Skip to content

feat(ui): add governed Job grade review states - #134

Draft
seonghobae wants to merge 11 commits into
feat/hr-workspace-protected-read-statefrom
feat/hr-workspace-job-grade-review-state
Draft

feat(ui): add governed Job grade review states#134
seonghobae wants to merge 11 commits into
feat/hr-workspace-protected-read-statefrom
feat/hr-workspace-job-grade-review-state

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Buyer-visible interaction gap

Parent #130 provides the shared protected-read accessibility state contract, but Job grade design review still lacked workflow-specific UI evidence for loading authoritative Job/Job Analysis evidence, human-only review, immutable review recording, stale evidence, authorization denial, and failure recovery.

This dependency-first slice consumes #130's existing Figma/Storybook interaction semantics and mirrors the separate #101 Job Grade Design Review governance boundary without importing that unmerged package, creating compensation/employment-decision authority, or reading foreign application tables.

RED → governed implementation

Initial head 772a69fe6ce6e5e6b008c29828eb966c90326504 intentionally contained only the regression and focused workflow; production Storybook/state owners were absent, so the gate was non-passing rather than silently absent.

After implementing the bounded state model, Storybook, CSS, traceability and primary accessibility references, exact head 56b759720ba6a56ec831bb16da8f313033100f47 produced a real hosted failure in run 33091441945, job 98585026421, at the exact-coverage interaction test. The first causal boundary was the regression itself: its whole-serialized-string privacy regex rejected required constant governance copy such as “does not authorize compensation,” even though no compensation value or field was present. Production semantics were not weakened. The regression was repaired to verify the exact allowed view-model key set plus explicit absence of value-bearing sensitive keys.

Current exact state

  • exact child head: 4d72fda8e3df41e6b4a9f81e3000895a446548b4
  • exact GitHub base recorded on this child: feat/hr-workspace-protected-read-state@b3b30058a79174000919d566fbbb1fdad80c62bf
  • current parent feat(ui): add accessible protected-read request states #130 head has since advanced to c92749cf5889a39de1ba8036742f96fd3451f459; therefore this child is intentionally stale relative to the live parent and must not inherit the parent's newer evidence
  • state: open · Draft · mergeable
  • exact-head workflow HR Workspace Job Grade Review State Quality run 33283652359, check/job 99182956631 (Job grade review state contract): terminal SUCCESS on 4d72fda8e3df41e6b4a9f81e3000895a446548b4
  • that focused contract is the only exact-head check-run currently materialized. Required browser/accessibility/Foundation/SAST/Security/Recovery/OpenCode/Noema/Strix/central coverage evidence is absent on this child head and therefore non-passing
  • there are no submitted reviews and no inline review threads; consequently there is no qualifying independent current-head non-author approval

Any predecessor-head GREEN/check/review evidence is historical and non-transferable.

Governed interaction contract

The governed states are idle, loading, review, recording, recorded, denied, stale, and error. In-flight states are busy and duplicate-submit disabled. review and recorded remain read-only/human-review evidence and explicitly do not authorize compensation, promotion, assignment, candidate, or employment decisions. Denial/stale/failure states use assertive alerts and always provide a safe next action. State evidence never carries Person/candidate identity, contact data, compensation/salary/rating/assessment values, credentials/tokens, prompts, or model output.

Storybook reuses Figma Orgmetra Baseline Storybook Inventory node 1:64 and existing Orgmetra design/focus tokens. WAI-ARIA 1.2 and WCAG 2.2 primary references plus protected-main/active-PR ownership distinctions are recorded under docs/doctoring and docs/traceability.

Dependency discipline

Keep Draft. Process #53#130 first. Because #130 has advanced beyond this child's recorded base, do not restack merely to manufacture fresh CI while the dependency root remains unintegrated. After those dependencies actually integrate, retarget/revalidate this child against fresh protected develop, reconcile intervening HR Workspace changes, and rerun every applicable browser/accessibility/Foundation/SAST/Security/Recovery/central workflow on one resulting exact head. This focused GREEN is stack-local and does not transfer parent checks or reviews.

Do not self-approve, use routine administrator bypass, race another lifecycle writer, infer compensation or employment-decision authority from UI state, transfer predecessor evidence, create no-op evidence churn, or mutate a dedicated-writer dependency.

@coderabbitai

coderabbitai Bot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: high

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant