feat(job-analysis): persist governed qualification-rule evidence - #105
Draft
seonghobae wants to merge 4 commits into
Draft
feat(job-analysis): persist governed qualification-rule evidence#105seonghobae wants to merge 4 commits into
seonghobae wants to merge 4 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Aug 24, 2026
seonghobae
marked this pull request as ready for review
August 25, 2026 23:30
seonghobae
marked this pull request as draft
August 26, 2026 11:08
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Buyer-visible gap
#104 creates non-authorizing human-review evidence for a proposed Job qualification rule; Orgmetra also needs a normalized durable persistence boundary for the reviewed rule artifact. This stacked Orgmetra-only lane adds immutable tenant-scoped qualification-rule persistence without evaluating candidates or granting employment-decision authority.
Retained persistence contract
Current child exact head remains
e9e4731b7bcd41db0e88186ae07e38742c0e220c. It implements tenant-scopedjob_qualification_rule_record, bitemporal version lineage, same-Job validated Job Analysis binding, SHA-256 review/provenance evidence, PostgreSQL-owned recorded time, immutable audit/outbox correlation, correction-not-rewrite history, TRUNCATE resistance and FORCE-RLS tenant isolation. Persisted state remainsrequires_authoritative_activationandnot_authorized_for_candidate_or_employment_decision; candidate/person PII, raw rule text, cut scores, assessment outcomes, compensation, prompts and model output remain absent.e9e4731b...is the valid ordinary successor to168f194...and retains trusted migration/functionsearch_pathcontrols, PostgreSQL regressions, repository inventory/manifest updates and traceability/ADR correction.Dependency boundary — 2026-09-06
Parent #104 is now exact
fde420ae11680a8b54eada785683db1afecca6bdon protecteddevelop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Its protected-parent/workflow-consolidation and docs-to-code repairs remain intact. Current exact-head #104 evidence is Foundation34017994517SUCCESS and SAST34017994471SUCCESS. Security34017994490is terminal FAILURE only in the dependency-review job after exact checkout atCheck dependency review support; OSV, Scorecard and Trivy are successful. CodeQL34017994488is terminal FAILURE only after both Python and Actions shards successfully request current-head dispatch and then failRelease runner or enforce current-head CodeQL verdict. These are central owner/control-plane failures, not permission to transfer predecessor evidence or bypass required checks.This child is still based on predecessor parent snapshot
d92ac4cb798b3bd32b632c0ab677c03f944070e4, so it does not contain #104's later trust-boundary, protected-parent, workflow-consolidation, or traceability repairs. Keep it Draft until #104 integrates normally.The child also contains its own historical
.github/workflows/job-qualification-rule-persistence-quality.ymlusingubuntu-latest. When #105 is eventually restacked, that workflow must not be carried blindly into protected truth. Its PostgreSQL/provenance and installed-artifact obligations must be reconciled into the canonical Foundation owner path, with a regression against workflow resurrection and a final manifest reseal.Required order
Keep Draft. Resolve #104's central exact-head gate availability/authorization and obtain qualifying independent approval → integrate #104 normally → non-force adopt/retarget #105 onto the resulting protected parent while preserving the complete
e9e4731b...persistence/search-path/PostgreSQL/provenance delta → reconcile the child workflow without resurrecting retired leaf CI → reseal exact final bytes → reacquire Foundation/SAST/Security/Recovery/PostgreSQL/package evidence.No force-push, destructive rebase, self-approval, routine administrator bypass, gate weakening, predecessor-evidence transfer, mutable-parent source copy, or simple Close.