Skip to content

feat(job-analysis): persist governed qualification-rule evidence - #105

Draft
seonghobae wants to merge 4 commits into
feat/job-qualification-rule-reviewfrom
feat/job-qualification-rule-persistence
Draft

feat(job-analysis): persist governed qualification-rule evidence#105
seonghobae wants to merge 4 commits into
feat/job-qualification-rule-reviewfrom
feat/job-qualification-rule-persistence

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Buyer-visible gap

#104 creates non-authorizing human-review evidence for a proposed Job qualification rule; Orgmetra also needs a normalized durable persistence boundary for the reviewed rule artifact. This stacked Orgmetra-only lane adds immutable tenant-scoped qualification-rule persistence without evaluating candidates or granting employment-decision authority.

Retained persistence contract

Current child exact head remains e9e4731b7bcd41db0e88186ae07e38742c0e220c. It implements tenant-scoped job_qualification_rule_record, bitemporal version lineage, same-Job validated Job Analysis binding, SHA-256 review/provenance evidence, PostgreSQL-owned recorded time, immutable audit/outbox correlation, correction-not-rewrite history, TRUNCATE resistance and FORCE-RLS tenant isolation. Persisted state remains requires_authoritative_activation and not_authorized_for_candidate_or_employment_decision; candidate/person PII, raw rule text, cut scores, assessment outcomes, compensation, prompts and model output remain absent.

e9e4731b... is the valid ordinary successor to 168f194... and retains trusted migration/function search_path controls, PostgreSQL regressions, repository inventory/manifest updates and traceability/ADR correction.

Dependency boundary — 2026-09-06

Parent #104 is now exact fde420ae11680a8b54eada785683db1afecca6bd on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Its protected-parent/workflow-consolidation and docs-to-code repairs remain intact. Current exact-head #104 evidence is Foundation 34017994517 SUCCESS and SAST 34017994471 SUCCESS. Security 34017994490 is terminal FAILURE only in the dependency-review job after exact checkout at Check dependency review support; OSV, Scorecard and Trivy are successful. CodeQL 34017994488 is terminal FAILURE only after both Python and Actions shards successfully request current-head dispatch and then fail Release runner or enforce current-head CodeQL verdict. These are central owner/control-plane failures, not permission to transfer predecessor evidence or bypass required checks.

This child is still based on predecessor parent snapshot d92ac4cb798b3bd32b632c0ab677c03f944070e4, so it does not contain #104's later trust-boundary, protected-parent, workflow-consolidation, or traceability repairs. Keep it Draft until #104 integrates normally.

The child also contains its own historical .github/workflows/job-qualification-rule-persistence-quality.yml using ubuntu-latest. When #105 is eventually restacked, that workflow must not be carried blindly into protected truth. Its PostgreSQL/provenance and installed-artifact obligations must be reconciled into the canonical Foundation owner path, with a regression against workflow resurrection and a final manifest reseal.

Required order

Keep Draft. Resolve #104's central exact-head gate availability/authorization and obtain qualifying independent approval → integrate #104 normally → non-force adopt/retarget #105 onto the resulting protected parent while preserving the complete e9e4731b... persistence/search-path/PostgreSQL/provenance delta → reconcile the child workflow without resurrecting retired leaf CI → reseal exact final bytes → reacquire Foundation/SAST/Security/Recovery/PostgreSQL/package evidence.

No force-push, destructive rebase, self-approval, routine administrator bypass, gate weakening, predecessor-evidence transfer, mutable-parent source copy, or simple Close.

@coderabbitai

coderabbitai Bot commented Aug 24, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 4 potential issues.

Open in Devin Review

Comment thread tests/test_job_qualification_rule_persistence_postgres.sh
Comment thread database/migrations/0019_job_qualification_rule_persistence.sql
Comment thread database/migrations/0019_job_qualification_rule_persistence.sql
Comment thread database/migrations/0019_job_qualification_rule_persistence.sql
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant