Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
229 commits
Select commit Hold shift + click to select a range
095b899
test: define structured interview plan quality contract
seonghobae Aug 18, 2026
f4da61d
test: add RED structured interview plan regressions
seonghobae Aug 18, 2026
19a4a5f
feat: add governed structured interview plan
seonghobae Aug 18, 2026
12566d6
feat: export structured interview plan contract
seonghobae Aug 18, 2026
89cd211
docs: explain structured interview plan boundary
seonghobae Aug 18, 2026
fd89a19
docs: record structured interview plan slice
seonghobae Aug 18, 2026
043e5b4
docs: doctor structured interview plan evidence
seonghobae Aug 18, 2026
0dbba0f
docs: record structured interview plan decision
seonghobae Aug 18, 2026
735c27d
docs: trace structured interview plan contract
seonghobae Aug 18, 2026
dac45f0
ci: add structured interview plan quality gate
seonghobae Aug 18, 2026
ee043e8
refactor: keep interview plan builder explicitly typed
seonghobae Aug 18, 2026
91d9860
test: require question-to-competency mapping evidence
seonghobae Aug 18, 2026
e7a2a73
fix: bind questions to governed competency mapping evidence
seonghobae Aug 18, 2026
dd9f3aa
docs: bind interview questions to competency map evidence
seonghobae Aug 18, 2026
66ddaac
docs: record competency mapping hardening
seonghobae Aug 18, 2026
eca3fa7
docs: require question competency map evidence
seonghobae Aug 18, 2026
8c54d1f
docs: trace question competency mapping evidence
seonghobae Aug 18, 2026
092dd77
test: require cardinality-only interview error
seonghobae Aug 18, 2026
1e4ea43
fix: describe interview count constraint precisely
seonghobae Aug 18, 2026
ae03344
Merge branch 'develop' into feat/structured-interview-plan
opencode-agent[bot] Aug 19, 2026
40c3cbf
merge: reconcile structured interview plan with current protected dev…
seonghobae Aug 19, 2026
de15f6d
merge: reconcile structured interview plan with latest protected develop
seonghobae Aug 19, 2026
4b9633f
chore: reconcile structured interview plan with protected develop
seonghobae Aug 19, 2026
b8fd5be
test: reject value-bearing structured interview metadata
seonghobae Aug 19, 2026
870908d
fix: close structured interview metadata privacy boundary
seonghobae Aug 19, 2026
d0de9ad
test: use opaque UUID interview plan fixtures
seonghobae Aug 19, 2026
6eedc7b
docs: harden structured interview privacy guidance
seonghobae Aug 19, 2026
5fa63bb
docs: record structured interview privacy boundary
seonghobae Aug 19, 2026
62baef9
docs: trace structured interview privacy regressions
seonghobae Aug 19, 2026
fb42902
docs: record structured interview privacy hardening
seonghobae Aug 19, 2026
8154e96
Merge branch 'develop' into feat/structured-interview-plan
github-actions[bot] Aug 19, 2026
8093e76
test: require structured interview docstrings
seonghobae Aug 19, 2026
c60f900
docs: make structured interview regressions readable
seonghobae Aug 19, 2026
d9ffd07
chore: reconcile structured interview plan onto develop
seonghobae Aug 19, 2026
7d67ed6
test: require structured interview evidence version
seonghobae Aug 19, 2026
f139416
fix: bind structured interview evidence version
seonghobae Aug 19, 2026
9d76aa6
docs: trace structured interview evidence versions
seonghobae Aug 19, 2026
fd96303
merge develop into structured interview plan after #49
seonghobae Aug 19, 2026
2fbb6bd
test: reject UUIDv1 interview trust references
seonghobae Aug 19, 2026
cd58ec6
fix: require UUIDv4 interview trust references
seonghobae Aug 19, 2026
ac8a37c
docs: record UUIDv4 trust-reference boundary
seonghobae Aug 19, 2026
5cb75af
test: require tenant-scoped interview resolution
seonghobae Aug 19, 2026
39a5744
fix: require authoritative interview plan resolution
seonghobae Aug 19, 2026
1dc200b
docs: explain authoritative interview activation checks
seonghobae Aug 19, 2026
cfbf1d6
docs: record authoritative interview resolution boundary
seonghobae Aug 19, 2026
c1320d5
docs: trace authoritative interview activation evidence
seonghobae Aug 19, 2026
2955b57
docs: record authoritative interview activation hardening
seonghobae Aug 19, 2026
1ceca52
chore: reconcile interview plan onto restored develop
seonghobae Aug 19, 2026
09a3b8e
test: require honest interview activation traceability
seonghobae Aug 19, 2026
277bf47
docs: correct structured interview activation evidence boundary
seonghobae Aug 19, 2026
ff49751
test: reject correlating tenant UUIDv1 in interview plans
seonghobae Aug 20, 2026
2b320b2
fix: require opaque UUIDv4 tenant identity in interview plans
seonghobae Aug 20, 2026
01a7c3a
docs: bind interview-plan tenant identity to UUIDv4 opacity
seonghobae Aug 20, 2026
e4f388a
docs: require UUIDv4 tenant opacity in interview-plan ADR
seonghobae Aug 20, 2026
6261180
docs: trace UUIDv4 tenant opacity in interview plans
seonghobae Aug 20, 2026
9751d45
docs: record interview-plan tenant UUIDv4 hardening
seonghobae Aug 20, 2026
b4a0a56
Merge remote-tracking branch 'refs/remotes/origin/develop' into HEAD
seonghobae Aug 20, 2026
b0f1e18
test: require interview plans to accept canonical tenant UUIDv7
seonghobae Aug 20, 2026
456e548
fix: honor authoritative tenant UUID contract in interview plans
seonghobae Aug 20, 2026
b9cf166
docs: align interview tenant identity with Orgmetra core
seonghobae Aug 20, 2026
887c7c9
docs: separate tenant and packet UUID ownership
seonghobae Aug 20, 2026
ed90333
docs: trace authoritative tenant UUID interoperability
seonghobae Aug 20, 2026
e199842
docs: record tenant identity interoperability repair
seonghobae Aug 20, 2026
aee7389
chore: integrate protected develop into interview-plan lane
seonghobae Aug 20, 2026
211ce77
chore: reconcile structured interview plan with current develop
seonghobae Aug 20, 2026
4a274fe
test(interview-plan): expose duplicate ADR numbering
seonghobae Aug 20, 2026
b2da11c
fix(interview-plan): renumber ADR after job-analysis integration
seonghobae Aug 20, 2026
50540d5
test(interview-plan): require executable governed activation
seonghobae Aug 20, 2026
f69553f
feat(interview-plan): execute fail-closed human activation
seonghobae Aug 20, 2026
460c4e4
feat(interview-plan): export governed activation contracts
seonghobae Aug 20, 2026
69aa96b
test(interview-plan): satisfy executable docstring contract
seonghobae Aug 20, 2026
6e2fc73
docs(interview-plan): document executable activation boundary
seonghobae Aug 20, 2026
47197a0
docs(traceability): bind structured interview activation evidence
seonghobae Aug 20, 2026
953aa86
docs(adr): record executable activation decision
seonghobae Aug 20, 2026
48bc773
docs(changelog): record governed activation receipt
seonghobae Aug 20, 2026
2931805
test(interview-plan): align traceability regression with activation b…
seonghobae Aug 20, 2026
4e6d294
fix(interview-plan): remove unused receipt import
seonghobae Aug 20, 2026
09f88be
fix(interview-plan): remove protocol no-op expression
seonghobae Aug 20, 2026
ed3e99f
chore(interview-plan): integrate protected develop after #41
seonghobae Aug 20, 2026
867cb11
test(interview-plan): reject pre-generation approval evidence
seonghobae Aug 21, 2026
b3b5542
fix(interview-plan): enforce activation time ordering
seonghobae Aug 21, 2026
af5d7b2
docs(interview-plan): document activation chronology guard
seonghobae Aug 21, 2026
eddc92b
docs(interview-plan): record temporal integrity repair
seonghobae Aug 21, 2026
d4afadf
docs(interview-plan): trace activation chronology invariant
seonghobae Aug 21, 2026
6e6cc4f
test(interview-plan): prove temporal guard precedes authority
seonghobae Aug 21, 2026
d641400
test(interview): reject unvalidated activation plan objects
seonghobae Aug 21, 2026
0292790
fix(interview): require validated activation plan type
seonghobae Aug 21, 2026
049205d
docs(interview): document activation plan type boundary
seonghobae Aug 21, 2026
a2135d6
docs(interview): record activation plan type repair
seonghobae Aug 21, 2026
c8cfe76
docs(interview): trace validated activation plan boundary
seonghobae Aug 21, 2026
1f30abb
docs(interview): record exact activation plan type decision
seonghobae Aug 21, 2026
58f84fd
fix(interview-plan): remove unreachable protocol statement
seonghobae Aug 21, 2026
0476132
chore(interview-plan): integrate protected develop after #43
seonghobae Aug 21, 2026
656a374
test(interview-plan): bind approval time to authority
seonghobae Aug 21, 2026
e516cb5
fix(interview-plan): verify approval time at authority boundary
seonghobae Aug 21, 2026
33ecde8
test(interview-plan): adapt authority fixtures to approval time
seonghobae Aug 21, 2026
260ace0
test(interview-plan): align authority fixture contract
seonghobae Aug 21, 2026
42a6a28
docs(interview-plan): bind approval instant to authority
seonghobae Aug 21, 2026
680f977
docs(interview-plan): trace authoritative approval-time binding
seonghobae Aug 21, 2026
4ab7b82
docs(interview-plan): record authority-bound approval time
seonghobae Aug 21, 2026
11838bc
docs(interview-plan): record approval-time verification repair
seonghobae Aug 21, 2026
a4f5c55
test(interview-plan): reject recorded-time subclasses
seonghobae Aug 21, 2026
6afb318
fix(interview-plan): require exact recorded-time type
seonghobae Aug 21, 2026
138073d
test(interview-plan): align traceability activation regression
seonghobae Aug 21, 2026
1cb7dc5
test(interview-plan): reject forged string evidence types
seonghobae Aug 21, 2026
9cadc9f
fix(interview-plan): require exact string evidence types
seonghobae Aug 21, 2026
c944722
test(interview-plan): reject forged governance codes
seonghobae Aug 21, 2026
58eba76
fix(interview-plan): require exact governance-code text
seonghobae Aug 21, 2026
e1a2035
test(interview-plan): document runtime integrity regressions
seonghobae Aug 21, 2026
09a8fd4
test(interview-plan): name invalid approval timestamp
seonghobae Aug 21, 2026
d4a6ed6
refactor(interview-plan): make timestamp diagnostics field-aware
seonghobae Aug 21, 2026
f770a5f
fix(interview-plan): report approval timestamp failures precisely
seonghobae Aug 21, 2026
d26e5a7
test(interview-plan): require authoritative receipt issuance
seonghobae Aug 21, 2026
68a977f
fix(interview-plan): require authoritative receipt issuance
seonghobae Aug 21, 2026
70c9cce
test(interview-plan): reject receipt scope replacement
seonghobae Aug 21, 2026
a0d52aa
fix(interview-plan): consume receipt issuance capability
seonghobae Aug 21, 2026
febd6fe
test(interview-plan): require redacted verification repr
seonghobae Aug 21, 2026
2a83d9a
fix(interview-plan): redact activation verification repr
seonghobae Aug 21, 2026
2a662c0
test(interview-plan): reject mutable verification subclasses
seonghobae Aug 21, 2026
d8002d8
fix(interview-plan): require exact verification evidence type
seonghobae Aug 21, 2026
8a88fd4
test(interview-plan): reject forged verification scope strings
seonghobae Aug 21, 2026
e32ba5e
fix(interview-plan): require exact digest runtime type
seonghobae Aug 21, 2026
2d4945f
fix(interview-plan): validate exact authority scope evidence
seonghobae Aug 21, 2026
428b439
test(interview-plan): expose runtime evidence subclass forgery
seonghobae Aug 21, 2026
d6f32a6
fix(interview-plan): require exact canonical evidence containers
seonghobae Aug 21, 2026
050522a
docs(interview-plan): record canonical runtime-type hardening
seonghobae Aug 21, 2026
8aaf0b7
docs(traceability): bind exact runtime evidence types
seonghobae Aug 21, 2026
3c388a4
test(interview-plan): reject authority-time plan mutation
seonghobae Aug 21, 2026
d57cb69
fix(interview-plan): freeze plan evidence across authority call
seonghobae Aug 21, 2026
ae43337
docs(interview-plan): record authority-call snapshot integrity
seonghobae Aug 21, 2026
1e70ba4
docs(traceability): bind pre-authority plan snapshot
seonghobae Aug 21, 2026
ef8c4f7
docs(adr): close activation plan-mutation TOCTOU
seonghobae Aug 21, 2026
8d8896b
test(traceability): require activation snapshot evidence
seonghobae Aug 21, 2026
06637b8
test(interview-plan): reject rewritten activation receipts
seonghobae Aug 29, 2026
ab299c3
fix(interview-plan): bind receipts to issuance evidence
seonghobae Aug 29, 2026
8eb3a26
docs(interview-plan): trace receipt issuance integrity
seonghobae Aug 29, 2026
c907958
docs(interview-plan): record receipt integrity repair
seonghobae Aug 29, 2026
c678ad4
docs(interview-plan): define creation-bound receipt integrity
seonghobae Aug 29, 2026
072596e
test(interview-plan): expose post-issuance plan mutation
seonghobae Aug 29, 2026
ae291c6
fix(interview-plan): bind plan canonical evidence to issuance
seonghobae Aug 29, 2026
7a131cb
test(interview-plan): cover missing plan issuance evidence
seonghobae Aug 29, 2026
ee0791a
test(interview-plan): align authority mutation with plan seal
seonghobae Aug 29, 2026
b3ad9ce
test(interview-plan): cover plan seal cleanup fail-closure
seonghobae Aug 29, 2026
01c26f4
docs(interview-plan): record creation-bound plan integrity
seonghobae Aug 29, 2026
46a4bf3
docs(adr): bind structured interview plan issuance integrity
seonghobae Aug 29, 2026
33d700d
docs(traceability): cover creation-bound interview plans
seonghobae Aug 29, 2026
ae6a511
docs(interview-plan): explain creation-bound plan evidence
seonghobae Aug 29, 2026
d3cfc89
fix(interview-plan): remove obsolete mutation branch
seonghobae Aug 29, 2026
a750b11
test(interview-plan): make traceability assertion semantic
