. The examples below are anchors only; execution order comes from a fresh oldest/dependency-root-first graph. -The entries below are useful anchors only. They are intentionally not an authoritative or exhaustive queue; live execution order comes from a fresh GitHub graph and remains oldest/dependency-root first. +### Oldest root gate -### Draft / dependency-constrained examples +PR #40 (`8d8896b14db10a5a4981f0b9e209ea00ee3be64c`) is open, non-draft and mergeable. Structured Interview Plan, Foundation, SAST, Security, and Recovery are terminal GREEN on that exact head. Fresh reviews are COMMENTED only and the remaining unresolved threads are informational. It still has no qualifying independent non-author `APPROVE`, and issue #89's protection defect remains open, so it is intentionally unmerged. -| PR | Head SHA | Branch | Current snapshot reason | -|---|---|---|---| -| [#99](https://github.com/ContextualWisdomLab/Orgmetra/pull/99) | `09dc3135606669cdd60778db531cd3f6af34e171` | `feat/employment-compensation-core` | Draft in fresh GitHub state; do not infer readiness from its body | -| [#82](https://github.com/ContextualWisdomLab/Orgmetra/pull/82) | `0c3a776f2e2c6f93c25e11c5c3ce3fa66a10b5c9` | `feat/outbox-retry-policy` | Stacked on #51; dependency-first | -| [#77](https://github.com/ContextualWisdomLab/Orgmetra/pull/77) | `9b02cb911377a5beb9f541e9acf2eb51ff065ee9` | `feat/hr-data-disposition-request` | Stacked on #76; dependency-first | -| [#67](https://github.com/ContextualWisdomLab/Orgmetra/pull/67) | `cf59b3001fa58e5a978099c2a5692a03f4849fdd` | `feat/candidate-withdrawal-governance` | Stacked on #66; dependency-first | -| [#58](https://github.com/ContextualWisdomLab/Orgmetra/pull/58) | `c79a6ed49627e6a47947f171aeeed2bf02a8c152` | `build/validation-analysis-reproducibility` | Stacked on #57; dependency-first | +### Dependency-constrained Draft descendants -Keep a PR Draft whenever any applicable exact-current-head required workflow is absent, queued, pending, cancelled, skipped-required, neutral, failed, or stale; when a valid defect remains unresolved; or when its stack dependency has not integrated. Do not transfer predecessor checks or reviews. +These descendants remain Draft. Lane-local GREEN evidence is not integrated protected-base evidence and parent checks/reviews do not transfer. + +| PR | Exact child head | Dependency | +|---|---|---| +| #58 | `c79a6ed49627e6a47947f171aeeed2bf02a8c152` | #57 | +| #67 | `cf59b3001fa58e5a978099c2a5692a03f4849fdd` | #66 | +| #77 | `9b02cb911377a5beb9f541e9acf2eb51ff065ee9` | #76 | +| #82 | `0c3a776f2e2c6f93c25e11c5c3ce3fa66a10b5c9` | #51 | +| #105 | `168f19402b3b17762cfe60f8a0e93c649a082989` | #104 | +| #106 | `c35ad114edbce7a4ebafcea793748493f1346351` | #94 | +| #107 | `5e521fd829de313a037f45ac28227c2ae5362d37` | #98 | +| #108 | `5027c772e5588b33e953258de008f0253389e95c` | #80 | +| #109 | `1eb17d1dbfa2ec822a9c6cce52d8a92b19ed9353` | #101 | +| #112 | `4f2a003769bf8f773559ac8122702f1451f0e8c0` | #111 | -### Ready-for-review examples on develop +Do not restack these descendants merely to manufacture fresh evidence while their parents remain unintegrated. After a parent integrates, retarget/reconcile the child against the then-current `develop`, refetch the resulting exact head/base/conflict state, and rerun all applicable Foundation/SAST/Security/Recovery/product gates without transferring predecessor evidence. -These are snapshot examples only; re-fetch each head, base, review state, threads, workflows, and effective repository rules before acting. +### Selected current root capabilities -| PR | Head SHA | Capability | +The following are current open-root anchors with terminal exact-head GREEN evidence and are useful for product-gap reasoning. They remain unmerged pending live governance gates. + +| PR | Exact head | Capability | |---|---|---| -| [#40](https://github.com/ContextualWisdomLab/Orgmetra/pull/40) | `8d8896b14db10a5a4981f0b9e209ea00ee3be64c` | Governed structured interview plan | -| [#42](https://github.com/ContextualWisdomLab/Orgmetra/pull/42) | `9b871a3245671f0d14ea56e103ac0d9b91482d43` | Selection outcome monitoring plan | -| [#44](https://github.com/ContextualWisdomLab/Orgmetra/pull/44) | `482d2970cf872cb6f0b4e15fb8805f8bbfd990ff` | Performance review packet | -| [#45](https://github.com/ContextualWisdomLab/Orgmetra/pull/45) | `e0af2501d540de48f7c0e0e3d09ac3e2e5417d2b` | Assignment change review packet | -| [#46](https://github.com/ContextualWisdomLab/Orgmetra/pull/46) | `595c190e30e499abea1284c7307ea0783ada1efd` | Employment separation review packet | -| [#80](https://github.com/ContextualWisdomLab/Orgmetra/pull/80) | `2300c0a0605d89e58aa70ac04b0dee9a7d516882` | Candidate offer response evidence | -| [#81](https://github.com/ContextualWisdomLab/Orgmetra/pull/81) | `78a9cb1e047db5c79ca855b992d44749b9214992` | Contextual Orchestrator draft evidence | -| [#94](https://github.com/ContextualWisdomLab/Orgmetra/pull/94) | `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc` | Bitemporal Position reporting hierarchy | -| [#95](https://github.com/ContextualWisdomLab/Orgmetra/pull/95) | `adf055d79d188ba18d06ecf80dc1117858c987f4` | Position reporting-change review | -| [#96](https://github.com/ContextualWisdomLab/Orgmetra/pull/96) | `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd` | Organization hierarchy-change review | -| [#97](https://github.com/ContextualWisdomLab/Orgmetra/pull/97) | `9715b06d0a459aed7f29293e02de8c2a452e2b87` | Bitemporal Position vacancy evidence | -| [#98](https://github.com/ContextualWisdomLab/Orgmetra/pull/98) | `9aeeb204acce429f85b028029c9531a5b05f37e1` | Governed HR document evidence | +| #53 | `43ae3c73c0abef8f23d1c14f4e41d25b8c9b14df` | Evidence-centered HR workspace / Storybook slice | +| #75 | `282ff0966add47a80a2edd76f84c4c65a868fedb` | Governed HR data-export review | +| #80 | `5070f34cd13814f09d74162347f837cb34d76a57` | Candidate offer-response evidence | +| #81 | `78a9cb1e047db5c79ca855b992d44749b9214992` | Contextual Orchestrator draft-evidence boundary | +| #98 | `9aeeb204acce429f85b028029c9531a5b05f37e1` | Governed HR document evidence | +| #99 | `fff082f56e34e47cb83a19316d132c5638d3b633` | Employment-scoped bitemporal base compensation | +| #101 | `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` | Governed Job-grade design review | +| #102 | `d87cb05f723f106c653f2ea07680872fd9c62ada` | Purpose-bound audit-evidence review | +| #104 | `d92ac4cb798b3bd32b632c0ab677c03f944070e4` | Governed Job qualification-rule review | +| #110 | `bc84eaa145166a3f77a57f0c94c6d7459cfc65f3` | Vacancy-to-Assignment fill orchestration | +| #111 | `cfff42f5cf884ff67169ddeff645c6933e19337a` | Governed Position lifecycle-change review | + +This table intentionally does not assert that every root is merge-authorized. Fresh review and effective-rule state remain authoritative. + +## Buyer-visible progress since the previous snapshot -Many other open roots exist. Never use this table to skip an older root or an independently actionable lane. +Several items that were previously listed as unresolved product gaps now have active owner lanes and must no longer be described as absent: -## Buyer-facing gaps after the open queue +1. **Job grade/band governance:** #101 provides reviewed Job-grade design evidence; #109 is the dependency-first bitemporal persistence descendant. +2. **Offer-to-hire close:** #80 owns candidate offer-response evidence; #108 is the dependency-first bridge to the authoritative confirmed-hire boundary. +3. **Vacancy-to-Assignment fill:** #110 owns the current orchestration slice and delegates final persistence to the authoritative People mutation boundary. +4. **Position lifecycle:** #111 owns human-reviewed lifecycle-change evidence; #112 is the dependency-first authoritative application descendant. +5. **HR document evidence:** #98 owns the value-minimized evidence packet; #107 is the dependency-first immutable persistence descendant. -Do not open withholding, payroll-pay, statutory accounting, or year-end settlement tables/UI inside Orgmetra without an accepted owner boundary. +These are active-PR capabilities, **not protected-main truth** until integrated. -1. Job-grade design against a persisted Job Analysis snapshot, with a normalized grade/band model and accessible Storybooked interaction. -2. Job-analysis LLM draft assistance through Contextual Orchestrator/NVIDIA NIM, with semantic-unit provenance and mandatory human confirmation before snapshot persistence. -3. Offer-to-hire close: connect governed candidate offer response to the authoritative confirmed-hire mutation path without turning response evidence into hire authority. -4. Vacancy-to-assignment: let an authorized operator fill/freeze a staffable Position through authoritative Assignment truth, preserving bitemporal and audit/outbox evidence. -5. Purpose-bound document retrieve/export for governed HR document evidence with field minimization, retention/export controls, and immutable audit rather than indiscriminate masking. -6. For new buyer-visible screens, maintain Storybook, design tokens, accessibility evidence, wireframes, and a governed Figma/Product Design handoff when material. -7. External finance/accounting or billing integration remains planned until a published owner API/event contract is accepted; Orgmetra must not create statutory-account truth or direct cross-service application-table SQL. +## Highest-value buyer gaps after the current queue -## Open PRs observed 2026-08-24 (anchors, not authority) +Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -Fifty open PRs were observed. New roots since the previous snapshot include #52 (TEPP analysis adapter), #54 (workforce composition change), #55 (People read hardening), #56 (Organization hierarchy snapshot), #57 (validity analysis handoff), #59-#65 (recorded-time/runtime-integrity repairs), #66 (normalized candidate application), #68 (Naruon calendar integrity), #69-#73 (bitemporal/correction/chronology hardening), #74 (People operability probes), #75/#76/#77 (HR data export/retention/disposition governance), #78 (SBOM/provenance release evidence), #79 (Kubernetes reference deployment), #90 (People HTTP telemetry), #91-#96 (privacy/performance/reporting/hierarchy evidence lanes), #100 (this document), #102-#104 (audit/work-capacity/qualification-rule reviews), #110 (vacancy fill orchestration, draft), #111 (Position lifecycle review), #112 (lifecycle application, stacked draft). Stacks remain dependency-first: #105→#104, #106→#94, #107→#98, #108→#80, #109→#101, #112→#111, #77→#76, #67→#66, #58→#57. +1. **Purpose-bound HR document retrieval/export execution.** #75 reviews export intent and #98/#107 govern document evidence/persistence, but a customer still needs an authorized document read/egress execution boundary that re-resolves tenant/Person/Employment scope, purpose, permitted fields/artifact, retention/legal-hold state, delivery destination, human approval, and immutable audit before bytes leave the owner boundary. +2. **Authoritative Employment leave/absence truth.** #47 provides a governed leave review packet, but protected `develop` still lacks a normalized bitemporal leave/absence application/persistence boundary that preserves Employment scope, business time, system-recorded time, human review, correction-not-rewrite history, tenant isolation, and audit/outbox evidence without turning policy review into payroll or scheduling authority. +3. **Job-Analysis-specific model-assisted draft workflow.** #81 provides the generic Contextual Orchestrator draft-evidence contract; a later Job Analysis slice should bind semantic-unit Task/FJA/KSAO draft provenance to an exact Job Analysis snapshot workflow and require explicit human confirmation before authoritative persistence. Model output remains untrusted draft evidence. +4. **Accessible buyer interaction for the newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, and qualification-rule capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. #53 is a useful existing workspace anchor rather than permission to invent protected-main API behavior. +5. **Integrated release readiness.** Source SBOM/provenance, probes, telemetry and Kubernetes reference lanes exist, but no release/version/tag should be created until one exact integrated protected head satisfies applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together and source/artifact hashes are reverified. + +External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. ## Technical non-negotiables -- Exact 100% owned production statement/branch coverage where tooling exposes it, plus beginner-readable public docs/docstrings and realistic round-trip/security/privacy/concurrency/recovery cases. -- Database objects use descriptive two-or-more-word `snake_case`, 3NF by default, tenant/context isolation, opaque public IDs, and distinct business/effective versus system-recorded time. -- Job, Position, and Assignment remain separate authoritative concepts. -- Necessary PII stays usable only through purpose-bound authorization, least privilege, field minimization, encryption, retention/export controls, and immutable audit evidence. -- High-impact employment decisions require explicit accountable human confirmation with actor/purpose/reason/evidence versioning; LLM output remains untrusted draft evidence only. -- Design write paths toward CSAP and SOC 2 evidence readiness without claiming certification. +- Exact 100% owned production statement/branch coverage where tooling exposes it, plus beginner-readable public docs/docstrings and realistic security/privacy/concurrency/migration/recovery/accessibility cases. +- Descriptive two-or-more-word `snake_case` database objects and 3NF by default. +- Job, Position, Assignment, Employment, Organization, and Person remain distinct authoritative concepts. +- Business/effective time and system-recorded time remain separate; correction is correction-not-rewrite. +- Tenant/context isolation, opaque public correlation, least privilege, field minimization, encryption/retention/export controls, and immutable audit/outbox remain mandatory. +- Necessary PII remains usable only through purpose-bound authorization; indiscriminate masking is not a substitute for access control. +- High-impact employment decisions require accountable human confirmation with actor/purpose/reason/evidence versioning. LLM output remains untrusted draft evidence only. - Preserve modular MSA extraction boundaries; do not introduce direct cross-service application-table SQL. -- Failed checks are repair triggers at the first causal owner boundary. Review wait on one lane never blocks independent Orgmetra work. +- Design toward CSAP and SOC 2 evidence readiness without claiming certification. +- Queued, pending, cancelled, skipped-required, neutral, absent, stale, predecessor, status-only, or model-only evidence is non-passing. ## Execution loop -Each run: refetch protected `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, reviews/threads, exact-head workflows and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects test-first when practicable; rerun exact-head evidence; resolve only addressed threads; and merge only with qualifying independent non-author approval plus actually enforceable protection. Refresh this document only as a snapshot after material state changes; never treat its recorded SHAs as current truth. +Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, reviews/threads, exact-head workflows, releases and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when practicable; rerun exact-head evidence; resolve only addressed threads; and merge only with qualifying independent non-author approval plus actually enforceable protection. Refresh this document only after material state changes and never use its recorded SHAs as current control-plane truth. ## Doctoring (APA 7th) -Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee selection procedures* (29 C.F.R. Part 1607). +American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. -Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). +Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee selection procedures* (29 C.F.R. Part 1607). International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management — Requirements and recommendations for human capital reporting and disclosure*. ISO. -American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. +Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). From 626b8def9a548aad9599fa2b4488353d8638fada Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 05:28:22 +0900 Subject: [PATCH 005/201] docs: append automation diagnostics to refreshed gap baseline --- docs/product-technical-gap-baseline.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0f700a28e..9aa9ec632 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -120,6 +120,13 @@ External finance/accounting and billing/collection integration remains planned/o Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, reviews/threads, exact-head workflows, releases and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when practicable; rerun exact-head evidence; resolve only addressed threads; and merge only with qualifying independent non-author approval plus actually enforceable protection. Refresh this document only after material state changes and never use its recorded SHAs as current control-plane truth. +## 2026-08-24/25 automation findings (operator diagnostics) + +1. **Strix failures were infrastructure, not source defects.** Repeated `strix` failures traced to NVIDIA NIM `429 Too Many Requests` during scanner LLM connection (three primary attempts plus fallback exhausted, no report artifact, fail-closed). Local exact-head verification reproduced all owned package suites green at 100% statement/branch coverage; the scan lane, not the code, was failing. Remediation: staggered same-head re-scan dispatch (`repository_dispatch strix-scan`) instead of concurrent bursts. +2. **Org review-dispatch budget was zero.** `ORG_SWEEP_REVIEW_DISPATCH_LIMIT` was `0`, so the org queue sweep could never dispatch an OpenCode review anywhere. Restored to `2` with `ORG_SWEEP_BRANCH_UPDATE_LIMIT=1`; `ContextualWisdomLab/Orgmetra` added to the central targeted-dispatch allowlist. Diagnose future zero-review stalls against this variable first. +3. **Strix gate semantics after a completed scan.** A real reported vulnerability fails the required check by design. PR #52's first completed scan surfaced one legitimate MEDIUM IDOR-shaped finding (cross-field reference validation missing in `TeppAnalysisRequestPacket`); repaired at head `e068df7` with temporal ordering, distinct workspace/snapshot identifiers, and a scope digest binding every retry-stable correlation. Scanner finding -> test-first root repair -> fresh full-head evidence is the intended loop. +4. **Shared-credential saturation is the remaining systemic constraint.** The OpenCode GitHub App installation token hits GitHub API rate limits mid-sweep before reaching later repositories, and NVIDIA NIM 429s arrive org-wide because one key is shared. Both are transient retryable infra states, never source defects; a scan can complete with zero vulnerabilities yet fail closed on one transient backend signal in its console output. + ## Doctoring (APA 7th) American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. From 9616df3ef6a51707a5e826d78890641f1fa9a460 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 13:57:14 +0900 Subject: [PATCH 006/201] docs: record 2026-08-25 strix token-exchange outage rerun evidence --- docs/product-technical-gap-baseline.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9aa9ec632..2009525a5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -34,7 +34,7 @@ Do not revive these merged heads. Extend default-branch truth only through a cur ## Live open-PR control snapshot -The repository currently has 68 open PRs. The examples below are anchors only; execution order comes from a fresh oldest/dependency-root-first graph. +The repository currently has 70 open PRs (verified 2026-08-25). The examples below are anchors only; execution order comes from a fresh oldest/dependency-root-first graph. ### Oldest root gate @@ -126,6 +126,9 @@ Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependen 2. **Org review-dispatch budget was zero.** `ORG_SWEEP_REVIEW_DISPATCH_LIMIT` was `0`, so the org queue sweep could never dispatch an OpenCode review anywhere. Restored to `2` with `ORG_SWEEP_BRANCH_UPDATE_LIMIT=1`; `ContextualWisdomLab/Orgmetra` added to the central targeted-dispatch allowlist. Diagnose future zero-review stalls against this variable first. 3. **Strix gate semantics after a completed scan.** A real reported vulnerability fails the required check by design. PR #52's first completed scan surfaced one legitimate MEDIUM IDOR-shaped finding (cross-field reference validation missing in `TeppAnalysisRequestPacket`); repaired at head `e068df7` with temporal ordering, distinct workspace/snapshot identifiers, and a scope digest binding every retry-stable correlation. Scanner finding -> test-first root repair -> fresh full-head evidence is the intended loop. 4. **Shared-credential saturation is the remaining systemic constraint.** The OpenCode GitHub App installation token hits GitHub API rate limits mid-sweep before reaching later repositories, and NVIDIA NIM 429s arrive org-wide because one key is shared. Both are transient retryable infra states, never source defects; a scan can complete with zero vulnerabilities yet fail closed on one transient backend signal in its console output. +5. **2026-08-25 second Strix failure mode: OpenCode app-token exchange outage (distinct from NIM 429).** Twelve PR heads (#80, #85, #95, #97, #98, #99, #102, #103, #104, #110, #111, #113) showed terminal `strix=FAILURE` where the job log shows `curl: (22) ... error: 500` against `https://api.opencode.ai` followed by "OpenCode app token exchange unavailable: app token request did not complete." six times, then the fail-closed provider-unavailable error; the scanner never produced findings, so no source defect is implied. Remediation applied: provider health re-verified (`/health` → 200) and each failed run re-executed on its identical head via the authenticated REST endpoint `POST /repos/{owner}/{repo}/actions/runs/{id}/rerun` (`--failed` rerun), preserving exact-head semantics without transferring predecessor evidence. +6. **Hourly review-repair heartbeat survived a transient GitHub read failure.** Run 32805870622 failed once inside `fetch_open_prs` when `gh api graphql` returned non-JSON text ("invalid character ' ' in literal false"), an upstream/API hiccup the scheduler script does not yet retry; the next heartbeat succeeded. Candidate hardening at the owning central boundary: bounded retry/backoff around `run_github_read` for non-deterministic CLI failures. +7. **Review pipeline state at this snapshot:** the only qualifying review submission found was `opencode-agent CHANGES_REQUESTED` on PR #54 (coverage-evidence blocker on head `cc6784ec…`, workflow run 32790319079); Devin/CodeRabbit/github-code-quality comments do not satisfy approval gates. All other open PRs await current-head dispatch through the restored org sweep budget (finding 2). Nothing here authorizes a merge while issue #89's effective-protection defect remains open. ## Doctoring (APA 7th) From c3cbd5a2815114699fe5b59c3fefe006db249e2c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 01:06:49 -0700 Subject: [PATCH 007/201] docs: align buyer baseline with effective ruleset truth --- docs/product-technical-gap-baseline.md | 125 +++++++++++-------------- 1 file changed, 53 insertions(+), 72 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2009525a5..5942452bd 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,20 +2,37 @@ Inventory date: 2026-08-25 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, branch-protection truth, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and bases, dependency ancestry, reviews/threads, exact-head workflows, effective repository rules, releases, and changed refs before acting. +This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, stack ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. Orgmetra owns authoritative HRIS employment truth inside its published boundaries. Keyverse and other dedicated-writer CWL repositories remain read-only dependencies consumed only through published package/API/event contracts and existing owner-control paths. No static product-gap document may authorize a write into another dedicated-writer repository. -## Repository-control truth +## Effective repository-control truth -GitHub currently reports `develop` as `protected: true`, but the effective branch-protection payload observed for the same branch has `protection.enabled=false`, required-status enforcement `off`, and no required contexts/checks. Issue #89 owns that repository-settings defect. +The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-25 show this ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`, which includes Orgmetra `develop`. + +The active ruleset requires: + +- pull-request integration; +- **2 approving reviews**; +- dismissal of stale approvals after a push; +- approval after the last push; +- required review-thread resolution; +- extra approval for unattributed changes; +- the central required-workflow set from `ContextualWisdomLab/.github@main` (`close-empty-pr.yml`, `opencode-review.yml`, `pr-review-merge-scheduler.yml`, `security-scan.yml`, `strix.yml`, `sast-semgrep.yml`, and `noema-review.yml`); +- branch-deletion protection; and +- non-fast-forward protection. + +Issue #89 remains open for two narrower commercial-control gaps. First, the effective ruleset still grants `OrganizationAdmin` an `always` bypass and the connected user reports `current_user_can_bypass=always`; routine administrator bypass is not an acceptable steady-state acquisition-grade control. Second, the ruleset does not itself enumerate every Orgmetra-local Foundation, Recovery, coverage/package/provenance, and product-quality gate, so merge readiness must continue to require fresh exact-head terminal GREEN for every applicable local gate unless fail-closed transitive enforcement is proven. + +The classic branch payload may still report `protection.enabled=false`, required-status enforcement `off`, and no classic contexts/checks. That is **not evidence that `develop` has no effective protection** while ruleset 18156473 is active. Buyer-facing documents and PR metadata must not repeat that obsolete inference. Consequences: -- a GREEN PR is not merge-authorized merely because GitHub computes it as mergeable; -- qualifying independent non-author approval is still required where the repository governance contract requires it; -- no workflow shim, author approval, predecessor check, model-only status, or manual force merge substitutes for enforceable branch protection; -- immediately before any future merge, refetch the unchanged exact head, independently resolved live base, reviews, unresolved threads, effective rules/protection, and every applicable exact-head check. +- a GREEN or GitHub-mergeable PR is not merge-authorized; +- two qualifying approvals and the last-push/review-thread rules remain mandatory; +- routine administrator bypass must not be used as a normal merge path; +- no workflow shim, author approval, predecessor check, status-only/model-only result, or force merge substitutes for the effective ruleset plus applicable exact-head local gates; +- immediately before any future merge, refetch the unchanged exact head, live base, formal reviews, unresolved threads, effective ruleset, and every applicable exact-head check/job. ## Merged buyer-visible anchors on `develop` @@ -32,74 +49,39 @@ This is a selected shipped inventory, not a replacement for Git history. Do not revive these merged heads. Extend default-branch truth only through a current owner-scoped change when a fresh buyer gap remains. -## Live open-PR control snapshot - -The repository currently has 70 open PRs (verified 2026-08-25). The examples below are anchors only; execution order comes from a fresh oldest/dependency-root-first graph. - -### Oldest root gate - -PR #40 (`8d8896b14db10a5a4981f0b9e209ea00ee3be64c`) is open, non-draft and mergeable. Structured Interview Plan, Foundation, SAST, Security, and Recovery are terminal GREEN on that exact head. Fresh reviews are COMMENTED only and the remaining unresolved threads are informational. It still has no qualifying independent non-author `APPROVE`, and issue #89's protection defect remains open, so it is intentionally unmerged. +## Fresh control anchors -### Dependency-constrained Draft descendants +The following anchors were freshly rechecked during the 2026-08-25 maintenance loop. They are intentionally sparse: an exhaustive static PR table becomes stale faster than it helps buyers or maintainers. -These descendants remain Draft. Lane-local GREEN evidence is not integrated protected-base evidence and parent checks/reviews do not transfer. +- **Oldest dependency-root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`, open, non-draft, mergeable, and exact-head GREEN for Structured Interview Plan, Foundation, SAST, Security, and Recovery. Submitted reviews are COMMENTED only; there is no qualifying `APPROVE`. +- **PR #54** remains exact head `cc6784ec33b1145c342bbbb99ebece1d37aeec80` with Orgmetra-owned product/Foundation/security/recovery evidence GREEN, but it is the sole open `CHANGES_REQUESTED` lane. The cited blocker is owned by the existing central `.github` coverage/review path (`.github#1250` / PR #1052), not an Orgmetra-native source failure. Keep that dependency boundary read-only from this loop. +- **PR #110** is exact head `305757e7daa3e8fd4d79ef385b42828e6f99d04c` and its People/Foundation/Recovery/SAST/Security/Job-Analysis gates are terminal GREEN. GitHub currently reports it Draft; prior event history shows a separate same-repository lifecycle writer repeatedly alternating Draft/Ready state, so this loop must not race that writer merely to change PR state. +- **PR #113** is exact head `3da7ad076f977a3ccd9e130a58786c9d26763a16` with Workforce/People/Job-Analysis/Foundation/Recovery/SAST/Security GREEN, but live GitHub state is Draft despite stale body text claiming Ready. Treat the live lifecycle state as authoritative and do not race the other writer. +- **PR #114** is the dependency-first child of #113 at exact head `656544bc4d86122ee42b50246500bf31785d6d53`; focused `Employment Absence Persistence Quality` is terminal GREEN. This is stack-local evidence only and cannot transfer parent checks/reviews or authorize integration before #113. -| PR | Exact child head | Dependency | -|---|---|---| -| #58 | `c79a6ed49627e6a47947f171aeeed2bf02a8c152` | #57 | -| #67 | `cf59b3001fa58e5a978099c2a5692a03f4849fdd` | #66 | -| #77 | `9b02cb911377a5beb9f541e9acf2eb51ff065ee9` | #76 | -| #82 | `0c3a776f2e2c6f93c25e11c5c3ce3fa66a10b5c9` | #51 | -| #105 | `168f19402b3b17762cfe60f8a0e93c649a082989` | #104 | -| #106 | `c35ad114edbce7a4ebafcea793748493f1346351` | #94 | -| #107 | `5e521fd829de313a037f45ac28227c2ae5362d37` | #98 | -| #108 | `5027c772e5588b33e953258de008f0253389e95c` | #80 | -| #109 | `1eb17d1dbfa2ec822a9c6cce52d8a92b19ed9353` | #101 | -| #112 | `4f2a003769bf8f773559ac8122702f1451f0e8c0` | #111 | +The repository currently has a large open PR graph. Execution order must come from a fresh oldest/dependency-root-first graph, not from recorded queue counts in this snapshot. -Do not restack these descendants merely to manufacture fresh evidence while their parents remain unintegrated. After a parent integrates, retarget/reconcile the child against the then-current `develop`, refetch the resulting exact head/base/conflict state, and rerun all applicable Foundation/SAST/Security/Recovery/product gates without transferring predecessor evidence. +## Active-PR capabilities that are no longer buyer gaps -### Selected current root capabilities +Several capabilities previously described as absent now have active owner lanes. They remain **active-PR truth, not default-branch truth**, until integrated. -The following are current open-root anchors with terminal exact-head GREEN evidence and are useful for product-gap reasoning. They remain unmerged pending live governance gates. +- Job grade/band governance has a reviewed design-evidence root and a dependency-first bitemporal persistence child. +- Candidate offer response and offer-to-hire closure have active evidence/bridge lanes. +- Vacancy-to-Assignment fill orchestration is implemented on #110 and delegates final persistence to the authoritative People mutation boundary. +- Position lifecycle review/application and Position reporting review/persistence have active dependency-ordered lanes. +- HR document evidence and immutable document metadata persistence have active dependency-ordered lanes. +- Reason-free authoritative Employment absence truth is implemented on #113, with durable bitemporal persistence on child #114. -| PR | Exact head | Capability | -|---|---|---| -| #53 | `43ae3c73c0abef8f23d1c14f4e41d25b8c9b14df` | Evidence-centered HR workspace / Storybook slice | -| #75 | `282ff0966add47a80a2edd76f84c4c65a868fedb` | Governed HR data-export review | -| #80 | `5070f34cd13814f09d74162347f837cb34d76a57` | Candidate offer-response evidence | -| #81 | `78a9cb1e047db5c79ca855b992d44749b9214992` | Contextual Orchestrator draft-evidence boundary | -| #98 | `9aeeb204acce429f85b028029c9531a5b05f37e1` | Governed HR document evidence | -| #99 | `fff082f56e34e47cb83a19316d132c5638d3b633` | Employment-scoped bitemporal base compensation | -| #101 | `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` | Governed Job-grade design review | -| #102 | `d87cb05f723f106c653f2ea07680872fd9c62ada` | Purpose-bound audit-evidence review | -| #104 | `d92ac4cb798b3bd32b632c0ab677c03f944070e4` | Governed Job qualification-rule review | -| #110 | `bc84eaa145166a3f77a57f0c94c6d7459cfc65f3` | Vacancy-to-Assignment fill orchestration | -| #111 | `cfff42f5cf884ff67169ddeff645c6933e19337a` | Governed Position lifecycle-change review | - -This table intentionally does not assert that every root is merge-authorized. Fresh review and effective-rule state remain authoritative. - -## Buyer-visible progress since the previous snapshot - -Several items that were previously listed as unresolved product gaps now have active owner lanes and must no longer be described as absent: - -1. **Job grade/band governance:** #101 provides reviewed Job-grade design evidence; #109 is the dependency-first bitemporal persistence descendant. -2. **Offer-to-hire close:** #80 owns candidate offer-response evidence; #108 is the dependency-first bridge to the authoritative confirmed-hire boundary. -3. **Vacancy-to-Assignment fill:** #110 owns the current orchestration slice and delegates final persistence to the authoritative People mutation boundary. -4. **Position lifecycle:** #111 owns human-reviewed lifecycle-change evidence; #112 is the dependency-first authoritative application descendant. -5. **HR document evidence:** #98 owns the value-minimized evidence packet; #107 is the dependency-first immutable persistence descendant. - -These are active-PR capabilities, **not protected-main truth** until integrated. +Do not describe these capabilities as shipped until their owner PRs integrate into fresh `develop`. ## Highest-value buyer gaps after the current queue Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Purpose-bound HR document retrieval/export execution.** #75 reviews export intent and #98/#107 govern document evidence/persistence, but a customer still needs an authorized document read/egress execution boundary that re-resolves tenant/Person/Employment scope, purpose, permitted fields/artifact, retention/legal-hold state, delivery destination, human approval, and immutable audit before bytes leave the owner boundary. -2. **Authoritative Employment leave/absence truth.** #47 provides a governed leave review packet, but protected `develop` still lacks a normalized bitemporal leave/absence application/persistence boundary that preserves Employment scope, business time, system-recorded time, human review, correction-not-rewrite history, tenant isolation, and audit/outbox evidence without turning policy review into payroll or scheduling authority. -3. **Job-Analysis-specific model-assisted draft workflow.** #81 provides the generic Contextual Orchestrator draft-evidence contract; a later Job Analysis slice should bind semantic-unit Task/FJA/KSAO draft provenance to an exact Job Analysis snapshot workflow and require explicit human confirmation before authoritative persistence. Model output remains untrusted draft evidence. -4. **Accessible buyer interaction for the newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, and qualification-rule capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. #53 is a useful existing workspace anchor rather than permission to invent protected-main API behavior. -5. **Integrated release readiness.** Source SBOM/provenance, probes, telemetry and Kubernetes reference lanes exist, but no release/version/tag should be created until one exact integrated protected head satisfies applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together and source/artifact hashes are reverified. +1. **Purpose-bound HR document retrieval/export execution.** Export-review and document-evidence/persistence lanes exist, but a customer still needs an authorized document read/egress execution boundary that re-resolves tenant/Person/Employment scope, purpose, permitted artifact/fields, retention/legal-hold state, destination, accountable human approval, and immutable audit before bytes leave the owner boundary. +2. **Job-Analysis-specific model-assisted draft workflow.** A generic Contextual Orchestrator draft-evidence boundary exists, but Job Analysis still needs a bounded workflow binding semantic-unit Task/FJA/KSAO draft provenance to an exact Job Analysis snapshot and explicit human confirmation before authoritative persistence. Model output remains untrusted draft evidence. +3. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, and workforce-capacity capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. +4. **Integrated release readiness.** Source SBOM/provenance, health/readiness, telemetry, and Kubernetes reference lanes exist, but no release/version/tag should be created until one exact integrated `develop` head satisfies all applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together and source/artifact hashes are reverified. External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. @@ -118,17 +100,16 @@ External finance/accounting and billing/collection integration remains planned/o ## Execution loop -Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, reviews/threads, exact-head workflows, releases and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when practicable; rerun exact-head evidence; resolve only addressed threads; and merge only with qualifying independent non-author approval plus actually enforceable protection. Refresh this document only after material state changes and never use its recorded SHAs as current control-plane truth. +Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, formal reviews/threads, exact-head workflows/jobs, releases, changed refs and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when an executable regression is appropriate; rerun exact-head evidence; resolve only addressed threads; and merge only when the unchanged head satisfies the effective ruleset plus every applicable local gate. Refresh this document only after material buyer/product state changes and never use its recorded SHAs as current control-plane truth. + +For live-state documentation defects such as repository ruleset truth, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop must refetch the effective ruleset and reject stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. -## 2026-08-24/25 automation findings (operator diagnostics) +## 2026-08-24/25 operator diagnostics -1. **Strix failures were infrastructure, not source defects.** Repeated `strix` failures traced to NVIDIA NIM `429 Too Many Requests` during scanner LLM connection (three primary attempts plus fallback exhausted, no report artifact, fail-closed). Local exact-head verification reproduced all owned package suites green at 100% statement/branch coverage; the scan lane, not the code, was failing. Remediation: staggered same-head re-scan dispatch (`repository_dispatch strix-scan`) instead of concurrent bursts. -2. **Org review-dispatch budget was zero.** `ORG_SWEEP_REVIEW_DISPATCH_LIMIT` was `0`, so the org queue sweep could never dispatch an OpenCode review anywhere. Restored to `2` with `ORG_SWEEP_BRANCH_UPDATE_LIMIT=1`; `ContextualWisdomLab/Orgmetra` added to the central targeted-dispatch allowlist. Diagnose future zero-review stalls against this variable first. -3. **Strix gate semantics after a completed scan.** A real reported vulnerability fails the required check by design. PR #52's first completed scan surfaced one legitimate MEDIUM IDOR-shaped finding (cross-field reference validation missing in `TeppAnalysisRequestPacket`); repaired at head `e068df7` with temporal ordering, distinct workspace/snapshot identifiers, and a scope digest binding every retry-stable correlation. Scanner finding -> test-first root repair -> fresh full-head evidence is the intended loop. -4. **Shared-credential saturation is the remaining systemic constraint.** The OpenCode GitHub App installation token hits GitHub API rate limits mid-sweep before reaching later repositories, and NVIDIA NIM 429s arrive org-wide because one key is shared. Both are transient retryable infra states, never source defects; a scan can complete with zero vulnerabilities yet fail closed on one transient backend signal in its console output. -5. **2026-08-25 second Strix failure mode: OpenCode app-token exchange outage (distinct from NIM 429).** Twelve PR heads (#80, #85, #95, #97, #98, #99, #102, #103, #104, #110, #111, #113) showed terminal `strix=FAILURE` where the job log shows `curl: (22) ... error: 500` against `https://api.opencode.ai` followed by "OpenCode app token exchange unavailable: app token request did not complete." six times, then the fail-closed provider-unavailable error; the scanner never produced findings, so no source defect is implied. Remediation applied: provider health re-verified (`/health` → 200) and each failed run re-executed on its identical head via the authenticated REST endpoint `POST /repos/{owner}/{repo}/actions/runs/{id}/rerun` (`--failed` rerun), preserving exact-head semantics without transferring predecessor evidence. -6. **Hourly review-repair heartbeat survived a transient GitHub read failure.** Run 32805870622 failed once inside `fetch_open_prs` when `gh api graphql` returned non-JSON text ("invalid character ' ' in literal false"), an upstream/API hiccup the scheduler script does not yet retry; the next heartbeat succeeded. Candidate hardening at the owning central boundary: bounded retry/backoff around `run_github_read` for non-deterministic CLI failures. -7. **Review pipeline state at this snapshot:** the only qualifying review submission found was `opencode-agent CHANGES_REQUESTED` on PR #54 (coverage-evidence blocker on head `cc6784ec…`, workflow run 32790319079); Devin/CodeRabbit/github-code-quality comments do not satisfy approval gates. All other open PRs await current-head dispatch through the restored org sweep budget (finding 2). Nothing here authorizes a merge while issue #89's effective-protection defect remains open. +- Repeated Strix failures have included NVIDIA NIM 429 saturation and a separate OpenCode app-token exchange 500 outage. Provider-unavailable runs are non-passing but do not imply a source defect without a scanner finding. Same-head reruns preserve exact-head semantics after transient recovery. +- Org review dispatch was previously disabled by `ORG_SWEEP_REVIEW_DISPATCH_LIMIT=0`; the central owner restored bounded dispatch. This remains foreign owner-control evidence, not permission for Orgmetra to mutate central `.github`. +- PR #54 demonstrates why source ownership matters: its Orgmetra-native gates are GREEN while the current blocking review cites a central coverage-evidence failure. Repair must stay at the existing central owner boundary. +- Review capacity remains the dominant integration constraint: the effective ruleset requires two qualifying approvals, while current Orgmetra open PRs have no qualifying `APPROVE` in the fresh review search. ## Doctoring (APA 7th) From fe02c7c65461be9c506f45fd5a26ce0b27dadef0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 01:10:02 -0700 Subject: [PATCH 008/201] docs: label product baseline references correctly --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5942452bd..5750c65c4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -111,7 +111,7 @@ For live-state documentation defects such as repository ruleset truth, do **not* - PR #54 demonstrates why source ownership matters: its Orgmetra-native gates are GREEN while the current blocking review cites a central coverage-evidence failure. Repair must stay at the existing central owner boundary. - Review capacity remains the dominant integration constraint: the effective ruleset requires two qualifying approvals, while current Orgmetra open PRs have no qualifying `APPROVE` in the fresh review search. -## Doctoring (APA 7th) +## References (APA 7th) American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. From c3289c8fafc524021d9fbdca2bd0be651ea82202 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 17:39:36 +0900 Subject: [PATCH 009/201] docs: record 2026-08-25 review-triage drain and strix owning-boundary fix --- docs/product-technical-gap-baseline.md | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5750c65c4..9dba6e819 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -104,6 +104,12 @@ Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependen For live-state documentation defects such as repository ruleset truth, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop must refetch the effective ruleset and reject stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. + +### 2026-08-25 review-triage and provider-repair progress + +1. **Open review threads are the approval bottleneck, and they are being drained at the source.** The central approve-gate treats unresolved non-outdated threads as REQUEST_CHANGES blockers, so triage now resolves reviewer findings per lane with evidence-backed replies: PR #110 (4/4 threads), #60 (3/3), and #66 (10/10) are fully resolved after root repairs on their own heads — forged finite-exact-Decimal allocation guard plus NIST SP 800-53 Release 5.2.0 citation (#110), built-in non-UTC `timezone` reinjection rejection plus exact-type digest/version validation (#60), and the correctable-anchor partial unique index, artifact registration across validator/contract-core/ADR-index/manifest, RLS `WITH CHECK` INSERT denial evidence, and vendor-tree pruning in the markdown scan so `validate_repository.py` passes identically on workspaces with `node_modules` (#66). All three lanes re-passed their owned suites at 100% statement/branch coverage or disposable-Postgres contracts locally before push. +2. **Second Strix failure mode has an owning-boundary fix pending merge.** Central PR ContextualWisdomLab/.github#1323 isolates direct-OpenAI fallback models from a foreign ambient `LLM_API_BASE` (the literal "404 page not found" path), with a function-execution regression contract pinning NVIDIA-base inheritance for non-OpenAI models. Until it merges and required checks land, remaining `strix=FAILURE` rows stay typed infrastructure evidence, not source defects. +3. **Manifest integrity is now branch-honest.** The candidate-application lane regenerated `manifest.json` through `validate_repository.py --print-manifest`; `generated_for_branch` names its own lane instead of inheriting `feat/audit-outbox-envelope`, closing the provenance mismatch flagged by review. ## 2026-08-24/25 operator diagnostics - Repeated Strix failures have included NVIDIA NIM 429 saturation and a separate OpenCode app-token exchange 500 outage. Provider-unavailable runs are non-passing but do not imply a source defect without a scanner finding. Same-head reruns preserve exact-head semantics after transient recovery. @@ -119,4 +125,4 @@ Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management — Requirements and recommendations for human capital reporting and disclosure*. ISO. -Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). +Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). \ No newline at end of file From 4a07d0d0ac6b0115c74b4109fc17871b685c590c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 13:07:22 -0700 Subject: [PATCH 010/201] docs: refresh active buyer-gap ownership --- docs/product-technical-gap-baseline.md | 43 +++++++++++++------------- 1 file changed, 21 insertions(+), 22 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9dba6e819..5a7c5e17b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product and technical gap baseline -Inventory date: 2026-08-25 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Inventory date: 2026-08-26 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, stack ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -8,7 +8,7 @@ Orgmetra owns authoritative HRIS employment truth inside its published boundarie ## Effective repository-control truth -The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-25 show this ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`, which includes Orgmetra `develop`. +The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-26 show this ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`, which includes Orgmetra `develop`. The active ruleset requires: @@ -22,7 +22,7 @@ The active ruleset requires: - branch-deletion protection; and - non-fast-forward protection. -Issue #89 remains open for two narrower commercial-control gaps. First, the effective ruleset still grants `OrganizationAdmin` an `always` bypass and the connected user reports `current_user_can_bypass=always`; routine administrator bypass is not an acceptable steady-state acquisition-grade control. Second, the ruleset does not itself enumerate every Orgmetra-local Foundation, Recovery, coverage/package/provenance, and product-quality gate, so merge readiness must continue to require fresh exact-head terminal GREEN for every applicable local gate unless fail-closed transitive enforcement is proven. +Issue #89 remains open for three narrower commercial-control gaps. First, the effective ruleset still grants `OrganizationAdmin` an `always` bypass and the connected user reports `current_user_can_bypass=always`; routine administrator bypass is not an acceptable steady-state acquisition-grade control. Second, the ruleset does not itself enumerate every Orgmetra-local Foundation, Recovery, coverage/package/provenance, and product-quality gate, so merge readiness must continue to require fresh exact-head terminal GREEN for every applicable local gate unless fail-closed transitive enforcement is proven. Third, multiple technically GREEN PRs have been converted back to Draft by a separate same-repository lifecycle writer; this loop must not race that writer and must treat live lifecycle state as authoritative where the collision is evidenced. The classic branch payload may still report `protection.enabled=false`, required-status enforcement `off`, and no classic contexts/checks. That is **not evidence that `develop` has no effective protection** while ruleset 18156473 is active. Buyer-facing documents and PR metadata must not repeat that obsolete inference. @@ -51,13 +51,14 @@ Do not revive these merged heads. Extend default-branch truth only through a cur ## Fresh control anchors -The following anchors were freshly rechecked during the 2026-08-25 maintenance loop. They are intentionally sparse: an exhaustive static PR table becomes stale faster than it helps buyers or maintainers. +The following anchors were freshly rechecked during the 2026-08-26 maintenance loop. They are intentionally sparse: an exhaustive static PR table becomes stale faster than it helps buyers or maintainers. - **Oldest dependency-root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`, open, non-draft, mergeable, and exact-head GREEN for Structured Interview Plan, Foundation, SAST, Security, and Recovery. Submitted reviews are COMMENTED only; there is no qualifying `APPROVE`. - **PR #54** remains exact head `cc6784ec33b1145c342bbbb99ebece1d37aeec80` with Orgmetra-owned product/Foundation/security/recovery evidence GREEN, but it is the sole open `CHANGES_REQUESTED` lane. The cited blocker is owned by the existing central `.github` coverage/review path (`.github#1250` / PR #1052), not an Orgmetra-native source failure. Keep that dependency boundary read-only from this loop. -- **PR #110** is exact head `305757e7daa3e8fd4d79ef385b42828e6f99d04c` and its People/Foundation/Recovery/SAST/Security/Job-Analysis gates are terminal GREEN. GitHub currently reports it Draft; prior event history shows a separate same-repository lifecycle writer repeatedly alternating Draft/Ready state, so this loop must not race that writer merely to change PR state. -- **PR #113** is exact head `3da7ad076f977a3ccd9e130a58786c9d26763a16` with Workforce/People/Job-Analysis/Foundation/Recovery/SAST/Security GREEN, but live GitHub state is Draft despite stale body text claiming Ready. Treat the live lifecycle state as authoritative and do not race the other writer. +- **PR #110** is exact head `305757e7daa3e8fd4d79ef385b42828e6f99d04c` and its People/Foundation/Recovery/SAST/Security/Job-Analysis gates are terminal GREEN. GitHub has reported it Draft after a separate same-repository lifecycle writer repeatedly alternated Draft/Ready state, so this loop must not race that writer merely to change PR state. +- **PR #113** is exact head `3da7ad076f977a3ccd9e130a58786c9d26763a16` with Workforce/People/Job-Analysis/Foundation/Recovery/SAST/Security GREEN, but live lifecycle state has been controlled by the separate lifecycle writer. Treat the live state as authoritative rather than trusting stale body copy. - **PR #114** is the dependency-first child of #113 at exact head `656544bc4d86122ee42b50246500bf31785d6d53`; focused `Employment Absence Persistence Quality` is terminal GREEN. This is stack-local evidence only and cannot transfer parent checks/reviews or authorize integration before #113. +- **PR #119** is the dependency-first child of #96 at exact head `2d51b29b4788867c0656282c2ad8fea17c916e34`; focused `Organization Hierarchy Change Application Quality` run `32887781628` / job `97932188148` is terminal GREEN after the TRUNCATE regression was corrected to exercise the table-owned append-only guard. This remains stack-local focused evidence only: #96 must integrate first, then #119 must retarget to fresh `develop` and rerun all applicable integration/security/recovery/product gates. The repository currently has a large open PR graph. Execution order must come from a fresh oldest/dependency-root-first graph, not from recorded queue counts in this snapshot. @@ -71,6 +72,10 @@ Several capabilities previously described as absent now have active owner lanes. - Position lifecycle review/application and Position reporting review/persistence have active dependency-ordered lanes. - HR document evidence and immutable document metadata persistence have active dependency-ordered lanes. - Reason-free authoritative Employment absence truth is implemented on #113, with durable bitemporal persistence on child #114. +- **Purpose-bound HR document retrieval is now owned by PR #116.** That root lane re-resolves exact tenant/document/Person/Employment/artifact/retention scope, requires purpose-bound authorization to remain current through artifact verification, verifies bounded bytes by SHA-256, appends value-minimized immutable audit evidence, and only then releases content. It does not yet make the distinct outbound-export/egress operation a shipped capability. +- **Job-Analysis-specific model-assisted Task/FJA/KSAO drafting is now owned by PR #117.** The lane binds one exact Job Analysis snapshot to canonical semantic units and model provenance, keeps raw model output untrusted, requires a distinct accountable human reviewer, and never grants authoritative Job Analysis persistence by itself. +- **Release-readiness review evidence is now owned by PR #118.** It binds one exact candidate revision to source/SBOM/provenance/test/coverage/security/SAST/recovery/operability/accessibility/migration/rollback/package-reproducibility evidence and remains permanently `not_authorized_to_release`; an actual release still requires fresh integrated-default-branch proof and live governance. +- Organization hierarchy parent-change application is implemented as dependency-first child #119 under review root #96; its focused bitemporal/RLS/audit/concurrency lane is GREEN but remains non-integrated stack-local truth. Do not describe these capabilities as shipped until their owner PRs integrate into fresh `develop`. @@ -78,10 +83,10 @@ Do not describe these capabilities as shipped until their owner PRs integrate in Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Purpose-bound HR document retrieval/export execution.** Export-review and document-evidence/persistence lanes exist, but a customer still needs an authorized document read/egress execution boundary that re-resolves tenant/Person/Employment scope, purpose, permitted artifact/fields, retention/legal-hold state, destination, accountable human approval, and immutable audit before bytes leave the owner boundary. -2. **Job-Analysis-specific model-assisted draft workflow.** A generic Contextual Orchestrator draft-evidence boundary exists, but Job Analysis still needs a bounded workflow binding semantic-unit Task/FJA/KSAO draft provenance to an exact Job Analysis snapshot and explicit human confirmation before authoritative persistence. Model output remains untrusted draft evidence. -3. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, and workforce-capacity capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. -4. **Integrated release readiness.** Source SBOM/provenance, health/readiness, telemetry, and Kubernetes reference lanes exist, but no release/version/tag should be created until one exact integrated `develop` head satisfies all applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together and source/artifact hashes are reverified. +1. **Purpose-bound HR export/egress execution.** Export-review evidence and purpose-bound document retrieval now have owner lanes, but Orgmetra still needs a distinct outbound operation that re-resolves the exact authorized fields/artifact, destination class, retention/legal-hold state, human export approval, authorization freshness, egress policy, immutable audit/outbox and final byte/hash evidence immediately before data leaves the Orgmetra boundary. Retrieval authorization must not be treated as export authorization. +2. **Authoritative performance-goal activation/persistence.** PR #92 owns value-minimized performance goal-plan review evidence, but no current owner lane persists or applies a reviewed plan as authoritative bitemporal performance-goal truth. Any implementation must re-resolve Employment/Job/cycle scope, preserve goal/rating separation, require human authority, and append immutable audit/outbox evidence; review packets must not mutate authoritative truth by themselves. +3. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. +4. **Authoritative release operation after governed readiness review.** PR #118 owns non-authorizing release-readiness evidence, but no release/version/tag is authorized until one exact integrated `develop` head satisfies all applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together, the live ruleset and qualifying approvals are freshly verified, and source/artifact hashes are rechecked. The future operation must fail closed rather than converting a review packet into release authority. External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. @@ -102,20 +107,14 @@ External finance/accounting and billing/collection integration remains planned/o Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, formal reviews/threads, exact-head workflows/jobs, releases, changed refs and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when an executable regression is appropriate; rerun exact-head evidence; resolve only addressed threads; and merge only when the unchanged head satisfies the effective ruleset plus every applicable local gate. Refresh this document only after material buyer/product state changes and never use its recorded SHAs as current control-plane truth. -For live-state documentation defects such as repository ruleset truth, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop must refetch the effective ruleset and reject stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. +For live-state documentation defects such as repository ruleset truth or active owner-lane ownership, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop must refetch the effective ruleset/current PR graph and reject stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. +### 2026-08-25/26 review-triage and provider-repair progress -### 2026-08-25 review-triage and provider-repair progress - -1. **Open review threads are the approval bottleneck, and they are being drained at the source.** The central approve-gate treats unresolved non-outdated threads as REQUEST_CHANGES blockers, so triage now resolves reviewer findings per lane with evidence-backed replies: PR #110 (4/4 threads), #60 (3/3), and #66 (10/10) are fully resolved after root repairs on their own heads — forged finite-exact-Decimal allocation guard plus NIST SP 800-53 Release 5.2.0 citation (#110), built-in non-UTC `timezone` reinjection rejection plus exact-type digest/version validation (#60), and the correctable-anchor partial unique index, artifact registration across validator/contract-core/ADR-index/manifest, RLS `WITH CHECK` INSERT denial evidence, and vendor-tree pruning in the markdown scan so `validate_repository.py` passes identically on workspaces with `node_modules` (#66). All three lanes re-passed their owned suites at 100% statement/branch coverage or disposable-Postgres contracts locally before push. -2. **Second Strix failure mode has an owning-boundary fix pending merge.** Central PR ContextualWisdomLab/.github#1323 isolates direct-OpenAI fallback models from a foreign ambient `LLM_API_BASE` (the literal "404 page not found" path), with a function-execution regression contract pinning NVIDIA-base inheritance for non-OpenAI models. Until it merges and required checks land, remaining `strix=FAILURE` rows stay typed infrastructure evidence, not source defects. -3. **Manifest integrity is now branch-honest.** The candidate-application lane regenerated `manifest.json` through `validate_repository.py --print-manifest`; `generated_for_branch` names its own lane instead of inheriting `feat/audit-outbox-envelope`, closing the provenance mismatch flagged by review. -## 2026-08-24/25 operator diagnostics - -- Repeated Strix failures have included NVIDIA NIM 429 saturation and a separate OpenCode app-token exchange 500 outage. Provider-unavailable runs are non-passing but do not imply a source defect without a scanner finding. Same-head reruns preserve exact-head semantics after transient recovery. -- Org review dispatch was previously disabled by `ORG_SWEEP_REVIEW_DISPATCH_LIMIT=0`; the central owner restored bounded dispatch. This remains foreign owner-control evidence, not permission for Orgmetra to mutate central `.github`. -- PR #54 demonstrates why source ownership matters: its Orgmetra-native gates are GREEN while the current blocking review cites a central coverage-evidence failure. Repair must stay at the existing central owner boundary. -- Review capacity remains the dominant integration constraint: the effective ruleset requires two qualifying approvals, while current Orgmetra open PRs have no qualifying `APPROVE` in the fresh review search. +1. **Open review threads remain an approval bottleneck, and triage is performed against current source.** The central approve-gate treats unresolved non-outdated threads as blockers, so findings are verified rather than mechanically accepted. Repaired findings are resolved only after current-head evidence; informational observations remain informational. +2. **Central review/provider failures stay at their dedicated owner boundary.** PR #54 demonstrates the rule: its Orgmetra-native gates are GREEN while its current `CHANGES_REQUESTED` cites a central `.github` coverage/review failure. Repair stays on the existing central owner path; Orgmetra does not create a local weakening or competing foreign writer. +3. **Manifest and buyer-state evidence must remain branch-honest.** Deterministic provenance mismatches are repaired by rebinding exact artifacts, and dynamic PR/ruleset/release statements are freshly refetched instead of being treated as permanent truth. +4. **Review capacity remains the dominant integration constraint.** The effective ruleset requires two qualifying approvals, while the fresh repository-wide review search still has no qualifying open-PR `APPROVE`. ## References (APA 7th) From c27acdc65c3adeb0fcd3695b0db6a62cf106f5dd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 13:55:44 -0700 Subject: [PATCH 011/201] docs: refresh buyer-gap ownership through export and goal activation --- docs/product-technical-gap-baseline.md | 88 +++++++++++--------------- 1 file changed, 36 insertions(+), 52 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5a7c5e17b..cb5174698 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,41 +2,29 @@ Inventory date: 2026-08-26 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, stack ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. +This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, stack ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. -Orgmetra owns authoritative HRIS employment truth inside its published boundaries. Keyverse and other dedicated-writer CWL repositories remain read-only dependencies consumed only through published package/API/event contracts and existing owner-control paths. No static product-gap document may authorize a write into another dedicated-writer repository. +Orgmetra owns authoritative HRIS/HCM truth only inside its published boundaries. Keyverse and the other dedicated-writer CWL repositories remain read-only dependencies consumed through published package/API/event contracts and existing owner-control paths. A static product-gap document never authorizes writes into another dedicated-writer repository. ## Effective repository-control truth -The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-26 show this ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`, which includes Orgmetra `develop`. +The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. -The active ruleset requires: +The active ruleset requires pull-request integration, **2 approving reviews**, stale-approval dismissal after a push, approval after the last push, review-thread resolution, extra approval for unattributed changes, the central required-workflow set, branch-deletion protection, and non-fast-forward protection. -- pull-request integration; -- **2 approving reviews**; -- dismissal of stale approvals after a push; -- approval after the last push; -- required review-thread resolution; -- extra approval for unattributed changes; -- the central required-workflow set from `ContextualWisdomLab/.github@main` (`close-empty-pr.yml`, `opencode-review.yml`, `pr-review-merge-scheduler.yml`, `security-scan.yml`, `strix.yml`, `sast-semgrep.yml`, and `noema-review.yml`); -- branch-deletion protection; and -- non-fast-forward protection. +Issue #89 tracks the remaining acquisition-grade control gaps. `OrganizationAdmin` still has an `always` bypass and the connected user reports `current_user_can_bypass=always`; routine administrator bypass is not an acceptable steady-state commercial control. In addition, the effective ruleset does not itself enumerate every Orgmetra-local Foundation, Recovery, exact coverage/package/provenance, and product-quality gate, so merge readiness must continue to require fresh exact-head terminal GREEN for every applicable local gate unless fail-closed composition is directly proven. Finally, multiple technically GREEN PRs have been converted back to Draft by a separate same-repository lifecycle writer; this loop must not race that writer and must treat live lifecycle state as authoritative when that collision is evidenced. -Issue #89 remains open for three narrower commercial-control gaps. First, the effective ruleset still grants `OrganizationAdmin` an `always` bypass and the connected user reports `current_user_can_bypass=always`; routine administrator bypass is not an acceptable steady-state acquisition-grade control. Second, the ruleset does not itself enumerate every Orgmetra-local Foundation, Recovery, coverage/package/provenance, and product-quality gate, so merge readiness must continue to require fresh exact-head terminal GREEN for every applicable local gate unless fail-closed transitive enforcement is proven. Third, multiple technically GREEN PRs have been converted back to Draft by a separate same-repository lifecycle writer; this loop must not race that writer and must treat live lifecycle state as authoritative where the collision is evidenced. - -The classic branch payload may still report `protection.enabled=false`, required-status enforcement `off`, and no classic contexts/checks. That is **not evidence that `develop` has no effective protection** while ruleset 18156473 is active. Buyer-facing documents and PR metadata must not repeat that obsolete inference. +The classic branch payload can still report `protection.enabled=false`, required-status enforcement `off`, and no classic contexts/checks. That is **not evidence that `develop` has no effective protection** while ruleset 18156473 is active. Consequences: -- a GREEN or GitHub-mergeable PR is not merge-authorized; -- two qualifying approvals and the last-push/review-thread rules remain mandatory; -- routine administrator bypass must not be used as a normal merge path; -- no workflow shim, author approval, predecessor check, status-only/model-only result, or force merge substitutes for the effective ruleset plus applicable exact-head local gates; +- GREEN or GitHub-mergeable is not merge authorization; +- two qualifying approvals and the last-push/thread rules remain mandatory; +- routine administrator bypass is not a normal merge path; +- no workflow shim, author approval, predecessor check, status-only/model-only result, or force merge substitutes for the effective ruleset plus applicable exact-head local gates; and - immediately before any future merge, refetch the unchanged exact head, live base, formal reviews, unresolved threads, effective ruleset, and every applicable exact-head check/job. -## Merged buyer-visible anchors on `develop` - -This is a selected shipped inventory, not a replacement for Git history. +## Selected merged buyer-visible anchors on `develop` | Merged PR | Capability | |---|---| @@ -47,24 +35,26 @@ This is a selected shipped inventory, not a replacement for Git history. | #41 | Governed candidate evidence intake | | #43 | Governed offer approval packet | -Do not revive these merged heads. Extend default-branch truth only through a current owner-scoped change when a fresh buyer gap remains. +This is a selected shipped inventory, not a replacement for Git history. Do not revive merged heads; extend default-branch truth only through a current owner-scoped change when a fresh buyer gap remains. ## Fresh control anchors -The following anchors were freshly rechecked during the 2026-08-26 maintenance loop. They are intentionally sparse: an exhaustive static PR table becomes stale faster than it helps buyers or maintainers. +The following anchors were freshly rechecked during the 2026-08-26 maintenance loop. They are intentionally sparse because an exhaustive static PR table becomes stale faster than it helps buyers or maintainers. -- **Oldest dependency-root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`, open, non-draft, mergeable, and exact-head GREEN for Structured Interview Plan, Foundation, SAST, Security, and Recovery. Submitted reviews are COMMENTED only; there is no qualifying `APPROVE`. -- **PR #54** remains exact head `cc6784ec33b1145c342bbbb99ebece1d37aeec80` with Orgmetra-owned product/Foundation/security/recovery evidence GREEN, but it is the sole open `CHANGES_REQUESTED` lane. The cited blocker is owned by the existing central `.github` coverage/review path (`.github#1250` / PR #1052), not an Orgmetra-native source failure. Keep that dependency boundary read-only from this loop. -- **PR #110** is exact head `305757e7daa3e8fd4d79ef385b42828e6f99d04c` and its People/Foundation/Recovery/SAST/Security/Job-Analysis gates are terminal GREEN. GitHub has reported it Draft after a separate same-repository lifecycle writer repeatedly alternated Draft/Ready state, so this loop must not race that writer merely to change PR state. +- **Oldest dependency-root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`, open, non-draft, mergeable, and exact-head GREEN for Structured Interview Plan, Foundation, SAST, Security, and Recovery. All fetched review threads are resolved and submitted reviews are COMMENTED only; there is no qualifying independent `APPROVE`. +- **PR #54** remains exact head `cc6784ec33b1145c342bbbb99ebece1d37aeec80` with Orgmetra-owned product/Foundation/security/recovery evidence GREEN, but it is the sole open `CHANGES_REQUESTED` lane. Its cited blocker is owned by the existing central `.github` coverage/review path (`.github#1250` / PR #1052), not an Orgmetra-native source failure. Keep that dedicated-writer boundary read-only from this loop. +- **PR #75** is exact head `a938a2a145e02db7f378533b9dea36167568c22b`, open, non-draft and mergeable. HR Data Export, Foundation, Recovery, SAST and Security are all exact-head GREEN. Its process-local issuance seal is explicitly defense in depth rather than durable serialization or export authority. +- **PR #110** is exact head `305757e7daa3e8fd4d79ef385b42828e6f99d04c` and its People/Foundation/Recovery/SAST/Security/Job-Analysis gates are terminal GREEN. GitHub has also reported it Draft after a separate same-repository lifecycle writer alternated Draft/Ready state, so this loop must not race that writer merely to change PR lifecycle state. - **PR #113** is exact head `3da7ad076f977a3ccd9e130a58786c9d26763a16` with Workforce/People/Job-Analysis/Foundation/Recovery/SAST/Security GREEN, but live lifecycle state has been controlled by the separate lifecycle writer. Treat the live state as authoritative rather than trusting stale body copy. -- **PR #114** is the dependency-first child of #113 at exact head `656544bc4d86122ee42b50246500bf31785d6d53`; focused `Employment Absence Persistence Quality` is terminal GREEN. This is stack-local evidence only and cannot transfer parent checks/reviews or authorize integration before #113. -- **PR #119** is the dependency-first child of #96 at exact head `2d51b29b4788867c0656282c2ad8fea17c916e34`; focused `Organization Hierarchy Change Application Quality` run `32887781628` / job `97932188148` is terminal GREEN after the TRUNCATE regression was corrected to exercise the table-owned append-only guard. This remains stack-local focused evidence only: #96 must integrate first, then #119 must retarget to fresh `develop` and rerun all applicable integration/security/recovery/product gates. +- **PR #114** is the dependency-first child of #113 at exact head `656544bc4d86122ee42b50246500bf31785d6d53`; focused `Employment Absence Persistence Quality` is terminal GREEN. This is stack-local evidence only. +- **PR #119** is the dependency-first child of #96 at exact head `2d51b29b4788867c0656282c2ad8fea17c916e34`; focused `Organization Hierarchy Change Application Quality` is terminal GREEN after its TRUNCATE regression was corrected to exercise the table-owned append-only guard. It remains stack-local evidence only. +- **PR #121** is the dependency-first performance-goal activation child of #92. Predecessor head `b5815d7c470dab20192dbf590250417296b255fa` reached exact 100% owned statement/branch coverage but failed one test because a case-sensitive error regex expected lowercase `verification` while production correctly emitted the governed type name `PerformanceGoalPlanActivationVerification`. The minimal test-contract repair is exact head `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`; its new hosted evidence must be treated as non-passing until terminal on that exact head. -The repository currently has a large open PR graph. Execution order must come from a fresh oldest/dependency-root-first graph, not from recorded queue counts in this snapshot. +Execution order comes from a fresh oldest/dependency-root-first graph, not from recorded queue counts in this snapshot. -## Active-PR capabilities that are no longer buyer gaps +## Active-PR capabilities that are no longer unowned buyer gaps -Several capabilities previously described as absent now have active owner lanes. They remain **active-PR truth, not default-branch truth**, until integrated. +The capabilities below remain **active-PR truth, not default-branch truth**, until integrated. - Job grade/band governance has a reviewed design-evidence root and a dependency-first bitemporal persistence child. - Candidate offer response and offer-to-hire closure have active evidence/bridge lanes. @@ -72,21 +62,22 @@ Several capabilities previously described as absent now have active owner lanes. - Position lifecycle review/application and Position reporting review/persistence have active dependency-ordered lanes. - HR document evidence and immutable document metadata persistence have active dependency-ordered lanes. - Reason-free authoritative Employment absence truth is implemented on #113, with durable bitemporal persistence on child #114. -- **Purpose-bound HR document retrieval is now owned by PR #116.** That root lane re-resolves exact tenant/document/Person/Employment/artifact/retention scope, requires purpose-bound authorization to remain current through artifact verification, verifies bounded bytes by SHA-256, appends value-minimized immutable audit evidence, and only then releases content. It does not yet make the distinct outbound-export/egress operation a shipped capability. -- **Job-Analysis-specific model-assisted Task/FJA/KSAO drafting is now owned by PR #117.** The lane binds one exact Job Analysis snapshot to canonical semantic units and model provenance, keeps raw model output untrusted, requires a distinct accountable human reviewer, and never grants authoritative Job Analysis persistence by itself. -- **Release-readiness review evidence is now owned by PR #118.** It binds one exact candidate revision to source/SBOM/provenance/test/coverage/security/SAST/recovery/operability/accessibility/migration/rollback/package-reproducibility evidence and remains permanently `not_authorized_to_release`; an actual release still requires fresh integrated-default-branch proof and live governance. -- Organization hierarchy parent-change application is implemented as dependency-first child #119 under review root #96; its focused bitemporal/RLS/audit/concurrency lane is GREEN but remains non-integrated stack-local truth. +- **Purpose-bound HR document retrieval is owned by PR #116.** It re-resolves exact tenant/document/Person/Employment/artifact/retention scope, requires purpose-bound authorization to remain current through artifact verification, verifies bounded bytes by SHA-256, appends value-minimized immutable audit evidence, and only then releases content. +- **Purpose-bound outbound HR export execution is now owned by Draft child PR #120 under #75.** The lane is distinct from retrieval: it freshly re-authorizes exact reviewed scope, materializes protected fields under a hard byte budget, commits value-minimized audit evidence before egress, rechecks authorization freshness after protected work and audit latency, and only then permits a host-owned one-time-download egress port. #120 is still based on an older #75 head, so it must not inherit the repaired parent evidence; #75 must integrate first and #120 must then retarget/revalidate on fresh `develop`. +- **Job-Analysis-specific model-assisted Task/FJA/KSAO drafting is owned by PR #117.** Raw model output remains untrusted draft evidence and a distinct accountable human reviewer is required. +- **Release-readiness review evidence is owned by PR #118.** It binds one exact candidate revision to source/SBOM/provenance/test/coverage/security/SAST/recovery/operability/accessibility/migration/rollback/package-reproducibility evidence and remains `not_authorized_to_release`. +- **Performance-goal authoritative activation is now owned by Draft child PR #121 under #92.** The activation boundary requires the reviewed human actor, exact scope re-verification, mutation-resistant plan evidence and a non-decision activation receipt. It remains dependency-first and non-integrated; authoritative durable goal-plan persistence is still a separate gap. +- Organization hierarchy parent-change application is implemented as dependency-first child #119 under review root #96; its focused bitemporal/RLS/audit/concurrency lane is GREEN but non-integrated. -Do not describe these capabilities as shipped until their owner PRs integrate into fresh `develop`. +Do not describe any of these capabilities as shipped until their owner PRs integrate into fresh `develop`. -## Highest-value buyer gaps after the current queue +## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Purpose-bound HR export/egress execution.** Export-review evidence and purpose-bound document retrieval now have owner lanes, but Orgmetra still needs a distinct outbound operation that re-resolves the exact authorized fields/artifact, destination class, retention/legal-hold state, human export approval, authorization freshness, egress policy, immutable audit/outbox and final byte/hash evidence immediately before data leaves the Orgmetra boundary. Retrieval authorization must not be treated as export authorization. -2. **Authoritative performance-goal activation/persistence.** PR #92 owns value-minimized performance goal-plan review evidence, but no current owner lane persists or applies a reviewed plan as authoritative bitemporal performance-goal truth. Any implementation must re-resolve Employment/Job/cycle scope, preserve goal/rating separation, require human authority, and append immutable audit/outbox evidence; review packets must not mutate authoritative truth by themselves. -3. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. -4. **Authoritative release operation after governed readiness review.** PR #118 owns non-authorizing release-readiness evidence, but no release/version/tag is authorized until one exact integrated `develop` head satisfies all applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together, the live ruleset and qualifying approvals are freshly verified, and source/artifact hashes are rechecked. The future operation must fail closed rather than converting a review packet into release authority. +1. **Authoritative performance-goal persistence after activation.** PR #92 owns goal-plan review evidence and #121 owns the dependency-first activation boundary, but no current owner lane persists an activated plan as authoritative bitemporal performance-goal truth. Any future persistence lane must re-resolve Employment/Job/cycle scope, preserve goal/rating separation, require accountable human authority, bind the activation evidence version and append immutable audit/outbox evidence. Review or activation packets must not mutate authoritative truth by themselves. +2. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. +3. **Authoritative release operation after governed readiness review.** PR #118 owns non-authorizing release-readiness evidence, but no release/version/tag is authorized until one exact integrated `develop` head satisfies all applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together, the live ruleset and qualifying approvals are freshly verified, and source/artifact hashes are rechecked. A future release operation must fail closed rather than converting a review packet into release authority. External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. @@ -107,14 +98,7 @@ External finance/accounting and billing/collection integration remains planned/o Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, formal reviews/threads, exact-head workflows/jobs, releases, changed refs and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when an executable regression is appropriate; rerun exact-head evidence; resolve only addressed threads; and merge only when the unchanged head satisfies the effective ruleset plus every applicable local gate. Refresh this document only after material buyer/product state changes and never use its recorded SHAs as current control-plane truth. -For live-state documentation defects such as repository ruleset truth or active owner-lane ownership, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop must refetch the effective ruleset/current PR graph and reject stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. - -### 2026-08-25/26 review-triage and provider-repair progress - -1. **Open review threads remain an approval bottleneck, and triage is performed against current source.** The central approve-gate treats unresolved non-outdated threads as blockers, so findings are verified rather than mechanically accepted. Repaired findings are resolved only after current-head evidence; informational observations remain informational. -2. **Central review/provider failures stay at their dedicated owner boundary.** PR #54 demonstrates the rule: its Orgmetra-native gates are GREEN while its current `CHANGES_REQUESTED` cites a central `.github` coverage/review failure. Repair stays on the existing central owner path; Orgmetra does not create a local weakening or competing foreign writer. -3. **Manifest and buyer-state evidence must remain branch-honest.** Deterministic provenance mismatches are repaired by rebinding exact artifacts, and dynamic PR/ruleset/release statements are freshly refetched instead of being treated as permanent truth. -4. **Review capacity remains the dominant integration constraint.** The effective ruleset requires two qualifying approvals, while the fresh repository-wide review search still has no qualifying open-PR `APPROVE`. +For live-state documentation defects such as repository ruleset truth or active owner-lane ownership, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop refetches the effective ruleset/current PR graph and rejects stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. ## References (APA 7th) @@ -124,4 +108,4 @@ Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management — Requirements and recommendations for human capital reporting and disclosure*. ISO. -Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). \ No newline at end of file +Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). From cf089816fd6040d46a39c2ee6c0220e865090a75 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 26 Aug 2026 06:54:37 +0900 Subject: [PATCH 012/201] docs: record 2026-08-26 review-triage sweep and repair ledger --- docs/product-technical-gap-baseline.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index cb5174698..7c71d7e9b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -41,6 +41,14 @@ This is a selected shipped inventory, not a replacement for Git history. Do not The following anchors were freshly rechecked during the 2026-08-26 maintenance loop. They are intentionally sparse because an exhaustive static PR table becomes stale faster than it helps buyers or maintainers. +### 2026-08-26 review-triage sweep (this loop) + +Every open non-draft lane's unresolved review threads were triaged to zero or answered with exact-head evidence, and verified defects were repaired at their owning boundaries: + +- Runtime-integrity repairs pushed: #46 digest exact-type boundary (`5e611821`+`30052671`), #47 digest exact-type (`8562166d`), #62 str-subclass/overflow closure (`6ad5b867`), #71 dead except arms (`1d7ed5bb`), #79 probe/scratch/manifest-tracking plus provenance branch truth (`31b623ae`,`d4750c0c`,`3f8a2826`), #80 overflow normalization (`a72463a4`), #90 telemetry start-time defense (concurrent `5be8b828`), #92 off-lifecycle export governance (`52fe06e2`), #93 KeyError-to-governance-error + label truth (`0163d9ab`), #97 ratio-band revalidation and canonical four-place FTE scale (`642e0afd`,`dc942b35`), #111 coverable binding-drift release (`de9fc672`,`03f3f6de`), #116 documented freshness recheck + `__all__` order (`54314a3e`), #117/#118 explicit src-layout discovery (`2994f942`,`eb529093`). +- Declined-with-evidence findings: #70 same-status overlap rejection (DATA_MODEL single-valued version-family invariant and employment-coverage precedent), #91 clean-checkout claim (`.gitignore` covers compileall artifacts; exact-head GREEN proves it), #66 anchor-orphan premise (anchors are immutable; corrections version, never re-anchor). +- Cross-module convergence items recorded for future reviewed sweeps: WeakKeyDictionary issuance registries everywhere, reflective payload inventories, uniform exact-type validators, ADR multi-word status parsing, org-loop consecutive-failure alerting. + - **Oldest dependency-root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`, open, non-draft, mergeable, and exact-head GREEN for Structured Interview Plan, Foundation, SAST, Security, and Recovery. All fetched review threads are resolved and submitted reviews are COMMENTED only; there is no qualifying independent `APPROVE`. - **PR #54** remains exact head `cc6784ec33b1145c342bbbb99ebece1d37aeec80` with Orgmetra-owned product/Foundation/security/recovery evidence GREEN, but it is the sole open `CHANGES_REQUESTED` lane. Its cited blocker is owned by the existing central `.github` coverage/review path (`.github#1250` / PR #1052), not an Orgmetra-native source failure. Keep that dedicated-writer boundary read-only from this loop. - **PR #75** is exact head `a938a2a145e02db7f378533b9dea36167568c22b`, open, non-draft and mergeable. HR Data Export, Foundation, Recovery, SAST and Security are all exact-head GREEN. Its process-local issuance seal is explicitly defense in depth rather than durable serialization or export authority. From f41df5ec325041132c0dbfd71f59f944b8b234d1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 22:03:21 -0700 Subject: [PATCH 013/201] docs: refresh product gap control truth --- docs/product-technical-gap-baseline.md | 83 ++++++++++---------------- 1 file changed, 32 insertions(+), 51 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7c71d7e9b..9d4f5e688 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,29 +2,36 @@ Inventory date: 2026-08-26 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, stack ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. +This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. Orgmetra owns authoritative HRIS/HCM truth only inside its published boundaries. Keyverse and the other dedicated-writer CWL repositories remain read-only dependencies consumed through published package/API/event contracts and existing owner-control paths. A static product-gap document never authorizes writes into another dedicated-writer repository. ## Effective repository-control truth -The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. +The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-26 show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. -The active ruleset requires pull-request integration, **2 approving reviews**, stale-approval dismissal after a push, approval after the last push, review-thread resolution, extra approval for unattributed changes, the central required-workflow set, branch-deletion protection, and non-fast-forward protection. +The **current live ruleset is weaker than Orgmetra's acquisition-grade acceptance policy**: -Issue #89 tracks the remaining acquisition-grade control gaps. `OrganizationAdmin` still has an `always` bypass and the connected user reports `current_user_can_bypass=always`; routine administrator bypass is not an acceptable steady-state commercial control. In addition, the effective ruleset does not itself enumerate every Orgmetra-local Foundation, Recovery, exact coverage/package/provenance, and product-quality gate, so merge readiness must continue to require fresh exact-head terminal GREEN for every applicable local gate unless fail-closed composition is directly proven. Finally, multiple technically GREEN PRs have been converted back to Draft by a separate same-repository lifecycle writer; this loop must not race that writer and must treat live lifecycle state as authoritative when that collision is evidenced. +- it requires **1** approving review, not two; +- `dismiss_stale_reviews_on_push = true`; +- `require_last_push_approval = false`; +- review-thread resolution and extra approval for unattributed changes remain enabled; +- the central required-workflow set plus deletion/non-fast-forward protection remain enabled; and +- `OrganizationAdmin` retains `bypass_mode=always`, while the connected user reports `current_user_can_bypass=always`. -The classic branch payload can still report `protection.enabled=false`, required-status enforcement `off`, and no classic contexts/checks. That is **not evidence that `develop` has no effective protection** while ruleset 18156473 is active. +Issue #89 owns the remaining repository-governance gap. Orgmetra's commercial acceptance remains stricter than the live ruleset: **at least two qualifying independent non-author approvals, approval after the last push, resolved conversations, every applicable exact-current-head local/central gate terminal GREEN, and no routine administrator bypass**. Organization-settings changes belong to the existing central owner-control path; Orgmetra must not simulate them with a workflow shim. + +The classic branch payload can still report `protection.enabled=false`, required-status enforcement `off`, and no classic contexts/checks. That is **not** evidence that `develop` lacks an effective ruleset while organization ruleset 18156473 is active. Consequences: - GREEN or GitHub-mergeable is not merge authorization; -- two qualifying approvals and the last-push/thread rules remain mandatory; +- queued, pending, cancelled, skipped, neutral, absent, stale, predecessor, status-only, or model-only evidence is non-passing; - routine administrator bypass is not a normal merge path; -- no workflow shim, author approval, predecessor check, status-only/model-only result, or force merge substitutes for the effective ruleset plus applicable exact-head local gates; and +- a technically GREEN PR that another same-repository lifecycle writer has returned to Draft remains Draft until that authoritative writer advances it; and - immediately before any future merge, refetch the unchanged exact head, live base, formal reviews, unresolved threads, effective ruleset, and every applicable exact-head check/job. -## Selected merged buyer-visible anchors on `develop` +## Selected shipped buyer-visible anchors on `develop` | Merged PR | Capability | |---|---| @@ -35,57 +42,31 @@ Consequences: | #41 | Governed candidate evidence intake | | #43 | Governed offer approval packet | -This is a selected shipped inventory, not a replacement for Git history. Do not revive merged heads; extend default-branch truth only through a current owner-scoped change when a fresh buyer gap remains. - -## Fresh control anchors - -The following anchors were freshly rechecked during the 2026-08-26 maintenance loop. They are intentionally sparse because an exhaustive static PR table becomes stale faster than it helps buyers or maintainers. - -### 2026-08-26 review-triage sweep (this loop) - -Every open non-draft lane's unresolved review threads were triaged to zero or answered with exact-head evidence, and verified defects were repaired at their owning boundaries: - -- Runtime-integrity repairs pushed: #46 digest exact-type boundary (`5e611821`+`30052671`), #47 digest exact-type (`8562166d`), #62 str-subclass/overflow closure (`6ad5b867`), #71 dead except arms (`1d7ed5bb`), #79 probe/scratch/manifest-tracking plus provenance branch truth (`31b623ae`,`d4750c0c`,`3f8a2826`), #80 overflow normalization (`a72463a4`), #90 telemetry start-time defense (concurrent `5be8b828`), #92 off-lifecycle export governance (`52fe06e2`), #93 KeyError-to-governance-error + label truth (`0163d9ab`), #97 ratio-band revalidation and canonical four-place FTE scale (`642e0afd`,`dc942b35`), #111 coverable binding-drift release (`de9fc672`,`03f3f6de`), #116 documented freshness recheck + `__all__` order (`54314a3e`), #117/#118 explicit src-layout discovery (`2994f942`,`eb529093`). -- Declined-with-evidence findings: #70 same-status overlap rejection (DATA_MODEL single-valued version-family invariant and employment-coverage precedent), #91 clean-checkout claim (`.gitignore` covers compileall artifacts; exact-head GREEN proves it), #66 anchor-orphan premise (anchors are immutable; corrections version, never re-anchor). -- Cross-module convergence items recorded for future reviewed sweeps: WeakKeyDictionary issuance registries everywhere, reflective payload inventories, uniform exact-type validators, ADR multi-word status parsing, org-loop consecutive-failure alerting. - -- **Oldest dependency-root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`, open, non-draft, mergeable, and exact-head GREEN for Structured Interview Plan, Foundation, SAST, Security, and Recovery. All fetched review threads are resolved and submitted reviews are COMMENTED only; there is no qualifying independent `APPROVE`. -- **PR #54** remains exact head `cc6784ec33b1145c342bbbb99ebece1d37aeec80` with Orgmetra-owned product/Foundation/security/recovery evidence GREEN, but it is the sole open `CHANGES_REQUESTED` lane. Its cited blocker is owned by the existing central `.github` coverage/review path (`.github#1250` / PR #1052), not an Orgmetra-native source failure. Keep that dedicated-writer boundary read-only from this loop. -- **PR #75** is exact head `a938a2a145e02db7f378533b9dea36167568c22b`, open, non-draft and mergeable. HR Data Export, Foundation, Recovery, SAST and Security are all exact-head GREEN. Its process-local issuance seal is explicitly defense in depth rather than durable serialization or export authority. -- **PR #110** is exact head `305757e7daa3e8fd4d79ef385b42828e6f99d04c` and its People/Foundation/Recovery/SAST/Security/Job-Analysis gates are terminal GREEN. GitHub has also reported it Draft after a separate same-repository lifecycle writer alternated Draft/Ready state, so this loop must not race that writer merely to change PR lifecycle state. -- **PR #113** is exact head `3da7ad076f977a3ccd9e130a58786c9d26763a16` with Workforce/People/Job-Analysis/Foundation/Recovery/SAST/Security GREEN, but live lifecycle state has been controlled by the separate lifecycle writer. Treat the live state as authoritative rather than trusting stale body copy. -- **PR #114** is the dependency-first child of #113 at exact head `656544bc4d86122ee42b50246500bf31785d6d53`; focused `Employment Absence Persistence Quality` is terminal GREEN. This is stack-local evidence only. -- **PR #119** is the dependency-first child of #96 at exact head `2d51b29b4788867c0656282c2ad8fea17c916e34`; focused `Organization Hierarchy Change Application Quality` is terminal GREEN after its TRUNCATE regression was corrected to exercise the table-owned append-only guard. It remains stack-local evidence only. -- **PR #121** is the dependency-first performance-goal activation child of #92. Predecessor head `b5815d7c470dab20192dbf590250417296b255fa` reached exact 100% owned statement/branch coverage but failed one test because a case-sensitive error regex expected lowercase `verification` while production correctly emitted the governed type name `PerformanceGoalPlanActivationVerification`. The minimal test-contract repair is exact head `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`; its new hosted evidence must be treated as non-passing until terminal on that exact head. - -Execution order comes from a fresh oldest/dependency-root-first graph, not from recorded queue counts in this snapshot. +This is a selected shipped inventory, not a replacement for Git history. Do not describe active-PR capability as shipped until its owner PR integrates into fresh `develop`. -## Active-PR capabilities that are no longer unowned buyer gaps +## Fresh active-owner truth -The capabilities below remain **active-PR truth, not default-branch truth**, until integrated. +The following material owner lanes were freshly rechecked during the 2026-08-26 maintenance loop. -- Job grade/band governance has a reviewed design-evidence root and a dependency-first bitemporal persistence child. -- Candidate offer response and offer-to-hire closure have active evidence/bridge lanes. -- Vacancy-to-Assignment fill orchestration is implemented on #110 and delegates final persistence to the authoritative People mutation boundary. -- Position lifecycle review/application and Position reporting review/persistence have active dependency-ordered lanes. -- HR document evidence and immutable document metadata persistence have active dependency-ordered lanes. -- Reason-free authoritative Employment absence truth is implemented on #113, with durable bitemporal persistence on child #114. -- **Purpose-bound HR document retrieval is owned by PR #116.** It re-resolves exact tenant/document/Person/Employment/artifact/retention scope, requires purpose-bound authorization to remain current through artifact verification, verifies bounded bytes by SHA-256, appends value-minimized immutable audit evidence, and only then releases content. -- **Purpose-bound outbound HR export execution is now owned by Draft child PR #120 under #75.** The lane is distinct from retrieval: it freshly re-authorizes exact reviewed scope, materializes protected fields under a hard byte budget, commits value-minimized audit evidence before egress, rechecks authorization freshness after protected work and audit latency, and only then permits a host-owned one-time-download egress port. #120 is still based on an older #75 head, so it must not inherit the repaired parent evidence; #75 must integrate first and #120 must then retarget/revalidate on fresh `develop`. -- **Job-Analysis-specific model-assisted Task/FJA/KSAO drafting is owned by PR #117.** Raw model output remains untrusted draft evidence and a distinct accountable human reviewer is required. -- **Release-readiness review evidence is owned by PR #118.** It binds one exact candidate revision to source/SBOM/provenance/test/coverage/security/SAST/recovery/operability/accessibility/migration/rollback/package-reproducibility evidence and remains `not_authorized_to_release`. -- **Performance-goal authoritative activation is now owned by Draft child PR #121 under #92.** The activation boundary requires the reviewed human actor, exact scope re-verification, mutation-resistant plan evidence and a non-decision activation receipt. It remains dependency-first and non-integrated; authoritative durable goal-plan persistence is still a separate gap. -- Organization hierarchy parent-change application is implemented as dependency-first child #119 under review root #96; its focused bitemporal/RLS/audit/concurrency lane is GREEN but non-integrated. +- **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The existing foreign owner path is `.github#1250` / PR #1052; Orgmetra must not weaken local 100% coverage to compensate. +- **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. +- **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and now fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. +- **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation and has focused exact-head GREEN; **#125 now owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125 remains Draft with its exact-head persistence workflow queued, so none of this stack is shipped truth. +- **PR #118** owns non-authorizing release-readiness evidence. Its branch has advanced to exact head `eb529093b44be17bb282d3fd5c6c592d66f111af` with explicit src-layout package discovery. Release Readiness/Foundation/Recovery/SAST are GREEN on that head, while the current Security Scan is non-passing because the `osv-scan` job failed during `Set up job` before any source checkout or scan step. That pre-source failure is not converted into an Orgmetra product-code workaround, and no release authority is inferred from predecessor GREEN. +- **PR #124** owns the hardware-acceleration ADR security hardening. Hardware Acceleration ADR/Recovery/Job-Analysis/SAST/Security are GREEN on exact head `007c4133b60af46cc2a0771e5a393a86a2342a7d`, while Foundation CI remains queued; keep it non-passing until Foundation terminates successfully on the same head. +- **PR #123** owns customer-facing copy cleanup on exact head `382a46ac31222bf32980e27ed4c998a8ce019095`; every materialized exact-head Orgmetra workflow is GREEN and Devin reports zero issues, but there is still no qualifying independent approval. +- **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. +- **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. -Do not describe any of these capabilities as shipped until their owner PRs integrate into fresh `develop`. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation, and performance-goal persistence remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Authoritative performance-goal persistence after activation.** PR #92 owns goal-plan review evidence and #121 owns the dependency-first activation boundary, but no current owner lane persists an activated plan as authoritative bitemporal performance-goal truth. Any future persistence lane must re-resolve Employment/Job/cycle scope, preserve goal/rating separation, require accountable human authority, bind the activation evidence version and append immutable audit/outbox evidence. Review or activation packets must not mutate authoritative truth by themselves. -2. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. -3. **Authoritative release operation after governed readiness review.** PR #118 owns non-authorizing release-readiness evidence, but no release/version/tag is authorized until one exact integrated `develop` head satisfies all applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together, the live ruleset and qualifying approvals are freshly verified, and source/artifact hashes are rechecked. A future release operation must fail closed rather than converting a review packet into release authority. +1. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities need cohesive Product Design/Figma handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. +2. **Authoritative release operation after governed readiness review.** PR #118 deliberately stops at `not_authorized_to_release`. No release/version/tag is authorized until one exact integrated `develop` head satisfies build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together, the live ruleset and qualifying approvals are freshly verified, and source/artifact hashes are rechecked. A future operation boundary must freshly authorize the exact integrated revision and fail closed rather than turning a review packet into release authority. +3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. @@ -104,7 +85,7 @@ External finance/accounting and billing/collection integration remains planned/o ## Execution loop -Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, formal reviews/threads, exact-head workflows/jobs, releases, changed refs and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when an executable regression is appropriate; rerun exact-head evidence; resolve only addressed threads; and merge only when the unchanged head satisfies the effective ruleset plus every applicable local gate. Refresh this document only after material buyer/product state changes and never use its recorded SHAs as current control-plane truth. +Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, formal reviews/threads, exact-head workflows/jobs, releases, changed refs and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when an executable regression is appropriate; rerun exact-head evidence; resolve only addressed threads; and merge only when the unchanged head satisfies the effective ruleset plus every applicable local gate. For live-state documentation defects such as repository ruleset truth or active owner-lane ownership, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop refetches the effective ruleset/current PR graph and rejects stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. From 5d5748e02a1fa605d621eb85e7cc284058d0cbd0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 26 Aug 2026 11:07:23 -0700 Subject: [PATCH 014/201] docs: refresh commercial gap ownership --- docs/product-technical-gap-baseline.md | 19 ++++++++++--------- 1 file changed, 10 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9d4f5e688..b93518c13 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product and technical gap baseline -Inventory date: 2026-08-26 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Inventory date: 2026-08-27 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -8,7 +8,7 @@ Orgmetra owns authoritative HRIS/HCM truth only inside its published boundaries. ## Effective repository-control truth -The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-26 show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. +The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-27 show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. The **current live ruleset is weaker than Orgmetra's acquisition-grade acceptance policy**: @@ -46,26 +46,27 @@ This is a selected shipped inventory, not a replacement for Git history. Do not ## Fresh active-owner truth -The following material owner lanes were freshly rechecked during the 2026-08-26 maintenance loop. +The following material owner lanes were freshly rechecked during the 2026-08-27 maintenance loop. - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The existing foreign owner path is `.github#1250` / PR #1052; Orgmetra must not weaken local 100% coverage to compensate. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and now fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. -- **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation and has focused exact-head GREEN; **#125 now owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125 remains Draft with its exact-head persistence workflow queued, so none of this stack is shipped truth. -- **PR #118** owns non-authorizing release-readiness evidence. Its branch has advanced to exact head `eb529093b44be17bb282d3fd5c6c592d66f111af` with explicit src-layout package discovery. Release Readiness/Foundation/Recovery/SAST are GREEN on that head, while the current Security Scan is non-passing because the `osv-scan` job failed during `Set up job` before any source checkout or scan step. That pre-source failure is not converted into an Orgmetra product-code workaround, and no release authority is inferred from predecessor GREEN. -- **PR #124** owns the hardware-acceleration ADR security hardening. Hardware Acceleration ADR/Recovery/Job-Analysis/SAST/Security are GREEN on exact head `007c4133b60af46cc2a0771e5a393a86a2342a7d`, while Foundation CI remains queued; keep it non-passing until Foundation terminates successfully on the same head. +- **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. +- **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. +- **PR #118 → #126 → #127** now owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. +- **PR #124** owns the hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`. Hardware Acceleration ADR/Foundation/Recovery/Job-Analysis/SAST/Security are all terminal GREEN on that head; live Draft state remains authoritative because of a separate lifecycle writer. - **PR #123** owns customer-facing copy cleanup on exact head `382a46ac31222bf32980e27ed4c998a8ce019095`; every materialized exact-head Orgmetra workflow is GREEN and Devin reports zero issues, but there is still no qualifying independent approval. - **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. +- **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation, and performance-goal persistence remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, and release authorization/publication remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. 1. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities need cohesive Product Design/Figma handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. -2. **Authoritative release operation after governed readiness review.** PR #118 deliberately stops at `not_authorized_to_release`. No release/version/tag is authorized until one exact integrated `develop` head satisfies build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together, the live ruleset and qualifying approvals are freshly verified, and source/artifact hashes are rechecked. A future operation boundary must freshly authorize the exact integrated revision and fail closed rather than turning a review packet into release authority. +2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. From 2a1213867a5659666ae97191ccda11613d1a04f9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 04:01:56 -0700 Subject: [PATCH 015/201] docs(product): record protected-read UI owner lane --- docs/product-technical-gap-baseline.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b93518c13..c2dbffe7a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,6 +50,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-27 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The existing foreign owner path is `.github#1250` / PR #1052; Orgmetra must not weaken local 100% coverage to compensate. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. +- **PR #53 → #130** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. Do not open a competing shared protected-read-state UI writer. - **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. - **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. - **PR #118 → #126 → #127** now owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. @@ -59,13 +60,13 @@ The following material owner lanes were freshly rechecked during the 2026-08-27 - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, and release authorization/publication remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and HR Workspace protected-read interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Accessible buyer interaction for newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities need cohesive Product Design/Figma handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. The existing HR workspace lane is an anchor, not permission to invent unavailable default-branch APIs. +1. **Complete accessible buyer interaction without duplicating #130.** The shared protected-read state pattern is now owned by #130 under #53, so a second generic loading/error/read-only/focus writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities **after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs**. Reuse #130's protected-read state semantics and existing design tokens where applicable, then add only workflow-specific high-risk confirmation, keyboard/focus/ARIA, evidence provenance and customer next-action behavior. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. @@ -98,4 +99,4 @@ Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management — Requirements and recommendations for human capital reporting and disclosure*. ISO. -Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). +Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). \ No newline at end of file From c5c322b5cbaeffdca929a7d18e8f0c238844f84c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 05:13:14 -0700 Subject: [PATCH 016/201] docs(product): assign export delivery UI owner lane --- docs/product-technical-gap-baseline.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c2dbffe7a..2f1faf938 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-27 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The existing foreign owner path is `.github#1250` / PR #1052; Orgmetra must not weaken local 100% coverage to compensate. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #53 → #130** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. Do not open a competing shared protected-read-state UI writer. -- **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. +- **PR #53 → #130 → #131** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 now owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has `HR Workspace Export Delivery State Quality` run `33070554785` / job `98511379714` terminal GREEN with exact 100% line/branch/function thresholds and clean checkout. Both children remain Draft, dependency-first active-PR truth. Do not open a competing shared protected-read or one-time-export interaction writer. +- **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. - **PR #118 → #126 → #127** now owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. - **PR #124** owns the hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`. Hardware Acceleration ADR/Foundation/Recovery/Job-Analysis/SAST/Security are all terminal GREEN on that head; live Draft state remains authoritative because of a separate lifecycle writer. @@ -60,13 +60,13 @@ The following material owner lanes were freshly rechecked during the 2026-08-27 - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and HR Workspace protected-read interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, and one-time HR export delivery interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating #130.** The shared protected-read state pattern is now owned by #130 under #53, so a second generic loading/error/read-only/focus writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, export and performance-goal capabilities **after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs**. Reuse #130's protected-read state semantics and existing design tokens where applicable, then add only workflow-specific high-risk confirmation, keyboard/focus/ARIA, evidence provenance and customer next-action behavior. +1. **Complete accessible buyer interaction without duplicating #130/#131.** The shared protected-read state pattern is owned by #130 under #53 and the one-time export delivery interaction is now owned by #131, so another generic loading/error/read-only/focus writer or parallel export-confirmation writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity and performance-goal capabilities **after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs**. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From 817c44ea14076eedbab1b882797e40ec40bfecff Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 08:18:09 -0700 Subject: [PATCH 017/201] docs: assign document retrieval UI owner and refresh central handoff truth --- docs/product-technical-gap-baseline.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2f1faf938..4fc2b72f8 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product and technical gap baseline -Inventory date: 2026-08-27 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Inventory date: 2026-08-28 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -8,7 +8,7 @@ Orgmetra owns authoritative HRIS/HCM truth only inside its published boundaries. ## Effective repository-control truth -The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-27 show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. +The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-28 show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. The **current live ruleset is weaker than Orgmetra's acquisition-grade acceptance policy**: @@ -46,27 +46,27 @@ This is a selected shipped inventory, not a replacement for Git history. Do not ## Fresh active-owner truth -The following material owner lanes were freshly rechecked during the 2026-08-27 maintenance loop. +The following material owner lanes were freshly rechecked during the 2026-08-28 maintenance loop. -- **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The existing foreign owner path is `.github#1250` / PR #1052; Orgmetra must not weaken local 100% coverage to compensate. +- **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #53 → #130 → #131** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 now owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has `HR Workspace Export Delivery State Quality` run `33070554785` / job `98511379714` terminal GREEN with exact 100% line/branch/function thresholds and clean checkout. Both children remain Draft, dependency-first active-PR truth. Do not open a competing shared protected-read or one-time-export interaction writer. +- **PR #53 → #130 with workflow-specific children #131 and #132** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 now owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. All children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, or document-retrieval interaction writer. - **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. -- **PR #118 → #126 → #127** now owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. +- **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. - **PR #124** owns the hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`. Hardware Acceleration ADR/Foundation/Recovery/Job-Analysis/SAST/Security are all terminal GREEN on that head; live Draft state remains authoritative because of a separate lifecycle writer. - **PR #123** owns customer-facing copy cleanup on exact head `382a46ac31222bf32980e27ed4c998a8ce019095`; every materialized exact-head Orgmetra workflow is GREEN and Devin reports zero issues, but there is still no qualifying independent approval. -- **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. +- **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence and never imports or substitutes for #116 authorization/audit semantics. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, and one-time HR export delivery interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, and HR document retrieval interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating #130/#131.** The shared protected-read state pattern is owned by #130 under #53 and the one-time export delivery interaction is now owned by #131, so another generic loading/error/read-only/focus writer or parallel export-confirmation writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for Job-grade, document, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity and performance-goal capabilities **after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs**. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. +1. **Complete accessible buyer interaction without duplicating #130/#131/#132.** The shared protected-read state pattern is owned by #130 under #53, the one-time export delivery interaction by #131, and the HR document retrieval interaction by #132. Another generic loading/error/read-only/focus writer, parallel export-confirmation writer, or duplicate document-retrieval interaction writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for Job-grade, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, and performance-goal capabilities **after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs**. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From c171601b0d702654484b99585ac0eefe02799b59 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 10:05:19 -0700 Subject: [PATCH 018/201] docs: assign Job grade UI owner in buyer gap baseline --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4fc2b72f8..3dfc4b9d5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,7 +50,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #53 → #130 with workflow-specific children #131 and #132** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 now owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. All children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, or document-retrieval interaction writer. +- **PR #53 → #130 with workflow-specific children #131, #132, and #134** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#134 owns the workflow-specific Job grade design-review interaction** as another sibling child of #130: loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale-evidence recovery, authorization denial and failure recovery while explicitly retaining no compensation/promotion/assignment/candidate/employment-decision authority. #134 exact head `83a6bdf6af86cf4a79ddbcd7e35b24f74da9322d` has `HR Workspace Job Grade Review State Quality` run `33091544470` / job `98585381713` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. All children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, or Job-grade review interaction writer. - **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. @@ -60,13 +60,13 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, and HR document retrieval interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, HR document retrieval interaction states, and Job-grade review interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating #130/#131/#132.** The shared protected-read state pattern is owned by #130 under #53, the one-time export delivery interaction by #131, and the HR document retrieval interaction by #132. Another generic loading/error/read-only/focus writer, parallel export-confirmation writer, or duplicate document-retrieval interaction writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for Job-grade, Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, and performance-goal capabilities **after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs**. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. +1. **Complete accessible buyer interaction without duplicating #130/#131/#132/#134.** The shared protected-read state pattern is owned by #130 under #53, the one-time export delivery interaction by #131, the HR document retrieval interaction by #132, and the Job-grade design-review interaction by #134. Another generic loading/error/read-only/focus writer, parallel export-confirmation writer, duplicate document-retrieval writer, or second Job-grade review-state writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, and performance-goal capabilities **after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs**. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From d4fd7a6d3924e8de35656852b862a3bd0a8780ab Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 12:11:04 -0700 Subject: [PATCH 019/201] docs: assign Position lifecycle UI ownership --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3dfc4b9d5..be63249b8 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,7 +50,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #53 → #130 with workflow-specific children #131, #132, and #134** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#134 owns the workflow-specific Job grade design-review interaction** as another sibling child of #130: loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale-evidence recovery, authorization denial and failure recovery while explicitly retaining no compensation/promotion/assignment/candidate/employment-decision authority. #134 exact head `83a6bdf6af86cf4a79ddbcd7e35b24f74da9322d` has `HR Workspace Job Grade Review State Quality` run `33091544470` / job `98585381713` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. All children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, or Job-grade review interaction writer. +- **PR #53 → #130 with workflow-specific children #131, #132, #134, and #135** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#134 owns the workflow-specific Job grade design-review interaction** as another sibling child of #130: loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale-evidence recovery, authorization denial and failure recovery while explicitly retaining no compensation/promotion/assignment/candidate/employment-decision authority. #134 exact head `83a6bdf6af86cf4a79ddbcd7e35b24f74da9322d` has `HR Workspace Job Grade Review State Quality` run `33091544470` / job `98585381713` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#135 owns the workflow-specific Position lifecycle human-review interaction** as another sibling child of #130: fresh Position/Assignment evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, read-only recorded evidence, stale-evidence and staffing-conflict fail-closed states, authorization denial and failure recovery, while explicitly retaining no Position mutation authority. #135 exact head `99a4f186a1131809165b188a4865ccb89ee3f4f3` has `HR Workspace Position Lifecycle Review State Quality` run `33107012654` / job `98639432674` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. #111 remains the separate Position lifecycle review-evidence owner and #112 the authoritative application owner. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade review, or Position-lifecycle review interaction writer. - **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. @@ -60,13 +60,13 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, HR document retrieval interaction states, and Job-grade review interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, HR document retrieval interaction states, Job-grade review interaction states, and Position lifecycle review interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating #130/#131/#132/#134.** The shared protected-read state pattern is owned by #130 under #53, the one-time export delivery interaction by #131, the HR document retrieval interaction by #132, and the Job-grade design-review interaction by #134. Another generic loading/error/read-only/focus writer, parallel export-confirmation writer, duplicate document-retrieval writer, or second Job-grade review-state writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for Position lifecycle/reporting, qualification-rule, absence, workforce-capacity, and performance-goal capabilities **after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs**. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. +1. **Complete accessible buyer interaction without duplicating #130/#131/#132/#134/#135.** The shared protected-read state pattern is owned by #130 under #53, the one-time export delivery interaction by #131, the HR document retrieval interaction by #132, the Job-grade design-review interaction by #134, and the Position lifecycle human-review interaction by #135. Another generic loading/error/read-only/focus writer, parallel export-confirmation writer, duplicate document-retrieval writer, second Job-grade review-state writer, or second Position-lifecycle review-state writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for **Position reporting, qualification-rule, absence, workforce-capacity, and performance-goal** capabilities after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From b5dbbb399e345fc989f543b6b9a66f0e977614eb Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 13:11:10 -0700 Subject: [PATCH 020/201] docs: assign qualification review UI owner --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index be63249b8..103a8ade9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,7 +50,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #53 → #130 with workflow-specific children #131, #132, #134, and #135** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#134 owns the workflow-specific Job grade design-review interaction** as another sibling child of #130: loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale-evidence recovery, authorization denial and failure recovery while explicitly retaining no compensation/promotion/assignment/candidate/employment-decision authority. #134 exact head `83a6bdf6af86cf4a79ddbcd7e35b24f74da9322d` has `HR Workspace Job Grade Review State Quality` run `33091544470` / job `98585381713` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#135 owns the workflow-specific Position lifecycle human-review interaction** as another sibling child of #130: fresh Position/Assignment evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, read-only recorded evidence, stale-evidence and staffing-conflict fail-closed states, authorization denial and failure recovery, while explicitly retaining no Position mutation authority. #135 exact head `99a4f186a1131809165b188a4865ccb89ee3f4f3` has `HR Workspace Position Lifecycle Review State Quality` run `33107012654` / job `98639432674` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. #111 remains the separate Position lifecycle review-evidence owner and #112 the authoritative application owner. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade review, or Position-lifecycle review interaction writer. +- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, and #136** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#134 owns the workflow-specific Job grade design-review interaction** as another sibling child of #130: loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale-evidence recovery, authorization denial and failure recovery while explicitly retaining no compensation/promotion/assignment/candidate/employment-decision authority. #134 exact head `83a6bdf6af86cf4a79ddbcd7e35b24f74da9322d` has `HR Workspace Job Grade Review State Quality` run `33091544470` / job `98585381713` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#135 owns the workflow-specific Position lifecycle human-review interaction** as another sibling child of #130: fresh Position/Assignment evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, read-only recorded evidence, stale-evidence and staffing-conflict fail-closed states, authorization denial and failure recovery, while explicitly retaining no Position mutation authority. #135 exact head `99a4f186a1131809165b188a4865ccb89ee3f4f3` has `HR Workspace Position Lifecycle Review State Quality` run `33107012654` / job `98639432674` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#136 owns the workflow-specific qualification-rule human-review interaction** as another sibling child of #130: fresh Job/Job Analysis/Task/KSAO/source evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, stale and incomplete-evidence-scope fail-closed states, authorization denial/failure recovery, and explicit copy that review neither evaluates/ranks/rejects/advances a candidate nor authorizes an employment decision. #136 exact head `7d99027b39d4c022539d1c95e0120259723ad840` has `HR Workspace Qualification Rule Review State Quality` run `33111901755` / job `98656599091` terminal GREEN under exact 100% line/branch/function coverage and clean checkout. #104 remains the separate qualification-rule review-evidence owner and #105 the persistence owner. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade review, Position-lifecycle review, or qualification-rule review interaction writer. - **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. @@ -60,13 +60,13 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, HR document retrieval interaction states, Job-grade review interaction states, and Position lifecycle review interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, HR document retrieval interaction states, Job-grade review interaction states, Position lifecycle review interaction states, and qualification-rule review interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating #130/#131/#132/#134/#135.** The shared protected-read state pattern is owned by #130 under #53, the one-time export delivery interaction by #131, the HR document retrieval interaction by #132, the Job-grade design-review interaction by #134, and the Position lifecycle human-review interaction by #135. Another generic loading/error/read-only/focus writer, parallel export-confirmation writer, duplicate document-retrieval writer, second Job-grade review-state writer, or second Position-lifecycle review-state writer would be duplicative. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for **Position reporting, qualification-rule, absence, workforce-capacity, and performance-goal** capabilities after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. +1. **Complete accessible buyer interaction without duplicating #130/#131/#132/#134/#135/#136.** The shared protected-read state pattern is owned by #130 under #53; one-time export delivery by #131; HR document retrieval by #132; Job-grade design review by #134; Position lifecycle human review by #135; and qualification-rule human review by #136. Another generic loading/error/read-only/focus writer or any duplicate workflow-specific owner would be unsafe. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for **Position reporting, absence, workforce-capacity, and performance-goal** capabilities after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From 753dd3583b638d519598bc26af1779f131cfa670 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 14:06:03 -0700 Subject: [PATCH 021/201] docs(product): assign Position reporting interaction owner --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 103a8ade9..ecbffc612 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,7 +50,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, and #136** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#134 owns the workflow-specific Job grade design-review interaction** as another sibling child of #130: loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale-evidence recovery, authorization denial and failure recovery while explicitly retaining no compensation/promotion/assignment/candidate/employment-decision authority. #134 exact head `83a6bdf6af86cf4a79ddbcd7e35b24f74da9322d` has `HR Workspace Job Grade Review State Quality` run `33091544470` / job `98585381713` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#135 owns the workflow-specific Position lifecycle human-review interaction** as another sibling child of #130: fresh Position/Assignment evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, read-only recorded evidence, stale-evidence and staffing-conflict fail-closed states, authorization denial and failure recovery, while explicitly retaining no Position mutation authority. #135 exact head `99a4f186a1131809165b188a4865ccb89ee3f4f3` has `HR Workspace Position Lifecycle Review State Quality` run `33107012654` / job `98639432674` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#136 owns the workflow-specific qualification-rule human-review interaction** as another sibling child of #130: fresh Job/Job Analysis/Task/KSAO/source evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, stale and incomplete-evidence-scope fail-closed states, authorization denial/failure recovery, and explicit copy that review neither evaluates/ranks/rejects/advances a candidate nor authorizes an employment decision. #136 exact head `7d99027b39d4c022539d1c95e0120259723ad840` has `HR Workspace Qualification Rule Review State Quality` run `33111901755` / job `98656599091` terminal GREEN under exact 100% line/branch/function coverage and clean checkout. #104 remains the separate qualification-rule review-evidence owner and #105 the persistence owner. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade review, Position-lifecycle review, or qualification-rule review interaction writer. +- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, and #137** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#134 owns the workflow-specific Job grade design-review interaction** as another sibling child of #130: loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale-evidence recovery, authorization denial and failure recovery while explicitly retaining no compensation/promotion/assignment/candidate/employment-decision authority. #134 exact head `83a6bdf6af86cf4a79ddbcd7e35b24f74da9322d` has `HR Workspace Job Grade Review State Quality` run `33091544470` / job `98585381713` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#135 owns the workflow-specific Position lifecycle human-review interaction** as another sibling child of #130: fresh Position/Assignment evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, read-only recorded evidence, stale-evidence and staffing-conflict fail-closed states, authorization denial and failure recovery, while explicitly retaining no Position mutation authority. #135 exact head `99a4f186a1131809165b188a4865ccb89ee3f4f3` has `HR Workspace Position Lifecycle Review State Quality` run `33107012654` / job `98639432674` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#136 owns the workflow-specific qualification-rule human-review interaction** as another sibling child of #130: fresh Job/Job Analysis/Task/KSAO/source evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, stale and incomplete-evidence-scope fail-closed states, authorization denial/failure recovery, and explicit copy that review neither evaluates/ranks/rejects/advances a candidate nor authorizes an employment decision. #136 exact head `7d99027b39d4c022539d1c95e0120259723ad840` has `HR Workspace Qualification Rule Review State Quality` run `33111901755` / job `98656599091` terminal GREEN under exact 100% line/branch/function coverage and clean checkout. **#137 owns the workflow-specific Position reporting-line human-review interaction** as another sibling child of #130: fresh Position/reporting evidence loading, Figma-required high-risk confirmation, duplicate review-recording prevention, read-only recorded evidence, stale evidence, hierarchy-integrity blocking for cycle/duplicate-manager/self-report/staffable-Position conflicts, authorization denial/failure recovery, and explicit copy that review does not apply a reporting-line change or authorize an employment decision. RED head `fbeddab51d07f19753fc057e22992674590ccff3` produced terminal failing `HR Workspace Position Reporting Review State Quality` run `33116279543` before the production owner existed. #137 current head `b34e82fe36530525b4cbcb38e439f94b90d8cc89` has exact-head run `33116421611` / job `98672108690` terminal GREEN under the workflow's exact 100% line/branch/function coverage thresholds and clean checkout. #94/#95/#106/#133 remain the separate Position-reporting snapshot/review/persistence/structural-evidence owners. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade review, Position-lifecycle review, qualification-rule review, or Position-reporting review interaction writer. - **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. @@ -60,13 +60,13 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, HR document retrieval interaction states, Job-grade review interaction states, Position lifecycle review interaction states, and qualification-rule review interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, HR document retrieval interaction states, Job-grade review interaction states, Position lifecycle review interaction states, qualification-rule review interaction states, and Position reporting review interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating #130/#131/#132/#134/#135/#136.** The shared protected-read state pattern is owned by #130 under #53; one-time export delivery by #131; HR document retrieval by #132; Job-grade design review by #134; Position lifecycle human review by #135; and qualification-rule human review by #136. Another generic loading/error/read-only/focus writer or any duplicate workflow-specific owner would be unsafe. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for **Position reporting, absence, workforce-capacity, and performance-goal** capabilities after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. +1. **Complete accessible buyer interaction without duplicating #130/#131/#132/#134/#135/#136/#137.** The shared protected-read state pattern is owned by #130 under #53; one-time export delivery by #131; HR document retrieval by #132; Job-grade design review by #134; Position lifecycle human review by #135; qualification-rule human review by #136; and Position reporting-line human review by #137. Another generic loading/error/read-only/focus writer or any duplicate workflow-specific owner would be unsafe. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for **absence, workforce-capacity, and performance-goal** capabilities after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From 69898ddd3d932814347abfe0f41feefddd735b76 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 15:10:05 -0700 Subject: [PATCH 022/201] docs: assign work-capacity UI owner --- docs/product-technical-gap-baseline.md | 37 ++++++++++++++++---------- 1 file changed, 23 insertions(+), 14 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ecbffc612..86a6ee678 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -15,8 +15,8 @@ The **current live ruleset is weaker than Orgmetra's acquisition-grade acceptanc - it requires **1** approving review, not two; - `dismiss_stale_reviews_on_push = true`; - `require_last_push_approval = false`; -- review-thread resolution and extra approval for unattributed changes remain enabled; -- the central required-workflow set plus deletion/non-fast-forward protection remain enabled; and +- review-thread resolution and the central required-workflow set remain enabled; +- deletion and non-fast-forward updates remain prohibited; and - `OrganizationAdmin` retains `bypass_mode=always`, while the connected user reports `current_user_can_bypass=always`. Issue #89 owns the remaining repository-governance gap. Orgmetra's commercial acceptance remains stricter than the live ruleset: **at least two qualifying independent non-author approvals, approval after the last push, resolved conversations, every applicable exact-current-head local/central gate terminal GREEN, and no routine administrator bypass**. Organization-settings changes belong to the existing central owner-control path; Orgmetra must not simulate them with a workflow shim. @@ -50,25 +50,34 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, and #137** is the HR Workspace accessibility stack. #53 owns the current evidence-centered HR workspace anchor and is exact-head GREEN but live Draft under the separate lifecycle writer. **#130 owns the shared protected-read interaction states already required by the existing Figma Storybook Inventory node `1:64`**: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete denial/transport-failure next actions, existing design-token usage, and `:focus-visible`. #130 exact head `b3b30058a79174000919d566fbbb1fdad80c62bf` has focused `HR Workspace Protected Read State Quality` GREEN at exact 100% line/branch/function coverage, but that is stack-local evidence only. **#131 owns the workflow-specific one-time HR export delivery interaction** on top of #130: Figma-required high-risk confirmation, a single confirmed-ready handoff, duplicate-send prevention during publication, read-only delivered receipt state, fail-closed delivery-indeterminate `do not send again; reconcile` behavior, and authorization-denied next actions. #131 exact head `8cfeb21f2bad73a9c7a4a60b1b7597e4779f429e` has focused GREEN with exact 100% line/branch/function thresholds. **#132 owns the workflow-specific HR document retrieval interaction** as a sibling child of #130: purpose review, authorization/loading, bounded artifact verification, immutable audit-before-release, authenticated-session read-only handoff, authorization-expired/denied/failure states, duplicate-submit prevention, and value-minimized customer next-action copy. #132 exact head `c12f66aba337ab50c1ba7ce75dd1054a8d512762` has `HR Workspace Document Retrieval State Quality` run `33086795934` / job `98568514152` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#134 owns the workflow-specific Job grade design-review interaction** as another sibling child of #130: loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale-evidence recovery, authorization denial and failure recovery while explicitly retaining no compensation/promotion/assignment/candidate/employment-decision authority. #134 exact head `83a6bdf6af86cf4a79ddbcd7e35b24f74da9322d` has `HR Workspace Job Grade Review State Quality` run `33091544470` / job `98585381713` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#135 owns the workflow-specific Position lifecycle human-review interaction** as another sibling child of #130: fresh Position/Assignment evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, read-only recorded evidence, stale-evidence and staffing-conflict fail-closed states, authorization denial and failure recovery, while explicitly retaining no Position mutation authority. #135 exact head `99a4f186a1131809165b188a4865ccb89ee3f4f3` has `HR Workspace Position Lifecycle Review State Quality` run `33107012654` / job `98639432674` terminal GREEN under exact 100% line/branch/function coverage thresholds and clean checkout. **#136 owns the workflow-specific qualification-rule human-review interaction** as another sibling child of #130: fresh Job/Job Analysis/Task/KSAO/source evidence loading, Figma-required `high-risk-confirmation`, duplicate review-recording prevention, stale and incomplete-evidence-scope fail-closed states, authorization denial/failure recovery, and explicit copy that review neither evaluates/ranks/rejects/advances a candidate nor authorizes an employment decision. #136 exact head `7d99027b39d4c022539d1c95e0120259723ad840` has `HR Workspace Qualification Rule Review State Quality` run `33111901755` / job `98656599091` terminal GREEN under exact 100% line/branch/function coverage and clean checkout. **#137 owns the workflow-specific Position reporting-line human-review interaction** as another sibling child of #130: fresh Position/reporting evidence loading, Figma-required high-risk confirmation, duplicate review-recording prevention, read-only recorded evidence, stale evidence, hierarchy-integrity blocking for cycle/duplicate-manager/self-report/staffable-Position conflicts, authorization denial/failure recovery, and explicit copy that review does not apply a reporting-line change or authorize an employment decision. RED head `fbeddab51d07f19753fc057e22992674590ccff3` produced terminal failing `HR Workspace Position Reporting Review State Quality` run `33116279543` before the production owner existed. #137 current head `b34e82fe36530525b4cbcb38e439f94b90d8cc89` has exact-head run `33116421611` / job `98672108690` terminal GREEN under the workflow's exact 100% line/branch/function coverage thresholds and clean checkout. #94/#95/#106/#133 remain the separate Position-reporting snapshot/review/persistence/structural-evidence owners. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade review, Position-lifecycle review, qualification-rule review, or Position-reporting review interaction writer. -- **PR #75** owns governed HR export review evidence. Its exact-current-head local gates are GREEN, but live Draft state is controlled by the separate PR-lifecycle writer. **Child #120** owns audited one-time export egress and fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery; it remains dependency-first and must not inherit parent evidence. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. -- **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; **#125 owns durable activated goal-plan persistence** with exact reviewed/activation evidence-to-normalized-truth binding. #125's focused exact-head persistence workflow is GREEN, but that is stack-local evidence only and none of this stack is shipped truth. -- **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118's release-readiness package is exact-head GREEN and remains non-authorizing; #126 owns exact-revision authorization with focused exact-head GREEN; #127 owns reconciled at-most-once publication with focused exact-head GREEN and explicit no-republish behavior after ambiguous external outcomes. The child evidence is stack-local, no parent checks/reviews transfer, and the repository release collection remains empty. -- **PR #124** owns the hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`. Hardware Acceleration ADR/Foundation/Recovery/Job-Analysis/SAST/Security are all terminal GREEN on that head; live Draft state remains authoritative because of a separate lifecycle writer. -- **PR #123** owns customer-facing copy cleanup on exact head `382a46ac31222bf32980e27ed4c998a8ce019095`; every materialized exact-head Orgmetra workflow is GREEN and Devin reports zero issues, but there is still no qualifying independent approval. -- **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence and never imports or substitutes for #116 authorization/audit semantics. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. +- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, and #138** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. + - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. + - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. + - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. + - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. + - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. + - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. #137 exact head `b34e82fe36530525b4cbcb38e439f94b90d8cc89` has focused exact 100% line/branch/function GREEN. + - **#138 now owns Employment work-capacity human-review interaction** while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `9e3f5c5b1c959bef37831e8cba8695504a18061f` has `HR Workspace Work Capacity Review State Quality` run `33121181610` / job `98688132674` terminal GREEN: exact candidate checkout, 5 focused tests, **100% line/branch/function coverage**, and clean checkout. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. + All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, or Employment-work-capacity interaction writer. +- **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. +- **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding. Child GREEN is stack-local only. +- **PR #103 → #128** is the Employment work-capacity backend stack. #103 owns human review evidence; #128 owns dependency-first durable persistence. #138 is presentation/interaction only and must never substitute for authoritative backend validation or mutation. +- **PR #113 → #114** is the Employment absence truth/persistence stack. Absence remains reason-free authoritative HRIS evidence and is distinct from work-capacity, leave-review, payroll, scheduling, and employment-decision semantics. +- **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118 owns readiness review, #126 exact-revision authorization, and #127 reconciled at-most-once publication. No parent checks/reviews transfer and the repository release collection remains empty. +- **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. -- **PR #128** owns dependency-first Employment work-capacity persistence and has focused exact-head persistence GREEN under parent #103; it remains active-PR truth only until parent-first integration and fresh-base full-gate revalidation. +- **PR #124** owns hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`; local exact-head ADR/Foundation/Recovery/Job-Analysis/SAST/Security evidence is GREEN, while live Draft state remains authoritative. -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, HR Workspace protected-read interaction states, one-time HR export delivery interaction states, HR document retrieval interaction states, Job-grade review interaction states, Position lifecycle review interaction states, qualification-rule review interaction states, and Position reporting review interaction states remain active-PR truth only. Their focused GREEN evidence, where present, never transfers across parent integration or restack. +Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and all HR Workspace interaction children remain active-PR truth only. Their focused GREEN evidence never transfers across parent integration or restack. ## Highest-value buyer gaps after the current owner lanes Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating #130/#131/#132/#134/#135/#136/#137.** The shared protected-read state pattern is owned by #130 under #53; one-time export delivery by #131; HR document retrieval by #132; Job-grade design review by #134; Position lifecycle human review by #135; qualification-rule human review by #136; and Position reporting-line human review by #137. Another generic loading/error/read-only/focus writer or any duplicate workflow-specific owner would be unsafe. The remaining UI gap is workflow-specific Product Design/Figma/Storybook interaction for **absence, workforce-capacity, and performance-goal** capabilities after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read state semantics and existing design tokens where applicable, and reuse #131's high-risk confirmation/no-republish pattern only where the workflow has equivalent consequential or at-most-once semantics. Add only workflow-specific keyboard/focus/ARIA, evidence provenance and customer next-action behavior. -2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A new parallel release writer would be duplicative and unsafe. -3. **Integration closure is itself a buyer risk until the dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. +1. **Complete accessible buyer interaction without duplicating the #130 child owners.** The shared protected-read state pattern is owned by #130 under #53; export delivery by #131; document retrieval by #132; Job-grade review by #134; Position lifecycle review by #135; qualification-rule review by #136; Position reporting-line review by #137; and **Employment work-capacity review by #138**. Another generic loading/error/read-only/focus writer or duplicate workflow-specific owner would be unsafe. The remaining workflow-specific Product Design/Figma/Storybook gaps are now **Employment absence** and **performance-goal** interaction, after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read semantics and existing design tokens; add only workflow-specific keyboard/focus/ARIA, evidence provenance, and customer next-action behavior. +2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A parallel release writer would be duplicative and unsafe. +3. **Integration closure is itself a buyer risk until dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. From 391d302d6a9849b5fb511050020730f29f332667 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 16:11:16 -0700 Subject: [PATCH 023/201] docs: assign Employment absence UI owner --- docs/product-technical-gap-baseline.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 86a6ee678..b8a1b3de9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -51,19 +51,20 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. -- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, and #138** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. +- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, and #139** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. #137 exact head `b34e82fe36530525b4cbcb38e439f94b90d8cc89` has focused exact 100% line/branch/function GREEN. - - **#138 now owns Employment work-capacity human-review interaction** while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `9e3f5c5b1c959bef37831e8cba8695504a18061f` has `HR Workspace Work Capacity Review State Quality` run `33121181610` / job `98688132674` terminal GREEN: exact candidate checkout, 5 focused tests, **100% line/branch/function coverage**, and clean checkout. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, or Employment-work-capacity interaction writer. + - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `9e3f5c5b1c959bef37831e8cba8695504a18061f` has `HR Workspace Work Capacity Review State Quality` run `33121181610` / job `98688132674` terminal GREEN: exact candidate checkout, 5 focused tests, **100% line/branch/function coverage**, and clean checkout. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. + - **#139 now owns reason-free Employment absence interaction** while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `cbbf975733c74413fe91310415c67a034090133d` has `HR Workspace Employment Absence State Quality` run `33125277888` / job `98701821651` terminal GREEN after a genuine contract-first RED on run `33125117860` / job `98701273064`. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. + All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, or Employment-absence interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding. Child GREEN is stack-local only. - **PR #103 → #128** is the Employment work-capacity backend stack. #103 owns human review evidence; #128 owns dependency-first durable persistence. #138 is presentation/interaction only and must never substitute for authoritative backend validation or mutation. -- **PR #113 → #114** is the Employment absence truth/persistence stack. Absence remains reason-free authoritative HRIS evidence and is distinct from work-capacity, leave-review, payroll, scheduling, and employment-decision semantics. +- **PR #113 → #114** is the Employment absence truth/persistence stack. Absence remains reason-free authoritative HRIS evidence and is distinct from work-capacity, leave-review, payroll, scheduling, and employment-decision semantics. #139 is presentation/interaction only and must never infer a reason, attendance/fitness, or consequential authority. - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118 owns readiness review, #126 exact-revision authorization, and #127 reconciled at-most-once publication. No parent checks/reviews transfer and the repository release collection remains empty. - **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. @@ -75,7 +76,7 @@ Dependency-first descendants for qualification-rule persistence, Position report Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating the #130 child owners.** The shared protected-read state pattern is owned by #130 under #53; export delivery by #131; document retrieval by #132; Job-grade review by #134; Position lifecycle review by #135; qualification-rule review by #136; Position reporting-line review by #137; and **Employment work-capacity review by #138**. Another generic loading/error/read-only/focus writer or duplicate workflow-specific owner would be unsafe. The remaining workflow-specific Product Design/Figma/Storybook gaps are now **Employment absence** and **performance-goal** interaction, after their owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read semantics and existing design tokens; add only workflow-specific keyboard/focus/ARIA, evidence provenance, and customer next-action behavior. +1. **Complete accessible buyer interaction without duplicating the #130 child owners.** The shared protected-read state pattern is owned by #130 under #53; export delivery by #131; document retrieval by #132; Job-grade review by #134; Position lifecycle review by #135; qualification-rule review by #136; Position reporting-line review by #137; Employment work-capacity review by #138; and **Employment absence read interaction by #139**. Another generic loading/error/read-only/focus writer or duplicate workflow-specific owner would be unsafe. The remaining workflow-specific Product Design/Figma/Storybook gap is now **performance-goal interaction**, after its #92 → #121 → #125 owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read semantics and existing design tokens; add only workflow-specific keyboard/focus/ARIA, evidence provenance, and customer next-action behavior. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From 333ac23bd2ab138fd5ac5132a88e3f826ab41fb5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 17:07:12 -0700 Subject: [PATCH 024/201] docs: register performance-goal interaction owner --- docs/product-technical-gap-baseline.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b8a1b3de9..f2ea042ab 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -51,7 +51,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. -- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, and #139** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. +- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. @@ -59,10 +59,11 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. #137 exact head `b34e82fe36530525b4cbcb38e439f94b90d8cc89` has focused exact 100% line/branch/function GREEN. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `9e3f5c5b1c959bef37831e8cba8695504a18061f` has `HR Workspace Work Capacity Review State Quality` run `33121181610` / job `98688132674` terminal GREEN: exact candidate checkout, 5 focused tests, **100% line/branch/function coverage**, and clean checkout. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - - **#139 now owns reason-free Employment absence interaction** while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `cbbf975733c74413fe91310415c67a034090133d` has `HR Workspace Employment Absence State Quality` run `33125277888` / job `98701821651` terminal GREEN after a genuine contract-first RED on run `33125117860` / job `98701273064`. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, or Employment-absence interaction writer. + - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `cbbf975733c74413fe91310415c67a034090133d` has `HR Workspace Employment Absence State Quality` run `33125277888` / job `98701821651` terminal GREEN after a genuine contract-first RED on run `33125117860` / job `98701273064`. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. + - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. #140 exact head `260ddd27324aee5e67e09077e84a814b92d5891e` has `HR Workspace Performance Goal Review State Quality` run `33128554172` / job `98712427872` terminal GREEN after genuine contract-first RED run `33128460316` / job `98712125205`. The UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. + All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. -- **PR #92 → #121 → #125** is the performance-goal stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding. Child GREEN is stack-local only. +- **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child GREEN is stack-local only. - **PR #103 → #128** is the Employment work-capacity backend stack. #103 owns human review evidence; #128 owns dependency-first durable persistence. #138 is presentation/interaction only and must never substitute for authoritative backend validation or mutation. - **PR #113 → #114** is the Employment absence truth/persistence stack. Absence remains reason-free authoritative HRIS evidence and is distinct from work-capacity, leave-review, payroll, scheduling, and employment-decision semantics. #139 is presentation/interaction only and must never infer a reason, attendance/fitness, or consequential authority. - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118 owns readiness review, #126 exact-revision authorization, and #127 reconciled at-most-once publication. No parent checks/reviews transfer and the repository release collection remains empty. @@ -76,7 +77,7 @@ Dependency-first descendants for qualification-rule persistence, Position report Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Complete accessible buyer interaction without duplicating the #130 child owners.** The shared protected-read state pattern is owned by #130 under #53; export delivery by #131; document retrieval by #132; Job-grade review by #134; Position lifecycle review by #135; qualification-rule review by #136; Position reporting-line review by #137; Employment work-capacity review by #138; and **Employment absence read interaction by #139**. Another generic loading/error/read-only/focus writer or duplicate workflow-specific owner would be unsafe. The remaining workflow-specific Product Design/Figma/Storybook gap is now **performance-goal interaction**, after its #92 → #121 → #125 owner contracts are integrated or can be consumed without inventing unavailable default-branch APIs. Reuse #130's protected-read semantics and existing design tokens; add only workflow-specific keyboard/focus/ARIA, evidence provenance, and customer next-action behavior. +1. **Integrate the accessible buyer-interaction stack instead of opening another UI writer.** The currently named workflow-specific HR Workspace interaction gaps are owned under #53 → #130 by #131/#132/#134/#135/#136/#137/#138/#139/#140. No additional named generic or workflow-specific interaction gap is presently proven by the fresh owner graph. The commercial risk is now dependency-first integration: land #53 and #130 first, then retarget/revalidate each child against fresh `develop`, reconcile intervening Storybook/Figma/UI changes, and obtain browser/accessibility/Foundation/Recovery/SAST/Security plus every applicable central exact-head gate before representing any child as shipped. A new UI PR is justified only by newly verified buyer evidence that is outside these owner scopes. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From 29e9445ed27e2904d1d00eddc159c6fe22fa23e2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 18:47:14 -0700 Subject: [PATCH 025/201] docs(product): register employing-organization owner lane --- docs/product-technical-gap-baseline.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f2ea042ab..d10b6edff 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,7 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN, but the required central Strix workflow is absent on this exact SHA and remains non-passing under the `.github#1327` owner-control handoff. #141 stays Draft and active-PR truth only; do not create a competing employer-scope relationship writer or treat it as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. @@ -110,4 +111,4 @@ Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management — Requirements and recommendations for human capital reporting and disclosure*. ISO. -Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). \ No newline at end of file +Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). From c8d199d9e772205cd09a7f905360b556fce05eb0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 18:55:34 -0700 Subject: [PATCH 026/201] docs(product): track materialized employing-org Strix canary --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d10b6edff..3414d6692 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,7 +50,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN, but the required central Strix workflow is absent on this exact SHA and remains non-passing under the `.github#1327` owner-control handoff. #141 stays Draft and active-PR truth only; do not create a competing employer-scope relationship writer or treat it as payroll/statutory-account authority. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. The required central Strix check has now materialized as job `98729417430` in central run `33133495444`, but remains `in_progress`; under fail-closed commercial policy that is still non-passing until an authoritative structured finding/no-finding analysis completes with terminal SUCCESS. The existing `.github#1327` owner-control handoff remains authoritative. #141 stays Draft and active-PR truth only; do not create a competing employer-scope relationship writer or treat it as payroll/statutory-account authority. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. From c2a3d685b1330e5b5e42daac4921f58ea948e301 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 19:12:19 -0700 Subject: [PATCH 027/201] docs: record terminal Strix failure for PR 141 --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3414d6692..086a0bd33 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. The required central Strix check has now materialized as job `98729417430` in central run `33133495444`, but remains `in_progress`; under fail-closed commercial policy that is still non-passing until an authoritative structured finding/no-finding analysis completes with terminal SUCCESS. The existing `.github#1327` owner-control handoff remains authoritative. #141 stays Draft and active-PR truth only; do not create a competing employer-scope relationship writer or treat it as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; no Orgmetra-local provider shim or gate weakening is valid. #141 remains Draft active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 4aa189bfb0985515a967401b786f688615270fda Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 11:14:52 +0900 Subject: [PATCH 028/201] docs: refresh active PR readiness in gap baseline --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 086a0bd33..958987869 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,7 +50,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; no Orgmetra-local provider shim or gate weakening is valid. #141 remains Draft active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; no Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. @@ -70,7 +70,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118 owns readiness review, #126 exact-revision authorization, and #127 reconciled at-most-once publication. No parent checks/reviews transfer and the repository release collection remains empty. - **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. -- **PR #124** owns hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`; local exact-head ADR/Foundation/Recovery/Job-Analysis/SAST/Security evidence is GREEN, while live Draft state remains authoritative. +- **PR #124** owns hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`; local exact-head ADR/Foundation/Recovery/Job-Analysis/SAST/Security evidence is GREEN, while its live Ready-for-review state remains authoritative. Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and all HR Workspace interaction children remain active-PR truth only. Their focused GREEN evidence never transfers across parent integration or restack. From c5365410c9ef663624b705dbd6253e05d17665d8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 12:04:52 +0900 Subject: [PATCH 029/201] docs: record central Strix remediation owner --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 958987869..3cd4ca90c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; no Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `48f893bab61990c88f103f07310e8eb9203766e1`, currently still open/blocked while its unchanged-head Strix run completes and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `48f893bab61990c88f103f07310e8eb9203766e1`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From f8363fbe130e87486059221b1c8efa2436b6f369 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 12:07:24 +0900 Subject: [PATCH 030/201] docs: track latest central Strix head --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3cd4ca90c..10ee7bd22 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `48f893bab61990c88f103f07310e8eb9203766e1`, currently still open/blocked while its unchanged-head Strix run completes and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `48f893bab61990c88f103f07310e8eb9203766e1`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `6beae6b647b7b4576412409b4134c8ae78a4436d`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `6beae6b647b7b4576412409b4134c8ae78a4436d`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 8e007d513c24538349265fc24fa834799e8c9dfe Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 12:11:46 +0900 Subject: [PATCH 031/201] docs: align central Strix owner snapshot --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 10ee7bd22..b6b1d2ae9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `6beae6b647b7b4576412409b4134c8ae78a4436d`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `6beae6b647b7b4576412409b4134c8ae78a4436d`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `4c2bdcb986685e59614b1d9ac62eaf6ca228a796`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `4c2bdcb986685e59614b1d9ac62eaf6ca228a796`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 8778c9843115a0df998c0a4042a32db0a2f20919 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 12:23:56 +0900 Subject: [PATCH 032/201] docs: reconcile shipped capability status --- README.md | 2 +- docs/TRACEABILITY.md | 2 +- docs/adr/0007-governed-job-analysis-evidence.md | 2 +- docs/adr/0014-job-analysis-snapshot-persistence.md | 2 +- docs/adr/0017-governed-offer-approval.md | 6 +++--- docs/adr/0025-governed-candidate-evidence-intake.md | 4 ++-- docs/adr/README.md | 4 ++-- docs/product-technical-gap-baseline.md | 6 +++--- docs/traceability/candidate-evidence-intake.md | 2 +- docs/traceability/offer-approval.md | 2 +- manifest.json | 2 +- 11 files changed, 17 insertions(+), 17 deletions(-) diff --git a/README.md b/README.md index 47bb087a3..872b922a5 100644 --- a/README.md +++ b/README.md @@ -78,4 +78,4 @@ Job evidence ## Status -Protected `develop` includes the employment-truth kernel, governed candidate-to-worker conversion, purpose-bound PII authorization, normalized worker-bound validity studies, criterion-observation scope, bitemporal workforce-composition evidence, the governed Naruon intent adapter, and requisition review packets. This active PR adds durable purpose-bound People mutation and confirmed-hire materialization paths for Employment, Position, and Assignment with atomic audit/outbox evidence and tenant-scoped idempotency; treat those write paths as active-PR truth until this exact head passes all fresh protected-base gates and merges. +Protected `develop` includes the employment-truth kernel, durable purpose-bound People mutation and confirmed-hire materialization paths for Employment, Position, and Assignment with atomic audit/outbox evidence and tenant-scoped idempotency, governed Job Analysis snapshot persistence/read, candidate evidence intake, offer approval packets, governed candidate-to-worker conversion, purpose-bound PII authorization, normalized worker-bound validity studies, criterion-observation scope, bitemporal workforce-composition evidence, the governed Naruon intent adapter, and requisition review packets. Active PRs remain separate from this protected-branch shipped truth until their exact heads pass all fresh protected-base gates and merge. diff --git a/docs/TRACEABILITY.md b/docs/TRACEABILITY.md index 22a4178fe..7e7281195 100644 --- a/docs/TRACEABILITY.md +++ b/docs/TRACEABILITY.md @@ -15,7 +15,7 @@ | Governed candidate-to-worker conversion | Talent Acquisition / People core | `candidate_worker_conversion_record` with candidate, person, employment, selection decision, audit event and outbox evidence | PostgreSQL exact hire/evidence/audit-envelope binding, correction provenance, tenant RLS, legacy-write rejection and bitemporal history contract | ADR-0001, ADR-0003, ADR-0006 | implemented_on_protected_main | | GET-only People API | People API / purpose-bound read boundary | `GET /v1/tenants/{tenant_record_id}/people/{person_record_id}`, `read_worker_people_record()`, `PostgresPeopleReadPort` | People API HTTP and PostgreSQL read contracts with exact 100% owned statement/branch coverage; current conversion lineage; no mutation writes | ADR-0002, ADR-0008 | implemented_on_protected_main | | Governed People writes and confirmed-hire materialization | People API / purpose-bound mutation boundary | `POST /v1/employment-records`, `POST /v1/position-records`, `POST /v1/assignment-records`, `POST /v1/tenants/{tenant_record_id}/candidate-worker-conversions`, `people_mutation_idempotency_record` | People command/HTTP/PostgreSQL contracts with exact owned statement/branch coverage plus PostgreSQL tenant-RLS, atomic audit/outbox/idempotency, identical-retry replay, changed-command rejection, rollback, and concurrent-key regression | ADR-0002, ADR-0006, ADR-0008 | implemented_on_protected_main | -| Evidence-grounded Job analysis with governed Task/FJA/KSAO persistence | Job Analysis / Workforce Validation | `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `FunctionalJobAnalysisProfile`, `TaskKSAOLink`, `EvidenceSource`, `job_analysis_snapshot`, `job_analysis_task_item`, `job_analysis_ksao_item`, `job_analysis_task_ksao_link`, `job_analysis_write_command`, `POST /v1/tenants/{tenant_record_id}/job-analysis-snapshots`, `GET /v1/tenants/{tenant_record_id}/job-analysis-snapshots/{analysis_record_id}` | domain tenant/Job isolation, source/version/digest provenance, task-KSAO completeness, deterministic canonicalization, accountable human-review and LLM-draft-only regressions; migration 0013 PostgreSQL parent-scope/RLS/append-only/idempotency/audit-outbox persistence; exact route/OpenAPI/error contracts and 100% owned service statement/branch coverage | ADR-0007, ADR-0014 | implemented_on_active_pr | +| Evidence-grounded Job analysis with governed Task/FJA/KSAO persistence | Job Analysis / Workforce Validation | `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `FunctionalJobAnalysisProfile`, `TaskKSAOLink`, `EvidenceSource`, `job_analysis_snapshot`, `job_analysis_task_item`, `job_analysis_ksao_item`, `job_analysis_task_ksao_link`, `job_analysis_write_command`, `POST /v1/tenants/{tenant_record_id}/job-analysis-snapshots`, `GET /v1/tenants/{tenant_record_id}/job-analysis-snapshots/{analysis_record_id}` | domain tenant/Job isolation, source/version/digest provenance, task-KSAO completeness, deterministic canonicalization, accountable human-review and LLM-draft-only regressions; migration 0013 PostgreSQL parent-scope/RLS/append-only/idempotency/audit-outbox persistence; exact route/OpenAPI/error contracts and 100% owned service statement/branch coverage | ADR-0007, ADR-0014 | implemented_on_protected_main | | Job-, cycle-, and staffing-scoped performance criterion observations | Performance / Workforce Validation | `criterion_observation`, `criterion_blueprint`, `performance_cycle`, `assignment_record`, `employment_record_version`, `position_record`, `position_record_version` | PostgreSQL wrong-Job, pre-assignment, out-of-cycle, frozen-Position, terminated-employment, closed-recorded-time, and session-TimeZone/UTC-midnight rejection plus valid worker-Job/staffing acceptance | ADR-0009 | implemented_on_protected_main | | Governed immutable audit and transactional outbox persistence | Audit Provenance / Integration Hub | `AuditOutboxEvent.canonical_json()`, `audit_event_record`, `outbox_delivery_record`, SHA-256 envelope digest | canonical-byte/digest regression plus PostgreSQL digest, allowlist/PII, high-impact confirmation, append-only, atomicity, lease-transition, terminal-state, and reserved-UUID tests | ADR-0006 | implemented_on_active_pr | | Tenant-safe atomic outbox claiming and crash recovery | Integration Hub dispatcher boundary | `outbox_delivery_record` pending/expired-lease claim indexes plus `claim_outbox_delivery(...)` | PostgreSQL already-expired-new-lease rejection, due-order claim, live-lease exclusion, pre-exhaustion takeover with `lease_expired` evidence, retry-budget claim bound, tenant-context binding, opaque-worker validation, and bounded-lease contract | ADR-0006 | implemented_on_active_pr | diff --git a/docs/adr/0007-governed-job-analysis-evidence.md b/docs/adr/0007-governed-job-analysis-evidence.md index f9aeea835..2a161d356 100644 --- a/docs/adr/0007-governed-job-analysis-evidence.md +++ b/docs/adr/0007-governed-job-analysis-evidence.md @@ -1,6 +1,6 @@ # ADR 0007: Governed job-analysis evidence snapshots -- Status: Accepted on stacked implementation branch +- Status: Accepted on protected `develop` - Date: 2026-08-17 - Owners: Orgmetra Job Analysis / Workforce Validation diff --git a/docs/adr/0014-job-analysis-snapshot-persistence.md b/docs/adr/0014-job-analysis-snapshot-persistence.md index cef05e28f..e0a6b3c92 100644 --- a/docs/adr/0014-job-analysis-snapshot-persistence.md +++ b/docs/adr/0014-job-analysis-snapshot-persistence.md @@ -1,6 +1,6 @@ # ADR 0014: Persist governed job-analysis snapshots -- Status: Accepted on active implementation branch +- Status: Accepted on protected `develop` - Date: 2026-08-20 - Owners: Orgmetra Job Analysis / Workforce Validation diff --git a/docs/adr/0017-governed-offer-approval.md b/docs/adr/0017-governed-offer-approval.md index c662a0429..f2bf102f3 100644 --- a/docs/adr/0017-governed-offer-approval.md +++ b/docs/adr/0017-governed-offer-approval.md @@ -1,12 +1,12 @@ # ADR 0017: Governed offer approval evidence -- Status: Proposed — active PR only +- Status: Accepted on protected `develop` - Date: 2026-08-19 - Scope: Talent Acquisition offer review ## Context -Protected `develop` can govern candidate, requisition, selection, and employment evidence, but it does not yet expose a bounded pre-send contract proving that a proposed offer is tied to the selected candidate, authoritative Job/optional Position, reviewed selection decision, compensation-package provenance, offer-terms provenance, and accountable human approval. +Protected `develop` now exposes a bounded pre-send contract proving that a proposed offer is tied to the selected candidate, authoritative Job/optional Position, reviewed selection decision, compensation-package provenance, offer-terms provenance, and accountable human approval. Offer review is high-impact employment workflow. A governance envelope must not become an alternate decision authority, a salary-value cache, or a channel that lets generated/model material masquerade as an approved offer. Different opaque requester/approver references also do not prove that the authoritative actor boundary resolves them to different people, and UUID syntax does not prove that the referenced candidate, requisition, Job/Position, selection decision, compensation package, or offer terms belong to the packet tenant. Packet-owned UUIDv1 references also carry timestamp/node-derived correlation metadata. The authoritative tenant identifier is different: it is issued by Orgmetra core, so this leaf package must accept the canonical non-sentinel operational UUID contract owned by that boundary rather than silently imposing a second version policy. @@ -30,7 +30,7 @@ Canonical JSON and SHA-256 are audit-correlation evidence only. The packet does A buyer can review one deterministic, PII-minimized envelope before an offer moves to the authoritative offer workflow. Compensation values stay in their purpose-bound owner boundary, while Orgmetra keeps exact provenance references, evidence version, and human accountability. Packet-owned UUIDv1/non-v4 references fail closed before serialization without making this leaf package incompatible with authoritative Orgmetra tenant UUIDs. Cross-tenant evidence mixing is fail-closed at the host approval boundary because every packet reference must resolve in the exact tenant. Requester/approver separation is proven only after tenant-scoped authoritative actor resolution. New offer-review reason categories require an explicit contract change and regression evidence rather than accepting arbitrary caller text. -Downstream offer persistence/execution must independently enforce authorization, tenant-scoped source-evidence resolution, idempotency where applicable, and immutable audit/outbox evidence. This ADR remains proposed active-PR truth until integrated into protected `develop`. +Downstream offer persistence/execution must independently enforce authorization, tenant-scoped source-evidence resolution, idempotency where applicable, and immutable audit/outbox evidence. This ADR records the accepted protected-`develop` offer-review boundary; downstream execution remains a separate authority. ## References diff --git a/docs/adr/0025-governed-candidate-evidence-intake.md b/docs/adr/0025-governed-candidate-evidence-intake.md index ab66b3088..3c274884e 100644 --- a/docs/adr/0025-governed-candidate-evidence-intake.md +++ b/docs/adr/0025-governed-candidate-evidence-intake.md @@ -1,6 +1,6 @@ # ADR 0025: Govern candidate evidence intake as reference-only evidence -- **Status:** Proposed — active PR only +- **Status:** Accepted on protected `develop` - **Date:** 2026-08-19 ## Context @@ -40,7 +40,7 @@ Canonical JSON plus SHA-256 provide immutable audit correlation but do not estab - The packet does not store raw candidate evidence, decide whether an item is lawfully usable, or prove the referenced policy was followed. - UUID-backed tenant and candidate references are still sensitive correlating metadata and require least-privilege handling. - Evidence sealing, authoritative selection decisions, immutable audit/outbox, deletion/retention execution, export controls, accommodations, adverse-impact monitoring, and jurisdiction-specific legal review remain separate obligations. -- This ADR remains proposed until its exact PR head merges into protected `develop`. +- This ADR records the accepted protected-`develop` candidate-evidence intake boundary; later sealing, selection, retention, and legal-use obligations remain separate authorities. ## References diff --git a/docs/adr/README.md b/docs/adr/README.md index 099a21139..99d98fa45 100644 --- a/docs/adr/README.md +++ b/docs/adr/README.md @@ -8,11 +8,11 @@ | [0004](0004-employment-position-version-and-assignment-binding.md) | Employment and position versions bind assignments | Accepted | | [0005](0005-exclusive-employment-and-staffable-seats.md) | Exclusive employment and staffable seats | Accepted | | [0006](0006-governed-audit-outbox-envelope.md) | Governed audit/outbox envelope and durable persistence | Accepted on stacked implementation branch | -| [0007](0007-governed-job-analysis-evidence.md) | Governed job-analysis evidence snapshots | Accepted on stacked implementation branch | +| [0007](0007-governed-job-analysis-evidence.md) | Governed job-analysis evidence snapshots | Accepted on protected `develop` | | [0008](0008-purpose-bound-pii-authorization.md) | Purpose-bound PII authorization | Accepted on protected `develop` | | [0009](0009-performance-criterion-observation-scope.md) | Performance criterion observations require worker-job scope | Accepted on active implementation branch | | [0010](0010-naruon-calendar-intent-boundary.md) | Naruon calendar intent boundary | Accepted on active implementation branch | | [0011](0011-bitemporal-workforce-composition.md) | Bitemporal workforce composition | Accepted on active implementation branch | | [0012](0012-governed-migration-handoff.md) | Governed migration handoff | Accepted on active implementation branch | | [0013](0013-governed-requisition-review-packet.md) | Governed requisition review packet | Accepted on active implementation branch | -| [0014](0014-job-analysis-snapshot-persistence.md) | Persist governed job-analysis snapshots | Accepted on active implementation branch | +| [0014](0014-job-analysis-snapshot-persistence.md) | Persist governed job-analysis snapshots | Accepted on protected `develop` | diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b6b1d2ae9..64e7345dc 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -78,7 +78,7 @@ Dependency-first descendants for qualification-rule persistence, Position report Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Integrate the accessible buyer-interaction stack instead of opening another UI writer.** The currently named workflow-specific HR Workspace interaction gaps are owned under #53 → #130 by #131/#132/#134/#135/#136/#137/#138/#139/#140. No additional named generic or workflow-specific interaction gap is presently proven by the fresh owner graph. The commercial risk is now dependency-first integration: land #53 and #130 first, then retarget/revalidate each child against fresh `develop`, reconcile intervening Storybook/Figma/UI changes, and obtain browser/accessibility/Foundation/Recovery/SAST/Security plus every applicable central exact-head gate before representing any child as shipped. A new UI PR is justified only by newly verified buyer evidence that is outside these owner scopes. +1. **Integrate the accessible buyer-interaction stack and retain the unowned P1 surfaces.** The currently named workflow-specific HR Workspace interaction gaps are owned under #53 → #130 by #131/#132/#134/#135/#136/#137/#138/#139/#140. Separately, the PRD still names the Job Architecture workspace, Candidate Evidence workspace, hiring decision record, Employee Profile with bitemporal assignment history, and Validation dashboard shell; the wireframe baseline also names HR Home, Job Architecture, Recruiting Workspace, Employee Profile, Validate, and Admin & Integrations. No UI/Storybook implementation or owner PR is currently proven for those buyer surfaces, so they remain unowned planned gaps rather than shipped truth. The commercial risk is dependency-first integration: land #53 and #130 first, then retarget/revalidate each child against fresh `develop`, reconcile intervening Storybook/Figma/UI changes, and obtain browser/accessibility/Foundation/Recovery/SAST/Security plus every applicable central exact-head gate before representing any child as shipped. Do not open a competing interaction writer for an already-owned scope. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. @@ -90,7 +90,7 @@ External finance/accounting and billing/collection integration remains planned/o - Descriptive two-or-more-word `snake_case` database objects and 3NF by default. - Job, Position, Assignment, Employment, Organization, and Person remain distinct authoritative concepts. - Business/effective time and system-recorded time remain separate; correction is correction-not-rewrite. -- Tenant/context isolation, opaque public correlation, least privilege, field minimization, encryption/retention/export controls, and immutable audit/outbox remain mandatory. +- Tenant/context isolation, opaque public correlation, least privilege, field minimization, encryption/retention/export controls, immutable audit-event and escalation evidence, and guarded mutable outbox transitions remain mandatory. - Necessary PII remains usable only through purpose-bound authorization; indiscriminate masking is not a substitute for access control. - High-impact employment decisions require accountable human confirmation with actor/purpose/reason/evidence versioning. LLM output remains untrusted draft evidence only. - Preserve modular MSA extraction boundaries; do not introduce direct cross-service application-table SQL. @@ -99,7 +99,7 @@ External finance/accounting and billing/collection integration remains planned/o ## Execution loop -Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, formal reviews/threads, exact-head workflows/jobs, releases, changed refs and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when an executable regression is appropriate; rerun exact-head evidence; resolve only addressed threads; and merge only when the unchanged head satisfies the effective ruleset plus every applicable local gate. +Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, formal reviews/threads, exact-head workflows/jobs, releases, changed refs and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when an executable regression is appropriate; rerun exact-head evidence; resolve only addressed threads; and merge only when the unchanged head satisfies the effective ruleset, the commercial acceptance policy of at least two qualifying independent non-author approvals including approval after the last push with resolved conversations, and every applicable local/central gate. For live-state documentation defects such as repository ruleset truth or active owner-lane ownership, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop refetches the effective ruleset/current PR graph and rejects stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. diff --git a/docs/traceability/candidate-evidence-intake.md b/docs/traceability/candidate-evidence-intake.md index 62955813c..c3dfa8b04 100644 --- a/docs/traceability/candidate-evidence-intake.md +++ b/docs/traceability/candidate-evidence-intake.md @@ -1,6 +1,6 @@ # Candidate evidence intake traceability -- **Maturity:** `implemented_on_active_pr` +- **Maturity:** `implemented_on_protected_main` - **Buyer capability:** Candidate Evidence workspace governance boundary - **Owned contract:** `CandidateEvidenceIntakePacket` diff --git a/docs/traceability/offer-approval.md b/docs/traceability/offer-approval.md index 5104cfb8d..8da33aabe 100644 --- a/docs/traceability/offer-approval.md +++ b/docs/traceability/offer-approval.md @@ -1,6 +1,6 @@ # Governed offer approval traceability -Status: **active PR / proposed capability**, not protected-main truth. +Status: **implemented on protected `develop`**; downstream offer persistence/execution remains a separate authority. | Buyer requirement | Executable evidence | Contract outcome | | --- | --- | --- | diff --git a/manifest.json b/manifest.json index 97f2bab14..857506485 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353","bytes":17295,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"1a9fc400d26d8137ae5911488794a6d3fa915957c95f27b36a48cef0fdf823c6","bytes":3785,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"dbf6fd91375ea28e05456d2a0c9ba629506cbac6f52f5dfda61ae68db2395f7e","bytes":11462,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"827298ddd997b47f78a89e89911ad8ea72e517b7714303637f0329b8cb52cabd","bytes":14100,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"953c6d2b9864a78b461b576092ec3f198f0b76709eaaaf7d0ed0182f95182c52","bytes":5653,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"1ac10bb2747b0a5b4d62f627825cfd7f978f3fa88d7575bffc23d56371240a64","bytes":7057,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"3e1050a964cc4ed76a1a0cf1e699ae5080acf8c9336f0decdd6d5229359db3c9","bytes":3917,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1656ef8b57c836ef7936a8e9cb6a824681eb7563157a1ab0a29deb25849a457b","bytes":5568,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"713855d670001d3964ecb36cc653830502fb1d82a58b9e39f564b6992dd2bd80","bytes":5965,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"70bf2cbdf903a8793d6d8bc116a08331931090118341f42010236e09c6cc1802","bytes":4693,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"a7ab6fee50aaa63f7f407516a4cb39885faeb0fc6e5035ee8fc352ed73430105","bytes":5365,"lines":49},{"path":"docs/adr/README.md","sha256":"f3b3b5ed3b3b31a40a0a3696abf0065e3c25879b6be50077f38ffae742b9d002","bytes":1838,"lines":18},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353","bytes":17295,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"a84b9bbea7edcb52fb0ff5ec4ecd0cbdd8335ea3ee03de3aa700d5fb1712ad3c","bytes":11467,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"827298ddd997b47f78a89e89911ad8ea72e517b7714303637f0329b8cb52cabd","bytes":14100,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"1ac10bb2747b0a5b4d62f627825cfd7f978f3fa88d7575bffc23d56371240a64","bytes":7057,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"3e1050a964cc4ed76a1a0cf1e699ae5080acf8c9336f0decdd6d5229359db3c9","bytes":3917,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1656ef8b57c836ef7936a8e9cb6a824681eb7563157a1ab0a29deb25849a457b","bytes":5568,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"713855d670001d3964ecb36cc653830502fb1d82a58b9e39f564b6992dd2bd80","bytes":5965,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"70bf2cbdf903a8793d6d8bc116a08331931090118341f42010236e09c6cc1802","bytes":4693,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"d76a91517ea7c17dfdb1a34654cc29934580d6a5f98eb5bc307c856f1717bac0","bytes":1819,"lines":18},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From 8267ea2b6666d87530a41a0f5f14924dac2de8a0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 12:28:14 +0900 Subject: [PATCH 033/201] docs: index accepted ADRs --- docs/adr/README.md | 2 ++ manifest.json | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/adr/README.md b/docs/adr/README.md index 99d98fa45..3ecd82eb9 100644 --- a/docs/adr/README.md +++ b/docs/adr/README.md @@ -16,3 +16,5 @@ | [0012](0012-governed-migration-handoff.md) | Governed migration handoff | Accepted on active implementation branch | | [0013](0013-governed-requisition-review-packet.md) | Governed requisition review packet | Accepted on active implementation branch | | [0014](0014-job-analysis-snapshot-persistence.md) | Persist governed job-analysis snapshots | Accepted on protected `develop` | +| [0017](0017-governed-offer-approval.md) | Governed offer approval evidence | Accepted on protected `develop` | +| [0025](0025-governed-candidate-evidence-intake.md) | Govern candidate evidence intake as reference-only evidence | Accepted on protected `develop` | diff --git a/manifest.json b/manifest.json index 857506485..8389fb57b 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353","bytes":17295,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"a84b9bbea7edcb52fb0ff5ec4ecd0cbdd8335ea3ee03de3aa700d5fb1712ad3c","bytes":11467,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"827298ddd997b47f78a89e89911ad8ea72e517b7714303637f0329b8cb52cabd","bytes":14100,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"1ac10bb2747b0a5b4d62f627825cfd7f978f3fa88d7575bffc23d56371240a64","bytes":7057,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"3e1050a964cc4ed76a1a0cf1e699ae5080acf8c9336f0decdd6d5229359db3c9","bytes":3917,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1656ef8b57c836ef7936a8e9cb6a824681eb7563157a1ab0a29deb25849a457b","bytes":5568,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"713855d670001d3964ecb36cc653830502fb1d82a58b9e39f564b6992dd2bd80","bytes":5965,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"70bf2cbdf903a8793d6d8bc116a08331931090118341f42010236e09c6cc1802","bytes":4693,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"d76a91517ea7c17dfdb1a34654cc29934580d6a5f98eb5bc307c856f1717bac0","bytes":1819,"lines":18},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353","bytes":17295,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"a84b9bbea7edcb52fb0ff5ec4ecd0cbdd8335ea3ee03de3aa700d5fb1712ad3c","bytes":11467,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"827298ddd997b47f78a89e89911ad8ea72e517b7714303637f0329b8cb52cabd","bytes":14100,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"1ac10bb2747b0a5b4d62f627825cfd7f978f3fa88d7575bffc23d56371240a64","bytes":7057,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"3e1050a964cc4ed76a1a0cf1e699ae5080acf8c9336f0decdd6d5229359db3c9","bytes":3917,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1656ef8b57c836ef7936a8e9cb6a824681eb7563157a1ab0a29deb25849a457b","bytes":5568,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"713855d670001d3964ecb36cc653830502fb1d82a58b9e39f564b6992dd2bd80","bytes":5965,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"70bf2cbdf903a8793d6d8bc116a08331931090118341f42010236e09c6cc1802","bytes":4693,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"77e22f0c4de51210f11efee70e339d17964b462185595f94c747a12cce85312f","bytes":2083,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From 57cb9e461bf594e96c0b125349325f35cba95d20 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 12:34:30 +0900 Subject: [PATCH 034/201] docs: refresh central remediation head --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 64e7345dc..7a79d58a6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `4c2bdcb986685e59614b1d9ac62eaf6ca228a796`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `4c2bdcb986685e59614b1d9ac62eaf6ca228a796`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `5f1c1da39e94eac12e70ee2c1e4ca61367fd5399`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `5f1c1da39e94eac12e70ee2c1e4ca61367fd5399`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 85937794156270edafc95073fc8f5c2a7d247a4a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 13:29:36 +0900 Subject: [PATCH 035/201] docs: refresh central remediation head --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7a79d58a6..5e7e3de90 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `5f1c1da39e94eac12e70ee2c1e4ca61367fd5399`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `5f1c1da39e94eac12e70ee2c1e4ca61367fd5399`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `30540d2cbe3243c38b17eb19661fe1c395ee8caf`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `30540d2cbe3243c38b17eb19661fe1c395ee8caf`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From bffb186812ee0bed42cd4710956f980c522feed9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 13:34:13 +0900 Subject: [PATCH 036/201] docs: refresh central remediation head again --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5e7e3de90..d39678ca6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `30540d2cbe3243c38b17eb19661fe1c395ee8caf`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `30540d2cbe3243c38b17eb19661fe1c395ee8caf`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `cc6bb0571136a9b342d745008799a3bd1fc24cfc`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `cc6bb0571136a9b342d745008799a3bd1fc24cfc`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 79f13a72458f9a11f39ea068c11582057c5d7c07 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 13:39:38 +0900 Subject: [PATCH 037/201] docs: reconcile protected capability statuses --- docs/TRACEABILITY.md | 2 +- .../0009-performance-criterion-observation-scope.md | 2 +- docs/adr/0010-naruon-calendar-intent-boundary.md | 2 +- docs/adr/0011-bitemporal-workforce-composition.md | 2 +- docs/adr/0012-governed-migration-handoff.md | 2 +- docs/adr/0013-governed-requisition-review-packet.md | 4 ++-- docs/adr/README.md | 10 +++++----- docs/traceability/migration-handoff.md | 2 +- docs/traceability/naruon-calendar-intent.md | 2 +- docs/traceability/requisition-review.md | 2 +- docs/traceability/workforce-composition.md | 2 +- manifest.json | 2 +- 12 files changed, 17 insertions(+), 17 deletions(-) diff --git a/docs/TRACEABILITY.md b/docs/TRACEABILITY.md index 7e7281195..005638ba9 100644 --- a/docs/TRACEABILITY.md +++ b/docs/TRACEABILITY.md @@ -31,7 +31,7 @@ | External contract | Orgmetra owner boundary | Integration style | Required evidence | ADR | Maturity | |---|---|---|---|---|---| | Keyverse identity and authorization | API Gateway / purpose-bound authorization | Published OIDC/API identity and scope contract plus Orgmetra-owned `orgmetra_keyverse_adapter` policy evaluation | tenant/actor/resource agreement, exact opaque target-resource reference, purpose, operation-specific scope, requested-field minimization, opaque subject, no stored credentials or protected values in authorization evidence | ADR-0002, ADR-0008 | implemented_on_protected_main | -| naruon communication and calendar | Integration Hub | Published API/event adapter | idempotency, delivery audit, no direct table access | ADR-0002 | planned | +| naruon communication and calendar | Integration Hub | Published API/event adapter | idempotency, delivery audit, no direct table access | ADR-0002 | implemented_on_protected_main | | Psychometrics Commons @ `cc5850a0d1eacbbf16d03075534fce460a8286e6` | Workforce Validation | Immutable response/result snapshot contract | pinned revision, model/version/provenance snapshot, immutable result linkage, no direct application-table access | ADR-0002 | accepted_architecture | | fast-mlsirm @ `fb67ced09d8ee00542c05d56374537a9a7239751` | Workforce Validation | Published `orgmetra.fast_mlsirm.v1` result contract; direct calls only from approved offline validation worker | pinned revision, contract identifier, backend/result provenance, CPU/GPU parity evidence where material, no duplicated kernel | ADR-0002 | accepted_architecture | | TEPP temporal evidence | Workforce Validation | Published package/API contract | temporal provenance and version binding | ADR-0002 | planned | diff --git a/docs/adr/0009-performance-criterion-observation-scope.md b/docs/adr/0009-performance-criterion-observation-scope.md index 69baa87c9..f2a679005 100644 --- a/docs/adr/0009-performance-criterion-observation-scope.md +++ b/docs/adr/0009-performance-criterion-observation-scope.md @@ -1,6 +1,6 @@ # ADR 0009: Performance criterion observations require worker-job scope -Status: Accepted +Status: Accepted on protected `develop` ## Context diff --git a/docs/adr/0010-naruon-calendar-intent-boundary.md b/docs/adr/0010-naruon-calendar-intent-boundary.md index 6bed4dd49..155c623ce 100644 --- a/docs/adr/0010-naruon-calendar-intent-boundary.md +++ b/docs/adr/0010-naruon-calendar-intent-boundary.md @@ -2,7 +2,7 @@ ## Status -Accepted on active PR only. This document is not protected-`develop` product truth until its owning PR integrates. +Accepted on protected `develop`. ## Context diff --git a/docs/adr/0011-bitemporal-workforce-composition.md b/docs/adr/0011-bitemporal-workforce-composition.md index 7e9302870..a6a26bab6 100644 --- a/docs/adr/0011-bitemporal-workforce-composition.md +++ b/docs/adr/0011-bitemporal-workforce-composition.md @@ -2,7 +2,7 @@ ## Status -Accepted on active PR #33 only. This document is not protected-`develop` product truth until the owning PR integrates. +Accepted on protected `develop`. ## Context diff --git a/docs/adr/0012-governed-migration-handoff.md b/docs/adr/0012-governed-migration-handoff.md index ec9ab40f0..c1b99dc14 100644 --- a/docs/adr/0012-governed-migration-handoff.md +++ b/docs/adr/0012-governed-migration-handoff.md @@ -2,7 +2,7 @@ ## Status -Accepted on this active PR only. This is not protected-`develop` product truth until the owning PR integrates. +Accepted on protected `develop`. ## Context diff --git a/docs/adr/0013-governed-requisition-review-packet.md b/docs/adr/0013-governed-requisition-review-packet.md index 4f1e0b239..ba53dcc28 100644 --- a/docs/adr/0013-governed-requisition-review-packet.md +++ b/docs/adr/0013-governed-requisition-review-packet.md @@ -1,6 +1,6 @@ # ADR 0013: Governed requisition review packet -- Status: Accepted on active implementation branch +- Status: Accepted on protected `develop` - Date: 2026-08-18 - Owners: Talent Acquisition / Job Architecture / People Governance @@ -39,7 +39,7 @@ The packet cannot claim approval, open a requisition, create a candidate, or per - Routine `repr()` output does not disclose trust-bearing references or digests. - Requisition approval requires authoritative resolved-actor separation; two different opaque references alone cannot satisfy the hiring-manager/approver separation requirement. - Downstream persistence must still enforce purpose-bound authorization, idempotency, human approval, and immutable audit/outbox evidence at the authoritative mutation boundary. -- This ADR describes active-PR truth only until the corresponding exact head integrates into protected `develop`. +- This ADR records the protected `develop` requisition-review boundary; downstream approval and creation remain separate authorities. ## References diff --git a/docs/adr/README.md b/docs/adr/README.md index 3ecd82eb9..ab42115b2 100644 --- a/docs/adr/README.md +++ b/docs/adr/README.md @@ -10,11 +10,11 @@ | [0006](0006-governed-audit-outbox-envelope.md) | Governed audit/outbox envelope and durable persistence | Accepted on stacked implementation branch | | [0007](0007-governed-job-analysis-evidence.md) | Governed job-analysis evidence snapshots | Accepted on protected `develop` | | [0008](0008-purpose-bound-pii-authorization.md) | Purpose-bound PII authorization | Accepted on protected `develop` | -| [0009](0009-performance-criterion-observation-scope.md) | Performance criterion observations require worker-job scope | Accepted on active implementation branch | -| [0010](0010-naruon-calendar-intent-boundary.md) | Naruon calendar intent boundary | Accepted on active implementation branch | -| [0011](0011-bitemporal-workforce-composition.md) | Bitemporal workforce composition | Accepted on active implementation branch | -| [0012](0012-governed-migration-handoff.md) | Governed migration handoff | Accepted on active implementation branch | -| [0013](0013-governed-requisition-review-packet.md) | Governed requisition review packet | Accepted on active implementation branch | +| [0009](0009-performance-criterion-observation-scope.md) | Performance criterion observations require worker-job scope | Accepted on protected `develop` | +| [0010](0010-naruon-calendar-intent-boundary.md) | Naruon calendar intent boundary | Accepted on protected `develop` | +| [0011](0011-bitemporal-workforce-composition.md) | Bitemporal workforce composition | Accepted on protected `develop` | +| [0012](0012-governed-migration-handoff.md) | Governed migration handoff | Accepted on protected `develop` | +| [0013](0013-governed-requisition-review-packet.md) | Governed requisition review packet | Accepted on protected `develop` | | [0014](0014-job-analysis-snapshot-persistence.md) | Persist governed job-analysis snapshots | Accepted on protected `develop` | | [0017](0017-governed-offer-approval.md) | Governed offer approval evidence | Accepted on protected `develop` | | [0025](0025-governed-candidate-evidence-intake.md) | Govern candidate evidence intake as reference-only evidence | Accepted on protected `develop` | diff --git a/docs/traceability/migration-handoff.md b/docs/traceability/migration-handoff.md index 27ec3f113..d09f2f87a 100644 --- a/docs/traceability/migration-handoff.md +++ b/docs/traceability/migration-handoff.md @@ -2,7 +2,7 @@ ## Status -Active-PR only. This evidence does not describe protected-`develop` product truth until the owning PR integrates. +Implemented on protected `develop`; this remains a pre-write handoff boundary rather than a migration executor. | Requirement | Decision / owner contract | Production implementation | Executable evidence | |---|---|---|---| diff --git a/docs/traceability/naruon-calendar-intent.md b/docs/traceability/naruon-calendar-intent.md index 790447641..f1e15676a 100644 --- a/docs/traceability/naruon-calendar-intent.md +++ b/docs/traceability/naruon-calendar-intent.md @@ -2,7 +2,7 @@ ## Status -Active-PR only. This evidence does not describe protected-`develop` product truth until the owning PR integrates. +Implemented on protected `develop`; Naruon remains the owner of provider execution. | Requirement | Decision / contract | Production implementation | Executable evidence | |---|---|---|---| diff --git a/docs/traceability/requisition-review.md b/docs/traceability/requisition-review.md index ca9bfe0ec..6d0ff6391 100644 --- a/docs/traceability/requisition-review.md +++ b/docs/traceability/requisition-review.md @@ -2,7 +2,7 @@ ## Maturity -**Active PR only.** Protected `develop` does not contain this capability until the candidate branch is integrated with fresh protected-head evidence. +**Implemented on protected `develop`.** This packet remains review evidence rather than an authoritative requisition or approval. ## Requirement-to-evidence map diff --git a/docs/traceability/workforce-composition.md b/docs/traceability/workforce-composition.md index c33c5ca0d..014e29a49 100644 --- a/docs/traceability/workforce-composition.md +++ b/docs/traceability/workforce-composition.md @@ -2,7 +2,7 @@ ## Status -Active-PR only. This evidence does not describe protected-`develop` product truth until PR #33 integrates. +Implemented on protected `develop`; the aggregate boundary remains descriptive and does not make employment decisions. | Requirement | Decision / contract | Production implementation | Executable evidence | |---|---|---|---| diff --git a/manifest.json b/manifest.json index 8389fb57b..72a5f48d2 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353","bytes":17295,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"a84b9bbea7edcb52fb0ff5ec4ecd0cbdd8335ea3ee03de3aa700d5fb1712ad3c","bytes":11467,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"827298ddd997b47f78a89e89911ad8ea72e517b7714303637f0329b8cb52cabd","bytes":14100,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"1ac10bb2747b0a5b4d62f627825cfd7f978f3fa88d7575bffc23d56371240a64","bytes":7057,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"3e1050a964cc4ed76a1a0cf1e699ae5080acf8c9336f0decdd6d5229359db3c9","bytes":3917,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1656ef8b57c836ef7936a8e9cb6a824681eb7563157a1ab0a29deb25849a457b","bytes":5568,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"713855d670001d3964ecb36cc653830502fb1d82a58b9e39f564b6992dd2bd80","bytes":5965,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"70bf2cbdf903a8793d6d8bc116a08331931090118341f42010236e09c6cc1802","bytes":4693,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"77e22f0c4de51210f11efee70e339d17964b462185595f94c747a12cce85312f","bytes":2083,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353","bytes":17295,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"b5e6496ce1e990caccc8d12f5f7635ba9b9f9984d3f5f40138db3c16f301411a","bytes":11489,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"827298ddd997b47f78a89e89911ad8ea72e517b7714303637f0329b8cb52cabd","bytes":14100,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"44b9542225479fee3f1f63ae52cbc09f9e764a3930b91bbf5ff52a6f8363e6c0","bytes":2038,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From 9d212c83cff230e3f1096c0cc2132f83ec1091b2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 13:41:21 +0900 Subject: [PATCH 038/201] docs: refresh central PR head --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d39678ca6..9771d06b6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -50,8 +50,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `cc6bb0571136a9b342d745008799a3bd1fc24cfc`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `cc6bb0571136a9b342d745008799a3bd1fc24cfc`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `4a694d5057961d787f2b12ae55e1c4296d022a70`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `4a694d5057961d787f2b12ae55e1c4296d022a70`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 371b5719718d8b98384ce5e9619330299673e5b1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 13:46:49 +0900 Subject: [PATCH 039/201] docs: enumerate merged product anchors --- docs/product-technical-gap-baseline.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9771d06b6..6080604e8 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -35,10 +35,15 @@ Consequences: | Merged PR | Capability | |---|---| +| #25 | Governed Job Analysis evidence boundary | | #26 | `validity_study_case_record` integrity | | #28 | Performance-criterion Job-scope guard | | #31 | Governed People mutation API | +| #32 | Governed Naruon calendar intent adapter | +| #33 | Bitemporal workforce-composition evidence | +| #35 | Governed HRIS migration handoff | | #38 | Governed Job Analysis snapshot persistence/read | +| #39 | Governed requisition review packet | | #41 | Governed candidate evidence intake | | #43 | Governed offer approval packet | From 9114e6ef63188941915c59e4d3448334d495d3dc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:09:54 +0900 Subject: [PATCH 040/201] docs: refresh active PR baseline heads --- docs/product-technical-gap-baseline.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6080604e8..38e201501 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -54,6 +54,8 @@ This is a selected shipped inventory, not a replacement for Git history. Do not The following material owner lanes were freshly rechecked during the 2026-08-28 maintenance loop. - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. +- **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage; hosted checks are still running with no exact-head failure observed, all review threads are resolved, and no qualifying approval is present. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. +- **PR #44** remains Draft at exact head `f75dc8d46e26d0dba8adb3f184a744b540971928`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; hosted checks are still queued or in progress, all review threads are resolved, and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `4a694d5057961d787f2b12ae55e1c4296d022a70`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `4a694d5057961d787f2b12ae55e1c4296d022a70`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From 96011e14597c65cda3f35c90cc2634def2df81d9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:18:23 +0900 Subject: [PATCH 041/201] docs: record current gate outcomes --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 38e201501..cf1057090 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -54,8 +54,8 @@ This is a selected shipped inventory, not a replacement for Git history. Do not The following material owner lanes were freshly rechecked during the 2026-08-28 maintenance loop. - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. -- **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage; hosted checks are still running with no exact-head failure observed, all review threads are resolved, and no qualifying approval is present. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. -- **PR #44** remains Draft at exact head `f75dc8d46e26d0dba8adb3f184a744b540971928`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; hosted checks are still queued or in progress, all review threads are resolved, and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. +- **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. +- **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 39 hosted checks are attached with 7 success, 6 skipped, 26 queued/in progress, and no terminal failure observed at the latest read. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `4a694d5057961d787f2b12ae55e1c4296d022a70`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `4a694d5057961d787f2b12ae55e1c4296d022a70`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From 0e11fee2b559a37c729f1b3fbb402b67ea3e6520 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:27:28 +0900 Subject: [PATCH 042/201] docs: refresh current central gate baseline --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index cf1057090..08111fa2a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -55,10 +55,10 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. -- **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 39 hosted checks are attached with 7 success, 6 skipped, 26 queued/in progress, and no terminal failure observed at the latest read. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. +- **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `4a694d5057961d787f2b12ae55e1c4296d022a70`, currently still open/blocked while its unchanged-head checks complete and qualifying independent approval is absent. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `4a694d5057961d787f2b12ae55e1c4296d022a70`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `7d249234c970ab6f10a08ef88398383190996ba2`, currently still open with exact-head hosted checks incomplete and no qualifying independent approval. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `7d249234c970ab6f10a08ef88398383190996ba2`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From aafcfd364de9558a23c669f95f4555d472b25024 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:32:37 +0900 Subject: [PATCH 043/201] docs: mark audit outbox ADR as shipped --- .../0006-governed-audit-outbox-envelope.md | 2 +- docs/adr/README.md | 2 +- manifest.json | 482 +++++++++++++++++- 3 files changed, 483 insertions(+), 3 deletions(-) diff --git a/docs/adr/0006-governed-audit-outbox-envelope.md b/docs/adr/0006-governed-audit-outbox-envelope.md index bd86f2684..c9c88c6a9 100644 --- a/docs/adr/0006-governed-audit-outbox-envelope.md +++ b/docs/adr/0006-governed-audit-outbox-envelope.md @@ -1,6 +1,6 @@ # ADR-0006: Governed audit/outbox envelope and durable persistence -- **Status:** Accepted for the stacked implementation branch; not protected-main truth until merged. +- **Status:** Accepted on protected `develop`. - **Decision date:** 2026-08-17 - **Scope:** Orgmetra-owned audit envelope, immutable audit persistence, guarded outbox delivery state, tenant-safe atomic dispatcher claiming, expired-lease takeover, owner-bound completion/retry, database-budget-governed terminal dead-letter escalation, review hardening, and privileged recovery of an expired exhausted lease when its recorded final worker identity is permanently unavailable. Exponential retry policy, retention/export workflows, and external delivery receipts remain subsequent work. diff --git a/docs/adr/README.md b/docs/adr/README.md index ab42115b2..dcf692c4d 100644 --- a/docs/adr/README.md +++ b/docs/adr/README.md @@ -7,7 +7,7 @@ | [0003](0003-bitemporal-hris-data-contract.md) | Bitemporal HRIS data contract | Accepted | | [0004](0004-employment-position-version-and-assignment-binding.md) | Employment and position versions bind assignments | Accepted | | [0005](0005-exclusive-employment-and-staffable-seats.md) | Exclusive employment and staffable seats | Accepted | -| [0006](0006-governed-audit-outbox-envelope.md) | Governed audit/outbox envelope and durable persistence | Accepted on stacked implementation branch | +| [0006](0006-governed-audit-outbox-envelope.md) | Governed audit/outbox envelope and durable persistence | Accepted on protected `develop` | | [0007](0007-governed-job-analysis-evidence.md) | Governed job-analysis evidence snapshots | Accepted on protected `develop` | | [0008](0008-purpose-bound-pii-authorization.md) | Purpose-bound PII authorization | Accepted on protected `develop` | | [0009](0009-performance-criterion-observation-scope.md) | Performance criterion observations require worker-job scope | Accepted on protected `develop` | diff --git a/manifest.json b/manifest.json index 72a5f48d2..c4542f1d6 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1,481 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353","bytes":17295,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"b5e6496ce1e990caccc8d12f5f7635ba9b9f9984d3f5f40138db3c16f301411a","bytes":11489,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"827298ddd997b47f78a89e89911ad8ea72e517b7714303637f0329b8cb52cabd","bytes":14100,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"44b9542225479fee3f1f63ae52cbc09f9e764a3930b91bbf5ff52a6f8363e6c0","bytes":2038,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{ + "package": "orgmetra-foundation-pack", + "version": "0.1.0", + "generated_for_branch": "feat/audit-outbox-envelope", + "files": [ + { + "path": ".github/workflows/foundation-ci.yml", + "sha256": "12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537", + "bytes": 4379, + "lines": 123 + }, + { + "path": ".github/workflows/job-analysis-api-quality.yml", + "sha256": "352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a", + "bytes": 4159, + "lines": 105 + }, + { + "path": ".gitignore", + "sha256": "145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21", + "bytes": 375, + "lines": 37 + }, + { + "path": "AGENTS.md", + "sha256": "28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16", + "bytes": 2246, + "lines": 34 + }, + { + "path": "ARCHITECTURE.md", + "sha256": "52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850", + "bytes": 7864, + "lines": 107 + }, + { + "path": "CHANGELOG.md", + "sha256": "32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353", + "bytes": 17295, + "lines": 76 + }, + { + "path": "CLAUDE.md", + "sha256": "add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f", + "bytes": 1229, + "lines": 20 + }, + { + "path": "LICENSE", + "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", + "bytes": 11358, + "lines": 202 + }, + { + "path": "NOTICE", + "sha256": "34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042", + "bytes": 305, + "lines": 4 + }, + { + "path": "README.md", + "sha256": "c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e", + "bytes": 3889, + "lines": 81 + }, + { + "path": "database/migrations/0001_foundation_schema.sql", + "sha256": "ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd", + "bytes": 38747, + "lines": 916 + }, + { + "path": "database/migrations/0002_sealed_evidence_digest.sql", + "sha256": "93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c", + "bytes": 6649, + "lines": 202 + }, + { + "path": "database/migrations/0003_audit_outbox_persistence.sql", + "sha256": "2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc", + "bytes": 15417, + "lines": 423 + }, + { + "path": "database/migrations/0004_outbox_delivery_claim.sql", + "sha256": "d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef", + "bytes": 9451, + "lines": 234 + }, + { + "path": "database/migrations/0005_outbox_delivery_finalization.sql", + "sha256": "b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961", + "bytes": 6125, + "lines": 170 + }, + { + "path": "database/migrations/0006_outbox_delivery_dead_letter.sql", + "sha256": "c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7", + "bytes": 24919, + "lines": 628 + }, + { + "path": "database/migrations/0007_outbox_retry_exhaustion.sql", + "sha256": "812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5", + "bytes": 19081, + "lines": 476 + }, + { + "path": "database/migrations/0008_audit_outbox_review_hardening.sql", + "sha256": "c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b", + "bytes": 17562, + "lines": 448 + }, + { + "path": "database/migrations/0009_candidate_worker_conversion_governance.sql", + "sha256": "4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9", + "bytes": 11537, + "lines": 281 + }, + { + "path": "database/migrations/0010_validity_study_case_integrity.sql", + "sha256": "3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1", + "bytes": 11979, + "lines": 313 + }, + { + "path": "database/migrations/0011_criterion_observation_scope.sql", + "sha256": "f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9", + "bytes": 7444, + "lines": 165 + }, + { + "path": "database/migrations/0012_people_mutation_idempotency.sql", + "sha256": "52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69", + "bytes": 3162, + "lines": 76 + }, + { + "path": "database/migrations/0013_job_analysis_snapshot.sql", + "sha256": "b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee", + "bytes": 12713, + "lines": 260 + }, + { + "path": "docs/API_CONTRACT.md", + "sha256": "63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589", + "bytes": 4555, + "lines": 76 + }, + { + "path": "docs/DATA_MODEL.md", + "sha256": "6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a", + "bytes": 13366, + "lines": 85 + }, + { + "path": "docs/ERD.md", + "sha256": "546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe", + "bytes": 6964, + "lines": 70 + }, + { + "path": "docs/OPERABILITY.md", + "sha256": "82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62", + "bytes": 11189, + "lines": 71 + }, + { + "path": "docs/PRD.md", + "sha256": "3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1", + "bytes": 5490, + "lines": 111 + }, + { + "path": "docs/SECURITY.md", + "sha256": "01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac", + "bytes": 11185, + "lines": 64 + }, + { + "path": "docs/STORYBOARD.md", + "sha256": "6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2", + "bytes": 1342, + "lines": 28 + }, + { + "path": "docs/STORYBOOK.md", + "sha256": "82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9", + "bytes": 1389, + "lines": 50 + }, + { + "path": "docs/TEST_STRATEGY.md", + "sha256": "d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8", + "bytes": 16534, + "lines": 135 + }, + { + "path": "docs/THREAT_MODEL.md", + "sha256": "f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252", + "bytes": 6736, + "lines": 23 + }, + { + "path": "docs/TRACEABILITY.md", + "sha256": "b5e6496ce1e990caccc8d12f5f7635ba9b9f9984d3f5f40138db3c16f301411a", + "bytes": 11489, + "lines": 40 + }, + { + "path": "docs/TRD.md", + "sha256": "23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077", + "bytes": 9064, + "lines": 101 + }, + { + "path": "docs/UML.md", + "sha256": "fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9", + "bytes": 5528, + "lines": 122 + }, + { + "path": "docs/USER_STORIES.md", + "sha256": "5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f", + "bytes": 2670, + "lines": 37 + }, + { + "path": "docs/WIREFRAMES.md", + "sha256": "b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e", + "bytes": 2005, + "lines": 77 + }, + { + "path": "docs/adr/0001-orgmetra-authoritative-hris-record.md", + "sha256": "0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572", + "bytes": 6108, + "lines": 53 + }, + { + "path": "docs/adr/0002-federated-cwl-integration-boundaries.md", + "sha256": "b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2", + "bytes": 4072, + "lines": 44 + }, + { + "path": "docs/adr/0003-bitemporal-hris-data-contract.md", + "sha256": "d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799", + "bytes": 4453, + "lines": 47 + }, + { + "path": "docs/adr/0004-employment-position-version-and-assignment-binding.md", + "sha256": "fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182", + "bytes": 1872, + "lines": 30 + }, + { + "path": "docs/adr/0005-exclusive-employment-and-staffable-seats.md", + "sha256": "10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b", + "bytes": 2091, + "lines": 34 + }, + { + "path": "docs/adr/0006-governed-audit-outbox-envelope.md", + "sha256": "987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9", + "bytes": 14046, + "lines": 66 + }, + { + "path": "docs/adr/0007-governed-job-analysis-evidence.md", + "sha256": "0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5", + "bytes": 5643, + "lines": 57 + }, + { + "path": "docs/adr/0008-purpose-bound-pii-authorization.md", + "sha256": "c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7", + "bytes": 5988, + "lines": 55 + }, + { + "path": "docs/adr/0009-performance-criterion-observation-scope.md", + "sha256": "5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e", + "bytes": 7080, + "lines": 57 + }, + { + "path": "docs/adr/0010-naruon-calendar-intent-boundary.md", + "sha256": "ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e", + "bytes": 3835, + "lines": 35 + }, + { + "path": "docs/adr/0011-bitemporal-workforce-composition.md", + "sha256": "1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103", + "bytes": 5482, + "lines": 53 + }, + { + "path": "docs/adr/0012-governed-migration-handoff.md", + "sha256": "cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc", + "bytes": 5887, + "lines": 59 + }, + { + "path": "docs/adr/0013-governed-requisition-review-packet.md", + "sha256": "2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48", + "bytes": 4704, + "lines": 46 + }, + { + "path": "docs/adr/0014-job-analysis-snapshot-persistence.md", + "sha256": "d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d", + "bytes": 5356, + "lines": 49 + }, + { + "path": "docs/adr/README.md", + "sha256": "f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af", + "bytes": 2028, + "lines": 20 + }, + { + "path": "docs/doctoring/REFERENCES.md", + "sha256": "929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5", + "bytes": 6352, + "lines": 69 + }, + { + "path": "docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md", + "sha256": "b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd", + "bytes": 8227, + "lines": 226 + }, + { + "path": "docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md", + "sha256": "4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d", + "bytes": 6237, + "lines": 187 + }, + { + "path": "package.json", + "sha256": "59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5", + "bytes": 388, + "lines": 9 + }, + { + "path": "packages/hris-kernel/src/orgmetra_hris_kernel/audit.py", + "sha256": "3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190", + "bytes": 7707, + "lines": 160 + }, + { + "path": "packages/hris-kernel/tests/test_audit_outbox.py", + "sha256": "5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c", + "bytes": 7556, + "lines": 200 + }, + { + "path": "schemas/openapi.yaml", + "sha256": "09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f", + "bytes": 29503, + "lines": 1020 + }, + { + "path": "scripts/foundation-contract-core.mjs", + "sha256": "595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445", + "bytes": 28173, + "lines": 689 + }, + { + "path": "scripts/foundation-contract.mjs", + "sha256": "5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a", + "bytes": 218, + "lines": 6 + }, + { + "path": "tests/dispatcher-inventory.test.mjs", + "sha256": "09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261", + "bytes": 1597, + "lines": 34 + }, + { + "path": "tests/foundation-contract.test.mjs", + "sha256": "960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615", + "bytes": 14860, + "lines": 386 + }, + { + "path": "tests/openapi-contract.test.mjs", + "sha256": "80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc", + "bytes": 6438, + "lines": 195 + }, + { + "path": "tests/test_audit_outbox_hardening_postgres.sh", + "sha256": "518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0", + "bytes": 13396, + "lines": 333 + }, + { + "path": "tests/test_audit_outbox_postgres.sh", + "sha256": "e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2", + "bytes": 13443, + "lines": 357 + }, + { + "path": "tests/test_bitemporal_postgres.sh", + "sha256": "7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc", + "bytes": 8209, + "lines": 230 + }, + { + "path": "tests/test_candidate_worker_conversion_postgres.sh", + "sha256": "681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90", + "bytes": 14673, + "lines": 344 + }, + { + "path": "tests/test_criterion_observation_scope_postgres.sh", + "sha256": "0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d", + "bytes": 17811, + "lines": 469 + }, + { + "path": "tests/test_evidence_sealing_postgres.sh", + "sha256": "57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7", + "bytes": 11349, + "lines": 370 + }, + { + "path": "tests/test_job_analysis_snapshot_postgres.sh", + "sha256": "ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f", + "bytes": 13542, + "lines": 296 + }, + { + "path": "tests/test_operational_uuid_postgres.sh", + "sha256": "7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7", + "bytes": 3346, + "lines": 101 + }, + { + "path": "tests/test_outbox_claim_postgres.sh", + "sha256": "1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b", + "bytes": 14817, + "lines": 429 + }, + { + "path": "tests/test_outbox_dead_letter_postgres.sh", + "sha256": "0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d", + "bytes": 14008, + "lines": 377 + }, + { + "path": "tests/test_people_mutation_idempotency_postgres.sh", + "sha256": "3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5", + "bytes": 16191, + "lines": 381 + }, + { + "path": "tests/test_tenant_isolation_postgres.sh", + "sha256": "dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a", + "bytes": 15134, + "lines": 388 + }, + { + "path": "tests/test_validity_study_case_postgres.sh", + "sha256": "0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02", + "bytes": 14708, + "lines": 301 + }, + { + "path": "tests/validate_repository.py", + "sha256": "918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9", + "bytes": 27291, + "lines": 638 + } + ] +} From 5c69d7116efddb04f2e9bc82adf4dd600c361657 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:34:41 +0900 Subject: [PATCH 044/201] docs: mark audit outbox changelog as shipped --- CHANGELOG.md | 2 +- manifest.json | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 99f4752d7..97f7196de 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,7 +12,7 @@ All notable changes to Orgmetra will be documented in this file. - Active performance-criterion scope hardening: `criterion_observation_scope_guard` rejects criterion outcomes for a Job the worker did not effectively hold at the observation date, observations before the relevant assignment, and observations outside the referenced performance cycle while preserving valid multiple-assignment cases and existing bitemporal correction semantics. The guard evaluates current-recorded facts, derives the date coordinate from `observed_at` in UTC so session `TimeZone` cannot alter the result, uses a trusted function search path, and adds no PII or automated employment decision authority. The Foundation PostgreSQL contract also rejects a closed `recorded_to` on each time-coordinate lookup and proves UTC midnight plus non-UTC session `TimeZone` boundaries. - Bitemporal tenant-scoped organization hierarchy validation that rejects visible indirect parent cycles and reuses single-valued recorded-time reconstruction before graph traversal. - Stacked governed job-analysis evidence contract via `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `TaskKSAOLink`, `FunctionalJobAnalysisProfile`, and `EvidenceSource`: tenant/Job-scoped observable tasks, explicit Task-to-KSAO linkage, importance/difficulty/proficiency ratings, source/version/retrieval/SHA-256 provenance, deterministic canonical snapshot bytes, current O*NET evidence support, and historical DOT Data/People/Things compatibility. Validated snapshots require accountable human review and complete non-LLM evidence; LLM-origin material remains `analysis_draft`, and the snapshot is evidence input rather than a hiring, promotion, termination, compensation, or other high-impact employment decision. -- Stacked governed audit/outbox slice via `AuditOutboxEvent`, `audit_event_record`, `outbox_delivery_record`, and `outbox_delivery_escalation_record`: CloudEvents 1.0-compatible PII-minimized metadata, exact canonical JSON bytes, database-verified SHA-256 digests, mandatory human confirmation for high-impact events, immutable audit evidence, tenant RLS, atomic audit/outbox insertion, guarded pending/leased/delivered/dead-lettered delivery state, tenant-safe `claim_outbox_delivery(...)` with deterministic due-work ordering, `FOR UPDATE ... SKIP LOCKED`, opaque worker identity, bounded future leases, immutable envelope return, and atomic takeover of genuinely expired leases only while retry attempts remain; owner-bound `complete_outbox_delivery(...)` and `retry_outbox_delivery(...)`; database-budget-governed `dead_letter_outbox_delivery(...)`; and a separately privileged `operator_dead_letter_expired_outbox_delivery(...)` recovery path for an exhausted final lease whose recorded worker identity is permanently unavailable. `maximum_attempt_count` is persisted on the delivery row, defaults to 5, is constrained to 1 through 100, and cannot be lowered by a dispatcher during finalization. Migration 0007 prevents retry or expired-lease takeover from creating attempt N+1; migration 0008 adds TRUNCATE guards, trusted function search paths, a concurrently built due-work partial index, session-independent immutable envelope validation, and operator recovery backed by separate NOLOGIN/NOBYPASSRLS owner/capability roles so the externally assignable operator role can invoke recovery without receiving direct transport-table read/write rights. Migration 0008 also rejects pre-existing reserved recovery-role names before project DDL, atomically contains the temporary schema-creation privilege used for function ownership handoff, and forces deferred escalation binding while the narrow SECURITY DEFINER owner is still active. Exponential/backoff policy selection, policy-specific producer configuration, and external delivery receipts remain subsequent work. +- Governed audit/outbox slice on protected `develop` via `AuditOutboxEvent`, `audit_event_record`, `outbox_delivery_record`, and `outbox_delivery_escalation_record`: CloudEvents 1.0-compatible PII-minimized metadata, exact canonical JSON bytes, database-verified SHA-256 digests, mandatory human confirmation for high-impact events, immutable audit evidence, tenant RLS, atomic audit/outbox insertion, guarded pending/leased/delivered/dead-lettered delivery state, tenant-safe `claim_outbox_delivery(...)` with deterministic due-work ordering, `FOR UPDATE ... SKIP LOCKED`, opaque worker identity, bounded future leases, immutable envelope return, and atomic takeover of genuinely expired leases only while retry attempts remain; owner-bound `complete_outbox_delivery(...)` and `retry_outbox_delivery(...)`; database-budget-governed `dead_letter_outbox_delivery(...)`; and a separately privileged `operator_dead_letter_expired_outbox_delivery(...)` recovery path for an exhausted final lease whose recorded worker identity is permanently unavailable. `maximum_attempt_count` is persisted on the delivery row, defaults to 5, is constrained to 1 through 100, and cannot be lowered by a dispatcher during finalization. Migration 0007 prevents retry or expired-lease takeover from creating attempt N+1; migration 0008 adds TRUNCATE guards, trusted function search paths, a concurrently built due-work partial index, session-independent immutable envelope validation, and operator recovery backed by separate NOLOGIN/NOBYPASSRLS owner/capability roles so the externally assignable operator role can invoke recovery without receiving direct transport-table read/write rights. Migration 0008 also rejects pre-existing reserved recovery-role names before project DDL, atomically contains the temporary schema-creation privilege used for function ownership handoff, and forces deferred escalation binding while the narrow SECURITY DEFINER owner is still active. Exponential/backoff policy selection, policy-specific producer configuration, and external delivery receipts remain subsequent work. - `orgmetra_hris_kernel` 0.4.0 with exclusive-versus-concurrent employment, staffable position coverage, exclusive-seat capacity, and `validate_assignment_write` at 100% statement and branch coverage. - `POST /v1/employment-records`, `POST /v1/position-records`, and `POST /v1/assignment-records` with the same Keyverse mutation context, confirmation, and versioned evidence composition as other high-impact commands. - `employment_record_version.employment_concurrency_code` constrained to `exclusive` or `concurrent`. diff --git a/manifest.json b/manifest.json index c4542f1d6..7239a939b 100644 --- a/manifest.json +++ b/manifest.json @@ -35,8 +35,8 @@ }, { "path": "CHANGELOG.md", - "sha256": "32cc4ef78d1eca557fa01731026840be01211a043eb0ada552e4e6cb9eace353", - "bytes": 17295, + "sha256": "1d6098c49026a7ff8da9735f20550125d7d14b5b3c67fe18841602dfe82301b5", + "bytes": 17310, "lines": 76 }, { From 8fc6d8106abcc3fa413587c76119890a7f82ac60 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:37:58 +0900 Subject: [PATCH 045/201] docs: refresh gateway remediation head --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 08111fa2a..1298cac07 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -57,8 +57,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `7d249234c970ab6f10a08ef88398383190996ba2`, currently still open with exact-head hosted checks incomplete and no qualifying independent approval. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `7d249234c970ab6f10a08ef88398383190996ba2`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `dc03010bfc7034cd13c8508aea362169274daf8c`, currently still open with exact-head hosted checks incomplete and no qualifying independent approval. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `dc03010bfc7034cd13c8508aea362169274daf8c`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 9e54ed02a3300480a2c437003e91e87ca38f50fa Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:56:21 +0900 Subject: [PATCH 046/201] docs: refresh central remediation ownership --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1298cac07..22e870801 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -57,8 +57,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; the active central remediation is `.github#1369` at exact head `dc03010bfc7034cd13c8508aea362169274daf8c`, currently still open with exact-head hosted checks incomplete and no qualifying independent approval. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. The active gateway remediation is `.github#1369` at exact head `dc03010bfc7034cd13c8508aea362169274daf8c`; its central Checks are not transferable proof for Orgmetra leaf PRs, and it remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; central remediation `.github#1369` merged into protected `main` at exact merge commit `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09`. Follow-up `.github#1378` is open at exact head `bc9325e1a3f18477adf7ae2925bc88345a46a42a`, based on `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09`, with hosted checks incomplete and no qualifying independent approval. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` merged into protected `main` at exact merge commit `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09`; follow-up `.github#1378` is at exact head `bc9325e1a3f18477adf7ae2925bc88345a46a42a` with its hosted checks still incomplete and no qualifying independent approval. These central Checks are not transferable proof for Orgmetra leaf PRs, and every follow-up remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 0ccdb29ee99150ab152561c21a79404b47cd4739 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 15:03:05 +0900 Subject: [PATCH 047/201] docs: record central gateway follow-up merge --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 22e870801..87c429dd3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -57,8 +57,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; central remediation `.github#1369` merged into protected `main` at exact merge commit `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09`. Follow-up `.github#1378` is open at exact head `bc9325e1a3f18477adf7ae2925bc88345a46a42a`, based on `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09`, with hosted checks incomplete and no qualifying independent approval. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` merged into protected `main` at exact merge commit `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09`; follow-up `.github#1378` is at exact head `bc9325e1a3f18477adf7ae2925bc88345a46a42a` with its hosted checks still incomplete and no qualifying independent approval. These central Checks are not transferable proof for Orgmetra leaf PRs, and every follow-up remains protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; central remediation `.github#1369` merged into protected `main` at exact merge commit `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09`; follow-up `.github#1378` merged into protected `main` at exact merge commit `cb369942be4cd7783753be45552d758ebaf79870`. Current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 0e3bfc281b13877f7c35f607af013c243c1d8d1e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 16:33:53 +0900 Subject: [PATCH 048/201] docs: refresh current product gap baseline --- docs/product-technical-gap-baseline.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 87c429dd3..497362191 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -57,7 +57,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `ede293c0ff7cce6c329f8b4dfef9a4cd7fcc3dca` has Employment Employing Organization/Foundation/Recovery/Job-Analysis/SAST/Security local workflows terminal GREEN after deterministic provenance was resealed for migration `0040` and its PostgreSQL regression. Exact-head OpenCode, Noema, coverage source-tree/evidence, CodeQL, dependency/OSV/Trivy/Scorecard/Semgrep evidence is also GREEN. Required central Strix run `33133495444` / job `98729417430` is now terminal **FAILURE** on trusted central source `17052a7ca3c16db90932a4d6036b43165ddee418`: exact target/base materialization and workflow setup succeeded, but the provider chain exhausted NVIDIA primary (429), NVIDIA fallback (404), OpenRouter (`502 Invalid URL`), and direct OpenAI (`429 insufficient_quota` / `credit_balance_exhausted`) without producing an authoritative structured finding/no-finding report. Diagnostic artifact `strix-reports` id `9671596184` has SHA-256 `96c73b5f5dedb8b0bed8d4b81d622248ca5dedeba97209da680e288e208d4f06`. This is fail-closed foreign-owner evidence routed through existing `.github#1327`; central remediation `.github#1369` merged into protected `main` at exact merge commit `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09`; follow-up `.github#1378` merged into protected `main` at exact merge commit `cb369942be4cd7783753be45552d758ebaf79870`. Current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. No Orgmetra-local provider shim or gate weakening is valid. #141 is Ready-for-review active-PR truth and becomes Strix-passing only after a fresh unchanged-head required Strix terminal SUCCESS with a complete authoritative structured report. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `f7bb1e3b7d14bac5b9a77b268fa176c7230702fe` has 37 exact-head checks terminal without failure, while seven checks remain queued and required central Strix is still in progress; local People/Foundation/Employment-Organization/Recovery/Job-Analysis/SAST/Security evidence already includes terminal GREEN results, and Devin Review is terminal PASS. The exact-head review state is `REVIEW_REQUIRED` with zero unresolved threads but no qualifying independent approval, so it remains active-PR truth and is not merge-authorized. No stale predecessor check/review or provider fallback is being promoted to passing evidence; if Strix fails without an authoritative structured report, route it through `.github#1327` rather than adding a leaf shim or weakening the gate. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. @@ -69,6 +69,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `9e3f5c5b1c959bef37831e8cba8695504a18061f` has `HR Workspace Work Capacity Review State Quality` run `33121181610` / job `98688132674` terminal GREEN: exact candidate checkout, 5 focused tests, **100% line/branch/function coverage**, and clean checkout. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `cbbf975733c74413fe91310415c67a034090133d` has `HR Workspace Employment Absence State Quality` run `33125277888` / job `98701821651` terminal GREEN after a genuine contract-first RED on run `33125117860` / job `98701273064`. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. #140 exact head `260ddd27324aee5e67e09077e84a814b92d5891e` has `HR Workspace Performance Goal Review State Quality` run `33128554172` / job `98712427872` terminal GREEN after genuine contract-first RED run `33128460316` / job `98712125205`. The UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. + - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner; #143 remains Draft and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. + - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). It remains Draft and read-only; it does not evaluate, rank, reject, advance, or authorize an employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child GREEN is stack-local only. @@ -85,7 +87,7 @@ Dependency-first descendants for qualification-rule persistence, Position report Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. -1. **Integrate the accessible buyer-interaction stack and retain the unowned P1 surfaces.** The currently named workflow-specific HR Workspace interaction gaps are owned under #53 → #130 by #131/#132/#134/#135/#136/#137/#138/#139/#140. Separately, the PRD still names the Job Architecture workspace, Candidate Evidence workspace, hiring decision record, Employee Profile with bitemporal assignment history, and Validation dashboard shell; the wireframe baseline also names HR Home, Job Architecture, Recruiting Workspace, Employee Profile, Validate, and Admin & Integrations. No UI/Storybook implementation or owner PR is currently proven for those buyer surfaces, so they remain unowned planned gaps rather than shipped truth. The commercial risk is dependency-first integration: land #53 and #130 first, then retarget/revalidate each child against fresh `develop`, reconcile intervening Storybook/Figma/UI changes, and obtain browser/accessibility/Foundation/Recovery/SAST/Security plus every applicable central exact-head gate before representing any child as shipped. Do not open a competing interaction writer for an already-owned scope. +1. **Integrate the accessible buyer-interaction stack and retain the unowned P1 surfaces.** The currently named workflow-specific HR Workspace interaction gaps are owned under #53 → #130 by #131/#132/#134/#135/#136/#137/#138/#139/#140, while Employee Profile assignment history and the Candidate Evidence timeline now have the separate #142 → #143 and #144 owners. The PRD still names the Job Architecture workspace, hiring decision record, and Validation dashboard shell; the wireframe baseline also names HR Home, Job Architecture, Recruiting Workspace, Employee Profile, Validate, and Admin & Integrations. No shipped UI/Storybook integration is proven for these surfaces, so they remain active-PR or unowned planned gaps rather than protected-main truth. The commercial risk is dependency-first integration: land #53 and #130 first, then retarget/revalidate each child against fresh `develop`, reconcile intervening Storybook/Figma/UI changes, and obtain browser/accessibility/Foundation/Recovery/SAST/Security plus every applicable central exact-head gate before representing any child as shipped. Do not open a competing interaction writer for an already-owned scope. 2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A parallel release writer would be duplicative and unsafe. 3. **Integration closure is itself a buyer risk until dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. From 7e45b45cb0eb28f241b5b2f00dd4ea50c89a4582 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 17:26:18 +0900 Subject: [PATCH 049/201] docs: refresh candidate withdrawal and employment heads --- docs/product-technical-gap-baseline.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 497362191..cbb48b568 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -57,7 +57,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** owns the active authoritative bitemporal **Employment → employing legal Organization** relationship independently of Position and Assignment. Current exact head `f7bb1e3b7d14bac5b9a77b268fa176c7230702fe` has 37 exact-head checks terminal without failure, while seven checks remain queued and required central Strix is still in progress; local People/Foundation/Employment-Organization/Recovery/Job-Analysis/SAST/Security evidence already includes terminal GREEN results, and Devin Review is terminal PASS. The exact-head review state is `REVIEW_REQUIRED` with zero unresolved threads but no qualifying independent approval, so it remains active-PR truth and is not merge-authorized. No stale predecessor check/review or provider fallback is being promoted to passing evidence; if Strix fails without an authoritative structured report, route it through `.github#1327` rather than adding a leaf shim or weakening the gate. Do not create a competing employer-scope relationship writer or treat this relation as payroll/statutory-account authority. +- **PR #141** now has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. The current exact-head hosted suite remains queued/in progress across coverage, security, PostgreSQL restore/integrity, SAST, Noema, Strix, and feature-quality checks; CodeRabbit is successful, all current review threads are resolved, and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. +- **PR #67** now has exact current head `5ab94166823ee8f5a0344f846250602d00b70724`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; its exact-head PostgreSQL workflow is still in progress, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. From 62c721a5dfedc7572a91d581655ad8cb311bcbb2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 17:45:00 +0900 Subject: [PATCH 050/201] docs: record candidate withdrawal gate state --- docs/product-technical-gap-baseline.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index cbb48b568..2de52ef3d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -58,7 +58,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **PR #141** now has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. The current exact-head hosted suite remains queued/in progress across coverage, security, PostgreSQL restore/integrity, SAST, Noema, Strix, and feature-quality checks; CodeRabbit is successful, all current review threads are resolved, and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. -- **PR #67** now has exact current head `5ab94166823ee8f5a0344f846250602d00b70724`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; its exact-head PostgreSQL workflow is still in progress, and no qualifying independent approval exists. +- **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN, but exact-head `opencode-review` and `strix` are terminal FAILURE; three informational Devin threads remain unresolved and no qualifying independent approval exists. Its source is active-PR truth only. +- **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. From 50344077943af8950a4274628b1c96f96a9cb425 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 17:46:53 +0900 Subject: [PATCH 051/201] docs: record resolved parent review threads --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2de52ef3d..8d314bc94 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -58,7 +58,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **PR #141** now has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. The current exact-head hosted suite remains queued/in progress across coverage, security, PostgreSQL restore/integrity, SAST, Noema, Strix, and feature-quality checks; CodeRabbit is successful, all current review threads are resolved, and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. -- **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN, but exact-head `opencode-review` and `strix` are terminal FAILURE; three informational Devin threads remain unresolved and no qualifying independent approval exists. Its source is active-PR truth only. +- **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN, but exact-head `opencode-review` and `strix` are terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From 7578cf2c119daa37881e4a11b2a39358b4980883 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 17:51:40 +0900 Subject: [PATCH 052/201] docs: refresh terminal gate evidence --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8d314bc94..971dd9351 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -57,8 +57,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** now has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. The current exact-head hosted suite remains queued/in progress across coverage, security, PostgreSQL restore/integrity, SAST, Noema, Strix, and feature-quality checks; CodeRabbit is successful, all current review threads are resolved, and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. -- **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN, but exact-head `opencode-review` and `strix` are terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. +- **PR #141** has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful checks, 8 skipped checks, and 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. +- **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, while the previous `strix` attempt is terminal FAILURE after contextual-orchestrator backend HTTP 500 responses and a bounded failed-job rerun is pending. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From 878180c511bee3b26a769fcc32f7118f1b397bcf Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 17:53:00 +0900 Subject: [PATCH 053/201] docs: record cancelled Strix retry --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 971dd9351..93366c89d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -58,7 +58,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **PR #141** has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful checks, 8 skipped checks, and 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. -- **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, while the previous `strix` attempt is terminal FAILURE after contextual-orchestrator backend HTTP 500 responses and a bounded failed-job rerun is pending. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. +- **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, while the previous `strix` attempt is terminal FAILURE after contextual-orchestrator backend HTTP 500 responses and its failed-job rerun was cancelled before a runner job started. No authoritative Strix evidence was produced. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From b44f1edd4f9225b8b45056c377acbfe5e375e45a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 18:15:38 +0900 Subject: [PATCH 054/201] docs: record leave and compensation review heads --- docs/product-technical-gap-baseline.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 93366c89d..bd99ccd70 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -56,6 +56,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. +- **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #48** is active at exact head `dc3fa7ec81e6e2e6bc433d6cb39573fd8e185ff0` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set still has terminal `opencode-review` **FAILURE** plus an in-progress `strix`, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **PR #141** has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful checks, 8 skipped checks, and 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, while the previous `strix` attempt is terminal FAILURE after contextual-orchestrator backend HTTP 500 responses and its failed-job rerun was cancelled before a runner job started. No authoritative Strix evidence was produced. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. From c2bee36840876a21c8695c9b54572347c39f2949 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 18:24:00 +0900 Subject: [PATCH 055/201] docs: record compensation strix blocker --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index bd99ccd70..cd98ba6b8 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -57,7 +57,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #48** is active at exact head `dc3fa7ec81e6e2e6bc433d6cb39573fd8e185ff0` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set still has terminal `opencode-review` **FAILURE** plus an in-progress `strix`, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. +- **PR #48** is active at exact head `dc3fa7ec81e6e2e6bc433d6cb39573fd8e185ff0` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **PR #141** has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful checks, 8 skipped checks, and 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, while the previous `strix` attempt is terminal FAILURE after contextual-orchestrator backend HTTP 500 responses and its failed-job rerun was cancelled before a runner job started. No authoritative Strix evidence was produced. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. From 6908cac58240c7ec7d7804afb2e264c9cad497e0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 20:58:19 +0900 Subject: [PATCH 056/201] chore: keep manifest compact --- manifest.json | 482 +------------------------------------------------- 1 file changed, 1 insertion(+), 481 deletions(-) diff --git a/manifest.json b/manifest.json index 7239a939b..12ee769ad 100644 --- a/manifest.json +++ b/manifest.json @@ -1,481 +1 @@ -{ - "package": "orgmetra-foundation-pack", - "version": "0.1.0", - "generated_for_branch": "feat/audit-outbox-envelope", - "files": [ - { - "path": ".github/workflows/foundation-ci.yml", - "sha256": "12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537", - "bytes": 4379, - "lines": 123 - }, - { - "path": ".github/workflows/job-analysis-api-quality.yml", - "sha256": "352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a", - "bytes": 4159, - "lines": 105 - }, - { - "path": ".gitignore", - "sha256": "145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21", - "bytes": 375, - "lines": 37 - }, - { - "path": "AGENTS.md", - "sha256": "28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16", - "bytes": 2246, - "lines": 34 - }, - { - "path": "ARCHITECTURE.md", - "sha256": "52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850", - "bytes": 7864, - "lines": 107 - }, - { - "path": "CHANGELOG.md", - "sha256": "1d6098c49026a7ff8da9735f20550125d7d14b5b3c67fe18841602dfe82301b5", - "bytes": 17310, - "lines": 76 - }, - { - "path": "CLAUDE.md", - "sha256": "add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f", - "bytes": 1229, - "lines": 20 - }, - { - "path": "LICENSE", - "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", - "bytes": 11358, - "lines": 202 - }, - { - "path": "NOTICE", - "sha256": "34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042", - "bytes": 305, - "lines": 4 - }, - { - "path": "README.md", - "sha256": "c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e", - "bytes": 3889, - "lines": 81 - }, - { - "path": "database/migrations/0001_foundation_schema.sql", - "sha256": "ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd", - "bytes": 38747, - "lines": 916 - }, - { - "path": "database/migrations/0002_sealed_evidence_digest.sql", - "sha256": "93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c", - "bytes": 6649, - "lines": 202 - }, - { - "path": "database/migrations/0003_audit_outbox_persistence.sql", - "sha256": "2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc", - "bytes": 15417, - "lines": 423 - }, - { - "path": "database/migrations/0004_outbox_delivery_claim.sql", - "sha256": "d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef", - "bytes": 9451, - "lines": 234 - }, - { - "path": "database/migrations/0005_outbox_delivery_finalization.sql", - "sha256": "b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961", - "bytes": 6125, - "lines": 170 - }, - { - "path": "database/migrations/0006_outbox_delivery_dead_letter.sql", - "sha256": "c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7", - "bytes": 24919, - "lines": 628 - }, - { - "path": "database/migrations/0007_outbox_retry_exhaustion.sql", - "sha256": "812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5", - "bytes": 19081, - "lines": 476 - }, - { - "path": "database/migrations/0008_audit_outbox_review_hardening.sql", - "sha256": "c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b", - "bytes": 17562, - "lines": 448 - }, - { - "path": "database/migrations/0009_candidate_worker_conversion_governance.sql", - "sha256": "4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9", - "bytes": 11537, - "lines": 281 - }, - { - "path": "database/migrations/0010_validity_study_case_integrity.sql", - "sha256": "3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1", - "bytes": 11979, - "lines": 313 - }, - { - "path": "database/migrations/0011_criterion_observation_scope.sql", - "sha256": "f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9", - "bytes": 7444, - "lines": 165 - }, - { - "path": "database/migrations/0012_people_mutation_idempotency.sql", - "sha256": "52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69", - "bytes": 3162, - "lines": 76 - }, - { - "path": "database/migrations/0013_job_analysis_snapshot.sql", - "sha256": "b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee", - "bytes": 12713, - "lines": 260 - }, - { - "path": "docs/API_CONTRACT.md", - "sha256": "63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589", - "bytes": 4555, - "lines": 76 - }, - { - "path": "docs/DATA_MODEL.md", - "sha256": "6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a", - "bytes": 13366, - "lines": 85 - }, - { - "path": "docs/ERD.md", - "sha256": "546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe", - "bytes": 6964, - "lines": 70 - }, - { - "path": "docs/OPERABILITY.md", - "sha256": "82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62", - "bytes": 11189, - "lines": 71 - }, - { - "path": "docs/PRD.md", - "sha256": "3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1", - "bytes": 5490, - "lines": 111 - }, - { - "path": "docs/SECURITY.md", - "sha256": "01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac", - "bytes": 11185, - "lines": 64 - }, - { - "path": "docs/STORYBOARD.md", - "sha256": "6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2", - "bytes": 1342, - "lines": 28 - }, - { - "path": "docs/STORYBOOK.md", - "sha256": "82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9", - "bytes": 1389, - "lines": 50 - }, - { - "path": "docs/TEST_STRATEGY.md", - "sha256": "d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8", - "bytes": 16534, - "lines": 135 - }, - { - "path": "docs/THREAT_MODEL.md", - "sha256": "f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252", - "bytes": 6736, - "lines": 23 - }, - { - "path": "docs/TRACEABILITY.md", - "sha256": "b5e6496ce1e990caccc8d12f5f7635ba9b9f9984d3f5f40138db3c16f301411a", - "bytes": 11489, - "lines": 40 - }, - { - "path": "docs/TRD.md", - "sha256": "23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077", - "bytes": 9064, - "lines": 101 - }, - { - "path": "docs/UML.md", - "sha256": "fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9", - "bytes": 5528, - "lines": 122 - }, - { - "path": "docs/USER_STORIES.md", - "sha256": "5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f", - "bytes": 2670, - "lines": 37 - }, - { - "path": "docs/WIREFRAMES.md", - "sha256": "b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e", - "bytes": 2005, - "lines": 77 - }, - { - "path": "docs/adr/0001-orgmetra-authoritative-hris-record.md", - "sha256": "0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572", - "bytes": 6108, - "lines": 53 - }, - { - "path": "docs/adr/0002-federated-cwl-integration-boundaries.md", - "sha256": "b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2", - "bytes": 4072, - "lines": 44 - }, - { - "path": "docs/adr/0003-bitemporal-hris-data-contract.md", - "sha256": "d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799", - "bytes": 4453, - "lines": 47 - }, - { - "path": "docs/adr/0004-employment-position-version-and-assignment-binding.md", - "sha256": "fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182", - "bytes": 1872, - "lines": 30 - }, - { - "path": "docs/adr/0005-exclusive-employment-and-staffable-seats.md", - "sha256": "10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b", - "bytes": 2091, - "lines": 34 - }, - { - "path": "docs/adr/0006-governed-audit-outbox-envelope.md", - "sha256": "987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9", - "bytes": 14046, - "lines": 66 - }, - { - "path": "docs/adr/0007-governed-job-analysis-evidence.md", - "sha256": "0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5", - "bytes": 5643, - "lines": 57 - }, - { - "path": "docs/adr/0008-purpose-bound-pii-authorization.md", - "sha256": "c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7", - "bytes": 5988, - "lines": 55 - }, - { - "path": "docs/adr/0009-performance-criterion-observation-scope.md", - "sha256": "5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e", - "bytes": 7080, - "lines": 57 - }, - { - "path": "docs/adr/0010-naruon-calendar-intent-boundary.md", - "sha256": "ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e", - "bytes": 3835, - "lines": 35 - }, - { - "path": "docs/adr/0011-bitemporal-workforce-composition.md", - "sha256": "1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103", - "bytes": 5482, - "lines": 53 - }, - { - "path": "docs/adr/0012-governed-migration-handoff.md", - "sha256": "cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc", - "bytes": 5887, - "lines": 59 - }, - { - "path": "docs/adr/0013-governed-requisition-review-packet.md", - "sha256": "2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48", - "bytes": 4704, - "lines": 46 - }, - { - "path": "docs/adr/0014-job-analysis-snapshot-persistence.md", - "sha256": "d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d", - "bytes": 5356, - "lines": 49 - }, - { - "path": "docs/adr/README.md", - "sha256": "f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af", - "bytes": 2028, - "lines": 20 - }, - { - "path": "docs/doctoring/REFERENCES.md", - "sha256": "929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5", - "bytes": 6352, - "lines": 69 - }, - { - "path": "docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md", - "sha256": "b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd", - "bytes": 8227, - "lines": 226 - }, - { - "path": "docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md", - "sha256": "4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d", - "bytes": 6237, - "lines": 187 - }, - { - "path": "package.json", - "sha256": "59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5", - "bytes": 388, - "lines": 9 - }, - { - "path": "packages/hris-kernel/src/orgmetra_hris_kernel/audit.py", - "sha256": "3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190", - "bytes": 7707, - "lines": 160 - }, - { - "path": "packages/hris-kernel/tests/test_audit_outbox.py", - "sha256": "5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c", - "bytes": 7556, - "lines": 200 - }, - { - "path": "schemas/openapi.yaml", - "sha256": "09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f", - "bytes": 29503, - "lines": 1020 - }, - { - "path": "scripts/foundation-contract-core.mjs", - "sha256": "595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445", - "bytes": 28173, - "lines": 689 - }, - { - "path": "scripts/foundation-contract.mjs", - "sha256": "5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a", - "bytes": 218, - "lines": 6 - }, - { - "path": "tests/dispatcher-inventory.test.mjs", - "sha256": "09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261", - "bytes": 1597, - "lines": 34 - }, - { - "path": "tests/foundation-contract.test.mjs", - "sha256": "960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615", - "bytes": 14860, - "lines": 386 - }, - { - "path": "tests/openapi-contract.test.mjs", - "sha256": "80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc", - "bytes": 6438, - "lines": 195 - }, - { - "path": "tests/test_audit_outbox_hardening_postgres.sh", - "sha256": "518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0", - "bytes": 13396, - "lines": 333 - }, - { - "path": "tests/test_audit_outbox_postgres.sh", - "sha256": "e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2", - "bytes": 13443, - "lines": 357 - }, - { - "path": "tests/test_bitemporal_postgres.sh", - "sha256": "7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc", - "bytes": 8209, - "lines": 230 - }, - { - "path": "tests/test_candidate_worker_conversion_postgres.sh", - "sha256": "681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90", - "bytes": 14673, - "lines": 344 - }, - { - "path": "tests/test_criterion_observation_scope_postgres.sh", - "sha256": "0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d", - "bytes": 17811, - "lines": 469 - }, - { - "path": "tests/test_evidence_sealing_postgres.sh", - "sha256": "57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7", - "bytes": 11349, - "lines": 370 - }, - { - "path": "tests/test_job_analysis_snapshot_postgres.sh", - "sha256": "ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f", - "bytes": 13542, - "lines": 296 - }, - { - "path": "tests/test_operational_uuid_postgres.sh", - "sha256": "7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7", - "bytes": 3346, - "lines": 101 - }, - { - "path": "tests/test_outbox_claim_postgres.sh", - "sha256": "1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b", - "bytes": 14817, - "lines": 429 - }, - { - "path": "tests/test_outbox_dead_letter_postgres.sh", - "sha256": "0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d", - "bytes": 14008, - "lines": 377 - }, - { - "path": "tests/test_people_mutation_idempotency_postgres.sh", - "sha256": "3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5", - "bytes": 16191, - "lines": 381 - }, - { - "path": "tests/test_tenant_isolation_postgres.sh", - "sha256": "dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a", - "bytes": 15134, - "lines": 388 - }, - { - "path": "tests/test_validity_study_case_postgres.sh", - "sha256": "0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02", - "bytes": 14708, - "lines": 301 - }, - { - "path": "tests/validate_repository.py", - "sha256": "918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9", - "bytes": 27291, - "lines": 638 - } - ] -} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"1d6098c49026a7ff8da9735f20550125d7d14b5b3c67fe18841602dfe82301b5","bytes":17310,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"b5e6496ce1e990caccc8d12f5f7635ba9b9f9984d3f5f40138db3c16f301411a","bytes":11489,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From 5591bea9d4947840846dca76dc1ae53d85b16f4a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 22:52:18 +0900 Subject: [PATCH 057/201] docs: separate Naruon intent from provider execution --- docs/TRACEABILITY.md | 2 +- manifest.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/TRACEABILITY.md b/docs/TRACEABILITY.md index 005638ba9..3e4ea8f6b 100644 --- a/docs/TRACEABILITY.md +++ b/docs/TRACEABILITY.md @@ -31,7 +31,7 @@ | External contract | Orgmetra owner boundary | Integration style | Required evidence | ADR | Maturity | |---|---|---|---|---|---| | Keyverse identity and authorization | API Gateway / purpose-bound authorization | Published OIDC/API identity and scope contract plus Orgmetra-owned `orgmetra_keyverse_adapter` policy evaluation | tenant/actor/resource agreement, exact opaque target-resource reference, purpose, operation-specific scope, requested-field minimization, opaque subject, no stored credentials or protected values in authorization evidence | ADR-0002, ADR-0008 | implemented_on_protected_main | -| naruon communication and calendar | Integration Hub | Published API/event adapter | idempotency, delivery audit, no direct table access | ADR-0002 | implemented_on_protected_main | +| Naruon calendar intent | Integration Hub | Published `/api/calendar/writeback-intent` intent adapter; provider execution remains Naruon-owned and out of this slice | purpose-bound human confirmation, exact contract/provenance validation, intent-only audit correlation, no provider execution or direct table access | ADR-0002, ADR-0010 | implemented_on_protected_main | | Psychometrics Commons @ `cc5850a0d1eacbbf16d03075534fce460a8286e6` | Workforce Validation | Immutable response/result snapshot contract | pinned revision, model/version/provenance snapshot, immutable result linkage, no direct application-table access | ADR-0002 | accepted_architecture | | fast-mlsirm @ `fb67ced09d8ee00542c05d56374537a9a7239751` | Workforce Validation | Published `orgmetra.fast_mlsirm.v1` result contract; direct calls only from approved offline validation worker | pinned revision, contract identifier, backend/result provenance, CPU/GPU parity evidence where material, no duplicated kernel | ADR-0002 | accepted_architecture | | TEPP temporal evidence | Workforce Validation | Published package/API contract | temporal provenance and version binding | ADR-0002 | planned | diff --git a/manifest.json b/manifest.json index 12ee769ad..f8c566bd6 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"1d6098c49026a7ff8da9735f20550125d7d14b5b3c67fe18841602dfe82301b5","bytes":17310,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"b5e6496ce1e990caccc8d12f5f7635ba9b9f9984d3f5f40138db3c16f301411a","bytes":11489,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"1d6098c49026a7ff8da9735f20550125d7d14b5b3c67fe18841602dfe82301b5","bytes":17310,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"5bbf8e87bf5ca9ae6935988c50156ec29e48aaf69f6a86e5e5987f4bc7f7a023","bytes":11677,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From 8e4d831ae87b7ce4ea17a92958738411988fb632 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 04:13:32 +0900 Subject: [PATCH 058/201] docs: refresh product gap baseline and shipped traceability --- docs/TRACEABILITY.md | 10 ++++++---- docs/product-technical-gap-baseline.md | 20 +++++++++++--------- manifest.json | 2 +- 3 files changed, 18 insertions(+), 14 deletions(-) diff --git a/docs/TRACEABILITY.md b/docs/TRACEABILITY.md index 3e4ea8f6b..a61b35f4b 100644 --- a/docs/TRACEABILITY.md +++ b/docs/TRACEABILITY.md @@ -11,15 +11,17 @@ | Normalized bitemporal organization/job/employment/position history | Core bounded contexts | `organization_unit_version`, `job_profile_version`, `employment_record_version`, `position_record_version` | PostgreSQL non-overlap, concurrent conflict, correction, rewrite-rejection, assignment-employment binding, and single-valued historical reconstruction | ADR-0001, ADR-0003, ADR-0004 | implemented_on_active_pr | | Acyclic organization hierarchy at historical coordinates | Organization core | `organization_unit_version.parent_organization_unit_id` | indirect A→B→C→A rejection plus future-recorded and foreign-tenant isolation in `orgmetra_hris_kernel` | ADR-0001, ADR-0003 | implemented_on_protected_main | | Effective/system time | Bitemporal HRIS | `effective_from`, `recorded_from` | strict half-open interval and historical-coordinate tests | ADR-0003 | implemented_on_active_pr | -| Evidence-backed human selection decisions | Talent Acquisition | `decision_evidence_set`, `selection_decision_evidence`, `selection_decision` | database-owned SHA-256 sealing, non-empty evidence, drift/reuse rejection, OpenAPI human-confirmation tests | ADR-0001 | implemented_on_active_pr | +| Evidence-backed human selection decisions | Talent Acquisition | `decision_evidence_set`, `selection_decision_evidence`, `selection_decision` | database-owned SHA-256 sealing, non-empty evidence, drift/reuse rejection, OpenAPI human-confirmation tests | ADR-0001 | implemented_on_protected_main | | Governed candidate-to-worker conversion | Talent Acquisition / People core | `candidate_worker_conversion_record` with candidate, person, employment, selection decision, audit event and outbox evidence | PostgreSQL exact hire/evidence/audit-envelope binding, correction provenance, tenant RLS, legacy-write rejection and bitemporal history contract | ADR-0001, ADR-0003, ADR-0006 | implemented_on_protected_main | | GET-only People API | People API / purpose-bound read boundary | `GET /v1/tenants/{tenant_record_id}/people/{person_record_id}`, `read_worker_people_record()`, `PostgresPeopleReadPort` | People API HTTP and PostgreSQL read contracts with exact 100% owned statement/branch coverage; current conversion lineage; no mutation writes | ADR-0002, ADR-0008 | implemented_on_protected_main | | Governed People writes and confirmed-hire materialization | People API / purpose-bound mutation boundary | `POST /v1/employment-records`, `POST /v1/position-records`, `POST /v1/assignment-records`, `POST /v1/tenants/{tenant_record_id}/candidate-worker-conversions`, `people_mutation_idempotency_record` | People command/HTTP/PostgreSQL contracts with exact owned statement/branch coverage plus PostgreSQL tenant-RLS, atomic audit/outbox/idempotency, identical-retry replay, changed-command rejection, rollback, and concurrent-key regression | ADR-0002, ADR-0006, ADR-0008 | implemented_on_protected_main | | Evidence-grounded Job analysis with governed Task/FJA/KSAO persistence | Job Analysis / Workforce Validation | `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `FunctionalJobAnalysisProfile`, `TaskKSAOLink`, `EvidenceSource`, `job_analysis_snapshot`, `job_analysis_task_item`, `job_analysis_ksao_item`, `job_analysis_task_ksao_link`, `job_analysis_write_command`, `POST /v1/tenants/{tenant_record_id}/job-analysis-snapshots`, `GET /v1/tenants/{tenant_record_id}/job-analysis-snapshots/{analysis_record_id}` | domain tenant/Job isolation, source/version/digest provenance, task-KSAO completeness, deterministic canonicalization, accountable human-review and LLM-draft-only regressions; migration 0013 PostgreSQL parent-scope/RLS/append-only/idempotency/audit-outbox persistence; exact route/OpenAPI/error contracts and 100% owned service statement/branch coverage | ADR-0007, ADR-0014 | implemented_on_protected_main | +| Governed candidate evidence intake | Talent Acquisition | `CandidateEvidenceIntakePacket` and `docs/traceability/candidate-evidence-intake.md` | Candidate Evidence Quality contract tests for tenant scope, opaque references, evidence versioning, redacted representation, human review, and exact 100% coverage | ADR-0025 | implemented_on_protected_main | +| Governed offer approval evidence | Talent Acquisition | `OfferApprovalPacket` and `docs/traceability/offer-approval.md` | Offer Approval Quality contract tests for tenant identity, opaque references, actor separation, evidence versioning, human approval, and delivery denial | ADR-0017 | implemented_on_protected_main | | Job-, cycle-, and staffing-scoped performance criterion observations | Performance / Workforce Validation | `criterion_observation`, `criterion_blueprint`, `performance_cycle`, `assignment_record`, `employment_record_version`, `position_record`, `position_record_version` | PostgreSQL wrong-Job, pre-assignment, out-of-cycle, frozen-Position, terminated-employment, closed-recorded-time, and session-TimeZone/UTC-midnight rejection plus valid worker-Job/staffing acceptance | ADR-0009 | implemented_on_protected_main | -| Governed immutable audit and transactional outbox persistence | Audit Provenance / Integration Hub | `AuditOutboxEvent.canonical_json()`, `audit_event_record`, `outbox_delivery_record`, SHA-256 envelope digest | canonical-byte/digest regression plus PostgreSQL digest, allowlist/PII, high-impact confirmation, append-only, atomicity, lease-transition, terminal-state, and reserved-UUID tests | ADR-0006 | implemented_on_active_pr | -| Tenant-safe atomic outbox claiming and crash recovery | Integration Hub dispatcher boundary | `outbox_delivery_record` pending/expired-lease claim indexes plus `claim_outbox_delivery(...)` | PostgreSQL already-expired-new-lease rejection, due-order claim, live-lease exclusion, pre-exhaustion takeover with `lease_expired` evidence, retry-budget claim bound, tenant-context binding, opaque-worker validation, and bounded-lease contract | ADR-0006 | implemented_on_active_pr | -| Owner-bound outbox completion, retry, and terminal dead-letter escalation | Integration Hub dispatcher boundary | immutable `outbox_delivery_record.maximum_attempt_count`, `complete_outbox_delivery(...)`, `retry_outbox_delivery(...)`, `dead_letter_outbox_delivery(...)`, `outbox_delivery_escalation_record` | PostgreSQL foreign/stale-owner denial, dispatcher-budget-signature rejection, direct-terminal-DML rejection, stored-budget exhaustion, retry-attempt-N+1 denial, exhausted expired-lease non-reclaimability, recorded-owner terminalization, nonterminal-escalation rejection, terminal non-reclaimability, and append-only escalation evidence | ADR-0006 | implemented_on_active_pr | +| Governed immutable audit and transactional outbox persistence | Audit Provenance / Integration Hub | `AuditOutboxEvent.canonical_json()`, `audit_event_record`, `outbox_delivery_record`, SHA-256 envelope digest | canonical-byte/digest regression plus PostgreSQL digest, allowlist/PII, high-impact confirmation, append-only, atomicity, lease-transition, terminal-state, and reserved-UUID tests | ADR-0006 | implemented_on_protected_main | +| Tenant-safe atomic outbox claiming and crash recovery | Integration Hub dispatcher boundary | `outbox_delivery_record` pending/expired-lease claim indexes plus `claim_outbox_delivery(...)` | PostgreSQL already-expired-new-lease rejection, due-order claim, live-lease exclusion, pre-exhaustion takeover with `lease_expired` evidence, retry-budget claim bound, tenant-context binding, opaque-worker validation, and bounded-lease contract | ADR-0006 | implemented_on_protected_main | +| Owner-bound outbox completion, retry, and terminal dead-letter escalation | Integration Hub dispatcher boundary | immutable `outbox_delivery_record.maximum_attempt_count`, `complete_outbox_delivery(...)`, `retry_outbox_delivery(...)`, `dead_letter_outbox_delivery(...)`, `outbox_delivery_escalation_record` | PostgreSQL foreign/stale-owner denial, dispatcher-budget-signature rejection, direct-terminal-DML rejection, stored-budget exhaustion, retry-attempt-N+1 denial, exhausted expired-lease non-reclaimability, recorded-owner terminalization, nonterminal-escalation rejection, terminal non-reclaimability, and append-only escalation evidence | ADR-0006 | implemented_on_protected_main | | Predictive-validity case integrity | Workforce Validation | `validity_study`, normalized `validity_study_case_record`, exact `selection_decision`, sealed `decision_evidence_set`, governed `candidate_worker_conversion_record`, `criterion_observation` | `test_validity_study_case_postgres.sh`: legacy loose-link write rejection; exact evidence-set ID, Job, criterion and worker mismatch rejection; study/observation system-recorded visibility boundaries; governed upstream decision/evidence/conversion lineage from the evidence-sealing and candidate-worker conversion contracts; UPDATE/DELETE/TRUNCATE protection; missing/foreign-tenant RLS denial. Statistical estimation remains subsequent work. | ADR-0001, SIOP Principles 5th ed., 29 C.F.R. Part 1607 | implemented_on_protected_main | | Purpose-bound PII access | Security architecture / Keyverse adapter boundary | `PurposeBoundAccessPolicy`, `PurposeBoundAccessRequest.resource_reference`, `AuthorizationDecision.resource_reference` | exact tenant/actor/resource binding, exact opaque target correlation for allow/deny audit evidence, resource/purpose/operation matching, operation-specific scope, field-subset minimization, malformed-attribute rejection, reserved-UUID rejection, PII-minimized denial evidence, and exact 100% owned statement/branch coverage | ADR-0008 | implemented_on_protected_main | | Least-privilege API capability | Keyverse gateway boundary | operation scope conceptual | structural per-operation scope and confused-deputy contract tests | ADR-0002 | implemented_on_active_pr | diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index cd98ba6b8..29b8f2dd3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,8 @@ # Product and technical gap baseline -Inventory date: 2026-08-28 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Inventory date: 2026-08-29 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. + +At this snapshot, 100 pull requests and one non-PR issue (#89) are open; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -8,7 +10,7 @@ Orgmetra owns authoritative HRIS/HCM truth only inside its published boundaries. ## Effective repository-control truth -The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-28 show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. +The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-29 show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. The **current live ruleset is weaker than Orgmetra's acquisition-grade acceptance policy**: @@ -51,7 +53,7 @@ This is a selected shipped inventory, not a replacement for Git history. Do not ## Fresh active-owner truth -The following material owner lanes were freshly rechecked during the 2026-08-28 maintenance loop. +The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. - **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. @@ -59,7 +61,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #48** is active at exact head `dc3fa7ec81e6e2e6bc433d6cb39573fd8e185ff0` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** has exact current head `93b10659346e5b6628f0510837d0df80928867ed` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful checks, 8 skipped checks, and 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. +- **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 46 passing/skipped checks and 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, while the previous `strix` attempt is terminal FAILURE after contextual-orchestrator backend HTTP 500 responses and its failed-job rerun was cancelled before a runner job started. No authoritative Strix evidence was produced. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. @@ -69,10 +71,10 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. - - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. #137 exact head `b34e82fe36530525b4cbcb38e439f94b90d8cc89` has focused exact 100% line/branch/function GREEN. - - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `9e3f5c5b1c959bef37831e8cba8695504a18061f` has `HR Workspace Work Capacity Review State Quality` run `33121181610` / job `98688132674` terminal GREEN: exact candidate checkout, 5 focused tests, **100% line/branch/function coverage**, and clean checkout. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `cbbf975733c74413fe91310415c67a034090133d` has `HR Workspace Employment Absence State Quality` run `33125277888` / job `98701821651` terminal GREEN after a genuine contract-first RED on run `33125117860` / job `98701273064`. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. #140 exact head `260ddd27324aee5e67e09077e84a814b92d5891e` has `HR Workspace Performance Goal Review State Quality` run `33128554172` / job `98712427872` terminal GREEN after genuine contract-first RED run `33128460316` / job `98712125205`. The UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. + - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. #137 exact head `56fb4698250bdfc085eac69973b2058585f5e94e` has its focused state-contract check terminal GREEN. + - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `b213fbcbe053fe863495a5a9c392d318c0017abe` has its focused state-contract check terminal GREEN. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. + - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `81026b0fc0842acdac6134055cfb19d49625fc08` has its focused state-contract check terminal GREEN. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. + - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. #140 exact head `bbf7746b3371da24bcd4f8817b137cc31d42866f` has its focused state-contract check terminal GREEN. The UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner; #143 remains Draft and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). It remains Draft and read-only; it does not evaluate, rank, reject, advance, or authorize an employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. @@ -83,7 +85,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118 owns readiness review, #126 exact-revision authorization, and #127 reconciled at-most-once publication. No parent checks/reviews transfer and the repository release collection remains empty. - **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. -- **PR #124** owns hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`; local exact-head ADR/Foundation/Recovery/Job-Analysis/SAST/Security evidence is GREEN, while its live Ready-for-review state remains authoritative. +- **PR #124** owns hardware-acceleration ADR security hardening at exact head `40caf5f1fb154639b24479a775c772daa8250543`; its exact-head hosted suite has terminal `opencode-review` FAILURE, no qualifying independent approval, and remains active-PR truth despite being Ready-for-review. Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and all HR Workspace interaction children remain active-PR truth only. Their focused GREEN evidence never transfers across parent integration or restack. diff --git a/manifest.json b/manifest.json index f8c566bd6..bddf8c327 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"1d6098c49026a7ff8da9735f20550125d7d14b5b3c67fe18841602dfe82301b5","bytes":17310,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"5bbf8e87bf5ca9ae6935988c50156ec29e48aaf69f6a86e5e5987f4bc7f7a023","bytes":11677,"lines":40},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"1d6098c49026a7ff8da9735f20550125d7d14b5b3c67fe18841602dfe82301b5","bytes":17310,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"cb2f64be642a4d2312ab8800df848023e5bffd5a9b2b27db7b47fa6623120850","bytes":12374,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From 876828739d415a2f01bcd6c36a934dab54035fbe Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 04:17:11 +0900 Subject: [PATCH 059/201] docs: clarify current structured interview gate state --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 29b8f2dd3..14bfa235b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -55,7 +55,7 @@ This is a selected shipped inventory, not a replacement for Git history. Do not The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. -- **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security evidence is GREEN, but formal OpenCode `CHANGES_REQUESTED` is current because the central `.github` coverage-evidence path double-wraps pytest-cov projects and later reports `No data was collected`. The canonical foreign owner handoff is **`.github#1250`**. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. +- **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security and the current `coverage-evidence` check are terminal GREEN, but formal OpenCode `CHANGES_REQUESTED` remains from an earlier same-head coverage-evidence failure. The canonical foreign owner handoff is **`.github#1250`**; the existing review workflow has been asked to re-evaluate the unchanged head. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. From c2aac0922cf4c40d866c1b435f9ccfa540babef0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 05:57:09 +0900 Subject: [PATCH 060/201] docs(baseline): refresh active owner lane snapshot --- docs/product-technical-gap-baseline.md | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 14bfa235b..67e911983 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -61,8 +61,12 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #48** is active at exact head `dc3fa7ec81e6e2e6bc433d6cb39573fd8e185ff0` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. -- **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 46 passing/skipped checks and 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. -- **PR #66** remains the unmerged normalized-application dependency at exact head `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal GREEN; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, while the previous `strix` attempt is terminal FAILURE after contextual-orchestrator backend HTTP 500 responses and its failed-job rerun was cancelled before a runner job started. No authoritative Strix evidence was produced. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. +- **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. +- **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. +- **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. +- **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful and 7 skipped checks, while `opencode-review` is terminal FAILURE for missing a current-head verdict and `strix` is still in progress; all current review threads are resolved and no qualifying independent approval exists. +- **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. +- **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. - **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. @@ -77,6 +81,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. #140 exact head `bbf7746b3371da24bcd4f8817b137cc31d42866f` has its focused state-contract check terminal GREEN. The UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner; #143 remains Draft and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). It remains Draft and read-only; it does not evaluate, rank, reject, advance, or authorize an employment decision. + - **#145 → #148** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, and #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child GREEN is stack-local only. @@ -85,7 +90,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118 owns readiness review, #126 exact-revision authorization, and #127 reconciled at-most-once publication. No parent checks/reviews transfer and the repository release collection remains empty. - **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. -- **PR #124** owns hardware-acceleration ADR security hardening at exact head `40caf5f1fb154639b24479a775c772daa8250543`; its exact-head hosted suite has terminal `opencode-review` FAILURE, no qualifying independent approval, and remains active-PR truth despite being Ready-for-review. +- **PR #124** owns hardware-acceleration ADR security hardening at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`; its exact-head hosted suite has terminal `opencode-review` and `strix` FAILURE, no qualifying independent approval, and remains active-PR truth despite being Ready-for-review. Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and all HR Workspace interaction children remain active-PR truth only. Their focused GREEN evidence never transfers across parent integration or restack. From 866a2c53f02af3593b86753fb111cc90c960ff05 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:21:07 +0900 Subject: [PATCH 061/201] docs(baseline): record employment history lane --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 67e911983..7bd94a5db 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -67,6 +67,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful and 7 skipped checks, while `opencode-review` is terminal FAILURE for missing a current-head verdict and `strix` is still in progress; all current review threads are resolved and no qualifying independent approval exists. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. +- **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` on protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful and 7 skipped checks, with `opencode-review` terminal FAILURE and `strix` still in progress. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From 38823bb28e49f5d02d65a0f2ecc298e7930c0f03 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:23:37 +0900 Subject: [PATCH 062/201] docs(baseline): record candidate timeline evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7bd94a5db..4717e0169 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -81,7 +81,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `81026b0fc0842acdac6134055cfb19d49625fc08` has its focused state-contract check terminal GREEN. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. #140 exact head `bbf7746b3371da24bcd4f8817b137cc31d42866f` has its focused state-contract check terminal GREEN. The UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner; #143 remains Draft and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). It remains Draft and read-only; it does not evaluate, rank, reject, advance, or authorize an employment decision. + - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - **#145 → #148** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, and #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. From 981d12ada5edcf276b5a87de8a4c1d1b70a51cb8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:28:15 +0900 Subject: [PATCH 063/201] docs(baseline): record goal review gate evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4717e0169..766423795 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -79,7 +79,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. #137 exact head `56fb4698250bdfc085eac69973b2058585f5e94e` has its focused state-contract check terminal GREEN. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `b213fbcbe053fe863495a5a9c392d318c0017abe` has its focused state-contract check terminal GREEN. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `81026b0fc0842acdac6134055cfb19d49625fc08` has its focused state-contract check terminal GREEN. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. #140 exact head `bbf7746b3371da24bcd4f8817b137cc31d42866f` has its focused state-contract check terminal GREEN. The UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. + - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner; #143 remains Draft and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - **#145 → #148** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, and #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. From e7773c348d9d5e1cd79558005f3b2043c2cc81a9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:34:43 +0900 Subject: [PATCH 064/201] docs(baseline): record workspace gate evidence --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 766423795..595d057e7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -76,9 +76,9 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. - - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. #137 exact head `56fb4698250bdfc085eac69973b2058585f5e94e` has its focused state-contract check terminal GREEN. - - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. #138 exact head `b213fbcbe053fe863495a5a9c392d318c0017abe` has its focused state-contract check terminal GREEN. The UI records review semantics only; it does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. #139 exact head `81026b0fc0842acdac6134055cfb19d49625fc08` has its focused state-contract check terminal GREEN. The UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. + - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. + - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. + - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner; #143 remains Draft and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. From 54a66964f5d934d413d9de83349606fb5f24430b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:40:23 +0900 Subject: [PATCH 065/201] docs(baseline): record assignment history evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 595d057e7..bc56b183f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -80,7 +80,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner; #143 remains Draft and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. + - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - **#145 → #148** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, and #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. From 3d7223615710fbe724d625ee543c9936bc06f445 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:44:14 +0900 Subject: [PATCH 066/201] docs(baseline): record qualification review evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index bc56b183f..ffcb78c05 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -75,7 +75,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. - - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. + - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. From 2a47f37f6405b16d724e98826f5f2d899fa123bd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:47:53 +0900 Subject: [PATCH 067/201] docs: reconcile shipped job analysis changelog --- CHANGELOG.md | 6 +++--- manifest.json | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 97f7196de..2bd04d452 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,8 +7,8 @@ All notable changes to Orgmetra will be documented in this file. ### Added - Accepted ADRs 0001–0003 now include buyer-facing Context, Decision, and Consequences grounded in verified ISO 30400:2022, ISO 30414:2025, Uniform Guidelines (29 C.F.R. Part 1607), SIOP (2018), OpenAPI Specification v3.2.0, OpenID Connect Core 1.0 errata set 2, CloudEvents v1.0.2, Jensen and Snodgrass (1999), Snodgrass (1999), and Allen (1983) records already listed in `docs/doctoring/REFERENCES.md`. ADRs 0004 and 0005 gained APA 7th References pointers to that same bibliography without changing their Decision bodies. -- Active-PR governed Job Analysis persistence/API on the canonical `JobAnalysisSnapshot` model: migration `0013_job_analysis_snapshot.sql` stores immutable tenant-scoped snapshot, Task, KSAO, Task–KSAO, FJA and write-command evidence; `POST /v1/tenants/{tenant_record_id}/job-analysis-snapshots` and matching GET enforce purpose-bound Keyverse scope, authenticated-principal actor authority, bounded/strict JSON handling, transactional Idempotency-Key serialization, parent-scope fail-closed integrity, forced RLS, and atomic audit/outbox evidence. ADR 0014 records the persistence decision while ADR 0007 remains the domain/evidence authority; validated evidence still requires accountable human review and non-LLM provenance, and the service does not make a high-impact employment decision. -- Active-PR `orgmetra_selection_review` packet for PII-minimized, evidence-bound human selection review: canonical operational tenant identity, UUID-backed opaque candidate/Job/sealed-evidence/reviewer references, explicit purpose/reason/evidence version, deterministic canonical JSON and SHA-256 correlation, mandatory human decision state, redacted packet repr, and provenance-paired model evidence that remains `untrusted_draft`, with exact 100% owned statement and branch coverage required by its quality gate. +- Protected-main governed Job Analysis persistence/API on the canonical `JobAnalysisSnapshot` model: migration `0013_job_analysis_snapshot.sql` stores immutable tenant-scoped snapshot, Task, KSAO, Task–KSAO, FJA and write-command evidence; `POST /v1/tenants/{tenant_record_id}/job-analysis-snapshots` and matching GET enforce purpose-bound Keyverse scope, authenticated-principal actor authority, bounded/strict JSON handling, transactional Idempotency-Key serialization, parent-scope fail-closed integrity, forced RLS, and atomic audit/outbox evidence. ADR 0014 records the persistence decision while ADR 0007 remains the domain/evidence authority; validated evidence still requires accountable human review and non-LLM provenance, and the service does not make a high-impact employment decision. +- Protected-main `orgmetra_selection_review` packet for PII-minimized, evidence-bound human selection review: canonical operational tenant identity, UUID-backed opaque candidate/Job/sealed-evidence/reviewer references, explicit purpose/reason/evidence version, deterministic canonical JSON and SHA-256 correlation, mandatory human decision state, redacted packet repr, and provenance-paired model evidence that remains `untrusted_draft`, with exact 100% owned statement and branch coverage required by its quality gate. - Active performance-criterion scope hardening: `criterion_observation_scope_guard` rejects criterion outcomes for a Job the worker did not effectively hold at the observation date, observations before the relevant assignment, and observations outside the referenced performance cycle while preserving valid multiple-assignment cases and existing bitemporal correction semantics. The guard evaluates current-recorded facts, derives the date coordinate from `observed_at` in UTC so session `TimeZone` cannot alter the result, uses a trusted function search path, and adds no PII or automated employment decision authority. The Foundation PostgreSQL contract also rejects a closed `recorded_to` on each time-coordinate lookup and proves UTC midnight plus non-UTC session `TimeZone` boundaries. - Bitemporal tenant-scoped organization hierarchy validation that rejects visible indirect parent cycles and reuses single-valued recorded-time reconstruction before graph traversal. - Stacked governed job-analysis evidence contract via `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `TaskKSAOLink`, `FunctionalJobAnalysisProfile`, and `EvidenceSource`: tenant/Job-scoped observable tasks, explicit Task-to-KSAO linkage, importance/difficulty/proficiency ratings, source/version/retrieval/SHA-256 provenance, deterministic canonical snapshot bytes, current O*NET evidence support, and historical DOT Data/People/Things compatibility. Validated snapshots require accountable human review and complete non-LLM evidence; LLM-origin material remains `analysis_draft`, and the snapshot is evidence input rather than a hiring, promotion, termination, compensation, or other high-impact employment decision. @@ -73,4 +73,4 @@ All notable changes to Orgmetra will be documented in this file. ### Notes -- Protected `develop` at `e7ddb7a78a5e1460410005d10f43ebf18c5e12e4` includes normalized validity-study and criterion integrity, bitemporal workforce composition, governed candidate-to-worker conversion, purpose-bound PII authorization, GET-only People reads, governed People mutation/idempotency API, and the accepted ADR 0001–0003 source expansion integrated by #37. Job Analysis persistence/API and the selection-review packet remain active-PR truth until their unchanged exact heads satisfy fresh gates and merge. +- Protected `develop` at `e7ddb7a78a5e1460410005d10f43ebf18c5e12e4` includes normalized validity-study and criterion integrity, bitemporal workforce composition, governed candidate-to-worker conversion, purpose-bound PII authorization, GET-only People reads, governed People mutation/idempotency API, and the accepted ADR 0001–0003 source expansion integrated by #37. Subsequent protected-develop merges recorded governed Job Analysis persistence/API and the selection-review packet as shipped capabilities; current active hardening and exact protected-head status are tracked in the README, TRACEABILITY, and product gap baseline rather than this historical anchor. diff --git a/manifest.json b/manifest.json index bddf8c327..e375d0d63 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"1d6098c49026a7ff8da9735f20550125d7d14b5b3c67fe18841602dfe82301b5","bytes":17310,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"cb2f64be642a4d2312ab8800df848023e5bffd5a9b2b27db7b47fa6623120850","bytes":12374,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"cb2f64be642a4d2312ab8800df848023e5bffd5a9b2b27db7b47fa6623120850","bytes":12374,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From 66cb92ea3f75405bbe4571c3e1577ad93a540b62 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:49:07 +0900 Subject: [PATCH 068/201] docs(baseline): clarify draft base branch --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ffcb78c05..3a2920af1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -67,7 +67,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful and 7 skipped checks, while `opencode-review` is terminal FAILURE for missing a current-head verdict and `strix` is still in progress; all current review threads are resolved and no qualifying independent approval exists. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. -- **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` on protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful and 7 skipped checks, with `opencode-review` terminal FAILURE and `strix` still in progress. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. +- **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful and 7 skipped checks, with `opencode-review` terminal FAILURE and `strix` still in progress. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From b5d04a94c06de03f5b35d95bd3d45004c96c615e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 06:58:30 +0900 Subject: [PATCH 069/201] docs(baseline): record job grade and lifecycle evidence --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3a2920af1..6f13b0a1b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -73,8 +73,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. - - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. + - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. At exact head `40b26388527fa65596ea6875e1d3d2b025942c2c`, its local focused contract passes 7 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. + - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. From 9348aaa79a60ea6ca0201c7c5e3533e9359c0169 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 07:07:27 +0900 Subject: [PATCH 070/201] docs(baseline): record position span-of-control evidence --- docs/product-technical-gap-baseline.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 87c429dd3..c1ac58153 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product and technical gap baseline -Inventory date: 2026-08-28 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Inventory date: 2026-08-29 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -78,6 +78,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-28 - **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #124** owns hardware-acceleration ADR security hardening at exact head `34a6520bf69731e69da27138e627ae774071376b`; local exact-head ADR/Foundation/Recovery/Job-Analysis/SAST/Security evidence is GREEN, while its live Ready-for-review state remains authoritative. +- **PR #133** owns Position span-of-control structural evidence. Exact head `139c715062c044fa3cb13967d94268069310c7b3` now includes the current `feat/position-reporting-hierarchy` base at `2ff1262b976029e447dc736e6472eebbac30a7f5` and reconciles the UTC-range regression cases. The exact workflow-equivalent HRIS-kernel run passed `213` tests with `100%` statement/branch coverage; the dedicated hosted Check is currently **QUEUED**, the PR remains Draft with no qualifying approval, and no review threads are unresolved. It remains active-PR truth only and is not shipped on `develop`. Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and all HR Workspace interaction children remain active-PR truth only. Their focused GREEN evidence never transfers across parent integration or restack. From c70d39dce69b480291f65786665e65d3ca8f367a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 07:10:48 +0900 Subject: [PATCH 071/201] docs(traceability): mark shipped kernel capabilities --- docs/TRACEABILITY.md | 12 ++++++------ manifest.json | 2 +- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/docs/TRACEABILITY.md b/docs/TRACEABILITY.md index a61b35f4b..bb515d71f 100644 --- a/docs/TRACEABILITY.md +++ b/docs/TRACEABILITY.md @@ -4,13 +4,13 @@ | Requirement | Architecture | Data object | Test family | ADR | Maturity | |---|---|---|---|---|---| -| Separate person/employment/organization/job/position/assignment | Core bounded contexts | `person_record`, `employment_record`, `employment_record_version`, `organization_unit`, `job_profile`, `position_record`, `position_record_version`, `assignment_record` | schema/domain and `orgmetra_hris_kernel` tests | ADR-0001, ADR-0004, ADR-0005 | implemented_on_active_pr | -| Exclusive employment and staffable seats | Core bounded contexts | `employment_concurrency_code`, staffable `position_status_code`, assignment allocation totals | Memorial Hospital exclusivity, freeze, and seat-capacity kernel tests plus OpenAPI employment/position/assignment commands | ADR-0005 | implemented_on_active_pr | -| Tenant-qualified HRIS integrity and fail-closed isolation | Core bounded contexts / Security architecture | `tenant_record`, tenant-qualified foreign keys, forced row-level security policies, tenant-scoped kernel query parameters | PostgreSQL cross-tenant FK/application-role RLS contracts plus kernel cross-tenant reconstruction, employment coverage, position coverage, seat-capacity, portfolio, exclusivity, and organization-hierarchy regressions | ADR-0001, ADR-0003 | implemented_on_active_pr | -| Reserved UUID sentinel exclusion | Persistence integrity boundary | every foundation UUID `*_id` column plus audit/outbox identifiers | PostgreSQL inventory proof plus Nil/Max foundation and audit/outbox persistence regressions | ADR-0001, RFC 9562 | implemented_on_active_pr | -| Normalized bitemporal organization/job/employment/position history | Core bounded contexts | `organization_unit_version`, `job_profile_version`, `employment_record_version`, `position_record_version` | PostgreSQL non-overlap, concurrent conflict, correction, rewrite-rejection, assignment-employment binding, and single-valued historical reconstruction | ADR-0001, ADR-0003, ADR-0004 | implemented_on_active_pr | +| Separate person/employment/organization/job/position/assignment | Core bounded contexts | `person_record`, `employment_record`, `employment_record_version`, `organization_unit`, `job_profile`, `position_record`, `position_record_version`, `assignment_record` | schema/domain and `orgmetra_hris_kernel` tests | ADR-0001, ADR-0004, ADR-0005 | implemented_on_protected_main | +| Exclusive employment and staffable seats | Core bounded contexts | `employment_concurrency_code`, staffable `position_status_code`, assignment allocation totals | Memorial Hospital exclusivity, freeze, and seat-capacity kernel tests plus OpenAPI employment/position/assignment commands | ADR-0005 | implemented_on_protected_main | +| Tenant-qualified HRIS integrity and fail-closed isolation | Core bounded contexts / Security architecture | `tenant_record`, tenant-qualified foreign keys, forced row-level security policies, tenant-scoped kernel query parameters | PostgreSQL cross-tenant FK/application-role RLS contracts plus kernel cross-tenant reconstruction, employment coverage, position coverage, seat-capacity, portfolio, exclusivity, and organization-hierarchy regressions | ADR-0001, ADR-0003 | implemented_on_protected_main | +| Reserved UUID sentinel exclusion | Persistence integrity boundary | every foundation UUID `*_id` column plus audit/outbox identifiers | PostgreSQL inventory proof plus Nil/Max foundation and audit/outbox persistence regressions | ADR-0001, RFC 9562 | implemented_on_protected_main | +| Normalized bitemporal organization/job/employment/position history | Core bounded contexts | `organization_unit_version`, `job_profile_version`, `employment_record_version`, `position_record_version` | PostgreSQL non-overlap, concurrent conflict, correction, rewrite-rejection, assignment-employment binding, and single-valued historical reconstruction | ADR-0001, ADR-0003, ADR-0004 | implemented_on_protected_main | | Acyclic organization hierarchy at historical coordinates | Organization core | `organization_unit_version.parent_organization_unit_id` | indirect A→B→C→A rejection plus future-recorded and foreign-tenant isolation in `orgmetra_hris_kernel` | ADR-0001, ADR-0003 | implemented_on_protected_main | -| Effective/system time | Bitemporal HRIS | `effective_from`, `recorded_from` | strict half-open interval and historical-coordinate tests | ADR-0003 | implemented_on_active_pr | +| Effective/system time | Bitemporal HRIS | `effective_from`, `recorded_from` | strict half-open interval and historical-coordinate tests | ADR-0003 | implemented_on_protected_main | | Evidence-backed human selection decisions | Talent Acquisition | `decision_evidence_set`, `selection_decision_evidence`, `selection_decision` | database-owned SHA-256 sealing, non-empty evidence, drift/reuse rejection, OpenAPI human-confirmation tests | ADR-0001 | implemented_on_protected_main | | Governed candidate-to-worker conversion | Talent Acquisition / People core | `candidate_worker_conversion_record` with candidate, person, employment, selection decision, audit event and outbox evidence | PostgreSQL exact hire/evidence/audit-envelope binding, correction provenance, tenant RLS, legacy-write rejection and bitemporal history contract | ADR-0001, ADR-0003, ADR-0006 | implemented_on_protected_main | | GET-only People API | People API / purpose-bound read boundary | `GET /v1/tenants/{tenant_record_id}/people/{person_record_id}`, `read_worker_people_record()`, `PostgresPeopleReadPort` | People API HTTP and PostgreSQL read contracts with exact 100% owned statement/branch coverage; current conversion lineage; no mutation writes | ADR-0002, ADR-0008 | implemented_on_protected_main | diff --git a/manifest.json b/manifest.json index e375d0d63..dc84d87f1 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"cb2f64be642a4d2312ab8800df848023e5bffd5a9b2b27db7b47fa6623120850","bytes":12374,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"e96cd0aef6bc6251947fb8a05685c17406e3564a200db312b9f6505fdf944a7b","bytes":12404,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From ac204a76ec4267db509b710cdd21ae11736af2eb Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 07:12:59 +0900 Subject: [PATCH 072/201] docs(baseline): record span-of-control hosted check --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2f5d559c3..4ba84b8f4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -92,7 +92,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence. - **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. - **PR #124** owns hardware-acceleration ADR security hardening at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`; its exact-head hosted suite has terminal `opencode-review` and `strix` FAILURE, no qualifying independent approval, and remains active-PR truth despite being Ready-for-review. -- **PR #133** owns Position span-of-control structural evidence. Exact head `139c715062c044fa3cb13967d94268069310c7b3` now includes the current `feat/position-reporting-hierarchy` base at `2ff1262b976029e447dc736e6472eebbac30a7f5` and reconciles the UTC-range regression cases. The exact workflow-equivalent HRIS-kernel run passed `213` tests with `100%` statement/branch coverage; the dedicated hosted Check is currently **QUEUED**, the PR remains Draft with no qualifying approval, and no review threads are unresolved. It remains active-PR truth only and is not shipped on `develop`. +- **PR #133** owns Position span-of-control structural evidence. Exact head `139c715062c044fa3cb13967d94268069310c7b3` now includes the current `feat/position-reporting-hierarchy` base at `2ff1262b976029e447dc736e6472eebbac30a7f5` and reconciles the UTC-range regression cases. The exact workflow-equivalent HRIS-kernel run passed `213` tests with `100%` statement/branch coverage; dedicated hosted Check [run 33215365348 / job 98997658110](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33215365348/job/98997658110) is terminal **GREEN**, the PR remains Draft with no qualifying approval, and no review threads are unresolved. It remains active-PR truth only and is not shipped on `develop`. Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and all HR Workspace interaction children remain active-PR truth only. Their focused GREEN evidence never transfers across parent integration or restack. From ef1237a5aed488c45956a5274ec542c6dbb9c28b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 09:29:48 +0900 Subject: [PATCH 073/201] docs(baseline): refresh current governance evidence --- docs/product-technical-gap-baseline.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4ba84b8f4..96dbee6ef 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -55,11 +55,11 @@ This is a selected shipped inventory, not a replacement for Git history. Do not The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. -- **Oldest root PR #40** remains exact head `8d8896b14db10a5a4981f0b9e209ea00ee3be64c`. Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security and the current `coverage-evidence` check are terminal GREEN, but formal OpenCode `CHANGES_REQUESTED` remains from an earlier same-head coverage-evidence failure. The canonical foreign owner handoff is **`.github#1250`**; the existing review workflow has been asked to re-evaluate the unchanged head. The previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR; Orgmetra must not weaken local 100% coverage or create a competing foreign repair. +- **Oldest root PR #40** remains exact head `c678ad4d6c2dd41c56e3f9368a39ff19046897a8`. Its current Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security checks are terminal GREEN, while exact-head `opencode-review` and `strix` are terminal FAILURE; the current review findings checked during this loop were already implemented or intentionally resolved, so no leaf source repair is warranted. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #48** is active at exact head `dc3fa7ec81e6e2e6bc433d6cb39573fd8e185ff0` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. +- **PR #48** is active at exact head `227926e3dafed17a2ec287b3102315c866648f6c` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. @@ -68,8 +68,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. - **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful and 7 skipped checks, with `opencode-review` terminal FAILURE and `strix` still in progress. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. -- **PR #67** now has exact current head `18bf097b2daefa61f30d127f513d32f1333360ca`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. Foundation/manifest validation and 56 Node contract tests pass locally; exact-head Candidate Withdrawal PostgreSQL run `33156400198` / job `98800086944` is terminal GREEN across checkout, syntax, persistence, anti-forgery/tenant isolation, and read-only validation. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33`. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **PR #67** now has exact current head `f0afa82ec4d0bfa6404b76d1bb7817e96a93b75d`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From 0255dd99b7654cf05916e126efd23d9eb655c221 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 09:34:33 +0900 Subject: [PATCH 074/201] docs(baseline): record current PR inventory --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 96dbee6ef..8105a9eab 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-29 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 100 pull requests and one non-PR issue (#89) are open; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 106 pull requests and one non-PR issue (#89) are open; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -82,7 +82,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - - **#145 → #148** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, and #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. + - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child GREEN is stack-local only. From 75c036d5a44e6780fdcaea3edd92e3e3ee3e5908 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 09:47:04 +0900 Subject: [PATCH 075/201] docs(traceability): reconcile shipped control maturity --- docs/TRACEABILITY.md | 4 ++-- docs/product-technical-gap-baseline.md | 2 ++ manifest.json | 2 +- 3 files changed, 5 insertions(+), 3 deletions(-) diff --git a/docs/TRACEABILITY.md b/docs/TRACEABILITY.md index bb515d71f..464206324 100644 --- a/docs/TRACEABILITY.md +++ b/docs/TRACEABILITY.md @@ -24,8 +24,8 @@ | Owner-bound outbox completion, retry, and terminal dead-letter escalation | Integration Hub dispatcher boundary | immutable `outbox_delivery_record.maximum_attempt_count`, `complete_outbox_delivery(...)`, `retry_outbox_delivery(...)`, `dead_letter_outbox_delivery(...)`, `outbox_delivery_escalation_record` | PostgreSQL foreign/stale-owner denial, dispatcher-budget-signature rejection, direct-terminal-DML rejection, stored-budget exhaustion, retry-attempt-N+1 denial, exhausted expired-lease non-reclaimability, recorded-owner terminalization, nonterminal-escalation rejection, terminal non-reclaimability, and append-only escalation evidence | ADR-0006 | implemented_on_protected_main | | Predictive-validity case integrity | Workforce Validation | `validity_study`, normalized `validity_study_case_record`, exact `selection_decision`, sealed `decision_evidence_set`, governed `candidate_worker_conversion_record`, `criterion_observation` | `test_validity_study_case_postgres.sh`: legacy loose-link write rejection; exact evidence-set ID, Job, criterion and worker mismatch rejection; study/observation system-recorded visibility boundaries; governed upstream decision/evidence/conversion lineage from the evidence-sealing and candidate-worker conversion contracts; UPDATE/DELETE/TRUNCATE protection; missing/foreign-tenant RLS denial. Statistical estimation remains subsequent work. | ADR-0001, SIOP Principles 5th ed., 29 C.F.R. Part 1607 | implemented_on_protected_main | | Purpose-bound PII access | Security architecture / Keyverse adapter boundary | `PurposeBoundAccessPolicy`, `PurposeBoundAccessRequest.resource_reference`, `AuthorizationDecision.resource_reference` | exact tenant/actor/resource binding, exact opaque target correlation for allow/deny audit evidence, resource/purpose/operation matching, operation-specific scope, field-subset minimization, malformed-attribute rejection, reserved-UUID rejection, PII-minimized denial evidence, and exact 100% owned statement/branch coverage | ADR-0008 | implemented_on_protected_main | -| Least-privilege API capability | Keyverse gateway boundary | operation scope conceptual | structural per-operation scope and confused-deputy contract tests | ADR-0002 | implemented_on_active_pr | -| Client-safe failure correlation | API error boundary | `support_reference` conceptual | error disclosure and support-lookup tests | ADR-0002 | implemented_on_active_pr | +| Least-privilege API capability | Keyverse gateway boundary | operation scope conceptual | structural per-operation scope and confused-deputy contract tests | ADR-0002 | implemented_on_protected_main | +| Client-safe failure correlation | API error boundary | `support_reference` conceptual | error disclosure and support-lookup tests | ADR-0002 | implemented_on_protected_main | | Foundation artifact integrity | Repository governance | deterministic `manifest.json` file inventory | SHA-256/byte/line validation plus Python/Node inventory-equivalence regression and explicit dispatcher/validity/criterion/job-analysis migration and execution-contract provenance regression | ADR-0001 | implemented_on_active_pr | ## 4. CWL integration traceability diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8105a9eab..3b6255057 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -37,8 +37,10 @@ Consequences: | Merged PR | Capability | |---|---| +| #23 | Governed audit/outbox envelope and durable delivery evidence | | #25 | Governed Job Analysis evidence boundary | | #26 | `validity_study_case_record` integrity | +| #27 | Purpose-bound PII authorization and least-privilege capability boundary | | #28 | Performance-criterion Job-scope guard | | #31 | Governed People mutation API | | #32 | Governed Naruon calendar intent adapter | diff --git a/manifest.json b/manifest.json index dc84d87f1..e2b3b2645 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"e96cd0aef6bc6251947fb8a05685c17406e3564a200db312b9f6505fdf944a7b","bytes":12404,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"25b4108e6d14c7051ab3989132692368d87c818725927e3fc1d4cf3fc4ca79f2","bytes":12414,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From 1501bb9bcdcb4eeded2af31a00f7fb5960777bfe Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 09:52:28 +0900 Subject: [PATCH 076/201] docs(traceability): mark foundation integrity shipped --- docs/TRACEABILITY.md | 2 +- manifest.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/TRACEABILITY.md b/docs/TRACEABILITY.md index 464206324..5266c25fa 100644 --- a/docs/TRACEABILITY.md +++ b/docs/TRACEABILITY.md @@ -26,7 +26,7 @@ | Purpose-bound PII access | Security architecture / Keyverse adapter boundary | `PurposeBoundAccessPolicy`, `PurposeBoundAccessRequest.resource_reference`, `AuthorizationDecision.resource_reference` | exact tenant/actor/resource binding, exact opaque target correlation for allow/deny audit evidence, resource/purpose/operation matching, operation-specific scope, field-subset minimization, malformed-attribute rejection, reserved-UUID rejection, PII-minimized denial evidence, and exact 100% owned statement/branch coverage | ADR-0008 | implemented_on_protected_main | | Least-privilege API capability | Keyverse gateway boundary | operation scope conceptual | structural per-operation scope and confused-deputy contract tests | ADR-0002 | implemented_on_protected_main | | Client-safe failure correlation | API error boundary | `support_reference` conceptual | error disclosure and support-lookup tests | ADR-0002 | implemented_on_protected_main | -| Foundation artifact integrity | Repository governance | deterministic `manifest.json` file inventory | SHA-256/byte/line validation plus Python/Node inventory-equivalence regression and explicit dispatcher/validity/criterion/job-analysis migration and execution-contract provenance regression | ADR-0001 | implemented_on_active_pr | +| Foundation artifact integrity | Repository governance | deterministic `manifest.json` file inventory | SHA-256/byte/line validation plus Python/Node inventory-equivalence regression and explicit dispatcher/validity/criterion/job-analysis migration and execution-contract provenance regression | ADR-0001 | implemented_on_protected_main | ## 4. CWL integration traceability diff --git a/manifest.json b/manifest.json index e2b3b2645..4917d73de 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"25b4108e6d14c7051ab3989132692368d87c818725927e3fc1d4cf3fc4ca79f2","bytes":12414,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"27af9b5fcc359a5131d146a258d55bfad5aa45c3310860821912e2446c75e0f2","bytes":12419,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} From eebb9272167317117a8f2a7a775cee5de0e88ada Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 10:51:26 +0900 Subject: [PATCH 077/201] docs(baseline): refresh employment history gate state --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3b6255057..59fdf3a98 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -69,7 +69,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful and 7 skipped checks, while `opencode-review` is terminal FAILURE for missing a current-head verdict and `strix` is still in progress; all current review threads are resolved and no qualifying independent approval exists. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. -- **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful and 7 skipped checks, with `opencode-review` terminal FAILURE and `strix` still in progress. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. +- **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 36 successful, 2 failed, and 0 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `f0afa82ec4d0bfa6404b76d1bb7817e96a93b75d`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From 7f302cb001c45264d0ed7f2b499036dfa58e8e36 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 10:55:04 +0900 Subject: [PATCH 078/201] docs(baseline): correct hosted check totals --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 59fdf3a98..0e180b2ee 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -69,7 +69,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful and 7 skipped checks, while `opencode-review` is terminal FAILURE for missing a current-head verdict and `strix` is still in progress; all current review threads are resolved and no qualifying independent approval exists. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. -- **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 36 successful, 2 failed, and 0 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. +- **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful, 2 failed, and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `f0afa82ec4d0bfa6404b76d1bb7817e96a93b75d`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From d73f2c8d6e5f6cfbdf42d2a7438447153e106ea9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 11:10:08 +0900 Subject: [PATCH 079/201] docs(baseline): refresh current review evidence --- docs/product-technical-gap-baseline.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0e180b2ee..60083e187 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -66,7 +66,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. -- **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful and 7 skipped checks, while `opencode-review` is terminal FAILURE for missing a current-head verdict and `strix` is still in progress; all current review threads are resolved and no qualifying independent approval exists. +- **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful, 2 failed, and 8 skipped checks; both `opencode-review` and `strix` are terminal FAILURE, with no current-head OpenCode verdict and no authoritative Strix report. All current review threads are resolved and no qualifying independent approval exists. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. - **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful, 2 failed, and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. @@ -77,11 +77,11 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. At exact head `40b26388527fa65596ea6875e1d3d2b025942c2c`, its local focused contract passes 7 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. - - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is queued after a workflow-trigger regression fix covering protected `develop` and the parent branch. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. + - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. + - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. + - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. + - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. + - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. From eb396b9a822c07dbf1f6cb2b1db4380f66caa1b1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 22:57:03 +0900 Subject: [PATCH 080/201] docs: refresh live PR gap evidence --- docs/product-technical-gap-baseline.md | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 60083e187..aa58d7f70 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-29 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 106 pull requests and one non-PR issue (#89) are open; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 100 pull requests and one non-PR issue (#89) are open; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -57,9 +57,9 @@ This is a selected shipped inventory, not a replacement for Git history. Do not The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. -- **Oldest root PR #40** remains exact head `c678ad4d6c2dd41c56e3f9368a39ff19046897a8`. Its current Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security checks are terminal GREEN, while exact-head `opencode-review` and `strix` are terminal FAILURE; the current review findings checked during this loop were already implemented or intentionally resolved, so no leaf source repair is warranted. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. -- **PR #42** remains active at exact head `fca40417cfc60947a5836cf1a90815fdf118b889`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. -- **PR #44** remains Draft at exact head `e011579f7191f41b500f017314c5ce6283e7d4e4`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; 44 hosted checks are attached with 37 success, 6 skipped, no active checks, and terminal `opencode-review` **FAILURE** because no current-head OpenCode verdict was posted. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. +- **Oldest root PR #40** remains exact head `c67c8695b7565e90d957063dbfa260eb3917a969`. Its current Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security checks are terminal GREEN, while exact-head `opencode-review` and `strix` are terminal FAILURE; the current review findings checked during this loop were already implemented or intentionally resolved, so no leaf source repair is warranted. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. +- **PR #42** remains active at exact head `a9823aaff3364971cca0d42134864c21fde27c49`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. +- **PR #44** remains Draft at exact head `7a0e328929219dab59e696ce16389dd588067f1f`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; its current hosted checks include terminal `opencode-review` and `strix` **FAILURE**. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #48** is active at exact head `227926e3dafed17a2ec287b3102315c866648f6c` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. - **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. @@ -69,8 +69,9 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful, 2 failed, and 8 skipped checks; both `opencode-review` and `strix` are terminal FAILURE, with no current-head OpenCode verdict and no authoritative Strix report. All current review threads are resolved and no qualifying independent approval exists. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. -- **PR #149** remains exact head `c148d518af1240e8a0b27964179136c980912b3c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful, 2 failed, and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. -- **PR #67** now has exact current head `f0afa82ec4d0bfa6404b76d1bb7817e96a93b75d`, synchronized with normalized-application base `5f9c4700265f400830cfe00ad7e313ea26c61d70`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. +- **PR #151** remains Draft at exact head `cecd4a571172eb5120094583197009389d256509`. Its standalone external-delivery-receipt package passes 48 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Exact-head `noema-review` failed after token-minting setup and `opencode-review` failed because no current-head verdict was posted; no qualifying independent approval exists, so it remains active-PR truth only. +- **PR #149** remains exact head `32022b49e218c11a91476038f8e96d6183535f5c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful, 2 failed, and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. +- **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. From c963d11a542c197e7d001e3d1d1611aa71835d06 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 23:10:05 +0900 Subject: [PATCH 081/201] docs: refresh employment history evidence count --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index aa58d7f70..2b65b0675 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -70,7 +70,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. - **PR #151** remains Draft at exact head `cecd4a571172eb5120094583197009389d256509`. Its standalone external-delivery-receipt package passes 48 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Exact-head `noema-review` failed after token-minting setup and `opencode-review` failed because no current-head verdict was posted; no qualifying independent approval exists, so it remains active-PR truth only. -- **PR #149** remains exact head `32022b49e218c11a91476038f8e96d6183535f5c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 157 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful, 2 failed, and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. +- **PR #149** remains exact head `32022b49e218c11a91476038f8e96d6183535f5c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 159 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful, 2 failed, and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From 48fc1f278ced09513d5c5af033d9dc32bbb97bda Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 23:13:08 +0900 Subject: [PATCH 082/201] docs: refresh external receipt evidence snapshot --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2b65b0675..7e416acc5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -69,7 +69,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful, 2 failed, and 8 skipped checks; both `opencode-review` and `strix` are terminal FAILURE, with no current-head OpenCode verdict and no authoritative Strix report. All current review threads are resolved and no qualifying independent approval exists. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. -- **PR #151** remains Draft at exact head `cecd4a571172eb5120094583197009389d256509`. Its standalone external-delivery-receipt package passes 48 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Exact-head `noema-review` failed after token-minting setup and `opencode-review` failed because no current-head verdict was posted; no qualifying independent approval exists, so it remains active-PR truth only. +- **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `32022b49e218c11a91476038f8e96d6183535f5c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 159 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful, 2 failed, and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From 657cc9b41876cfa7d90074d335df2d5ab7b4af15 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 23:29:39 +0900 Subject: [PATCH 083/201] docs: refresh employment history PR evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7e416acc5..7014a616e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -70,7 +70,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. -- **PR #149** remains exact head `32022b49e218c11a91476038f8e96d6183535f5c` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, and fail-closed persistence-boundary checks. The full People API suite passes locally with 159 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 33 successful, 2 failed, and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. +- **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 3 failed, 7 skipped, and 1 pending check, with `opencode-review`, `dependency-review`, and `noema-review` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From f1d1bc2edebeafd5c20c0dafcf2468c0558bfbac Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 23:40:33 +0900 Subject: [PATCH 084/201] docs: refresh employment history hosted checks --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7014a616e..7be696e38 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -70,7 +70,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. -- **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 3 failed, 7 skipped, and 1 pending check, with `opencode-review`, `dependency-review`, and `noema-review` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. +- **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. From 98a85a03ebcfcbe20950bd92144b93b2d1260204 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 00:02:54 +0900 Subject: [PATCH 085/201] docs: refresh workforce review baseline --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7be696e38..36bbc9ea4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product and technical gap baseline -Inventory date: 2026-08-29 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. At this snapshot, 100 pull requests and one non-PR issue (#89) are open; the repository has no releases. These counts are dated evidence, not live merge authorization. @@ -62,7 +62,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #44** remains Draft at exact head `7a0e328929219dab59e696ce16389dd588067f1f`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; its current hosted checks include terminal `opencode-review` and `strix` **FAILURE**. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #48** is active at exact head `227926e3dafed17a2ec287b3102315c866648f6c` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. -- **PR #54** has the same dedicated central coverage/review owner blocker while its Orgmetra-owned exact-head product/Foundation/security/recovery evidence is GREEN. It remains non-ready while that `CHANGES_REQUESTED` stands. +- **PR #54** remains exact head `c27a9f6c9949acd29d3ee90fd1e9662c603e7cf2` after reconciling direct-construction staffing totals and making workforce-change FTE deltas independent of ambient Decimal precision. Its HRIS kernel suite passes 210 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 7 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); the Strix run remains in progress. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 57dd24381bc53f3bbcd4d0eda5bb94002873a7dd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 00:13:59 +0900 Subject: [PATCH 086/201] docs: record exact workforce aggregation head --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 36bbc9ea4..280805f6f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -62,7 +62,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #44** remains Draft at exact head `7a0e328929219dab59e696ce16389dd588067f1f`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; its current hosted checks include terminal `opencode-review` and `strix` **FAILURE**. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #48** is active at exact head `227926e3dafed17a2ec287b3102315c866648f6c` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. -- **PR #54** remains exact head `c27a9f6c9949acd29d3ee90fd1e9662c603e7cf2` after reconciling direct-construction staffing totals and making workforce-change FTE deltas independent of ambient Decimal precision. Its HRIS kernel suite passes 210 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 7 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); the Strix run remains in progress. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. +- **PR #54** remains exact head `d829fba116b2a9843f1ffc8a09c72f38d732e511` after reconciling direct-construction staffing totals and making workforce endpoint aggregation and change deltas independent of ambient Decimal precision. Its HRIS kernel suite passes 211 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 7 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); the Strix job `99118967920` remains in progress. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 20ee463cb359872cbc9ff4ea63abfa564cf6d230 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 00:21:11 +0900 Subject: [PATCH 087/201] docs: record final workforce gate state --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 280805f6f..804691eb1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -62,7 +62,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #44** remains Draft at exact head `7a0e328929219dab59e696ce16389dd588067f1f`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; its current hosted checks include terminal `opencode-review` and `strix` **FAILURE**. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #48** is active at exact head `227926e3dafed17a2ec287b3102315c866648f6c` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. -- **PR #54** remains exact head `d829fba116b2a9843f1ffc8a09c72f38d732e511` after reconciling direct-construction staffing totals and making workforce endpoint aggregation and change deltas independent of ambient Decimal precision. Its HRIS kernel suite passes 211 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 7 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); the Strix job `99118967920` remains in progress. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. +- **PR #54** remains exact head `fd39e07b2ab3490a3ebe0cecd6361f52f162c5d7` after reconciling direct-construction staffing totals, making workforce endpoint aggregation and change deltas independent of ambient Decimal precision, and hardening employment/Position allocation limits under low precision. Its HRIS kernel suite passes 213 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 6 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); no Strix check surfaced for this exact head. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 81f687d849d4659e60d82455a441fe4749139bef Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 00:32:53 +0900 Subject: [PATCH 088/201] docs: refresh validity and compensation PR evidence --- docs/product-technical-gap-baseline.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 804691eb1..ba82b6ae6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -61,8 +61,9 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #42** remains active at exact head `a9823aaff3364971cca0d42134864c21fde27c49`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `7a0e328929219dab59e696ce16389dd588067f1f`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; its current hosted checks include terminal `opencode-review` and `strix` **FAILURE**. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #48** is active at exact head `227926e3dafed17a2ec287b3102315c866648f6c` after rejecting `str` subclasses at the compensation-evidence digest boundary with a regression test. Its local package suite has `73` tests and exact 100% statement/branch coverage, and its exact-head compensation-review quality run is GREEN; the protected set has terminal `opencode-review` **FAILURE** for missing a current-head verdict and terminal `strix` **FAILURE** because the provider/backend was unavailable, with `mergeStateStatus=BLOCKED` and no qualifying independent approval. It remains active-PR truth only. +- **PR #48** is active at exact head `9eab9d50ae0a202f4c3398ae60fba726c60ccb67` after freezing caller-controlled compensation-review recorded-time evidence as a detached exact UTC instant and documenting the boundary. Its local package suite has `77` tests and exact 100% statement/branch coverage; the current exact-head hosted set has 31 successful, 7 skipped, 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`), with `strix` still in progress when observed. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #54** remains exact head `fd39e07b2ab3490a3ebe0cecd6361f52f162c5d7` after reconciling direct-construction staffing totals, making workforce endpoint aggregation and change deltas independent of ambient Decimal precision, and hardening employment/Position allocation limits under low precision. Its HRIS kernel suite passes 213 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 6 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); no Strix check surfaced for this exact head. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. +- **PR #57** remains exact head `4359cfbb4cd8ee5885acb9110d7723099d712353` with a governed selection-validity analysis handoff and aggregate scientific result envelope bound to the reviewed `fast-mlsirm` revision. Its local package suite passes 92 tests with exact 100% statement/branch coverage; the exact-head hosted set has 35 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`). All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From a4e839d52f13c6426cfc102a06c9ff62ea513ace Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 01:04:30 +0900 Subject: [PATCH 089/201] docs: record current runtime-integrity PR evidence --- docs/product-technical-gap-baseline.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ba82b6ae6..0388952db 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -64,6 +64,14 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #48** is active at exact head `9eab9d50ae0a202f4c3398ae60fba726c60ccb67` after freezing caller-controlled compensation-review recorded-time evidence as a detached exact UTC instant and documenting the boundary. Its local package suite has `77` tests and exact 100% statement/branch coverage; the current exact-head hosted set has 31 successful, 7 skipped, 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`), with `strix` still in progress when observed. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #54** remains exact head `fd39e07b2ab3490a3ebe0cecd6361f52f162c5d7` after reconciling direct-construction staffing totals, making workforce endpoint aggregation and change deltas independent of ambient Decimal precision, and hardening employment/Position allocation limits under low precision. Its HRIS kernel suite passes 213 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 6 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); no Strix check surfaced for this exact head. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. - **PR #57** remains exact head `4359cfbb4cd8ee5885acb9110d7723099d712353` with a governed selection-validity analysis handoff and aggregate scientific result envelope bound to the reviewed `fast-mlsirm` revision. Its local package suite passes 92 tests with exact 100% statement/branch coverage; the exact-head hosted set has 35 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`). All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #56** is exact head `d0a5207e234e3d9c1ce52c904514cc2504cdda90` after removing bare cross-tenant UUID ownership inference that could reject valid tenant-qualified UUID collisions; its HRIS kernel suite passes 198 tests with exact 100% statement/branch coverage, Ruff, compile, and diff checks. The new exact-head hosted set was still running when recorded (4 completed, 4 skipped, 26 pending of 38 observed); all current review threads were answered/resolved, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #59** remains exact head `3e2eded6e75f16a8a53e106fb11865bc60e77916` with 98 local offer-approval tests and exact 100% statement/branch coverage. Its exact-head hosted set has 24 successful, 4 skipped, and 2 terminal failures (`strix`, `opencode-review`); all current review threads are resolved and no qualifying independent approval exists. +- **PR #60** remains exact head `6417a590e97916782f600aee0c1f05220b42ff9d` with 85 local selection-review tests and exact 100% statement/branch coverage. Its exact-head hosted set has 24 successful, 4 skipped, and 2 terminal failures (`strix`, `opencode-review`); all current review threads are resolved and no qualifying independent approval exists. +- **PR #61** remains exact head `0c957b3207f349ade77e2ade093cb9a0aaedd967` with 90 local candidate-evidence tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. +- **PR #62** remains exact head `6ad5b867bf96561feef4639287ac2183f27921dc` with 75 local requisition-review tests and exact 100% statement/branch coverage. Its exact-head hosted set has 27 successful, 3 skipped, and no terminal failures; all current review threads are resolved and no qualifying independent approval exists. +- **PR #63** is exact head `5c5250953273051276a356ac91ea9a248968c80a` after rejecting nested `TaskEvidence` and `KSAORequirement` subclasses before canonical job-analysis serialization. Its HRIS kernel suite passes 206 tests with exact 100% statement/branch coverage; the exact-head hosted set was still running when recorded with 13 successful, 2 skipped, 1 terminal failure (`dependency-review`), and 14 pending of 45 observed. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #64** remains exact head `c397053ba62dfaf4dd84d6b3d581fccb756e55bb` with 178 local People API tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. +- **PR #65** remains exact head `c8b7f30097a30ab95956d4a73f0a38848cfe9ca1` with 62 local Keyverse authorization/binding tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From c6e55e0c95d94091c749efebd06b3296d9e7b8d8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 01:10:35 +0900 Subject: [PATCH 090/201] docs: refresh organization hierarchy PR evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0388952db..6f65cc289 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -64,7 +64,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #48** is active at exact head `9eab9d50ae0a202f4c3398ae60fba726c60ccb67` after freezing caller-controlled compensation-review recorded-time evidence as a detached exact UTC instant and documenting the boundary. Its local package suite has `77` tests and exact 100% statement/branch coverage; the current exact-head hosted set has 31 successful, 7 skipped, 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`), with `strix` still in progress when observed. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #54** remains exact head `fd39e07b2ab3490a3ebe0cecd6361f52f162c5d7` after reconciling direct-construction staffing totals, making workforce endpoint aggregation and change deltas independent of ambient Decimal precision, and hardening employment/Position allocation limits under low precision. Its HRIS kernel suite passes 213 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 6 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); no Strix check surfaced for this exact head. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. - **PR #57** remains exact head `4359cfbb4cd8ee5885acb9110d7723099d712353` with a governed selection-validity analysis handoff and aggregate scientific result envelope bound to the reviewed `fast-mlsirm` revision. Its local package suite passes 92 tests with exact 100% statement/branch coverage; the exact-head hosted set has 35 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`). All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #56** is exact head `d0a5207e234e3d9c1ce52c904514cc2504cdda90` after removing bare cross-tenant UUID ownership inference that could reject valid tenant-qualified UUID collisions; its HRIS kernel suite passes 198 tests with exact 100% statement/branch coverage, Ruff, compile, and diff checks. The new exact-head hosted set was still running when recorded (4 completed, 4 skipped, 26 pending of 38 observed); all current review threads were answered/resolved, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #56** is exact head `68af42cb80807b6638d745d1687fd3c6a814d64f` after removing bare cross-tenant UUID ownership inference that could reject valid tenant-qualified UUID collisions and aligning the builder exception contract. Its HRIS kernel suite passes 198 tests with exact 100% statement/branch coverage, Ruff, compile, and diff checks. The new exact-head hosted set was still running when recorded (3 skipped, 2 in progress, 25 queued of 39 observed); all current review threads were answered/resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #59** remains exact head `3e2eded6e75f16a8a53e106fb11865bc60e77916` with 98 local offer-approval tests and exact 100% statement/branch coverage. Its exact-head hosted set has 24 successful, 4 skipped, and 2 terminal failures (`strix`, `opencode-review`); all current review threads are resolved and no qualifying independent approval exists. - **PR #60** remains exact head `6417a590e97916782f600aee0c1f05220b42ff9d` with 85 local selection-review tests and exact 100% statement/branch coverage. Its exact-head hosted set has 24 successful, 4 skipped, and 2 terminal failures (`strix`, `opencode-review`); all current review threads are resolved and no qualifying independent approval exists. - **PR #61** remains exact head `0c957b3207f349ade77e2ade093cb9a0aaedd967` with 90 local candidate-evidence tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. From 5f96c569ccbd63533e3bfa12a7cdb5b9f21e38c9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 01:36:28 +0900 Subject: [PATCH 091/201] docs: record interval and position review evidence --- docs/product-technical-gap-baseline.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6f65cc289..9d2d28695 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -72,6 +72,10 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #63** is exact head `5c5250953273051276a356ac91ea9a248968c80a` after rejecting nested `TaskEvidence` and `KSAORequirement` subclasses before canonical job-analysis serialization. Its HRIS kernel suite passes 206 tests with exact 100% statement/branch coverage; the exact-head hosted set was still running when recorded with 13 successful, 2 skipped, 1 terminal failure (`dependency-review`), and 14 pending of 45 observed. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #64** remains exact head `c397053ba62dfaf4dd84d6b3d581fccb756e55bb` with 178 local People API tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. - **PR #65** remains exact head `c8b7f30097a30ab95956d4a73f0a38848cfe9ca1` with 62 local Keyverse authorization/binding tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. +- **PR #68** is exact head `ffb0f2b55d5d5bd543bc5b94e56f1d9b7e4b1271` after making the adversarial calendar-response equality and inequality fixture consistent so exact-type validation cannot be bypassed. Its Naruon adapter suite passes 45 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`). All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #69** is exact head `6fdf537463c32fdd50daec477d571ce97d60fc3f` after rejecting caller-controlled `timedelta` subclasses during recorded-time canonicalization and synchronizing the protected-`develop` SHA in the changelog. Its HRIS kernel suite passes 186 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass for the documentation follow-up. The newly restarted exact-head hosted set currently has 4 successful, 31 pending, and 6 skipped checks with no terminal failure observed; all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #70** is exact head `e4624c0fb4034fe53654ed661e32156f9e14c31e` after rejecting every overlapping recorded-visible PositionVersion pair for one seat, including same-status duplicates, and aligning ADR 0005 with the single-valued persistence contract. Its HRIS kernel suite passes 173 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass. The exact-head hosted set was restarted with 2 successful and 34 pending checks plus 7 skipped checks; all current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #71** remains exact head `1d7ed5bbfb18b35d589c69a6e8d93754ba299589` with hardened value-free migration-handoff runtime checks for exact text, integer, target, dependency-revision, and envelope-mode types. Its migration-adapter suite passes 71 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful and 8 skipped checks, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 8505883ca1034e1a26e41850cacc4fac50c2ef31 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 01:59:47 +0900 Subject: [PATCH 092/201] docs: record criterion chronology review evidence --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9d2d28695..281550728 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -76,6 +76,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #69** is exact head `6fdf537463c32fdd50daec477d571ce97d60fc3f` after rejecting caller-controlled `timedelta` subclasses during recorded-time canonicalization and synchronizing the protected-`develop` SHA in the changelog. Its HRIS kernel suite passes 186 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass for the documentation follow-up. The newly restarted exact-head hosted set currently has 4 successful, 31 pending, and 6 skipped checks with no terminal failure observed; all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #70** is exact head `e4624c0fb4034fe53654ed661e32156f9e14c31e` after rejecting every overlapping recorded-visible PositionVersion pair for one seat, including same-status duplicates, and aligning ADR 0005 with the single-valued persistence contract. Its HRIS kernel suite passes 173 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass. The exact-head hosted set was restarted with 2 successful and 34 pending checks plus 7 skipped checks; all current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #71** remains exact head `1d7ed5bbfb18b35d589c69a6e8d93754ba299589` with hardened value-free migration-handoff runtime checks for exact text, integer, target, dependency-revision, and envelope-mode types. Its migration-adapter suite passes 71 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful and 8 skipped checks, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #72** is exact head `585498a8d135d1707531112b4b295a17e9933bff` after moving the criterion chronology guard into sequential migration `0014`, preserving protected-base migration `0011` and its trigger binding, and rejecting caller-ordered timestamps plus future `observed_at` and `recorded_from` values relative to statement time. Foundation validation and the 55 Node contract tests pass locally; local PostgreSQL tooling is unavailable. Its exact-head hosted set has 36 successful, 7 skipped, 2 in progress, 1 pending, and 2 terminal failures (`opencode-review` and `dependency-review`); all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 865379e51f9013388ce33ec181a86fedefcf33db Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 02:02:59 +0900 Subject: [PATCH 093/201] docs: record correction-boundary review evidence --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 281550728..c6dd979ee 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -77,6 +77,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #70** is exact head `e4624c0fb4034fe53654ed661e32156f9e14c31e` after rejecting every overlapping recorded-visible PositionVersion pair for one seat, including same-status duplicates, and aligning ADR 0005 with the single-valued persistence contract. Its HRIS kernel suite passes 173 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass. The exact-head hosted set was restarted with 2 successful and 34 pending checks plus 7 skipped checks; all current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #71** remains exact head `1d7ed5bbfb18b35d589c69a6e8d93754ba299589` with hardened value-free migration-handoff runtime checks for exact text, integer, target, dependency-revision, and envelope-mode types. Its migration-adapter suite passes 71 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful and 8 skipped checks, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #72** is exact head `585498a8d135d1707531112b4b295a17e9933bff` after moving the criterion chronology guard into sequential migration `0014`, preserving protected-base migration `0011` and its trigger binding, and rejecting caller-ordered timestamps plus future `observed_at` and `recorded_from` values relative to statement time. Foundation validation and the 55 Node contract tests pass locally; local PostgreSQL tooling is unavailable. Its exact-head hosted set has 36 successful, 7 skipped, 2 in progress, 1 pending, and 2 terminal failures (`opencode-review` and `dependency-review`); all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #73** remains exact head `b4cad54cf6067b672c71eb41c87fd62d75097bb3` after hardening the recorded-correction boundary to the four authoritative HRIS fact types, exact `RecordedInterval`, and exact built-in datetime endpoints. Its full HRIS-kernel suite passes 176 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 40 successful, 6 skipped, and 1 terminal failure (`opencode-review`); no exact-head Strix evidence, qualifying independent approval, or unresolved review thread exists, so it remains active-PR truth only. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 98c815fbdd4ae4bdb834a93e3646f7248c8960f4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 02:05:47 +0900 Subject: [PATCH 094/201] docs: record people operability review evidence --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c6dd979ee..0f782c443 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -78,6 +78,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #71** remains exact head `1d7ed5bbfb18b35d589c69a6e8d93754ba299589` with hardened value-free migration-handoff runtime checks for exact text, integer, target, dependency-revision, and envelope-mode types. Its migration-adapter suite passes 71 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful and 8 skipped checks, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #72** is exact head `585498a8d135d1707531112b4b295a17e9933bff` after moving the criterion chronology guard into sequential migration `0014`, preserving protected-base migration `0011` and its trigger binding, and rejecting caller-ordered timestamps plus future `observed_at` and `recorded_from` values relative to statement time. Foundation validation and the 55 Node contract tests pass locally; local PostgreSQL tooling is unavailable. Its exact-head hosted set has 36 successful, 7 skipped, 2 in progress, 1 pending, and 2 terminal failures (`opencode-review` and `dependency-review`); all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #73** remains exact head `b4cad54cf6067b672c71eb41c87fd62d75097bb3` after hardening the recorded-correction boundary to the four authoritative HRIS fact types, exact `RecordedInterval`, and exact built-in datetime endpoints. Its full HRIS-kernel suite passes 176 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 40 successful, 6 skipped, and 1 terminal failure (`opencode-review`); no exact-head Strix evidence, qualifying independent approval, or unresolved review thread exists, so it remains active-PR truth only. +- **PR #74** remains exact head `7d75e683b5bca2881f70e4447e69b3de80babd00` with dependency-free `/health` liveness and owned-PostgreSQL `/ready` readiness offloaded from the ASGI event loop. Its People API suite passes 157 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); Noema is terminal GREEN, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 6f6bc3468aeade4f4175e49166fb5da1fe82becc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 02:15:48 +0900 Subject: [PATCH 095/201] docs: record governed export review evidence --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0f782c443..83a0d4cdb 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -79,6 +79,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #72** is exact head `585498a8d135d1707531112b4b295a17e9933bff` after moving the criterion chronology guard into sequential migration `0014`, preserving protected-base migration `0011` and its trigger binding, and rejecting caller-ordered timestamps plus future `observed_at` and `recorded_from` values relative to statement time. Foundation validation and the 55 Node contract tests pass locally; local PostgreSQL tooling is unavailable. Its exact-head hosted set has 36 successful, 7 skipped, 2 in progress, 1 pending, and 2 terminal failures (`opencode-review` and `dependency-review`); all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #73** remains exact head `b4cad54cf6067b672c71eb41c87fd62d75097bb3` after hardening the recorded-correction boundary to the four authoritative HRIS fact types, exact `RecordedInterval`, and exact built-in datetime endpoints. Its full HRIS-kernel suite passes 176 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 40 successful, 6 skipped, and 1 terminal failure (`opencode-review`); no exact-head Strix evidence, qualifying independent approval, or unresolved review thread exists, so it remains active-PR truth only. - **PR #74** remains exact head `7d75e683b5bca2881f70e4447e69b3de80babd00` with dependency-free `/health` liveness and owned-PostgreSQL `/ready` readiness offloaded from the ASGI event loop. Its People API suite passes 157 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); Noema is terminal GREEN, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #75** remains Draft at exact head `968111f88d59f340f78afd5f6aea2291221bffa1` with a value-minimized, human-reviewed HR data export control packet that never exports values or authorizes egress. Its focused package suite passes 65 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 33 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, and `strix`); the failures are missing OpenCode current-head verdict and contextual-orchestrator sidecar provisioning failures before Noema/Strix review, not local package failures. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and the Draft state remains authoritative; it is active-PR truth only and must not transfer evidence to stacked child #120. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From f393350e531e9766dcacc8301b5e2ab874757c57 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 02:45:42 +0900 Subject: [PATCH 096/201] docs: record retention disposition review evidence --- docs/product-technical-gap-baseline.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 83a0d4cdb..db095e521 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -80,6 +80,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #73** remains exact head `b4cad54cf6067b672c71eb41c87fd62d75097bb3` after hardening the recorded-correction boundary to the four authoritative HRIS fact types, exact `RecordedInterval`, and exact built-in datetime endpoints. Its full HRIS-kernel suite passes 176 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 40 successful, 6 skipped, and 1 terminal failure (`opencode-review`); no exact-head Strix evidence, qualifying independent approval, or unresolved review thread exists, so it remains active-PR truth only. - **PR #74** remains exact head `7d75e683b5bca2881f70e4447e69b3de80babd00` with dependency-free `/health` liveness and owned-PostgreSQL `/ready` readiness offloaded from the ASGI event loop. Its People API suite passes 157 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); Noema is terminal GREEN, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #75** remains Draft at exact head `968111f88d59f340f78afd5f6aea2291221bffa1` with a value-minimized, human-reviewed HR data export control packet that never exports values or authorizes egress. Its focused package suite passes 65 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 33 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, and `strix`); the failures are missing OpenCode current-head verdict and contextual-orchestrator sidecar provisioning failures before Noema/Strix review, not local package failures. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and the Draft state remains authoritative; it is active-PR truth only and must not transfer evidence to stacked child #120. +- **PR #76** remains open/non-draft at exact head `a48632c9862f54f128790be6e33bd1736f228f73` for the governed HR retention review packet. Its focused suite passes 52 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 22 successful, 7 skipped, 2 terminal failures (`opencode-review` and `dependency-review`), and 10 in progress; `noema-review`, `strix`, Semgrep, Devin Review, and PostgreSQL contract jobs are not terminally successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; it remains active-PR truth only and must not transfer evidence to child #120. +- **PR #77** remains open/non-draft at exact head `0df26b073b32219b91b2c0f872dfabaa15226fc6` on stacked base `fe9caec106f915d7ff309868c64cccf1bf8bceb4`, adding the separate non-authorizing HR disposition request boundary. Its focused suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head dedicated contract Check is in progress, Devin Review is pending/analyzing, and CodeRabbit is successful only because review is skipped for the stacked base branch. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=unstable`; parent #76 remains unmerged, so no parent/child evidence transfers. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 46efa2c23ce5bb2140a30162846f35b4bb31d23e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 02:49:13 +0900 Subject: [PATCH 097/201] docs: refresh correction PR exact-head evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index db095e521..540811aa1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -77,7 +77,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #70** is exact head `e4624c0fb4034fe53654ed661e32156f9e14c31e` after rejecting every overlapping recorded-visible PositionVersion pair for one seat, including same-status duplicates, and aligning ADR 0005 with the single-valued persistence contract. Its HRIS kernel suite passes 173 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass. The exact-head hosted set was restarted with 2 successful and 34 pending checks plus 7 skipped checks; all current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #71** remains exact head `1d7ed5bbfb18b35d589c69a6e8d93754ba299589` with hardened value-free migration-handoff runtime checks for exact text, integer, target, dependency-revision, and envelope-mode types. Its migration-adapter suite passes 71 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful and 8 skipped checks, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #72** is exact head `585498a8d135d1707531112b4b295a17e9933bff` after moving the criterion chronology guard into sequential migration `0014`, preserving protected-base migration `0011` and its trigger binding, and rejecting caller-ordered timestamps plus future `observed_at` and `recorded_from` values relative to statement time. Foundation validation and the 55 Node contract tests pass locally; local PostgreSQL tooling is unavailable. Its exact-head hosted set has 36 successful, 7 skipped, 2 in progress, 1 pending, and 2 terminal failures (`opencode-review` and `dependency-review`); all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #73** remains exact head `b4cad54cf6067b672c71eb41c87fd62d75097bb3` after hardening the recorded-correction boundary to the four authoritative HRIS fact types, exact `RecordedInterval`, and exact built-in datetime endpoints. Its full HRIS-kernel suite passes 176 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 40 successful, 6 skipped, and 1 terminal failure (`opencode-review`); no exact-head Strix evidence, qualifying independent approval, or unresolved review thread exists, so it remains active-PR truth only. +- **PR #73** remains exact head `acaebb70d777bf4aecbe64d0e71430c0ec0fefa3` after hardening the recorded-correction boundary to the four authoritative HRIS fact types, exact `RecordedInterval`, exact built-in datetime endpoints, and detached built-in fixed-offset timezone evidence. Its full HRIS-kernel suite passes 180 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 36 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`); Devin Review is successful but no authoritative Strix report or OpenCode/Noema protected verdict is available. All current review threads are resolved and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #74** remains exact head `7d75e683b5bca2881f70e4447e69b3de80babd00` with dependency-free `/health` liveness and owned-PostgreSQL `/ready` readiness offloaded from the ASGI event loop. Its People API suite passes 157 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); Noema is terminal GREEN, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #75** remains Draft at exact head `968111f88d59f340f78afd5f6aea2291221bffa1` with a value-minimized, human-reviewed HR data export control packet that never exports values or authorizes egress. Its focused package suite passes 65 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 33 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, and `strix`); the failures are missing OpenCode current-head verdict and contextual-orchestrator sidecar provisioning failures before Noema/Strix review, not local package failures. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and the Draft state remains authoritative; it is active-PR truth only and must not transfer evidence to stacked child #120. - **PR #76** remains open/non-draft at exact head `a48632c9862f54f128790be6e33bd1736f228f73` for the governed HR retention review packet. Its focused suite passes 52 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 22 successful, 7 skipped, 2 terminal failures (`opencode-review` and `dependency-review`), and 10 in progress; `noema-review`, `strix`, Semgrep, Devin Review, and PostgreSQL contract jobs are not terminally successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; it remains active-PR truth only and must not transfer evidence to child #120. From 963c9c6067a85a4cc3d12b1dfc5f91b9d41ea7da Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 03:04:00 +0900 Subject: [PATCH 098/201] docs: record release candidate evidence status --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 540811aa1..8c06f962a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -82,6 +82,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #75** remains Draft at exact head `968111f88d59f340f78afd5f6aea2291221bffa1` with a value-minimized, human-reviewed HR data export control packet that never exports values or authorizes egress. Its focused package suite passes 65 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 33 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, and `strix`); the failures are missing OpenCode current-head verdict and contextual-orchestrator sidecar provisioning failures before Noema/Strix review, not local package failures. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and the Draft state remains authoritative; it is active-PR truth only and must not transfer evidence to stacked child #120. - **PR #76** remains open/non-draft at exact head `a48632c9862f54f128790be6e33bd1736f228f73` for the governed HR retention review packet. Its focused suite passes 52 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 22 successful, 7 skipped, 2 terminal failures (`opencode-review` and `dependency-review`), and 10 in progress; `noema-review`, `strix`, Semgrep, Devin Review, and PostgreSQL contract jobs are not terminally successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; it remains active-PR truth only and must not transfer evidence to child #120. - **PR #77** remains open/non-draft at exact head `0df26b073b32219b91b2c0f872dfabaa15226fc6` on stacked base `fe9caec106f915d7ff309868c64cccf1bf8bceb4`, adding the separate non-authorizing HR disposition request boundary. Its focused suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head dedicated contract Check is in progress, Devin Review is pending/analyzing, and CodeRabbit is successful only because review is skipped for the stacked base branch. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=unstable`; parent #76 remains unmerged, so no parent/child evidence transfers. +- **PR #78** remains open/non-draft at exact head `c07211cfbc678b6e02d373bca9c3015673983c71` for reproducible release-candidate source, SBOM, and unsigned provenance evidence. The pinned-runtime Node harness passes with CPython 3.14.7, producing byte-identical archive/SBOM/provenance artifacts across isolated builds; compileall and diff checks pass. Its exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review and CodeRabbit are successful, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the unsigned evidence is active-PR truth only and does not authorize a release. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From a2978fbfe7488d159aec253e5719f5139100e147 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 03:10:43 +0900 Subject: [PATCH 099/201] docs: record Kubernetes reference review evidence --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8c06f962a..faa7b4f0f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -83,6 +83,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #76** remains open/non-draft at exact head `a48632c9862f54f128790be6e33bd1736f228f73` for the governed HR retention review packet. Its focused suite passes 52 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 22 successful, 7 skipped, 2 terminal failures (`opencode-review` and `dependency-review`), and 10 in progress; `noema-review`, `strix`, Semgrep, Devin Review, and PostgreSQL contract jobs are not terminally successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; it remains active-PR truth only and must not transfer evidence to child #120. - **PR #77** remains open/non-draft at exact head `0df26b073b32219b91b2c0f872dfabaa15226fc6` on stacked base `fe9caec106f915d7ff309868c64cccf1bf8bceb4`, adding the separate non-authorizing HR disposition request boundary. Its focused suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head dedicated contract Check is in progress, Devin Review is pending/analyzing, and CodeRabbit is successful only because review is skipped for the stacked base branch. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=unstable`; parent #76 remains unmerged, so no parent/child evidence transfers. - **PR #78** remains open/non-draft at exact head `c07211cfbc678b6e02d373bca9c3015673983c71` for reproducible release-candidate source, SBOM, and unsigned provenance evidence. The pinned-runtime Node harness passes with CPython 3.14.7, producing byte-identical archive/SBOM/provenance artifacts across isolated builds; compileall and diff checks pass. Its exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review and CodeRabbit are successful, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the unsigned evidence is active-PR truth only and does not authorize a release. +- **PR #79** remains open/non-draft at exact head `3f8a2826396aceb51fb78e14bf12dde713f99b0c` for the hardened Kubernetes People API reference deployment. Its local Kubernetes contract passes 8/8 and foundation validation passes 55/55; the exact-head hosted set has 37 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review is successful and all review threads are resolved, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the sentinel image and cluster adaptation remain separate release/operations controls. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From e804d057e9ab6a60a4b83657cdb5e59071c072ad Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 03:28:05 +0900 Subject: [PATCH 100/201] docs: refresh criterion chronology evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index faa7b4f0f..1578a4751 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -76,7 +76,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #69** is exact head `6fdf537463c32fdd50daec477d571ce97d60fc3f` after rejecting caller-controlled `timedelta` subclasses during recorded-time canonicalization and synchronizing the protected-`develop` SHA in the changelog. Its HRIS kernel suite passes 186 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass for the documentation follow-up. The newly restarted exact-head hosted set currently has 4 successful, 31 pending, and 6 skipped checks with no terminal failure observed; all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #70** is exact head `e4624c0fb4034fe53654ed661e32156f9e14c31e` after rejecting every overlapping recorded-visible PositionVersion pair for one seat, including same-status duplicates, and aligning ADR 0005 with the single-valued persistence contract. Its HRIS kernel suite passes 173 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass. The exact-head hosted set was restarted with 2 successful and 34 pending checks plus 7 skipped checks; all current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #71** remains exact head `1d7ed5bbfb18b35d589c69a6e8d93754ba299589` with hardened value-free migration-handoff runtime checks for exact text, integer, target, dependency-revision, and envelope-mode types. Its migration-adapter suite passes 71 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful and 8 skipped checks, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #72** is exact head `585498a8d135d1707531112b4b295a17e9933bff` after moving the criterion chronology guard into sequential migration `0014`, preserving protected-base migration `0011` and its trigger binding, and rejecting caller-ordered timestamps plus future `observed_at` and `recorded_from` values relative to statement time. Foundation validation and the 55 Node contract tests pass locally; local PostgreSQL tooling is unavailable. Its exact-head hosted set has 36 successful, 7 skipped, 2 in progress, 1 pending, and 2 terminal failures (`opencode-review` and `dependency-review`); all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. +- **PR #72** is exact head `a8ddab514ebf5e09c44186862884b4b9b4e6f4dd` after preserving protected-base migration `0011` and its trigger binding, applying chronology enforcement in `0014`, and changing omitted observation `recorded_from` to `statement_timestamp()` in sequential migration `0015` so valid inserts after a long transaction begins are not rejected. Foundation validation and the 55 Node contract tests pass locally; the pinned PostgreSQL 16.14 criterion contract passes, including the long-transaction default regression. Its current exact-head hosted set has 11 successful, 6 skipped, 1 terminal failure (`dependency-review`), and 24 in progress; Devin Review is pending/analyzing, CodeRabbit is successful but rate limited, all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`, so it remains active-PR truth only. - **PR #73** remains exact head `acaebb70d777bf4aecbe64d0e71430c0ec0fefa3` after hardening the recorded-correction boundary to the four authoritative HRIS fact types, exact `RecordedInterval`, exact built-in datetime endpoints, and detached built-in fixed-offset timezone evidence. Its full HRIS-kernel suite passes 180 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 36 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`); Devin Review is successful but no authoritative Strix report or OpenCode/Noema protected verdict is available. All current review threads are resolved and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #74** remains exact head `7d75e683b5bca2881f70e4447e69b3de80babd00` with dependency-free `/health` liveness and owned-PostgreSQL `/ready` readiness offloaded from the ASGI event loop. Its People API suite passes 157 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); Noema is terminal GREEN, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #75** remains Draft at exact head `968111f88d59f340f78afd5f6aea2291221bffa1` with a value-minimized, human-reviewed HR data export control packet that never exports values or authorizes egress. Its focused package suite passes 65 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 33 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, and `strix`); the failures are missing OpenCode current-head verdict and contextual-orchestrator sidecar provisioning failures before Noema/Strix review, not local package failures. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and the Draft state remains authoritative; it is active-PR truth only and must not transfer evidence to stacked child #120. From 2f5998b634df113f65f6f754881bd8f134556b4b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 03:32:43 +0900 Subject: [PATCH 101/201] docs: record candidate offer response review evidence --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1578a4751..1e8600870 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -84,6 +84,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #77** remains open/non-draft at exact head `0df26b073b32219b91b2c0f872dfabaa15226fc6` on stacked base `fe9caec106f915d7ff309868c64cccf1bf8bceb4`, adding the separate non-authorizing HR disposition request boundary. Its focused suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head dedicated contract Check is in progress, Devin Review is pending/analyzing, and CodeRabbit is successful only because review is skipped for the stacked base branch. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=unstable`; parent #76 remains unmerged, so no parent/child evidence transfers. - **PR #78** remains open/non-draft at exact head `c07211cfbc678b6e02d373bca9c3015673983c71` for reproducible release-candidate source, SBOM, and unsigned provenance evidence. The pinned-runtime Node harness passes with CPython 3.14.7, producing byte-identical archive/SBOM/provenance artifacts across isolated builds; compileall and diff checks pass. Its exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review and CodeRabbit are successful, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the unsigned evidence is active-PR truth only and does not authorize a release. - **PR #79** remains open/non-draft at exact head `3f8a2826396aceb51fb78e14bf12dde713f99b0c` for the hardened Kubernetes People API reference deployment. Its local Kubernetes contract passes 8/8 and foundation validation passes 55/55; the exact-head hosted set has 37 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review is successful and all review threads are resolved, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the sentinel image and cluster adaptation remain separate release/operations controls. +- **PR #80** remains open/non-draft at exact head `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702` for value-minimized candidate offer acceptance/decline evidence that grants no hire authority and does not mutate Keyverse. Its focused package suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure; Devin Review is successful and CodeRabbit is successful with a rate-limit description. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; Keyverse remains read-only and child #108 is dependency-first. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 9c980e6edf7b93409c0d5f654d01c05e489ab0ec Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 03:40:48 +0900 Subject: [PATCH 102/201] docs: record contextual orchestrator draft evidence status --- docs/product-technical-gap-baseline.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1e8600870..59de938b5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -81,10 +81,11 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #74** remains exact head `7d75e683b5bca2881f70e4447e69b3de80babd00` with dependency-free `/health` liveness and owned-PostgreSQL `/ready` readiness offloaded from the ASGI event loop. Its People API suite passes 157 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); Noema is terminal GREEN, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #75** remains Draft at exact head `968111f88d59f340f78afd5f6aea2291221bffa1` with a value-minimized, human-reviewed HR data export control packet that never exports values or authorizes egress. Its focused package suite passes 65 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 33 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, and `strix`); the failures are missing OpenCode current-head verdict and contextual-orchestrator sidecar provisioning failures before Noema/Strix review, not local package failures. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and the Draft state remains authoritative; it is active-PR truth only and must not transfer evidence to stacked child #120. - **PR #76** remains open/non-draft at exact head `a48632c9862f54f128790be6e33bd1736f228f73` for the governed HR retention review packet. Its focused suite passes 52 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 22 successful, 7 skipped, 2 terminal failures (`opencode-review` and `dependency-review`), and 10 in progress; `noema-review`, `strix`, Semgrep, Devin Review, and PostgreSQL contract jobs are not terminally successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; it remains active-PR truth only and must not transfer evidence to child #120. -- **PR #77** remains open/non-draft at exact head `0df26b073b32219b91b2c0f872dfabaa15226fc6` on stacked base `fe9caec106f915d7ff309868c64cccf1bf8bceb4`, adding the separate non-authorizing HR disposition request boundary. Its focused suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head dedicated contract Check is in progress, Devin Review is pending/analyzing, and CodeRabbit is successful only because review is skipped for the stacked base branch. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=unstable`; parent #76 remains unmerged, so no parent/child evidence transfers. +- **PR #77** remains open/non-draft at exact head `0df26b073b32219b91b2c0f872dfabaa15226fc6` on stacked base `fe9caec106f915d7ff309868c64cccf1bf8bceb4`, adding the separate non-authorizing HR disposition request boundary. Its focused suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head dedicated contract Check is terminal successful, Devin Review is successful, and CodeRabbit is successful only because review is skipped for the stacked base branch. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=CLEAN`; parent #76 remains unmerged, so no parent/child evidence transfers. - **PR #78** remains open/non-draft at exact head `c07211cfbc678b6e02d373bca9c3015673983c71` for reproducible release-candidate source, SBOM, and unsigned provenance evidence. The pinned-runtime Node harness passes with CPython 3.14.7, producing byte-identical archive/SBOM/provenance artifacts across isolated builds; compileall and diff checks pass. Its exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review and CodeRabbit are successful, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the unsigned evidence is active-PR truth only and does not authorize a release. - **PR #79** remains open/non-draft at exact head `3f8a2826396aceb51fb78e14bf12dde713f99b0c` for the hardened Kubernetes People API reference deployment. Its local Kubernetes contract passes 8/8 and foundation validation passes 55/55; the exact-head hosted set has 37 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review is successful and all review threads are resolved, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the sentinel image and cluster adaptation remain separate release/operations controls. - **PR #80** remains open/non-draft at exact head `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702` for value-minimized candidate offer acceptance/decline evidence that grants no hire authority and does not mutate Keyverse. Its focused package suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure; Devin Review is successful and CodeRabbit is successful with a rate-limit description. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; Keyverse remains read-only and child #108 is dependency-first. +- **PR #81** remains open and Draft at exact head `e8bd6b28eb335d01c366869f044fbce0005d91dd` for the Orgmetra-owned, value-minimized Contextual Orchestrator draft-evidence boundary. Its focused suite passes 36 tests with exact 100% statement/branch coverage; compileall, Ruff, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure or in-progress run, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, Foundation, and package-quality evidence where applicable. Devin Review and CodeRabbit are successful; all current review threads are resolved, but no qualifying independent approval exists, `reviewDecision=REVIEW_REQUIRED`, and GitHub reports `mergeStateStatus=BLOCKED`. Its Draft state is intentionally not changed because a separate lifecycle writer owns that transition; model output remains `untrusted_draft`, requires human review, and carries no employment-decision authority. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 9431bac611495749037e13d21198d88dcdc6ebf8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 03:47:39 +0900 Subject: [PATCH 103/201] docs: record outbox retry policy status --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 59de938b5..9e2d5a035 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -86,6 +86,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #79** remains open/non-draft at exact head `3f8a2826396aceb51fb78e14bf12dde713f99b0c` for the hardened Kubernetes People API reference deployment. Its local Kubernetes contract passes 8/8 and foundation validation passes 55/55; the exact-head hosted set has 37 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review is successful and all review threads are resolved, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the sentinel image and cluster adaptation remain separate release/operations controls. - **PR #80** remains open/non-draft at exact head `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702` for value-minimized candidate offer acceptance/decline evidence that grants no hire authority and does not mutate Keyverse. Its focused package suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure; Devin Review is successful and CodeRabbit is successful with a rate-limit description. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; Keyverse remains read-only and child #108 is dependency-first. - **PR #81** remains open and Draft at exact head `e8bd6b28eb335d01c366869f044fbce0005d91dd` for the Orgmetra-owned, value-minimized Contextual Orchestrator draft-evidence boundary. Its focused suite passes 36 tests with exact 100% statement/branch coverage; compileall, Ruff, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure or in-progress run, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, Foundation, and package-quality evidence where applicable. Devin Review and CodeRabbit are successful; all current review threads are resolved, but no qualifying independent approval exists, `reviewDecision=REVIEW_REQUIRED`, and GitHub reports `mergeStateStatus=BLOCKED`. Its Draft state is intentionally not changed because a separate lifecycle writer owns that transition; model output remains `untrusted_draft`, requires human review, and carries no employment-decision authority. +- **PR #82** remains open/non-draft at exact head `3d6d4791358b82f2840dd0dd201a0407e6e88a6e`, stacked on PR #51 (`docs/protected-truth-refresh`). Its pinned PostgreSQL retry-policy contract passes, as do foundation validation (61/61), shell syntax, and diff checks. The PR base metadata is `b25ac55556e8868da42c0f4c1466bc04cee95dfb`, while the moved base branch tip is `aa33f8f9f2a7c0a72c91947e3edac90334bcaabf`; GitHub reports `mergeStateStatus=DIRTY`/conflicting and exact-head hosted Checks are absent because the child targets the stacked branch. No qualifying independent approval exists and all current review threads are resolved; do not rebase by force-push, transfer parent evidence, or merge before #51 integrates and #82 is retargeted/revalidated against fresh `develop`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From e5eb4adf3adc99ea79672fcb1da41cd4ef5d8843 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 03:52:46 +0900 Subject: [PATCH 104/201] docs: record semantic job evidence status --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9e2d5a035..e576d44b2 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -87,6 +87,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #80** remains open/non-draft at exact head `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702` for value-minimized candidate offer acceptance/decline evidence that grants no hire authority and does not mutate Keyverse. Its focused package suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure; Devin Review is successful and CodeRabbit is successful with a rate-limit description. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; Keyverse remains read-only and child #108 is dependency-first. - **PR #81** remains open and Draft at exact head `e8bd6b28eb335d01c366869f044fbce0005d91dd` for the Orgmetra-owned, value-minimized Contextual Orchestrator draft-evidence boundary. Its focused suite passes 36 tests with exact 100% statement/branch coverage; compileall, Ruff, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure or in-progress run, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, Foundation, and package-quality evidence where applicable. Devin Review and CodeRabbit are successful; all current review threads are resolved, but no qualifying independent approval exists, `reviewDecision=REVIEW_REQUIRED`, and GitHub reports `mergeStateStatus=BLOCKED`. Its Draft state is intentionally not changed because a separate lifecycle writer owns that transition; model output remains `untrusted_draft`, requires human review, and carries no employment-decision authority. - **PR #82** remains open/non-draft at exact head `3d6d4791358b82f2840dd0dd201a0407e6e88a6e`, stacked on PR #51 (`docs/protected-truth-refresh`). Its pinned PostgreSQL retry-policy contract passes, as do foundation validation (61/61), shell syntax, and diff checks. The PR base metadata is `b25ac55556e8868da42c0f4c1466bc04cee95dfb`, while the moved base branch tip is `aa33f8f9f2a7c0a72c91947e3edac90334bcaabf`; GitHub reports `mergeStateStatus=DIRTY`/conflicting and exact-head hosted Checks are absent because the child targets the stacked branch. No qualifying independent approval exists and all current review threads are resolved; do not rebase by force-push, transfer parent evidence, or merge before #51 integrates and #82 is retargeted/revalidated against fresh `develop`. +- **PR #83** remains open/non-draft at exact head `c340e7599f147b25fab4c94cd2042a96d6128235` for the Orgmetra-owned Semantic Data Portal ontology evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, and diff checks. The actor trust boundary now requires opaque canonical `actor:` UUIDv4 correlations; human-readable actor handles are rejected. The exact-head hosted snapshot has 11 successful, 6 skipped, 1 terminal `dependency-review` failure, and 29 in progress; Devin Review and CodeRabbit are pending/analyzing. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 30743025a3863a4313f403e276b6446b1c1462a1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:00:21 +0900 Subject: [PATCH 105/201] docs: record psychometrics evidence PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e576d44b2..024121f1a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -88,6 +88,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #81** remains open and Draft at exact head `e8bd6b28eb335d01c366869f044fbce0005d91dd` for the Orgmetra-owned, value-minimized Contextual Orchestrator draft-evidence boundary. Its focused suite passes 36 tests with exact 100% statement/branch coverage; compileall, Ruff, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure or in-progress run, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, Foundation, and package-quality evidence where applicable. Devin Review and CodeRabbit are successful; all current review threads are resolved, but no qualifying independent approval exists, `reviewDecision=REVIEW_REQUIRED`, and GitHub reports `mergeStateStatus=BLOCKED`. Its Draft state is intentionally not changed because a separate lifecycle writer owns that transition; model output remains `untrusted_draft`, requires human review, and carries no employment-decision authority. - **PR #82** remains open/non-draft at exact head `3d6d4791358b82f2840dd0dd201a0407e6e88a6e`, stacked on PR #51 (`docs/protected-truth-refresh`). Its pinned PostgreSQL retry-policy contract passes, as do foundation validation (61/61), shell syntax, and diff checks. The PR base metadata is `b25ac55556e8868da42c0f4c1466bc04cee95dfb`, while the moved base branch tip is `aa33f8f9f2a7c0a72c91947e3edac90334bcaabf`; GitHub reports `mergeStateStatus=DIRTY`/conflicting and exact-head hosted Checks are absent because the child targets the stacked branch. No qualifying independent approval exists and all current review threads are resolved; do not rebase by force-push, transfer parent evidence, or merge before #51 integrates and #82 is retargeted/revalidated against fresh `develop`. - **PR #83** remains open/non-draft at exact head `c340e7599f147b25fab4c94cd2042a96d6128235` for the Orgmetra-owned Semantic Data Portal ontology evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, and diff checks. The actor trust boundary now requires opaque canonical `actor:` UUIDv4 correlations; human-readable actor handles are rejected. The exact-head hosted snapshot has 11 successful, 6 skipped, 1 terminal `dependency-review` failure, and 29 in progress; Devin Review and CodeRabbit are pending/analyzing. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #85** remains open/non-draft at exact head `199e37799802815fbc82aecfdad6ff8d0970a62d` for the Orgmetra-owned psychometrics result evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, diff checks, and CodeGraph reindexing. The integrity boundary now emits the exact payload and canonical JSON snapshot that passed creation-seal verification, with regressions for both export APIs. The exact-head hosted snapshot has 3 successful, 6 skipped, 1 terminal `dependency-review` failure, and 25 queued/in progress; Devin is pending analysis and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From bbe269accfbd516adf53cd34eacd5fbad9f86f2d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:05:27 +0900 Subject: [PATCH 106/201] docs: record keyverse lifecycle PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 024121f1a..0a41dd8cb 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -89,6 +89,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #82** remains open/non-draft at exact head `3d6d4791358b82f2840dd0dd201a0407e6e88a6e`, stacked on PR #51 (`docs/protected-truth-refresh`). Its pinned PostgreSQL retry-policy contract passes, as do foundation validation (61/61), shell syntax, and diff checks. The PR base metadata is `b25ac55556e8868da42c0f4c1466bc04cee95dfb`, while the moved base branch tip is `aa33f8f9f2a7c0a72c91947e3edac90334bcaabf`; GitHub reports `mergeStateStatus=DIRTY`/conflicting and exact-head hosted Checks are absent because the child targets the stacked branch. No qualifying independent approval exists and all current review threads are resolved; do not rebase by force-push, transfer parent evidence, or merge before #51 integrates and #82 is retargeted/revalidated against fresh `develop`. - **PR #83** remains open/non-draft at exact head `c340e7599f147b25fab4c94cd2042a96d6128235` for the Orgmetra-owned Semantic Data Portal ontology evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, and diff checks. The actor trust boundary now requires opaque canonical `actor:` UUIDv4 correlations; human-readable actor handles are rejected. The exact-head hosted snapshot has 11 successful, 6 skipped, 1 terminal `dependency-review` failure, and 29 in progress; Devin Review and CodeRabbit are pending/analyzing. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #85** remains open/non-draft at exact head `199e37799802815fbc82aecfdad6ff8d0970a62d` for the Orgmetra-owned psychometrics result evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, diff checks, and CodeGraph reindexing. The integrity boundary now emits the exact payload and canonical JSON snapshot that passed creation-seal verification, with regressions for both export APIs. The exact-head hosted snapshot has 3 successful, 6 skipped, 1 terminal `dependency-review` failure, and 25 queued/in progress; Devin is pending analysis and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #86** remains open/non-draft at exact head `be0b787301f3daae54994ddb064c403d07c61a01` for the Orgmetra-owned, non-executing Keyverse identity deprovision review boundary. Its focused suite passes 25 tests with exact 100% statement/branch coverage (112/20), compileall, Ruff, and diff checks; pytest source discovery is configured without a manual `PYTHONPATH` override. The current head corrects the doctoring reference to the actual completed review date `2026-08-22 UTC`. The exact-head hosted snapshot has 6 skipped and 27 queued/in progress checks, with no terminal success or failure yet; Devin and CodeRabbit are pending. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 01973b2abee9b02052443b6a2d5021440fb23022 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:10:44 +0900 Subject: [PATCH 107/201] docs: record candidate conversion PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0a41dd8cb..31eddc194 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -90,6 +90,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #83** remains open/non-draft at exact head `c340e7599f147b25fab4c94cd2042a96d6128235` for the Orgmetra-owned Semantic Data Portal ontology evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, and diff checks. The actor trust boundary now requires opaque canonical `actor:` UUIDv4 correlations; human-readable actor handles are rejected. The exact-head hosted snapshot has 11 successful, 6 skipped, 1 terminal `dependency-review` failure, and 29 in progress; Devin Review and CodeRabbit are pending/analyzing. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #85** remains open/non-draft at exact head `199e37799802815fbc82aecfdad6ff8d0970a62d` for the Orgmetra-owned psychometrics result evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, diff checks, and CodeGraph reindexing. The integrity boundary now emits the exact payload and canonical JSON snapshot that passed creation-seal verification, with regressions for both export APIs. The exact-head hosted snapshot has 3 successful, 6 skipped, 1 terminal `dependency-review` failure, and 25 queued/in progress; Devin is pending analysis and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #86** remains open/non-draft at exact head `be0b787301f3daae54994ddb064c403d07c61a01` for the Orgmetra-owned, non-executing Keyverse identity deprovision review boundary. Its focused suite passes 25 tests with exact 100% statement/branch coverage (112/20), compileall, Ruff, and diff checks; pytest source discovery is configured without a manual `PYTHONPATH` override. The current head corrects the doctoring reference to the actual completed review date `2026-08-22 UTC`. The exact-head hosted snapshot has 6 skipped and 27 queued/in progress checks, with no terminal success or failure yet; Devin and CodeRabbit are pending. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #87** remains open/non-draft at exact head `0c4fe88ed0e0b1a117e1adeebe6e5aa1975e87a7` for database-authored candidate-to-worker conversion system-recorded time. Its repository and foundation validation, shell syntax, diff checks, and pinned PostgreSQL 16.14 contract pass; the contract rejects caller backdating, verifies server-authored transaction time and UTC event serialization, and preserves correction history. The exact-head hosted snapshot is terminal with 37 successful, 8 skipped, and 2 failures (`opencode-review`, `strix`); Devin is successful and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 1e4b31d2f6fcbb7a0ff54e51758bbfd203f7fe75 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:15:50 +0900 Subject: [PATCH 108/201] docs: record job analysis budget PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 31eddc194..93a8e7196 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -91,6 +91,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #85** remains open/non-draft at exact head `199e37799802815fbc82aecfdad6ff8d0970a62d` for the Orgmetra-owned psychometrics result evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, diff checks, and CodeGraph reindexing. The integrity boundary now emits the exact payload and canonical JSON snapshot that passed creation-seal verification, with regressions for both export APIs. The exact-head hosted snapshot has 3 successful, 6 skipped, 1 terminal `dependency-review` failure, and 25 queued/in progress; Devin is pending analysis and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #86** remains open/non-draft at exact head `be0b787301f3daae54994ddb064c403d07c61a01` for the Orgmetra-owned, non-executing Keyverse identity deprovision review boundary. Its focused suite passes 25 tests with exact 100% statement/branch coverage (112/20), compileall, Ruff, and diff checks; pytest source discovery is configured without a manual `PYTHONPATH` override. The current head corrects the doctoring reference to the actual completed review date `2026-08-22 UTC`. The exact-head hosted snapshot has 6 skipped and 27 queued/in progress checks, with no terminal success or failure yet; Devin and CodeRabbit are pending. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #87** remains open/non-draft at exact head `0c4fe88ed0e0b1a117e1adeebe6e5aa1975e87a7` for database-authored candidate-to-worker conversion system-recorded time. Its repository and foundation validation, shell syntax, diff checks, and pinned PostgreSQL 16.14 contract pass; the contract rejects caller backdating, verifies server-authored transaction time and UTC event serialization, and preserves correction history. The exact-head hosted snapshot is terminal with 37 successful, 8 skipped, and 2 failures (`opencode-review`, `strix`); Devin is successful and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #88** remains open/non-draft at exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd` for bounded pre-authentication Job Analysis HTTP request metadata. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; paths are capped at 256 characters and headers at 64 frames/16 KiB before authentication. The exact-head hosted snapshot is terminal with 36 successful, 8 skipped, and no failures or in-progress runs, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, and package-quality evidence where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 06466191dbf0b905c2d8bc778c2a40225dd6faf0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:22:11 +0900 Subject: [PATCH 109/201] docs: record People telemetry PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 93a8e7196..4f4307cab 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -92,6 +92,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #86** remains open/non-draft at exact head `be0b787301f3daae54994ddb064c403d07c61a01` for the Orgmetra-owned, non-executing Keyverse identity deprovision review boundary. Its focused suite passes 25 tests with exact 100% statement/branch coverage (112/20), compileall, Ruff, and diff checks; pytest source discovery is configured without a manual `PYTHONPATH` override. The current head corrects the doctoring reference to the actual completed review date `2026-08-22 UTC`. The exact-head hosted snapshot has 6 skipped and 27 queued/in progress checks, with no terminal success or failure yet; Devin and CodeRabbit are pending. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #87** remains open/non-draft at exact head `0c4fe88ed0e0b1a117e1adeebe6e5aa1975e87a7` for database-authored candidate-to-worker conversion system-recorded time. Its repository and foundation validation, shell syntax, diff checks, and pinned PostgreSQL 16.14 contract pass; the contract rejects caller backdating, verifies server-authored transaction time and UTC event serialization, and preserves correction history. The exact-head hosted snapshot is terminal with 37 successful, 8 skipped, and 2 failures (`opencode-review`, `strix`); Devin is successful and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #88** remains open/non-draft at exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd` for bounded pre-authentication Job Analysis HTTP request metadata. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; paths are capped at 256 characters and headers at 64 frames/16 KiB before authentication. The exact-head hosted snapshot is terminal with 36 successful, 8 skipped, and no failures or in-progress runs, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, and package-quality evidence where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #90** remains open/non-draft at exact head `3d3fd3c57b76855c8e394eb7067af30c3063c13d` for privacy-safe People HTTP operational telemetry. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; the middleware emits only bounded method/route/status/duration/error dimensions and degrades without changing HR request behavior. The exact-head hosted snapshot has 33 successful, 6 skipped, and 1 terminal `opencode-review` failure with no in-progress run; Noema, SAST, dependency, security, recovery, PostgreSQL, and People API quality checks are successful where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From acf52e5e3b78d199687d43442a6610c02eb0648c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:24:26 +0900 Subject: [PATCH 110/201] docs: reconcile live PR queue and rerun guidance --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4f4307cab..e97f1230e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 100 pull requests and one non-PR issue (#89) are open; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 108 pull requests and one non-PR issue (#89) are open, verified with the GitHub `open` filters at `2026-08-29 19:23 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -102,7 +102,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. +- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. From b0bb17cf737c8f63f63c9294fca282ad251c30b8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:28:14 +0900 Subject: [PATCH 111/201] docs: record data-rights request PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e97f1230e..69cf57349 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -93,6 +93,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #87** remains open/non-draft at exact head `0c4fe88ed0e0b1a117e1adeebe6e5aa1975e87a7` for database-authored candidate-to-worker conversion system-recorded time. Its repository and foundation validation, shell syntax, diff checks, and pinned PostgreSQL 16.14 contract pass; the contract rejects caller backdating, verifies server-authored transaction time and UTC event serialization, and preserves correction history. The exact-head hosted snapshot is terminal with 37 successful, 8 skipped, and 2 failures (`opencode-review`, `strix`); Devin is successful and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #88** remains open/non-draft at exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd` for bounded pre-authentication Job Analysis HTTP request metadata. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; paths are capped at 256 characters and headers at 64 frames/16 KiB before authentication. The exact-head hosted snapshot is terminal with 36 successful, 8 skipped, and no failures or in-progress runs, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, and package-quality evidence where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #90** remains open/non-draft at exact head `3d3fd3c57b76855c8e394eb7067af30c3063c13d` for privacy-safe People HTTP operational telemetry. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; the middleware emits only bounded method/route/status/duration/error dimensions and degrades without changing HR request behavior. The exact-head hosted snapshot has 33 successful, 6 skipped, and 1 terminal `opencode-review` failure with no in-progress run; Noema, SAST, dependency, security, recovery, PostgreSQL, and People API quality checks are successful where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #91** remains open/non-draft at exact head `0b050dbcfbebf09f510d9e4b92409fda49f8d108` for value-minimized, non-authorizing HR data-rights request evidence. Its installed-package-equivalent suite passes 72 tests with exact 100% statement/branch coverage, and the workflow compile, package, and clean-checkout boundaries were verified; the process-local registry rejects conflicting live reissuance while durable uniqueness remains an authoritative persistence concern. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From dc04ca016aaec506a33ed42e0b42ea2a5313c5bc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:30:32 +0900 Subject: [PATCH 112/201] docs: record performance goal plan PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 69cf57349..850398ef3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -94,6 +94,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #88** remains open/non-draft at exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd` for bounded pre-authentication Job Analysis HTTP request metadata. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; paths are capped at 256 characters and headers at 64 frames/16 KiB before authentication. The exact-head hosted snapshot is terminal with 36 successful, 8 skipped, and no failures or in-progress runs, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, and package-quality evidence where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #90** remains open/non-draft at exact head `3d3fd3c57b76855c8e394eb7067af30c3063c13d` for privacy-safe People HTTP operational telemetry. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; the middleware emits only bounded method/route/status/duration/error dimensions and degrades without changing HR request behavior. The exact-head hosted snapshot has 33 successful, 6 skipped, and 1 terminal `opencode-review` failure with no in-progress run; Noema, SAST, dependency, security, recovery, PostgreSQL, and People API quality checks are successful where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #91** remains open/non-draft at exact head `0b050dbcfbebf09f510d9e4b92409fda49f8d108` for value-minimized, non-authorizing HR data-rights request evidence. Its installed-package-equivalent suite passes 72 tests with exact 100% statement/branch coverage, and the workflow compile, package, and clean-checkout boundaries were verified; the process-local registry rejects conflicting live reissuance while durable uniqueness remains an authoritative persistence concern. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #92** remains open/non-draft at exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487` for value-minimized, non-authorizing performance goal-plan activation evidence. Its package suite passes 40 tests with exact 100% statement/branch coverage; the workflow triggers on its ADR, builds and tests the isolated wheel artifact, and the off-lifecycle export path fails closed with the governed `ValueError`. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 16ce574b90c351fc4b88a716f62ebcd6517c5b5d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:32:37 +0900 Subject: [PATCH 113/201] docs: record performance context PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 850398ef3..fcc7d1d30 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -95,6 +95,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #90** remains open/non-draft at exact head `3d3fd3c57b76855c8e394eb7067af30c3063c13d` for privacy-safe People HTTP operational telemetry. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; the middleware emits only bounded method/route/status/duration/error dimensions and degrades without changing HR request behavior. The exact-head hosted snapshot has 33 successful, 6 skipped, and 1 terminal `opencode-review` failure with no in-progress run; Noema, SAST, dependency, security, recovery, PostgreSQL, and People API quality checks are successful where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #91** remains open/non-draft at exact head `0b050dbcfbebf09f510d9e4b92409fda49f8d108` for value-minimized, non-authorizing HR data-rights request evidence. Its installed-package-equivalent suite passes 72 tests with exact 100% statement/branch coverage, and the workflow compile, package, and clean-checkout boundaries were verified; the process-local registry rejects conflicting live reissuance while durable uniqueness remains an authoritative persistence concern. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #92** remains open/non-draft at exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487` for value-minimized, non-authorizing performance goal-plan activation evidence. Its package suite passes 40 tests with exact 100% statement/branch coverage; the workflow triggers on its ADR, builds and tests the isolated wheel artifact, and the off-lifecycle export path fails closed with the governed `ValueError`. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #93** remains open/non-draft at exact head `951167e58a5a1f97254c290ae77354e5a0faeaee` for value-minimized, non-authorizing performance-context evidence. Its package suite passes 46 tests with exact 100% statement/branch coverage; the workflow uses a reviewed build lock, installs the wheel without a misleading test extra, triggers on its ADR, and isolates per-test packet references while preserving intentional conflict tests. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From ac384abe2d2bd6c0c2b089e2614d2a33ac8bb0bc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:35:53 +0900 Subject: [PATCH 114/201] docs: record position reporting PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index fcc7d1d30..984a4010a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -96,6 +96,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #91** remains open/non-draft at exact head `0b050dbcfbebf09f510d9e4b92409fda49f8d108` for value-minimized, non-authorizing HR data-rights request evidence. Its installed-package-equivalent suite passes 72 tests with exact 100% statement/branch coverage, and the workflow compile, package, and clean-checkout boundaries were verified; the process-local registry rejects conflicting live reissuance while durable uniqueness remains an authoritative persistence concern. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #92** remains open/non-draft at exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487` for value-minimized, non-authorizing performance goal-plan activation evidence. Its package suite passes 40 tests with exact 100% statement/branch coverage; the workflow triggers on its ADR, builds and tests the isolated wheel artifact, and the off-lifecycle export path fails closed with the governed `ValueError`. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #93** remains open/non-draft at exact head `951167e58a5a1f97254c290ae77354e5a0faeaee` for value-minimized, non-authorizing performance-context evidence. Its package suite passes 46 tests with exact 100% statement/branch coverage; the workflow uses a reviewed build lock, installs the wheel without a misleading test extra, triggers on its ADR, and isolates per-test packet references while preserving intentional conflict tests. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #94** remains open/non-draft at exact head `2ff1262b976029e447dc736e6472eebbac30a7f5` for the bitemporal, tenant-scoped Position reporting hierarchy. The full HRIS-kernel suite passes 187 tests with exact 100% statement/branch coverage; the public-root export, UTC system-time normalization, staffable endpoint validation, single-manager invariant, and cycle rejection are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 8e63aafbcd62284a2f355d76d238e50ccbeed0b8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:38:23 +0900 Subject: [PATCH 115/201] docs: record position reporting review PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 984a4010a..acd97549d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -97,6 +97,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #92** remains open/non-draft at exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487` for value-minimized, non-authorizing performance goal-plan activation evidence. Its package suite passes 40 tests with exact 100% statement/branch coverage; the workflow triggers on its ADR, builds and tests the isolated wheel artifact, and the off-lifecycle export path fails closed with the governed `ValueError`. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #93** remains open/non-draft at exact head `951167e58a5a1f97254c290ae77354e5a0faeaee` for value-minimized, non-authorizing performance-context evidence. Its package suite passes 46 tests with exact 100% statement/branch coverage; the workflow uses a reviewed build lock, installs the wheel without a misleading test extra, triggers on its ADR, and isolates per-test packet references while preserving intentional conflict tests. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #94** remains open/non-draft at exact head `2ff1262b976029e447dc736e6472eebbac30a7f5` for the bitemporal, tenant-scoped Position reporting hierarchy. The full HRIS-kernel suite passes 187 tests with exact 100% statement/branch coverage; the public-root export, UTC system-time normalization, staffable endpoint validation, single-manager invariant, and cycle rejection are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #95** remains open/non-draft at exact head `adf055d79d188ba18d06ecf80dc1117858c987f4` for value-minimized, human-review-only Position reporting-change evidence. Its package suite passes 45 tests with exact 100% statement/branch coverage; the reviewed integer-ordering adversary, canonical export, and process-local issuance checks are covered. The exact-head hosted snapshot has 63 successful and 15 skipped checks with no terminal failure and 2 non-terminal contexts; Devin and Code Quality are successful. All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 6456da554f27ec06ac4b705032dd26104dd8687e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:40:46 +0900 Subject: [PATCH 116/201] docs: record organization hierarchy review PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index acd97549d..0506a0b5a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -98,6 +98,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #93** remains open/non-draft at exact head `951167e58a5a1f97254c290ae77354e5a0faeaee` for value-minimized, non-authorizing performance-context evidence. Its package suite passes 46 tests with exact 100% statement/branch coverage; the workflow uses a reviewed build lock, installs the wheel without a misleading test extra, triggers on its ADR, and isolates per-test packet references while preserving intentional conflict tests. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #94** remains open/non-draft at exact head `2ff1262b976029e447dc736e6472eebbac30a7f5` for the bitemporal, tenant-scoped Position reporting hierarchy. The full HRIS-kernel suite passes 187 tests with exact 100% statement/branch coverage; the public-root export, UTC system-time normalization, staffable endpoint validation, single-manager invariant, and cycle rejection are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #95** remains open/non-draft at exact head `adf055d79d188ba18d06ecf80dc1117858c987f4` for value-minimized, human-review-only Position reporting-change evidence. Its package suite passes 45 tests with exact 100% statement/branch coverage; the reviewed integer-ordering adversary, canonical export, and process-local issuance checks are covered. The exact-head hosted snapshot has 63 successful and 15 skipped checks with no terminal failure and 2 non-terminal contexts; Devin and Code Quality are successful. All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #96** remains open/non-draft at exact head `6a8454ff8ad0c52790b4a72f1fde67f61cc11358` for value-minimized, human-review-only Organization hierarchy-change evidence. Its package suite passes 49 tests with exact 100% statement/branch coverage; issuance rejects future system-recorded timestamps, and tenant/reference, root-transition, self-parent, chronology, and canonical-export cases are covered. The exact-head hosted snapshot has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From b4a6cc3c0e1eae2288085b51c5f6e46a742899cd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:47:25 +0900 Subject: [PATCH 117/201] docs: record Position vacancy PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0506a0b5a..039ff9f28 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -99,6 +99,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #94** remains open/non-draft at exact head `2ff1262b976029e447dc736e6472eebbac30a7f5` for the bitemporal, tenant-scoped Position reporting hierarchy. The full HRIS-kernel suite passes 187 tests with exact 100% statement/branch coverage; the public-root export, UTC system-time normalization, staffable endpoint validation, single-manager invariant, and cycle rejection are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #95** remains open/non-draft at exact head `adf055d79d188ba18d06ecf80dc1117858c987f4` for value-minimized, human-review-only Position reporting-change evidence. Its package suite passes 45 tests with exact 100% statement/branch coverage; the reviewed integer-ordering adversary, canonical export, and process-local issuance checks are covered. The exact-head hosted snapshot has 63 successful and 15 skipped checks with no terminal failure and 2 non-terminal contexts; Devin and Code Quality are successful. All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #96** remains open/non-draft at exact head `6a8454ff8ad0c52790b4a72f1fde67f61cc11358` for value-minimized, human-review-only Organization hierarchy-change evidence. Its package suite passes 49 tests with exact 100% statement/branch coverage; issuance rejects future system-recorded timestamps, and tenant/reference, root-transition, self-parent, chronology, and canonical-export cases are covered. The exact-head hosted snapshot has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #97** remains open/non-draft at exact head `b13846dabe600cf78cbdd1409499c3726181bf47` for bitemporal, tenant-scoped Position vacancy evidence. Its full HRIS-kernel suite passes 194 tests with exact 100% statement/branch coverage; canonical four-decimal FTE/ratio validation, duplicate visible Assignment rejection, position coverage, seat capacity, cutoff normalization, and fail-closed vacancy semantics are covered. The exact-head hosted snapshot has 38 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are present, and all 9 current review threads are resolved. No qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 79fc355c4a09d58f50b32dc2f0d6764152e9d098 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:51:57 +0900 Subject: [PATCH 118/201] docs: record document evidence PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 039ff9f28..27eff7096 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -100,6 +100,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #95** remains open/non-draft at exact head `adf055d79d188ba18d06ecf80dc1117858c987f4` for value-minimized, human-review-only Position reporting-change evidence. Its package suite passes 45 tests with exact 100% statement/branch coverage; the reviewed integer-ordering adversary, canonical export, and process-local issuance checks are covered. The exact-head hosted snapshot has 63 successful and 15 skipped checks with no terminal failure and 2 non-terminal contexts; Devin and Code Quality are successful. All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #96** remains open/non-draft at exact head `6a8454ff8ad0c52790b4a72f1fde67f61cc11358` for value-minimized, human-review-only Organization hierarchy-change evidence. Its package suite passes 49 tests with exact 100% statement/branch coverage; issuance rejects future system-recorded timestamps, and tenant/reference, root-transition, self-parent, chronology, and canonical-export cases are covered. The exact-head hosted snapshot has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #97** remains open/non-draft at exact head `b13846dabe600cf78cbdd1409499c3726181bf47` for bitemporal, tenant-scoped Position vacancy evidence. Its full HRIS-kernel suite passes 194 tests with exact 100% statement/branch coverage; canonical four-decimal FTE/ratio validation, duplicate visible Assignment rejection, position coverage, seat capacity, cutoff normalization, and fail-closed vacancy semantics are covered. The exact-head hosted snapshot has 38 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are present, and all 9 current review threads are resolved. No qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #98** remains open/non-draft at exact head `6a9f3e214079e2b46bba9776a862f194b899f0e4` for value-minimized, non-authorizing HR document-record evidence. Its focused package suite passes 23 tests with exact 100% statement/branch coverage; artifact-reference-only storage, provenance/retention digests, UTC received/recorded time ordering, immutable issuance sealing, and employment-decision non-authority are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 20ec7afe6f7b5739e86ac39fe2d8a566884eddda Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:56:12 +0900 Subject: [PATCH 119/201] docs: record compensation PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 27eff7096..0c3ed1aae 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -101,6 +101,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #96** remains open/non-draft at exact head `6a8454ff8ad0c52790b4a72f1fde67f61cc11358` for value-minimized, human-review-only Organization hierarchy-change evidence. Its package suite passes 49 tests with exact 100% statement/branch coverage; issuance rejects future system-recorded timestamps, and tenant/reference, root-transition, self-parent, chronology, and canonical-export cases are covered. The exact-head hosted snapshot has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #97** remains open/non-draft at exact head `b13846dabe600cf78cbdd1409499c3726181bf47` for bitemporal, tenant-scoped Position vacancy evidence. Its full HRIS-kernel suite passes 194 tests with exact 100% statement/branch coverage; canonical four-decimal FTE/ratio validation, duplicate visible Assignment rejection, position coverage, seat capacity, cutoff normalization, and fail-closed vacancy semantics are covered. The exact-head hosted snapshot has 38 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are present, and all 9 current review threads are resolved. No qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #98** remains open/non-draft at exact head `6a9f3e214079e2b46bba9776a862f194b899f0e4` for value-minimized, non-authorizing HR document-record evidence. Its focused package suite passes 23 tests with exact 100% statement/branch coverage; artifact-reference-only storage, provenance/retention digests, UTC received/recorded time ordering, immutable issuance sealing, and employment-decision non-authority are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #99** remains Draft at exact head `5815889310cc134ada8869eb57b9981e56aa181b` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted snapshot has 36 successful, 6 skipped, and 1 terminal `opencode-review` failure with 1 non-terminal context; all 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 6345f0b6e22aad57070794609af5a1a11875c489 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 04:58:36 +0900 Subject: [PATCH 120/201] docs: record job grade review PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0c3ed1aae..1eaa25f65 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -102,6 +102,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #97** remains open/non-draft at exact head `b13846dabe600cf78cbdd1409499c3726181bf47` for bitemporal, tenant-scoped Position vacancy evidence. Its full HRIS-kernel suite passes 194 tests with exact 100% statement/branch coverage; canonical four-decimal FTE/ratio validation, duplicate visible Assignment rejection, position coverage, seat capacity, cutoff normalization, and fail-closed vacancy semantics are covered. The exact-head hosted snapshot has 38 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are present, and all 9 current review threads are resolved. No qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #98** remains open/non-draft at exact head `6a9f3e214079e2b46bba9776a862f194b899f0e4` for value-minimized, non-authorizing HR document-record evidence. Its focused package suite passes 23 tests with exact 100% statement/branch coverage; artifact-reference-only storage, provenance/retention digests, UTC received/recorded time ordering, immutable issuance sealing, and employment-decision non-authority are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #99** remains Draft at exact head `5815889310cc134ada8869eb57b9981e56aa181b` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted snapshot has 36 successful, 6 skipped, and 1 terminal `opencode-review` failure with 1 non-terminal context; all 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. +- **PR #101** remains Draft at exact head `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` for non-authorizing, human-reviewed Job-grade design evidence. Its focused package suite passes 60 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks. The exact-head hosted snapshot has 35 successful and 8 skipped checks with 2 non-terminal contexts and no terminal failure; all 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 0c1d308c6fa20e882c3bc60fd4d1679edb4df9fc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:05:00 +0900 Subject: [PATCH 121/201] docs: record compensation workflow repair --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1eaa25f65..e3e19f4e4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -101,7 +101,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #96** remains open/non-draft at exact head `6a8454ff8ad0c52790b4a72f1fde67f61cc11358` for value-minimized, human-review-only Organization hierarchy-change evidence. Its package suite passes 49 tests with exact 100% statement/branch coverage; issuance rejects future system-recorded timestamps, and tenant/reference, root-transition, self-parent, chronology, and canonical-export cases are covered. The exact-head hosted snapshot has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #97** remains open/non-draft at exact head `b13846dabe600cf78cbdd1409499c3726181bf47` for bitemporal, tenant-scoped Position vacancy evidence. Its full HRIS-kernel suite passes 194 tests with exact 100% statement/branch coverage; canonical four-decimal FTE/ratio validation, duplicate visible Assignment rejection, position coverage, seat capacity, cutoff normalization, and fail-closed vacancy semantics are covered. The exact-head hosted snapshot has 38 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are present, and all 9 current review threads are resolved. No qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #98** remains open/non-draft at exact head `6a9f3e214079e2b46bba9776a862f194b899f0e4` for value-minimized, non-authorizing HR document-record evidence. Its focused package suite passes 23 tests with exact 100% statement/branch coverage; artifact-reference-only storage, provenance/retention digests, UTC received/recorded time ordering, immutable issuance sealing, and employment-decision non-authority are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #99** remains Draft at exact head `5815889310cc134ada8869eb57b9981e56aa181b` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted snapshot has 36 successful, 6 skipped, and 1 terminal `opencode-review` failure with 1 non-terminal context; all 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. +- **PR #99** remains Draft at exact head `1b0f4834c5152131815f1d02073f29d47c1c6c97` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted rollup has 4 successful, 6 skipped, 1 terminal `dependency-review` failure, and 30 non-terminal contexts; the dedicated Employment Compensation Core Quality run `33272503669` is in progress after the workflow-file repair. The pre-fix run `33176719158` failed before creating a job and is stale evidence; no prior cancelled/failed Strix evidence transfers to this head. All 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #101** remains Draft at exact head `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` for non-authorizing, human-reviewed Job-grade design evidence. Its focused package suite passes 60 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks. The exact-head hosted snapshot has 35 successful and 8 skipped checks with 2 non-terminal contexts and no terminal failure; all 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. From 5f7e140e2d4e9f67595482d4833e4202fdeb3239 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:06:06 +0900 Subject: [PATCH 122/201] docs: record compensation workflow result --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e3e19f4e4..00596a5e7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -101,7 +101,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #96** remains open/non-draft at exact head `6a8454ff8ad0c52790b4a72f1fde67f61cc11358` for value-minimized, human-review-only Organization hierarchy-change evidence. Its package suite passes 49 tests with exact 100% statement/branch coverage; issuance rejects future system-recorded timestamps, and tenant/reference, root-transition, self-parent, chronology, and canonical-export cases are covered. The exact-head hosted snapshot has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #97** remains open/non-draft at exact head `b13846dabe600cf78cbdd1409499c3726181bf47` for bitemporal, tenant-scoped Position vacancy evidence. Its full HRIS-kernel suite passes 194 tests with exact 100% statement/branch coverage; canonical four-decimal FTE/ratio validation, duplicate visible Assignment rejection, position coverage, seat capacity, cutoff normalization, and fail-closed vacancy semantics are covered. The exact-head hosted snapshot has 38 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are present, and all 9 current review threads are resolved. No qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #98** remains open/non-draft at exact head `6a9f3e214079e2b46bba9776a862f194b899f0e4` for value-minimized, non-authorizing HR document-record evidence. Its focused package suite passes 23 tests with exact 100% statement/branch coverage; artifact-reference-only storage, provenance/retention digests, UTC received/recorded time ordering, immutable issuance sealing, and employment-decision non-authority are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #99** remains Draft at exact head `1b0f4834c5152131815f1d02073f29d47c1c6c97` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted rollup has 4 successful, 6 skipped, 1 terminal `dependency-review` failure, and 30 non-terminal contexts; the dedicated Employment Compensation Core Quality run `33272503669` is in progress after the workflow-file repair. The pre-fix run `33176719158` failed before creating a job and is stale evidence; no prior cancelled/failed Strix evidence transfers to this head. All 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. +- **PR #99** remains Draft at exact head `1b0f4834c5152131815f1d02073f29d47c1c6c97` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted rollup has 35 successful, 6 skipped, and 2 terminal failures (`dependency-review`, `opencode-review`) with 2 non-terminal contexts (`noema-review` and one unnamed status); the dedicated Employment Compensation Core Quality run `33272503669` is terminal GREEN. The pre-fix run `33176719158` failed before creating a job and is stale evidence; no prior cancelled/failed Strix evidence transfers to this head. All 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #101** remains Draft at exact head `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` for non-authorizing, human-reviewed Job-grade design evidence. Its focused package suite passes 60 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks. The exact-head hosted snapshot has 35 successful and 8 skipped checks with 2 non-terminal contexts and no terminal failure; all 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. From accb5e2c303b7b9e0d910f64fbbed0484ed5ac9a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:10:58 +0900 Subject: [PATCH 123/201] docs: record audit review PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 00596a5e7..54226ca90 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -103,6 +103,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #98** remains open/non-draft at exact head `6a9f3e214079e2b46bba9776a862f194b899f0e4` for value-minimized, non-authorizing HR document-record evidence. Its focused package suite passes 23 tests with exact 100% statement/branch coverage; artifact-reference-only storage, provenance/retention digests, UTC received/recorded time ordering, immutable issuance sealing, and employment-decision non-authority are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #99** remains Draft at exact head `1b0f4834c5152131815f1d02073f29d47c1c6c97` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted rollup has 35 successful, 6 skipped, and 2 terminal failures (`dependency-review`, `opencode-review`) with 2 non-terminal contexts (`noema-review` and one unnamed status); the dedicated Employment Compensation Core Quality run `33272503669` is terminal GREEN. The pre-fix run `33176719158` failed before creating a job and is stale evidence; no prior cancelled/failed Strix evidence transfers to this head. All 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #101** remains Draft at exact head `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` for non-authorizing, human-reviewed Job-grade design evidence. Its focused package suite passes 60 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks. The exact-head hosted snapshot has 35 successful and 8 skipped checks with 2 non-terminal contexts and no terminal failure; all 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. +- **PR #102** remains open/non-draft at exact head `5344d77a9bd1058fee9fcecb7c6aaebc39ced995` for purpose-bound, non-authorizing audit-evidence review. Its focused package suite passes 68 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks; authorization-before-read, detached callback snapshots, tenant/time/limit bounds, canonical CloudEvents verification, digest sealing, and strict ordering are covered. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 8 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 026161c30056bb4678ea3d4423880e13a3c835ba Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:19:07 +0900 Subject: [PATCH 124/201] docs: record employment work capacity review PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 54226ca90..93e2b5ed5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -104,6 +104,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #99** remains Draft at exact head `1b0f4834c5152131815f1d02073f29d47c1c6c97` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted rollup has 35 successful, 6 skipped, and 2 terminal failures (`dependency-review`, `opencode-review`) with 2 non-terminal contexts (`noema-review` and one unnamed status); the dedicated Employment Compensation Core Quality run `33272503669` is terminal GREEN. The pre-fix run `33176719158` failed before creating a job and is stale evidence; no prior cancelled/failed Strix evidence transfers to this head. All 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #101** remains Draft at exact head `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` for non-authorizing, human-reviewed Job-grade design evidence. Its focused package suite passes 60 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks. The exact-head hosted snapshot has 35 successful and 8 skipped checks with 2 non-terminal contexts and no terminal failure; all 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #102** remains open/non-draft at exact head `5344d77a9bd1058fee9fcecb7c6aaebc39ced995` for purpose-bound, non-authorizing audit-evidence review. Its focused package suite passes 68 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks; authorization-before-read, detached callback snapshots, tenant/time/limit bounds, canonical CloudEvents verification, digest sealing, and strict ordering are covered. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 8 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #103** remains open/non-draft at exact head `267d9d5bc58d2e951fe3e428876682c8a5e1daa5` for human-reviewed, non-authorizing Employment work-capacity change evidence. Its focused package suite passes 36 tests with exact 100% statement/branch coverage (170/46); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet keeps Employment/Assignment/compensation/payroll/leave/scheduling mutation outside its boundary, requires exact four-decimal capacity ratios and distinct actor UUIDv4 references, and owns system-recorded UTC issuance time. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 8f87329a3abda11b6bc9d6688a91b3f7ec43fe4f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:20:57 +0900 Subject: [PATCH 125/201] docs: refresh compensation and work capacity evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 93e2b5ed5..12dfd7874 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -101,7 +101,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #96** remains open/non-draft at exact head `6a8454ff8ad0c52790b4a72f1fde67f61cc11358` for value-minimized, human-review-only Organization hierarchy-change evidence. Its package suite passes 49 tests with exact 100% statement/branch coverage; issuance rejects future system-recorded timestamps, and tenant/reference, root-transition, self-parent, chronology, and canonical-export cases are covered. The exact-head hosted snapshot has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #97** remains open/non-draft at exact head `b13846dabe600cf78cbdd1409499c3726181bf47` for bitemporal, tenant-scoped Position vacancy evidence. Its full HRIS-kernel suite passes 194 tests with exact 100% statement/branch coverage; canonical four-decimal FTE/ratio validation, duplicate visible Assignment rejection, position coverage, seat capacity, cutoff normalization, and fail-closed vacancy semantics are covered. The exact-head hosted snapshot has 38 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are present, and all 9 current review threads are resolved. No qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #98** remains open/non-draft at exact head `6a9f3e214079e2b46bba9776a862f194b899f0e4` for value-minimized, non-authorizing HR document-record evidence. Its focused package suite passes 23 tests with exact 100% statement/branch coverage; artifact-reference-only storage, provenance/retention digests, UTC received/recorded time ordering, immutable issuance sealing, and employment-decision non-authority are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #99** remains Draft at exact head `1b0f4834c5152131815f1d02073f29d47c1c6c97` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted rollup has 35 successful, 6 skipped, and 2 terminal failures (`dependency-review`, `opencode-review`) with 2 non-terminal contexts (`noema-review` and one unnamed status); the dedicated Employment Compensation Core Quality run `33272503669` is terminal GREEN. The pre-fix run `33176719158` failed before creating a job and is stale evidence; no prior cancelled/failed Strix evidence transfers to this head. All 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. +- **PR #99** remains Draft at exact head `1b0f4834c5152131815f1d02073f29d47c1c6c97` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted rollup has 35 successful, 6 skipped, and 3 terminal failures (`noema-review`, `dependency-review`, `opencode-review`) with 1 non-terminal context (`CodeRabbit`); the dedicated Employment Compensation Core Quality run `33272503669` is terminal GREEN. The pre-fix run `33176719158` failed before creating a job and is stale evidence; no prior cancelled/failed Strix evidence transfers to this head. All 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #101** remains Draft at exact head `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` for non-authorizing, human-reviewed Job-grade design evidence. Its focused package suite passes 60 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks. The exact-head hosted snapshot has 35 successful and 8 skipped checks with 2 non-terminal contexts and no terminal failure; all 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #102** remains open/non-draft at exact head `5344d77a9bd1058fee9fcecb7c6aaebc39ced995` for purpose-bound, non-authorizing audit-evidence review. Its focused package suite passes 68 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks; authorization-before-read, detached callback snapshots, tenant/time/limit bounds, canonical CloudEvents verification, digest sealing, and strict ordering are covered. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 8 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #103** remains open/non-draft at exact head `267d9d5bc58d2e951fe3e428876682c8a5e1daa5` for human-reviewed, non-authorizing Employment work-capacity change evidence. Its focused package suite passes 36 tests with exact 100% statement/branch coverage (170/46); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet keeps Employment/Assignment/compensation/payroll/leave/scheduling mutation outside its boundary, requires exact four-decimal capacity ratios and distinct actor UUIDv4 references, and owns system-recorded UTC issuance time. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. From 27fc399e76745bb4a633b071f1216c7d04961e41 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:24:18 +0900 Subject: [PATCH 126/201] docs: record qualification rule review PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 12dfd7874..5f42f4ed1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -105,6 +105,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #101** remains Draft at exact head `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` for non-authorizing, human-reviewed Job-grade design evidence. Its focused package suite passes 60 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks. The exact-head hosted snapshot has 35 successful and 8 skipped checks with 2 non-terminal contexts and no terminal failure; all 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. - **PR #102** remains open/non-draft at exact head `5344d77a9bd1058fee9fcecb7c6aaebc39ced995` for purpose-bound, non-authorizing audit-evidence review. Its focused package suite passes 68 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks; authorization-before-read, detached callback snapshots, tenant/time/limit bounds, canonical CloudEvents verification, digest sealing, and strict ordering are covered. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 8 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #103** remains open/non-draft at exact head `267d9d5bc58d2e951fe3e428876682c8a5e1daa5` for human-reviewed, non-authorizing Employment work-capacity change evidence. Its focused package suite passes 36 tests with exact 100% statement/branch coverage (170/46); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet keeps Employment/Assignment/compensation/payroll/leave/scheduling mutation outside its boundary, requires exact four-decimal capacity ratios and distinct actor UUIDv4 references, and owns system-recorded UTC issuance time. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #104** remains open/non-draft at exact head `14eab4eb21924f85c9d4eeef325ca37bfff37de3` for human-reviewed, non-authorizing Job qualification-rule evidence. Its focused package suite passes 55 tests with exact 100% statement/branch coverage (165/38); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet binds Job/Job Analysis provenance and reviewed rule categories while never evaluating candidates, rejecting applicants, mutating Job truth, or authorizing employment decisions. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 13f34eb56effe2b3b887f862871ba202fba88ba0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:29:09 +0900 Subject: [PATCH 127/201] docs: record qualification rule persistence PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5f42f4ed1..b64122e12 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -106,6 +106,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #102** remains open/non-draft at exact head `5344d77a9bd1058fee9fcecb7c6aaebc39ced995` for purpose-bound, non-authorizing audit-evidence review. Its focused package suite passes 68 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks; authorization-before-read, detached callback snapshots, tenant/time/limit bounds, canonical CloudEvents verification, digest sealing, and strict ordering are covered. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 8 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #103** remains open/non-draft at exact head `267d9d5bc58d2e951fe3e428876682c8a5e1daa5` for human-reviewed, non-authorizing Employment work-capacity change evidence. Its focused package suite passes 36 tests with exact 100% statement/branch coverage (170/46); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet keeps Employment/Assignment/compensation/payroll/leave/scheduling mutation outside its boundary, requires exact four-decimal capacity ratios and distinct actor UUIDv4 references, and owns system-recorded UTC issuance time. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #104** remains open/non-draft at exact head `14eab4eb21924f85c9d4eeef325ca37bfff37de3` for human-reviewed, non-authorizing Job qualification-rule evidence. Its focused package suite passes 55 tests with exact 100% statement/branch coverage (165/38); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet binds Job/Job Analysis provenance and reviewed rule categories while never evaluating candidates, rejecting applicants, mutating Job truth, or authorizing employment decisions. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #105** remains Draft at exact head `e9e4731b7bcd41db0e88186ae07e38742c0e220c`, stacked on the unmerged Job qualification-rule review lane with base tip `d92ac4cb798b3bd32b632c0ab677c03f944070e4`. Its real PostgreSQL 16.14 full-chain persistence contract passes, as do Foundation validation (55/55), shellcheck, actionlint, and diff checks; the migration enforces tenant-scoped bitemporal rule history, immutable transaction-time intervals, reviewed Job Analysis scope, audit/outbox correlation, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From b10a98b71241c0ea0e9ab36ac8f341e24203be7b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:34:05 +0900 Subject: [PATCH 128/201] docs: record position reporting persistence PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b64122e12..e31628457 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -107,6 +107,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #103** remains open/non-draft at exact head `267d9d5bc58d2e951fe3e428876682c8a5e1daa5` for human-reviewed, non-authorizing Employment work-capacity change evidence. Its focused package suite passes 36 tests with exact 100% statement/branch coverage (170/46); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet keeps Employment/Assignment/compensation/payroll/leave/scheduling mutation outside its boundary, requires exact four-decimal capacity ratios and distinct actor UUIDv4 references, and owns system-recorded UTC issuance time. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #104** remains open/non-draft at exact head `14eab4eb21924f85c9d4eeef325ca37bfff37de3` for human-reviewed, non-authorizing Job qualification-rule evidence. Its focused package suite passes 55 tests with exact 100% statement/branch coverage (165/38); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet binds Job/Job Analysis provenance and reviewed rule categories while never evaluating candidates, rejecting applicants, mutating Job truth, or authorizing employment decisions. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #105** remains Draft at exact head `e9e4731b7bcd41db0e88186ae07e38742c0e220c`, stacked on the unmerged Job qualification-rule review lane with base tip `d92ac4cb798b3bd32b632c0ab677c03f944070e4`. Its real PostgreSQL 16.14 full-chain persistence contract passes, as do Foundation validation (55/55), shellcheck, actionlint, and diff checks; the migration enforces tenant-scoped bitemporal rule history, immutable transaction-time intervals, reviewed Job Analysis scope, audit/outbox correlation, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. +- **PR #106** remains Draft at exact head `a367b4ea09f6abb4b6b8523c1e7726ee11bfc483`, stacked on the unmerged Position reporting hierarchy lane with base tip `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc`. Its real PostgreSQL 16.14 persistence, immutable review/application audit binding, and concurrent cycle-prevention contracts all pass; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration enforces tenant-scoped bitemporal Position relationships, staffable endpoint coverage, same-tenant review/audit scope, actor separation, immutable closure, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From ef68ffa7e9d46e5a4bf95543822fcabc8b52a52c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:37:52 +0900 Subject: [PATCH 129/201] docs: record document persistence PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e31628457..065b0a4ec 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -108,6 +108,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #104** remains open/non-draft at exact head `14eab4eb21924f85c9d4eeef325ca37bfff37de3` for human-reviewed, non-authorizing Job qualification-rule evidence. Its focused package suite passes 55 tests with exact 100% statement/branch coverage (165/38); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet binds Job/Job Analysis provenance and reviewed rule categories while never evaluating candidates, rejecting applicants, mutating Job truth, or authorizing employment decisions. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #105** remains Draft at exact head `e9e4731b7bcd41db0e88186ae07e38742c0e220c`, stacked on the unmerged Job qualification-rule review lane with base tip `d92ac4cb798b3bd32b632c0ab677c03f944070e4`. Its real PostgreSQL 16.14 full-chain persistence contract passes, as do Foundation validation (55/55), shellcheck, actionlint, and diff checks; the migration enforces tenant-scoped bitemporal rule history, immutable transaction-time intervals, reviewed Job Analysis scope, audit/outbox correlation, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #106** remains Draft at exact head `a367b4ea09f6abb4b6b8523c1e7726ee11bfc483`, stacked on the unmerged Position reporting hierarchy lane with base tip `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc`. Its real PostgreSQL 16.14 persistence, immutable review/application audit binding, and concurrent cycle-prevention contracts all pass; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration enforces tenant-scoped bitemporal Position relationships, staffable endpoint coverage, same-tenant review/audit scope, actor separation, immutable closure, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. +- **PR #107** remains Draft at exact head `78e67a0493c6b25210b0fcc4a8a6efddf5d339c7`, stacked on the unmerged Document Record Evidence lane with base tip `59b809bead617d9045357396df684991548bdc30`. Its real PostgreSQL 16.14 immutable document-metadata persistence contract passes; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration stores artifact/provenance references and digests only, binds the exact canonical evidence JSON, enforces PostgreSQL system time, immutability, RLS, and no direct Person/Employment/audit/outbox application-table foreign keys. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 9404ebbddbc2b333ec43a52b76614900084d34bc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 05:45:01 +0900 Subject: [PATCH 130/201] docs: record offer-to-hire close review state --- docs/product-technical-gap-baseline.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 065b0a4ec..32d79f1f3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 108 pull requests and one non-PR issue (#89) are open, verified with the GitHub `open` filters at `2026-08-29 19:23 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 108 pull requests and one non-PR issue (#89) are open, verified with the GitHub `open` filters at `2026-08-29 20:44 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -109,6 +109,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #105** remains Draft at exact head `e9e4731b7bcd41db0e88186ae07e38742c0e220c`, stacked on the unmerged Job qualification-rule review lane with base tip `d92ac4cb798b3bd32b632c0ab677c03f944070e4`. Its real PostgreSQL 16.14 full-chain persistence contract passes, as do Foundation validation (55/55), shellcheck, actionlint, and diff checks; the migration enforces tenant-scoped bitemporal rule history, immutable transaction-time intervals, reviewed Job Analysis scope, audit/outbox correlation, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #106** remains Draft at exact head `a367b4ea09f6abb4b6b8523c1e7726ee11bfc483`, stacked on the unmerged Position reporting hierarchy lane with base tip `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc`. Its real PostgreSQL 16.14 persistence, immutable review/application audit binding, and concurrent cycle-prevention contracts all pass; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration enforces tenant-scoped bitemporal Position relationships, staffable endpoint coverage, same-tenant review/audit scope, actor separation, immutable closure, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #107** remains Draft at exact head `78e67a0493c6b25210b0fcc4a8a6efddf5d339c7`, stacked on the unmerged Document Record Evidence lane with base tip `59b809bead617d9045357396df684991548bdc30`. Its real PostgreSQL 16.14 immutable document-metadata persistence contract passes; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration stores artifact/provenance references and digests only, binds the exact canonical evidence JSON, enforces PostgreSQL system time, immutability, RLS, and no direct Person/Employment/audit/outbox application-table foreign keys. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. +- **PR #108** remains Draft at exact head `d465d1cd34ec3eeaee863535a7a4142cd018e06b`, stacked on candidate-response parent #80 at the stale recorded base tip `5070f34cd13814f09d74162347f837cb34d76a57`; current parent #80 has advanced to `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702`. Its focused offer-to-hire suite passes 12 tests with exact 100% statement/branch coverage (106/30); compileall, Ruff, actionlint, diff checks, candidate-response package tests (65), and Foundation validation (55/55) pass. The bridge validates accepted-response integrity, authorizes the exact selection decision before protected candidate/offer resolution, requires exact authoritative scope/evidence binding, and delegates mutation only through the existing confirmed-hire path. Its exact-head hosted set has 1 successful dedicated check plus successful Draft-skipped CodeRabbit, all 2 review threads are resolved, and no qualifying independent approval exists. It remains dependency-first active-PR truth only; no parent or stale-base evidence transfers. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 1c7329b1de0cb4214862ad9a8b6696436e70146c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 06:09:59 +0900 Subject: [PATCH 131/201] docs: record vacancy and lifecycle review PR state --- docs/product-technical-gap-baseline.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 32d79f1f3..351326685 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 108 pull requests and one non-PR issue (#89) are open, verified with the GitHub `open` filters at `2026-08-29 20:44 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 108 pull requests and one non-PR issue (#89) are open, verified with the GitHub `open` filters at `2026-08-29 21:09 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -110,6 +110,9 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #106** remains Draft at exact head `a367b4ea09f6abb4b6b8523c1e7726ee11bfc483`, stacked on the unmerged Position reporting hierarchy lane with base tip `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc`. Its real PostgreSQL 16.14 persistence, immutable review/application audit binding, and concurrent cycle-prevention contracts all pass; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration enforces tenant-scoped bitemporal Position relationships, staffable endpoint coverage, same-tenant review/audit scope, actor separation, immutable closure, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #107** remains Draft at exact head `78e67a0493c6b25210b0fcc4a8a6efddf5d339c7`, stacked on the unmerged Document Record Evidence lane with base tip `59b809bead617d9045357396df684991548bdc30`. Its real PostgreSQL 16.14 immutable document-metadata persistence contract passes; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration stores artifact/provenance references and digests only, binds the exact canonical evidence JSON, enforces PostgreSQL system time, immutability, RLS, and no direct Person/Employment/audit/outbox application-table foreign keys. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #108** remains Draft at exact head `d465d1cd34ec3eeaee863535a7a4142cd018e06b`, stacked on candidate-response parent #80 at the stale recorded base tip `5070f34cd13814f09d74162347f837cb34d76a57`; current parent #80 has advanced to `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702`. Its focused offer-to-hire suite passes 12 tests with exact 100% statement/branch coverage (106/30); compileall, Ruff, actionlint, diff checks, candidate-response package tests (65), and Foundation validation (55/55) pass. The bridge validates accepted-response integrity, authorizes the exact selection decision before protected candidate/offer resolution, requires exact authoritative scope/evidence binding, and delegates mutation only through the existing confirmed-hire path. Its exact-head hosted set has 1 successful dedicated check plus successful Draft-skipped CodeRabbit, all 2 review threads are resolved, and no qualifying independent approval exists. It remains dependency-first active-PR truth only; no parent or stale-base evidence transfers. +- **PR #109** remains Draft at exact head `19e1186ef8111ba6b039c7021f43d4d345275f58`, stacked on Job-grade design parent #101 at base tip `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2`. Its real PostgreSQL 16.14 persistence contract passes after the contract runner was corrected to honor the configured database connection; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration preserves tenant-scoped bitemporal Job-grade history, immutable audit/outbox correlation, and RLS isolation. Its exact-head hosted set has 1 successful dedicated check and no pending contexts; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. +- **PR #110** remains Draft at exact head `16aaac791bc390c4d73c178bc14f09b7d17ab55f`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its full People API suite passes 159 tests with exact 100% statement/branch coverage (1498/500); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. Vacancy-fill orchestration now revalidates command values at the runtime trust boundary and exposes the public API without authorizing employment decisions. Its exact-head hosted set has 33 successful and 7 skipped checks, 3 terminal failures (`opencode-review`, `dependency-review`, `noema-review`), and 1 pending `strix`; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #111** remains Draft at exact head `03f3f6de674ee07cf33b9d2a75f58a8d210d7ed8`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its focused Position lifecycle-review suite passes 36 tests with exact 100% statement/branch coverage (142/40); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet remains human-review evidence and does not mutate Position truth or authorize employment decisions. Its exact-head hosted set has 35 successful and 8 skipped checks with no pending or terminal failure; all 8 current review threads are resolved, no qualifying independent approval exists, and Draft state plus `reviewDecision=REVIEW_REQUIRED` keep it non-authorized. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 2dfbd714e208f08eff178c163725ccce6ce122ce Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 06:11:17 +0900 Subject: [PATCH 132/201] docs: record current stacked parent tip --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 351326685..10259314b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -107,7 +107,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #103** remains open/non-draft at exact head `267d9d5bc58d2e951fe3e428876682c8a5e1daa5` for human-reviewed, non-authorizing Employment work-capacity change evidence. Its focused package suite passes 36 tests with exact 100% statement/branch coverage (170/46); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet keeps Employment/Assignment/compensation/payroll/leave/scheduling mutation outside its boundary, requires exact four-decimal capacity ratios and distinct actor UUIDv4 references, and owns system-recorded UTC issuance time. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #104** remains open/non-draft at exact head `14eab4eb21924f85c9d4eeef325ca37bfff37de3` for human-reviewed, non-authorizing Job qualification-rule evidence. Its focused package suite passes 55 tests with exact 100% statement/branch coverage (165/38); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet binds Job/Job Analysis provenance and reviewed rule categories while never evaluating candidates, rejecting applicants, mutating Job truth, or authorizing employment decisions. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #105** remains Draft at exact head `e9e4731b7bcd41db0e88186ae07e38742c0e220c`, stacked on the unmerged Job qualification-rule review lane with base tip `d92ac4cb798b3bd32b632c0ab677c03f944070e4`. Its real PostgreSQL 16.14 full-chain persistence contract passes, as do Foundation validation (55/55), shellcheck, actionlint, and diff checks; the migration enforces tenant-scoped bitemporal rule history, immutable transaction-time intervals, reviewed Job Analysis scope, audit/outbox correlation, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. -- **PR #106** remains Draft at exact head `a367b4ea09f6abb4b6b8523c1e7726ee11bfc483`, stacked on the unmerged Position reporting hierarchy lane with base tip `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc`. Its real PostgreSQL 16.14 persistence, immutable review/application audit binding, and concurrent cycle-prevention contracts all pass; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration enforces tenant-scoped bitemporal Position relationships, staffable endpoint coverage, same-tenant review/audit scope, actor separation, immutable closure, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. +- **PR #106** remains Draft at exact head `a367b4ea09f6abb4b6b8523c1e7726ee11bfc483`, stacked on the unmerged Position reporting hierarchy lane at recorded base tip `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc`; the tracked parent branch has advanced to `2ff1262b976029e447dc736e6472eebbac30a7f5`, so the stale-base distinction remains explicit. Its real PostgreSQL 16.14 persistence, immutable review/application audit binding, and concurrent cycle-prevention contracts all pass; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration enforces tenant-scoped bitemporal Position relationships, staffable endpoint coverage, same-tenant review/audit scope, actor separation, immutable closure, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #107** remains Draft at exact head `78e67a0493c6b25210b0fcc4a8a6efddf5d339c7`, stacked on the unmerged Document Record Evidence lane with base tip `59b809bead617d9045357396df684991548bdc30`. Its real PostgreSQL 16.14 immutable document-metadata persistence contract passes; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration stores artifact/provenance references and digests only, binds the exact canonical evidence JSON, enforces PostgreSQL system time, immutability, RLS, and no direct Person/Employment/audit/outbox application-table foreign keys. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. - **PR #108** remains Draft at exact head `d465d1cd34ec3eeaee863535a7a4142cd018e06b`, stacked on candidate-response parent #80 at the stale recorded base tip `5070f34cd13814f09d74162347f837cb34d76a57`; current parent #80 has advanced to `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702`. Its focused offer-to-hire suite passes 12 tests with exact 100% statement/branch coverage (106/30); compileall, Ruff, actionlint, diff checks, candidate-response package tests (65), and Foundation validation (55/55) pass. The bridge validates accepted-response integrity, authorizes the exact selection decision before protected candidate/offer resolution, requires exact authoritative scope/evidence binding, and delegates mutation only through the existing confirmed-hire path. Its exact-head hosted set has 1 successful dedicated check plus successful Draft-skipped CodeRabbit, all 2 review threads are resolved, and no qualifying independent approval exists. It remains dependency-first active-PR truth only; no parent or stale-base evidence transfers. - **PR #109** remains Draft at exact head `19e1186ef8111ba6b039c7021f43d4d345275f58`, stacked on Job-grade design parent #101 at base tip `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2`. Its real PostgreSQL 16.14 persistence contract passes after the contract runner was corrected to honor the configured database connection; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration preserves tenant-scoped bitemporal Job-grade history, immutable audit/outbox correlation, and RLS isolation. Its exact-head hosted set has 1 successful dedicated check and no pending contexts; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. From ef103a676930538b637288a8aa3bdcd217b8d431 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 06:20:34 +0900 Subject: [PATCH 133/201] docs: record Position lifecycle application PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 10259314b..a10207849 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -113,6 +113,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #109** remains Draft at exact head `19e1186ef8111ba6b039c7021f43d4d345275f58`, stacked on Job-grade design parent #101 at base tip `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2`. Its real PostgreSQL 16.14 persistence contract passes after the contract runner was corrected to honor the configured database connection; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration preserves tenant-scoped bitemporal Job-grade history, immutable audit/outbox correlation, and RLS isolation. Its exact-head hosted set has 1 successful dedicated check and no pending contexts; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. - **PR #110** remains Draft at exact head `16aaac791bc390c4d73c178bc14f09b7d17ab55f`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its full People API suite passes 159 tests with exact 100% statement/branch coverage (1498/500); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. Vacancy-fill orchestration now revalidates command values at the runtime trust boundary and exposes the public API without authorizing employment decisions. Its exact-head hosted set has 33 successful and 7 skipped checks, 3 terminal failures (`opencode-review`, `dependency-review`, `noema-review`), and 1 pending `strix`; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #111** remains Draft at exact head `03f3f6de674ee07cf33b9d2a75f58a8d210d7ed8`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its focused Position lifecycle-review suite passes 36 tests with exact 100% statement/branch coverage (142/40); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet remains human-review evidence and does not mutate Position truth or authorize employment decisions. Its exact-head hosted set has 35 successful and 8 skipped checks with no pending or terminal failure; all 8 current review threads are resolved, no qualifying independent approval exists, and Draft state plus `reviewDecision=REVIEW_REQUIRED` keep it non-authorized. +- **PR #112** remains Draft at exact head `1889851f9f8c7e0528e047ec53f33f947be6dd88`, stacked on Position lifecycle review at recorded base tip `b9e85a1b8eb92f168fd261aa150a6204490c8023`. Its three real PostgreSQL 16.14 lifecycle contracts pass: application persistence, transition validation, and fresh Position/Assignment snapshot integrity; Foundation validation (55/55), shellcheck, actionlint, diff checks, and manifest verification pass. The database boundary accepts only canonical human-reviewed transitions with fresh tenant-scoped snapshots, preserves bitemporal Position truth, and binds immutable audit/outbox evidence while revoking default PUBLIC execution of the high-impact function. Its exact-head hosted set has 1 successful dedicated check and no pending context; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 1eb044abbfe5713903579fe7c5b737dac3b1adf1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 06:32:27 +0900 Subject: [PATCH 134/201] docs: record employment absence PR state --- docs/product-technical-gap-baseline.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a10207849..fc5f7e3f7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -114,6 +114,8 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #110** remains Draft at exact head `16aaac791bc390c4d73c178bc14f09b7d17ab55f`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its full People API suite passes 159 tests with exact 100% statement/branch coverage (1498/500); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. Vacancy-fill orchestration now revalidates command values at the runtime trust boundary and exposes the public API without authorizing employment decisions. Its exact-head hosted set has 33 successful and 7 skipped checks, 3 terminal failures (`opencode-review`, `dependency-review`, `noema-review`), and 1 pending `strix`; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #111** remains Draft at exact head `03f3f6de674ee07cf33b9d2a75f58a8d210d7ed8`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its focused Position lifecycle-review suite passes 36 tests with exact 100% statement/branch coverage (142/40); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet remains human-review evidence and does not mutate Position truth or authorize employment decisions. Its exact-head hosted set has 35 successful and 8 skipped checks with no pending or terminal failure; all 8 current review threads are resolved, no qualifying independent approval exists, and Draft state plus `reviewDecision=REVIEW_REQUIRED` keep it non-authorized. - **PR #112** remains Draft at exact head `1889851f9f8c7e0528e047ec53f33f947be6dd88`, stacked on Position lifecycle review at recorded base tip `b9e85a1b8eb92f168fd261aa150a6204490c8023`. Its three real PostgreSQL 16.14 lifecycle contracts pass: application persistence, transition validation, and fresh Position/Assignment snapshot integrity; Foundation validation (55/55), shellcheck, actionlint, diff checks, and manifest verification pass. The database boundary accepts only canonical human-reviewed transitions with fresh tenant-scoped snapshots, preserves bitemporal Position truth, and binds immutable audit/outbox evidence while revoking default PUBLIC execution of the high-impact function. Its exact-head hosted set has 1 successful dedicated check and no pending context; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. +- **PR #113** remains Draft at exact head `9e53a80f2f91616253e076cfff92d659a6f1cb08`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects reserved Nil/Max UUID sentinels at the Employment absence domain boundary; the HRIS kernel suite passes 204 tests with exact 100% statement/branch coverage, and compileall, Ruff, npm validation, and diff checks pass. Its exact-head hosted set currently has 6 skipped completed checks and 30 pending checks with no terminal failure; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #114** remains Draft at exact head `d99ad8b7c5e0cee2e6ae73bb2e06ab702b43cfc0`, stacked on parent #113's recorded base tip `3da7ad076f977a3ccd9e130a58786c9d26763a16`; the parent branch now points to `9e53a80f2f91616253e076cfff92d659a6f1cb08`, so the stale-base distinction remains explicit. Its fresh PostgreSQL 16.14 persistence contract passes, as do Foundation validation (55/55), ShellCheck, bash syntax, actionlint, diff checks, and manifest verification. The migration adds separate tenant-qualified bitemporal absence identity/version relations, full active/leave coverage validation for confirmed facts, post-coverage cancellation correction, serialized overlap rejection, immutable system-time closure, forced RLS, and opaque audit/outbox correlations without querying foreign service tables. Its exact-head hosted set has 1 successful dedicated check and no pending context; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. After #113 integrates, retarget this child to fresh `develop`, reconcile migration ordering, and rerun all applicable gates on the resulting exact head. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From f354c918d1dd20433d59a1b506d39791983105c1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 06:49:58 +0900 Subject: [PATCH 135/201] docs: record freshness and retrieval PR state --- docs/product-technical-gap-baseline.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index fc5f7e3f7..0528ce5f3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -114,8 +114,10 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #110** remains Draft at exact head `16aaac791bc390c4d73c178bc14f09b7d17ab55f`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its full People API suite passes 159 tests with exact 100% statement/branch coverage (1498/500); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. Vacancy-fill orchestration now revalidates command values at the runtime trust boundary and exposes the public API without authorizing employment decisions. Its exact-head hosted set has 33 successful and 7 skipped checks, 3 terminal failures (`opencode-review`, `dependency-review`, `noema-review`), and 1 pending `strix`; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #111** remains Draft at exact head `03f3f6de674ee07cf33b9d2a75f58a8d210d7ed8`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its focused Position lifecycle-review suite passes 36 tests with exact 100% statement/branch coverage (142/40); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet remains human-review evidence and does not mutate Position truth or authorize employment decisions. Its exact-head hosted set has 35 successful and 8 skipped checks with no pending or terminal failure; all 8 current review threads are resolved, no qualifying independent approval exists, and Draft state plus `reviewDecision=REVIEW_REQUIRED` keep it non-authorized. - **PR #112** remains Draft at exact head `1889851f9f8c7e0528e047ec53f33f947be6dd88`, stacked on Position lifecycle review at recorded base tip `b9e85a1b8eb92f168fd261aa150a6204490c8023`. Its three real PostgreSQL 16.14 lifecycle contracts pass: application persistence, transition validation, and fresh Position/Assignment snapshot integrity; Foundation validation (55/55), shellcheck, actionlint, diff checks, and manifest verification pass. The database boundary accepts only canonical human-reviewed transitions with fresh tenant-scoped snapshots, preserves bitemporal Position truth, and binds immutable audit/outbox evidence while revoking default PUBLIC execution of the high-impact function. Its exact-head hosted set has 1 successful dedicated check and no pending context; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. -- **PR #113** remains Draft at exact head `9e53a80f2f91616253e076cfff92d659a6f1cb08`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects reserved Nil/Max UUID sentinels at the Employment absence domain boundary; the HRIS kernel suite passes 204 tests with exact 100% statement/branch coverage, and compileall, Ruff, npm validation, and diff checks pass. Its exact-head hosted set currently has 6 skipped completed checks and 30 pending checks with no terminal failure; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. +- **PR #113** remains Draft at exact head `9e53a80f2f91616253e076cfff92d659a6f1cb08`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects reserved Nil/Max UUID sentinels at the Employment absence domain boundary; the HRIS kernel suite passes 204 tests with exact 100% statement/branch coverage, and compileall, Ruff, npm validation, and diff checks pass. Its exact-head hosted set currently has 25 successful and 6 skipped checks, 2 terminal failures (`dependency-review`, `noema-review`), and 9 pending checks; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. - **PR #114** remains Draft at exact head `d99ad8b7c5e0cee2e6ae73bb2e06ab702b43cfc0`, stacked on parent #113's recorded base tip `3da7ad076f977a3ccd9e130a58786c9d26763a16`; the parent branch now points to `9e53a80f2f91616253e076cfff92d659a6f1cb08`, so the stale-base distinction remains explicit. Its fresh PostgreSQL 16.14 persistence contract passes, as do Foundation validation (55/55), ShellCheck, bash syntax, actionlint, diff checks, and manifest verification. The migration adds separate tenant-qualified bitemporal absence identity/version relations, full active/leave coverage validation for confirmed facts, post-coverage cancellation correction, serialized overlap rejection, immutable system-time closure, forced RLS, and opaque audit/outbox correlations without querying foreign service tables. Its exact-head hosted set has 1 successful dedicated check and no pending context; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. After #113 integrates, retarget this child to fresh `develop`, reconcile migration ordering, and rerun all applicable gates on the resulting exact head. +- **PR #115** remains Draft at exact head `de2b0aa5e6cd226815b25f7e83a8130c6f124a6a`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The read-only hourly freshness audit now compares recorded open PR/issue counts with complete live queues, fails closed on empty or malformed `develop` evidence, and explicitly checks out the default branch on manual dispatch; its 10 regression tests, Ruff, compileall, Foundation validation (55/55), actionlint, and diff checks pass. Its exact-head hosted set has 6 skipped completed checks and 26 pending checks with no terminal failure; all 7 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. +- **PR #116** remains Draft at exact head `5c19fdc708b765f7ee2942eee7b455ba5bbcf289`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The HR document retrieval boundary now performs a final authorization-freshness check after immutable audit append and before byte release; package tests pass 29 tests with exact 100% statement/branch coverage (284/72), alongside Foundation validation (55/55), Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 6 skipped completed checks and 27 pending checks with no terminal failure; all 5 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 4f38e130a00f2b08650646660e7ae46da62b1898 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 06:55:35 +0900 Subject: [PATCH 136/201] docs: record job analysis draft PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0528ce5f3..4f3a2ecba 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -118,6 +118,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #114** remains Draft at exact head `d99ad8b7c5e0cee2e6ae73bb2e06ab702b43cfc0`, stacked on parent #113's recorded base tip `3da7ad076f977a3ccd9e130a58786c9d26763a16`; the parent branch now points to `9e53a80f2f91616253e076cfff92d659a6f1cb08`, so the stale-base distinction remains explicit. Its fresh PostgreSQL 16.14 persistence contract passes, as do Foundation validation (55/55), ShellCheck, bash syntax, actionlint, diff checks, and manifest verification. The migration adds separate tenant-qualified bitemporal absence identity/version relations, full active/leave coverage validation for confirmed facts, post-coverage cancellation correction, serialized overlap rejection, immutable system-time closure, forced RLS, and opaque audit/outbox correlations without querying foreign service tables. Its exact-head hosted set has 1 successful dedicated check and no pending context; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. After #113 integrates, retarget this child to fresh `develop`, reconcile migration ordering, and rerun all applicable gates on the resulting exact head. - **PR #115** remains Draft at exact head `de2b0aa5e6cd226815b25f7e83a8130c6f124a6a`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The read-only hourly freshness audit now compares recorded open PR/issue counts with complete live queues, fails closed on empty or malformed `develop` evidence, and explicitly checks out the default branch on manual dispatch; its 10 regression tests, Ruff, compileall, Foundation validation (55/55), actionlint, and diff checks pass. Its exact-head hosted set has 6 skipped completed checks and 26 pending checks with no terminal failure; all 7 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. - **PR #116** remains Draft at exact head `5c19fdc708b765f7ee2942eee7b455ba5bbcf289`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The HR document retrieval boundary now performs a final authorization-freshness check after immutable audit append and before byte release; package tests pass 29 tests with exact 100% statement/branch coverage (284/72), alongside Foundation validation (55/55), Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 6 skipped completed checks and 27 pending checks with no terminal failure; all 5 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. +- **PR #117** remains Draft at exact head `394a3ac5644d2ab7e9a04fd118269d438dad3f46`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Review found no additional source defect; its model-draft workflow passes 35 package tests with exact 100% statement/branch coverage (251/76), plus docstring, Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 33 successful and 8 skipped checks, 2 terminal failures (`opencode-review`, `strix`), and no pending checks; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From dec018fba0043746dfdfe7564dbb2c98c780f9c3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 07:04:37 +0900 Subject: [PATCH 137/201] docs: record release readiness review PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4f3a2ecba..b1193b00a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -119,6 +119,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #115** remains Draft at exact head `de2b0aa5e6cd226815b25f7e83a8130c6f124a6a`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The read-only hourly freshness audit now compares recorded open PR/issue counts with complete live queues, fails closed on empty or malformed `develop` evidence, and explicitly checks out the default branch on manual dispatch; its 10 regression tests, Ruff, compileall, Foundation validation (55/55), actionlint, and diff checks pass. Its exact-head hosted set has 6 skipped completed checks and 26 pending checks with no terminal failure; all 7 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. - **PR #116** remains Draft at exact head `5c19fdc708b765f7ee2942eee7b455ba5bbcf289`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The HR document retrieval boundary now performs a final authorization-freshness check after immutable audit append and before byte release; package tests pass 29 tests with exact 100% statement/branch coverage (284/72), alongside Foundation validation (55/55), Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 6 skipped completed checks and 27 pending checks with no terminal failure; all 5 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. - **PR #117** remains Draft at exact head `394a3ac5644d2ab7e9a04fd118269d438dad3f46`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Review found no additional source defect; its model-draft workflow passes 35 package tests with exact 100% statement/branch coverage (251/76), plus docstring, Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 33 successful and 8 skipped checks, 2 terminal failures (`opencode-review`, `strix`), and no pending checks; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. +- **PR #118** is non-draft at exact head `beece4d2ffcd20258bf0e015477dd45448ed05d0`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects Git's null OID so readiness evidence cannot bind to a nonexistent candidate; its package suite passes 25 tests with exact 100% statement/branch coverage (148/38), plus docstring, compileall, Ruff, actionlint, diff, and Foundation validation (55/55). Its exact-head hosted snapshot currently has 6 skipped completed checks and 27 pending checks with no terminal failure; all 4 current review threads are resolved, no qualifying independent approval exists, and `reviewDecision=REVIEW_REQUIRED`/`mergeStateStatus=BLOCKED` keep it non-authorized. The packet remains non-authorizing and cannot tag, sign, publish, deploy, or release. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From b4ffa623675fb3cb36d370a1abed1fe35300bb57 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 07:52:08 +0900 Subject: [PATCH 138/201] docs: record hierarchy application PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b1193b00a..6dcf88141 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -120,6 +120,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #116** remains Draft at exact head `5c19fdc708b765f7ee2942eee7b455ba5bbcf289`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The HR document retrieval boundary now performs a final authorization-freshness check after immutable audit append and before byte release; package tests pass 29 tests with exact 100% statement/branch coverage (284/72), alongside Foundation validation (55/55), Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 6 skipped completed checks and 27 pending checks with no terminal failure; all 5 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. - **PR #117** remains Draft at exact head `394a3ac5644d2ab7e9a04fd118269d438dad3f46`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Review found no additional source defect; its model-draft workflow passes 35 package tests with exact 100% statement/branch coverage (251/76), plus docstring, Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 33 successful and 8 skipped checks, 2 terminal failures (`opencode-review`, `strix`), and no pending checks; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. - **PR #118** is non-draft at exact head `beece4d2ffcd20258bf0e015477dd45448ed05d0`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects Git's null OID so readiness evidence cannot bind to a nonexistent candidate; its package suite passes 25 tests with exact 100% statement/branch coverage (148/38), plus docstring, compileall, Ruff, actionlint, diff, and Foundation validation (55/55). Its exact-head hosted snapshot currently has 6 skipped completed checks and 27 pending checks with no terminal failure; all 4 current review threads are resolved, no qualifying independent approval exists, and `reviewDecision=REVIEW_REQUIRED`/`mergeStateStatus=BLOCKED` keep it non-authorized. The packet remains non-authorizing and cannot tag, sign, publish, deploy, or release. +- **PR #119** remains open/non-draft at exact head `f7c83600471ae0363d9b4a2b2533aedba01166b1`, stacked on parent #96 at recorded base `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd`; parent #96 has advanced to `6a8454ff8ad0c52790b4a72f1fde67f61cc11358`, so GitHub reports `mergeStateStatus=DIRTY`/`CONFLICTING`. The valid repair hardens typed/null-safe review validation, tenant/unit-qualified predecessor and deferred successor bindings, reviewed-column integrity, and cycle detection across future effective-time boundaries. The review package passes 48 tests with exact 100% statement/branch coverage (182/60); real PostgreSQL 16.14 application and 0028 concurrency contracts, Foundation validation (55/55), actionlint, bash syntax, CodeGraph sync, and diff checks pass. Exact-head GitHub check-runs currently total 0, no qualifying approval exists, 16 of 17 review threads are resolved, and the caller-controlled tenant-context security thread remains unresolved. This child is not merge-authorized and must be retargeted/revalidated only after #96 integrates. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 941ae863c39a7c818d585db26fc3584ced28eec4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 07:59:02 +0900 Subject: [PATCH 139/201] docs: record HR export execution PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6dcf88141..8f75c5043 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -121,6 +121,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #117** remains Draft at exact head `394a3ac5644d2ab7e9a04fd118269d438dad3f46`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Review found no additional source defect; its model-draft workflow passes 35 package tests with exact 100% statement/branch coverage (251/76), plus docstring, Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 33 successful and 8 skipped checks, 2 terminal failures (`opencode-review`, `strix`), and no pending checks; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. - **PR #118** is non-draft at exact head `beece4d2ffcd20258bf0e015477dd45448ed05d0`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects Git's null OID so readiness evidence cannot bind to a nonexistent candidate; its package suite passes 25 tests with exact 100% statement/branch coverage (148/38), plus docstring, compileall, Ruff, actionlint, diff, and Foundation validation (55/55). Its exact-head hosted snapshot currently has 6 skipped completed checks and 27 pending checks with no terminal failure; all 4 current review threads are resolved, no qualifying independent approval exists, and `reviewDecision=REVIEW_REQUIRED`/`mergeStateStatus=BLOCKED` keep it non-authorized. The packet remains non-authorizing and cannot tag, sign, publish, deploy, or release. - **PR #119** remains open/non-draft at exact head `f7c83600471ae0363d9b4a2b2533aedba01166b1`, stacked on parent #96 at recorded base `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd`; parent #96 has advanced to `6a8454ff8ad0c52790b4a72f1fde67f61cc11358`, so GitHub reports `mergeStateStatus=DIRTY`/`CONFLICTING`. The valid repair hardens typed/null-safe review validation, tenant/unit-qualified predecessor and deferred successor bindings, reviewed-column integrity, and cycle detection across future effective-time boundaries. The review package passes 48 tests with exact 100% statement/branch coverage (182/60); real PostgreSQL 16.14 application and 0028 concurrency contracts, Foundation validation (55/55), actionlint, bash syntax, CodeGraph sync, and diff checks pass. Exact-head GitHub check-runs currently total 0, no qualifying approval exists, 16 of 17 review threads are resolved, and the caller-controlled tenant-context security thread remains unresolved. This child is not merge-authorized and must be retargeted/revalidated only after #96 integrates. +- **PR #120** remains Draft at exact head `aadf4916ee64820b4f5c6a78430c9fec675e2078`, based on `feat/governed-hr-data-export-control` at `282ff0966add47a80a2edd76f84c4c65a868fedb`; parent #75 is still Draft and unintegrated at exact head `968111f88d59f340f78afd5f6aea2291221bffa1`. Its focused HR export execution suite passes 129 tests with exact 100% statement/branch coverage (497/114), covering authorization-expiry races, immutable audit-before-egress, exact artifact binding, and reconciliation-only at-most-once delivery after ambiguous publication. The exact-head hosted set contains one terminal successful check, `HR data export contract and 100% coverage`; no parent or predecessor evidence transfers. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=DIRTY`/`mergeable=false` with `reviewDecision=null`; it remains dependency-first active-PR truth only and must be retargeted/revalidated after #75 integrates. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From 43a0582b446d5aacdb6bad3f65be1aa53d4f0fd6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 08:06:07 +0900 Subject: [PATCH 140/201] docs: record goal activation PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8f75c5043..f247c0189 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -122,6 +122,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #118** is non-draft at exact head `beece4d2ffcd20258bf0e015477dd45448ed05d0`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects Git's null OID so readiness evidence cannot bind to a nonexistent candidate; its package suite passes 25 tests with exact 100% statement/branch coverage (148/38), plus docstring, compileall, Ruff, actionlint, diff, and Foundation validation (55/55). Its exact-head hosted snapshot currently has 6 skipped completed checks and 27 pending checks with no terminal failure; all 4 current review threads are resolved, no qualifying independent approval exists, and `reviewDecision=REVIEW_REQUIRED`/`mergeStateStatus=BLOCKED` keep it non-authorized. The packet remains non-authorizing and cannot tag, sign, publish, deploy, or release. - **PR #119** remains open/non-draft at exact head `f7c83600471ae0363d9b4a2b2533aedba01166b1`, stacked on parent #96 at recorded base `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd`; parent #96 has advanced to `6a8454ff8ad0c52790b4a72f1fde67f61cc11358`, so GitHub reports `mergeStateStatus=DIRTY`/`CONFLICTING`. The valid repair hardens typed/null-safe review validation, tenant/unit-qualified predecessor and deferred successor bindings, reviewed-column integrity, and cycle detection across future effective-time boundaries. The review package passes 48 tests with exact 100% statement/branch coverage (182/60); real PostgreSQL 16.14 application and 0028 concurrency contracts, Foundation validation (55/55), actionlint, bash syntax, CodeGraph sync, and diff checks pass. Exact-head GitHub check-runs currently total 0, no qualifying approval exists, 16 of 17 review threads are resolved, and the caller-controlled tenant-context security thread remains unresolved. This child is not merge-authorized and must be retargeted/revalidated only after #96 integrates. - **PR #120** remains Draft at exact head `aadf4916ee64820b4f5c6a78430c9fec675e2078`, based on `feat/governed-hr-data-export-control` at `282ff0966add47a80a2edd76f84c4c65a868fedb`; parent #75 is still Draft and unintegrated at exact head `968111f88d59f340f78afd5f6aea2291221bffa1`. Its focused HR export execution suite passes 129 tests with exact 100% statement/branch coverage (497/114), covering authorization-expiry races, immutable audit-before-egress, exact artifact binding, and reconciliation-only at-most-once delivery after ambiguous publication. The exact-head hosted set contains one terminal successful check, `HR data export contract and 100% coverage`; no parent or predecessor evidence transfers. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=DIRTY`/`mergeable=false` with `reviewDecision=null`; it remains dependency-first active-PR truth only and must be retargeted/revalidated after #75 integrates. +- **PR #121** remains open/non-draft at exact head `c7fba99a3b86cae612083242091fc6fd0b426ebb`, based on `feat/performance-goal-plan-evidence` at recorded base `141574958df2238d107121138c1ffb5f854126cc`; parent #92 is unintegrated at current exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487`. The valid repair separates future-time admission from sealed receipt serialization so issued activation evidence remains readable after wall-clock rollback; its focused suite passes 61 tests with exact 100% statement/branch coverage (321/76), plus compileall, Ruff, diff, and CodeGraph synchronization. The exact-head hosted set has one terminal successful dedicated check, all 4 current review threads are resolved, and no qualifying independent approval exists. GitHub reports `mergeStateStatus=CLEAN`/`mergeable=true` with `reviewDecision=null`; it remains stack-local active-PR truth only and must be retargeted/revalidated after #92 integrates. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. From a918da4e6d7bd9d53e37b7e25a6843df6855c8c3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 08:09:55 +0900 Subject: [PATCH 141/201] docs: record service portability PR state --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f247c0189..dfccaa923 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -125,7 +125,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #121** remains open/non-draft at exact head `c7fba99a3b86cae612083242091fc6fd0b426ebb`, based on `feat/performance-goal-plan-evidence` at recorded base `141574958df2238d107121138c1ffb5f854126cc`; parent #92 is unintegrated at current exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487`. The valid repair separates future-time admission from sealed receipt serialization so issued activation evidence remains readable after wall-clock rollback; its focused suite passes 61 tests with exact 100% statement/branch coverage (321/76), plus compileall, Ruff, diff, and CodeGraph synchronization. The exact-head hosted set has one terminal successful dedicated check, all 4 current review threads are resolved, and no qualifying independent approval exists. GitHub reports `mergeStateStatus=CLEAN`/`mergeable=true` with `reviewDecision=null`; it remains stack-local active-PR truth only and must be retargeted/revalidated after #92 integrates. - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. -- **PR #122** remains exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e` with all applicable hosted service, PostgreSQL, Foundation, SAST, dependency, security, OpenCode, Noema, and Strix checks GREEN; it has no qualifying independent approval and is not merge-authorized. +- **PR #122** remains open/non-draft at exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its target-side portability contract passes from the service directories with 69 job-analysis API tests and 146 People API tests, both at exact 100% statement/branch coverage; compileall and diff checks pass. The exact-head hosted set is terminal with 37 successful and 8 skipped checks, including coverage, SAST, dependency, security, OpenCode, Noema, Strix, PostgreSQL, recovery, and Foundation evidence where applicable. The one current review thread is resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains target-side active-PR truth only and does not repair the central coverage pipeline. - **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful, 2 failed, and 8 skipped checks; both `opencode-review` and `strix` are terminal FAILURE, with no current-head OpenCode verdict and no authoritative Strix report. All current review threads are resolved and no qualifying independent approval exists. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. From d46c379e026c3c8bc9af6093e0b9f3286d175a3b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 08:15:05 +0900 Subject: [PATCH 142/201] docs: record customer copy PR state --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index dfccaa923..4db16f9e3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -126,7 +126,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains open/non-draft at exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its target-side portability contract passes from the service directories with 69 job-analysis API tests and 146 People API tests, both at exact 100% statement/branch coverage; compileall and diff checks pass. The exact-head hosted set is terminal with 37 successful and 8 skipped checks, including coverage, SAST, dependency, security, OpenCode, Noema, Strix, PostgreSQL, recovery, and Foundation evidence where applicable. The one current review thread is resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains target-side active-PR truth only and does not repair the central coverage pipeline. -- **PR #123** remains exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1` after branch-bound manifest provenance was resealed. Its exact-head suite has 39 successful, 2 failed, and 8 skipped checks; both `opencode-review` and `strix` are terminal FAILURE, with no current-head OpenCode verdict and no authoritative Strix report. All current review threads are resolved and no qualifying independent approval exists. +- **PR #123** remains open/non-draft at exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after branch-bound manifest provenance was resealed. The affected candidate-evidence, offer-approval, requisition-review, HRIS-kernel, and People API suites pass locally with 75, 84, 61, 171, and 146 tests respectively, all at exact 100% statement/branch coverage; repository validation and Foundation validation (55/55) pass. Its exact-head hosted set has 39 successful, 2 failed, and 8 skipped raw check-runs; latest-by-name evidence is 39 successful, 2 skipped, and 2 terminal failures (`opencode-review` and `strix`) with no current-head OpenCode verdict or authoritative Strix report. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains active-PR truth only. - **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. From c5b82b92c1560442801503703a921347a64a67c0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 08:18:22 +0900 Subject: [PATCH 143/201] docs: record acceleration ADR PR state --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4db16f9e3..ba9fd6aa1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -127,7 +127,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains open/non-draft at exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its target-side portability contract passes from the service directories with 69 job-analysis API tests and 146 People API tests, both at exact 100% statement/branch coverage; compileall and diff checks pass. The exact-head hosted set is terminal with 37 successful and 8 skipped checks, including coverage, SAST, dependency, security, OpenCode, Noema, Strix, PostgreSQL, recovery, and Foundation evidence where applicable. The one current review thread is resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains target-side active-PR truth only and does not repair the central coverage pipeline. - **PR #123** remains open/non-draft at exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after branch-bound manifest provenance was resealed. The affected candidate-evidence, offer-approval, requisition-review, HRIS-kernel, and People API suites pass locally with 75, 84, 61, 171, and 146 tests respectively, all at exact 100% statement/branch coverage; repository validation and Foundation validation (55/55) pass. Its exact-head hosted set has 39 successful, 2 failed, and 8 skipped raw check-runs; latest-by-name evidence is 39 successful, 2 skipped, and 2 terminal failures (`opencode-review` and `strix`) with no current-head OpenCode verdict or authoritative Strix report. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains active-PR truth only. -- **PR #124** remains exact head `e17c9cbf51d14f63e844c9137865d58521c40701` after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its exact-head suite has 35 successful and 8 skipped checks, with `opencode-review` and `strix` terminal FAILURE; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth only. +- **PR #124** remains open/non-draft at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its ADR contract passes 6 tests; Foundation validation (55/55), actionlint, and diff checks pass. The exact-head hosted set has 35 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); all 13 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`. It remains active-PR truth only and does not authorize accelerator implementation, promotion, release, or deployment. - **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. From 5c1b15a4660cb93ac9f23fd8edd1aaeb8945ce72 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 08:37:29 +0900 Subject: [PATCH 144/201] docs: record goal-plan persistence security repair --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ba9fd6aa1..f259aeb24 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -128,7 +128,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #122** remains open/non-draft at exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its target-side portability contract passes from the service directories with 69 job-analysis API tests and 146 People API tests, both at exact 100% statement/branch coverage; compileall and diff checks pass. The exact-head hosted set is terminal with 37 successful and 8 skipped checks, including coverage, SAST, dependency, security, OpenCode, Noema, Strix, PostgreSQL, recovery, and Foundation evidence where applicable. The one current review thread is resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains target-side active-PR truth only and does not repair the central coverage pipeline. - **PR #123** remains open/non-draft at exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after branch-bound manifest provenance was resealed. The affected candidate-evidence, offer-approval, requisition-review, HRIS-kernel, and People API suites pass locally with 75, 84, 61, 171, and 146 tests respectively, all at exact 100% statement/branch coverage; repository validation and Foundation validation (55/55) pass. Its exact-head hosted set has 39 successful, 2 failed, and 8 skipped raw check-runs; latest-by-name evidence is 39 successful, 2 skipped, and 2 terminal failures (`opencode-review` and `strix`) with no current-head OpenCode verdict or authoritative Strix report. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains active-PR truth only. - **PR #124** remains open/non-draft at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its ADR contract passes 6 tests; Foundation validation (55/55), actionlint, and diff checks pass. The exact-head hosted set has 35 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); all 13 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`. It remains active-PR truth only and does not authorize accelerator implementation, promotion, release, or deployment. -- **PR #125** remains exact head `fb48b527f846ee7e893d2e251a33cca7d8a8a0ca` as a Draft child of #121. Its dedicated persistence contract is GREEN after a real PostgreSQL 16.14 migration/trigger/RLS rehearsal, but no qualifying independent approval exists and the Draft state prevents merge authorization. +- **PR #125** remains open/Draft at exact head `ea97b791fc3d27d786d2bd81c19b994dcc872208`, targeting `feat/performance-goal-plan-activation` at `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`, as a dependency-first child of #121. Exact-head local PostgreSQL 16.14 persistence tests pass, including the search-path shadowing regression; Foundation validation is 55/55 and shellcheck/diff checks pass. Its one exact-head hosted persistence check is in progress with no terminal failure yet; no qualifying independent approval exists, all current review threads are resolved, and GraphQL reports `MERGEABLE`/`CLEAN` while it remains Draft. It is active-PR/stack-local truth only and must retarget/revalidate after #121 integrates. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. @@ -148,7 +148,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. -- **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child GREEN is stack-local only. +- **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding and fixed function search paths. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child checks and any clean/mergeable state are stack-local only. - **PR #103 → #128** is the Employment work-capacity backend stack. #103 owns human review evidence; #128 owns dependency-first durable persistence. #138 is presentation/interaction only and must never substitute for authoritative backend validation or mutation. - **PR #113 → #114** is the Employment absence truth/persistence stack. Absence remains reason-free authoritative HRIS evidence and is distinct from work-capacity, leave-review, payroll, scheduling, and employment-decision semantics. #139 is presentation/interaction only and must never infer a reason, attendance/fitness, or consequential authority. - **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118 owns readiness review, #126 exact-revision authorization, and #127 reconciled at-most-once publication. No parent checks/reviews transfer and the repository release collection remains empty. From d78a5870a521f5cca80dc13aa30d5812515a8665 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 08:43:59 +0900 Subject: [PATCH 145/201] docs: record release authorization PR state --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f259aeb24..14ef7fa12 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -129,6 +129,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #123** remains open/non-draft at exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after branch-bound manifest provenance was resealed. The affected candidate-evidence, offer-approval, requisition-review, HRIS-kernel, and People API suites pass locally with 75, 84, 61, 171, and 146 tests respectively, all at exact 100% statement/branch coverage; repository validation and Foundation validation (55/55) pass. Its exact-head hosted set has 39 successful, 2 failed, and 8 skipped raw check-runs; latest-by-name evidence is 39 successful, 2 skipped, and 2 terminal failures (`opencode-review` and `strix`) with no current-head OpenCode verdict or authoritative Strix report. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains active-PR truth only. - **PR #124** remains open/non-draft at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its ADR contract passes 6 tests; Foundation validation (55/55), actionlint, and diff checks pass. The exact-head hosted set has 35 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); all 13 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`. It remains active-PR truth only and does not authorize accelerator implementation, promotion, release, or deployment. - **PR #125** remains open/Draft at exact head `ea97b791fc3d27d786d2bd81c19b994dcc872208`, targeting `feat/performance-goal-plan-activation` at `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`, as a dependency-first child of #121. Exact-head local PostgreSQL 16.14 persistence tests pass, including the search-path shadowing regression; Foundation validation is 55/55 and shellcheck/diff checks pass. Its one exact-head hosted persistence check is in progress with no terminal failure yet; no qualifying independent approval exists, all current review threads are resolved, and GraphQL reports `MERGEABLE`/`CLEAN` while it remains Draft. It is active-PR/stack-local truth only and must retarget/revalidate after #121 integrates. +- **PR #126** remains open/Draft at exact head `c13b2d35d135abf2e33447be217014cd5588d6cb`, stacked on PR #118 at `eb529093b44be17bb282d3fd5c6c592d66f111af`. Its release-authorization package passes 36 tests with exact 100% statement/branch coverage (226/58), plus isolated package-install, docstring, compile, Ruff, and diff checks; the dedicated exact-head check is terminal GREEN. No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged parent keep it non-authorized. It must retarget/revalidate on fresh `develop` after #118 integrates; no release/tag/publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. From afd3dda7e8d9eab697bd56b0048437cb9a83ce85 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 08:47:26 +0900 Subject: [PATCH 146/201] docs: record goal-plan persistence check --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 14ef7fa12..c96f2e7db 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -128,7 +128,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #122** remains open/non-draft at exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its target-side portability contract passes from the service directories with 69 job-analysis API tests and 146 People API tests, both at exact 100% statement/branch coverage; compileall and diff checks pass. The exact-head hosted set is terminal with 37 successful and 8 skipped checks, including coverage, SAST, dependency, security, OpenCode, Noema, Strix, PostgreSQL, recovery, and Foundation evidence where applicable. The one current review thread is resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains target-side active-PR truth only and does not repair the central coverage pipeline. - **PR #123** remains open/non-draft at exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after branch-bound manifest provenance was resealed. The affected candidate-evidence, offer-approval, requisition-review, HRIS-kernel, and People API suites pass locally with 75, 84, 61, 171, and 146 tests respectively, all at exact 100% statement/branch coverage; repository validation and Foundation validation (55/55) pass. Its exact-head hosted set has 39 successful, 2 failed, and 8 skipped raw check-runs; latest-by-name evidence is 39 successful, 2 skipped, and 2 terminal failures (`opencode-review` and `strix`) with no current-head OpenCode verdict or authoritative Strix report. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains active-PR truth only. - **PR #124** remains open/non-draft at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its ADR contract passes 6 tests; Foundation validation (55/55), actionlint, and diff checks pass. The exact-head hosted set has 35 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); all 13 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`. It remains active-PR truth only and does not authorize accelerator implementation, promotion, release, or deployment. -- **PR #125** remains open/Draft at exact head `ea97b791fc3d27d786d2bd81c19b994dcc872208`, targeting `feat/performance-goal-plan-activation` at `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`, as a dependency-first child of #121. Exact-head local PostgreSQL 16.14 persistence tests pass, including the search-path shadowing regression; Foundation validation is 55/55 and shellcheck/diff checks pass. Its one exact-head hosted persistence check is in progress with no terminal failure yet; no qualifying independent approval exists, all current review threads are resolved, and GraphQL reports `MERGEABLE`/`CLEAN` while it remains Draft. It is active-PR/stack-local truth only and must retarget/revalidate after #121 integrates. +- **PR #125** remains open/Draft at exact head `ea97b791fc3d27d786d2bd81c19b994dcc872208`, targeting `feat/performance-goal-plan-activation` at `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`, as a dependency-first child of #121. Exact-head local PostgreSQL 16.14 persistence tests pass, including the search-path shadowing regression; Foundation validation is 55/55 and shellcheck/diff checks pass. Its one exact-head hosted persistence check is terminal GREEN ([run 33281305828 / job 99176826069](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33281305828/job/99176826069)); no qualifying independent approval exists, all current review threads are resolved, and GraphQL reports `MERGEABLE`/`CLEAN` while it remains Draft. It is active-PR/stack-local truth only and must retarget/revalidate after #121 integrates. - **PR #126** remains open/Draft at exact head `c13b2d35d135abf2e33447be217014cd5588d6cb`, stacked on PR #118 at `eb529093b44be17bb282d3fd5c6c592d66f111af`. Its release-authorization package passes 36 tests with exact 100% statement/branch coverage (226/58), plus isolated package-install, docstring, compile, Ruff, and diff checks; the dedicated exact-head check is terminal GREEN. No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged parent keep it non-authorized. It must retarget/revalidate on fresh `develop` after #118 integrates; no release/tag/publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. From 880c6d4696f2d4a2112dba118fbaf6dba2bbcb27 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 08:55:02 +0900 Subject: [PATCH 147/201] docs: record release publication check --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c96f2e7db..4e2e3ad43 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -130,6 +130,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #124** remains open/non-draft at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its ADR contract passes 6 tests; Foundation validation (55/55), actionlint, and diff checks pass. The exact-head hosted set has 35 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); all 13 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`. It remains active-PR truth only and does not authorize accelerator implementation, promotion, release, or deployment. - **PR #125** remains open/Draft at exact head `ea97b791fc3d27d786d2bd81c19b994dcc872208`, targeting `feat/performance-goal-plan-activation` at `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`, as a dependency-first child of #121. Exact-head local PostgreSQL 16.14 persistence tests pass, including the search-path shadowing regression; Foundation validation is 55/55 and shellcheck/diff checks pass. Its one exact-head hosted persistence check is terminal GREEN ([run 33281305828 / job 99176826069](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33281305828/job/99176826069)); no qualifying independent approval exists, all current review threads are resolved, and GraphQL reports `MERGEABLE`/`CLEAN` while it remains Draft. It is active-PR/stack-local truth only and must retarget/revalidate after #121 integrates. - **PR #126** remains open/Draft at exact head `c13b2d35d135abf2e33447be217014cd5588d6cb`, stacked on PR #118 at `eb529093b44be17bb282d3fd5c6c592d66f111af`. Its release-authorization package passes 36 tests with exact 100% statement/branch coverage (226/58), plus isolated package-install, docstring, compile, Ruff, and diff checks; the dedicated exact-head check is terminal GREEN. No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged parent keep it non-authorized. It must retarget/revalidate on fresh `develop` after #118 integrates; no release/tag/publication authority is shipped. +- **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. From e4ca6d5266fe741208f4904d62ca115c1864d745 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:12:50 +0900 Subject: [PATCH 148/201] docs: record work-capacity persistence check --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4e2e3ad43..7b22f3d31 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -130,6 +130,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #124** remains open/non-draft at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its ADR contract passes 6 tests; Foundation validation (55/55), actionlint, and diff checks pass. The exact-head hosted set has 35 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); all 13 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`. It remains active-PR truth only and does not authorize accelerator implementation, promotion, release, or deployment. - **PR #125** remains open/Draft at exact head `ea97b791fc3d27d786d2bd81c19b994dcc872208`, targeting `feat/performance-goal-plan-activation` at `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`, as a dependency-first child of #121. Exact-head local PostgreSQL 16.14 persistence tests pass, including the search-path shadowing regression; Foundation validation is 55/55 and shellcheck/diff checks pass. Its one exact-head hosted persistence check is terminal GREEN ([run 33281305828 / job 99176826069](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33281305828/job/99176826069)); no qualifying independent approval exists, all current review threads are resolved, and GraphQL reports `MERGEABLE`/`CLEAN` while it remains Draft. It is active-PR/stack-local truth only and must retarget/revalidate after #121 integrates. - **PR #126** remains open/Draft at exact head `c13b2d35d135abf2e33447be217014cd5588d6cb`, stacked on PR #118 at `eb529093b44be17bb282d3fd5c6c592d66f111af`. Its release-authorization package passes 36 tests with exact 100% statement/branch coverage (226/58), plus isolated package-install, docstring, compile, Ruff, and diff checks; the dedicated exact-head check is terminal GREEN. No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged parent keep it non-authorized. It must retarget/revalidate on fresh `develop` after #118 integrates; no release/tag/publication authority is shipped. +- **PR #128** remains open/Draft at exact head `44440c9791c271715924de6d80e189bb8c0df049`, targeting PR #103 at `645d2f3b2db10e2bdfbe60422837a5986d8f39f8`. Its Employment work-capacity persistence migrations pass three real PostgreSQL regressions for resolution/RLS/history, retroactive-chain protection, and canonical review evidence; Foundation validation is 55/55, actionlint and shellcheck pass, and the exact-head persistence check is terminal GREEN ([run 33282710368 / job 99180472116](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33282710368/job/99180472116)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged review parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #103 integrates; no authoritative capacity truth is shipped on protected `develop`. - **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. From 241e6eb1515fd21eb4752beafcf2d23816352e2b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:19:19 +0900 Subject: [PATCH 149/201] docs: record separation approval boundary status --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7b22f3d31..e2fcc58b8 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -131,6 +131,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #125** remains open/Draft at exact head `ea97b791fc3d27d786d2bd81c19b994dcc872208`, targeting `feat/performance-goal-plan-activation` at `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`, as a dependency-first child of #121. Exact-head local PostgreSQL 16.14 persistence tests pass, including the search-path shadowing regression; Foundation validation is 55/55 and shellcheck/diff checks pass. Its one exact-head hosted persistence check is terminal GREEN ([run 33281305828 / job 99176826069](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33281305828/job/99176826069)); no qualifying independent approval exists, all current review threads are resolved, and GraphQL reports `MERGEABLE`/`CLEAN` while it remains Draft. It is active-PR/stack-local truth only and must retarget/revalidate after #121 integrates. - **PR #126** remains open/Draft at exact head `c13b2d35d135abf2e33447be217014cd5588d6cb`, stacked on PR #118 at `eb529093b44be17bb282d3fd5c6c592d66f111af`. Its release-authorization package passes 36 tests with exact 100% statement/branch coverage (226/58), plus isolated package-install, docstring, compile, Ruff, and diff checks; the dedicated exact-head check is terminal GREEN. No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged parent keep it non-authorized. It must retarget/revalidate on fresh `develop` after #118 integrates; no release/tag/publication authority is shipped. - **PR #128** remains open/Draft at exact head `44440c9791c271715924de6d80e189bb8c0df049`, targeting PR #103 at `645d2f3b2db10e2bdfbe60422837a5986d8f39f8`. Its Employment work-capacity persistence migrations pass three real PostgreSQL regressions for resolution/RLS/history, retroactive-chain protection, and canonical review evidence; Foundation validation is 55/55, actionlint and shellcheck pass, and the exact-head persistence check is terminal GREEN ([run 33282710368 / job 99180472116](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33282710368/job/99180472116)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged review parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #103 integrates; no authoritative capacity truth is shipped on protected `develop`. +- **PR #129** remains open/Draft at exact head `4c377a35055e126a5e2435ec36bd9ac1e593456e`, targeting PR #46 at `96fe0b69e8e1bc3caa0fa206146a87c6e5027746`. Its approval-boundary package passes 137 tests with exact 100% statement/branch coverage (388/86), plus compileall, Ruff, and diff checks; the exact-head focused workflow is terminal GREEN ([run 33166590078 / job 98833356045](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33166590078/job/98833356045)). The receipt remains human-approval evidence only and is fixed to `not_authorized_to_apply` and `not_authorized_to_execute`; no reviews, threads, or qualifying independent approval exist. GitHub reports REST `mergeable=false`/`dirty` and GraphQL `DIRTY`; the unmerged parent #46 keeps this child dependency-first and non-authorizing. It must remain Draft and be retargeted/revalidated on fresh `develop` only after #46 integrates; no Employment separation mutation or downstream owner execution is shipped. - **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. From 507d399cc1fb6efb681ae4edb91c83a19572b813 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:22:53 +0900 Subject: [PATCH 150/201] docs: record protected read state status --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e2fcc58b8..f12d92867 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -132,6 +132,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #126** remains open/Draft at exact head `c13b2d35d135abf2e33447be217014cd5588d6cb`, stacked on PR #118 at `eb529093b44be17bb282d3fd5c6c592d66f111af`. Its release-authorization package passes 36 tests with exact 100% statement/branch coverage (226/58), plus isolated package-install, docstring, compile, Ruff, and diff checks; the dedicated exact-head check is terminal GREEN. No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged parent keep it non-authorized. It must retarget/revalidate on fresh `develop` after #118 integrates; no release/tag/publication authority is shipped. - **PR #128** remains open/Draft at exact head `44440c9791c271715924de6d80e189bb8c0df049`, targeting PR #103 at `645d2f3b2db10e2bdfbe60422837a5986d8f39f8`. Its Employment work-capacity persistence migrations pass three real PostgreSQL regressions for resolution/RLS/history, retroactive-chain protection, and canonical review evidence; Foundation validation is 55/55, actionlint and shellcheck pass, and the exact-head persistence check is terminal GREEN ([run 33282710368 / job 99180472116](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33282710368/job/99180472116)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged review parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #103 integrates; no authoritative capacity truth is shipped on protected `develop`. - **PR #129** remains open/Draft at exact head `4c377a35055e126a5e2435ec36bd9ac1e593456e`, targeting PR #46 at `96fe0b69e8e1bc3caa0fa206146a87c6e5027746`. Its approval-boundary package passes 137 tests with exact 100% statement/branch coverage (388/86), plus compileall, Ruff, and diff checks; the exact-head focused workflow is terminal GREEN ([run 33166590078 / job 98833356045](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33166590078/job/98833356045)). The receipt remains human-approval evidence only and is fixed to `not_authorized_to_apply` and `not_authorized_to_execute`; no reviews, threads, or qualifying independent approval exist. GitHub reports REST `mergeable=false`/`dirty` and GraphQL `DIRTY`; the unmerged parent #46 keeps this child dependency-first and non-authorizing. It must remain Draft and be retargeted/revalidated on fresh `develop` only after #46 integrates; no Employment separation mutation or downstream owner execution is shipped. +- **PR #130** remains open/Draft at exact head `c92749cf5889a39de1ba8036742f96fd3451f459`, targeting PR #53 at `016f27e13f7a47cb78a1c936aa533cc8daa2c66c`. Its protected-read interaction contract passes 5 Node tests with exact 100% line/branch/function coverage, plus syntax and diff checks; the exact-head focused workflow is terminal GREEN ([run 33245740900 / job 99082759734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33245740900/job/99082759734)). It fails closed on prototype-inherited state names, makes loading busy/disabled, keeps loaded evidence read-only, and emits concrete denial/error next actions without protected values. No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but Draft and the unmerged parent keep it dependency-first and non-authorizing. It must retarget/revalidate on fresh `develop` after #53 integrates; no protected HR read API or employment-decision authority is shipped. - **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. From 3cb956b3bcca307e5541cf920639e694eb8c046d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:27:38 +0900 Subject: [PATCH 151/201] docs: record export delivery interaction status --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f12d92867..e1c351294 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -133,6 +133,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #128** remains open/Draft at exact head `44440c9791c271715924de6d80e189bb8c0df049`, targeting PR #103 at `645d2f3b2db10e2bdfbe60422837a5986d8f39f8`. Its Employment work-capacity persistence migrations pass three real PostgreSQL regressions for resolution/RLS/history, retroactive-chain protection, and canonical review evidence; Foundation validation is 55/55, actionlint and shellcheck pass, and the exact-head persistence check is terminal GREEN ([run 33282710368 / job 99180472116](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33282710368/job/99180472116)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged review parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #103 integrates; no authoritative capacity truth is shipped on protected `develop`. - **PR #129** remains open/Draft at exact head `4c377a35055e126a5e2435ec36bd9ac1e593456e`, targeting PR #46 at `96fe0b69e8e1bc3caa0fa206146a87c6e5027746`. Its approval-boundary package passes 137 tests with exact 100% statement/branch coverage (388/86), plus compileall, Ruff, and diff checks; the exact-head focused workflow is terminal GREEN ([run 33166590078 / job 98833356045](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33166590078/job/98833356045)). The receipt remains human-approval evidence only and is fixed to `not_authorized_to_apply` and `not_authorized_to_execute`; no reviews, threads, or qualifying independent approval exist. GitHub reports REST `mergeable=false`/`dirty` and GraphQL `DIRTY`; the unmerged parent #46 keeps this child dependency-first and non-authorizing. It must remain Draft and be retargeted/revalidated on fresh `develop` only after #46 integrates; no Employment separation mutation or downstream owner execution is shipped. - **PR #130** remains open/Draft at exact head `c92749cf5889a39de1ba8036742f96fd3451f459`, targeting PR #53 at `016f27e13f7a47cb78a1c936aa533cc8daa2c66c`. Its protected-read interaction contract passes 5 Node tests with exact 100% line/branch/function coverage, plus syntax and diff checks; the exact-head focused workflow is terminal GREEN ([run 33245740900 / job 99082759734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33245740900/job/99082759734)). It fails closed on prototype-inherited state names, makes loading busy/disabled, keeps loaded evidence read-only, and emits concrete denial/error next actions without protected values. No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but Draft and the unmerged parent keep it dependency-first and non-authorizing. It must retarget/revalidate on fresh `develop` after #53 integrates; no protected HR read API or employment-decision authority is shipped. +- **PR #131** remains open/Draft at exact head `9f2c36dec6de64f6d7de98fb653c4e7336eed0d2`; its recorded base SHA is the predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf`, while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. Its one-time export interaction contract passes 7 Node tests with exact 100% line/branch/function coverage, syntax/diff checks, and the CSS-import repair; the exact-head focused workflow is terminal GREEN ([run 33283287138 / job 99181985091](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33283287138/job/99181985091)). No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but the stale dependency base, Draft state, and unmerged #53 → #130 stack keep it non-authorizing. It must be reconciled against current #130 and retargeted/revalidated on fresh `develop` after the dependency stack integrates; no export authorization or durable one-time delivery is shipped. - **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. From f0923770bcdebbc7413196f7c74eecc48b7654d0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:29:39 +0900 Subject: [PATCH 152/201] docs: record document retrieval interaction status --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e1c351294..c5a4d2191 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -134,6 +134,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #129** remains open/Draft at exact head `4c377a35055e126a5e2435ec36bd9ac1e593456e`, targeting PR #46 at `96fe0b69e8e1bc3caa0fa206146a87c6e5027746`. Its approval-boundary package passes 137 tests with exact 100% statement/branch coverage (388/86), plus compileall, Ruff, and diff checks; the exact-head focused workflow is terminal GREEN ([run 33166590078 / job 98833356045](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33166590078/job/98833356045)). The receipt remains human-approval evidence only and is fixed to `not_authorized_to_apply` and `not_authorized_to_execute`; no reviews, threads, or qualifying independent approval exist. GitHub reports REST `mergeable=false`/`dirty` and GraphQL `DIRTY`; the unmerged parent #46 keeps this child dependency-first and non-authorizing. It must remain Draft and be retargeted/revalidated on fresh `develop` only after #46 integrates; no Employment separation mutation or downstream owner execution is shipped. - **PR #130** remains open/Draft at exact head `c92749cf5889a39de1ba8036742f96fd3451f459`, targeting PR #53 at `016f27e13f7a47cb78a1c936aa533cc8daa2c66c`. Its protected-read interaction contract passes 5 Node tests with exact 100% line/branch/function coverage, plus syntax and diff checks; the exact-head focused workflow is terminal GREEN ([run 33245740900 / job 99082759734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33245740900/job/99082759734)). It fails closed on prototype-inherited state names, makes loading busy/disabled, keeps loaded evidence read-only, and emits concrete denial/error next actions without protected values. No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but Draft and the unmerged parent keep it dependency-first and non-authorizing. It must retarget/revalidate on fresh `develop` after #53 integrates; no protected HR read API or employment-decision authority is shipped. - **PR #131** remains open/Draft at exact head `9f2c36dec6de64f6d7de98fb653c4e7336eed0d2`; its recorded base SHA is the predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf`, while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. Its one-time export interaction contract passes 7 Node tests with exact 100% line/branch/function coverage, syntax/diff checks, and the CSS-import repair; the exact-head focused workflow is terminal GREEN ([run 33283287138 / job 99181985091](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33283287138/job/99181985091)). No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but the stale dependency base, Draft state, and unmerged #53 → #130 stack keep it non-authorizing. It must be reconciled against current #130 and retargeted/revalidated on fresh `develop` after the dependency stack integrates; no export authorization or durable one-time delivery is shipped. +- **PR #132** remains open/Draft at exact head `97fb51167a6883d7f6191c53eda48863842fd14e`; its recorded base SHA is the predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf`, while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. Its document-retrieval interaction contract passes 6 Node tests with exact 100% line/branch/function coverage, syntax/diff checks, and exact-state/prototype-inheritance fail-closed regressions; the exact-head focused workflow is terminal GREEN ([run 33245126654 / job 99081169269](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33245126654/job/99081169269)). No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but the stale dependency base, Draft state, and unmerged #53 → #130 stack keep it non-authorizing. It must be reconciled against current #130 and retargeted/revalidated on fresh `develop` after the dependency stack integrates; no document retrieval authorization, export authority, or employment-decision authority is shipped. - **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. From df819a238f0fb426f943b9dbf3076ba201be5298 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:35:45 +0900 Subject: [PATCH 153/201] docs: refresh job grade interaction evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c5a4d2191..aa910dc19 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -143,7 +143,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. At exact head `40b26388527fa65596ea6875e1d3d2b025942c2c`, its local focused contract passes 7 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. + - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. At exact head `4d72fda8e3df41e6b4a9f81e3000895a446548b4`, its local focused contract passes 7 tests with exact 100% line/branch/function coverage, and its parent traceability is synchronized to current #130 head `c92749cf5889a39de1ba8036742f96fd3451f459` (the recorded child base remains the predecessor `b3b30058a79174000919d566fbbb1fdad80c62bf`). Its dedicated hosted check is terminal GREEN ([run 33283652359 / job 99182956631](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33283652359/job/99182956631)). It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. From 1d554fdf595e1466476dfc0f3aab3dc8920a028a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:37:49 +0900 Subject: [PATCH 154/201] docs: refresh position lifecycle interaction status --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index aa910dc19..96ad1c27e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -144,7 +144,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. At exact head `4d72fda8e3df41e6b4a9f81e3000895a446548b4`, its local focused contract passes 7 tests with exact 100% line/branch/function coverage, and its parent traceability is synchronized to current #130 head `c92749cf5889a39de1ba8036742f96fd3451f459` (the recorded child base remains the predecessor `b3b30058a79174000919d566fbbb1fdad80c62bf`). Its dedicated hosted check is terminal GREEN ([run 33283652359 / job 99182956631](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33283652359/job/99182956631)). It remains Draft dependency-first active-PR truth with no qualifying independent approval. - - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. + - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its recorded child base remains predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf` while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`; its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. From f54802e639052757469168d600831cb79bb6946c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:45:16 +0900 Subject: [PATCH 155/201] docs: record qualification review interaction status --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 96ad1c27e..3e87b567b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -145,7 +145,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. At exact head `4d72fda8e3df41e6b4a9f81e3000895a446548b4`, its local focused contract passes 7 tests with exact 100% line/branch/function coverage, and its parent traceability is synchronized to current #130 head `c92749cf5889a39de1ba8036742f96fd3451f459` (the recorded child base remains the predecessor `b3b30058a79174000919d566fbbb1fdad80c62bf`). Its dedicated hosted check is terminal GREEN ([run 33283652359 / job 99182956631](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33283652359/job/99182956631)). It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its recorded child base remains predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf` while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`; its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. + - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213758897 / job 98992701588](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213758897/job/98992701588)). Its recorded base is `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth and must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. From 221138d3a5fcda930527c5a450ca688678791a66 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:48:19 +0900 Subject: [PATCH 156/201] docs: record reporting review interaction status --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3e87b567b..98becff42 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -146,7 +146,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. At exact head `4d72fda8e3df41e6b4a9f81e3000895a446548b4`, its local focused contract passes 7 tests with exact 100% line/branch/function coverage, and its parent traceability is synchronized to current #130 head `c92749cf5889a39de1ba8036742f96fd3451f459` (the recorded child base remains the predecessor `b3b30058a79174000919d566fbbb1fdad80c62bf`). Its dedicated hosted check is terminal GREEN ([run 33283652359 / job 99182956631](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33283652359/job/99182956631)). It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its recorded child base remains predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf` while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`; its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213758897 / job 98992701588](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213758897/job/98992701588)). Its recorded base is `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth and must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. + - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213066619 / job 98990527663](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213066619/job/98990527663)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. From 1599076743bb326962b390a87f146da92d1fd9a0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:51:57 +0900 Subject: [PATCH 157/201] docs: record work capacity interaction status --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 98becff42..461cf6abe 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -147,7 +147,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its recorded child base remains predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf` while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`; its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213758897 / job 98992701588](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213758897/job/98992701588)). Its recorded base is `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth and must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213066619 / job 98990527663](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213066619/job/98990527663)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. + - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212959615 / job 98990188612](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212959615/job/98990188612)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. From 4e7e03b6a1c223a41aa65bf3f8b7d546ba004926 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:54:41 +0900 Subject: [PATCH 158/201] docs: record employment absence interaction status --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 461cf6abe..3af0e91d7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -148,7 +148,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213758897 / job 98992701588](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213758897/job/98992701588)). Its recorded base is `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth and must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213066619 / job 98990527663](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213066619/job/98990527663)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212959615 / job 98990188612](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212959615/job/98990188612)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. + - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212827583 / job 98989785049](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212827583/job/98989785049)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. From 35abc48c696bf22ed717ab37aa960ccbb2354791 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 09:57:10 +0900 Subject: [PATCH 159/201] docs: record performance goal interaction status --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3af0e91d7..1b1c3ecad 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -149,7 +149,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213066619 / job 98990527663](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213066619/job/98990527663)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212959615 / job 98990188612](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212959615/job/98990188612)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212827583 / job 98989785049](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212827583/job/98989785049)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, and the exact-head dedicated workflow is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. + - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212498784 / job 98988751106](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212498784/job/98988751106)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. From 926178cb3b6478b8bd60fb0e4dac633c56e89ae0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 10:03:56 +0900 Subject: [PATCH 160/201] docs: record employing organization PR status --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1b1c3ecad..f7c59a41c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -150,6 +150,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212959615 / job 98990188612](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212959615/job/98990188612)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212827583 / job 98989785049](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212827583/job/98989785049)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212498784 / job 98988751106](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212498784/job/98988751106)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. It must be retargeted/revalidated on fresh `develop` after #130 integrates. + - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 38 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. From ef150ec246ccd730c7fa8b0673ccf0de4a99c968 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 10:09:15 +0900 Subject: [PATCH 161/201] docs: record assignment history review evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f7c59a41c..bf4ac11a9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -151,7 +151,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212827583 / job 98989785049](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212827583/job/98989785049)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212498784 / job 98988751106](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212498784/job/98988751106)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 38 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. + - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. From 4d5eaa099f892cb549467d54788a8753df1ffbc2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 10:12:42 +0900 Subject: [PATCH 162/201] docs: record assignment history ui evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index bf4ac11a9..eecccfc18 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -151,7 +151,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212827583 / job 98989785049](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212827583/job/98989785049)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212498784 / job 98988751106](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212498784/job/98988751106)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 38 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is at exact head `b7fdd493809545a7fd562fb6464b09c853739149`, with its focused contract passing 6 tests at exact 100% line/branch/function coverage and its dedicated hosted check terminal GREEN. #143 remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only. Neither lane mutates Assignment truth or authorizes an employment decision. + - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is recorded on #130 base `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact child head `b7fdd493809545a7fd562fb6464b09c853739149`, its focused contract passes 6 tests at exact 100% line/branch/function coverage, repository validation passes 63 tests, and the dedicated hosted check is terminal GREEN ([run 33198343313 / job 98941173734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198343313/job/98941173734)). It remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only; it must be retargeted and revalidated on fresh `develop` after #130 and #142 integrate. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. From f0ddb033c8c66a8e8a1d82fb88d3523e49a32f9e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 10:16:54 +0900 Subject: [PATCH 163/201] docs: record candidate evidence ui evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index eecccfc18..ebe0115af 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -152,7 +152,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212498784 / job 98988751106](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212498784/job/98988751106)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 38 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is recorded on #130 base `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact child head `b7fdd493809545a7fd562fb6464b09c853739149`, its focused contract passes 6 tests at exact 100% line/branch/function coverage, repository validation passes 63 tests, and the dedicated hosted check is terminal GREEN ([run 33198343313 / job 98941173734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198343313/job/98941173734)). It remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only; it must be retargeted and revalidated on fresh `develop` after #130 and #142 integrate. Neither lane mutates Assignment truth or authorizes an employment decision. - - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). At exact head `4cafd78f86c466c7600f946ff237f898fa6f5e0b`, its focused contract passes 6 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision. + - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). Its recorded #130 base is `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact head `5fd7683ed8cd4bfbe9b217b64e22c0368ae6f486`, its focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and its dedicated hosted check is terminal GREEN ([run 33285252309 / job 99187216615](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285252309/job/99187216615)); the corrected action includes an explicit non-disabled hover state alongside visible focus treatment. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision and must be retargeted/revalidated on fresh `develop` after #130 and #142 integrate. - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. From 976e5cb0dc25f9bf0c13f5f86982ebb7cc7f53f0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 10:20:02 +0900 Subject: [PATCH 164/201] docs: record validation dashboard evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ebe0115af..be8603f71 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -153,7 +153,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 38 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is recorded on #130 base `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact child head `b7fdd493809545a7fd562fb6464b09c853739149`, its focused contract passes 6 tests at exact 100% line/branch/function coverage, repository validation passes 63 tests, and the dedicated hosted check is terminal GREEN ([run 33198343313 / job 98941173734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198343313/job/98941173734)). It remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only; it must be retargeted and revalidated on fresh `develop` after #130 and #142 integrate. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). Its recorded #130 base is `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact head `5fd7683ed8cd4bfbe9b217b64e22c0368ae6f486`, its focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and its dedicated hosted check is terminal GREEN ([run 33285252309 / job 99187216615](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285252309/job/99187216615)); the corrected action includes an explicit non-disabled hover state alongside visible focus treatment. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision and must be retargeted/revalidated on fresh `develop` after #130 and #142 integrate. - - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `63c679fd0688aacb4b250ec7d421d9b592669b3f`, #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. + - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding and fixed function search paths. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child checks and any clean/mergeable state are stack-local only. From 5ad10fa1c35a09a56aa534bb190de3250811ebf0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 10:31:23 +0900 Subject: [PATCH 165/201] docs: record validation and job architecture evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index be8603f71..e288a8715 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -153,7 +153,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 38 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is recorded on #130 base `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact child head `b7fdd493809545a7fd562fb6464b09c853739149`, its focused contract passes 6 tests at exact 100% line/branch/function coverage, repository validation passes 63 tests, and the dedicated hosted check is terminal GREEN ([run 33198343313 / job 98941173734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198343313/job/98941173734)). It remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only; it must be retargeted and revalidated on fresh `develop` after #130 and #142 integrate. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). Its recorded #130 base is `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact head `5fd7683ed8cd4bfbe9b217b64e22c0368ae6f486`, its focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and its dedicated hosted check is terminal GREEN ([run 33285252309 / job 99187216615](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285252309/job/99187216615)); the corrected action includes an explicit non-disabled hover state alongside visible focus treatment. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision and must be retargeted/revalidated on fresh `develop` after #130 and #142 integrate. - - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at `188e84e8e33f0d06af5e00791bc47a53ecb00434`, #147 owns Job Architecture workspace states at `4ba6bbece3abb8356d154f7e07f04f8259e0399b`, #148 owns the PostgreSQL Assignment-history read adapter at `927f108505603b49112f467ddb06b5c21843ee2c`, and #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. + - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at exact head `bd2eaa1b9f6c901758fb5e151f9354ecd8829914`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285501789 / job 99187886526](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285501789/job/99187886526) terminal GREEN; #147 owns Job Architecture workspace states at exact head `26e81931ec031bd9ac72f0053839cae58c21f6bb`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285574607 / job 99188079934](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285574607/job/99188079934) terminal GREEN; #148 owns the PostgreSQL Assignment-history read adapter at exact head `927f108505603b49112f467ddb06b5c21843ee2c`, with 184 People API tests, 256 subtests, exact 100% statement/branch coverage, and dedicated hosted run [33198401194 / job 98941396472](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198401194/job/98941396472) terminal GREEN; its current parent/base is #142 at `d832006843111cc03751ec2bcd532df916bbc1e2`. #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding and fixed function search paths. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child checks and any clean/mergeable state are stack-local only. From 852544f22f21b96b154a17b61da35c421c2f9b8d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 10:36:56 +0900 Subject: [PATCH 166/201] docs: record legal employer ui evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e288a8715..769f07ac5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -153,7 +153,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 38 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is recorded on #130 base `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact child head `b7fdd493809545a7fd562fb6464b09c853739149`, its focused contract passes 6 tests at exact 100% line/branch/function coverage, repository validation passes 63 tests, and the dedicated hosted check is terminal GREEN ([run 33198343313 / job 98941173734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198343313/job/98941173734)). It remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only; it must be retargeted and revalidated on fresh `develop` after #130 and #142 integrate. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). Its recorded #130 base is `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact head `5fd7683ed8cd4bfbe9b217b64e22c0368ae6f486`, its focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and its dedicated hosted check is terminal GREEN ([run 33285252309 / job 99187216615](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285252309/job/99187216615)); the corrected action includes an explicit non-disabled hover state alongside visible focus treatment. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision and must be retargeted/revalidated on fresh `develop` after #130 and #142 integrate. - - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at exact head `bd2eaa1b9f6c901758fb5e151f9354ecd8829914`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285501789 / job 99187886526](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285501789/job/99187886526) terminal GREEN; #147 owns Job Architecture workspace states at exact head `26e81931ec031bd9ac72f0053839cae58c21f6bb`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285574607 / job 99188079934](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285574607/job/99188079934) terminal GREEN; #148 owns the PostgreSQL Assignment-history read adapter at exact head `927f108505603b49112f467ddb06b5c21843ee2c`, with 184 People API tests, 256 subtests, exact 100% statement/branch coverage, and dedicated hosted run [33198401194 / job 98941396472](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198401194/job/98941396472) terminal GREEN; its current parent/base is #142 at `d832006843111cc03751ec2bcd532df916bbc1e2`. #150 owns legal-employer history presentation states at `e54023d308548cb8cbcbdb1dfd925fd4ab94765b`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. + - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at exact head `bd2eaa1b9f6c901758fb5e151f9354ecd8829914`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285501789 / job 99187886526](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285501789/job/99187886526) terminal GREEN; #147 owns Job Architecture workspace states at exact head `26e81931ec031bd9ac72f0053839cae58c21f6bb`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285574607 / job 99188079934](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285574607/job/99188079934) terminal GREEN; #148 owns the PostgreSQL Assignment-history read adapter at exact head `927f108505603b49112f467ddb06b5c21843ee2c`, with 184 People API tests, 256 subtests, exact 100% statement/branch coverage, and dedicated hosted run [33198401194 / job 98941396472](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198401194/job/98941396472) terminal GREEN; its current parent/base is #142 at `d832006843111cc03751ec2`. #150 owns legal-employer history presentation states at exact head `cfab4d70c38eccd5fd528a2314d1346602c405f7`, with 5 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33286022706 / job 99189253498](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33286022706/job/99189253498) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding and fixed function search paths. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child checks and any clean/mergeable state are stack-local only. From 3f61235247edea19c18d94527e82865b17634643 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 10:45:39 +0900 Subject: [PATCH 167/201] docs: record position history read evidence --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 769f07ac5..56335badb 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -137,6 +137,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #132** remains open/Draft at exact head `97fb51167a6883d7f6191c53eda48863842fd14e`; its recorded base SHA is the predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf`, while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. Its document-retrieval interaction contract passes 6 Node tests with exact 100% line/branch/function coverage, syntax/diff checks, and exact-state/prototype-inheritance fail-closed regressions; the exact-head focused workflow is terminal GREEN ([run 33245126654 / job 99081169269](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33245126654/job/99081169269)). No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but the stale dependency base, Draft state, and unmerged #53 → #130 stack keep it non-authorizing. It must be reconciled against current #130 and retargeted/revalidated on fresh `develop` after the dependency stack integrates; no document retrieval authorization, export authority, or employment-decision authority is shipped. - **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. +- **PR #152** remains Draft at exact head `44282cdb61269937f55bd1a69a106e948130d844`, targeting protected `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. It adds a purpose-bound Position-history read boundary that authorizes before retrieval, preserves separate business/system time, revalidates immutable persistence evidence, and keeps absent business ends semantically unbounded; the real `date.max` overlap regression was reproduced at test-only head `af8d0b9b88c50f17c87eb8ecf1eea29918835dce` and repaired at `955956f838c467c06c25b63127b7c6e976dea812`. The exact current local People API suite passes 158 tests and 259 subtests with 1,542 statements and 504 branches at 100%, plus repository validation (55/55), compileall, Ruff, and diff checks. Its dedicated exact-head People API check is GREEN ([run 33268072551 / job 99141581712](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33268072551/job/99141581712)); the exact-head hosted snapshot has 31 successful, 4 failed, and 8 skipped checks, with `dependency-review`, `opencode-review`, `noema-review`, and `strix` terminal FAILURE and no authoritative central verdicts. No formal review, current-head qualifying independent approval, or review thread exists; GitHub reports `REVIEW_REQUIRED`/`BLOCKED`, so it remains active-PR truth only and does not ship Position-history authority on protected `develop`. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From bcacb5f9b3096bcf18a5c40f0700c48b85b57e48 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 11:08:24 +0900 Subject: [PATCH 168/201] docs: record position history adapter evidence --- docs/product-technical-gap-baseline.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 56335badb..1a0c45215 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -138,6 +138,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #152** remains Draft at exact head `44282cdb61269937f55bd1a69a106e948130d844`, targeting protected `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. It adds a purpose-bound Position-history read boundary that authorizes before retrieval, preserves separate business/system time, revalidates immutable persistence evidence, and keeps absent business ends semantically unbounded; the real `date.max` overlap regression was reproduced at test-only head `af8d0b9b88c50f17c87eb8ecf1eea29918835dce` and repaired at `955956f838c467c06c25b63127b7c6e976dea812`. The exact current local People API suite passes 158 tests and 259 subtests with 1,542 statements and 504 branches at 100%, plus repository validation (55/55), compileall, Ruff, and diff checks. Its dedicated exact-head People API check is GREEN ([run 33268072551 / job 99141581712](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33268072551/job/99141581712)); the exact-head hosted snapshot has 31 successful, 4 failed, and 8 skipped checks, with `dependency-review`, `opencode-review`, `noema-review`, and `strix` terminal FAILURE and no authoritative central verdicts. No formal review, current-head qualifying independent approval, or review thread exists; GitHub reports `REVIEW_REQUIRED`/`BLOCKED`, so it remains active-PR truth only and does not ship Position-history authority on protected `develop`. +- **PR #153** is a Draft child of #152 at exact head `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`, recorded against parent #152 head `44282cdb61269937f55bd1a69a106e948130d844`. It supplies the canonical PostgreSQL adapter for #152's Position-history port, using a read-only tenant-scoped transaction, explicit Position-anchor/version predicates, UTC projection, and untrusted DB-API row revalidation; it adds no migration, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 185 tests and 259 subtests with 1,606 statements and 528 branches at 100%, plus repository validation (55/55), compileall, Ruff, actionlint, CodeGraph sync, and diff checks; an isolated PostgreSQL 16.14 RLS/UTC/bitemporal/typed-lineage contract also passed. Its dedicated exact-head check is terminal GREEN ([run 33287205030 / job 99192355928](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33287205030/job/99192355928)); it has no reviews, threads, or qualifying independent approval. GitHub reports `CLEAN` only for the stacked child, so parent integration, fresh protected-`develop` retargeting, all applicable central gates, and independent review remain required before any authorization or merge. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From 0a60be58084c46f390b4293208a8a4e8455417de Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 11:10:50 +0900 Subject: [PATCH 169/201] docs: refresh open queue snapshot --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1a0c45215..7c418de61 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 108 pull requests and one non-PR issue (#89) are open, verified with the GitHub `open` filters at `2026-08-29 21:09 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 109 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 02:10 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. From 18256b820a2b5bb60a5c5f0c7689c125be140999 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 11:38:25 +0900 Subject: [PATCH 170/201] docs: record position history HTTP read lane --- docs/product-technical-gap-baseline.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7c418de61..b5434282a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 109 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 02:10 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 110 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 02:37 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -139,6 +139,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. - **PR #152** remains Draft at exact head `44282cdb61269937f55bd1a69a106e948130d844`, targeting protected `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. It adds a purpose-bound Position-history read boundary that authorizes before retrieval, preserves separate business/system time, revalidates immutable persistence evidence, and keeps absent business ends semantically unbounded; the real `date.max` overlap regression was reproduced at test-only head `af8d0b9b88c50f17c87eb8ecf1eea29918835dce` and repaired at `955956f838c467c06c25b63127b7c6e976dea812`. The exact current local People API suite passes 158 tests and 259 subtests with 1,542 statements and 504 branches at 100%, plus repository validation (55/55), compileall, Ruff, and diff checks. Its dedicated exact-head People API check is GREEN ([run 33268072551 / job 99141581712](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33268072551/job/99141581712)); the exact-head hosted snapshot has 31 successful, 4 failed, and 8 skipped checks, with `dependency-review`, `opencode-review`, `noema-review`, and `strix` terminal FAILURE and no authoritative central verdicts. No formal review, current-head qualifying independent approval, or review thread exists; GitHub reports `REVIEW_REQUIRED`/`BLOCKED`, so it remains active-PR truth only and does not ship Position-history authority on protected `develop`. - **PR #153** is a Draft child of #152 at exact head `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`, recorded against parent #152 head `44282cdb61269937f55bd1a69a106e948130d844`. It supplies the canonical PostgreSQL adapter for #152's Position-history port, using a read-only tenant-scoped transaction, explicit Position-anchor/version predicates, UTC projection, and untrusted DB-API row revalidation; it adds no migration, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 185 tests and 259 subtests with 1,606 statements and 528 branches at 100%, plus repository validation (55/55), compileall, Ruff, actionlint, CodeGraph sync, and diff checks; an isolated PostgreSQL 16.14 RLS/UTC/bitemporal/typed-lineage contract also passed. Its dedicated exact-head check is terminal GREEN ([run 33287205030 / job 99192355928](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33287205030/job/99192355928)); it has no reviews, threads, or qualifying independent approval. GitHub reports `CLEAN` only for the stacked child, so parent integration, fresh protected-`develop` retargeting, all applicable central gates, and independent review remain required before any authorization or merge. +- **PR #154** is a Draft child of #153 at exact head `eba070206b881cc0f7193fe684cf4cb6f8c2d54b`, based on #153 at `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`. It exposes the purpose-bound, bitemporal Position-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized fields, and adds no write, cross-service query, Person/Employment/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 197 tests and 259 subtests with 1,728 statements and 558 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33288307945 / job 99195361332](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33288307945/job/99195361332)); CodeRabbit reports only `Review skipped: draft pull request`, with no formal reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` for the stacked child, but Draft state and unmerged parent #153 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From 1ce0c1f416633669786b62bdae0a1acb0029eca0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 12:04:54 +0900 Subject: [PATCH 171/201] docs: record employment history HTTP read lane --- docs/product-technical-gap-baseline.md | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b5434282a..5cbb2dc04 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 110 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 02:37 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 111 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 03:02 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -53,6 +53,10 @@ Consequences: This is a selected shipped inventory, not a replacement for Git history. Do not describe active-PR capability as shipped until its owner PR integrates into fresh `develop`. +## Current exact-head governance anchors + +- **PR #100** is non-draft at exact head `18256b820a2b5bb60a5c5f0c7689c125be140999`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 39 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; GraphQL reports 57 review threads with 2 unresolved and 68 reviews but no qualifying independent approval. It remains non-merge-authorized; no failed central gate or unresolved thread is bypassed. + ## Fresh active-owner truth The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. @@ -140,6 +144,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #152** remains Draft at exact head `44282cdb61269937f55bd1a69a106e948130d844`, targeting protected `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. It adds a purpose-bound Position-history read boundary that authorizes before retrieval, preserves separate business/system time, revalidates immutable persistence evidence, and keeps absent business ends semantically unbounded; the real `date.max` overlap regression was reproduced at test-only head `af8d0b9b88c50f17c87eb8ecf1eea29918835dce` and repaired at `955956f838c467c06c25b63127b7c6e976dea812`. The exact current local People API suite passes 158 tests and 259 subtests with 1,542 statements and 504 branches at 100%, plus repository validation (55/55), compileall, Ruff, and diff checks. Its dedicated exact-head People API check is GREEN ([run 33268072551 / job 99141581712](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33268072551/job/99141581712)); the exact-head hosted snapshot has 31 successful, 4 failed, and 8 skipped checks, with `dependency-review`, `opencode-review`, `noema-review`, and `strix` terminal FAILURE and no authoritative central verdicts. No formal review, current-head qualifying independent approval, or review thread exists; GitHub reports `REVIEW_REQUIRED`/`BLOCKED`, so it remains active-PR truth only and does not ship Position-history authority on protected `develop`. - **PR #153** is a Draft child of #152 at exact head `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`, recorded against parent #152 head `44282cdb61269937f55bd1a69a106e948130d844`. It supplies the canonical PostgreSQL adapter for #152's Position-history port, using a read-only tenant-scoped transaction, explicit Position-anchor/version predicates, UTC projection, and untrusted DB-API row revalidation; it adds no migration, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 185 tests and 259 subtests with 1,606 statements and 528 branches at 100%, plus repository validation (55/55), compileall, Ruff, actionlint, CodeGraph sync, and diff checks; an isolated PostgreSQL 16.14 RLS/UTC/bitemporal/typed-lineage contract also passed. Its dedicated exact-head check is terminal GREEN ([run 33287205030 / job 99192355928](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33287205030/job/99192355928)); it has no reviews, threads, or qualifying independent approval. GitHub reports `CLEAN` only for the stacked child, so parent integration, fresh protected-`develop` retargeting, all applicable central gates, and independent review remain required before any authorization or merge. - **PR #154** is a Draft child of #153 at exact head `eba070206b881cc0f7193fe684cf4cb6f8c2d54b`, based on #153 at `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`. It exposes the purpose-bound, bitemporal Position-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized fields, and adds no write, cross-service query, Person/Employment/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 197 tests and 259 subtests with 1,728 statements and 558 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33288307945 / job 99195361332](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33288307945/job/99195361332)); CodeRabbit reports only `Review skipped: draft pull request`, with no formal reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` for the stacked child, but Draft state and unmerged parent #153 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. +- **PR #155** is a Draft child of #149 at exact head `094466db22a707185fd2de06a1da7c228d7d6c3a`, based on #149 at `44c83128701f1985f8566b39cbf837c7b20f0111`. It exposes the purpose-bound, bitemporal Employment-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized `entries[].fields`, and adds no write, cross-service query, Position/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 172 tests with 1,646 statements and 536 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33289241743 / job 99197835852](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33289241743/job/99197835852)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent #149 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From 05e935711fb66247ee95a1acc25cf557929143a8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 12:23:49 +0900 Subject: [PATCH 172/201] docs: refresh exact-head product gap evidence --- docs/product-technical-gap-baseline.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5cbb2dc04..f3dd1187c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 111 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 03:02 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 112 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 03:22 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -55,7 +55,7 @@ This is a selected shipped inventory, not a replacement for Git history. Do not ## Current exact-head governance anchors -- **PR #100** is non-draft at exact head `18256b820a2b5bb60a5c5f0c7689c125be140999`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 39 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; GraphQL reports 57 review threads with 2 unresolved and 68 reviews but no qualifying independent approval. It remains non-merge-authorized; no failed central gate or unresolved thread is bypassed. +- **PR #100** is non-draft at exact head `1ce0c1f416633669786b62bdae0a1acb0029eca0`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 39 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; GraphQL reports 58 review threads with 3 unresolved and 69 reviews but no qualifying independent approval. It remains non-merge-authorized; no failed central gate or unresolved thread is bypassed. ## Fresh active-owner truth @@ -145,6 +145,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #153** is a Draft child of #152 at exact head `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`, recorded against parent #152 head `44282cdb61269937f55bd1a69a106e948130d844`. It supplies the canonical PostgreSQL adapter for #152's Position-history port, using a read-only tenant-scoped transaction, explicit Position-anchor/version predicates, UTC projection, and untrusted DB-API row revalidation; it adds no migration, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 185 tests and 259 subtests with 1,606 statements and 528 branches at 100%, plus repository validation (55/55), compileall, Ruff, actionlint, CodeGraph sync, and diff checks; an isolated PostgreSQL 16.14 RLS/UTC/bitemporal/typed-lineage contract also passed. Its dedicated exact-head check is terminal GREEN ([run 33287205030 / job 99192355928](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33287205030/job/99192355928)); it has no reviews, threads, or qualifying independent approval. GitHub reports `CLEAN` only for the stacked child, so parent integration, fresh protected-`develop` retargeting, all applicable central gates, and independent review remain required before any authorization or merge. - **PR #154** is a Draft child of #153 at exact head `eba070206b881cc0f7193fe684cf4cb6f8c2d54b`, based on #153 at `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`. It exposes the purpose-bound, bitemporal Position-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized fields, and adds no write, cross-service query, Person/Employment/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 197 tests and 259 subtests with 1,728 statements and 558 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33288307945 / job 99195361332](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33288307945/job/99195361332)); CodeRabbit reports only `Review skipped: draft pull request`, with no formal reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` for the stacked child, but Draft state and unmerged parent #153 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. - **PR #155** is a Draft child of #149 at exact head `094466db22a707185fd2de06a1da7c228d7d6c3a`, based on #149 at `44c83128701f1985f8566b39cbf837c7b20f0111`. It exposes the purpose-bound, bitemporal Employment-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized `entries[].fields`, and adds no write, cross-service query, Position/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 172 tests with 1,646 statements and 536 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33289241743 / job 99197835852](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33289241743/job/99197835852)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent #149 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. +- **PR #156** is a Draft child of #155 at exact head `1e0c5115d19b71a6bab64789c4e1953855b27683`, based on #155 at `094466db22a707185fd2de06a1da7c228d7d6c3a`. It supplies the canonical PostgreSQL adapter for the existing Employment-history read port, using exact operational tenant/Person/UTC validation, a read-only tenant-context-bound transaction, explicit bitemporal Employment/Person predicates, UTC projection, untrusted DB-API row revalidation, and immutable typed results; it adds no migration, field authorization, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 199 tests with 1,710 statements and 560 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, diff checks, and an isolated PostgreSQL 16.14 seeded-database validation pass. Its dedicated exact-head check is terminal GREEN ([run 33290057493 / job 99200008224](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33290057493/job/99200008224)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent chain #149 → #155 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From ae5406e01dad69c65f85df43de0d9f127c4b2a8a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 13:42:16 +0900 Subject: [PATCH 173/201] docs: record employer API compatibility lane --- docs/product-technical-gap-baseline.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f3dd1187c..a956798ca 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 112 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 03:22 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 113 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 04:40 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -55,7 +55,7 @@ This is a selected shipped inventory, not a replacement for Git history. Do not ## Current exact-head governance anchors -- **PR #100** is non-draft at exact head `1ce0c1f416633669786b62bdae0a1acb0029eca0`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 39 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; GraphQL reports 58 review threads with 3 unresolved and 69 reviews but no qualifying independent approval. It remains non-merge-authorized; no failed central gate or unresolved thread is bypassed. +- **PR #100** is non-draft at exact head `05e935711fb66247ee95a1acc25cf557929143a8`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 37 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; the documentation lane has no qualifying independent approval, and the central gate failures remain non-authorizing. It remains non-merge-authorized; no failed central gate is bypassed. ## Fresh active-owner truth @@ -127,7 +127,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #119** remains open/non-draft at exact head `f7c83600471ae0363d9b4a2b2533aedba01166b1`, stacked on parent #96 at recorded base `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd`; parent #96 has advanced to `6a8454ff8ad0c52790b4a72f1fde67f61cc11358`, so GitHub reports `mergeStateStatus=DIRTY`/`CONFLICTING`. The valid repair hardens typed/null-safe review validation, tenant/unit-qualified predecessor and deferred successor bindings, reviewed-column integrity, and cycle detection across future effective-time boundaries. The review package passes 48 tests with exact 100% statement/branch coverage (182/60); real PostgreSQL 16.14 application and 0028 concurrency contracts, Foundation validation (55/55), actionlint, bash syntax, CodeGraph sync, and diff checks pass. Exact-head GitHub check-runs currently total 0, no qualifying approval exists, 16 of 17 review threads are resolved, and the caller-controlled tenant-context security thread remains unresolved. This child is not merge-authorized and must be retargeted/revalidated only after #96 integrates. - **PR #120** remains Draft at exact head `aadf4916ee64820b4f5c6a78430c9fec675e2078`, based on `feat/governed-hr-data-export-control` at `282ff0966add47a80a2edd76f84c4c65a868fedb`; parent #75 is still Draft and unintegrated at exact head `968111f88d59f340f78afd5f6aea2291221bffa1`. Its focused HR export execution suite passes 129 tests with exact 100% statement/branch coverage (497/114), covering authorization-expiry races, immutable audit-before-egress, exact artifact binding, and reconciliation-only at-most-once delivery after ambiguous publication. The exact-head hosted set contains one terminal successful check, `HR data export contract and 100% coverage`; no parent or predecessor evidence transfers. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=DIRTY`/`mergeable=false` with `reviewDecision=null`; it remains dependency-first active-PR truth only and must be retargeted/revalidated after #75 integrates. - **PR #121** remains open/non-draft at exact head `c7fba99a3b86cae612083242091fc6fd0b426ebb`, based on `feat/performance-goal-plan-evidence` at recorded base `141574958df2238d107121138c1ffb5f854126cc`; parent #92 is unintegrated at current exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487`. The valid repair separates future-time admission from sealed receipt serialization so issued activation evidence remains readable after wall-clock rollback; its focused suite passes 61 tests with exact 100% statement/branch coverage (321/76), plus compileall, Ruff, diff, and CodeGraph synchronization. The exact-head hosted set has one terminal successful dedicated check, all 4 current review threads are resolved, and no qualifying independent approval exists. GitHub reports `mergeStateStatus=CLEAN`/`mergeable=true` with `reviewDecision=null`; it remains stack-local active-PR truth only and must be retargeted/revalidated after #92 integrates. -- **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 38 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. +- **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 40 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. - **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. - **PR #122** remains open/non-draft at exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its target-side portability contract passes from the service directories with 69 job-analysis API tests and 146 People API tests, both at exact 100% statement/branch coverage; compileall and diff checks pass. The exact-head hosted set is terminal with 37 successful and 8 skipped checks, including coverage, SAST, dependency, security, OpenCode, Noema, Strix, PostgreSQL, recovery, and Foundation evidence where applicable. The one current review thread is resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains target-side active-PR truth only and does not repair the central coverage pipeline. - **PR #123** remains open/non-draft at exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after branch-bound manifest provenance was resealed. The affected candidate-evidence, offer-approval, requisition-review, HRIS-kernel, and People API suites pass locally with 75, 84, 61, 171, and 146 tests respectively, all at exact 100% statement/branch coverage; repository validation and Foundation validation (55/55) pass. Its exact-head hosted set has 39 successful, 2 failed, and 8 skipped raw check-runs; latest-by-name evidence is 39 successful, 2 skipped, and 2 terminal failures (`opencode-review` and `strix`) with no current-head OpenCode verdict or authoritative Strix report. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains active-PR truth only. @@ -146,6 +146,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #154** is a Draft child of #153 at exact head `eba070206b881cc0f7193fe684cf4cb6f8c2d54b`, based on #153 at `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`. It exposes the purpose-bound, bitemporal Position-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized fields, and adds no write, cross-service query, Person/Employment/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 197 tests and 259 subtests with 1,728 statements and 558 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33288307945 / job 99195361332](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33288307945/job/99195361332)); CodeRabbit reports only `Review skipped: draft pull request`, with no formal reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` for the stacked child, but Draft state and unmerged parent #153 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. - **PR #155** is a Draft child of #149 at exact head `094466db22a707185fd2de06a1da7c228d7d6c3a`, based on #149 at `44c83128701f1985f8566b39cbf837c7b20f0111`. It exposes the purpose-bound, bitemporal Employment-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized `entries[].fields`, and adds no write, cross-service query, Position/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 172 tests with 1,646 statements and 536 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33289241743 / job 99197835852](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33289241743/job/99197835852)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent #149 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. - **PR #156** is a Draft child of #155 at exact head `1e0c5115d19b71a6bab64789c4e1953855b27683`, based on #155 at `094466db22a707185fd2de06a1da7c228d7d6c3a`. It supplies the canonical PostgreSQL adapter for the existing Employment-history read port, using exact operational tenant/Person/UTC validation, a read-only tenant-context-bound transaction, explicit bitemporal Employment/Person predicates, UTC projection, untrusted DB-API row revalidation, and immutable typed results; it adds no migration, field authorization, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 199 tests with 1,710 statements and 560 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, diff checks, and an isolated PostgreSQL 16.14 seeded-database validation pass. Its dedicated exact-head check is terminal GREEN ([run 33290057493 / job 99200008224](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33290057493/job/99200008224)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent chain #149 → #155 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. +- **PR #157** is a Draft child of #141 at exact head `3a904f63e96336e4ae8b52753dd91556d2c6d6c3`, based on #141 at `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`. It repairs the shipped V1 compatibility defect by retaining legacy terminated payloads, rejecting employer-less active/leave V1 requests with V2 migration guidance, and exposing employer-required V2 Employment and confirmed-hire contracts. The local People API suite passes 160 tests and 235 subtests with exact 100% statement/branch coverage; repository validation passes 57 tests, including OpenAPI V1/V2 assertions, and compileall, Ruff, actionlint, shellcheck, diff, and CodeGraph synchronization pass. Its only current check is CodeRabbit's draft skip; it has no reviews, threads, or qualifying independent approval, and inherits #141's unmerged parent and central OpenCode/Strix/approval blockers. No V2 truth is shipped until protected parent integration and fresh exact-head gates complete. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. @@ -159,7 +160,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212959615 / job 98990188612](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212959615/job/98990188612)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212827583 / job 98989785049](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212827583/job/98989785049)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212498784 / job 98988751106](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212498784/job/98988751106)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 38 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. + - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 40 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is recorded on #130 base `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact child head `b7fdd493809545a7fd562fb6464b09c853739149`, its focused contract passes 6 tests at exact 100% line/branch/function coverage, repository validation passes 63 tests, and the dedicated hosted check is terminal GREEN ([run 33198343313 / job 98941173734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198343313/job/98941173734)). It remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only; it must be retargeted and revalidated on fresh `develop` after #130 and #142 integrate. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). Its recorded #130 base is `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact head `5fd7683ed8cd4bfbe9b217b64e22c0368ae6f486`, its focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and its dedicated hosted check is terminal GREEN ([run 33285252309 / job 99187216615](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285252309/job/99187216615)); the corrected action includes an explicit non-disabled hover state alongside visible focus treatment. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision and must be retargeted/revalidated on fresh `develop` after #130 and #142 integrate. - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at exact head `bd2eaa1b9f6c901758fb5e151f9354ecd8829914`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285501789 / job 99187886526](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285501789/job/99187886526) terminal GREEN; #147 owns Job Architecture workspace states at exact head `26e81931ec031bd9ac72f0053839cae58c21f6bb`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285574607 / job 99188079934](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285574607/job/99188079934) terminal GREEN; #148 owns the PostgreSQL Assignment-history read adapter at exact head `927f108505603b49112f467ddb06b5c21843ee2c`, with 184 People API tests, 256 subtests, exact 100% statement/branch coverage, and dedicated hosted run [33198401194 / job 98941396472](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198401194/job/98941396472) terminal GREEN; its current parent/base is #142 at `d832006843111cc03751ec2`. #150 owns legal-employer history presentation states at exact head `cfab4d70c38eccd5fd528a2314d1346602c405f7`, with 5 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33286022706 / job 99189253498](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33286022706/job/99189253498) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. From a88c8d5a106b395922c74e4aa8f23839abe4aab1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 13:54:54 +0900 Subject: [PATCH 174/201] docs: repair assignment adapter provenance --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a956798ca..e7315393f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 113 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 04:40 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 113 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 04:53 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -55,7 +55,7 @@ This is a selected shipped inventory, not a replacement for Git history. Do not ## Current exact-head governance anchors -- **PR #100** is non-draft at exact head `05e935711fb66247ee95a1acc25cf557929143a8`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 37 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; the documentation lane has no qualifying independent approval, and the central gate failures remain non-authorizing. It remains non-merge-authorized; no failed central gate is bypassed. +- **PR #100** is non-draft at exact head `ae5406e01dad69c65f85df43de0d9f127c4b2a8a`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 37 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; it has 69 reviews but no qualifying independent approval, and two current review threads remain unresolved. The central gate failures and unresolved conversations remain non-authorizing; no failed central gate or unresolved thread is bypassed. ## Fresh active-owner truth @@ -163,7 +163,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 40 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is recorded on #130 base `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact child head `b7fdd493809545a7fd562fb6464b09c853739149`, its focused contract passes 6 tests at exact 100% line/branch/function coverage, repository validation passes 63 tests, and the dedicated hosted check is terminal GREEN ([run 33198343313 / job 98941173734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198343313/job/98941173734)). It remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only; it must be retargeted and revalidated on fresh `develop` after #130 and #142 integrate. Neither lane mutates Assignment truth or authorizes an employment decision. - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). Its recorded #130 base is `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact head `5fd7683ed8cd4bfbe9b217b64e22c0368ae6f486`, its focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and its dedicated hosted check is terminal GREEN ([run 33285252309 / job 99187216615](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285252309/job/99187216615)); the corrected action includes an explicit non-disabled hover state alongside visible focus treatment. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision and must be retargeted/revalidated on fresh `develop` after #130 and #142 integrate. - - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at exact head `bd2eaa1b9f6c901758fb5e151f9354ecd8829914`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285501789 / job 99187886526](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285501789/job/99187886526) terminal GREEN; #147 owns Job Architecture workspace states at exact head `26e81931ec031bd9ac72f0053839cae58c21f6bb`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285574607 / job 99188079934](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285574607/job/99188079934) terminal GREEN; #148 owns the PostgreSQL Assignment-history read adapter at exact head `927f108505603b49112f467ddb06b5c21843ee2c`, with 184 People API tests, 256 subtests, exact 100% statement/branch coverage, and dedicated hosted run [33198401194 / job 98941396472](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198401194/job/98941396472) terminal GREEN; its current parent/base is #142 at `d832006843111cc03751ec2`. #150 owns legal-employer history presentation states at exact head `cfab4d70c38eccd5fd528a2314d1346602c405f7`, with 5 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33286022706 / job 99189253498](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33286022706/job/99189253498) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. + - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at exact head `bd2eaa1b9f6c901758fb5e151f9354ecd8829914`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285501789 / job 99187886526](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285501789/job/99187886526) terminal GREEN; #147 owns Job Architecture workspace states at exact head `26e81931ec031bd9ac72f0053839cae58c21f6bb`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285574607 / job 99188079934](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285574607/job/99188079934) terminal GREEN; #148 owns the PostgreSQL Assignment-history read adapter at exact head `927f108505603b49112f467ddb06b5c21843ee2c`, with 184 People API tests, 256 subtests, exact 100% statement/branch coverage, and dedicated hosted run [33198401194 / job 98941396472](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198401194/job/98941396472) terminal GREEN; its current parent/base is #142 at `d832006843111cc03751ec2bcd532df916bbc1e2`. #150 owns legal-employer history presentation states at exact head `cfab4d70c38eccd5fd528a2314d1346602c405f7`, with 5 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33286022706 / job 99189253498](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33286022706/job/99189253498) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. - **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. - **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding and fixed function search paths. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child checks and any clean/mergeable state are stack-local only. From 8b714b7e19b088953f6d0b7a25c3fcefd930bd3a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 15:06:17 +0900 Subject: [PATCH 175/201] docs: record workforce evidence child and live PR heads --- docs/product-technical-gap-baseline.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e7315393f..5ff1c3efe 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. -At this snapshot, 113 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 04:53 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +At this snapshot, 114 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 06:02 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. @@ -55,18 +55,18 @@ This is a selected shipped inventory, not a replacement for Git history. Do not ## Current exact-head governance anchors -- **PR #100** is non-draft at exact head `ae5406e01dad69c65f85df43de0d9f127c4b2a8a`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 37 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; it has 69 reviews but no qualifying independent approval, and two current review threads remain unresolved. The central gate failures and unresolved conversations remain non-authorizing; no failed central gate or unresolved thread is bypassed. +- **PR #100** is non-draft at exact head `a88c8d5a106b395922c74e4aa8f23839abe4aab1`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 37 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; it has 69 reviews but no qualifying independent approval, and all current review threads are resolved. The central gate failures remain non-authorizing; no failed central gate is bypassed. ## Fresh active-owner truth The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. -- **Oldest root PR #40** remains exact head `c67c8695b7565e90d957063dbfa260eb3917a969`. Its current Orgmetra-native Structured Interview/Foundation/Recovery/SAST/Security checks are terminal GREEN, while exact-head `opencode-review` and `strix` are terminal FAILURE; the current review findings checked during this loop were already implemented or intentionally resolved, so no leaf source repair is warranted. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. +- **Oldest root PR #40** has moved to current exact head `6917e41f9053fab6f7e99f8185f2137e8fc5fca5` since the previous review snapshot. Earlier source, review, and hosted-check evidence does not transfer across that push; the current exact-head review is pending. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #42** remains active at exact head `a9823aaff3364971cca0d42134864c21fde27c49`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. -- **PR #44** remains Draft at exact head `7a0e328929219dab59e696ce16389dd588067f1f`. Its performance-review package has local `84` tests and exact 100% statement/branch coverage, while repository validation passes; its current hosted checks include terminal `opencode-review` and `strix` **FAILURE**. All review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. +- **PR #44** remains Draft at exact head `c5ad805371406484c992b29c809f32cb0b2a0039`. Its performance-review package has local `87` tests and exact 100% statement/branch coverage; its exact-head hosted set has 35 successful, 8 skipped, and 4 terminal central failures (`noema-review`, `strix`, `dependency-review`, and `opencode-review`). All 23 review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #48** is active at exact head `9eab9d50ae0a202f4c3398ae60fba726c60ccb67` after freezing caller-controlled compensation-review recorded-time evidence as a detached exact UTC instant and documenting the boundary. Its local package suite has `77` tests and exact 100% statement/branch coverage; the current exact-head hosted set has 31 successful, 7 skipped, 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`), with `strix` still in progress when observed. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #54** remains exact head `fd39e07b2ab3490a3ebe0cecd6361f52f162c5d7` after reconciling direct-construction staffing totals, making workforce endpoint aggregation and change deltas independent of ambient Decimal precision, and hardening employment/Position allocation limits under low precision. Its HRIS kernel suite passes 213 tests with exact 100% statement/branch coverage and repository validation passes 55 tests. The current exact-head hosted set has 36 successful, 6 skipped, and 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`); no Strix check surfaced for this exact head. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only while protected gates are incomplete. +- **PR #54** remains exact head `6dc0f3da8f716d1b67d48336e0cdfb8f35a2770e` after adding same-cutoff workforce-composition change evidence. Its parent HRIS kernel suite passes 213 tests with exact 100% statement/branch coverage; the current exact-head hosted set has 34 successful, 8 skipped, and 6 terminal failures (`Foundation validation`, `PostgreSQL restore rehearsal`, `noema-review`, `strix`, `dependency-review`, and `opencode-review`). Three valid evidence-boundary review findings were repaired in stacked child #158; the parent still has no qualifying independent approval and remains active-PR truth only while protected gates are incomplete. - **PR #57** remains exact head `4359cfbb4cd8ee5885acb9110d7723099d712353` with a governed selection-validity analysis handoff and aggregate scientific result envelope bound to the reviewed `fast-mlsirm` revision. Its local package suite passes 92 tests with exact 100% statement/branch coverage; the exact-head hosted set has 35 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`). All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #56** is exact head `68af42cb80807b6638d745d1687fd3c6a814d64f` after removing bare cross-tenant UUID ownership inference that could reject valid tenant-qualified UUID collisions and aligning the builder exception contract. Its HRIS kernel suite passes 198 tests with exact 100% statement/branch coverage, Ruff, compile, and diff checks. The new exact-head hosted set was still running when recorded (3 skipped, 2 in progress, 25 queued of 39 observed); all current review threads were answered/resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #59** remains exact head `3e2eded6e75f16a8a53e106fb11865bc60e77916` with 98 local offer-approval tests and exact 100% statement/branch coverage. Its exact-head hosted set has 24 successful, 4 skipped, and 2 terminal failures (`strix`, `opencode-review`); all current review threads are resolved and no qualifying independent approval exists. @@ -147,6 +147,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **PR #155** is a Draft child of #149 at exact head `094466db22a707185fd2de06a1da7c228d7d6c3a`, based on #149 at `44c83128701f1985f8566b39cbf837c7b20f0111`. It exposes the purpose-bound, bitemporal Employment-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized `entries[].fields`, and adds no write, cross-service query, Position/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 172 tests with 1,646 statements and 536 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33289241743 / job 99197835852](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33289241743/job/99197835852)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent #149 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. - **PR #156** is a Draft child of #155 at exact head `1e0c5115d19b71a6bab64789c4e1953855b27683`, based on #155 at `094466db22a707185fd2de06a1da7c228d7d6c3a`. It supplies the canonical PostgreSQL adapter for the existing Employment-history read port, using exact operational tenant/Person/UTC validation, a read-only tenant-context-bound transaction, explicit bitemporal Employment/Person predicates, UTC projection, untrusted DB-API row revalidation, and immutable typed results; it adds no migration, field authorization, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 199 tests with 1,710 statements and 560 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, diff checks, and an isolated PostgreSQL 16.14 seeded-database validation pass. Its dedicated exact-head check is terminal GREEN ([run 33290057493 / job 99200008224](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33290057493/job/99200008224)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent chain #149 → #155 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. - **PR #157** is a Draft child of #141 at exact head `3a904f63e96336e4ae8b52753dd91556d2c6d6c3`, based on #141 at `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`. It repairs the shipped V1 compatibility defect by retaining legacy terminated payloads, rejecting employer-less active/leave V1 requests with V2 migration guidance, and exposing employer-required V2 Employment and confirmed-hire contracts. The local People API suite passes 160 tests and 235 subtests with exact 100% statement/branch coverage; repository validation passes 57 tests, including OpenAPI V1/V2 assertions, and compileall, Ruff, actionlint, shellcheck, diff, and CodeGraph synchronization pass. Its only current check is CodeRabbit's draft skip; it has no reviews, threads, or qualifying independent approval, and inherits #141's unmerged parent and central OpenCode/Strix/approval blockers. No V2 truth is shipped until protected parent integration and fresh exact-head gates complete. +- **PR #158** is a Draft stacked child of #54 at exact head `065ef30b10f0fce9bd74ac442f307b41433aa58d`, based on parent exact head `6dc0f3da8f716d1b67d48336e0cdfb8f35a2770e`. It hardens malformed status-count handling, hostile Decimal FTE exponent handling, and cross-endpoint workforce-change export invariants, and refreshes the stale workforce ADR manifest entry. Its local HRIS kernel suite passes 230 tests with exact 100% statement/branch coverage; Foundation validation passes 55 Node tests, with compileall, Ruff, actionlint, diff, and CodeGraph synchronization passing. It has no reviews or qualifying independent approval; its hosted checks had only CodeRabbit's draft skip when created, and no evidence transfers until parent #54 integrates and all protected exact-head gates pass. - **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. - **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. - **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. From 0d46d1878cde4baa27934e28f25687a803124473 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 30 Aug 2026 15:12:21 +0900 Subject: [PATCH 176/201] docs: record exact current interview-plan evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5ff1c3efe..5608a5ec3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -61,7 +61,7 @@ This is a selected shipped inventory, not a replacement for Git history. Do not The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. -- **Oldest root PR #40** has moved to current exact head `6917e41f9053fab6f7e99f8185f2137e8fc5fca5` since the previous review snapshot. Earlier source, review, and hosted-check evidence does not transfer across that push; the current exact-head review is pending. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. +- **Oldest root PR #40** is exact head `6917e41f9053fab6f7e99f8185f2137e8fc5fca5` on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its interview-plan suite passes 136 tests with exact 100% statement/branch coverage; Foundation validation passes 55 Node tests, and compileall, Ruff, actionlint, shellcheck, and diff checks pass. The exact-head hosted set has 43 successful, 8 skipped, and 4 terminal central failures (`dependency-review`, `noema-review`, `opencode-review`, and `strix`); GitHub reports `MERGEABLE`/`CHANGES_REQUESTED`, with 86 reviews, no qualifying approval, and 62 review threads all resolved. No current leaf source defect was found; the central failures and review state remain non-authorizing. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #42** remains active at exact head `a9823aaff3364971cca0d42134864c21fde27c49`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `c5ad805371406484c992b29c809f32cb0b2a0039`. Its performance-review package has local `87` tests and exact 100% statement/branch coverage; its exact-head hosted set has 35 successful, 8 skipped, and 4 terminal central failures (`noema-review`, `strix`, `dependency-review`, and `opencode-review`). All 23 review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. From 0ff00cd15194c8ca9caedb6aabfe861d74801b1a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 31 Aug 2026 21:03:34 +0900 Subject: [PATCH 177/201] docs: record central required-review gate root cause Fresh 2026-08-31 exact-head sweep of the non-draft queue confirms the dominant merge blocker is the central required-review set, not leaf defects: opencode-review / noema-review fail closed with no current-head verdict from the .github dispatch agent; dependency-review fails closed on an intermittent GitHub dependency-graph HTTP 403; strix is terminal FAILURE on most non-draft PRs. #122 is the only non-draft PR with the whole central set GREEN, held only by REVIEW_REQUIRED. Also: gitignore the local .codegraph/ index; note removal of stranded PR #119 podman test-isolation wrappers and empty agent-registry files. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01FQWfxSuCi8U16WDJ9VyGjm --- .gitignore | 3 +++ docs/product-technical-gap-baseline.md | 15 +++++++++++++++ 2 files changed, 18 insertions(+) diff --git a/.gitignore b/.gitignore index 1f0b61ba5..8c0face9e 100644 --- a/.gitignore +++ b/.gitignore @@ -35,3 +35,6 @@ secrets/ artifacts/ reports/ *.log + +# Local code-intelligence index (colbymchenry/codegraph); never committed +.codegraph/ diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5608a5ec3..b9c983b3e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -57,6 +57,20 @@ This is a selected shipped inventory, not a replacement for Git history. Do not - **PR #100** is non-draft at exact head `a88c8d5a106b395922c74e4aa8f23839abe4aab1`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 37 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; it has 69 reviews but no qualifying independent approval, and all current review threads are resolved. The central gate failures remain non-authorizing; no failed central gate is bypassed. +## Central required-review gate status (2026-08-31 sweep) + +A fresh exact-head sweep on 2026-08-31 (Asia/Seoul) across the non-draft queue (#118, #121, #122, #123, #141) confirms the dominant merge blocker is the central required-review set, not leaf defects: + +- **`opencode-review`** fails closed on #118 (job `99169408282`, step "Fail closed without a current-head OpenCode verdict"): *"No APPROVED or CHANGES_REQUESTED from opencode-agent on the current head. This required check is not a review and must not succeed until the authenticated dispatch posts a current-head verdict."* The same terminal FAILURE is present on #123, #141, and #149. +- **`noema-review`** fails closed on #118 (job `99166936144`); it emits only the notice *"Noema reviewer will mint a repository-scoped cwl-noema-review installation token"* before exiting non-zero — no current-head verdict is posted. Also terminal FAILURE on #149. +- **`dependency-review`** fails closed on #118 (job `99166940453`, step "Check dependency review support"): *"Dependency review evidence unavailable for ContextualWisdomLab/Orgmetra at exact base `9e3e4847510e1e612b48474ba42b177b8ed824df` and head `beece4d2ffcd20258bf0e015477dd45448ed05d0`: HTTP 403; curl exit 0. … Failing closed."* It is GREEN on #122/#123/#141, so the 403 is intermittent GitHub dependency-graph service/permission behavior; the workflow's own remediation is to reverify dependency-graph configuration and rerun. +- **`strix`** is terminal FAILURE on #123, #141, and #149, and SUCCESS on #122. +- **PR #122** (`fix/central-sandbox-sibling-imports`) is the single non-draft PR with the entire central set GREEN (`opencode-review`, `noema-review`, `strix`, `dependency-review` all SUCCESS); it is held only by `REVIEW_REQUIRED` — no qualifying independent approval, no leaf failure. + +Consequence for the loop: the queue cannot progress on leaf fixes alone. The central OpenCode/Noema/Strix verdict-dispatch path lives in `ContextualWisdomLab/.github`; a missing current-head verdict is a hosted review-orchestration defect at that owner boundary, not an Orgmetra leaf-test failure, and must not be bypassed. Orgmetra-side action is limited to (a) keeping leaf evidence exact-head GREEN, (b) rerunning the intermittent `dependency-review` 403, and (c) raising the dispatch defect on the `.github` owner path. + +Local hygiene reconciled this sweep: removed stranded PR #119 test-isolation artifacts (`psql` and `.tmp-psql-wrapper` podman wrappers, empty `registered_agents.json`/`task_agent_mapping.json`) and the exited `orgmetra-pr119-postgres` container; added `.codegraph/` to `.gitignore` so the local code-intelligence index is never committed. + ## Fresh active-owner truth The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. @@ -64,6 +78,7 @@ The following material owner lanes were freshly rechecked during the 2026-08-29 - **Oldest root PR #40** is exact head `6917e41f9053fab6f7e99f8185f2137e8fc5fca5` on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its interview-plan suite passes 136 tests with exact 100% statement/branch coverage; Foundation validation passes 55 Node tests, and compileall, Ruff, actionlint, shellcheck, and diff checks pass. The exact-head hosted set has 43 successful, 8 skipped, and 4 terminal central failures (`dependency-review`, `noema-review`, `opencode-review`, and `strix`); GitHub reports `MERGEABLE`/`CHANGES_REQUESTED`, with 86 reviews, no qualifying approval, and 62 review threads all resolved. No current leaf source defect was found; the central failures and review state remain non-authorizing. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. - **PR #42** remains active at exact head `a9823aaff3364971cca0d42134864c21fde27c49`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. - **PR #44** remains Draft at exact head `c5ad805371406484c992b29c809f32cb0b2a0039`. Its performance-review package has local `87` tests and exact 100% statement/branch coverage; its exact-head hosted set has 35 successful, 8 skipped, and 4 terminal central failures (`noema-review`, `strix`, `dependency-review`, and `opencode-review`). All 23 review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. +- **PR #45** remains Draft at exact head `0023f13469cc0f6f9d1da08f3b1548062fa61dbe` on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its assignment-change review package passes 108 tests with exact 100% statement/branch coverage; the exact-head hosted set has 31 successful, 8 skipped, and 4 terminal central failures (`noema-review`, `strix`, `dependency-review`, and `opencode-review`). All 14 review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. - **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #48** is active at exact head `9eab9d50ae0a202f4c3398ae60fba726c60ccb67` after freezing caller-controlled compensation-review recorded-time evidence as a detached exact UTC instant and documenting the boundary. Its local package suite has `77` tests and exact 100% statement/branch coverage; the current exact-head hosted set has 31 successful, 7 skipped, 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`), with `strix` still in progress when observed. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. - **PR #54** remains exact head `6dc0f3da8f716d1b67d48336e0cdfb8f35a2770e` after adding same-cutoff workforce-composition change evidence. Its parent HRIS kernel suite passes 213 tests with exact 100% statement/branch coverage; the current exact-head hosted set has 34 successful, 8 skipped, and 6 terminal failures (`Foundation validation`, `PostgreSQL restore rehearsal`, `noema-review`, `strix`, `dependency-review`, and `opencode-review`). Three valid evidence-boundary review findings were repaired in stacked child #158; the parent still has no qualifying independent approval and remains active-PR truth only while protected gates are incomplete. From b2ab4951736235c376bee6a53f682b95dd15a0b0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 1 Sep 2026 21:19:08 +0900 Subject: [PATCH 178/201] fix: reseal manifest after codegraph ignore --- manifest.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifest.json b/manifest.json index 4917d73de..94e990d50 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"145fda644f5209fa1fb3e3b40c9af9258bfac6d1a634bba2520fd08fe6d77a21","bytes":375,"lines":37},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"27af9b5fcc359a5131d146a258d55bfad5aa45c3310860821912e2446c75e0f2","bytes":12419,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"46fbdd18f514f680ec88cd5c77d765094beff78b2919d5089f30c985015e05be","bytes":462,"lines":40},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"27af9b5fcc359a5131d146a258d55bfad5aa45c3310860821912e2446c75e0f2","bytes":12419,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} \ No newline at end of file From 61986f8643a47968ccb574bde85b626f7ca9df43 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 1 Sep 2026 21:58:00 +0900 Subject: [PATCH 179/201] docs(product): replace stale PR inventory with commercialization baseline --- docs/product-technical-gap-baseline.md | 404 +++++++++++-------------- 1 file changed, 181 insertions(+), 223 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b9c983b3e..ecf7dde1c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,233 +1,191 @@ # Product and technical gap baseline -Inventory date: 2026-08-30 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. +Verified: 2026-09-01 (Asia/Seoul). -At this snapshot, 114 pull requests and one non-PR issue (#89) are open, verified with paginated GitHub `open` filters at `2026-08-30 06:02 UTC`; the repository has no releases. These counts are dated evidence, not live merge authorization. +This document is the commercialization baseline for **Orgmetra**, not a frozen PR inventory and not merge authorization. It records product responsibility, shipped-vs-planned truth, causal control-plane blockers, and the next highest-leverage buyer gaps. Volatile PR heads, workflow run IDs, queue counts, review snapshots, mergeability, and base tips must be fetched live before every action rather than copied here until stale. -This is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, approval evidence, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and independently resolved bases, dependency ancestry, formal reviews and unresolved threads, exact-head workflow/job checkout SHAs, effective rulesets, releases, and changed refs before acting. +## 1. Product thesis and buyer outcome -Orgmetra owns authoritative HRIS/HCM truth only inside its published boundaries. Keyverse and the other dedicated-writer CWL repositories remain read-only dependencies consumed through published package/API/event contracts and existing owner-control paths. A static product-gap document never authorizes writes into another dedicated-writer repository. +Orgmetra is the ContextualWisdomLab evidence-centered HRIS/HCM system of record. Its commercial value is not another employee database: it preserves **what employment fact was true, when it was true, which evidence justified a high-impact decision, who acted, what purpose authorized access, and how later outcomes validate the original job/selection model**. -## Effective repository-control truth +Primary buyer/user roles from the PRD are HR operations owners, HRIS administrators, recruiters, hiring managers, job-analysis specialists, psychometricians/people-analytics scientists, compliance/audit reviewers, workers, and enterprise integration engineers. -The effective control plane for default branch `develop` is organization ruleset **18156473 — `CWL Central required workflows`**, not the empty classic branch-protection payload by itself. Fresh repository reads on 2026-08-29 show the ruleset is `enforcement: active` and targets `~DEFAULT_BRANCH`. +The buyer-facing lifecycle is: -The **current live ruleset is weaker than Orgmetra's acquisition-grade acceptance policy**: +1. govern job requirements and evidence; +2. collect candidate evidence without turning opaque references into decision authority; +3. record accountable human selection and offer decisions; +4. convert a selected candidate into authoritative worker/employment/assignment truth without losing provenance; +5. observe job-relevant performance over effective and system time; +6. validate selection evidence against later outcomes and fairness evidence; and +7. expose purpose-bound, auditable workflows through stable APIs and role workspaces. -- it requires **1** approving review, not two; -- `dismiss_stale_reviews_on_push = true`; +## 2. Truth-state contract + +Every feature claim must use one of these states. A documentation-only design is never promoted to shipped truth. + +| State | Meaning | +| --- | --- | +| **Shipped truth** | Present on protected `develop` with executable evidence. | +| **Active PR** | Implemented only on an open exact PR head; predecessor or sibling evidence does not transfer. | +| **Accepted architecture** | Accepted ADR/PRD/TRD boundary whose production implementation is incomplete. | +| **Planned** | Prioritized buyer capability with no executable production evidence yet. | +| **Research-only** | Evidence or experiment that must not be represented as product behavior. | +| **Superseded** | Replaced decision/evidence; retain only for provenance. | +| **Out of scope** | Owned by another bounded context/repository or explicitly rejected. | + +Merge, release, deployment, and compliance claims require fresh exact-head evidence independently of this file. + +## 3. Domain ownership and context map + +Orgmetra owns **authoritative employment truth**. It must not become a monolithic copy of specialist products. + +| Bounded context | Orgmetra responsibility | Integration boundary | +| --- | --- | --- | +| `people_core` | person anchors, employment, assignments, compensation references, candidate-worker linkage | Keyverse provides identity, not HRIS truth | +| `organization_core` | legal/organization units, reporting relations, locations, positions | external org identities remain referenced, not copied wholesale | +| `job_architecture` | jobs, tasks, FJA/KSAO evidence, qualification rules, SME approval, governed snapshots | ontology sources and contextual-orchestrator are evidence/draft adapters | +| `talent_acquisition` | requisitions, candidates, interviews, immutable decision-evidence sets, selection/offer governance | specialist assessment systems remain external evidence owners | +| `performance_management` | cycles, criterion blueprints, observations, calibration | observations bind authoritative worker/job/time scope | +| `workforce_validation` | validity-study registry, exact predictor/criterion links, subgroup/drift evidence, scientific adapters | fast-mlsirm/TEPP/Psychometrics Commons own specialist numerical/psychometric computation | +| `document_records` | canonical document/image metadata and immutable artifact references | Clearfolio/NewsDOM-style document services are adapters | +| `integration_hub` | idempotency, inbox/outbox, adapter state, migration/CDC boundary | Naruon, migration tools, and peer CWL systems remain behind versioned ACLs | +| `audit_provenance` | append-only audit/provenance evidence | no peer service may silently become authoritative HRIS state | + +The initial deployment may share one PostgreSQL cluster, but each bounded context keeps an owned schema, role, migrations, generated access layer, and contract. Cross-context application-table reads are prohibited; versioned API/event/adapters form the anti-corruption layer. A shared physical database is not a Shared Kernel license. + +## 4. Current protected-branch product truth + +Protected `develop` was freshly observed at `9e3e4847510e1e612b48474ba42b177b8ed824df`. This SHA is a dated evidence anchor only; every execution loop must re-fetch the branch before acting. + +Shipped foundation evidence includes: + +- bitemporal HRIS, tenant-isolation/RLS, evidence-sealing, audit/outbox and persistence contracts; +- governed candidate/selection/requisition/offer and job-analysis evidence packages; +- purpose-bound authorization and normalized employment/assignment/performance foundations; +- Keyverse/Naruon/migration adapter boundaries and design-token foundations; and +- PRD/TRD/ADR/UML/ERD/security/test/operability documentation sufficient to define intended modular boundaries. + +The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. + +There are currently no published GitHub releases. Do not manufacture a release merely to clear that count; release only when an integrated protected head has complete exact-head governance, security, operability and buyer-workflow evidence. + +## 5. Effective GitHub governance: P0 release blocker + +The effective control plane for Orgmetra `develop` is inherited organization ruleset **18156473 — `CWL Central required workflows`**. Classic branch-protection fields alone are not authoritative while that ruleset is active. + +Fresh live reads on 2026-09-01 show the inherited ruleset still has: + +- `required_approving_review_count = 1`; - `require_last_push_approval = false`; -- review-thread resolution and the central required-workflow set remain enabled; -- deletion and non-fast-forward updates remain prohibited; and -- `OrganizationAdmin` retains `bypass_mode=always`, while the connected user reports `current_user_can_bypass=always`. - -Issue #89 owns the remaining repository-governance gap. Orgmetra's commercial acceptance remains stricter than the live ruleset: **at least two qualifying independent non-author approvals, approval after the last push, resolved conversations, every applicable exact-current-head local/central gate terminal GREEN, and no routine administrator bypass**. Organization-settings changes belong to the existing central owner-control path; Orgmetra must not simulate them with a workflow shim. - -The classic branch payload can still report `protection.enabled=false`, required-status enforcement `off`, and no classic contexts/checks. That is **not** evidence that `develop` lacks an effective ruleset while organization ruleset 18156473 is active. - -Consequences: - -- GREEN or GitHub-mergeable is not merge authorization; -- queued, pending, cancelled, skipped, neutral, absent, stale, predecessor, status-only, or model-only evidence is non-passing; -- routine administrator bypass is not a normal merge path; -- a technically GREEN PR that another same-repository lifecycle writer has returned to Draft remains Draft until that authoritative writer advances it; and -- immediately before any future merge, refetch the unchanged exact head, live base, formal reviews, unresolved threads, effective ruleset, and every applicable exact-head check/job. - -## Selected shipped buyer-visible anchors on `develop` - -| Merged PR | Capability | -|---|---| -| #23 | Governed audit/outbox envelope and durable delivery evidence | -| #25 | Governed Job Analysis evidence boundary | -| #26 | `validity_study_case_record` integrity | -| #27 | Purpose-bound PII authorization and least-privilege capability boundary | -| #28 | Performance-criterion Job-scope guard | -| #31 | Governed People mutation API | -| #32 | Governed Naruon calendar intent adapter | -| #33 | Bitemporal workforce-composition evidence | -| #35 | Governed HRIS migration handoff | -| #38 | Governed Job Analysis snapshot persistence/read | -| #39 | Governed requisition review packet | -| #41 | Governed candidate evidence intake | -| #43 | Governed offer approval packet | - -This is a selected shipped inventory, not a replacement for Git history. Do not describe active-PR capability as shipped until its owner PR integrates into fresh `develop`. - -## Current exact-head governance anchors - -- **PR #100** is non-draft at exact head `a88c8d5a106b395922c74e4aa8f23839abe4aab1`, based on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its exact-head checks currently have 37 successful, 8 skipped, and 4 terminal failures (`opencode-review`, `strix`, `dependency-review`, `noema-review`), with no pending checks. GitHub reports `MERGEABLE`/`BLOCKED`; it has 69 reviews but no qualifying independent approval, and all current review threads are resolved. The central gate failures remain non-authorizing; no failed central gate is bypassed. - -## Central required-review gate status (2026-08-31 sweep) - -A fresh exact-head sweep on 2026-08-31 (Asia/Seoul) across the non-draft queue (#118, #121, #122, #123, #141) confirms the dominant merge blocker is the central required-review set, not leaf defects: - -- **`opencode-review`** fails closed on #118 (job `99169408282`, step "Fail closed without a current-head OpenCode verdict"): *"No APPROVED or CHANGES_REQUESTED from opencode-agent on the current head. This required check is not a review and must not succeed until the authenticated dispatch posts a current-head verdict."* The same terminal FAILURE is present on #123, #141, and #149. -- **`noema-review`** fails closed on #118 (job `99166936144`); it emits only the notice *"Noema reviewer will mint a repository-scoped cwl-noema-review installation token"* before exiting non-zero — no current-head verdict is posted. Also terminal FAILURE on #149. -- **`dependency-review`** fails closed on #118 (job `99166940453`, step "Check dependency review support"): *"Dependency review evidence unavailable for ContextualWisdomLab/Orgmetra at exact base `9e3e4847510e1e612b48474ba42b177b8ed824df` and head `beece4d2ffcd20258bf0e015477dd45448ed05d0`: HTTP 403; curl exit 0. … Failing closed."* It is GREEN on #122/#123/#141, so the 403 is intermittent GitHub dependency-graph service/permission behavior; the workflow's own remediation is to reverify dependency-graph configuration and rerun. -- **`strix`** is terminal FAILURE on #123, #141, and #149, and SUCCESS on #122. -- **PR #122** (`fix/central-sandbox-sibling-imports`) is the single non-draft PR with the entire central set GREEN (`opencode-review`, `noema-review`, `strix`, `dependency-review` all SUCCESS); it is held only by `REVIEW_REQUIRED` — no qualifying independent approval, no leaf failure. - -Consequence for the loop: the queue cannot progress on leaf fixes alone. The central OpenCode/Noema/Strix verdict-dispatch path lives in `ContextualWisdomLab/.github`; a missing current-head verdict is a hosted review-orchestration defect at that owner boundary, not an Orgmetra leaf-test failure, and must not be bypassed. Orgmetra-side action is limited to (a) keeping leaf evidence exact-head GREEN, (b) rerunning the intermittent `dependency-review` 403, and (c) raising the dispatch defect on the `.github` owner path. - -Local hygiene reconciled this sweep: removed stranded PR #119 test-isolation artifacts (`psql` and `.tmp-psql-wrapper` podman wrappers, empty `registered_agents.json`/`task_agent_mapping.json`) and the exited `orgmetra-pr119-postgres` container; added `.codegraph/` to `.gitignore` so the local code-intelligence index is never committed. - -## Fresh active-owner truth - -The following material owner lanes were freshly rechecked during the 2026-08-29 maintenance loop. - -- **Oldest root PR #40** is exact head `6917e41f9053fab6f7e99f8185f2137e8fc5fca5` on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its interview-plan suite passes 136 tests with exact 100% statement/branch coverage; Foundation validation passes 55 Node tests, and compileall, Ruff, actionlint, shellcheck, and diff checks pass. The exact-head hosted set has 43 successful, 8 skipped, and 4 terminal central failures (`dependency-review`, `noema-review`, `opencode-review`, and `strix`); GitHub reports `MERGEABLE`/`CHANGES_REQUESTED`, with 86 reviews, no qualifying approval, and 62 review threads all resolved. No current leaf source defect was found; the central failures and review state remain non-authorizing. The canonical foreign owner handoff is **`.github#1250`**; the previously cited `.github#1052` implementation path is closed without merge and must not be represented as an active owner PR. Orgmetra must not weaken local 100% coverage or create a competing foreign repair. -- **PR #42** remains active at exact head `a9823aaff3364971cca0d42134864c21fde27c49`. Its selection-monitoring package has local `116` tests and exact 100% statement/branch coverage, all review threads are resolved, and no qualifying approval is present. Its required OpenCode review check is terminal **FAILURE** because no current-head `opencode-agent` verdict was posted; this is a hosted review-orchestration blocker, not a leaf test failure. It remains active-PR truth only until fresh protected-base checks, independent approvals, and the required central gates complete. -- **PR #44** remains Draft at exact head `c5ad805371406484c992b29c809f32cb0b2a0039`. Its performance-review package has local `87` tests and exact 100% statement/branch coverage; its exact-head hosted set has 35 successful, 8 skipped, and 4 terminal central failures (`noema-review`, `strix`, `dependency-review`, and `opencode-review`). All 23 review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. -- **PR #45** remains Draft at exact head `0023f13469cc0f6f9d1da08f3b1548062fa61dbe` on protected `develop` `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its assignment-change review package passes 108 tests with exact 100% statement/branch coverage; the exact-head hosted set has 31 successful, 8 skipped, and 4 terminal central failures (`noema-review`, `strix`, `dependency-review`, and `opencode-review`). All 14 review threads are resolved and no qualifying approval is present. It remains active-PR truth only and must not be described as shipped. -- **PR #47** remains active at exact head `8562166d0d5bfca42f8a0ae323b80d78d015e22e`. Its employment-leave review package has local `119` tests and exact 100% statement/branch coverage; the exact-head package run is GREEN with 35 successful and 8 skipped checks, while `mergeStateStatus=BLOCKED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #48** is active at exact head `9eab9d50ae0a202f4c3398ae60fba726c60ccb67` after freezing caller-controlled compensation-review recorded-time evidence as a detached exact UTC instant and documenting the boundary. Its local package suite has `77` tests and exact 100% statement/branch coverage; the current exact-head hosted set has 31 successful, 7 skipped, 3 terminal failures (`opencode-review`, `dependency-review`, and `noema-review`), with `strix` still in progress when observed. All current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #54** remains exact head `6dc0f3da8f716d1b67d48336e0cdfb8f35a2770e` after adding same-cutoff workforce-composition change evidence. Its parent HRIS kernel suite passes 213 tests with exact 100% statement/branch coverage; the current exact-head hosted set has 34 successful, 8 skipped, and 6 terminal failures (`Foundation validation`, `PostgreSQL restore rehearsal`, `noema-review`, `strix`, `dependency-review`, and `opencode-review`). Three valid evidence-boundary review findings were repaired in stacked child #158; the parent still has no qualifying independent approval and remains active-PR truth only while protected gates are incomplete. -- **PR #57** remains exact head `4359cfbb4cd8ee5885acb9110d7723099d712353` with a governed selection-validity analysis handoff and aggregate scientific result envelope bound to the reviewed `fast-mlsirm` revision. Its local package suite passes 92 tests with exact 100% statement/branch coverage; the exact-head hosted set has 35 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`). All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #56** is exact head `68af42cb80807b6638d745d1687fd3c6a814d64f` after removing bare cross-tenant UUID ownership inference that could reject valid tenant-qualified UUID collisions and aligning the builder exception contract. Its HRIS kernel suite passes 198 tests with exact 100% statement/branch coverage, Ruff, compile, and diff checks. The new exact-head hosted set was still running when recorded (3 skipped, 2 in progress, 25 queued of 39 observed); all current review threads were answered/resolved, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #59** remains exact head `3e2eded6e75f16a8a53e106fb11865bc60e77916` with 98 local offer-approval tests and exact 100% statement/branch coverage. Its exact-head hosted set has 24 successful, 4 skipped, and 2 terminal failures (`strix`, `opencode-review`); all current review threads are resolved and no qualifying independent approval exists. -- **PR #60** remains exact head `6417a590e97916782f600aee0c1f05220b42ff9d` with 85 local selection-review tests and exact 100% statement/branch coverage. Its exact-head hosted set has 24 successful, 4 skipped, and 2 terminal failures (`strix`, `opencode-review`); all current review threads are resolved and no qualifying independent approval exists. -- **PR #61** remains exact head `0c957b3207f349ade77e2ade093cb9a0aaedd967` with 90 local candidate-evidence tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. -- **PR #62** remains exact head `6ad5b867bf96561feef4639287ac2183f27921dc` with 75 local requisition-review tests and exact 100% statement/branch coverage. Its exact-head hosted set has 27 successful, 3 skipped, and no terminal failures; all current review threads are resolved and no qualifying independent approval exists. -- **PR #63** is exact head `5c5250953273051276a356ac91ea9a248968c80a` after rejecting nested `TaskEvidence` and `KSAORequirement` subclasses before canonical job-analysis serialization. Its HRIS kernel suite passes 206 tests with exact 100% statement/branch coverage; the exact-head hosted set was still running when recorded with 13 successful, 2 skipped, 1 terminal failure (`dependency-review`), and 14 pending of 45 observed. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #64** remains exact head `c397053ba62dfaf4dd84d6b3d581fccb756e55bb` with 178 local People API tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. -- **PR #65** remains exact head `c8b7f30097a30ab95956d4a73f0a38848cfe9ca1` with 62 local Keyverse authorization/binding tests and exact 100% statement/branch coverage. Its exact-head hosted set has 26 successful, 3 skipped, and 1 terminal failure (`opencode-review`); all current review threads are resolved and no qualifying independent approval exists. -- **PR #68** is exact head `ffb0f2b55d5d5bd543bc5b94e56f1d9b7e4b1271` after making the adversarial calendar-response equality and inequality fixture consistent so exact-type validation cannot be bypassed. Its Naruon adapter suite passes 45 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`). All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #69** is exact head `6fdf537463c32fdd50daec477d571ce97d60fc3f` after rejecting caller-controlled `timedelta` subclasses during recorded-time canonicalization and synchronizing the protected-`develop` SHA in the changelog. Its HRIS kernel suite passes 186 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass for the documentation follow-up. The newly restarted exact-head hosted set currently has 4 successful, 31 pending, and 6 skipped checks with no terminal failure observed; all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #70** is exact head `e4624c0fb4034fe53654ed661e32156f9e14c31e` after rejecting every overlapping recorded-visible PositionVersion pair for one seat, including same-status duplicates, and aligning ADR 0005 with the single-valued persistence contract. Its HRIS kernel suite passes 173 tests with exact 100% statement/branch coverage; Foundation validation and the 55 Node contract tests pass. The exact-head hosted set was restarted with 2 successful and 34 pending checks plus 7 skipped checks; all current review threads are resolved, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #71** remains exact head `1d7ed5bbfb18b35d589c69a6e8d93754ba299589` with hardened value-free migration-handoff runtime checks for exact text, integer, target, dependency-revision, and envelope-mode types. Its migration-adapter suite passes 71 tests with exact 100% statement/branch coverage; the exact-head hosted set has 37 successful and 8 skipped checks, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #72** is exact head `a8ddab514ebf5e09c44186862884b4b9b4e6f4dd` after preserving protected-base migration `0011` and its trigger binding, applying chronology enforcement in `0014`, and changing omitted observation `recorded_from` to `statement_timestamp()` in sequential migration `0015` so valid inserts after a long transaction begins are not rejected. Foundation validation and the 55 Node contract tests pass locally; the pinned PostgreSQL 16.14 criterion contract passes, including the long-transaction default regression. Its current exact-head hosted set has 11 successful, 6 skipped, 1 terminal failure (`dependency-review`), and 24 in progress; Devin Review is pending/analyzing, CodeRabbit is successful but rate limited, all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`, so it remains active-PR truth only. -- **PR #73** remains exact head `acaebb70d777bf4aecbe64d0e71430c0ec0fefa3` after hardening the recorded-correction boundary to the four authoritative HRIS fact types, exact `RecordedInterval`, exact built-in datetime endpoints, and detached built-in fixed-offset timezone evidence. Its full HRIS-kernel suite passes 180 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 36 successful, 8 skipped, and 4 terminal failures (`strix`, `opencode-review`, `dependency-review`, and `noema-review`); Devin Review is successful but no authoritative Strix report or OpenCode/Noema protected verdict is available. All current review threads are resolved and no qualifying independent approval exists, so it remains active-PR truth only. -- **PR #74** remains exact head `7d75e683b5bca2881f70e4447e69b3de80babd00` with dependency-free `/health` liveness and owned-PostgreSQL `/ready` readiness offloaded from the ASGI event loop. Its People API suite passes 157 tests with exact 100% statement/branch coverage; Ruff, compile, and diff checks pass. The exact-head hosted set has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); Noema is terminal GREEN, all current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and it remains active-PR truth only. -- **PR #75** remains Draft at exact head `968111f88d59f340f78afd5f6aea2291221bffa1` with a value-minimized, human-reviewed HR data export control packet that never exports values or authorizes egress. Its focused package suite passes 65 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 33 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, and `strix`); the failures are missing OpenCode current-head verdict and contextual-orchestrator sidecar provisioning failures before Noema/Strix review, not local package failures. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and the Draft state remains authoritative; it is active-PR truth only and must not transfer evidence to stacked child #120. -- **PR #76** remains open/non-draft at exact head `a48632c9862f54f128790be6e33bd1736f228f73` for the governed HR retention review packet. Its focused suite passes 52 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 22 successful, 7 skipped, 2 terminal failures (`opencode-review` and `dependency-review`), and 10 in progress; `noema-review`, `strix`, Semgrep, Devin Review, and PostgreSQL contract jobs are not terminally successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; it remains active-PR truth only and must not transfer evidence to child #120. -- **PR #77** remains open/non-draft at exact head `0df26b073b32219b91b2c0f872dfabaa15226fc6` on stacked base `fe9caec106f915d7ff309868c64cccf1bf8bceb4`, adding the separate non-authorizing HR disposition request boundary. Its focused suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head dedicated contract Check is terminal successful, Devin Review is successful, and CodeRabbit is successful only because review is skipped for the stacked base branch. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=CLEAN`; parent #76 remains unmerged, so no parent/child evidence transfers. -- **PR #78** remains open/non-draft at exact head `c07211cfbc678b6e02d373bca9c3015673983c71` for reproducible release-candidate source, SBOM, and unsigned provenance evidence. The pinned-runtime Node harness passes with CPython 3.14.7, producing byte-identical archive/SBOM/provenance artifacts across isolated builds; compileall and diff checks pass. Its exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review and CodeRabbit are successful, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the unsigned evidence is active-PR truth only and does not authorize a release. -- **PR #79** remains open/non-draft at exact head `3f8a2826396aceb51fb78e14bf12dde713f99b0c` for the hardened Kubernetes People API reference deployment. Its local Kubernetes contract passes 8/8 and foundation validation passes 55/55; the exact-head hosted set has 37 successful and 8 skipped checks with no terminal failure, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, and PostgreSQL evidence where applicable. Devin Review is successful and all review threads are resolved, but no qualifying independent approval exists and GitHub reports `mergeable_state=blocked`; the sentinel image and cluster adaptation remain separate release/operations controls. -- **PR #80** remains open/non-draft at exact head `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702` for value-minimized candidate offer acceptance/decline evidence that grants no hire authority and does not mutate Keyverse. Its focused package suite passes 60 tests with exact 100% statement/branch coverage; Ruff, compileall, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure; Devin Review is successful and CodeRabbit is successful with a rate-limit description. All current review threads are resolved, `reviewDecision=REVIEW_REQUIRED`, no qualifying independent approval exists, and GitHub reports `mergeable_state=blocked`; Keyverse remains read-only and child #108 is dependency-first. -- **PR #81** remains open and Draft at exact head `e8bd6b28eb335d01c366869f044fbce0005d91dd` for the Orgmetra-owned, value-minimized Contextual Orchestrator draft-evidence boundary. Its focused suite passes 36 tests with exact 100% statement/branch coverage; compileall, Ruff, and diff checks pass. The exact-head hosted set has 35 successful and 8 skipped checks with no terminal failure or in-progress run, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, Foundation, and package-quality evidence where applicable. Devin Review and CodeRabbit are successful; all current review threads are resolved, but no qualifying independent approval exists, `reviewDecision=REVIEW_REQUIRED`, and GitHub reports `mergeStateStatus=BLOCKED`. Its Draft state is intentionally not changed because a separate lifecycle writer owns that transition; model output remains `untrusted_draft`, requires human review, and carries no employment-decision authority. -- **PR #82** remains open/non-draft at exact head `3d6d4791358b82f2840dd0dd201a0407e6e88a6e`, stacked on PR #51 (`docs/protected-truth-refresh`). Its pinned PostgreSQL retry-policy contract passes, as do foundation validation (61/61), shell syntax, and diff checks. The PR base metadata is `b25ac55556e8868da42c0f4c1466bc04cee95dfb`, while the moved base branch tip is `aa33f8f9f2a7c0a72c91947e3edac90334bcaabf`; GitHub reports `mergeStateStatus=DIRTY`/conflicting and exact-head hosted Checks are absent because the child targets the stacked branch. No qualifying independent approval exists and all current review threads are resolved; do not rebase by force-push, transfer parent evidence, or merge before #51 integrates and #82 is retargeted/revalidated against fresh `develop`. -- **PR #83** remains open/non-draft at exact head `c340e7599f147b25fab4c94cd2042a96d6128235` for the Orgmetra-owned Semantic Data Portal ontology evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, and diff checks. The actor trust boundary now requires opaque canonical `actor:` UUIDv4 correlations; human-readable actor handles are rejected. The exact-head hosted snapshot has 11 successful, 6 skipped, 1 terminal `dependency-review` failure, and 29 in progress; Devin Review and CodeRabbit are pending/analyzing. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #85** remains open/non-draft at exact head `199e37799802815fbc82aecfdad6ff8d0970a62d` for the Orgmetra-owned psychometrics result evidence boundary. Its focused suite passes 35 tests with exact 100% statement/branch coverage (156/30), compileall, Ruff, diff checks, and CodeGraph reindexing. The integrity boundary now emits the exact payload and canonical JSON snapshot that passed creation-seal verification, with regressions for both export APIs. The exact-head hosted snapshot has 3 successful, 6 skipped, 1 terminal `dependency-review` failure, and 25 queued/in progress; Devin is pending analysis and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #86** remains open/non-draft at exact head `be0b787301f3daae54994ddb064c403d07c61a01` for the Orgmetra-owned, non-executing Keyverse identity deprovision review boundary. Its focused suite passes 25 tests with exact 100% statement/branch coverage (112/20), compileall, Ruff, and diff checks; pytest source discovery is configured without a manual `PYTHONPATH` override. The current head corrects the doctoring reference to the actual completed review date `2026-08-22 UTC`. The exact-head hosted snapshot has 6 skipped and 27 queued/in progress checks, with no terminal success or failure yet; Devin and CodeRabbit are pending. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #87** remains open/non-draft at exact head `0c4fe88ed0e0b1a117e1adeebe6e5aa1975e87a7` for database-authored candidate-to-worker conversion system-recorded time. Its repository and foundation validation, shell syntax, diff checks, and pinned PostgreSQL 16.14 contract pass; the contract rejects caller backdating, verifies server-authored transaction time and UTC event serialization, and preserves correction history. The exact-head hosted snapshot is terminal with 37 successful, 8 skipped, and 2 failures (`opencode-review`, `strix`); Devin is successful and CodeRabbit is rate-limited. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #88** remains open/non-draft at exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd` for bounded pre-authentication Job Analysis HTTP request metadata. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; paths are capped at 256 characters and headers at 64 frames/16 KiB before authentication. The exact-head hosted snapshot is terminal with 36 successful, 8 skipped, and no failures or in-progress runs, including terminal GREEN OpenCode, Noema, Strix, SAST, dependency, security, recovery, PostgreSQL, and package-quality evidence where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #90** remains open/non-draft at exact head `3d3fd3c57b76855c8e394eb7067af30c3063c13d` for privacy-safe People HTTP operational telemetry. Its service suite passes 72 tests with exact 100% statement/branch coverage (603/214), compileall, Ruff, and diff checks; the middleware emits only bounded method/route/status/duration/error dimensions and degrades without changing HR request behavior. The exact-head hosted snapshot has 33 successful, 6 skipped, and 1 terminal `opencode-review` failure with no in-progress run; Noema, SAST, dependency, security, recovery, PostgreSQL, and People API quality checks are successful where applicable. Devin is successful and CodeRabbit is rate-limited; all current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #91** remains open/non-draft at exact head `0b050dbcfbebf09f510d9e4b92409fda49f8d108` for value-minimized, non-authorizing HR data-rights request evidence. Its installed-package-equivalent suite passes 72 tests with exact 100% statement/branch coverage, and the workflow compile, package, and clean-checkout boundaries were verified; the process-local registry rejects conflicting live reissuance while durable uniqueness remains an authoritative persistence concern. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #92** remains open/non-draft at exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487` for value-minimized, non-authorizing performance goal-plan activation evidence. Its package suite passes 40 tests with exact 100% statement/branch coverage; the workflow triggers on its ADR, builds and tests the isolated wheel artifact, and the off-lifecycle export path fails closed with the governed `ValueError`. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`opencode-review`, `noema-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #93** remains open/non-draft at exact head `951167e58a5a1f97254c290ae77354e5a0faeaee` for value-minimized, non-authorizing performance-context evidence. Its package suite passes 46 tests with exact 100% statement/branch coverage; the workflow uses a reviewed build lock, installs the wheel without a misleading test extra, triggers on its ADR, and isolates per-test packet references while preserving intentional conflict tests. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts; CodeRabbit and Devin are successful. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #94** remains open/non-draft at exact head `2ff1262b976029e447dc736e6472eebbac30a7f5` for the bitemporal, tenant-scoped Position reporting hierarchy. The full HRIS-kernel suite passes 187 tests with exact 100% statement/branch coverage; the public-root export, UTC system-time normalization, staffable endpoint validation, single-manager invariant, and cycle rejection are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #95** remains open/non-draft at exact head `adf055d79d188ba18d06ecf80dc1117858c987f4` for value-minimized, human-review-only Position reporting-change evidence. Its package suite passes 45 tests with exact 100% statement/branch coverage; the reviewed integer-ordering adversary, canonical export, and process-local issuance checks are covered. The exact-head hosted snapshot has 63 successful and 15 skipped checks with no terminal failure and 2 non-terminal contexts; Devin and Code Quality are successful. All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #96** remains open/non-draft at exact head `6a8454ff8ad0c52790b4a72f1fde67f61cc11358` for value-minimized, human-review-only Organization hierarchy-change evidence. Its package suite passes 49 tests with exact 100% statement/branch coverage; issuance rejects future system-recorded timestamps, and tenant/reference, root-transition, self-parent, chronology, and canonical-export cases are covered. The exact-head hosted snapshot has 37 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are successful. All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #97** remains open/non-draft at exact head `b13846dabe600cf78cbdd1409499c3726181bf47` for bitemporal, tenant-scoped Position vacancy evidence. Its full HRIS-kernel suite passes 194 tests with exact 100% statement/branch coverage; canonical four-decimal FTE/ratio validation, duplicate visible Assignment rejection, position coverage, seat capacity, cutoff normalization, and fail-closed vacancy semantics are covered. The exact-head hosted snapshot has 38 successful, 8 skipped, and 2 terminal failures (`opencode-review`, `strix`) with 2 non-terminal contexts; CodeRabbit and Devin are present, and all 9 current review threads are resolved. No qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #98** remains open/non-draft at exact head `6a9f3e214079e2b46bba9776a862f194b899f0e4` for value-minimized, non-authorizing HR document-record evidence. Its focused package suite passes 23 tests with exact 100% statement/branch coverage; artifact-reference-only storage, provenance/retention digests, UTC received/recorded time ordering, immutable issuance sealing, and employment-decision non-authority are covered. The exact-head hosted snapshot has 36 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #99** remains Draft at exact head `1b0f4834c5152131815f1d02073f29d47c1c6c97` for employment-scoped bitemporal base-compensation schema evidence. Its core migration contract and review-regression PostgreSQL scripts both pass against the pinned PostgreSQL 16.14 image; Foundation validation passes 55 tests and `git diff --check` passes. The exact-head hosted rollup has 35 successful, 6 skipped, and 3 terminal failures (`noema-review`, `dependency-review`, `opencode-review`) with 1 non-terminal context (`CodeRabbit`); the dedicated Employment Compensation Core Quality run `33272503669` is terminal GREEN. The pre-fix run `33176719158` failed before creating a job and is stale evidence; no prior cancelled/failed Strix evidence transfers to this head. All 20 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. -- **PR #101** remains Draft at exact head `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` for non-authorizing, human-reviewed Job-grade design evidence. Its focused package suite passes 60 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks. The exact-head hosted snapshot has 35 successful and 8 skipped checks with 2 non-terminal contexts and no terminal failure; all 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. Draft state remains authoritative. -- **PR #102** remains open/non-draft at exact head `5344d77a9bd1058fee9fcecb7c6aaebc39ced995` for purpose-bound, non-authorizing audit-evidence review. Its focused package suite passes 68 tests with exact 100% statement/branch coverage, compile, Ruff, and diff checks; authorization-before-read, detached callback snapshots, tenant/time/limit bounds, canonical CloudEvents verification, digest sealing, and strict ordering are covered. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts. All 8 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #103** remains open/non-draft at exact head `267d9d5bc58d2e951fe3e428876682c8a5e1daa5` for human-reviewed, non-authorizing Employment work-capacity change evidence. Its focused package suite passes 36 tests with exact 100% statement/branch coverage (170/46); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet keeps Employment/Assignment/compensation/payroll/leave/scheduling mutation outside its boundary, requires exact four-decimal capacity ratios and distinct actor UUIDv4 references, and owns system-recorded UTC issuance time. The exact-head hosted snapshot has 32 successful, 8 skipped, and 3 terminal failures (`noema-review`, `strix`, `opencode-review`) with 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 3 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #104** remains open/non-draft at exact head `14eab4eb21924f85c9d4eeef325ca37bfff37de3` for human-reviewed, non-authorizing Job qualification-rule evidence. Its focused package suite passes 55 tests with exact 100% statement/branch coverage (165/38); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet binds Job/Job Analysis provenance and reviewed rule categories while never evaluating candidates, rejecting applicants, mutating Job truth, or authorizing employment decisions. The exact-head hosted snapshot has 35 successful and 8 skipped checks with no terminal failure and 2 non-terminal contexts (`CodeRabbit`, `Devin Review`). All 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #105** remains Draft at exact head `e9e4731b7bcd41db0e88186ae07e38742c0e220c`, stacked on the unmerged Job qualification-rule review lane with base tip `d92ac4cb798b3bd32b632c0ab677c03f944070e4`. Its real PostgreSQL 16.14 full-chain persistence contract passes, as do Foundation validation (55/55), shellcheck, actionlint, and diff checks; the migration enforces tenant-scoped bitemporal rule history, immutable transaction-time intervals, reviewed Job Analysis scope, audit/outbox correlation, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. -- **PR #106** remains Draft at exact head `a367b4ea09f6abb4b6b8523c1e7726ee11bfc483`, stacked on the unmerged Position reporting hierarchy lane at recorded base tip `3f67182bb3065f2fc8fd974bfdd75a390d8a8fdc`; the tracked parent branch has advanced to `2ff1262b976029e447dc736e6472eebbac30a7f5`, so the stale-base distinction remains explicit. Its real PostgreSQL 16.14 persistence, immutable review/application audit binding, and concurrent cycle-prevention contracts all pass; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration enforces tenant-scoped bitemporal Position relationships, staffable endpoint coverage, same-tenant review/audit scope, actor separation, immutable closure, and RLS. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. -- **PR #107** remains Draft at exact head `78e67a0493c6b25210b0fcc4a8a6efddf5d339c7`, stacked on the unmerged Document Record Evidence lane with base tip `59b809bead617d9045357396df684991548bdc30`. Its real PostgreSQL 16.14 immutable document-metadata persistence contract passes; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration stores artifact/provenance references and digests only, binds the exact canonical evidence JSON, enforces PostgreSQL system time, immutability, RLS, and no direct Person/Employment/audit/outbox application-table foreign keys. Its exact-head hosted snapshot has 1 successful check and 1 non-terminal `CodeRabbit` context; all 4 current review threads are resolved, no qualifying independent approval exists, and no parent/child evidence transfers. GitHub reports `mergeStateStatus=CLEAN`, but Draft state and the unmerged parent keep it non-authorized. -- **PR #108** remains Draft at exact head `d465d1cd34ec3eeaee863535a7a4142cd018e06b`, stacked on candidate-response parent #80 at the stale recorded base tip `5070f34cd13814f09d74162347f837cb34d76a57`; current parent #80 has advanced to `a72463a431ee5fb90cc7956a8e2bdd1df4bcf702`. Its focused offer-to-hire suite passes 12 tests with exact 100% statement/branch coverage (106/30); compileall, Ruff, actionlint, diff checks, candidate-response package tests (65), and Foundation validation (55/55) pass. The bridge validates accepted-response integrity, authorizes the exact selection decision before protected candidate/offer resolution, requires exact authoritative scope/evidence binding, and delegates mutation only through the existing confirmed-hire path. Its exact-head hosted set has 1 successful dedicated check plus successful Draft-skipped CodeRabbit, all 2 review threads are resolved, and no qualifying independent approval exists. It remains dependency-first active-PR truth only; no parent or stale-base evidence transfers. -- **PR #109** remains Draft at exact head `19e1186ef8111ba6b039c7021f43d4d345275f58`, stacked on Job-grade design parent #101 at base tip `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2`. Its real PostgreSQL 16.14 persistence contract passes after the contract runner was corrected to honor the configured database connection; Foundation validation (55/55), shellcheck, actionlint, and diff checks pass. The migration preserves tenant-scoped bitemporal Job-grade history, immutable audit/outbox correlation, and RLS isolation. Its exact-head hosted set has 1 successful dedicated check and no pending contexts; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. -- **PR #110** remains Draft at exact head `16aaac791bc390c4d73c178bc14f09b7d17ab55f`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its full People API suite passes 159 tests with exact 100% statement/branch coverage (1498/500); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. Vacancy-fill orchestration now revalidates command values at the runtime trust boundary and exposes the public API without authorizing employment decisions. Its exact-head hosted set has 33 successful and 7 skipped checks, 3 terminal failures (`opencode-review`, `dependency-review`, `noema-review`), and 1 pending `strix`; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #111** remains Draft at exact head `03f3f6de674ee07cf33b9d2a75f58a8d210d7ed8`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its focused Position lifecycle-review suite passes 36 tests with exact 100% statement/branch coverage (142/40); compileall, Ruff, actionlint, diff checks, and Foundation validation (55/55) pass. The packet remains human-review evidence and does not mutate Position truth or authorize employment decisions. Its exact-head hosted set has 35 successful and 8 skipped checks with no pending or terminal failure; all 8 current review threads are resolved, no qualifying independent approval exists, and Draft state plus `reviewDecision=REVIEW_REQUIRED` keep it non-authorized. -- **PR #112** remains Draft at exact head `1889851f9f8c7e0528e047ec53f33f947be6dd88`, stacked on Position lifecycle review at recorded base tip `b9e85a1b8eb92f168fd261aa150a6204490c8023`. Its three real PostgreSQL 16.14 lifecycle contracts pass: application persistence, transition validation, and fresh Position/Assignment snapshot integrity; Foundation validation (55/55), shellcheck, actionlint, diff checks, and manifest verification pass. The database boundary accepts only canonical human-reviewed transitions with fresh tenant-scoped snapshots, preserves bitemporal Position truth, and binds immutable audit/outbox evidence while revoking default PUBLIC execution of the high-impact function. Its exact-head hosted set has 1 successful dedicated check and no pending context; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. -- **PR #113** remains Draft at exact head `9e53a80f2f91616253e076cfff92d659a6f1cb08`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects reserved Nil/Max UUID sentinels at the Employment absence domain boundary; the HRIS kernel suite passes 204 tests with exact 100% statement/branch coverage, and compileall, Ruff, npm validation, and diff checks pass. Its exact-head hosted set currently has 25 successful and 6 skipped checks, 2 terminal failures (`dependency-review`, `noema-review`), and 9 pending checks; all 5 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`reviewDecision=REVIEW_REQUIRED`. -- **PR #114** remains Draft at exact head `d99ad8b7c5e0cee2e6ae73bb2e06ab702b43cfc0`, stacked on parent #113's recorded base tip `3da7ad076f977a3ccd9e130a58786c9d26763a16`; the parent branch now points to `9e53a80f2f91616253e076cfff92d659a6f1cb08`, so the stale-base distinction remains explicit. Its fresh PostgreSQL 16.14 persistence contract passes, as do Foundation validation (55/55), ShellCheck, bash syntax, actionlint, diff checks, and manifest verification. The migration adds separate tenant-qualified bitemporal absence identity/version relations, full active/leave coverage validation for confirmed facts, post-coverage cancellation correction, serialized overlap rejection, immutable system-time closure, forced RLS, and opaque audit/outbox correlations without querying foreign service tables. Its exact-head hosted set has 1 successful dedicated check and no pending context; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/stacked-parent state keep it non-authorized. After #113 integrates, retarget this child to fresh `develop`, reconcile migration ordering, and rerun all applicable gates on the resulting exact head. -- **PR #115** remains Draft at exact head `de2b0aa5e6cd226815b25f7e83a8130c6f124a6a`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The read-only hourly freshness audit now compares recorded open PR/issue counts with complete live queues, fails closed on empty or malformed `develop` evidence, and explicitly checks out the default branch on manual dispatch; its 10 regression tests, Ruff, compileall, Foundation validation (55/55), actionlint, and diff checks pass. Its exact-head hosted set has 6 skipped completed checks and 26 pending checks with no terminal failure; all 7 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. -- **PR #116** remains Draft at exact head `5c19fdc708b765f7ee2942eee7b455ba5bbcf289`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The HR document retrieval boundary now performs a final authorization-freshness check after immutable audit append and before byte release; package tests pass 29 tests with exact 100% statement/branch coverage (284/72), alongside Foundation validation (55/55), Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 6 skipped completed checks and 27 pending checks with no terminal failure; all 5 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. -- **PR #117** remains Draft at exact head `394a3ac5644d2ab7e9a04fd118269d438dad3f46`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Review found no additional source defect; its model-draft workflow passes 35 package tests with exact 100% statement/branch coverage (251/76), plus docstring, Ruff, compileall, actionlint, and diff checks. Its exact-head hosted set has 33 successful and 8 skipped checks, 2 terminal failures (`opencode-review`, `strix`), and no pending checks; all 4 current review threads are resolved, no qualifying independent approval exists, and Draft/`mergeStateStatus=BLOCKED` keep it non-authorized. -- **PR #118** is non-draft at exact head `beece4d2ffcd20258bf0e015477dd45448ed05d0`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. The valid source repair rejects Git's null OID so readiness evidence cannot bind to a nonexistent candidate; its package suite passes 25 tests with exact 100% statement/branch coverage (148/38), plus docstring, compileall, Ruff, actionlint, diff, and Foundation validation (55/55). Its exact-head hosted snapshot currently has 6 skipped completed checks and 27 pending checks with no terminal failure; all 4 current review threads are resolved, no qualifying independent approval exists, and `reviewDecision=REVIEW_REQUIRED`/`mergeStateStatus=BLOCKED` keep it non-authorized. The packet remains non-authorizing and cannot tag, sign, publish, deploy, or release. -- **PR #119** remains open/non-draft at exact head `f7c83600471ae0363d9b4a2b2533aedba01166b1`, stacked on parent #96 at recorded base `b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd`; parent #96 has advanced to `6a8454ff8ad0c52790b4a72f1fde67f61cc11358`, so GitHub reports `mergeStateStatus=DIRTY`/`CONFLICTING`. The valid repair hardens typed/null-safe review validation, tenant/unit-qualified predecessor and deferred successor bindings, reviewed-column integrity, and cycle detection across future effective-time boundaries. The review package passes 48 tests with exact 100% statement/branch coverage (182/60); real PostgreSQL 16.14 application and 0028 concurrency contracts, Foundation validation (55/55), actionlint, bash syntax, CodeGraph sync, and diff checks pass. Exact-head GitHub check-runs currently total 0, no qualifying approval exists, 16 of 17 review threads are resolved, and the caller-controlled tenant-context security thread remains unresolved. This child is not merge-authorized and must be retargeted/revalidated only after #96 integrates. -- **PR #120** remains Draft at exact head `aadf4916ee64820b4f5c6a78430c9fec675e2078`, based on `feat/governed-hr-data-export-control` at `282ff0966add47a80a2edd76f84c4c65a868fedb`; parent #75 is still Draft and unintegrated at exact head `968111f88d59f340f78afd5f6aea2291221bffa1`. Its focused HR export execution suite passes 129 tests with exact 100% statement/branch coverage (497/114), covering authorization-expiry races, immutable audit-before-egress, exact artifact binding, and reconciliation-only at-most-once delivery after ambiguous publication. The exact-head hosted set contains one terminal successful check, `HR data export contract and 100% coverage`; no parent or predecessor evidence transfers. All 6 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=DIRTY`/`mergeable=false` with `reviewDecision=null`; it remains dependency-first active-PR truth only and must be retargeted/revalidated after #75 integrates. -- **PR #121** remains open/non-draft at exact head `c7fba99a3b86cae612083242091fc6fd0b426ebb`, based on `feat/performance-goal-plan-evidence` at recorded base `141574958df2238d107121138c1ffb5f854126cc`; parent #92 is unintegrated at current exact head `d12995adb9e795e9894e939aa60ab7b1a0a2c487`. The valid repair separates future-time admission from sealed receipt serialization so issued activation evidence remains readable after wall-clock rollback; its focused suite passes 61 tests with exact 100% statement/branch coverage (321/76), plus compileall, Ruff, diff, and CodeGraph synchronization. The exact-head hosted set has one terminal successful dedicated check, all 4 current review threads are resolved, and no qualifying independent approval exists. GitHub reports `mergeStateStatus=CLEAN`/`mergeable=true` with `reviewDecision=null`; it remains stack-local active-PR truth only and must be retargeted/revalidated after #92 integrates. -- **PR #141** has exact current head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33` after enforcing same-tenant employing-organization scope in both Employment and confirmed-hire writes, with matching tenant-isolation regression coverage. Its exact-head hosted suite is terminal with 40 successful and 8 skipped checks plus 2 failures: `opencode-review` and `strix`; all current review threads are resolved and no qualifying independent approval exists. It remains active-PR truth and is not merge-authorized; no predecessor evidence is transferred. -- **PR #66** remains the unmerged normalized-application dependency at exact head `04c60a6d485c1af32973959c37c9133ae928f59b`. Its Foundation, candidate-application, PostgreSQL integrity, SAST, dependency, and security checks are terminal with 37 successful and 8 skipped checks; exact-head `opencode-review` is terminal FAILURE for missing a current-head verdict, and `strix` is terminal FAILURE after three contextual-orchestrator backend HTTP 500 responses with no authoritative structured report. All current review threads are resolved and no qualifying independent approval exists. Its source is active-PR truth only. -- **PR #122** remains open/non-draft at exact head `60ad07a02c766b54673d7cbbdd7e7bdcd08d129e`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. Its target-side portability contract passes from the service directories with 69 job-analysis API tests and 146 People API tests, both at exact 100% statement/branch coverage; compileall and diff checks pass. The exact-head hosted set is terminal with 37 successful and 8 skipped checks, including coverage, SAST, dependency, security, OpenCode, Noema, Strix, PostgreSQL, recovery, and Foundation evidence where applicable. The one current review thread is resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains target-side active-PR truth only and does not repair the central coverage pipeline. -- **PR #123** remains open/non-draft at exact head `740cbec81ab43464cc4ae9c7a6f34b523426f9c1`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after branch-bound manifest provenance was resealed. The affected candidate-evidence, offer-approval, requisition-review, HRIS-kernel, and People API suites pass locally with 75, 84, 61, 171, and 146 tests respectively, all at exact 100% statement/branch coverage; repository validation and Foundation validation (55/55) pass. Its exact-head hosted set has 39 successful, 2 failed, and 8 skipped raw check-runs; latest-by-name evidence is 39 successful, 2 skipped, and 2 terminal failures (`opencode-review` and `strix`) with no current-head OpenCode verdict or authoritative Strix report. All current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`; it remains active-PR truth only. -- **PR #124** remains open/non-draft at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`, targeting `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`, after the acceleration doctoring note was sealed into both required-file lists and the manifest. Its ADR contract passes 6 tests; Foundation validation (55/55), actionlint, and diff checks pass. The exact-head hosted set has 35 successful, 8 skipped, and 2 terminal failures (`opencode-review` and `strix`); all 13 current review threads are resolved, no qualifying independent approval exists, and GitHub reports `mergeStateStatus=BLOCKED`/`mergeable=true` with `reviewDecision=REVIEW_REQUIRED`. It remains active-PR truth only and does not authorize accelerator implementation, promotion, release, or deployment. -- **PR #125** remains open/Draft at exact head `ea97b791fc3d27d786d2bd81c19b994dcc872208`, targeting `feat/performance-goal-plan-activation` at `a49df8a61baf406323f73e2e1a5f4fdd5d9c239f`, as a dependency-first child of #121. Exact-head local PostgreSQL 16.14 persistence tests pass, including the search-path shadowing regression; Foundation validation is 55/55 and shellcheck/diff checks pass. Its one exact-head hosted persistence check is terminal GREEN ([run 33281305828 / job 99176826069](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33281305828/job/99176826069)); no qualifying independent approval exists, all current review threads are resolved, and GraphQL reports `MERGEABLE`/`CLEAN` while it remains Draft. It is active-PR/stack-local truth only and must retarget/revalidate after #121 integrates. -- **PR #126** remains open/Draft at exact head `c13b2d35d135abf2e33447be217014cd5588d6cb`, stacked on PR #118 at `eb529093b44be17bb282d3fd5c6c592d66f111af`. Its release-authorization package passes 36 tests with exact 100% statement/branch coverage (226/58), plus isolated package-install, docstring, compile, Ruff, and diff checks; the dedicated exact-head check is terminal GREEN. No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged parent keep it non-authorized. It must retarget/revalidate on fresh `develop` after #118 integrates; no release/tag/publication authority is shipped. -- **PR #128** remains open/Draft at exact head `44440c9791c271715924de6d80e189bb8c0df049`, targeting PR #103 at `645d2f3b2db10e2bdfbe60422837a5986d8f39f8`. Its Employment work-capacity persistence migrations pass three real PostgreSQL regressions for resolution/RLS/history, retroactive-chain protection, and canonical review evidence; Foundation validation is 55/55, actionlint and shellcheck pass, and the exact-head persistence check is terminal GREEN ([run 33282710368 / job 99180472116](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33282710368/job/99180472116)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged review parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #103 integrates; no authoritative capacity truth is shipped on protected `develop`. -- **PR #129** remains open/Draft at exact head `4c377a35055e126a5e2435ec36bd9ac1e593456e`, targeting PR #46 at `96fe0b69e8e1bc3caa0fa206146a87c6e5027746`. Its approval-boundary package passes 137 tests with exact 100% statement/branch coverage (388/86), plus compileall, Ruff, and diff checks; the exact-head focused workflow is terminal GREEN ([run 33166590078 / job 98833356045](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33166590078/job/98833356045)). The receipt remains human-approval evidence only and is fixed to `not_authorized_to_apply` and `not_authorized_to_execute`; no reviews, threads, or qualifying independent approval exist. GitHub reports REST `mergeable=false`/`dirty` and GraphQL `DIRTY`; the unmerged parent #46 keeps this child dependency-first and non-authorizing. It must remain Draft and be retargeted/revalidated on fresh `develop` only after #46 integrates; no Employment separation mutation or downstream owner execution is shipped. -- **PR #130** remains open/Draft at exact head `c92749cf5889a39de1ba8036742f96fd3451f459`, targeting PR #53 at `016f27e13f7a47cb78a1c936aa533cc8daa2c66c`. Its protected-read interaction contract passes 5 Node tests with exact 100% line/branch/function coverage, plus syntax and diff checks; the exact-head focused workflow is terminal GREEN ([run 33245740900 / job 99082759734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33245740900/job/99082759734)). It fails closed on prototype-inherited state names, makes loading busy/disabled, keeps loaded evidence read-only, and emits concrete denial/error next actions without protected values. No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but Draft and the unmerged parent keep it dependency-first and non-authorizing. It must retarget/revalidate on fresh `develop` after #53 integrates; no protected HR read API or employment-decision authority is shipped. -- **PR #131** remains open/Draft at exact head `9f2c36dec6de64f6d7de98fb653c4e7336eed0d2`; its recorded base SHA is the predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf`, while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. Its one-time export interaction contract passes 7 Node tests with exact 100% line/branch/function coverage, syntax/diff checks, and the CSS-import repair; the exact-head focused workflow is terminal GREEN ([run 33283287138 / job 99181985091](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33283287138/job/99181985091)). No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but the stale dependency base, Draft state, and unmerged #53 → #130 stack keep it non-authorizing. It must be reconciled against current #130 and retargeted/revalidated on fresh `develop` after the dependency stack integrates; no export authorization or durable one-time delivery is shipped. -- **PR #132** remains open/Draft at exact head `97fb51167a6883d7f6191c53eda48863842fd14e`; its recorded base SHA is the predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf`, while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. Its document-retrieval interaction contract passes 6 Node tests with exact 100% line/branch/function coverage, syntax/diff checks, and exact-state/prototype-inheritance fail-closed regressions; the exact-head focused workflow is terminal GREEN ([run 33245126654 / job 99081169269](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33245126654/job/99081169269)). No reviews, threads, or qualifying independent approval exist; GitHub reports `CLEAN`/`mergeable=true`, but the stale dependency base, Draft state, and unmerged #53 → #130 stack keep it non-authorizing. It must be reconciled against current #130 and retargeted/revalidated on fresh `develop` after the dependency stack integrates; no document retrieval authorization, export authority, or employment-decision authority is shipped. -- **PR #127** remains open/Draft at exact head `931dfe98db23ba081c420ddeb0b6a267f3c9cb2f`, targeting PR #126 at `c13b2d35d135abf2e33447be217014cd5588d6cb`. Its release-publication package passes 40 tests with exact 100% statement/branch coverage (225/50), plus compileall, beginner-readable docstrings, Ruff, public-import, and diff checks; the exact-head dedicated check is terminal GREEN ([run 33211244727 / job 98984697272](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33211244727/job/98984697272)). No review threads or qualifying independent approval exist, and GraphQL reports `MERGEABLE`/`CLEAN` while Draft and the unmerged authorization parent keep it non-authorizing. It must retarget/revalidate on fresh `develop` after #126 integrates; no tag, release, deployment, or publication authority is shipped. -- **PR #151** remains Draft at exact head `a18bb75254af23e5658c4672e063b04bd98cc3de`. Its standalone external-delivery-receipt package passes 49 local tests with exact 100% statement/branch coverage and the dedicated hosted contract check is GREEN; the package remains untrusted evidence only and does not mutate or persist outbox delivery state. Its exact-head hosted suite has 31 successful, 4 failed, and 8 skipped checks; `noema-review`, `opencode-review`, `dependency-review`, and `strix` are terminal FAILURE, and no qualifying independent approval exists, so it remains active-PR truth only. -- **PR #152** remains Draft at exact head `44282cdb61269937f55bd1a69a106e948130d844`, targeting protected `develop` at `9e3e4847510e1e612b48474ba42b177b8ed824df`. It adds a purpose-bound Position-history read boundary that authorizes before retrieval, preserves separate business/system time, revalidates immutable persistence evidence, and keeps absent business ends semantically unbounded; the real `date.max` overlap regression was reproduced at test-only head `af8d0b9b88c50f17c87eb8ecf1eea29918835dce` and repaired at `955956f838c467c06c25b63127b7c6e976dea812`. The exact current local People API suite passes 158 tests and 259 subtests with 1,542 statements and 504 branches at 100%, plus repository validation (55/55), compileall, Ruff, and diff checks. Its dedicated exact-head People API check is GREEN ([run 33268072551 / job 99141581712](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33268072551/job/99141581712)); the exact-head hosted snapshot has 31 successful, 4 failed, and 8 skipped checks, with `dependency-review`, `opencode-review`, `noema-review`, and `strix` terminal FAILURE and no authoritative central verdicts. No formal review, current-head qualifying independent approval, or review thread exists; GitHub reports `REVIEW_REQUIRED`/`BLOCKED`, so it remains active-PR truth only and does not ship Position-history authority on protected `develop`. -- **PR #153** is a Draft child of #152 at exact head `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`, recorded against parent #152 head `44282cdb61269937f55bd1a69a106e948130d844`. It supplies the canonical PostgreSQL adapter for #152's Position-history port, using a read-only tenant-scoped transaction, explicit Position-anchor/version predicates, UTC projection, and untrusted DB-API row revalidation; it adds no migration, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 185 tests and 259 subtests with 1,606 statements and 528 branches at 100%, plus repository validation (55/55), compileall, Ruff, actionlint, CodeGraph sync, and diff checks; an isolated PostgreSQL 16.14 RLS/UTC/bitemporal/typed-lineage contract also passed. Its dedicated exact-head check is terminal GREEN ([run 33287205030 / job 99192355928](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33287205030/job/99192355928)); it has no reviews, threads, or qualifying independent approval. GitHub reports `CLEAN` only for the stacked child, so parent integration, fresh protected-`develop` retargeting, all applicable central gates, and independent review remain required before any authorization or merge. -- **PR #154** is a Draft child of #153 at exact head `eba070206b881cc0f7193fe684cf4cb6f8c2d54b`, based on #153 at `a4b9e94639ef251e4e1c7db8f8205815fddfdb1e`. It exposes the purpose-bound, bitemporal Position-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized fields, and adds no write, cross-service query, Person/Employment/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 197 tests and 259 subtests with 1,728 statements and 558 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33288307945 / job 99195361332](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33288307945/job/99195361332)); CodeRabbit reports only `Review skipped: draft pull request`, with no formal reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` for the stacked child, but Draft state and unmerged parent #153 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. -- **PR #155** is a Draft child of #149 at exact head `094466db22a707185fd2de06a1da7c228d7d6c3a`, based on #149 at `44c83128701f1985f8566b39cbf837c7b20f0111`. It exposes the purpose-bound, bitemporal Employment-history service through a separate read-only ASGI route, validates operational UUIDs/UTC `known_at`/purpose/fields before authentication, reuses the existing transport and auth parser, returns only authorized `entries[].fields`, and adds no write, cross-service query, Position/Assignment expansion, or employment-decision authority. The exact current local People API suite passes 172 tests with 1,646 statements and 536 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, and diff checks pass. Its dedicated exact-head HTTP check is terminal GREEN ([run 33289241743 / job 99197835852](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33289241743/job/99197835852)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent #149 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. -- **PR #156** is a Draft child of #155 at exact head `1e0c5115d19b71a6bab64789c4e1953855b27683`, based on #155 at `094466db22a707185fd2de06a1da7c228d7d6c3a`. It supplies the canonical PostgreSQL adapter for the existing Employment-history read port, using exact operational tenant/Person/UTC validation, a read-only tenant-context-bound transaction, explicit bitemporal Employment/Person predicates, UTC projection, untrusted DB-API row revalidation, and immutable typed results; it adds no migration, field authorization, mutation, cross-service SQL, disclosure authority, or employment decision. The exact current local People API suite passes 199 tests with 1,710 statements and 560 branches at 100%; `npm run validate`, compileall, Ruff, actionlint, CodeGraph sync, diff checks, and an isolated PostgreSQL 16.14 seeded-database validation pass. Its dedicated exact-head check is terminal GREEN ([run 33290057493 / job 99200008224](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33290057493/job/99200008224)); it has no reviews, threads, or qualifying independent approval. GitHub reports `MERGEABLE`/`CLEAN` only for the stacked child, but Draft state and unmerged parent chain #149 → #155 keep it non-authorizing; it must be retargeted/revalidated after parent integration and fresh protected-`develop` evidence. -- **PR #157** is a Draft child of #141 at exact head `3a904f63e96336e4ae8b52753dd91556d2c6d6c3`, based on #141 at `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`. It repairs the shipped V1 compatibility defect by retaining legacy terminated payloads, rejecting employer-less active/leave V1 requests with V2 migration guidance, and exposing employer-required V2 Employment and confirmed-hire contracts. The local People API suite passes 160 tests and 235 subtests with exact 100% statement/branch coverage; repository validation passes 57 tests, including OpenAPI V1/V2 assertions, and compileall, Ruff, actionlint, shellcheck, diff, and CodeGraph synchronization pass. Its only current check is CodeRabbit's draft skip; it has no reviews, threads, or qualifying independent approval, and inherits #141's unmerged parent and central OpenCode/Strix/approval blockers. No V2 truth is shipped until protected parent integration and fresh exact-head gates complete. -- **PR #158** is a Draft stacked child of #54 at exact head `065ef30b10f0fce9bd74ac442f307b41433aa58d`, based on parent exact head `6dc0f3da8f716d1b67d48336e0cdfb8f35a2770e`. It hardens malformed status-count handling, hostile Decimal FTE exponent handling, and cross-endpoint workforce-change export invariants, and refreshes the stale workforce ADR manifest entry. Its local HRIS kernel suite passes 230 tests with exact 100% statement/branch coverage; Foundation validation passes 55 Node tests, with compileall, Ruff, actionlint, diff, and CodeGraph synchronization passing. It has no reviews or qualifying independent approval; its hosted checks had only CodeRabbit's draft skip when created, and no evidence transfers until parent #54 integrates and all protected exact-head gates pass. -- **PR #149** remains exact head `44c83128701f1985f8566b39cbf837c7b20f0111` against protected `develop`, adding a purpose-bound Employment-history read contract with authorization-before-retrieval, bitemporal business/system-time validation, field minimization, deterministic ordering, structurally immutable Employment rows, and fail-closed persistence-boundary checks. The full People API suite passes locally with 160 tests and exact 100% statement/branch coverage; its exact-head hosted suite currently has 31 successful, 4 failed, and 8 skipped checks, with `opencode-review`, `dependency-review`, `noema-review`, and `strix` terminal FAILURE. It is Draft, has no qualifying independent approval, and is not merge-authorized; no PostgreSQL adapter or schema change is included in this slice. -- **PR #67** now has exact current head `ee5a56db3f64d972a08fab367fbed3f5005fa8f7`, synchronized with normalized-application base `04c60a6d485c1af32973959c37c9133ae928f59b`. Its candidate-withdrawal audit envelope binds identity-resolution reference/digest, withdrawal evidence digest, and evidence version in addition to the withdrawal reference, while generic audit envelopes retain their existing contract. It remains unmergeable as a dependency-first active PR because the parent is unmerged, `reviewDecision` is null, and no qualifying independent approval exists. -- **Required central Strix** remains an independent commercial merge gate. Authorized bounded fallback that completes authoritative structured analysis and terminal-successes the exact-head workflow is passing evidence (for example the existing #47/#48 positive canaries). Provider-chain exhaustion without an authoritative report remains non-passing (#42/#44/#45/#141 canaries) and belongs to the existing `.github#1327` owner path, not a leaf workaround. When operations rerun only failed jobs, `gh run rerun RUN_ID --failed` uses `POST /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs`; a full workflow rerun uses `/rerun` without `--failed`. Central gateway remediation `.github#1369` and follow-up `.github#1378` are merged into protected `main` at exact merge commits `aca94fbf75f5820e1e0b71e8deb938f9d4ca8f09` and `cb369942be4cd7783753be45552d758ebaf79870`; current central `main` is `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Active central PR **`.github#1395`** proposes the bounded scheduler fixes for exhausted stacked-review budget and target-repository default-branch classification; it is not merged and does not change protected-main truth. These central Checks are not transferable proof for Orgmetra leaf PRs, and future central changes remain protected by the same terminal Strix and independent-approval requirements. A required Strix workflow that fails to materialize at all is likewise non-passing and belongs to that central owner boundary rather than an Orgmetra-local shim. -- **PR #53 → #130 with workflow-specific children #131, #132, #134, #135, #136, #137, #138, #139, and #140** is the HR Workspace accessibility stack. #53 owns the evidence-centered workspace anchor. #130 owns the shared protected-read interaction semantics required by Figma Storybook Inventory node `1:64`: loading/disabled/error/read-only/focus behavior, `aria-busy`, duplicate-submit prevention, explicit read-only evidence, concrete next actions, existing design-token usage, and `:focus-visible`. Its focused evidence is stack-local only. - - **#131** owns one-time HR export delivery interaction: high-risk confirmation, duplicate-send prevention, read-only receipt, and reconciliation-only recovery after indeterminate delivery. - - **#132** owns purpose-bound HR document retrieval interaction: authorization/loading, bounded artifact verification, audit-before-release, read-only handoff, expiry/denial/failure states, and value-minimized next-action copy. - - **#134** owns Job-grade design-review interaction while retaining no compensation/promotion/assignment/candidate/employment-decision authority. At exact head `4d72fda8e3df41e6b4a9f81e3000895a446548b4`, its local focused contract passes 7 tests with exact 100% line/branch/function coverage, and its parent traceability is synchronized to current #130 head `c92749cf5889a39de1ba8036742f96fd3451f459` (the recorded child base remains the predecessor `b3b30058a79174000919d566fbbb1fdad80c62bf`). Its dedicated hosted check is terminal GREEN ([run 33283652359 / job 99182956631](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33283652359/job/99182956631)). It remains Draft dependency-first active-PR truth with no qualifying independent approval. - - **#135** owns Position lifecycle human-review interaction while retaining no Position mutation authority. At exact head `c06c0a2ab90a6cbd95c8c48f6cb00558e91b9684`, its recorded child base remains predecessor #130 commit `b3b30058a79174000919d566fbbb1fdad80c62bf` while current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`; its local focused contract passes 9 tests with exact 100% line/branch/function coverage and its dedicated hosted check is terminal GREEN. It remains Draft dependency-first active-PR truth with no qualifying independent approval. - - **#136** owns qualification-rule human-review interaction while neither evaluating/ranking/rejecting/advancing a candidate nor authorizing an employment decision. At exact head `dc4798a40ccfad8a77c2236d439dc20303e17930`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213758897 / job 98992701588](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213758897/job/98992701588)). Its recorded base is `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth and must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#137** owns Position reporting-line human-review interaction while #94/#95/#106/#133 remain the separate reporting snapshot/review/persistence/structural-evidence owners. At exact head `0538821f810db7344fdcc0cc46d7ef75def43c87`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33213066619 / job 98990527663](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33213066619/job/98990527663)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and never mutates reporting truth or authorizes an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#138** owns Employment work-capacity human-review interaction while #103/#128 remain the separate governed-review/persistence owners. At exact head `8781009710c53140cdecf1a74b34f1ef3e2e4e89`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212959615 / job 98990188612](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212959615/job/98990188612)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI records review semantics only and does not mutate Employment truth or authorize compensation, scheduling, leave, payroll, or an employment decision. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#139** owns reason-free Employment absence interaction while #113/#114 remain the separate bitemporal truth/persistence owners and #47 remains the separate leave-review owner. At exact head `ef79744ac5cccc791bc2890abe40c4dd0241ce0c`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212827583 / job 98989785049](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212827583/job/98989785049)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth, and the UI exposes only read-only absent/not-absent operational evidence, never a reason, attendance/fitness inference, leave/scheduling/compensation authority, or employment-decision authority. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#140** owns performance-goal human-review interaction while #92/#121/#125 remain the separate goal-plan review-evidence/activation/persistence owners. At exact head `a1e25e228e30d6deae17e7c8e153334261f1551a`, its local focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and the exact-head dedicated workflow is terminal GREEN ([run 33212498784 / job 98988751106](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33212498784/job/98988751106)). Its recorded base is #130 at `b3b30058a79174000919d566fbbb1fdad80c62bf`; current parent #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. No reviews, threads, or qualifying independent approval exist; it remains Draft dependency-first active-PR truth; the UI separates human review from activation, rating, compensation, and employment-decision authority and directs recorded review evidence to the separately governed activation boundary. It must be retargeted/revalidated on fresh `develop` after #130 integrates. - - **#141** owns the Employment-to-employing-legal-Organization bitemporal relation, exact-one legal-employer invariant, target-scoped authorization binding, audit/outbox correlation, and tenant/RLS persistence boundary. At exact head `8d12ee7cd05549a69c6debf5e0de0c5fc8668f33`, the real PostgreSQL 16.14 contract passes, the People API suite passes 155 tests with exact 100% statement/branch coverage, repository validation passes 56 tests, and compileall/Ruff/actionlint/shellcheck/diff checks pass. Its exact-head hosted snapshot has 40 successful and 8 skipped checks; required OpenCode and Strix are terminal failures without authoritative current-head verdicts, while all 36 review threads are resolved and no qualifying independent approval exists. It remains open/non-draft active-PR truth but `REVIEW_REQUIRED`/`BLOCKED`; no protected-default-branch employer truth is shipped until those central controls and protected review are satisfied. - - **#142 → #143** owns the Employee Profile bitemporal Assignment-history read and its presentation state boundary. #142 remains the backend read owner at exact head `d832006843111cc03751ec2bcd532df916bbc1e2`; its People API suite passes 159 tests and 256 subtests with exact 100% statement/branch coverage, repository validation passes 55 tests, and compileall/Ruff/diff checks pass. Its exact-head hosted snapshot is 33 successful and 8 skipped checks, with required OpenCode (run [33142287162 / job 98756469960](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287162/job/98756469960)) and Strix (run [33142287128 / job 98830775817](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33142287128/job/98830775817)) terminal failures; no submitted review, review thread, or qualifying independent approval exists, so it remains Draft and `REVIEW_REQUIRED`/`BLOCKED`. #143 is recorded on #130 base `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact child head `b7fdd493809545a7fd562fb6464b09c853739149`, its focused contract passes 6 tests at exact 100% line/branch/function coverage, repository validation passes 63 tests, and the dedicated hosted check is terminal GREEN ([run 33198343313 / job 98941173734](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198343313/job/98941173734)). It remains Draft with no qualifying independent approval and owns read-only loading/empty/denied/stale/error interaction only; it must be retargeted and revalidated on fresh `develop` after #130 and #142 integrate. Neither lane mutates Assignment truth or authorizes an employment decision. - - **#144** owns the Candidate Evidence timeline presentation boundary on top of merged governed Candidate Evidence intake (#41). Its recorded #130 base is `68896baa692ecf6fec8f21cfe5d981440be6071c`; current #130 head is `c92749cf5889a39de1ba8036742f96fd3451f459`. At exact head `5fd7683ed8cd4bfbe9b217b64e22c0368ae6f486`, its focused contract passes 6 tests with exact 100% line/branch/function coverage, repository validation passes 63 tests, and its dedicated hosted check is terminal GREEN ([run 33285252309 / job 99187216615](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285252309/job/99187216615)); the corrected action includes an explicit non-disabled hover state alongside visible focus treatment. It remains Draft and read-only with no qualifying independent approval; it does not evaluate, rank, reject, advance, or authorize an employment decision and must be retargeted/revalidated on fresh `develop` after #130 and #142 integrate. - - **#145 → #148 and #150** extend the same dependency-first surface set: #145 owns the Validation dashboard states at exact head `45accc8f2405013e4520e76fa70d01cbebf3c5cc`, with 6 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33285376235 / job 99187548564](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285376235/job/99187548564) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. #146 owns Hiring decision record states at exact head `bd2eaa1b9f6c901758fb5e151f9354ecd8829914`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285501789 / job 99187886526](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285501789/job/99187886526) terminal GREEN; #147 owns Job Architecture workspace states at exact head `26e81931ec031bd9ac72f0053839cae58c21f6bb`, with 6 focused tests at exact 100% line/branch/function coverage and dedicated hosted run [33285574607 / job 99188079934](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33285574607/job/99188079934) terminal GREEN; #148 owns the PostgreSQL Assignment-history read adapter at exact head `927f108505603b49112f467ddb06b5c21843ee2c`, with 184 People API tests, 256 subtests, exact 100% statement/branch coverage, and dedicated hosted run [33198401194 / job 98941396472](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33198401194/job/98941396472) terminal GREEN; its current parent/base is #142 at `d832006843111cc03751ec2bcd532df916bbc1e2`. #150 owns legal-employer history presentation states at exact head `cfab4d70c38eccd5fd528a2314d1346602c405f7`, with 5 focused tests at exact 100% line/branch/function coverage, 63 repository validation tests, and dedicated hosted run [33286022706 / job 99189253498](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33286022706/job/99189253498) terminal GREEN; its recorded base is #130 at `68896baa692ecf6fec8f21cfe5d981440be6071c` while current #130 is `c92749cf5889a39de1ba8036742f96fd3451f459`. All remain Draft active-PR truth; none replaces the parent backend or authorizes a high-impact employment decision. - All UI children remain Draft dependency-first active-PR truth. Do not open a competing shared protected-read, one-time-export, document-retrieval, Job-grade, Position-lifecycle, qualification-rule, Position-reporting, Employment-work-capacity, Employment-absence, or performance-goal interaction writer. -- **PR #75 → #120** owns governed HR export review and audited one-time egress. #120 fails closed on authorization-expiry races and ambiguous one-time publication through reconciliation-only recovery. #131 is presentation evidence only and does not inherit or replace #75/#120 authorization, audit, or at-most-once delivery semantics. -- **PR #92 → #121 → #125** is the performance-goal backend stack. #92 owns human-reviewed plan evidence; #121 owns authoritative activation; #125 owns durable activated goal-plan persistence with exact reviewed/activation evidence-to-normalized-truth binding and fixed function search paths. #140 is presentation/interaction only and must not substitute for those authority boundaries. Child checks and any clean/mergeable state are stack-local only. -- **PR #103 → #128** is the Employment work-capacity backend stack. #103 owns human review evidence; #128 owns dependency-first durable persistence. #138 is presentation/interaction only and must never substitute for authoritative backend validation or mutation. -- **PR #113 → #114** is the Employment absence truth/persistence stack. Absence remains reason-free authoritative HRIS evidence and is distinct from work-capacity, leave-review, payroll, scheduling, and employment-decision semantics. #139 is presentation/interaction only and must never infer a reason, attendance/fitness, or consequential authority. -- **PR #118 → #126 → #127** owns the release-control stack end to end without authorizing a release from predecessor evidence. #118 owns readiness review, #126 exact-revision authorization, and #127 reconciled at-most-once publication. No parent checks/reviews transfer and the repository release collection remains empty. -- **PR #116** owns purpose-bound HR document retrieval, including authorization freshness through artifact verification, bounded content verification, audit-before-release, and hash-bound installed-artifact evidence. #132 mirrors only the customer interaction sequence. -- **PR #117** owns Job-Analysis-specific model-assisted Task/FJA/KSAO draft workflow; raw model output remains untrusted draft evidence and distinct accountable human review is mandatory. -- **PR #124** owns hardware-acceleration ADR security hardening at exact head `e17c9cbf51d14f63e844c9137865d58521c40701`; its exact-head hosted suite has terminal `opencode-review` and `strix` FAILURE, no qualifying independent approval, and remains active-PR truth despite being Ready-for-review. -- **PR #133** owns Position span-of-control structural evidence. Exact head `139c715062c044fa3cb13967d94268069310c7b3` now includes the current `feat/position-reporting-hierarchy` base at `2ff1262b976029e447dc736e6472eebbac30a7f5` and reconciles the UTC-range regression cases. The exact workflow-equivalent HRIS-kernel run passed `213` tests with `100%` statement/branch coverage; dedicated hosted Check [run 33215365348 / job 98997658110](https://github.com/ContextualWisdomLab/Orgmetra/actions/runs/33215365348/job/98997658110) is terminal **GREEN**, the PR remains Draft with no qualifying approval, and no review threads are unresolved. It remains active-PR truth only and is not shipped on `develop`. - -Dependency-first descendants for qualification-rule persistence, Position reporting persistence, HR document persistence, offer-to-hire closure, Job-grade persistence, Position lifecycle application, Organization hierarchy application, Employment absence persistence, export execution, performance-goal activation/persistence, Employment work-capacity persistence, Employment-separation approval, release authorization/publication, and all HR Workspace interaction children remain active-PR truth only. Their focused GREEN evidence never transfers across parent integration or restack. - -## Highest-value buyer gaps after the current owner lanes - -Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. - -1. **Integrate the accessible buyer-interaction stack and retain the unowned P1 surfaces.** The currently named workflow-specific HR Workspace interaction gaps are owned under #53 → #130 by #131/#132/#134/#135/#136/#137/#138/#139/#140, while Employee Profile assignment history and the Candidate Evidence timeline now have the separate #142 → #143 and #144 owners. The PRD still names the Job Architecture workspace, hiring decision record, and Validation dashboard shell; the wireframe baseline also names HR Home, Job Architecture, Recruiting Workspace, Employee Profile, Validate, and Admin & Integrations. No shipped UI/Storybook integration is proven for these surfaces, so they remain active-PR or unowned planned gaps rather than protected-main truth. The commercial risk is dependency-first integration: land #53 and #130 first, then retarget/revalidate each child against fresh `develop`, reconcile intervening Storybook/Figma/UI changes, and obtain browser/accessibility/Foundation/Recovery/SAST/Security plus every applicable central exact-head gate before representing any child as shipped. Do not open a competing interaction writer for an already-owned scope. -2. **Integrated release-control closure, not another release boundary.** #118/#126/#127 already own readiness review, exact-revision authorization, and reconciled publication. The remaining commercial risk is integrating that dependency chain onto one fresh `develop` revision, then proving build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operability/security and central controls together before any tag/release is created. A parallel release writer would be duplicative and unsafe. -3. **Integration closure is itself a buyer risk until dependency stacks land.** A capability implemented only on a stacked child is not commercially available product truth. Parent-first integration, fresh-base retargeting, migration/provenance reconciliation, and new exact-head local/central evidence are required before those capabilities can be represented as shipped. - -External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. - -## Technical non-negotiables - -- Exact 100% owned production statement/branch coverage where tooling exposes it, plus beginner-readable public docs/docstrings and realistic security/privacy/concurrency/migration/recovery/accessibility cases. -- Descriptive two-or-more-word `snake_case` database objects and 3NF by default. -- Job, Position, Assignment, Employment, Organization, and Person remain distinct authoritative concepts. -- Business/effective time and system-recorded time remain separate; correction is correction-not-rewrite. -- Tenant/context isolation, opaque public correlation, least privilege, field minimization, encryption/retention/export controls, immutable audit-event and escalation evidence, and guarded mutable outbox transitions remain mandatory. -- Necessary PII remains usable only through purpose-bound authorization; indiscriminate masking is not a substitute for access control. -- High-impact employment decisions require accountable human confirmation with actor/purpose/reason/evidence versioning. LLM output remains untrusted draft evidence only. -- Preserve modular MSA extraction boundaries; do not introduce direct cross-service application-table SQL. -- Design toward CSAP and SOC 2 evidence readiness without claiming certification. -- Queued, pending, cancelled, skipped-required, neutral, absent, stale, predecessor, status-only, or model-only evidence is non-passing. - -## Execution loop - -Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, formal reviews/threads, exact-head workflows/jobs, releases, changed refs and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when an executable regression is appropriate; rerun exact-head evidence; resolve only addressed threads; and merge only when the unchanged head satisfies the effective ruleset, the commercial acceptance policy of at least two qualifying independent non-author approvals including approval after the last push with resolved conversations, and every applicable local/central gate. - -For live-state documentation defects such as repository ruleset truth or active owner-lane ownership, do **not** hard-code a volatile external GitHub payload into an executable repository test merely to create artificial RED evidence. The regression is operational: each execution loop refetches the effective ruleset/current PR graph and rejects stale buyer copy before acting. Executable regressions remain required for code-owned behavior and stable repository contracts. - -## References (APA 7th) - -American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. - -Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee selection procedures* (29 C.F.R. Part 1607). - -International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management — Requirements and recommendations for human capital reporting and disclosure*. ISO. - -Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). +- `required_reviewers = []`; +- `dismiss_stale_reviews_on_push = true`; +- required review-thread resolution enabled; +- central required workflows enabled; +- deletion and non-fast-forward protection enabled; and +- an `OrganizationAdmin` actor with routine `bypass_mode = always`. + +This is not the current governance decision. `.github#772` establishes that the present one-human-maintainer fleet cannot satisfy a positive generic independent-human approval count. The compliant repair is **not** a bot approval, service-account approval, self-approval, credential widening, or routine administrator bypass. The current target is: + +- `required_approving_review_count = 0` while no genuinely independent human reviewer exists; +- `require_last_push_approval = false` because the rule otherwise requires a different person from the latest pusher; +- no synthetic `required_reviewers` merely to recreate the unavailable human gate; +- review-thread resolution stays enabled; +- exact-current-head OpenCode, Noema, Strix, Security/SAST, Dependency Review, coverage, provenance and repository-specific quality gates remain fail-closed; +- deletion and non-fast-forward protection remain enabled; +- no routine `OrganizationAdmin/always` bypass; emergency repair belongs to a separately governed, time-bounded, auditable break-glass path; and +- merge-method policy must not be weakened merely to solve the reviewer-capacity problem. + +Causal owner: `ContextualWisdomLab/.github`, primarily issues #772/#1351/#1340/#1200 and the existing ruleset-audit writer PR #1176. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. + +**Canary:** Orgmetra PR #88 (`fix/job-analysis-http-request-budgets`) was freshly verified on exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd` with all observed deterministic hosted gates terminal-success and its review thread resolved, but with zero qualifying approvals. It is intentionally retained as a governance canary: after the central policy repair, an unchanged sole-author GREEN PR must no longer be blocked *only* by a reviewer identity that does not exist. Do not merge it through administrator bypass to fake that proof. + +## 6. Required-workflow availability: P0 evidence blocker + +The central Dependency Review workflow now correctly fails closed: it proceeds to the pinned GitHub Dependency Review action only after an exact `BASE_SHA...HEAD_SHA` dependency comparison returns transport success and HTTP `200`. + +Repeated public, non-fork Orgmetra canaries currently receive HTTP `403` with successful transport from the GitHub dependency comparison endpoint. This is **missing authoritative dependency-diff evidence**, not a clean review. OSV, Trivy, Scorecard, SAST or other scanners remain useful independent controls but are not semantic substitutes for Dependency Review. + +Causal owner/incident: `.github#810`. The original fail-open source defect is already repaired; the remaining work is an authorized GitHub/account/repository availability or configuration repair followed by an unchanged exact-head canary where the comparison returns `200` and the pinned action actually executes. Do not weaken the gate or create an Orgmetra-specific skip. + +## 7. Current baseline-writer evidence + +PR #100 owns this baseline. A predecessor exact head failed Foundation/Recovery-family repository-contract checks after `.codegraph/` was added to `.gitignore` without resealing `manifest.json`. The owner branch was repaired by resealing only the `.gitignore` manifest entry to the exact current digest/size/line count. + +Do **not** store PR #100's own current head inside this file: changing this file creates a new head and would make the value self-invalidating. Its PR body and GitHub API are the source for exact-current-head verification. All reviews/checks must be re-fetched after every push. + +## 8. Commercialization gap register + +| Gap | Current evidence | Buyer consequence | Owner / next acceptance evidence | Priority | +| --- | --- | --- | --- | --- | +| **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, PR #1176; live post-change ruleset read + unchanged Orgmetra canary | **P0** | +| **SEC-01 authoritative Dependency Review availability** | exact public comparisons repeatedly return 403; central gate correctly fails closed | merge queue can remain blocked without trustworthy dependency diff | `.github#810`; exact unchanged canary returns 200 and pinned action executes | **P0** | +| **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | +| **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | +| **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | +| **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | +| **OPS-01 commercial operability/SLO proof** | test/operability docs exist, but no released integrated web service proves buyer traffic characteristics | enterprise buyer lacks capacity/recovery evidence | compose deployment; Podman/Colima portability; async request handling; k6 per-page p95 ≤20 ms; recovery/backup/restore evidence; resource auto-tuning where required | **P1** | +| **SEC-02 certification-ready control evidence** | purpose-bound PII/RLS/audit contracts exist; certification is not claimed | security review still needs traceable operational evidence | NIST/SOC 2/CSAP control mapping, key management, retention/export/delete, break-glass, incident/recovery evidence; no indiscriminate PII masking | **P1** | +| **DATA-01 schema/name/persistence audit** | strong normalized temporal schema exists but every new migration/PR can introduce naming, hot-partition, lock or UPSERT drift | latent data debt can become irreversible after adoption | automated audit for at-least-two-token domain/DB identifiers where semantically required, snake_case default, 3NF ownership, per-item UPSERT/idempotency, partition/lock strategy | **P1 continuous** | +| **SCI-01 Rust scientific compute boundary** | TRD correctly reserves material mathematical/psychometric kernels for Rust; current HRIS packages are mainly governance/domain code | future analytics can regress into slow or unauditable Python numerics | every material math/psychometric/EDA/vector/matrix/token-size core is Rust or behind an explicit Rust API; CPU multithreading and justified GPU parity fixtures | **P1 continuous** | + +## 9. Next product loop after P0 governance repair + +The next buyer-visible vertical slice should be **Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation** rather than another isolated evidence packet. + +Minimum commercialization contract: + +1. **Gateway** — authenticated tenant/actor/purpose context; idempotency; exact OpenAPI validation; bounded async operations; no direct peer-table reads. +2. **Job Architecture** — governed snapshot provenance, SME review, qualification rules and clear next-action states. +3. **Candidate Evidence** — purpose-bound retrieval, immutable evidence version/reference, explicit insufficiency/escalation states, no autonomous hiring decision. +4. **Hiring Decision** — human confirmation, exact sealed evidence-set digest, actor/reason/provenance, candidate-worker conversion handoff. +5. **Employee Profile** — effective/system-time assignment history and correction semantics visible without exposing internal schema names. +6. **Validation** — exact predictor/criterion version linkage, job scope, time, subgroup/multilevel context and specialist scientific adapter evidence. +7. **UX evidence** — design tokens, Storybook scenario/edge inventory, screenshots at supported breakpoints, keyboard/touch/focus/error/degraded/permission/i18n states, exact-value alternatives for charts, WCAG 2.2 AA audit. +8. **Operability evidence** — compose-based deployment, recovery rehearsal, structured audit telemetry, k6 concurrency evidence with page p95 ≤20 ms, dependency/service failure behavior and clean close-connection handling. + +This slice must use existing bounded packages instead of duplicating their domain rules in UI code. + +## 10. Data, scientific and AI invariants + +- Database/domain object names must be semantically explicit. `snake_case` is the default for database objects and two-or-more meaningful tokens are preferred/required where a bare one-token name such as `id` would lose domain identity; legitimate context-required `camelCase`/`PascalCase` program identifiers remain valid. +- Authoritative relational design stays in 3NF unless an explicitly measured read model is separated from the system of record. +- Tenant, bitemporal, lock/partition and item-level UPSERT/idempotency contracts are tested at the database boundary, not assumed from application code. +- Multiple assignments/memberships and time-varying context must remain modelable so person-level inference does not silently commit an atomistic fallacy. +- Psychometric/statistical weights are estimated from reviewed mathematical models; no arbitrary rule-of-thumb weighting enters production. +- Material mathematical, psychometric, EDA, vector/linear/matrix and token-size core computation is Rust-first with bounded CPU parallelism and justified GPU parity evidence. +- LLM output is draft/supporting evidence only. LLM work uses the contextual-orchestrator boundary, schema-bound outputs, model/provider discovery, explicit test-time compute policy and immutable provenance; it never receives direct authoritative employment-decision power. + +## 11. Security, privacy and compliance posture + +Orgmetra targets evidence readiness for CSAP/SOC 2-style enterprise review without claiming certification. PII protection must be purpose-bound and operationally usable rather than indiscriminate masking that prevents legitimate HR work. Controls include tenant/actor/purpose/resource/lifetime authorization, least privilege, forced RLS, encryption, immutable audit evidence, retention/export/delete lifecycle, incident/recovery evidence and separately governed break-glass operation. + +Customer-facing language describes the user's next action and evidence state, not internal repository, schema, model or agent boundaries. + +## 12. Research and standards basis + +The following authoritative sources were re-checked for this baseline. They define design/audit constraints; they do not by themselves certify Orgmetra or establish legal compliance. + +- International Organization for Standardization. (2023). *ISO 30405:2023 Human resource management—Guidelines on recruitment* (2nd ed.). https://www.iso.org/standard/79488.html +- World Wide Web Consortium. (2023). *Web Content Accessibility Guidelines (WCAG) 2.2*. https://www.w3.org/TR/WCAG22/ +- Joint Task Force. (2020). *Security and privacy controls for information systems and organizations* (NIST Special Publication 800-53 Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5 +- Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). *Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile* (NIST AI 600-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.600-1 +- American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. American Educational Research Association. + +Implementation-specific research belongs in `docs/doctoring/` and ADR/traceability records beside the exact feature it constrains. A source citation without an executable invariant/test is documentation evidence only. + +## 13. Release gate + +A commercial release is allowed only from one freshly fetched protected `develop` head that simultaneously proves: + +- all release-scope PR dependencies are integrated in causal order; +- no unresolved valid review finding remains; +- every required exact-head deterministic gate is terminal-success, including authoritative Dependency Review rather than substitutes; +- protected-branch admission is satisfiable without synthetic approval or routine admin bypass; +- buyer vertical-slice E2E, accessibility, security, recovery and load evidence is terminal-success; +- migrations/rollback/backup-restore and tenant/purpose/audit invariants pass against production-equivalent PostgreSQL; +- documentation/ADR/TRD/API/events/schema/UI copy match the released implementation; +- release version and CHANGELOG identify the exact protected commit and migration/API compatibility; and +- no temporary self-modifying/source-fix workflow remains. + +Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. From dbefe8c621f78353dc0e78ee1e4c0fbf8047488c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 1 Sep 2026 21:58:42 +0900 Subject: [PATCH 180/201] docs(doctoring): trace commercialization and governance sources --- .../product-gap-baseline-references.md | 51 +++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 docs/doctoring/product-gap-baseline-references.md diff --git a/docs/doctoring/product-gap-baseline-references.md b/docs/doctoring/product-gap-baseline-references.md new file mode 100644 index 000000000..3e2c3fe51 --- /dev/null +++ b/docs/doctoring/product-gap-baseline-references.md @@ -0,0 +1,51 @@ +# Product-gap baseline references and applied boundaries + +Retrieved September 1, 2026. + +This doctoring note records the external sources re-checked while replacing `docs/product-technical-gap-baseline.md` and repairing its upstream governance assumptions. A citation is evidence for a design constraint, not certification, legal advice, merge authorization, or proof that an implementation satisfies the source. + +## Human-resource and selection governance + +International Organization for Standardization. (2023). *ISO 30405:2023 Human resource management—Guidelines on recruitment* (2nd ed.). https://www.iso.org/standard/79488.html + +American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. American Educational Research Association. + +### Applied boundary + +Orgmetra keeps recruitment/selection evidence reviewable and attributable, preserves job/evidence provenance, and keeps model output outside autonomous employment-decision authority. Criterion-related or fairness claims require exact predictor/criterion/version linkage and scientific evidence rather than a correlation-only product claim. These sources do not establish that a particular employment decision is lawful or valid. + +## Accessibility and customer interaction + +World Wide Web Consortium. (2023, October 5). *Web Content Accessibility Guidelines (WCAG) 2.2 is a W3C Recommendation*. https://www.w3.org/WAI/news/2023-10-05/wcag22rec/ + +### Applied boundary + +The P1 role-workspace release gate requires WCAG 2.2 AA-oriented evidence, including keyboard/focus behavior, touch-target and dragging alternatives, accessible authentication where applicable, consistent help/error semantics, exact-value alternatives for charts, responsive screenshots, and Storybook edge states. A design-token or wireframe document alone is not accessibility evidence. + +## Security, privacy and AI risk + +Joint Task Force. (2020). *Security and privacy controls for information systems and organizations* (NIST Special Publication 800-53 Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5 + +Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). *Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile* (NIST AI 600-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.600-1 + +### Applied boundary + +Orgmetra treats tenant/actor/purpose/resource authorization, immutable audit evidence, least privilege, retention/export/delete, recovery, provenance, and separately governed emergency access as executable control boundaries. Generative-AI output is supporting/draft evidence routed through the contextual-orchestrator boundary; it does not obtain authoritative HRIS write or employment-decision authority merely because a model response is structured. These NIST publications inform evidence readiness and risk management; they are not SOC 2, CSAP, or product certification claims. + +## GitHub protected-branch and dependency-review semantics + +GitHub. (n.d.). *Available rules for rulesets*. GitHub Docs. https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets + +GitHub. (n.d.). *REST API endpoints for dependency review*. GitHub Docs. https://docs.github.com/en/rest/dependency-graph/dependency-review + +GitHub. (n.d.). *Dependency graph*. GitHub Docs. https://docs.github.com/en/code-security/concepts/supply-chain-security/dependency-graph + +### Applied boundary + +The current one-human-maintainer governance decision uses the documented ability to set the generic required approving-review count to zero; it also disables latest-push approval because that rule requires approval from someone other than the latest pusher. The repair does **not** manufacture independence through bot/service-account approvals and does not weaken required review-thread resolution or deterministic required workflows. + +For Dependency Review, an HTTP failure from the exact dependency comparison is treated as missing authoritative evidence and fails closed. Independent OSV/Trivy/SAST/Scorecard evidence is retained but is not promoted to a semantic substitute for GitHub Dependency Review. + +## Traceability rule + +When any cited source changes an executable invariant, the owning PR must carry a regression/contract test and the relevant ADR/TRD/API/schema/UI evidence must be updated on the same exact head. If only the prose changes, the result remains documentation evidence rather than implemented product behavior. From 7f2ebf7f29c2ff1aceddee7b0e432c6392ccc8f7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 04:20:18 +0900 Subject: [PATCH 181/201] docs(gaps): refresh live governance evidence --- docs/product-technical-gap-baseline.md | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ecf7dde1c..a5c301efa 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product and technical gap baseline -Verified: 2026-09-01 (Asia/Seoul). +Verified: 2026-09-02 (Asia/Seoul). This document is the commercialization baseline for **Orgmetra**, not a frozen PR inventory and not merge authorization. It records product responsibility, shipped-vs-planned truth, causal control-plane blockers, and the next highest-leverage buyer gaps. Volatile PR heads, workflow run IDs, queue counts, review snapshots, mergeability, and base tips must be fetched live before every action rather than copied here until stale. @@ -74,7 +74,7 @@ There are currently no published GitHub releases. Do not manufacture a release m The effective control plane for Orgmetra `develop` is inherited organization ruleset **18156473 — `CWL Central required workflows`**. Classic branch-protection fields alone are not authoritative while that ruleset is active. -Fresh live reads on 2026-09-01 show the inherited ruleset still has: +Fresh live reads on 2026-09-02 show the inherited ruleset still has: - `required_approving_review_count = 1`; - `require_last_push_approval = false`; @@ -82,9 +82,12 @@ Fresh live reads on 2026-09-01 show the inherited ruleset still has: - `dismiss_stale_reviews_on_push = true`; - required review-thread resolution enabled; - central required workflows enabled; +- only merge and squash allowed; - deletion and non-fast-forward protection enabled; and - an `OrganizationAdmin` actor with routine `bypass_mode = always`. +The central `.github` repository's own active ruleset **17921150 — `Lock default branch`** is a second live drift surface. Its approval count is already `0`, last-push approval is disabled, required reviewers are empty, review-thread resolution and deletion/non-fast-forward protection are enabled, but it still permits `rebase` and still exposes `OrganizationAdmin/always` bypass. Source-level audit policy and both live ruleset payloads must converge before governance repair is complete. + This is not the current governance decision. `.github#772` establishes that the present one-human-maintainer fleet cannot satisfy a positive generic independent-human approval count. The compliant repair is **not** a bot approval, service-account approval, self-approval, credential widening, or routine administrator bypass. The current target is: - `required_approving_review_count = 0` while no genuinely independent human reviewer exists; @@ -94,19 +97,19 @@ This is not the current governance decision. `.github#772` establishes that the - exact-current-head OpenCode, Noema, Strix, Security/SAST, Dependency Review, coverage, provenance and repository-specific quality gates remain fail-closed; - deletion and non-fast-forward protection remain enabled; - no routine `OrganizationAdmin/always` bypass; emergency repair belongs to a separately governed, time-bounded, auditable break-glass path; and -- merge-method policy must not be weakened merely to solve the reviewer-capacity problem. +- only merge and squash are accepted by the current audit; merge-method policy must not be weakened merely to solve the reviewer-capacity problem. Causal owner: `ContextualWisdomLab/.github`, primarily issues #772/#1351/#1340/#1200 and the existing ruleset-audit writer PR #1176. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. -**Canary:** Orgmetra PR #88 (`fix/job-analysis-http-request-budgets`) was freshly verified on exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd` with all observed deterministic hosted gates terminal-success and its review thread resolved, but with zero qualifying approvals. It is intentionally retained as a governance canary: after the central policy repair, an unchanged sole-author GREEN PR must no longer be blocked *only* by a reviewer identity that does not exist. Do not merge it through administrator bypass to fake that proof. +**Canary:** Orgmetra PR #88 (`fix/job-analysis-http-request-budgets`) was freshly re-verified on exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd`; the currently returned repository workflow runs are terminal-success, combined CodeRabbit/Devin statuses are successful, and its only inline review thread is resolved. It has no qualifying independent approval. It is intentionally retained as a governance canary: after the central policy repair, an unchanged sole-author GREEN PR must no longer be blocked *only* by a reviewer identity that does not exist. Do not merge it through administrator bypass to fake that proof. ## 6. Required-workflow availability: P0 evidence blocker The central Dependency Review workflow now correctly fails closed: it proceeds to the pinned GitHub Dependency Review action only after an exact `BASE_SHA...HEAD_SHA` dependency comparison returns transport success and HTTP `200`. -Repeated public, non-fork Orgmetra canaries currently receive HTTP `403` with successful transport from the GitHub dependency comparison endpoint. This is **missing authoritative dependency-diff evidence**, not a clean review. OSV, Trivy, Scorecard, SAST or other scanners remain useful independent controls but are not semantic substitutes for Dependency Review. +Fresh current-head evidence again reproduced the incident on a public, non-fork Orgmetra PR: exact head checkout and SHA verification succeeded on an Ubuntu 24.04 hosted runner; the comparison transport succeeded (`curl_exit=0`) but GitHub returned HTTP `403`, so the Dependency Review action was correctly skipped and the job failed closed. Independent OSV, Trivy and Scorecard jobs on that same Security run succeeded. This remains **missing authoritative dependency-diff evidence**, not a clean review, and those independent scanners are not semantic substitutes for Dependency Review. -Causal owner/incident: `.github#810`. The original fail-open source defect is already repaired; the remaining work is an authorized GitHub/account/repository availability or configuration repair followed by an unchanged exact-head canary where the comparison returns `200` and the pinned action actually executes. Do not weaken the gate or create an Orgmetra-specific skip. +Causal owner/incident: `.github#810`. The original fail-open source defect is already repaired; the remaining work is an authorized GitHub/account/repository availability or configuration repair followed by an unchanged exact-head canary where the comparison returns `200` and the pinned action actually executes. Do not infer the root cause from the status code alone, weaken the gate, or create an Orgmetra-specific skip. ## 7. Current baseline-writer evidence @@ -118,7 +121,7 @@ Do **not** store PR #100's own current head inside this file: changing this file | Gap | Current evidence | Buyer consequence | Owner / next acceptance evidence | Priority | | --- | --- | --- | --- | --- | -| **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, PR #1176; live post-change ruleset read + unchanged Orgmetra canary | **P0** | +| **GOV-01 satisfiable protected-branch admission** | inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, PR #1176; live post-change ruleset reads + unchanged Orgmetra canary | **P0** | | **SEC-01 authoritative Dependency Review availability** | exact public comparisons repeatedly return 403; central gate correctly fails closed | merge queue can remain blocked without trustworthy dependency diff | `.github#810`; exact unchanged canary returns 200 and pinned action executes | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | @@ -188,4 +191,4 @@ A commercial release is allowed only from one freshly fetched protected `develop - release version and CHANGELOG identify the exact protected commit and migration/API compatibility; and - no temporary self-modifying/source-fix workflow remains. -Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. +Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. \ No newline at end of file From f461787cf35cca45e0a851c6752f136f5f0a0b91 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 05:30:27 +0900 Subject: [PATCH 182/201] docs: align commercialization governance contract --- docs/product-technical-gap-baseline.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a5c301efa..6460a9453 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -78,6 +78,7 @@ Fresh live reads on 2026-09-02 show the inherited ruleset still has: - `required_approving_review_count = 1`; - `require_last_push_approval = false`; +- `require_code_owner_review = false`; - `required_reviewers = []`; - `dismiss_stale_reviews_on_push = true`; - required review-thread resolution enabled; @@ -86,12 +87,13 @@ Fresh live reads on 2026-09-02 show the inherited ruleset still has: - deletion and non-fast-forward protection enabled; and - an `OrganizationAdmin` actor with routine `bypass_mode = always`. -The central `.github` repository's own active ruleset **17921150 — `Lock default branch`** is a second live drift surface. Its approval count is already `0`, last-push approval is disabled, required reviewers are empty, review-thread resolution and deletion/non-fast-forward protection are enabled, but it still permits `rebase` and still exposes `OrganizationAdmin/always` bypass. Source-level audit policy and both live ruleset payloads must converge before governance repair is complete. +The central `.github` repository's own active ruleset **17921150 — `Lock default branch`** is a second live drift surface. Its approval count is already `0`, last-push approval and CODEOWNER review are disabled, required reviewers are empty, review-thread resolution and deletion/non-fast-forward protection are enabled, but it still permits `rebase` and still exposes `OrganizationAdmin/always` bypass. Source-level audit policy and both live ruleset payloads must converge before governance repair is complete. -This is not the current governance decision. `.github#772` establishes that the present one-human-maintainer fleet cannot satisfy a positive generic independent-human approval count. The compliant repair is **not** a bot approval, service-account approval, self-approval, credential widening, or routine administrator bypass. The current target is: +This is not the current governance decision. `.github#772` establishes that the present one-human-maintainer fleet cannot satisfy a positive generic independent-human approval count, a last-push approval by another person, or mandatory CODEOWNER approval by the same sole author. The compliant repair is **not** a bot approval, service-account approval, self-approval, credential widening, or routine administrator bypass. The current target is: - `required_approving_review_count = 0` while no genuinely independent human reviewer exists; - `require_last_push_approval = false` because the rule otherwise requires a different person from the latest pusher; +- `require_code_owner_review = false` while the sole code owner is also the author; - no synthetic `required_reviewers` merely to recreate the unavailable human gate; - review-thread resolution stays enabled; - exact-current-head OpenCode, Noema, Strix, Security/SAST, Dependency Review, coverage, provenance and repository-specific quality gates remain fail-closed; @@ -99,7 +101,7 @@ This is not the current governance decision. `.github#772` establishes that the - no routine `OrganizationAdmin/always` bypass; emergency repair belongs to a separately governed, time-bounded, auditable break-glass path; and - only merge and squash are accepted by the current audit; merge-method policy must not be weakened merely to solve the reviewer-capacity problem. -Causal owner: `ContextualWisdomLab/.github`, primarily issues #772/#1351/#1340/#1200 and the existing ruleset-audit writer PR #1176. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. +Causal owner: `ContextualWisdomLab/.github`, primarily issues #772/#1351/#1340/#1200 and the existing ruleset-audit writer PR #1176. That writer now carries a test-first regression for the CODEOWNER deadlock and the corresponding organization/repository auditor repair. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. **Canary:** Orgmetra PR #88 (`fix/job-analysis-http-request-budgets`) was freshly re-verified on exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd`; the currently returned repository workflow runs are terminal-success, combined CodeRabbit/Devin statuses are successful, and its only inline review thread is resolved. It has no qualifying independent approval. It is intentionally retained as a governance canary: after the central policy repair, an unchanged sole-author GREEN PR must no longer be blocked *only* by a reviewer identity that does not exist. Do not merge it through administrator bypass to fake that proof. @@ -121,7 +123,7 @@ Do **not** store PR #100's own current head inside this file: changing this file | Gap | Current evidence | Buyer consequence | Owner / next acceptance evidence | Priority | | --- | --- | --- | --- | --- | -| **GOV-01 satisfiable protected-branch admission** | inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, PR #1176; live post-change ruleset reads + unchanged Orgmetra canary | **P0** | +| **GOV-01 satisfiable protected-branch admission** | inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; source audit now also rejects same-author CODEOWNER review deadlock | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, PR #1176; live post-change ruleset reads + unchanged Orgmetra canary | **P0** | | **SEC-01 authoritative Dependency Review availability** | exact public comparisons repeatedly return 403; central gate correctly fails closed | merge queue can remain blocked without trustworthy dependency diff | `.github#810`; exact unchanged canary returns 200 and pinned action executes | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | @@ -191,4 +193,4 @@ A commercial release is allowed only from one freshly fetched protected `develop - release version and CHANGELOG identify the exact protected commit and migration/API compatibility; and - no temporary self-modifying/source-fix workflow remains. -Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. \ No newline at end of file +Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. From a76df82374ff4a2bd3687875ce7729ed775790d5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 10:50:43 +0900 Subject: [PATCH 183/201] docs(commercialization): track owner-plane governance repair --- docs/product-technical-gap-baseline.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6460a9453..5845bdc19 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -101,7 +101,9 @@ This is not the current governance decision. `.github#772` establishes that the - no routine `OrganizationAdmin/always` bypass; emergency repair belongs to a separately governed, time-bounded, auditable break-glass path; and - only merge and squash are accepted by the current audit; merge-method policy must not be weakened merely to solve the reviewer-capacity problem. -Causal owner: `ContextualWisdomLab/.github`, primarily issues #772/#1351/#1340/#1200 and the existing ruleset-audit writer PR #1176. That writer now carries a test-first regression for the CODEOWNER deadlock and the corresponding organization/repository auditor repair. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. +Causal owner: `ContextualWisdomLab/.github`. Issue #772 defines the satisfiable one-human policy, #1351 tracks fleet reconciliation, and #1176 remains the canonical audit contract. **Active owner-plane successor PR #1644 now adds the missing reviewed mutation path** instead of relying on an application connector that can only read rulesets. It pins exactly rulesets 17921150 and 18156473, refuses identity/provenance drift, preserves unrelated controls, binds privileged mutation to the exact protected-main SHA, verifies immutable ruleset history, treats ambiguous PUT outcomes as unresolved until history/live-state evidence proves convergence, and uses a separately provisioned protected-environment `CWL_RULESET_ADMIN_TOKEN` rather than widening ordinary repository credentials. Source integration alone is intentionally insufficient: after #1644 reaches protected `main`, a controlled maintenance interval must provision the least-privilege owner-plane credential, enable `CWL_RULESET_RECONCILE_ENABLED`, perform and verify the mutation, disable/retain the reconciler according to the reviewed drift-repair policy, and then re-run the canonical audit plus Orgmetra canary. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. + +The #1644 focused owner-plane suite exposed deterministic test-contract drift on a predecessor exact head rather than an authorization failure. The writer branch repaired the logged failures by making merge-method fixtures include explicit CODEOWNER=false, registering dynamically loaded Python 3.12 dataclass modules in `sys.modules`, parsing the current workflow job ordering instead of assuming `validate` is first, passing the exact editable PUT projection into history-transition tests while keeping full live/history states, aligning recovery-document assertions with the newest-displaced-state contract, and preserving fail-closed code-owner drift when review parameters are malformed. A fresh successor exact-head owner-plane run is required; predecessor failures do not transfer. **Canary:** Orgmetra PR #88 (`fix/job-analysis-http-request-budgets`) was freshly re-verified on exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd`; the currently returned repository workflow runs are terminal-success, combined CodeRabbit/Devin statuses are successful, and its only inline review thread is resolved. It has no qualifying independent approval. It is intentionally retained as a governance canary: after the central policy repair, an unchanged sole-author GREEN PR must no longer be blocked *only* by a reviewer identity that does not exist. Do not merge it through administrator bypass to fake that proof. @@ -111,7 +113,7 @@ The central Dependency Review workflow now correctly fails closed: it proceeds t Fresh current-head evidence again reproduced the incident on a public, non-fork Orgmetra PR: exact head checkout and SHA verification succeeded on an Ubuntu 24.04 hosted runner; the comparison transport succeeded (`curl_exit=0`) but GitHub returned HTTP `403`, so the Dependency Review action was correctly skipped and the job failed closed. Independent OSV, Trivy and Scorecard jobs on that same Security run succeeded. This remains **missing authoritative dependency-diff evidence**, not a clean review, and those independent scanners are not semantic substitutes for Dependency Review. -Causal owner/incident: `.github#810`. The original fail-open source defect is already repaired; the remaining work is an authorized GitHub/account/repository availability or configuration repair followed by an unchanged exact-head canary where the comparison returns `200` and the pinned action actually executes. Do not infer the root cause from the status code alone, weaken the gate, or create an Orgmetra-specific skip. +Causal owner/incident: `.github#810`. The original fail-open source defect is already repaired; active central PR #1643 owns an identity-hardening and temporary anonymous-vs-minimally-scoped-token A/B diagnostic. The diagnostic must execute on its unchanged exact head before its temporary canary workflow is removed. The remaining acceptance is an authorized GitHub/account/repository availability or configuration repair followed by an unchanged public non-fork canary where the exact comparison returns `200` and the pinned Dependency Review action actually executes. Do not infer the root cause from the status code alone, weaken the gate, or create an Orgmetra-specific skip. ## 7. Current baseline-writer evidence @@ -123,8 +125,8 @@ Do **not** store PR #100's own current head inside this file: changing this file | Gap | Current evidence | Buyer consequence | Owner / next acceptance evidence | Priority | | --- | --- | --- | --- | --- | -| **GOV-01 satisfiable protected-branch admission** | inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; source audit now also rejects same-author CODEOWNER review deadlock | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, PR #1176; live post-change ruleset reads + unchanged Orgmetra canary | **P0** | -| **SEC-01 authoritative Dependency Review availability** | exact public comparisons repeatedly return 403; central gate correctly fails closed | merge queue can remain blocked without trustworthy dependency diff | `.github#810`; exact unchanged canary returns 200 and pinned action executes | **P0** | +| **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; #1176 defines the canonical audit and active #1644 now implements the separately privileged, history-verified owner-plane reconciliation path | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, audit PR #1176, owner-plane PR #1644; terminal exact-head source evidence → protected-main integration → least-privilege maintenance apply → full live post-change reads + canonical audit + unchanged Orgmetra #88 canary | **P0** | +| **SEC-01 authoritative Dependency Review availability** | exact public comparisons repeatedly return 403; central gate correctly fails closed; #1643 owns an unchanged-head anonymous/token A/B diagnostic that remains evidence-only until it runs | merge queue can remain blocked without trustworthy dependency diff | `.github#810`, PR #1643; capture decisive A/B evidence, remove the temporary canary workflow, then prove an unchanged public non-fork exact comparison returns 200 and pinned action executes | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | | **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | From 8304d8ddc02fc0c0733306ef9a7fb29d5bcbad40 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 18:22:30 +0900 Subject: [PATCH 184/201] docs(commercialization): track explicit assignment authority gap --- docs/product-technical-gap-baseline.md | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5845bdc19..1bb9ccee0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -66,6 +66,8 @@ Shipped foundation evidence includes: - Keyverse/Naruon/migration adapter boundaries and design-token foundations; and - PRD/TRD/ADR/UML/ERD/security/test/operability documentation sufficient to define intended modular boundaries. +Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. + The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. There are currently no published GitHub releases. Do not manufacture a release merely to clear that count; release only when an integrated protected head has complete exact-head governance, security, operability and buyer-workflow evidence. @@ -128,6 +130,7 @@ Do **not** store PR #100's own current head inside this file: changing this file | **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; #1176 defines the canonical audit and active #1644 now implements the separately privileged, history-verified owner-plane reconciliation path | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, audit PR #1176, owner-plane PR #1644; terminal exact-head source evidence → protected-main integration → least-privilege maintenance apply → full live post-change reads + canonical audit + unchanged Orgmetra #88 canary | **P0** | | **SEC-01 authoritative Dependency Review availability** | exact public comparisons repeatedly return 403; central gate correctly fails closed; #1643 owns an unchanged-head anonymous/token A/B diagnostic that remains evidence-only until it runs | merge queue can remain blocked without trustworthy dependency diff | `.github#810`, PR #1643; capture decisive A/B evidence, remove the temporary canary workflow, then prove an unchanged public non-fork exact comparison returns 200 and pinned action executes | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | +| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane and remain non-shipped while current exact-head evidence is non-terminal | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #162/#163; integrate explicit category across domain/API/PostgreSQL/OpenAPI with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification, then prove exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | | **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | | **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | @@ -146,7 +149,7 @@ Minimum commercialization contract: 2. **Job Architecture** — governed snapshot provenance, SME review, qualification rules and clear next-action states. 3. **Candidate Evidence** — purpose-bound retrieval, immutable evidence version/reference, explicit insufficiency/escalation states, no autonomous hiring decision. 4. **Hiring Decision** — human confirmation, exact sealed evidence-set digest, actor/reason/provenance, candidate-worker conversion handoff. -5. **Employee Profile** — effective/system-time assignment history and correction semantics visible without exposing internal schema names. +5. **Employee Profile** — effective/system-time assignment history and correction semantics visible without exposing internal schema names; assignment category is explicit HRIS truth rather than inferred from allocation or ordering. 6. **Validation** — exact predictor/criterion version linkage, job scope, time, subgroup/multilevel context and specialist scientific adapter evidence. 7. **UX evidence** — design tokens, Storybook scenario/edge inventory, screenshots at supported breakpoints, keyboard/touch/focus/error/degraded/permission/i18n states, exact-value alternatives for charts, WCAG 2.2 AA audit. 8. **Operability evidence** — compose-based deployment, recovery rehearsal, structured audit telemetry, k6 concurrency evidence with page p95 ≤20 ms, dependency/service failure behavior and clean close-connection handling. @@ -161,7 +164,7 @@ This slice must use existing bounded packages instead of duplicating their domai - Multiple assignments/memberships and time-varying context must remain modelable so person-level inference does not silently commit an atomistic fallacy. - Psychometric/statistical weights are estimated from reviewed mathematical models; no arbitrary rule-of-thumb weighting enters production. - Material mathematical, psychometric, EDA, vector/linear/matrix and token-size core computation is Rust-first with bounded CPU parallelism and justified GPU parity evidence. -- LLM output is draft/supporting evidence only. LLM work uses the contextual-orchestrator boundary, schema-bound outputs, model/provider discovery, explicit test-time compute policy and immutable provenance; it never receives direct authoritative employment-decision power. +- LLM output is draft/supporting evidence only. LLM work uses released contextual-orchestrator API/client/schema contracts; GitHub Actions request only `orchestrator/free` through the gateway token and never hard-code provider/model/group/paid fallback policy. contextual-orchestrator owns capability/price/latency/availability/accuracy discovery, supports schema-bound completions/responses and modality/embedding contracts, and preserves no-default-inference-timeout plus explicit user/provider/admin termination provenance. LLM output never receives direct authoritative employment-decision power. ## 11. Security, privacy and compliance posture @@ -195,4 +198,4 @@ A commercial release is allowed only from one freshly fetched protected `develop - release version and CHANGELOG identify the exact protected commit and migration/API compatibility; and - no temporary self-modifying/source-fix workflow remains. -Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. +Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. \ No newline at end of file From be380fcdf44e1be0329c6cba5ea19ea10a8c28e8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 18:24:28 +0900 Subject: [PATCH 185/201] docs(research): refresh accessibility and control standards --- docs/product-technical-gap-baseline.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1bb9ccee0..d8e1026ea 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -174,10 +174,12 @@ Customer-facing language describes the user's next action and evidence state, no ## 12. Research and standards basis -The following authoritative sources were re-checked for this baseline. They define design/audit constraints; they do not by themselves certify Orgmetra or establish legal compliance. +The following authoritative sources were re-checked on 2026-09-02. They define design/audit constraints; they do not by themselves certify Orgmetra or establish legal compliance. WCAG 2.2 remains the current published accessibility basis as ISO/IEC 40500:2025 while ISO/IEC has a newer revision project in development; draft work is not treated as a published requirement. NIST SP 800-53 Rev. 5 also has a finalized Release 5.2.0 control-catalog update from 2025, so current control mapping must use that release rather than assuming the original 2020 catalog is unchanged. - International Organization for Standardization. (2023). *ISO 30405:2023 Human resource management—Guidelines on recruitment* (2nd ed.). https://www.iso.org/standard/79488.html +- International Organization for Standardization, & International Electrotechnical Commission. (2025). *ISO/IEC 40500:2025 Information technology—W3C Web Content Accessibility Guidelines (WCAG) 2.2* (2nd ed.). https://www.iso.org/standard/91029.html - World Wide Web Consortium. (2023). *Web Content Accessibility Guidelines (WCAG) 2.2*. https://www.w3.org/TR/WCAG22/ +- National Institute of Standards and Technology. (2025, August 27). *NIST releases revision to SP 800-53 security and privacy controls (Release 5.2.0)*. https://csrc.nist.gov/news/2025/nist-releases-revision-to-sp-800-53-controls - Joint Task Force. (2020). *Security and privacy controls for information systems and organizations* (NIST Special Publication 800-53 Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5 - Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). *Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile* (NIST AI 600-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.600-1 - American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. American Educational Research Association. From 559ee68825511b431dfac6a4e5ebacbf351f5034 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 18:44:54 +0900 Subject: [PATCH 186/201] test: pin LLM routing and semantic ownership guidance --- tests/llm-routing-policy.test.mjs | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 tests/llm-routing-policy.test.mjs diff --git a/tests/llm-routing-policy.test.mjs b/tests/llm-routing-policy.test.mjs new file mode 100644 index 000000000..44c78cb18 --- /dev/null +++ b/tests/llm-routing-policy.test.mjs @@ -0,0 +1,28 @@ +import assert from 'node:assert/strict'; +import { readFileSync } from 'node:fs'; +import test from 'node:test'; + +function repositoryText(relativePath) { + return readFileSync(new URL(`../${relativePath}`, import.meta.url), 'utf8'); +} + +test('consumer guidance routes model-backed Actions only through contextual-orchestrator free', () => { + const agents = repositoryText('AGENTS.md'); + + assert.match(agents, /`orchestrator\/free`/); + assert.match(agents, /contextual-orchestrator/); + assert.match(agents, /gateway token/i); + assert.doesNotMatch(agents, /NVIDIA_NIM_API_KEY/); + assert.doesNotMatch(agents, /OPENAI_API_KEY/); + assert.doesNotMatch(agents, /OPENROUTER_API_KEY/); + assert.doesNotMatch(agents, /BYTEZ_API_KEY/); +}); + +test('core-boundary guidance separates ontology release from catalog governance', () => { + const claude = repositoryText('CLAUDE.md'); + + assert.match(claude, /ConceptWeave owns ontology/); + assert.match(claude, /semantic-data-portal owns catalog/); + assert.match(claude, /contextual-orchestrator owns bounded LLM orchestration traces/); + assert.doesNotMatch(claude, /Semantic Data Portal owns occupation\/skill\/ability ontology/); +}); From e129d7207950ee778a6467c7463bf8f69c61b06f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 18:45:06 +0900 Subject: [PATCH 187/201] docs: route model-backed Actions through contextual-orchestrator --- AGENTS.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/AGENTS.md b/AGENTS.md index fb8c0470c..19dcf0426 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -8,7 +8,7 @@ Build Orgmetra as a commercial-grade, evidence-centered HRIS and HCM platform th - Never bypass branch protection, required checks, independent review, OpenCode, Noema, Strix, SAST, or Security Scan gates. - Never self-approve or manufacture approval evidence. -- Never use `COPILOT_GITHUB_TOKEN` as a development model credential. Use `NVIDIA_NIM_API_KEY` for model-backed tests and OpenCode development paths. +- Model-backed GitHub Actions request only `orchestrator/free` through the released contextual-orchestrator gateway token. Consumer workflows must not select a provider, provider group, paid fallback, or use `COPILOT_GITHUB_TOKEN` or provider API keys directly. - Never make LLM output an autonomous high-impact employment decision. - Never copy another CWL product into Orgmetra when an adapter/package/API/event boundary is sufficient. - Never directly query another service's application database. From 57def8e3a8009a2ce188c12e93c130f35fd336b6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 18:45:18 +0900 Subject: [PATCH 188/201] docs: align semantic and orchestration ownership boundaries --- CLAUDE.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 33818e4c0..6e5d54ddb 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -11,9 +11,10 @@ Do not treat Orgmetra as a resume parser, ATS-only system, psychometric engine, - Psychometrics Commons owns assessment operations and immutable assessment result snapshots. - fast-mlsirm owns psychometric numerical kernels. - TEPP owns temporal/event/multilevel analysis artifacts. -- Semantic Data Portal owns occupation/skill/ability ontology and semantic catalog. +- ConceptWeave owns ontology and semantic-layer observe/discover/propose/align/validate/review/publish workflows and immutable semantic releases. +- semantic-data-portal owns catalog, governance, search, serving, and consumption of released semantic resources; it does not author Orgmetra domain truth. - Naruon owns mail/calendar/file control-plane integrations. -- Contextual Orchestrator owns bounded LLM orchestration traces. +- contextual-orchestrator owns bounded LLM orchestration traces, provider discovery, capability-aware routing, and gateway contracts; Orgmetra consumes only released APIs and schemas. ## Writing guidance From 2f01935aa7eb7acdf43aa5f70f0ff650ee251ba1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 18:48:53 +0900 Subject: [PATCH 189/201] chore: reseal foundation manifest for guidance repair --- manifest.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifest.json b/manifest.json index 94e990d50..4269f1911 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"46fbdd18f514f680ec88cd5c77d765094beff78b2919d5089f30c985015e05be","bytes":462,"lines":40},{"path":"AGENTS.md","sha256":"28f7b7bc010a7739cfdc3e793fb5d39a0e74b842ea9c190e9a251e2d0cbc3a16","bytes":2246,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"add33884f466d324e20875388d103de41c6e062938a6e98727dc83a87ffe976f","bytes":1229,"lines":20},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"27af9b5fcc359a5131d146a258d55bfad5aa45c3310860821912e2446c75e0f2","bytes":12419,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} \ No newline at end of file +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"46fbdd18f514f680ec88cd5c77d765094beff78b2919d5089f30c985015e05be","bytes":462,"lines":40},{"path":"AGENTS.md","sha256":"d968907ee765f78c55683f19d478d8f05cd068de463d07fc5cf4cfde0099eb51","bytes":2358,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"a121e79f799361b4b2b01328f42df29da9f7746484e3dc7b01e6495d7fc6f33c","bytes":1566,"lines":21},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"27af9b5fcc359a5131d146a258d55bfad5aa45c3310860821912e2446c75e0f2","bytes":12419,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} \ No newline at end of file From d6f299b70cd0b3b40f8579131810c6f4f8c9cb51 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 18:49:22 +0900 Subject: [PATCH 190/201] test: run LLM routing policy regression in foundation validation --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index ceb2fb8fc..b681b5a2a 100644 --- a/package.json +++ b/package.json @@ -4,6 +4,6 @@ "private": true, "description": "Orgmetra evidence-centered HRIS foundation baseline.", "scripts": { - "validate": "python3 tests/validate_repository.py && node scripts/foundation-contract.mjs && node --test tests/foundation-contract.test.mjs tests/openapi-contract.test.mjs tests/dispatcher-inventory.test.mjs" + "validate": "python3 tests/validate_repository.py && node scripts/foundation-contract.mjs && node --test tests/foundation-contract.test.mjs tests/openapi-contract.test.mjs tests/dispatcher-inventory.test.mjs tests/llm-routing-policy.test.mjs" } } From e3ed61b65a6f90400e03ad910d3930e422519cdb Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 18:50:26 +0900 Subject: [PATCH 191/201] chore: reseal manifest for routing regression registration --- manifest.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifest.json b/manifest.json index 4269f1911..40bdab29f 100644 --- a/manifest.json +++ b/manifest.json @@ -1 +1 @@ -{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"46fbdd18f514f680ec88cd5c77d765094beff78b2919d5089f30c985015e05be","bytes":462,"lines":40},{"path":"AGENTS.md","sha256":"d968907ee765f78c55683f19d478d8f05cd068de463d07fc5cf4cfde0099eb51","bytes":2358,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"a121e79f799361b4b2b01328f42df29da9f7746484e3dc7b01e6495d7fc6f33c","bytes":1566,"lines":21},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"27af9b5fcc359a5131d146a258d55bfad5aa45c3310860821912e2446c75e0f2","bytes":12419,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"59ae9e3e67c3fba9320cb18439692395cdfd16ae5c24e3c4cf30d77d63ebabb5","bytes":388,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} \ No newline at end of file +{"package":"orgmetra-foundation-pack","version":"0.1.0","generated_for_branch":"feat/audit-outbox-envelope","files":[{"path":".github/workflows/foundation-ci.yml","sha256":"12686a3bbd6445e6fdb202b4137dae118ddeeab1efb0c7f18ea6c8fa19d62537","bytes":4379,"lines":123},{"path":".github/workflows/job-analysis-api-quality.yml","sha256":"352dc78931dd94afea3e88912d38dcc4b562a004112f199f3d7a12d22b6d637a","bytes":4159,"lines":105},{"path":".gitignore","sha256":"46fbdd18f514f680ec88cd5c77d765094beff78b2919d5089f30c985015e05be","bytes":462,"lines":40},{"path":"AGENTS.md","sha256":"d968907ee765f78c55683f19d478d8f05cd068de463d07fc5cf4cfde0099eb51","bytes":2358,"lines":34},{"path":"ARCHITECTURE.md","sha256":"52d68786f7359c1a50d804996021e4c70e90accd2fff6f1a27c91de1dd8df850","bytes":7864,"lines":107},{"path":"CHANGELOG.md","sha256":"416cdb7898d24dd265790b2ba62c47e8e20dafc737371b754ef1a53f900f63e9","bytes":17470,"lines":76},{"path":"CLAUDE.md","sha256":"a121e79f799361b4b2b01328f42df29da9f7746484e3dc7b01e6495d7fc6f33c","bytes":1566,"lines":21},{"path":"LICENSE","sha256":"cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30","bytes":11358,"lines":202},{"path":"NOTICE","sha256":"34b4618e946bdd8d33407d6ac5279f0a0388f5e7c8f79d2e7d8c3c47d0266042","bytes":305,"lines":4},{"path":"README.md","sha256":"c5d656b223df3059d0e31fff8c44322000debf925295281d0b1ea17421f0814e","bytes":3889,"lines":81},{"path":"database/migrations/0001_foundation_schema.sql","sha256":"ce2ae52fc66b2f99597ea5285df82c66f90caa46174fef4930d68a8b6177d0dd","bytes":38747,"lines":916},{"path":"database/migrations/0002_sealed_evidence_digest.sql","sha256":"93d659ca8e0e9293a83d5422d043be7b1022c5470a5b22670aa3416fa334a04c","bytes":6649,"lines":202},{"path":"database/migrations/0003_audit_outbox_persistence.sql","sha256":"2aa7bbb8220923ec584537c0cd46f0cba2b692d69d431f097b7df6db75235bfc","bytes":15417,"lines":423},{"path":"database/migrations/0004_outbox_delivery_claim.sql","sha256":"d4504acf7d58528a2a8f4f03d1584b868c8d3ba9046a007b9c2e7cfef993b2ef","bytes":9451,"lines":234},{"path":"database/migrations/0005_outbox_delivery_finalization.sql","sha256":"b7e8790595b288f752d6ef5cc6cbfe4e1b6712248f5b7a3a25fa60016b6a4961","bytes":6125,"lines":170},{"path":"database/migrations/0006_outbox_delivery_dead_letter.sql","sha256":"c1fb91cdf98169fd6684984e86cb0a14fa19c8f1226028d2346a2a069df2b3c7","bytes":24919,"lines":628},{"path":"database/migrations/0007_outbox_retry_exhaustion.sql","sha256":"812f50d70ca5929c7eba964d34a208aedee660d11cc7ffc09d67688c4737e0d5","bytes":19081,"lines":476},{"path":"database/migrations/0008_audit_outbox_review_hardening.sql","sha256":"c3713a12db9d00fdc10005df1f86c07965e9555eefad78ca67e994537a739d9b","bytes":17562,"lines":448},{"path":"database/migrations/0009_candidate_worker_conversion_governance.sql","sha256":"4030666629a6b8deb383b8337ead4f09d6a945969313def2577a38f31f06cda9","bytes":11537,"lines":281},{"path":"database/migrations/0010_validity_study_case_integrity.sql","sha256":"3f594810ac9e1a6747a2bb4838e5ce65b921cb6e3d36fcdc3ff08b4a7579ebd1","bytes":11979,"lines":313},{"path":"database/migrations/0011_criterion_observation_scope.sql","sha256":"f9fe7c35f1ee7b167e1c2ba75a50a84febda9a6ccf8123b4f5726f51968694f9","bytes":7444,"lines":165},{"path":"database/migrations/0012_people_mutation_idempotency.sql","sha256":"52dbbb9ec7f9be5291593ba88f228d7fffd736dcb99547a08c1d6cad076afb69","bytes":3162,"lines":76},{"path":"database/migrations/0013_job_analysis_snapshot.sql","sha256":"b6553a5a4c94c4aa9f341a474e13bbe34db63044eda2446b3ebee178995977ee","bytes":12713,"lines":260},{"path":"docs/API_CONTRACT.md","sha256":"63533dff785da62b89e585d742a158e2aeb05913644f2bf9fb6486f281c2e589","bytes":4555,"lines":76},{"path":"docs/DATA_MODEL.md","sha256":"6ad29731ae7ee7aa5bf3a2d0bfef88894a35a2550edb2be3244d6f143d76444a","bytes":13366,"lines":85},{"path":"docs/ERD.md","sha256":"546001aa85c4fe020e0c39d881dc860daf7f69090596666fdf9092487b0725fe","bytes":6964,"lines":70},{"path":"docs/OPERABILITY.md","sha256":"82b2d3e70cec371ef35e9e0f982ac40fef84351976bc04b863b81d27023d5a62","bytes":11189,"lines":71},{"path":"docs/PRD.md","sha256":"3ad85ae633cce0fc7a93af39b21d7a7c70bb2efa786da6b12f3c5327906e34f1","bytes":5490,"lines":111},{"path":"docs/SECURITY.md","sha256":"01918512d8882060e9cff0c4aa8206e0eccbdfb61cfd7f829331123c7a9fe6ac","bytes":11185,"lines":64},{"path":"docs/STORYBOARD.md","sha256":"6e4ffb0eb03a80343f50d363ffc43b34da9348a44232dd947a9ff416ea92a3d2","bytes":1342,"lines":28},{"path":"docs/STORYBOOK.md","sha256":"82f79029b3c2b7a45393bad5ba8fabe61014d4b6149c7d4e73f70ba447f885e9","bytes":1389,"lines":50},{"path":"docs/TEST_STRATEGY.md","sha256":"d0a0bc3b54ed0fc7973747987f1afb117d6144c390b51ed9370eb571972a33f8","bytes":16534,"lines":135},{"path":"docs/THREAT_MODEL.md","sha256":"f314f375c2e41252536de224c7bc7e4a10ab8f340cb86642724e7399e32f4252","bytes":6736,"lines":23},{"path":"docs/TRACEABILITY.md","sha256":"27af9b5fcc359a5131d146a258d55bfad5aa45c3310860821912e2446c75e0f2","bytes":12419,"lines":42},{"path":"docs/TRD.md","sha256":"23697d88a4882698e1a2782b7da3f2ccd0d3cd2d6d1bffe89b6597dc16851077","bytes":9064,"lines":101},{"path":"docs/UML.md","sha256":"fe67c37aa88e5814ceb2db7e8f7d8d85ca27a994802efbb7c75164b387adf0a9","bytes":5528,"lines":122},{"path":"docs/USER_STORIES.md","sha256":"5535b39d8c71a36c81f78e2d6dbd90a2d32e6541790f0d28f6dd4baf3ea7b45f","bytes":2670,"lines":37},{"path":"docs/WIREFRAMES.md","sha256":"b03aa6419aeaf5d42a5698c4d43a434c1633b7ac6fd0b0bd0cda979077adc56e","bytes":2005,"lines":77},{"path":"docs/adr/0001-orgmetra-authoritative-hris-record.md","sha256":"0f8055b73c63d3130321415ad53233588ff952aabd1a88952b39c71747253572","bytes":6108,"lines":53},{"path":"docs/adr/0002-federated-cwl-integration-boundaries.md","sha256":"b77165f2aacfa6f4fde994baf77d5879c6da3e8dae4fd2db0ed912d60ae9b3b2","bytes":4072,"lines":44},{"path":"docs/adr/0003-bitemporal-hris-data-contract.md","sha256":"d7f2660616622c1a7994b28aa66d99d13836bcf755735595f9609a41282ab799","bytes":4453,"lines":47},{"path":"docs/adr/0004-employment-position-version-and-assignment-binding.md","sha256":"fee89e700414abe0b1cffec2acc687e5e014634db8f5ef9e8a92abba5c3cf182","bytes":1872,"lines":30},{"path":"docs/adr/0005-exclusive-employment-and-staffable-seats.md","sha256":"10f0eb409f4fa32d2c5bed2d583d8b43be8e61b5cbef0e927e5bebb5f5c8f85b","bytes":2091,"lines":34},{"path":"docs/adr/0006-governed-audit-outbox-envelope.md","sha256":"987a6f613501d0825fff8682c80d20468cbedf797559bf950a7ea0ca18f6dcf9","bytes":14046,"lines":66},{"path":"docs/adr/0007-governed-job-analysis-evidence.md","sha256":"0996bb1162d6a5e544d6efa8c66f17f03060a5ed38d5145bd8ed23c719dd77e5","bytes":5643,"lines":57},{"path":"docs/adr/0008-purpose-bound-pii-authorization.md","sha256":"c5157d3bc58f3d8d29e03104dd15eb2911cc1bb66e2c92a935b26d7164648dc7","bytes":5988,"lines":55},{"path":"docs/adr/0009-performance-criterion-observation-scope.md","sha256":"5ff47b4e579126e2d32ccd6d4c0e04f806686a4143a749bb14b60aa0ab43cb8e","bytes":7080,"lines":57},{"path":"docs/adr/0010-naruon-calendar-intent-boundary.md","sha256":"ca3cd67b226dbbc89a29598531b272cc208d9408beff012994f5dc3e23812d0e","bytes":3835,"lines":35},{"path":"docs/adr/0011-bitemporal-workforce-composition.md","sha256":"1bb7fa543d4a8ec03f076d3c88ad50181a145e554c9ec2fd5bd86e58e9c50103","bytes":5482,"lines":53},{"path":"docs/adr/0012-governed-migration-handoff.md","sha256":"cfe3e8f556e64a57a68ce676201929a5c2a48b9d13840056817dfe7729af1dbc","bytes":5887,"lines":59},{"path":"docs/adr/0013-governed-requisition-review-packet.md","sha256":"2ff83ca71f53993cf423b0336161f6cfba794181333a765165656517b128cd48","bytes":4704,"lines":46},{"path":"docs/adr/0014-job-analysis-snapshot-persistence.md","sha256":"d6d71187c4bae68b4b5555e3d74f3a243bef8f75192425b3a303baf6b371e26d","bytes":5356,"lines":49},{"path":"docs/adr/README.md","sha256":"f390154b397d57ba2b92deff74092968269a951249494c662d83e8add0cd68af","bytes":2028,"lines":20},{"path":"docs/doctoring/REFERENCES.md","sha256":"929f7ee36df16279f028f726fcf039982180deb377746fe3804f3c0d090778d5","bytes":6352,"lines":69},{"path":"docs/superpowers/plans/2026-08-15-orgmetra-foundation-implementation-plan.md","sha256":"b64f21abb19373e780db8b9e64deb8ba9a6219ccf9625a651f25407b8691fcbd","bytes":8227,"lines":226},{"path":"docs/superpowers/specs/2026-08-15-orgmetra-foundation-design.md","sha256":"4a0e1a7943e40d12bd3082db3757045b4085e5a089fea7bc0d8a1565ffcbcf1d","bytes":6237,"lines":187},{"path":"package.json","sha256":"e7a2b82f99f76bf795d3f88dd8ab3bfebc2372f4cc41e4c0b3b6b2ab0eb81cac","bytes":422,"lines":9},{"path":"packages/hris-kernel/src/orgmetra_hris_kernel/audit.py","sha256":"3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190","bytes":7707,"lines":160},{"path":"packages/hris-kernel/tests/test_audit_outbox.py","sha256":"5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c","bytes":7556,"lines":200},{"path":"schemas/openapi.yaml","sha256":"09c1e43486779198574fe31b8bcabbd1c1f74beec7bf86245ae578061619838f","bytes":29503,"lines":1020},{"path":"scripts/foundation-contract-core.mjs","sha256":"595e8381dbd62e97093b11eef818af5f04d6473ac592d57e3985ffbc2210d445","bytes":28173,"lines":689},{"path":"scripts/foundation-contract.mjs","sha256":"5242dcdbe0935775edf074462c82600e9bc4927d9fdc50c47727af915fd4b23a","bytes":218,"lines":6},{"path":"tests/dispatcher-inventory.test.mjs","sha256":"09f5e64410e6b7a26bf8d6ce61c50b737da2ea85d955f91eba63aa21f1537261","bytes":1597,"lines":34},{"path":"tests/foundation-contract.test.mjs","sha256":"960306fd7cda7b982a52c4428a432d10a4f570430a5d39fb23aeca0b2ede0615","bytes":14860,"lines":386},{"path":"tests/openapi-contract.test.mjs","sha256":"80c1610ef1c189fa325e55389501e0e51531ddf61ee335bb94d9cb3aa55a9fdc","bytes":6438,"lines":195},{"path":"tests/test_audit_outbox_hardening_postgres.sh","sha256":"518ba2f37ba6292943e5abe22c2599452b2f031a42e453b2493aedf8714421a0","bytes":13396,"lines":333},{"path":"tests/test_audit_outbox_postgres.sh","sha256":"e57a04920a0ba97fa6a06752d15ea150016ab8d44099e998c5c4f4067592b4d2","bytes":13443,"lines":357},{"path":"tests/test_bitemporal_postgres.sh","sha256":"7684b8c2ff52c044c081135515bd5aabbfd00e2daad0d471b0868701af2df6cc","bytes":8209,"lines":230},{"path":"tests/test_candidate_worker_conversion_postgres.sh","sha256":"681cb74d6cfa859ed92c6c2439881ea20c430ef8df94ec662e2807761a377f90","bytes":14673,"lines":344},{"path":"tests/test_criterion_observation_scope_postgres.sh","sha256":"0ee9539ee57f840c27d08009f7868cdc8662669df78a01dbc8be39216b8f1a3d","bytes":17811,"lines":469},{"path":"tests/test_evidence_sealing_postgres.sh","sha256":"57d16b632a0c60ffdcb4842ceb1cfe25d19c54cefeeefb622ff4fa6e83441ad7","bytes":11349,"lines":370},{"path":"tests/test_job_analysis_snapshot_postgres.sh","sha256":"ca9c323a1dd68cfc520277efbbb7495e37fb3ca027890928c8624e5b4f57403f","bytes":13542,"lines":296},{"path":"tests/test_operational_uuid_postgres.sh","sha256":"7378f98f0d4b3000e8ea641d8701f1540dbad71410b3637d81d799969e0f6ff7","bytes":3346,"lines":101},{"path":"tests/test_outbox_claim_postgres.sh","sha256":"1027806d436ebfe34e108c25b6a4001f43b9550f1d70057c6c0d7974323b0c9b","bytes":14817,"lines":429},{"path":"tests/test_outbox_dead_letter_postgres.sh","sha256":"0d728d578e64252e6079f2d141ddaa7fa9cfbf9784e625832273596d69a6e13d","bytes":14008,"lines":377},{"path":"tests/test_people_mutation_idempotency_postgres.sh","sha256":"3f57e12f80bd1b034c9aac54b669d8530106e3e26b3795689671fb53807b3cd5","bytes":16191,"lines":381},{"path":"tests/test_tenant_isolation_postgres.sh","sha256":"dd649435ef8ab9e57f0609c101917e36656a6d40d63de9bcdbdac23d764f6c3a","bytes":15134,"lines":388},{"path":"tests/test_validity_study_case_postgres.sh","sha256":"0070ad58300323c7f9900c5645e0df3106b36ccd245ae686e982c2fd6fa4dc02","bytes":14708,"lines":301},{"path":"tests/validate_repository.py","sha256":"918cf92fd18d81572e9bd5f5daa7f033c32731e2e13f0d00661d1c1de30b12a9","bytes":27291,"lines":638}]} \ No newline at end of file From 2ca0e6a441017390693a1a06ef8212a7da251ea8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 23:30:12 +0900 Subject: [PATCH 192/201] docs(gaps): refresh governance and security owner truth --- docs/product-technical-gap-baseline.md | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d8e1026ea..08d3f186b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -103,19 +103,19 @@ This is not the current governance decision. `.github#772` establishes that the - no routine `OrganizationAdmin/always` bypass; emergency repair belongs to a separately governed, time-bounded, auditable break-glass path; and - only merge and squash are accepted by the current audit; merge-method policy must not be weakened merely to solve the reviewer-capacity problem. -Causal owner: `ContextualWisdomLab/.github`. Issue #772 defines the satisfiable one-human policy, #1351 tracks fleet reconciliation, and #1176 remains the canonical audit contract. **Active owner-plane successor PR #1644 now adds the missing reviewed mutation path** instead of relying on an application connector that can only read rulesets. It pins exactly rulesets 17921150 and 18156473, refuses identity/provenance drift, preserves unrelated controls, binds privileged mutation to the exact protected-main SHA, verifies immutable ruleset history, treats ambiguous PUT outcomes as unresolved until history/live-state evidence proves convergence, and uses a separately provisioned protected-environment `CWL_RULESET_ADMIN_TOKEN` rather than widening ordinary repository credentials. Source integration alone is intentionally insufficient: after #1644 reaches protected `main`, a controlled maintenance interval must provision the least-privilege owner-plane credential, enable `CWL_RULESET_RECONCILE_ENABLED`, perform and verify the mutation, disable/retain the reconciler according to the reviewed drift-repair policy, and then re-run the canonical audit plus Orgmetra canary. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. +Causal owner: `ContextualWisdomLab/.github`. Issue #772 defines the satisfiable one-human policy and #1351 tracks fleet reconciliation. Retired #1176 is predecessor evidence only after verified complete carryover of every valid audit delta into the single active owner-plane/audit writer, **PR #1644**. PR #1644 pins exactly rulesets 17921150 and 18156473, refuses identity/provenance drift, preserves unrelated controls, binds privileged mutation to the exact protected-main SHA, verifies immutable ruleset history, treats ambiguous PUT outcomes as unresolved until history/live-state evidence proves convergence, and uses a separately provisioned protected-environment `CWL_RULESET_ADMIN_TOKEN` rather than widening ordinary repository credentials. Its current exact-head focused governance suite has reached terminal success after non-force reconciliation with protected `main`, while the broader security fleet remains non-terminal; focused success is not full merge authority. Source integration alone is intentionally insufficient: after #1644 reaches protected `main`, a controlled maintenance interval must provision the least-privilege owner-plane credential, enable `CWL_RULESET_RECONCILE_ENABLED`, perform and verify the mutation, disable/retain the reconciler according to the reviewed drift-repair policy, and then re-run the canonical audit plus Orgmetra canary. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. -The #1644 focused owner-plane suite exposed deterministic test-contract drift on a predecessor exact head rather than an authorization failure. The writer branch repaired the logged failures by making merge-method fixtures include explicit CODEOWNER=false, registering dynamically loaded Python 3.12 dataclass modules in `sys.modules`, parsing the current workflow job ordering instead of assuming `validate` is first, passing the exact editable PUT projection into history-transition tests while keeping full live/history states, aligning recovery-document assertions with the newest-displaced-state contract, and preserving fail-closed code-owner drift when review parameters are malformed. A fresh successor exact-head owner-plane run is required; predecessor failures do not transfer. +The #1644 owner-plane lineage has already repaired deterministic test-contract drift, collision/recovery ambiguity, post-settlement version races, and protected-main integration without force-push. Every later protected-main reconciliation resets exact-head evidence, so only the current unchanged writer head may authorize ordinary integration. Completed one-shot source-fix machinery is absent from the current owner tree. -**Canary:** Orgmetra PR #88 (`fix/job-analysis-http-request-budgets`) was freshly re-verified on exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd`; the currently returned repository workflow runs are terminal-success, combined CodeRabbit/Devin statuses are successful, and its only inline review thread is resolved. It has no qualifying independent approval. It is intentionally retained as a governance canary: after the central policy repair, an unchanged sole-author GREEN PR must no longer be blocked *only* by a reviewer identity that does not exist. Do not merge it through administrator bypass to fake that proof. +**Canary:** Orgmetra PR #88 (`fix/job-analysis-http-request-budgets`) was freshly re-verified on exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd`; the currently returned repository workflow runs are terminal-success, combined CodeRabbit/Devin statuses are successful, and its only inline review thread is resolved. It has no qualifying independent approval. It is intentionally retained as a governance canary: after the central policy repair, an unchanged sole-author GREEN PR must no longer be blocked *only* by a reviewer identity that does not exist. Repository-native auto-merge is currently disabled for Orgmetra, so that setting cannot be used to disguise the admission defect. Do not merge it through administrator bypass to fake that proof. ## 6. Required-workflow availability: P0 evidence blocker -The central Dependency Review workflow now correctly fails closed: it proceeds to the pinned GitHub Dependency Review action only after an exact `BASE_SHA...HEAD_SHA` dependency comparison returns transport success and HTTP `200`. +The central Dependency Review workflow must fail closed: it may proceed to the pinned GitHub Dependency Review action only after an exact immutable `BASE_SHA...HEAD_SHA` dependency comparison returns transport success and authenticated HTTP `200`. -Fresh current-head evidence again reproduced the incident on a public, non-fork Orgmetra PR: exact head checkout and SHA verification succeeded on an Ubuntu 24.04 hosted runner; the comparison transport succeeded (`curl_exit=0`) but GitHub returned HTTP `403`, so the Dependency Review action was correctly skipped and the job failed closed. Independent OSV, Trivy and Scorecard jobs on that same Security run succeeded. This remains **missing authoritative dependency-diff evidence**, not a clean review, and those independent scanners are not semantic substitutes for Dependency Review. +The temporary `.github#1643` diagnostic completed its evidentiary purpose: on one unchanged exact-head A/B canary, the anonymous dependency comparison returned HTTP `404` while the same exact repository/base/head comparison using a minimally scoped job token with `contents: read` + `pull-requests: read` returned HTTP `200`, both with successful transport. Therefore anonymous responses are not availability authority. The canonical current owner is Draft **`.github#1725`**, which carries the valid diagnostic deltas without the temporary canary: reusable callers explicitly grant the least-privilege permission envelope, repository/base/head values must be legal immutable identities before transport, only authenticated HTTP 200 authorizes `actions/dependency-review-action`, and every authenticated non-200 remains fail-closed. Exact-head security evidence for #1725 remains non-terminal, so none of this owner repair is protected/released truth yet. -Causal owner/incident: `.github#810`. The original fail-open source defect is already repaired; active central PR #1643 owns an identity-hardening and temporary anonymous-vs-minimally-scoped-token A/B diagnostic. The diagnostic must execute on its unchanged exact head before its temporary canary workflow is removed. The remaining acceptance is an authorized GitHub/account/repository availability or configuration repair followed by an unchanged public non-fork canary where the exact comparison returns `200` and the pinned Dependency Review action actually executes. Do not infer the root cause from the status code alone, weaken the gate, or create an Orgmetra-specific skip. +Orgmetra must not infer a clean dependency review from independent OSV, Trivy or Scorecard success, and it must not create a leaf skip. After #1725 reaches protected `ContextualWisdomLab/.github/main` through ordinary protection, consumers must pin the released immutable owner workflow identity and prove an unchanged public non-fork exact comparison returns HTTP 200 and the pinned Dependency Review action materially executes. ## 7. Current baseline-writer evidence @@ -127,8 +127,8 @@ Do **not** store PR #100's own current head inside this file: changing this file | Gap | Current evidence | Buyer consequence | Owner / next acceptance evidence | Priority | | --- | --- | --- | --- | --- | -| **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; #1176 defines the canonical audit and active #1644 now implements the separately privileged, history-verified owner-plane reconciliation path | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351`, audit PR #1176, owner-plane PR #1644; terminal exact-head source evidence → protected-main integration → least-privilege maintenance apply → full live post-change reads + canonical audit + unchanged Orgmetra #88 canary | **P0** | -| **SEC-01 authoritative Dependency Review availability** | exact public comparisons repeatedly return 403; central gate correctly fails closed; #1643 owns an unchanged-head anonymous/token A/B diagnostic that remains evidence-only until it runs | merge queue can remain blocked without trustworthy dependency diff | `.github#810`, PR #1643; capture decisive A/B evidence, remove the temporary canary workflow, then prove an unchanged public non-fork exact comparison returns 200 and pinned action executes | **P0** | +| **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; retired #1176 has transferred its valid audit deltas into active #1644, whose focused current-head governance validation succeeds while broader evidence remains non-terminal | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351/#1644`; terminal unchanged-head evidence → protected-main integration → least-privilege maintenance apply → immutable-history/full live-payload convergence → canonical audit + unchanged Orgmetra #88 ordinary-path proof | **P0** | +| **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | | **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane and remain non-shipped while current exact-head evidence is non-terminal | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #162/#163; integrate explicit category across domain/API/PostgreSQL/OpenAPI with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification, then prove exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | From 465abcb6c1d021f3d0aa6b94468adf1bc848502d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 13:11:26 +0900 Subject: [PATCH 193/201] docs(gaps): add assignment correction provenance gap --- docs/product-technical-gap-baseline.md | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 08d3f186b..6da2acd08 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product and technical gap baseline -Verified: 2026-09-02 (Asia/Seoul). +Verified: 2026-09-03 (Asia/Seoul) for Orgmetra protected/product refs. External owner-repository evidence retains its separately dated doctoring until re-fetched in that owner lane. This document is the commercialization baseline for **Orgmetra**, not a frozen PR inventory and not merge authorization. It records product responsibility, shipped-vs-planned truth, causal control-plane blockers, and the next highest-leverage buyer gaps. Volatile PR heads, workflow run IDs, queue counts, review snapshots, mergeability, and base tips must be fetched live before every action rather than copied here until stale. @@ -56,7 +56,7 @@ The initial deployment may share one PostgreSQL cluster, but each bounded contex ## 4. Current protected-branch product truth -Protected `develop` was freshly observed at `9e3e4847510e1e612b48474ba42b177b8ed824df`. This SHA is a dated evidence anchor only; every execution loop must re-fetch the branch before acting. +Protected `develop` was freshly observed at `5c5cd3258c34fd2cbbdacd7420afd05f2617aa29`. This SHA is a dated evidence anchor only; every execution loop must re-fetch the branch before acting. The protected change since the prior baseline anchor is CI admission only: Foundation CI and Recovery Rehearsal Quality now skip docs-only changes. It does not promote any pending HR domain feature to Shipped truth. Shipped foundation evidence includes: @@ -68,6 +68,8 @@ Shipped foundation evidence includes: Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. +Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision runtime subtypes before semantic replay or database I/O. It remains downstream of #163 and has non-terminal exact-head hosted evidence, so correction provenance is **Active PR**, not Shipped truth. + The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. There are currently no published GitHub releases. Do not manufacture a release merely to clear that count; release only when an integrated protected head has complete exact-head governance, security, operability and buyer-workflow evidence. @@ -76,7 +78,7 @@ There are currently no published GitHub releases. Do not manufacture a release m The effective control plane for Orgmetra `develop` is inherited organization ruleset **18156473 — `CWL Central required workflows`**. Classic branch-protection fields alone are not authoritative while that ruleset is active. -Fresh live reads on 2026-09-02 show the inherited ruleset still has: +Fresh Orgmetra live reads on 2026-09-03 show the inherited ruleset still has: - `required_approving_review_count = 1`; - `require_last_push_approval = false`; @@ -119,7 +121,7 @@ Orgmetra must not infer a clean dependency review from independent OSV, Trivy or ## 7. Current baseline-writer evidence -PR #100 owns this baseline. A predecessor exact head failed Foundation/Recovery-family repository-contract checks after `.codegraph/` was added to `.gitignore` without resealing `manifest.json`. The owner branch was repaired by resealing only the `.gitignore` manifest entry to the exact current digest/size/line count. +PR #100 owns this baseline. A predecessor exact head failed Foundation/Recovery-family repository-contract checks after `.codegraph/` was added to `.gitignore` without resealing `manifest.json`. The owner branch was repaired by resealing only the `.gitignore` manifest entry to the exact current digest/size/line count. The owner branch has now also adopted protected #166's two CI admission changes as a two-parent non-force merge before this baseline update, so it is not knowingly carrying the stale pre-#166 protected tree. Do **not** store PR #100's own current head inside this file: changing this file creates a new head and would make the value self-invalidating. Its PR body and GitHub API are the source for exact-current-head verification. All reviews/checks must be re-fetched after every push. @@ -131,6 +133,7 @@ Do **not** store PR #100's own current head inside this file: changing this file | **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | | **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane and remain non-shipped while current exact-head evidence is non-terminal | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #162/#163; integrate explicit category across domain/API/PostgreSQL/OpenAPI with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification, then prove exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence | **P1 buyer truth** | +| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; current exact head remains downstream of #163 with queued hosted evidence | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #163 first → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | | **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | | **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | @@ -200,4 +203,4 @@ A commercial release is allowed only from one freshly fetched protected `develop - release version and CHANGELOG identify the exact protected commit and migration/API compatibility; and - no temporary self-modifying/source-fix workflow remains. -Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. \ No newline at end of file +Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. From 56887f65b9fd03db5eec3c8fb321f79a5b040149 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 14:41:00 +0900 Subject: [PATCH 194/201] docs(gaps): align protected workflow and correction time truth --- docs/product-technical-gap-baseline.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6da2acd08..7752c8542 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -56,7 +56,7 @@ The initial deployment may share one PostgreSQL cluster, but each bounded contex ## 4. Current protected-branch product truth -Protected `develop` was freshly observed at `5c5cd3258c34fd2cbbdacd7420afd05f2617aa29`. This SHA is a dated evidence anchor only; every execution loop must re-fetch the branch before acting. The protected change since the prior baseline anchor is CI admission only: Foundation CI and Recovery Rehearsal Quality now skip docs-only changes. It does not promote any pending HR domain feature to Shipped truth. +Protected `develop` was freshly observed at `ef1b143368cb6249c9520ca8cae10ebe844a5aa1`. This SHA is a dated evidence anchor only; every execution loop must re-fetch the branch before acting. The latest protected change restores Foundation CI and Recovery Rehearsal Quality documentation-content checks after the preceding docs-only path exclusions proved unsound: both workflows hash or otherwise validate governed documentation/traceability artifacts, so docs-only changes must remain in their admission scope. This protected workflow repair does not promote any pending HR domain feature to Shipped truth. Shipped foundation evidence includes: @@ -66,9 +66,9 @@ Shipped foundation evidence includes: - Keyverse/Naruon/migration adapter boundaries and design-token foundations; and - PRD/TRD/ADR/UML/ERD/security/test/operability documentation sufficient to define intended modular boundaries. -Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. +Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. The #163 branch has non-force adopted the current protected workflow truth rather than retaining the superseded docs-only exclusions. -Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision runtime subtypes before semantic replay or database I/O. It remains downstream of #163 and has non-terminal exact-head hosted evidence, so correction provenance is **Active PR**, not Shipped truth. +Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. @@ -121,7 +121,7 @@ Orgmetra must not infer a clean dependency review from independent OSV, Trivy or ## 7. Current baseline-writer evidence -PR #100 owns this baseline. A predecessor exact head failed Foundation/Recovery-family repository-contract checks after `.codegraph/` was added to `.gitignore` without resealing `manifest.json`. The owner branch was repaired by resealing only the `.gitignore` manifest entry to the exact current digest/size/line count. The owner branch has now also adopted protected #166's two CI admission changes as a two-parent non-force merge before this baseline update, so it is not knowingly carrying the stale pre-#166 protected tree. +PR #100 owns this baseline. A predecessor exact head failed Foundation/Recovery-family repository-contract checks after `.codegraph/` was added to `.gitignore` without resealing `manifest.json`. The owner branch was repaired by resealing only the `.gitignore` manifest entry to the exact current digest/size/line count. The branch has now non-force adopted protected `develop@ef1b143368cb6249c9520ca8cae10ebe844a5aa1` through a two-parent merge. That protected change reverts #166's docs-only workflow exclusions because Foundation and recovery admission contain documentation-content contracts; the baseline therefore no longer carries or describes those exclusions as current truth. Do **not** store PR #100's own current head inside this file: changing this file creates a new head and would make the value self-invalidating. Its PR body and GitHub API are the source for exact-current-head verification. All reviews/checks must be re-fetched after every push. @@ -132,8 +132,8 @@ Do **not** store PR #100's own current head inside this file: changing this file | **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; retired #1176 has transferred its valid audit deltas into active #1644, whose focused current-head governance validation succeeds while broader evidence remains non-terminal | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351/#1644`; terminal unchanged-head evidence → protected-main integration → least-privilege maintenance apply → immutable-history/full live-payload convergence → canonical audit + unchanged Orgmetra #88 ordinary-path proof | **P0** | | **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | -| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane and remain non-shipped while current exact-head evidence is non-terminal | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #162/#163; integrate explicit category across domain/API/PostgreSQL/OpenAPI with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification, then prove exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence | **P1 buyer truth** | -| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; current exact head remains downstream of #163 with queued hosted evidence | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #163 first → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | +| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #162/#163; integrate explicit category across domain/API/PostgreSQL/OpenAPI with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification, then prove exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence | **P1 buyer truth** | +| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; the dedicated exact-head workflow executes the regression, but the child remains downstream of #163 with non-terminal hosted evidence | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #163 first → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | | **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | | **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | From c976ab4bb4c44803ce5415b46aa05cd6887e1834 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 15:34:44 +0900 Subject: [PATCH 195/201] docs: record canonical People runtime prerequisites --- docs/product-technical-gap-baseline.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7752c8542..b35cff7ca 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -68,7 +68,9 @@ Shipped foundation evidence includes: Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. The #163 branch has non-force adopted the current protected workflow truth rather than retaining the superseded docs-only exclusions. -Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. +Fresh owner-path review found two shared runtime-integrity prerequisites that sit below the Assignment feature and therefore must not be copied into #163/#165. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities, and it has non-force adopted current protected `develop`. Draft PR #65 is the canonical purpose-bound authorization-evidence owner: a new test-first repair proves that exact class identity alone was insufficient because an exact `AuthorizationDecision` could still contain runtime-confusing boolean/UUID/string/frozenset evidence or an inconsistent target/verdict; the owner now validates those fields at construction. Both remain **Active PR**, not protected truth. The correct causal order is #64/#65 ordinary protected integration → non-force adoption by #163 → #163 integration → non-force adoption by #165. Assignment branches must not depend on either mutable owner branch as though it were a released contract. + +Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #64/#65/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. @@ -132,15 +134,15 @@ Do **not** store PR #100's own current head inside this file: changing this file | **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; retired #1176 has transferred its valid audit deltas into active #1644, whose focused current-head governance validation succeeds while broader evidence remains non-terminal | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351/#1644`; terminal unchanged-head evidence → protected-main integration → least-privilege maintenance apply → immutable-history/full live-payload convergence → canonical audit + unchanged Orgmetra #88 ordinary-path proof | **P0** | | **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | -| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #162/#163; integrate explicit category across domain/API/PostgreSQL/OpenAPI with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification, then prove exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence | **P1 buyer truth** | -| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; the dedicated exact-head workflow executes the regression, but the child remains downstream of #163 with non-terminal hosted evidence | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #163 first → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | +| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; generic mutation/authz runtime hardening remains in canonical Draft owners #64/#65 | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #64/#65 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | +| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #64/#65 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #64/#65 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | | **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | | **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | | **OPS-01 commercial operability/SLO proof** | test/operability docs exist, but no released integrated web service proves buyer traffic characteristics | enterprise buyer lacks capacity/recovery evidence | compose deployment; Podman/Colima portability; async request handling; k6 per-page p95 ≤20 ms; recovery/backup/restore evidence; resource auto-tuning where required | **P1** | | **SEC-02 certification-ready control evidence** | purpose-bound PII/RLS/audit contracts exist; certification is not claimed | security review still needs traceable operational evidence | NIST/SOC 2/CSAP control mapping, key management, retention/export/delete, break-glass, incident/recovery evidence; no indiscriminate PII masking | **P1** | | **DATA-01 schema/name/persistence audit** | strong normalized temporal schema exists but every new migration/PR can introduce naming, hot-partition, lock or UPSERT drift | latent data debt can become irreversible after adoption | automated audit for at-least-two-token domain/DB identifiers where semantically required, snake_case default, 3NF ownership, per-item UPSERT/idempotency, partition/lock strategy | **P1 continuous** | -| **SCI-01 Rust scientific compute boundary** | TRD correctly reserves material mathematical/psychometric kernels for Rust; current HRIS packages are mainly governance/domain code | future analytics can regress into slow or unauditable Python numerics | every material math/psychometric/EDA/vector/matrix/token-size core is Rust or behind an explicit Rust API; CPU multithreading and justified GPU parity fixtures | **P1 continuous** | +| **SCI-01 Rust scientific compute boundary** | TRD correctly reserves material mathematical/psychometric kernels for Rust; current HRIS packages are mainly governance/domain code | future analytics can regress into slow or unauditable Python numerics | every material math/psychometric/EDA/vector/linear/matrix/token-size core is Rust or behind an explicit Rust API; CPU multithreading and justified GPU parity fixtures | **P1 continuous** | ## 9. Next product loop after P0 governance repair @@ -203,4 +205,4 @@ A commercial release is allowed only from one freshly fetched protected `develop - release version and CHANGELOG identify the exact protected commit and migration/API compatibility; and - no temporary self-modifying/source-fix workflow remains. -Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. +Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. \ No newline at end of file From 55de0cfda91f6b34e6a8802714b85046160a29cb Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 15:41:06 +0900 Subject: [PATCH 196/201] docs: add canonical runner prerequisite to commercialization order --- docs/product-technical-gap-baseline.md | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b35cff7ca..af54db61b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -68,9 +68,9 @@ Shipped foundation evidence includes: Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. The #163 branch has non-force adopted the current protected workflow truth rather than retaining the superseded docs-only exclusions. -Fresh owner-path review found two shared runtime-integrity prerequisites that sit below the Assignment feature and therefore must not be copied into #163/#165. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities, and it has non-force adopted current protected `develop`. Draft PR #65 is the canonical purpose-bound authorization-evidence owner: a new test-first repair proves that exact class identity alone was insufficient because an exact `AuthorizationDecision` could still contain runtime-confusing boolean/UUID/string/frozenset evidence or an inconsistent target/verdict; the owner now validates those fields at construction. Both remain **Active PR**, not protected truth. The correct causal order is #64/#65 ordinary protected integration → non-force adoption by #163 → #163 integration → non-force adoption by #165. Assignment branches must not depend on either mutable owner branch as though it were a released contract. +Fresh owner-path review found three shared prerequisites below the Assignment feature that must remain in canonical owners rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization-evidence owner: test-first repair proves exact class identity alone was insufficient because exact decisions could contain runtime-confusing evidence or contradictory verdict/reason polarity; the owner validates those values while keeping bounded recovery guidance non-authoritative. All three remain **Active PR**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. -Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #64/#65/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. +Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #161/#64/#65/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. @@ -115,6 +115,8 @@ The #1644 owner-plane lineage has already repaired deterministic test-contract d ## 6. Required-workflow availability: P0 evidence blocker +Repository-local workflow determinism and organization-owned dependency evidence are separate gates. Orgmetra Draft PR #161 owns the repository-local selector repair: every repository-owned runner job uses explicit `ubuntu-24.04`, a test rejects reintroduction of `ubuntu-latest`, and earlier exact heads acquired hosted runners and reached repository-owned GREEN. Its current exact head has the corrected labels but remains queued before checkout with no runner assigned. Therefore #161 is necessary to remove a moving runner alias, but it does not by itself repair the current shared Actions admission queue. Consumer/feature PRs must not copy the workflow diff or generate no-op commits to simulate execution; integrate #161 normally when current-head evidence permits and then let descendants adopt protected truth. + The central Dependency Review workflow must fail closed: it may proceed to the pinned GitHub Dependency Review action only after an exact immutable `BASE_SHA...HEAD_SHA` dependency comparison returns transport success and authenticated HTTP `200`. The temporary `.github#1643` diagnostic completed its evidentiary purpose: on one unchanged exact-head A/B canary, the anonymous dependency comparison returned HTTP `404` while the same exact repository/base/head comparison using a minimally scoped job token with `contents: read` + `pull-requests: read` returned HTTP `200`, both with successful transport. Therefore anonymous responses are not availability authority. The canonical current owner is Draft **`.github#1725`**, which carries the valid diagnostic deltas without the temporary canary: reusable callers explicitly grant the least-privilege permission envelope, repository/base/head values must be legal immutable identities before transport, only authenticated HTTP 200 authorizes `actions/dependency-review-action`, and every authenticated non-200 remains fail-closed. Exact-head security evidence for #1725 remains non-terminal, so none of this owner repair is protected/released truth yet. @@ -132,10 +134,11 @@ Do **not** store PR #100's own current head inside this file: changing this file | Gap | Current evidence | Buyer consequence | Owner / next acceptance evidence | Priority | | --- | --- | --- | --- | --- | | **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; retired #1176 has transferred its valid audit deltas into active #1644, whose focused current-head governance validation succeeds while broader evidence remains non-terminal | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351/#1644`; terminal unchanged-head evidence → protected-main integration → least-privilege maintenance apply → immutable-history/full live-payload convergence → canonical audit + unchanged Orgmetra #88 ordinary-path proof | **P0** | +| **RUN-01 deterministic repository runner selection** | protected Orgmetra workflows still use moving `ubuntu-latest`; Draft #161 replaces every repository-owned selector with explicit `ubuntu-24.04` and has historical runner-acquisition/GREEN evidence, while its current exact-head jobs remain unassigned before checkout | product/security evidence can be ambiguous about runner image and is currently unavailable through the shared queue | Orgmetra #161; exact-head explicit-image regression + material hosted execution → ordinary protected integration → descendant non-force protected adoption; shared admission failure remains a separate owner-plane incident | **P0 evidence** | | **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | -| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; generic mutation/authz runtime hardening remains in canonical Draft owners #64/#65 | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #64/#65 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | -| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #64/#65 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #64/#65 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | +| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; runner/mutation/authz prerequisites remain in canonical Draft owners #161/#64/#65 | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #161 then #64/#65 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | +| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #161/#64/#65 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #161/#64/#65 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | | **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | | **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | From 5e03ac25bdf3bb6f4ee9e6ee68722429e2cb56b8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 17:26:52 +0900 Subject: [PATCH 197/201] docs: track authorization input integrity --- docs/product-technical-gap-baseline.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index af54db61b..408275fcc 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -68,9 +68,9 @@ Shipped foundation evidence includes: Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. The #163 branch has non-force adopted the current protected workflow truth rather than retaining the superseded docs-only exclusions. -Fresh owner-path review found three shared prerequisites below the Assignment feature that must remain in canonical owners rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization-evidence owner: test-first repair proves exact class identity alone was insufficient because exact decisions could contain runtime-confusing evidence or contradictory verdict/reason polarity; the owner validates those values while keeping bounded recovery guidance non-authoritative. All three remain **Active PR**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. +Fresh owner-path review found three shared owner lanes below the Assignment feature that must remain canonical rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization-evidence owner: its active lineage validates exact decision values and verdict semantics, structurally detaches issued `AuthorizationDecision` evidence, binds policy/request evaluation to validated creation-time authority snapshots, and fails closed if caller-visible policy/request fields or scopes are rewritten after issuance. Issue #168 is a repair finding inside that same owner lane, not a competing Assignment implementation: test-first coverage proves that rejected direct policy/request reinitialization must be side-effect free, and the current repair rejects already-issued objects before constructor slot writes while retaining keyword construction and dataclass-style value semantics. #65/#168 still require fresh exact-head hosted/review evidence and remain **Active PR/issue**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65/#168 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. -Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #161/#64/#65/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. +Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #161/#64/#65/#168/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. @@ -137,8 +137,9 @@ Do **not** store PR #100's own current head inside this file: changing this file | **RUN-01 deterministic repository runner selection** | protected Orgmetra workflows still use moving `ubuntu-latest`; Draft #161 replaces every repository-owned selector with explicit `ubuntu-24.04` and has historical runner-acquisition/GREEN evidence, while its current exact-head jobs remain unassigned before checkout | product/security evidence can be ambiguous about runner image and is currently unavailable through the shared queue | Orgmetra #161; exact-head explicit-image regression + material hosted execution → ordinary protected integration → descendant non-force protected adoption; shared admission failure remains a separate owner-plane incident | **P0 evidence** | | **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | -| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; runner/mutation/authz prerequisites remain in canonical Draft owners #161/#64/#65 | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #161 then #64/#65 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | -| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #161/#64/#65 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #161/#64/#65 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | +| **AUTH-01 issued authorization evidence integrity** | Draft #65 owns detached `AuthorizationDecision` state plus creation-time policy/request snapshots; #168 RED/fix closes rejected direct-reinitialization side effects before any issued field write, while arbitrary low-level field rewrites remain fail-closed through snapshot comparison; current exact-head hosted/review evidence remains non-terminal | authorization may be semantically fail-closed yet still expose unstable audit/cache/log value state if rejected object mutation has side effects | Orgmetra #65/#168; fresh exact-head package/People coverage + security/review evidence → ordinary protected integration before Assignment descendants consume the contract | **P1 security foundation** | +| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; runner/mutation/authz prerequisites remain in canonical Draft owners #161/#64/#65 with #168 as an open acceptance item in the #65 lane | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #161 then #64/#65/#168 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | +| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #161/#64/#65/#168 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #161/#64/#65/#168 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | | **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | | **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | From a79f0826590140b93ee655eaca9a394dabd5c60a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 17:50:56 +0900 Subject: [PATCH 198/201] docs(product): record authorization constructor provenance gap --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 408275fcc..129c64fa4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -68,7 +68,7 @@ Shipped foundation evidence includes: Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. The #163 branch has non-force adopted the current protected workflow truth rather than retaining the superseded docs-only exclusions. -Fresh owner-path review found three shared owner lanes below the Assignment feature that must remain canonical rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization-evidence owner: its active lineage validates exact decision values and verdict semantics, structurally detaches issued `AuthorizationDecision` evidence, binds policy/request evaluation to validated creation-time authority snapshots, and fails closed if caller-visible policy/request fields or scopes are rewritten after issuance. Issue #168 is a repair finding inside that same owner lane, not a competing Assignment implementation: test-first coverage proves that rejected direct policy/request reinitialization must be side-effect free, and the current repair rejects already-issued objects before constructor slot writes while retaining keyword construction and dataclass-style value semantics. #65/#168 still require fresh exact-head hosted/review evidence and remain **Active PR/issue**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65/#168 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. +Fresh owner-path review found three shared owner lanes below the Assignment feature that must remain canonical rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization-evidence owner: its active lineage validates exact decision values and verdict semantics, structurally detaches issued `AuthorizationDecision` evidence, binds policy/request evaluation to validated creation-time authority snapshots, and fails closed if caller-visible policy/request fields or scopes are rewritten after issuance. Issue #168 is a repair finding inside that same owner lane, not a competing Assignment implementation: the first test-first repair makes rejected policy/request reinitialization side-effect free by rejecting already-issued objects before constructor slot writes; a subsequent RED proved that direct public `__post_init__` could otherwise register an exact object forged without the governed constructor, so current owner code additionally gates snapshot issuance on constructor-scoped lifecycle state that is always discarded after construction. #65/#168 still require fresh exact-head hosted/review evidence and remain **Active PR/issue**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65/#168 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #161/#64/#65/#168/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. @@ -137,7 +137,7 @@ Do **not** store PR #100's own current head inside this file: changing this file | **RUN-01 deterministic repository runner selection** | protected Orgmetra workflows still use moving `ubuntu-latest`; Draft #161 replaces every repository-owned selector with explicit `ubuntu-24.04` and has historical runner-acquisition/GREEN evidence, while its current exact-head jobs remain unassigned before checkout | product/security evidence can be ambiguous about runner image and is currently unavailable through the shared queue | Orgmetra #161; exact-head explicit-image regression + material hosted execution → ordinary protected integration → descendant non-force protected adoption; shared admission failure remains a separate owner-plane incident | **P0 evidence** | | **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | -| **AUTH-01 issued authorization evidence integrity** | Draft #65 owns detached `AuthorizationDecision` state plus creation-time policy/request snapshots; #168 RED/fix closes rejected direct-reinitialization side effects before any issued field write, while arbitrary low-level field rewrites remain fail-closed through snapshot comparison; current exact-head hosted/review evidence remains non-terminal | authorization may be semantically fail-closed yet still expose unstable audit/cache/log value state if rejected object mutation has side effects | Orgmetra #65/#168; fresh exact-head package/People coverage + security/review evidence → ordinary protected integration before Assignment descendants consume the contract | **P1 security foundation** | +| **AUTH-01 issued authorization evidence integrity** | Draft #65 owns detached `AuthorizationDecision` state plus creation-time policy/request snapshots; #168 closes rejected direct-reinitialization side effects before issued field writes and now also rejects direct lifecycle-hook issuance of exact policy/request objects that never traversed the governed constructor; arbitrary low-level field rewrites remain fail-closed through snapshot comparison; current exact-head hosted/review evidence remains non-terminal | authorization and downstream audit/cache/log evidence must not be widened or minted from an object whose governed construction/issuance provenance is absent | Orgmetra #65/#168; fresh exact-head package/People coverage + security/review evidence → ordinary protected integration before Assignment descendants consume the contract | **P1 security foundation** | | **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; runner/mutation/authz prerequisites remain in canonical Draft owners #161/#64/#65 with #168 as an open acceptance item in the #65 lane | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #161 then #64/#65/#168 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | | **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #161/#64/#65/#168 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #161/#64/#65/#168 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | From 2bd4810bb64e257527c84555c0a5e42b94755b1d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 20:02:15 +0900 Subject: [PATCH 199/201] docs(baseline): correct authorization trust boundary --- docs/product-technical-gap-baseline.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 129c64fa4..31d840a6e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -68,9 +68,9 @@ Shipped foundation evidence includes: Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. The #163 branch has non-force adopted the current protected workflow truth rather than retaining the superseded docs-only exclusions. -Fresh owner-path review found three shared owner lanes below the Assignment feature that must remain canonical rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization-evidence owner: its active lineage validates exact decision values and verdict semantics, structurally detaches issued `AuthorizationDecision` evidence, binds policy/request evaluation to validated creation-time authority snapshots, and fails closed if caller-visible policy/request fields or scopes are rewritten after issuance. Issue #168 is a repair finding inside that same owner lane, not a competing Assignment implementation: the first test-first repair makes rejected policy/request reinitialization side-effect free by rejecting already-issued objects before constructor slot writes; a subsequent RED proved that direct public `__post_init__` could otherwise register an exact object forged without the governed constructor, so current owner code additionally gates snapshot issuance on constructor-scoped lifecycle state that is always discarded after construction. #65/#168 still require fresh exact-head hosted/review evidence and remain **Active PR/issue**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65/#168 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. +Fresh owner-path review found three shared owner lanes below the Assignment feature that must remain canonical rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization owner. Its earlier #168–#171 lineage tried to make Python object-construction/registry provenance itself authorization authority; #172 proved first that module registries were writable and then, through an independent exact-head review plus closure-cell RED, that moving those registries into `__closure__` did not create a security boundary. The corrected owner contract now locates authority at the service TCB: Keyverse supplies authenticated identity/scopes, trusted Orgmetra service composition/policy sources supply HR policy, and request/model/plugin-controlled values do not. `PurposeBoundAccessPolicy` and `PurposeBoundAccessRequest` remain exact-type validated and UUID-detached, are revalidated into evaluation snapshots immediately before tenant/resource/purpose/operation/scope/field narrowing, and `AuthorizationDecision` is PII-minimized validated decision data rather than an unforgeable same-interpreter capability. Durable consumers have an explicit `validate_authorization_decision(...)` revalidation contract. No mutable module or closure registry is represented as issuance authority; arbitrary hostile same-process code is a service-compromise/isolation problem. #65/#168–#172 still require fresh exact-head hosted/review evidence and remain **Active PR/issue**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. -Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/authorization-decision/result runtime subtypes at their trust boundaries. Its correction-specific recorded-time ingress now also resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #161/#64/#65/#168/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. +Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/result runtime subtypes at their persistence/application trust boundaries. Authorization decision data consumed inside that trusted service process must be semantically revalidated against the canonical #65 contract rather than relying on Python object-construction provenance. Its correction-specific recorded-time ingress resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #161/#64/#65/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. @@ -137,9 +137,9 @@ Do **not** store PR #100's own current head inside this file: changing this file | **RUN-01 deterministic repository runner selection** | protected Orgmetra workflows still use moving `ubuntu-latest`; Draft #161 replaces every repository-owned selector with explicit `ubuntu-24.04` and has historical runner-acquisition/GREEN evidence, while its current exact-head jobs remain unassigned before checkout | product/security evidence can be ambiguous about runner image and is currently unavailable through the shared queue | Orgmetra #161; exact-head explicit-image regression + material hosted execution → ordinary protected integration → descendant non-force protected adoption; shared admission failure remains a separate owner-plane incident | **P0 evidence** | | **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | -| **AUTH-01 issued authorization evidence integrity** | Draft #65 owns detached `AuthorizationDecision` state plus creation-time policy/request snapshots; #168 closes rejected direct-reinitialization side effects before issued field writes and now also rejects direct lifecycle-hook issuance of exact policy/request objects that never traversed the governed constructor; arbitrary low-level field rewrites remain fail-closed through snapshot comparison; current exact-head hosted/review evidence remains non-terminal | authorization and downstream audit/cache/log evidence must not be widened or minted from an object whose governed construction/issuance provenance is absent | Orgmetra #65/#168; fresh exact-head package/People coverage + security/review evidence → ordinary protected integration before Assignment descendants consume the contract | **P1 security foundation** | -| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; runner/mutation/authz prerequisites remain in canonical Draft owners #161/#64/#65 with #168 as an open acceptance item in the #65 lane | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #161 then #64/#65/#168 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | -| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #161/#64/#65/#168 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #161/#64/#65/#168 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | +| **AUTH-01 purpose-bound authorization trust boundary** | Draft #65/#168–#172 retains exact tenant/resource/purpose/operation/scope/field narrowing, runtime-type validation, UUID detachment and decision semantic coherence; #172's module-registry and closure-cell REDs invalidated the earlier claim that Python object-construction/registry provenance can serve as unforgeable authority. Current owner code instead binds policy authority to trusted Orgmetra service composition/policy sources, revalidates policy/request immediately at evaluation and provides durable-consumer decision revalidation. Same-interpreter arbitrary hostile code is a service-isolation compromise, not an object-provenance condition. Exact-head hosted/review evidence remains non-terminal. | remote/request/model/plugin input must not become HR policy authority; durable consumers must not confuse validated decision data with an in-process capability; hostile executable code requires an isolation boundary | Orgmetra #65/#168–#172; fresh exact-head Keyverse/People/repository/security coverage + independent review → ordinary protected integration; quarantine/process isolation is required for intentionally hostile executable workloads | **P1 security foundation** | +| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; runner/mutation/authz prerequisites remain in canonical Draft owners #161/#64/#65 | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #161 then #64/#65 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | +| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #161/#64/#65 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #161/#64/#65 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | | **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | | **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | From e37348909661b51edb10ccabdaea790b36207df2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 21:08:57 +0900 Subject: [PATCH 200/201] docs: align AUTH-01 with Job Analysis runtime evidence --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 31d840a6e..db56c5cb3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -68,7 +68,7 @@ Shipped foundation evidence includes: Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. The #163 branch has non-force adopted the current protected workflow truth rather than retaining the superseded docs-only exclusions. -Fresh owner-path review found three shared owner lanes below the Assignment feature that must remain canonical rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization owner. Its earlier #168–#171 lineage tried to make Python object-construction/registry provenance itself authorization authority; #172 proved first that module registries were writable and then, through an independent exact-head review plus closure-cell RED, that moving those registries into `__closure__` did not create a security boundary. The corrected owner contract now locates authority at the service TCB: Keyverse supplies authenticated identity/scopes, trusted Orgmetra service composition/policy sources supply HR policy, and request/model/plugin-controlled values do not. `PurposeBoundAccessPolicy` and `PurposeBoundAccessRequest` remain exact-type validated and UUID-detached, are revalidated into evaluation snapshots immediately before tenant/resource/purpose/operation/scope/field narrowing, and `AuthorizationDecision` is PII-minimized validated decision data rather than an unforgeable same-interpreter capability. Durable consumers have an explicit `validate_authorization_decision(...)` revalidation contract. No mutable module or closure registry is represented as issuance authority; arbitrary hostile same-process code is a service-compromise/isolation problem. #65/#168–#172 still require fresh exact-head hosted/review evidence and remain **Active PR/issue**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. +Fresh owner-path review found three shared owner lanes below the Assignment feature that must remain canonical rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization and durable evidence-coherence owner. Its earlier #168–#171 lineage tried to make Python object-construction/registry provenance itself authorization authority; #172 proved first that module registries were writable and then, through an independent exact-head review plus closure-cell RED, that moving those registries into `__closure__` did not create a security boundary. The corrected owner contract now locates authority at the service TCB: Keyverse supplies authenticated identity/scopes, trusted Orgmetra service composition/policy sources supply HR policy, and request/model/plugin-controlled values do not. `PurposeBoundAccessPolicy` and `PurposeBoundAccessRequest` remain exact-type validated and UUID-detached, are revalidated into evaluation snapshots immediately before tenant/resource/purpose/operation/scope/field narrowing, and `AuthorizationDecision` is PII-minimized validated decision data rather than an unforgeable same-interpreter capability. Durable consumers have an explicit `validate_authorization_decision(...)` revalidation contract. Issue #173 extends the same trust-boundary rule into Job Analysis durable evidence: transactional audit tenant/resource/actor/purpose must agree with the write authority, `AuditOutboxEvent` is exact-type gated before field/serialization use, and `JobAnalysisSnapshot` is exact-type gated at semantic digest, PostgreSQL input, and write/read port return boundaries before authority fields or document serialization are consumed. No mutable module or closure registry is represented as issuance authority; arbitrary hostile same-process code is a service-compromise/isolation problem. #65/#168–#173 still require fresh exact-head hosted/review evidence and remain **Active PR/issue**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/result runtime subtypes at their persistence/application trust boundaries. Authorization decision data consumed inside that trusted service process must be semantically revalidated against the canonical #65 contract rather than relying on Python object-construction provenance. Its correction-specific recorded-time ingress resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #161/#64/#65/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. @@ -125,7 +125,7 @@ Orgmetra must not infer a clean dependency review from independent OSV, Trivy or ## 7. Current baseline-writer evidence -PR #100 owns this baseline. A predecessor exact head failed Foundation/Recovery-family repository-contract checks after `.codegraph/` was added to `.gitignore` without resealing `manifest.json`. The owner branch was repaired by resealing only the `.gitignore` manifest entry to the exact current digest/size/line count. The branch has now non-force adopted protected `develop@ef1b143368cb6249c9520ca8cae10ebe844a5aa1` through a two-parent merge. That protected change reverts #166's docs-only workflow exclusions because Foundation and recovery admission contain documentation-content contracts; the baseline therefore no longer carries or describes those exclusions as current truth. +PR #100 owns this baseline. A predecessor exact head failed Foundation/Recovery-family repository-contract checks after `.codegraph/` was added to `.gitignore` without resealing `manifest.json`. The owner branch was repaired by resealing only the `.gitignore` manifest entry to the exact current digest/size/line count. The branch has now non-force adopted protected `develop@ef1b143368cb6249c9520ca8cae10ebe844a5aa1` through a two-parent merge. That protected change reverts #166's docs-only workflow exclusions because Foundation and recovery admission contain documentation-content contracts; the baseline therefore no longer carries or describes those exclusions as current truth. This revision also updates AUTH-01 to include #173's Job Analysis audit-provenance and exact-snapshot runtime boundaries while retaining them as Active PR evidence rather than promoted protected truth. Do **not** store PR #100's own current head inside this file: changing this file creates a new head and would make the value self-invalidating. Its PR body and GitHub API are the source for exact-current-head verification. All reviews/checks must be re-fetched after every push. @@ -137,7 +137,7 @@ Do **not** store PR #100's own current head inside this file: changing this file | **RUN-01 deterministic repository runner selection** | protected Orgmetra workflows still use moving `ubuntu-latest`; Draft #161 replaces every repository-owned selector with explicit `ubuntu-24.04` and has historical runner-acquisition/GREEN evidence, while its current exact-head jobs remain unassigned before checkout | product/security evidence can be ambiguous about runner image and is currently unavailable through the shared queue | Orgmetra #161; exact-head explicit-image regression + material hosted execution → ordinary protected integration → descendant non-force protected adoption; shared admission failure remains a separate owner-plane incident | **P0 evidence** | | **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | | **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | -| **AUTH-01 purpose-bound authorization trust boundary** | Draft #65/#168–#172 retains exact tenant/resource/purpose/operation/scope/field narrowing, runtime-type validation, UUID detachment and decision semantic coherence; #172's module-registry and closure-cell REDs invalidated the earlier claim that Python object-construction/registry provenance can serve as unforgeable authority. Current owner code instead binds policy authority to trusted Orgmetra service composition/policy sources, revalidates policy/request immediately at evaluation and provides durable-consumer decision revalidation. Same-interpreter arbitrary hostile code is a service-isolation compromise, not an object-provenance condition. Exact-head hosted/review evidence remains non-terminal. | remote/request/model/plugin input must not become HR policy authority; durable consumers must not confuse validated decision data with an in-process capability; hostile executable code requires an isolation boundary | Orgmetra #65/#168–#172; fresh exact-head Keyverse/People/repository/security coverage + independent review → ordinary protected integration; quarantine/process isolation is required for intentionally hostile executable workloads | **P1 security foundation** | +| **AUTH-01 purpose-bound authorization and durable evidence trust boundary** | Draft #65/#168–#173 retains exact tenant/resource/purpose/operation/scope/field narrowing, runtime-type validation, UUID detachment and decision semantic coherence; #172 invalidated the earlier claim that Python object-construction/registry provenance can serve as unforgeable authority. Current owner code instead binds policy authority to trusted Orgmetra service composition/policy sources, revalidates policy/request immediately at evaluation and provides durable-consumer decision revalidation. #173 additionally binds Job Analysis audit tenant/resource/actor/purpose to write authority and exact-type gates `AuditOutboxEvent` plus `JobAnalysisSnapshot` before semantic serialization, PostgreSQL authority access, or write/read result consumption. Same-interpreter arbitrary hostile code is a service-isolation compromise, not an object-provenance condition. Exact-head hosted/review evidence remains non-terminal. | remote/request/model/plugin input must not become HR policy authority; durable consumers must not confuse validated decision data with an in-process capability or execute caller-defined evidence behavior before validation; hostile executable code requires an isolation boundary | Orgmetra #65/#168–#173; fresh exact-head Keyverse/People/Job-Analysis/repository/security coverage + independent review → ordinary protected integration; quarantine/process isolation is required for intentionally hostile executable workloads | **P1 security foundation** | | **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; runner/mutation/authz prerequisites remain in canonical Draft owners #161/#64/#65 | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #161 then #64/#65 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | | **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #161/#64/#65 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #161/#64/#65 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | | **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | From c0a40a4d598635cc1056a29451a4707d00c613c5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:41:41 +0900 Subject: [PATCH 201/201] docs: doctor commercialization baseline after workflow integration --- docs/product-technical-gap-baseline.md | 245 ++++++++++--------------- 1 file changed, 97 insertions(+), 148 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index db56c5cb3..d8077a935 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,212 +1,161 @@ # Product and technical gap baseline -Verified: 2026-09-03 (Asia/Seoul) for Orgmetra protected/product refs. External owner-repository evidence retains its separately dated doctoring until re-fetched in that owner lane. +Verified: 2026-09-04 (Asia/Seoul) for Orgmetra protected/product refs. External owner-repository evidence is treated as dependency context and must be re-fetched in its canonical owner lane before mutation or release claims. -This document is the commercialization baseline for **Orgmetra**, not a frozen PR inventory and not merge authorization. It records product responsibility, shipped-vs-planned truth, causal control-plane blockers, and the next highest-leverage buyer gaps. Volatile PR heads, workflow run IDs, queue counts, review snapshots, mergeability, and base tips must be fetched live before every action rather than copied here until stale. +This is Orgmetra’s durable commercialization baseline, not merge authorization and not a frozen PR inventory. Volatile PR heads, workflow-run IDs, queue states, reviews, mergeability and base tips are live GitHub truth and must be fetched again before every material action. ## 1. Product thesis and buyer outcome -Orgmetra is the ContextualWisdomLab evidence-centered HRIS/HCM system of record. Its commercial value is not another employee database: it preserves **what employment fact was true, when it was true, which evidence justified a high-impact decision, who acted, what purpose authorized access, and how later outcomes validate the original job/selection model**. +Orgmetra is the ContextualWisdomLab HRIS/HCM system of record for authoritative People, Organization, Position, Assignment, Job Architecture, FJA/KSAO, Talent, Assessment and Workforce truth. Its buyer value is evidence-preserving decision infrastructure: what employment fact was true, when it was true, what evidence justified a high-impact decision, who acted, what purpose authorized access, and how later outcomes validate the original job/selection model. -Primary buyer/user roles from the PRD are HR operations owners, HRIS administrators, recruiters, hiring managers, job-analysis specialists, psychometricians/people-analytics scientists, compliance/audit reviewers, workers, and enterprise integration engineers. +Primary users are HR operations owners, HRIS administrators, recruiters, hiring managers, job-analysis specialists, psychometricians/people-analytics scientists, compliance/audit reviewers, workers and enterprise integration engineers. -The buyer-facing lifecycle is: - -1. govern job requirements and evidence; -2. collect candidate evidence without turning opaque references into decision authority; -3. record accountable human selection and offer decisions; -4. convert a selected candidate into authoritative worker/employment/assignment truth without losing provenance; -5. observe job-relevant performance over effective and system time; -6. validate selection evidence against later outcomes and fairness evidence; and -7. expose purpose-bound, auditable workflows through stable APIs and role workspaces. +The buyer lifecycle is Job requirements/evidence → Candidate evidence → accountable human selection/offer → authoritative worker/employment/assignment truth → job-relevant performance evidence → validation/fairness evidence → purpose-bound operational workflows. ## 2. Truth-state contract -Every feature claim must use one of these states. A documentation-only design is never promoted to shipped truth. - | State | Meaning | | --- | --- | | **Shipped truth** | Present on protected `develop` with executable evidence. | -| **Active PR** | Implemented only on an open exact PR head; predecessor or sibling evidence does not transfer. | -| **Accepted architecture** | Accepted ADR/PRD/TRD boundary whose production implementation is incomplete. | -| **Planned** | Prioritized buyer capability with no executable production evidence yet. | -| **Research-only** | Evidence or experiment that must not be represented as product behavior. | -| **Superseded** | Replaced decision/evidence; retain only for provenance. | +| **Active PR** | Implemented only on an open exact PR head; predecessor/sibling evidence does not transfer. | +| **Accepted architecture** | Accepted ADR/PRD/TRD boundary whose implementation is incomplete. | +| **Planned** | Prioritized buyer capability without executable production evidence. | +| **Research-only** | Experiment/evidence that must not be represented as product behavior. | +| **Superseded** | Replaced decision/evidence retained for provenance only. | | **Out of scope** | Owned by another bounded context/repository or explicitly rejected. | -Merge, release, deployment, and compliance claims require fresh exact-head evidence independently of this file. +A documentation-only design is never promoted to shipped truth. Merge, release, deployment and compliance claims require fresh exact-head evidence independently of this file. ## 3. Domain ownership and context map -Orgmetra owns **authoritative employment truth**. It must not become a monolithic copy of specialist products. +Orgmetra owns authoritative HR domain truth. Specialist CWL systems are consumed through released/versioned contracts and ACLs; source copying, mutable-branch dependency and cross-service SQL are prohibited. | Bounded context | Orgmetra responsibility | Integration boundary | | --- | --- | --- | | `people_core` | person anchors, employment, assignments, compensation references, candidate-worker linkage | Keyverse provides identity, not HRIS truth | -| `organization_core` | legal/organization units, reporting relations, locations, positions | external org identities remain referenced, not copied wholesale | -| `job_architecture` | jobs, tasks, FJA/KSAO evidence, qualification rules, SME approval, governed snapshots | ontology sources and contextual-orchestrator are evidence/draft adapters | -| `talent_acquisition` | requisitions, candidates, interviews, immutable decision-evidence sets, selection/offer governance | specialist assessment systems remain external evidence owners | +| `organization_core` | legal/organization units, reporting relations, locations, positions | external organization identities are referenced, not copied wholesale | +| `job_architecture` | Jobs, tasks, FJA/KSAO evidence, qualification rules, SME approval, governed snapshots | ontology/contextual-orchestrator outputs are evidence/draft adapters | +| `talent_acquisition` | requisitions, candidates, interviews, decision-evidence sets, selection/offer governance | specialist assessment systems remain evidence owners | | `performance_management` | cycles, criterion blueprints, observations, calibration | observations bind authoritative worker/job/time scope | -| `workforce_validation` | validity-study registry, exact predictor/criterion links, subgroup/drift evidence, scientific adapters | fast-mlsirm/TEPP/Psychometrics Commons own specialist numerical/psychometric computation | -| `document_records` | canonical document/image metadata and immutable artifact references | Clearfolio/NewsDOM-style document services are adapters | -| `integration_hub` | idempotency, inbox/outbox, adapter state, migration/CDC boundary | Naruon, migration tools, and peer CWL systems remain behind versioned ACLs | -| `audit_provenance` | append-only audit/provenance evidence | no peer service may silently become authoritative HRIS state | - -The initial deployment may share one PostgreSQL cluster, but each bounded context keeps an owned schema, role, migrations, generated access layer, and contract. Cross-context application-table reads are prohibited; versioned API/event/adapters form the anti-corruption layer. A shared physical database is not a Shared Kernel license. - -## 4. Current protected-branch product truth - -Protected `develop` was freshly observed at `ef1b143368cb6249c9520ca8cae10ebe844a5aa1`. This SHA is a dated evidence anchor only; every execution loop must re-fetch the branch before acting. The latest protected change restores Foundation CI and Recovery Rehearsal Quality documentation-content checks after the preceding docs-only path exclusions proved unsound: both workflows hash or otherwise validate governed documentation/traceability artifacts, so docs-only changes must remain in their admission scope. This protected workflow repair does not promote any pending HR domain feature to Shipped truth. - -Shipped foundation evidence includes: - -- bitemporal HRIS, tenant-isolation/RLS, evidence-sealing, audit/outbox and persistence contracts; -- governed candidate/selection/requisition/offer and job-analysis evidence packages; -- purpose-bound authorization and normalized employment/assignment/performance foundations; -- Keyverse/Naruon/migration adapter boundaries and design-token foundations; and -- PRD/TRD/ADR/UML/ERD/security/test/operability documentation sufficient to define intended modular boundaries. - -Protected `develop` does **not** yet encode the HR decision that distinguishes a primary assignment from a concurrent secondary/TFT assignment. Allocation percentage, row order, position identity and graph topology are not classification authority. Orgmetra issue #162 and Draft PR #163 are the active `people_core` owner lane: new writes require explicit `primary | concurrent_secondary`; pre-contract history remains `legacy_unspecified` without inference; one tenant-local Employment may have at most one simultaneously visible primary assignment for one effective/system-time coordinate; category participates in semantic idempotency; and API/application/PostgreSQL boundaries must enforce the same vocabulary. Because #163 is still an Active PR with non-terminal exact-head evidence, none of that behavior is Shipped truth yet. The #163 branch has non-force adopted the current protected workflow truth rather than retaining the superseded docs-only exclusions. - -Fresh owner-path review found three shared owner lanes below the Assignment feature that must remain canonical rather than being copied into #163/#165. Draft PR #161 owns repository-local GitHub Actions runner selection: it replaces the moving `ubuntu-latest` alias with explicit `ubuntu-24.04`; its exact-head jobs carry the intended label but remain unassigned before checkout, separating selector correctness from the shared Actions admission/queue incident. Draft PR #64 is the canonical generic People mutation runtime-type owner: its current source requires exact governed command/result/`AuthorizationDecision` acceptance at mutation and PostgreSQL authorities. Draft PR #65 is the canonical purpose-bound authorization and durable evidence-coherence owner. Its earlier #168–#171 lineage tried to make Python object-construction/registry provenance itself authorization authority; #172 proved first that module registries were writable and then, through an independent exact-head review plus closure-cell RED, that moving those registries into `__closure__` did not create a security boundary. The corrected owner contract now locates authority at the service TCB: Keyverse supplies authenticated identity/scopes, trusted Orgmetra service composition/policy sources supply HR policy, and request/model/plugin-controlled values do not. `PurposeBoundAccessPolicy` and `PurposeBoundAccessRequest` remain exact-type validated and UUID-detached, are revalidated into evaluation snapshots immediately before tenant/resource/purpose/operation/scope/field narrowing, and `AuthorizationDecision` is PII-minimized validated decision data rather than an unforgeable same-interpreter capability. Durable consumers have an explicit `validate_authorization_decision(...)` revalidation contract. Issue #173 extends the same trust-boundary rule into Job Analysis durable evidence: transactional audit tenant/resource/actor/purpose must agree with the write authority, `AuditOutboxEvent` is exact-type gated before field/serialization use, and `JobAnalysisSnapshot` is exact-type gated at semantic digest, PostgreSQL input, and write/read port return boundaries before authority fields or document serialization are consumed. No mutable module or closure registry is represented as issuance authority; arbitrary hostile same-process code is a service-compromise/isolation problem. #65/#168–#173 still require fresh exact-head hosted/review evidence and remain **Active PR/issue**, not protected truth. The correct causal order is #161 ordinary protected integration → applicable #64/#65 protected integration → non-force adoption by #163 → #163 integration → non-force adoption/restack by #165. Assignment branches must not depend on mutable owner branches as though they were released contracts. - -Assignment category correction is a distinct dependent buyer gap rather than an implied capability of #163. Issue #164 and Draft PR #165 own immutable close → replacement → normalized predecessor/replacement supersession for already-committed explicit categories. The active child preserves tenant/Employment/Person/Position/allocation/effective truth, requires Keyverse purpose-bound authorization and human-confirmation/evidence metadata, records audit/outbox plus durable replay evidence in the same PostgreSQL transaction, and rejects caller-defined command/result runtime subtypes at their persistence/application trust boundaries. Authorization decision data consumed inside that trusted service process must be semantically revalidated against the canonical #65 contract rather than relying on Python object-construction provenance. Its correction-specific recorded-time ingress resolves an exact aware `datetime` offset once and detaches accepted caller-owned `tzinfo` behavior onto a built-in fixed-offset timezone; provider failures, offsetless evidence and executable `timedelta` subtypes fail closed under the correction error contract. The dedicated exact-head workflow executes that regression, but the child remains downstream of #161/#64/#65/#163 with non-terminal hosted evidence, so correction provenance is **Active PR**, not Shipped truth. +| `workforce_validation` | validity-study registry, exact predictor/criterion links, subgroup/drift evidence | fast-mlsirm/TEPP/Psychometrics Commons own specialist numerical/psychometric computation | +| `document_records` | canonical document/image metadata and immutable artifact references | document services remain adapters | +| `integration_hub` | idempotency, inbox/outbox, adapter state, migration/CDC boundary | peer systems remain behind versioned ACLs | +| `audit_provenance` | append-only audit/provenance evidence | no peer service silently becomes authoritative HRIS state | -The root package remains `orgmetra-foundation-pack` version `0.1.0`, private, with a validation-oriented script rather than a deployable buyer application. Current default-branch code search finds `orgmetra-gateway`, employee workspace and HR workspace as architecture/design references, while no React implementation is indexed. The P1 PRD promise—Job Architecture, Candidate Evidence, Hiring Decision, bitemporal Employee Profile and Validation workspaces—therefore has **no protected-branch buyer UI implementation evidence yet**. Treat this as a major commercialization gap, not as a documentation completion. +One physical PostgreSQL cluster may host multiple bounded contexts initially, but each context keeps an owned schema/role/migrations/access layer/contract. A shared physical database is not a Shared Kernel license. -There are currently no published GitHub releases. Do not manufacture a release merely to clear that count; release only when an integrated protected head has complete exact-head governance, security, operability and buyer-workflow evidence. +## 4. Current protected truth and owner stack -## 5. Effective GitHub governance: P0 release blocker +Protected `develop` is `eb9757f8649aaad026a9865508d9aad50c1a7a4f`, produced by normal integration of PR #161. #161 is therefore no longer a mutable prerequisite. Its protected delta consolidates repository-owned quality workflows and pins repository runner selection to explicit `ubuntu-24.04` without weakening domain, PostgreSQL or repository validation gates. -The effective control plane for Orgmetra `develop` is inherited organization ruleset **18156473 — `CWL Central required workflows`**. Classic branch-protection fields alone are not authoritative while that ruleset is active. +The selector repair did not resolve the wider Actions admission incident: exact-current-head #63/#64/#65 jobs still materialize with the intended `ubuntu-24.04` label but remain queued before checkout with no runner assigned. Treat this as runner admission evidence, not as evidence that the selector repair failed and not as justification for no-op retriggers or copying workflow bytes into feature branches. -Fresh Orgmetra live reads on 2026-09-03 show the inherited ruleset still has: +Current canonical owner order is: -- `required_approving_review_count = 1`; -- `require_last_push_approval = false`; -- `require_code_owner_review = false`; -- `required_reviewers = []`; -- `dismiss_stale_reviews_on_push = true`; -- required review-thread resolution enabled; -- central required workflows enabled; -- only merge and squash allowed; -- deletion and non-fast-forward protection enabled; and -- an `OrganizationAdmin` actor with routine `bypass_mode = always`. +1. **#63 shared HRIS-kernel audit/runtime evidence** — Draft and mechanically mergeable over current protected `develop`. A current CodeRabbit suggestion to add Job Analysis source/test files to `manifest.json` was verified against `tests/validate_repository.py` and rejected: the canonical manifest requires exact equality to its `REQUIRED` path set, which intentionally excludes those two files. Adding them would create `extra_entries` and make validation fail. The review thread was resolved without source change. +2. **#64 generic People mutation runtime integrity** — Draft and mechanically mergeable over current protected `develop`; current product/security checks remain non-terminal. +3. **#65 purpose-bound authorization plus Job Analysis durable/runtime integrity** — Draft and mechanically mergeable over current protected `develop`. Its #210 request-edge invariant is retained after #161 adoption: exact built-in Authorization text → header length at most 8,199 → Bearer parsing → token length at most 8,192. #65 must consume #63 only after #63 reaches protected truth, then reacquire exact-head evidence. +4. **#163 explicit Assignment category** — valid buyer/domain delta retained, but still based on predecessor protected truth and currently non-mergeable against current `develop`. This is a repair/restack finding, not a close condition. After #63 and applicable #64/#65 integrations, #163 must non-force adopt resulting protected truth and reacquire every exact-head gate. +5. **#165 Assignment category correction/supersession** — Draft child of #163. Preserve its close → replacement → predecessor/replacement provenance delta until #163 integrates, then non-force restack/adopt protected truth and rerun all exact-head gates. -The central `.github` repository's own active ruleset **17921150 — `Lock default branch`** is a second live drift surface. Its approval count is already `0`, last-push approval and CODEOWNER review are disabled, required reviewers are empty, review-thread resolution and deletion/non-fast-forward protection are enabled, but it still permits `rebase` and still exposes `OrganizationAdmin/always` bypass. Source-level audit policy and both live ruleset payloads must converge before governance repair is complete. +Protected `develop` still does not make explicit primary-vs-concurrent-secondary Assignment classification shipped truth. Allocation, row order, Position identity and graph topology are not classification authority. -This is not the current governance decision. `.github#772` establishes that the present one-human-maintainer fleet cannot satisfy a positive generic independent-human approval count, a last-push approval by another person, or mandatory CODEOWNER approval by the same sole author. The compliant repair is **not** a bot approval, service-account approval, self-approval, credential widening, or routine administrator bypass. The current target is: +There are no published Orgmetra GitHub releases as of this verification. Do not manufacture a release merely to clear the count. -- `required_approving_review_count = 0` while no genuinely independent human reviewer exists; -- `require_last_push_approval = false` because the rule otherwise requires a different person from the latest pusher; -- `require_code_owner_review = false` while the sole code owner is also the author; -- no synthetic `required_reviewers` merely to recreate the unavailable human gate; -- review-thread resolution stays enabled; -- exact-current-head OpenCode, Noema, Strix, Security/SAST, Dependency Review, coverage, provenance and repository-specific quality gates remain fail-closed; -- deletion and non-fast-forward protection remain enabled; -- no routine `OrganizationAdmin/always` bypass; emergency repair belongs to a separately governed, time-bounded, auditable break-glass path; and -- only merge and squash are accepted by the current audit; merge-method policy must not be weakened merely to solve the reviewer-capacity problem. +## 5. Effective GitHub governance -Causal owner: `ContextualWisdomLab/.github`. Issue #772 defines the satisfiable one-human policy and #1351 tracks fleet reconciliation. Retired #1176 is predecessor evidence only after verified complete carryover of every valid audit delta into the single active owner-plane/audit writer, **PR #1644**. PR #1644 pins exactly rulesets 17921150 and 18156473, refuses identity/provenance drift, preserves unrelated controls, binds privileged mutation to the exact protected-main SHA, verifies immutable ruleset history, treats ambiguous PUT outcomes as unresolved until history/live-state evidence proves convergence, and uses a separately provisioned protected-environment `CWL_RULESET_ADMIN_TOKEN` rather than widening ordinary repository credentials. Its current exact-head focused governance suite has reached terminal success after non-force reconciliation with protected `main`, while the broader security fleet remains non-terminal; focused success is not full merge authority. Source integration alone is intentionally insufficient: after #1644 reaches protected `main`, a controlled maintenance interval must provision the least-privilege owner-plane credential, enable `CWL_RULESET_RECONCILE_ENABLED`, perform and verify the mutation, disable/retain the reconciler according to the reviewed drift-repair policy, and then re-run the canonical audit plus Orgmetra canary. Orgmetra issue #89 mirrors this dependency. Orgmetra must not add a leaf workflow shim to simulate organization settings. +Orgmetra’s effective default-branch control plane is inherited organization ruleset **18156473 — `CWL Central required workflows`**, active as of 2026-09-04. Current live parameters are: -The #1644 owner-plane lineage has already repaired deterministic test-contract drift, collision/recovery ambiguity, post-settlement version races, and protected-main integration without force-push. Every later protected-main reconciliation resets exact-head evidence, so only the current unchanged writer head may authorize ordinary integration. Completed one-shot source-fix machinery is absent from the current owner tree. +- one approving review required; +- stale reviews dismissed after push; +- review-thread resolution required; +- extra approval required for unattributed changes; +- merge and squash are the allowed merge methods; +- deletion and non-fast-forward protection are enabled; +- required workflows are `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`; +- `OrganizationAdmin/always` bypass is exposed. -**Canary:** Orgmetra PR #88 (`fix/job-analysis-http-request-budgets`) was freshly re-verified on exact head `0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd`; the currently returned repository workflow runs are terminal-success, combined CodeRabbit/Devin statuses are successful, and its only inline review thread is resolved. It has no qualifying independent approval. It is intentionally retained as a governance canary: after the central policy repair, an unchanged sole-author GREEN PR must no longer be blocked *only* by a reviewer identity that does not exist. Repository-native auto-merge is currently disabled for Orgmetra, so that setting cannot be used to disguise the admission defect. Do not merge it through administrator bypass to fake that proof. +Routine bypass, self-approval, synthetic reviewer identity, gate weakening or treating model/bot review as the required human approval are not acceptable repair strategies. Central ruleset mutation remains owned by `ContextualWisdomLab/.github`; Orgmetra records the dependency and canary evidence but does not create a leaf workflow shim or copy central policy source. -## 6. Required-workflow availability: P0 evidence blocker - -Repository-local workflow determinism and organization-owned dependency evidence are separate gates. Orgmetra Draft PR #161 owns the repository-local selector repair: every repository-owned runner job uses explicit `ubuntu-24.04`, a test rejects reintroduction of `ubuntu-latest`, and earlier exact heads acquired hosted runners and reached repository-owned GREEN. Its current exact head has the corrected labels but remains queued before checkout with no runner assigned. Therefore #161 is necessary to remove a moving runner alias, but it does not by itself repair the current shared Actions admission queue. Consumer/feature PRs must not copy the workflow diff or generate no-op commits to simulate execution; integrate #161 normally when current-head evidence permits and then let descendants adopt protected truth. - -The central Dependency Review workflow must fail closed: it may proceed to the pinned GitHub Dependency Review action only after an exact immutable `BASE_SHA...HEAD_SHA` dependency comparison returns transport success and authenticated HTTP `200`. - -The temporary `.github#1643` diagnostic completed its evidentiary purpose: on one unchanged exact-head A/B canary, the anonymous dependency comparison returned HTTP `404` while the same exact repository/base/head comparison using a minimally scoped job token with `contents: read` + `pull-requests: read` returned HTTP `200`, both with successful transport. Therefore anonymous responses are not availability authority. The canonical current owner is Draft **`.github#1725`**, which carries the valid diagnostic deltas without the temporary canary: reusable callers explicitly grant the least-privilege permission envelope, repository/base/head values must be legal immutable identities before transport, only authenticated HTTP 200 authorizes `actions/dependency-review-action`, and every authenticated non-200 remains fail-closed. Exact-head security evidence for #1725 remains non-terminal, so none of this owner repair is protected/released truth yet. - -Orgmetra must not infer a clean dependency review from independent OSV, Trivy or Scorecard success, and it must not create a leaf skip. After #1725 reaches protected `ContextualWisdomLab/.github/main` through ordinary protection, consumers must pin the released immutable owner workflow identity and prove an unchanged public non-fork exact comparison returns HTTP 200 and the pinned Dependency Review action materially executes. - -## 7. Current baseline-writer evidence - -PR #100 owns this baseline. A predecessor exact head failed Foundation/Recovery-family repository-contract checks after `.codegraph/` was added to `.gitignore` without resealing `manifest.json`. The owner branch was repaired by resealing only the `.gitignore` manifest entry to the exact current digest/size/line count. The branch has now non-force adopted protected `develop@ef1b143368cb6249c9520ca8cae10ebe844a5aa1` through a two-parent merge. That protected change reverts #166's docs-only workflow exclusions because Foundation and recovery admission contain documentation-content contracts; the baseline therefore no longer carries or describes those exclusions as current truth. This revision also updates AUTH-01 to include #173's Job Analysis audit-provenance and exact-snapshot runtime boundaries while retaining them as Active PR evidence rather than promoted protected truth. - -Do **not** store PR #100's own current head inside this file: changing this file creates a new head and would make the value self-invalidating. Its PR body and GitHub API are the source for exact-current-head verification. All reviews/checks must be re-fetched after every push. - -## 8. Commercialization gap register +## 6. Commercialization gap register | Gap | Current evidence | Buyer consequence | Owner / next acceptance evidence | Priority | | --- | --- | --- | --- | --- | -| **GOV-01 satisfiable protected-branch admission** | live inherited ruleset still requires one unavailable generic approval and routine admin bypass; owner-repository ruleset still permits rebase and routine admin bypass; retired #1176 has transferred its valid audit deltas into active #1644, whose focused current-head governance validation succeeds while broader evidence remains non-terminal | GREEN work cannot progress normally; bypass would undermine evidence | `.github#772/#1351/#1644`; terminal unchanged-head evidence → protected-main integration → least-privilege maintenance apply → immutable-history/full live-payload convergence → canonical audit + unchanged Orgmetra #88 ordinary-path proof | **P0** | -| **RUN-01 deterministic repository runner selection** | protected Orgmetra workflows still use moving `ubuntu-latest`; Draft #161 replaces every repository-owned selector with explicit `ubuntu-24.04` and has historical runner-acquisition/GREEN evidence, while its current exact-head jobs remain unassigned before checkout | product/security evidence can be ambiguous about runner image and is currently unavailable through the shared queue | Orgmetra #161; exact-head explicit-image regression + material hosted execution → ordinary protected integration → descendant non-force protected adoption; shared admission failure remains a separate owner-plane incident | **P0 evidence** | -| **SEC-01 authoritative Dependency Review availability** | decisive A/B showed anonymous 404 vs minimally scoped job-token 200; canonical Draft #1725 keeps authenticated non-200 fail-closed, explicit caller permissions and immutable identity validation, but is not yet protected/released | merge queue can remain blocked without trustworthy dependency diff | `.github#810/#1725`; terminal unchanged-head evidence → ordinary protected integration → immutable consumer pin → unchanged public non-fork authenticated comparison 200 + pinned action execution | **P0** | -| **REL-01 integrated release evidence** | no published release; large active PR stack; no single integrated protected head yet proves the complete gate set | buyers cannot install/deploy a supported release | merge causal dependency roots in order; protected-head release checklist + signed/provenance evidence + CHANGELOG/version | **P0** | -| **AUTH-01 purpose-bound authorization and durable evidence trust boundary** | Draft #65/#168–#173 retains exact tenant/resource/purpose/operation/scope/field narrowing, runtime-type validation, UUID detachment and decision semantic coherence; #172 invalidated the earlier claim that Python object-construction/registry provenance can serve as unforgeable authority. Current owner code instead binds policy authority to trusted Orgmetra service composition/policy sources, revalidates policy/request immediately at evaluation and provides durable-consumer decision revalidation. #173 additionally binds Job Analysis audit tenant/resource/actor/purpose to write authority and exact-type gates `AuditOutboxEvent` plus `JobAnalysisSnapshot` before semantic serialization, PostgreSQL authority access, or write/read result consumption. Same-interpreter arbitrary hostile code is a service-isolation compromise, not an object-provenance condition. Exact-head hosted/review evidence remains non-terminal. | remote/request/model/plugin input must not become HR policy authority; durable consumers must not confuse validated decision data with an in-process capability or execute caller-defined evidence behavior before validation; hostile executable code requires an isolation boundary | Orgmetra #65/#168–#173; fresh exact-head Keyverse/People/Job-Analysis/repository/security coverage + independent review → ordinary protected integration; quarantine/process isolation is required for intentionally hostile executable workloads | **P1 security foundation** | -| **ASG-01 explicit assignment authority** | protected `develop` stores assignment allocation but not the explicit HR decision distinguishing primary from concurrent secondary/TFT; issue #162 and Draft PR #163 are the active test-first owner lane, have adopted current protected workflow truth non-force, and remain non-shipped while current exact-head evidence is non-terminal; runner/mutation/authz prerequisites remain in canonical Draft owners #161/#64/#65 | employee profile, reporting and downstream authorization/graph consumers would otherwise have to guess authoritative membership from allocation/order/topology | Orgmetra #161 then #64/#65 ordinary protected integration → #163 non-force protected adoption → #162/#163 explicit category domain/API/PostgreSQL/OpenAPI proof with bitemporal uniqueness, legacy provenance, semantic idempotency and no heuristic reclassification → exact-head PostgreSQL/People/Foundation/Recovery/Security/SAST/review evidence → ordinary protected integration | **P1 buyer truth** | -| **ASG-02 auditable assignment category correction** | issue #164 / dependent Draft #165 implement immutable predecessor closure, replacement Assignment, normalized supersession, purpose-bound HTTP/OpenAPI, audit/outbox and durable replay; correction-specific recorded time detaches accepted caller-owned timezone behavior onto a built-in fixed-offset timezone and fails closed on provider/offset integrity defects; child-local exact runtime gates remain downstream of shared #161/#64/#65 owners, and hosted evidence is non-terminal | HR operations cannot safely correct a misclassified primary/secondary Assignment without either rewriting history or creating provenance ambiguity | integrate #161/#64/#65 → non-force adopt into and integrate #163 → non-force restack/retarget #165 → exact-head PostgreSQL/full-People/idempotency/security/review GREEN → atomic canonical documentation/inventory handoff → ordinary protected integration | **P1 buyer truth** | -| **UX-01 role workspaces are design truth, not shipped UI** | P1 workspaces appear in PRD/wireframes/Storybook contract; protected branch shows foundation package and design tokens but no indexed React workspace implementation | buyers cannot complete the lifecycle through a coherent UI | executable Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook, screenshots, WCAG 2.2 AA, interaction/i18n/edge-state tests | **P1** | -| **API-01 deployable gateway/service composition** | architecture defines `orgmetra-gateway` and bounded services; protected code evidence is still foundation/package-oriented | integrations lack one deployable, supported application boundary | async-capable gateway, generated OpenAPI validation, auth/purpose/idempotency, service-owned DB access, contract/load tests | **P1** | -| **VAL-01 end-to-end validation workflow** | normalized validity/evidence architecture exists; specialist numerical ownership is correctly external | people analytics buyer cannot yet run a governed predictor→criterion→fairness workflow from UI/API | `workforce_validation` vertical slice integrating exact immutable snapshots through approved fast-mlsirm/TEPP/Psychometrics Commons boundaries; reproducibility/error evidence | **P1** | -| **OPS-01 commercial operability/SLO proof** | test/operability docs exist, but no released integrated web service proves buyer traffic characteristics | enterprise buyer lacks capacity/recovery evidence | compose deployment; Podman/Colima portability; async request handling; k6 per-page p95 ≤20 ms; recovery/backup/restore evidence; resource auto-tuning where required | **P1** | -| **SEC-02 certification-ready control evidence** | purpose-bound PII/RLS/audit contracts exist; certification is not claimed | security review still needs traceable operational evidence | NIST/SOC 2/CSAP control mapping, key management, retention/export/delete, break-glass, incident/recovery evidence; no indiscriminate PII masking | **P1** | -| **DATA-01 schema/name/persistence audit** | strong normalized temporal schema exists but every new migration/PR can introduce naming, hot-partition, lock or UPSERT drift | latent data debt can become irreversible after adoption | automated audit for at-least-two-token domain/DB identifiers where semantically required, snake_case default, 3NF ownership, per-item UPSERT/idempotency, partition/lock strategy | **P1 continuous** | -| **SCI-01 Rust scientific compute boundary** | TRD correctly reserves material mathematical/psychometric kernels for Rust; current HRIS packages are mainly governance/domain code | future analytics can regress into slow or unauditable Python numerics | every material math/psychometric/EDA/vector/linear/matrix/token-size core is Rust or behind an explicit Rust API; CPU multithreading and justified GPU parity fixtures | **P1 continuous** | +| **GOV-01 satisfiable protected admission** | inherited ruleset still requires one approval and exposes routine admin bypass | otherwise-GREEN work may be unable to progress normally, while bypass weakens auditability | canonical `.github` owner repair → live ruleset convergence → unchanged Orgmetra canary through ordinary path | **P0** | +| **RUN-01 Actions runner admission** | #161 selector/workflow consolidation is protected truth; current #63/#64/#65 jobs carry `ubuntu-24.04` yet remain pre-checkout with no runner | exact-head product/security evidence remains unavailable | central/repository Actions admission RCA; unchanged candidate must materially execute rather than no-op retrigger | **P0 evidence** | +| **SEC-01 authoritative Dependency Review** | required central workflow remains owner-controlled; substitutes cannot prove dependency diff | merge evidence can be incomplete or misleading | immutable released central workflow + authenticated exact comparison + material pinned action execution | **P0** | +| **REL-01 integrated release evidence** | no published release and no single integrated protected head proves the full buyer/security/operability gate set | buyers cannot install/deploy a supported release | causal owner integration → protected-head release checklist → version/CHANGELOG/tag/package/SBOM/provenance/reproducibility/rollback | **P0** | +| **AUTH-01 purpose-bound authorization/durable trust boundary** | #65 retains exact tenant/resource/purpose/operation/scope/field narrowing, exact runtime validation, decision revalidation, durable Job Analysis integrity and #210 request budget; still Active PR | remote/request/plugin-controlled data must not become HR policy authority or executable evidence before validation | #63 protected integration → #65 non-force protected adoption → exact-head product/PostgreSQL/security/review evidence → normal integration | **P1 security foundation** | +| **ASG-01 explicit Assignment authority** | #162/#163 retain explicit `primary | concurrent_secondary`; `legacy_unspecified` is historical/restoration provenance; #163 is currently behind/conflicting with current protected truth | employee profile/reporting/authorization/graph consumers otherwise have to guess authoritative membership | integrate #63/#64/#65 as applicable → non-force adopt protected truth into #163 → PostgreSQL/API/OpenAPI/idempotency/bitemporal evidence → ordinary integration | **P1 buyer truth** | +| **ASG-02 auditable Assignment correction** | #164/#165 retain immutable predecessor closure, replacement and normalized supersession provenance | HR operations cannot safely correct misclassification without rewriting history or losing provenance | #163 protected integration → #165 non-force restack/adoption → exact-head People/PostgreSQL/idempotency/security/review evidence → ordinary integration | **P1 buyer truth** | +| **UX-01 role workspaces** | PRD/wireframe/design foundations exist; buyer-facing executable workspace evidence is not yet sufficient for a release claim | buyer lifecycle is not yet proven end-to-end through a coherent UI | Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation vertical slice; Storybook/current-head E2E/a11y/i18n/edge-state evidence | **P1** | +| **API-01 deployable gateway/composition** | service/package contracts exist but no released integrated application boundary is available | integrations lack one supported deployment contract | async gateway, generated OpenAPI validation, purpose/idempotency, service-owned persistence, contract/load/recovery tests | **P1** | +| **VAL-01 governed validation workflow** | normalized validity/evidence architecture exists and scientific compute ownership remains external | people-analytics buyer cannot yet run the complete predictor→criterion→fairness workflow | exact immutable snapshots through released fast-mlsirm/TEPP/Psychometrics Commons contracts; reproducibility/error evidence | **P1** | +| **OPS-01 commercial operability/SLO** | operability/test contracts exist; no released integrated web service proves buyer traffic/recovery characteristics | enterprise buyer lacks capacity/recovery evidence | Podman/Colima → compose/k8s path, async handling, clean connection lifecycle, recovery rehearsal, k6 buyer-path p95 ≤20 ms | **P1** | +| **SEC-02 certification-ready control evidence** | purpose-bound PII/RLS/audit architecture exists; certification is not claimed | security review still requires operational control evidence | NIST/SOC 2/CSAP mapping, key/retention/export/delete/break-glass/incident/recovery evidence | **P1** | +| **DATA-01 schema/persistence audit** | strong bitemporal/tenant foundations exist; every new migration can still introduce naming, lock, hot-partition or idempotency drift | latent data debt becomes expensive after adoption | automated naming/3NF/ownership/UPSERT/idempotency/partition-lock audit | **P1 continuous** | +| **SCI-01 Rust scientific compute boundary** | HRIS domain code is not itself a reason to move into Rust; material math/psychometrics/EDA kernels remain Rust-first by architecture | future analytics could regress into slow or unauditable numerics | Rust API for material kernels, bounded CPU parallelism, justified GPU parity and true-parameter recovery evidence | **P1 continuous** | -## 9. Next product loop after P0 governance repair +## 7. Next buyer-visible product loop -The next buyer-visible vertical slice should be **Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation** rather than another isolated evidence packet. +After P0 governance/execution prerequisites are materially runnable, the next commercial slice should be **Job Architecture → Candidate Evidence → Hiring Decision → Employee Profile → Validation**, not another isolated evidence packet. -Minimum commercialization contract: +Minimum acceptance: -1. **Gateway** — authenticated tenant/actor/purpose context; idempotency; exact OpenAPI validation; bounded async operations; no direct peer-table reads. -2. **Job Architecture** — governed snapshot provenance, SME review, qualification rules and clear next-action states. -3. **Candidate Evidence** — purpose-bound retrieval, immutable evidence version/reference, explicit insufficiency/escalation states, no autonomous hiring decision. -4. **Hiring Decision** — human confirmation, exact sealed evidence-set digest, actor/reason/provenance, candidate-worker conversion handoff. -5. **Employee Profile** — effective/system-time assignment history and correction semantics visible without exposing internal schema names; assignment category is explicit HRIS truth rather than inferred from allocation or ordering. -6. **Validation** — exact predictor/criterion version linkage, job scope, time, subgroup/multilevel context and specialist scientific adapter evidence. -7. **UX evidence** — design tokens, Storybook scenario/edge inventory, screenshots at supported breakpoints, keyboard/touch/focus/error/degraded/permission/i18n states, exact-value alternatives for charts, WCAG 2.2 AA audit. -8. **Operability evidence** — compose-based deployment, recovery rehearsal, structured audit telemetry, k6 concurrency evidence with page p95 ≤20 ms, dependency/service failure behavior and clean close-connection handling. +1. authenticated tenant/actor/purpose context, idempotency and exact OpenAPI validation at the gateway; +2. governed Job snapshot provenance, SME review and qualification rules; +3. immutable Candidate Evidence references with insufficiency/escalation states and no autonomous hiring decision; +4. human-confirmed Hiring Decision bound to an exact sealed evidence set and candidate-worker conversion; +5. bitemporal Employee Profile with explicit Assignment category and correction provenance; +6. Validation with exact predictor/criterion versions, Job scope, time and subgroup/multilevel context; +7. material UI evidence for normal/loading/empty/error/permission/responsive/keyboard/touch/focus/i18n states in KO/EN/JA/ZH/VI/ES/DE/FR, including CJK/text expansion/font fallback; +8. operability/recovery/load evidence against production-equivalent PostgreSQL and real buyer paths rather than reduced samples or unrealistic warm-cache exclusions. -This slice must use existing bounded packages instead of duplicating their domain rules in UI code. +UI work must use reusable objects/page composition and product design evidence rather than template filler. Keyverse remains identity backend; authentication journey remains product form. Translation resources are versioned DB resources with screen-key cache and remain separate from ontology-label truth. -## 10. Data, scientific and AI invariants +## 8. Data, scientific and AI invariants -- Database/domain object names must be semantically explicit. `snake_case` is the default for database objects and two-or-more meaningful tokens are preferred/required where a bare one-token name such as `id` would lose domain identity; legitimate context-required `camelCase`/`PascalCase` program identifiers remain valid. -- Authoritative relational design stays in 3NF unless an explicitly measured read model is separated from the system of record. -- Tenant, bitemporal, lock/partition and item-level UPSERT/idempotency contracts are tested at the database boundary, not assumed from application code. -- Multiple assignments/memberships and time-varying context must remain modelable so person-level inference does not silently commit an atomistic fallacy. -- Psychometric/statistical weights are estimated from reviewed mathematical models; no arbitrary rule-of-thumb weighting enters production. -- Material mathematical, psychometric, EDA, vector/linear/matrix and token-size core computation is Rust-first with bounded CPU parallelism and justified GPU parity evidence. -- LLM output is draft/supporting evidence only. LLM work uses released contextual-orchestrator API/client/schema contracts; GitHub Actions request only `orchestrator/free` through the gateway token and never hard-code provider/model/group/paid fallback policy. contextual-orchestrator owns capability/price/latency/availability/accuracy discovery, supports schema-bound completions/responses and modality/embedding contracts, and preserves no-default-inference-timeout plus explicit user/provider/admin termination provenance. LLM output never receives direct authoritative employment-decision power. +- DDD subdomains, bounded contexts, UL, aggregates, entities, value objects, domain services, repositories, events and invariants must agree across code/API/DB/tests. +- Relational authoritative truth remains normalized; read models are separated explicitly when measured need justifies them. +- Tenant, bitemporal, lock/partition and item-level UPSERT/idempotency contracts are tested at database boundaries. +- Multiple assignments/memberships and time-varying context remain representable; person-level inference must not silently commit atomistic fallacy. +- Material mathematical/psychometric/EDA/vector/linear/matrix/token-size computation is Rust-first with bounded CPU parallelism and justified GPU parity. +- Psychometric acceptance uses true-parameter recovery, RMSE, bias, coverage and reproducibility. Synthetic data is unit-test evidence, not real-world acceptance. +- LLM output is draft/supporting evidence only. LLM work consumes released contextual-orchestrator API/client/schema contracts; GitHub Actions request only `orchestrator/free` through the gateway token and do not hard-code provider/model/group/paid fallback policy. Capability absence fails closed and is repaired in the canonical orchestrator owner. -## 11. Security, privacy and compliance posture +## 9. Security, privacy and compliance posture -Orgmetra targets evidence readiness for CSAP/SOC 2-style enterprise review without claiming certification. PII protection must be purpose-bound and operationally usable rather than indiscriminate masking that prevents legitimate HR work. Controls include tenant/actor/purpose/resource/lifetime authorization, least privilege, forced RLS, encryption, immutable audit evidence, retention/export/delete lifecycle, incident/recovery evidence and separately governed break-glass operation. +Orgmetra targets evidence readiness for CSAP/SOC 2-style enterprise review without claiming certification. PII controls are purpose-bound and operationally usable: tenant/actor/purpose/resource/lifetime authorization, least privilege, forced RLS where applicable, encryption, immutable audit evidence, retention/export/delete lifecycle, incident/recovery evidence and separately governed break-glass operation. -Customer-facing language describes the user's next action and evidence state, not internal repository, schema, model or agent boundaries. +Customer-facing language describes the user’s next action and evidence state, not internal repository/schema/model/agent boundaries. -## 12. Research and standards basis +## 10. Research and standards basis -The following authoritative sources were re-checked on 2026-09-02. They define design/audit constraints; they do not by themselves certify Orgmetra or establish legal compliance. WCAG 2.2 remains the current published accessibility basis as ISO/IEC 40500:2025 while ISO/IEC has a newer revision project in development; draft work is not treated as a published requirement. NIST SP 800-53 Rev. 5 also has a finalized Release 5.2.0 control-catalog update from 2025, so current control mapping must use that release rather than assuming the original 2020 catalog is unchanged. +These sources define design/audit constraints; they do not certify Orgmetra or establish legal compliance by citation alone. Implementation-specific citations and invariants belong in `docs/doctoring/`, ADRs and traceability records beside the code/test they constrain. - International Organization for Standardization. (2023). *ISO 30405:2023 Human resource management—Guidelines on recruitment* (2nd ed.). https://www.iso.org/standard/79488.html - International Organization for Standardization, & International Electrotechnical Commission. (2025). *ISO/IEC 40500:2025 Information technology—W3C Web Content Accessibility Guidelines (WCAG) 2.2* (2nd ed.). https://www.iso.org/standard/91029.html - World Wide Web Consortium. (2023). *Web Content Accessibility Guidelines (WCAG) 2.2*. https://www.w3.org/TR/WCAG22/ -- National Institute of Standards and Technology. (2025, August 27). *NIST releases revision to SP 800-53 security and privacy controls (Release 5.2.0)*. https://csrc.nist.gov/news/2025/nist-releases-revision-to-sp-800-53-controls - Joint Task Force. (2020). *Security and privacy controls for information systems and organizations* (NIST Special Publication 800-53 Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5 +- National Institute of Standards and Technology. (2025, August 27). *NIST releases revision to SP 800-53 security and privacy controls (Release 5.2.0)*. https://csrc.nist.gov/news/2025/nist-releases-revision-to-sp-800-53-controls - Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). *Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile* (NIST AI 600-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.600-1 - American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. American Educational Research Association. -Implementation-specific research belongs in `docs/doctoring/` and ADR/traceability records beside the exact feature it constrains. A source citation without an executable invariant/test is documentation evidence only. +A source citation without an executable invariant/test is documentation evidence only. -## 13. Release gate +## 11. Release gate A commercial release is allowed only from one freshly fetched protected `develop` head that simultaneously proves: -- all release-scope PR dependencies are integrated in causal order; -- no unresolved valid review finding remains; -- every required exact-head deterministic gate is terminal-success, including authoritative Dependency Review rather than substitutes; -- protected-branch admission is satisfiable without synthetic approval or routine admin bypass; -- buyer vertical-slice E2E, accessibility, security, recovery and load evidence is terminal-success; -- migrations/rollback/backup-restore and tenant/purpose/audit invariants pass against production-equivalent PostgreSQL; -- documentation/ADR/TRD/API/events/schema/UI copy match the released implementation; -- release version and CHANGELOG identify the exact protected commit and migration/API compatibility; and -- no temporary self-modifying/source-fix workflow remains. - -Until that evidence exists, `0.1.0` and the lack of a published release are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. \ No newline at end of file +- release-scope dependencies integrated in causal order; +- no unresolved valid review finding; +- every required exact-head deterministic gate terminal-success, including authoritative Dependency Review rather than substitutes; +- satisfiable protected-branch admission without synthetic approval or routine admin bypass; +- buyer vertical-slice E2E, accessibility, security, recovery and load evidence terminal-success; +- migrations/rollback/backup-restore and tenant/purpose/audit invariants against production-equivalent PostgreSQL; +- documentation/ADR/TRD/API/events/schema/UI copy matching released implementation; +- release version and CHANGELOG bound to the exact protected commit and migration/API compatibility; +- immutable package/release plus SBOM/provenance/reproducibility/rollback evidence; and +- no temporary purpose-complete self-modifying/source-fix workflow. + +Until this evidence exists, version `0.1.0` and zero published releases are correctly treated as pre-commercial integration state rather than a release-management defect to paper over. \ No newline at end of file