seonghobae Aug 29, 2026
2ac8894
test(interview-plan): expose activation integrity review findings
seonghobae Aug 29, 2026
cb38632
fix(interview-plan): make plan issuance seal single-registration
seonghobae Aug 29, 2026
b4b0150
fix(interview-plan): snapshot activation authority evidence
seonghobae Aug 29, 2026
0fef690
test(interview-plan): bind verification to approval instant
seonghobae Aug 29, 2026
927f2a2
test(interview-plan): attest reviewed approval time
seonghobae Aug 29, 2026
21fe4d9
test(interview-plan): keep mutation fixture contract-current
seonghobae Aug 29, 2026
76e9bac
test(interview-plan): keep type fixture contract-current
seonghobae Aug 29, 2026
b043b14
test(interview-plan): cover detached time and authority snapshots
seonghobae Aug 29, 2026
c3e3b65
docs(interview-plan): document detached activation evidence
seonghobae Aug 29, 2026
ba026ad
docs(interview-plan): record activation snapshot hardening
seonghobae Aug 29, 2026
db1ab58
docs(adr): define detached activation evidence boundary
seonghobae Aug 29, 2026
aae5006
docs(traceability): bind exact approval-time evidence
seonghobae Aug 29, 2026
52ae7df
test(interview-plan): bind traceability assertions to contract
seonghobae Aug 29, 2026
f3e8f23
test(interview-plan): prove immutable activation evidence boundaries
seonghobae Aug 29, 2026
ad83893
fix(interview-plan): detach activation evidence from runtime aliases
seonghobae Aug 29, 2026
1d90738
docs(interview-plan): align immutable activation evidence contract
seonghobae Aug 29, 2026
fc846e5
test(interview-plan): track detached activation traceability
seonghobae Aug 29, 2026
79b890b
test(interview-plan): reproduce mutable generated-time drift
seonghobae Aug 29, 2026
c476e91
fix(interview-plan): detach generated time before sealing
seonghobae Aug 29, 2026
6e923b3
docs(interview-plan): document generated-time detachment
seonghobae Aug 29, 2026
afc323a
docs(interview-plan): record generated-time integrity repair
seonghobae Aug 29, 2026
296b0fb
docs(adr): bind plan generation time to UTC snapshot
seonghobae Aug 29, 2026
2afcb01
docs(traceability): bind generated time to mutable-timezone regression
seonghobae Aug 29, 2026
460ed3c
test(interview-plan): reproduce UTC boundary overflow
seonghobae Aug 29, 2026
8878353
fix(interview-plan): fail closed on UTC range overflow
seonghobae Aug 29, 2026
054c3a7
fix(interview-plan): normalize approval range overflow
seonghobae Aug 29, 2026
3651948
docs(interview-plan): document UTC range fail-closure
seonghobae Aug 29, 2026
07b3bca
docs(adr): fail closed on unrepresentable UTC instants
seonghobae Aug 29, 2026
40a391a
docs(traceability): bind UTC boundary overflow regressions
seonghobae Aug 29, 2026
b7535b3
docs(interview-plan): record UTC boundary validation repair
seonghobae Aug 29, 2026
32f5211
test(interview-plan): reproduce receipt seal renewal
seonghobae Aug 29, 2026
7911661
fix(interview-plan): preserve receipt issuance seal
seonghobae Aug 29, 2026
3fd52e3
docs(interview-plan): record receipt single-registration seal
seonghobae Aug 29, 2026
a9ccc1e
docs(interview-plan): document receipt seal single registration
seonghobae Aug 29, 2026
885d787
docs(adr): prevent activation receipt seal renewal
seonghobae Aug 29, 2026
c67c869
docs(traceability): bind receipt seal renewal regression
seonghobae Aug 29, 2026
1a8a3cf
test(interview-plan): fail closed on hostile tzinfo evaluation
seonghobae Aug 29, 2026
7a02138
fix(interview-plan): normalize hostile plan timezone failures
seonghobae Aug 29, 2026
b023bc4
fix(interview-plan): normalize hostile activation timezone failures
seonghobae Aug 29, 2026
602f33e
test(interview-plan): normalize receipt timezone failures
seonghobae Aug 29, 2026
f54bfd7
fix(interview-plan): normalize canonical timestamp failures
seonghobae Aug 29, 2026
a4342c0
docs(interview-plan): record timezone trust-boundary repair
seonghobae Aug 29, 2026
49b05e0
docs(interview-plan): explain untrusted timezone handling
seonghobae Aug 29, 2026
5678d8b
docs(traceability): bind hostile timezone regressions
seonghobae Aug 29, 2026
34b20d8
docs(adr): treat timezone implementations as untrusted
seonghobae Aug 29, 2026
b84b57e
test(interview-plan): reject direct receipt minting with private sent…
seonghobae Aug 29, 2026
5ab76c1
fix(interview-plan): bind receipt issuance to verified factory
seonghobae Aug 29, 2026
4346c2c
test(interview-plan): require factory issuance for receipt export
seonghobae Aug 29, 2026
61ca1fe
docs(interview-plan): document factory-bound receipt issuance
seonghobae Aug 29, 2026
53b4010
docs(interview-plan): record verified-factory issuance repair
seonghobae Aug 29, 2026
f28556a
docs(traceability): bind receipt issuance to verified factory
seonghobae Aug 29, 2026
e115b86
docs(adr): make receipt issuance factory-bound
seonghobae Aug 29, 2026
4c25757
test(interview-plan): require supported Python compatibility lanes
seonghobae Aug 29, 2026
199be0c
build(interview-plan): pin coverage wheels for supported Python minors
seonghobae Aug 29, 2026
b428ed7
ci(interview-plan): test every supported Python minor
seonghobae Aug 29, 2026
fdf36e9
test(interview-plan): preserve factory receipt seal across revalidation
seonghobae Aug 29, 2026
1628b5d
test(interview-plan): hide receipt issuance capabilities from module …
seonghobae Aug 29, 2026
ebadac3
fix(interview-plan): encapsulate receipt issuance authority
seonghobae Aug 29, 2026
10fecfc
test(interview-plan): verify receipt reseal fail-closed through publi…
seonghobae Aug 29, 2026
c858c3e
fix(interview-plan): remove unreachable receipt reseal branch
seonghobae Aug 29, 2026
bd4d0cf
fix(interview-plan): preserve approval evidence field contract
seonghobae Aug 29, 2026
bf8897a
fix(ci): validate logical hashed requirements
seonghobae Aug 29, 2026
cb3b2a0
test(foundation): reproduce pipefail package lookup failure
seonghobae Aug 29, 2026
540b585
fix(foundation): make package lookup pipefail-safe
seonghobae Aug 29, 2026
242b088
test(interview-plan): reject constructor-bypassing issuance clone
seonghobae Aug 30, 2026
768b628
fix(interview-plan): bind issuance to constructor provenance
seonghobae Aug 30, 2026
c58fea3
docs(interview-plan): record constructor provenance boundary
seonghobae Aug 30, 2026
eea011a
docs(interview-plan): trace issuance provenance repair
seonghobae Aug 30, 2026
fe8a588
test(interview-plan): cover duplicate seal fail-closure
seonghobae Aug 30, 2026
c971494
test(interview-plan): reject direct class allocator issuance
seonghobae Aug 30, 2026
82b73d0
fix(interview-plan): gate issuance on full class construction
seonghobae Aug 30, 2026
a451072
docs(interview-plan): trace allocator provenance repair
seonghobae Aug 30, 2026
e367580
docs(interview-plan): define full-constructor provenance
seonghobae Aug 30, 2026
032de12
docs(interview-plan): trace full-constructor issuance proof
seonghobae Aug 30, 2026
ab035c4
test(interview-plan): reproduce timezone provenance reentrancy
seonghobae Aug 30, 2026
f7ca68b
fix(interview-plan): consume constructor provenance before callbacks
seonghobae Aug 30, 2026
78e7542
docs(interview-plan): document one-shot constructor provenance
seonghobae Aug 30, 2026
22551cc
docs(interview-plan): record reentrant constructor boundary
seonghobae Aug 30, 2026
da4162c
docs(interview-plan): changelog timezone reentrancy repair
seonghobae Aug 30, 2026
6917e41
docs(interview-plan): trace timezone provenance reentrancy
seonghobae Aug 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions .github/requirements/foundation-test.txt
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
# Reviewed Foundation CI test toolchain for CPython 3.14 on GitHub-hosted Ubuntu x86_64.
# Reviewed Foundation CI test toolchain for CPython 3.12-3.14 on GitHub-hosted Ubuntu x86_64.
# Version and artifact hash changes must be reverified against the official PyPI release JSON.
coverage==7.14.2 --hash=sha256:cda36d8e7bfd63b3e44e75163265429caa5d935b672b00f71bccc8c010518c64
coverage==7.14.2 \
--hash=sha256:8b4910cce599cd2438f8da65f5ef199a70a1cdb6ab314926df78271ca5954240 \
--hash=sha256:1d9a1b5813d00ea6151f6ccf64d1fa16892771dfdda12ba87162d15ec4ea3e1e \
--hash=sha256:cda36d8e7bfd63b3e44e75163265429caa5d935b672b00f71bccc8c010518c64
iniconfig==2.3.0 --hash=sha256:f631c04d2c48c52b84d0d0549c99ff3859c98df65b3101406327ecc7d53fbf12
packaging==26.2 --hash=sha256:5fc45236b9446107ff2415ce77c807cee2862cb6fac22b8a73826d0693b0980e
pluggy==1.6.0 --hash=sha256:e920276dd6813095e9377c0bc5566d94c932c33b27a3e3945d8389c374dd4746
Expand Down
104 changes: 104 additions & 0 deletions .github/workflows/interview-plan-quality.yml
Comment thread
devin-ai-integration[bot] marked this conversation as resolved.
Comment thread
devin-ai-integration[bot] marked this conversation as resolved.
Original file line number Diff line number Diff line change
@@ -0,0 +1,104 @@
name: Structured Interview Plan Quality

on:
pull_request:
branches:
- develop
paths:
- "packages/interview-plan/**"
- ".github/requirements/foundation-test.txt"
- ".github/workflows/interview-plan-quality.yml"
- ".gitignore"
- ".python-version"
- "conftest.py"
- "packages/conftest.py"
- "pyproject.toml"
- "pytest.ini"
- "setup.cfg"
- "tox.ini"
- "docs/adr/0015-governed-structured-interview-plan.md"
- "docs/doctoring/structured-interview-plan-references.md"
- "docs/traceability/structured-interview-plan.md"
workflow_dispatch:
Comment thread
seonghobae marked this conversation as resolved.

permissions:
contents: read

concurrency:
group: structured-interview-plan-quality-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
unit:
name: Structured interview plan contract and 100% coverage
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout exact candidate
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- name: Prove exact candidate checkout
env:
ORGMETRA_EXPECTED_HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: test "$(git rev-parse HEAD)" = "$ORGMETRA_EXPECTED_HEAD_SHA"
- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.14"
Comment thread
devin-ai-integration[bot] marked this conversation as resolved.
check-latest: false
- name: Install reviewed test toolchain
run: |
python -m pip install --require-hashes --no-deps --only-binary=:all: -r .github/requirements/foundation-test.txt
python -m pip check
- name: Compile structured interview plan package
run: python -m compileall -q packages/interview-plan/src packages/interview-plan/tests
- name: Test structured interview plan with exact statement and branch coverage
env:
PYTHONPATH: packages/interview-plan/src
COVERAGE_FILE: /tmp/orgmetra-structured-interview-plan.coverage
run: python -m pytest -c packages/interview-plan/pyproject.toml packages/interview-plan/tests
- name: Require clean checkout
run: |
git diff --exit-code
test -z "$(git status --porcelain)"
Comment thread
seonghobae marked this conversation as resolved.

compatibility:
name: Python ${{ matrix.python-version }} compatibility and 100% coverage
runs-on: ubuntu-latest
timeout-minutes: 10
strategy:
fail-fast: false
matrix:
python-version: ["3.12", "3.13"]
steps:
- name: Checkout exact candidate
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- name: Prove exact candidate checkout
env:
ORGMETRA_EXPECTED_HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: test "$(git rev-parse HEAD)" = "$ORGMETRA_EXPECTED_HEAD_SHA"
- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}
check-latest: false
- name: Install reviewed test toolchain
run: |
python -m pip install --require-hashes --no-deps --only-binary=:all: -r .github/requirements/foundation-test.txt
python -m pip check
- name: Compile structured interview plan package
run: python -m compileall -q packages/interview-plan/src packages/interview-plan/tests
- name: Test supported Python with exact statement and branch coverage
env:
PYTHONPATH: packages/interview-plan/src
COVERAGE_FILE: /tmp/orgmetra-structured-interview-plan-${{ matrix.python-version }}.coverage
run: python -m pytest -c packages/interview-plan/pyproject.toml packages/interview-plan/tests
- name: Require clean checkout
run: |
git diff --exit-code
test -z "$(git status --porcelain)"
72 changes: 72 additions & 0 deletions docs/adr/0015-governed-structured-interview-plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
# ADR 0015: Govern structured-interview plans as candidate-neutral evidence

- **Status:** Proposed — active PR only
- **Date:** 2026-08-18

## Context

Orgmetra already separates authoritative Job/Position/Assignment truth, governed requisition review, selection evidence, and accountable human employment decisions. A buyer still needs a defensible boundary between an approved opening and the interview that will be used as a selection procedure.

A structured interview is stronger when assessed competencies come from current job analysis, candidates receive the same predetermined questions, and responses are evaluated against common rating standards. A question count cannot prove that each governed competency is represented, so the approved question-to-competency mapping needs its own immutable evidence identity. Candidate identity, assessment values, and semantic/value-bearing labels are unnecessary at this pre-use boundary and would increase privacy risk. Packet-owned trust references therefore use UUIDv4; the authoritative tenant identifier instead follows Orgmetra core's canonical non-sentinel operational UUID contract.

Opaque identities and artifact digests identify evidence but do not prove tenant ownership, requisition-to-Job-to-job-analysis relationships, or distinct human identities. Those relationships must be re-resolved at authoritative owner boundaries immediately before activation. A prose-only `next_action` is insufficient: the package needs an executable host boundary that cannot issue activation evidence when authoritative checks reject or when returned verification evidence belongs to another plan, actor, or approval instant.

Plan-generation time and approval time are trust-bearing evidence. Caller-controlled mutable timezone state must not make one governed instant later represent a different UTC instant. Caller-owned `tzinfo` implementations are executable code and may raise arbitrary exceptions while `utcoffset()` is evaluated; such failures and unrepresentable UTC normalization must become field-specific governed validation before plan issuance, authority side effects, verification acceptance, or canonical export. Constructor provenance must also not remain ambient while such caller code runs: otherwise a reentrant timezone callback can invoke the plan allocator, retain a second object that inherits constructor eligibility, populate it later with otherwise valid fields, and mint issuance evidence without a normal class construction.

Python `frozen=True` is not an adversarial immutability or authorization boundary. `object.__setattr__` can rewrite dataclass fields, and low-level allocation can create a dataclass-shaped instance without completing its governed constructor. Merely executing a class `__new__` method is also not proof of construction because callers can invoke that allocator directly. A module-private constructor token is still reachable by Python callers. Therefore receipt shape construction must not itself confer human-approval authority, and plan issuance must prove that the exact live object entered through the normal full `StructuredInterviewPlan(...)` construction path before `__post_init__` may register creation evidence. Plan construction may register process-local integrity evidence because construction is the governed plan-issuance boundary, but activation-receipt issuance evidence must be registered only by the verified activation factory after authoritative host checks and exact-scope matching have completed.

## Decision

Add a transport-neutral `StructuredInterviewPlan` value object that binds:

- canonical non-sentinel Orgmetra tenant identity and one UUIDv4-backed opaque interview-plan reference;
- UUIDv4-backed requisition and authoritative Job references;
- exact job-analysis, question-set, question-to-competency mapping, and rating-anchor references plus independent SHA-256 digests;
- sorted, unique job-related competency references and a bounded 2–8 actor interviewer panel;
- a bounded question count at least as large as the governed competency count, while the separately bound mapping artifact supplies actual coverage evidence; and
- fixed purpose `structured_interview_plan`, closed reason `approved_requisition_interview`, bounded positive `evidence_version`, precision-preserving UTC time, mandatory human confirmation, and `requires_human_approval` state.

`tenant_record_id` follows the authoritative operational UUID contract. Packet-owned trust-bearing references require canonical non-sentinel UUIDv4 plus their expected namespace. Names, labels, compensation/protected-attribute values, and other semantic suffixes fail closed. Direct construction, builder construction, and `dataclasses.replace(...)` share the same plan validation. `evidence_version` is serialized canonically and changes immutable SHA-256 correlation when revised. Routine plan representation is fully redacted.

Before plan issuance evidence is registered, detach caller-owned `generated_at` into one built-in UTC `datetime` using one concrete offset read from the original aware value. Treat offset evaluation as an untrusted-code boundary: exceptions and offset arithmetic beyond Python's representable `datetime` range become the same field-specific `ValueError`. Store the built-in UTC snapshot rather than caller-owned `tzinfo` state. Canonical timestamp rendering reuses this fail-closed detachment.

A private metaclass arms a context-local **one-shot allocator ticket** immediately before the normal `StructuredInterviewPlan(...)` class construction. The exact `StructuredInterviewPlan.__new__()` invocation consumes that ticket before any field validation, `tzinfo.utcoffset()` call, or other caller-controlled callback can execute, then records construction eligibility only for that exact live object. Successful `__post_init__()` requires and consumes that provenance, computes a process-local HMAC over the canonical plan payload, registers the seal outside plan-writable slots, and records the exact identity as issued. Registration remains single-use for one live plan identity. `canonical_json()` requires exact issued-identity membership plus creation-bound HMAC evidence and uses constant-time comparison before returning bytes; `sha256_digest()` is downstream. An `object.__new__` clone, direct `StructuredInterviewPlan.__new__(StructuredInterviewPlan)` allocation, or allocator call reached reentrantly from caller-owned timezone code cannot call `__post_init__()` to mint fresh issuance evidence because none receives or retains the already-consumed constructor ticket. Low-level mutation, copied/reconstructed identities, missing issuance evidence, and attempted plan resealing fail closed. These context/identity/HMAC controls are same-process integrity evidence only, not a hostile-interpreter capability boundary, persisted signing scheme, portable signature, or replacement for immutable audit/outbox evidence.

Make authoritative activation executable through `StructuredInterviewActivationAuthority` and `activate_structured_interview_plan(...)`. Before authority work, activation requires the exact governed `StructuredInterviewPlan` runtime type, obtains creation-bound canonical plan JSON, derives tenant/interview-plan scope and SHA-256 from those bytes, detaches caller-owned `approved_at` into built-in UTC, validates the approving actor, and rejects chronology before plan generation. The authority receives only detached canonical plan JSON, its exact digest, approving actor, and normalized approval instant—never the live plan object. A retained alias therefore cannot change what the authority reviews through a temporary change-and-restore cycle; non-restored mutation is still rejected by the post-authority plan integrity check.

Implement `StructuredInterviewActivationVerification` as an exact `NamedTuple` carrying tenant, interview-plan reference, plan digest, approving actor, authority-evidence reference/digest, and reviewed `approved_at`. Activation rejects subclasses, unpacks the exact tuple once, normalizes returned approval time through the same fail-closed UTC helper, validates returned values, and compares the complete tenant/plan/digest/actor/time scope against the pre-call request.

`StructuredInterviewActivationReceipt` is a value-minimized receipt shape, not an authorization primitive. Its dataclass constructor validates tenant/reference/digest/time/fixed-governance values but **does not register issuance evidence**. Direct construction and `dataclasses.replace(...)` therefore produce unissued values whose `canonical_json()` and `sha256_digest()` fail closed. The constructor has no issuance-token parameter; a module-private legacy sentinel confers no authority and is retained only as a regression target proving that callers cannot mint issued receipts by importing a private module attribute.

Only after `activate_structured_interview_plan(...)` has accepted exact verification evidence, normalized the returned approval instant, validated all returned fields, and matched tenant, interview-plan reference, plan digest, approving actor, and approval time does it construct the receipt and register a process-local HMAC seal over that exact canonical payload. Issued receipt canonical export recomputes and constant-time compares the seal. Any low-level post-issuance rewrite or missing issuance evidence fails closed. The seal is same-process integrity evidence only; it is not a durable signing key, portable attestation, cross-process rehydration credential, or substitute for the host's immutable audit/outbox record.

The issued receipt records the exact plan digest, accountable UUIDv4 approving actor, authority-verification reference/digest, fixed purpose `structured_interview_activation`, fixed reason `human_approved_plan_activation`, bounded positive evidence version, detached precision-preserving UTC approval time, `human_confirmation=True`, and fixed `approved_for_use` state. Routine receipt and verification representations are fully redacted. The plan and receipt remain candidate-neutral: they contain no candidate identity, response, score, demographic attribute, compensation value, free-form model output, provider credential, or final selection recommendation.

## Consequences

### Positive

- Buyers can prove which Job Analysis, competencies, questions, mapping, rating anchors, panel, and evidence revision were reviewed before candidate use.
- Caller-controlled timezone failures and mutable timezone state cannot silently redefine governed plan or approval instants.
- Constructor-bypassing `object.__new__` clones, direct class-allocator calls, and reentrant allocator calls from caller-owned timezone callbacks cannot mint creation-bound plan issuance evidence merely by copying valid fields and invoking `__post_init__()`.
- The authoritative adapter reviews detached creation-bound plan evidence rather than a caller-owned live plan object.
- Authority verification fields are tuple-immutable at runtime and exact-type checked before one-time unpacking.
- A caller cannot mint an `approved_for_use` evidence artifact by importing a private constructor sentinel: direct and replaced receipt values remain unissued and cannot export canonical evidence.
- Receipt issuance is causally ordered after authoritative host verification and exact tenant/plan/digest/actor/time matching.
- Post-issuance receipt mutation and missing process-local issuance evidence fail closed before canonical export.
- Candidate PII and assessment values remain outside planning and activation artifacts.
- The authority protocol preserves standalone operation and later MSA extraction without cross-service application-table SQL or duplicated foreign-service state.

### Costs and constraints

- The package does not persist requisitions, Job Analysis, interview questions/mappings, responses, scores, or authoritative relationship-resolution results.
- The authority protocol is not proof that a concrete production adapter performs tenant/database/API checks correctly; production adapters still need executable integration evidence and immutable authority/audit records.
- Plan and activation-receipt HMAC seals and live-identity provenance exist only for the lifetime of their in-process objects. They are not portable signatures, durable verification credentials, or key-management facilities.
- Directly constructed receipt values are intentionally unusable as authoritative evidence until a supported future rehydration/issuance contract exists.
- Human approval remains mandatory; model output cannot activate or approve the plan.
- UUID/digest metadata and reference inequality do not establish tenant ownership, identity separation, scientific validity, fairness, or legal compliance.
- This ADR remains proposed until its exact PR head merges into protected `develop`.

## References

See `docs/doctoring/structured-interview-plan-references.md`.
17 changes: 17 additions & 0 deletions docs/doctoring/structured-interview-plan-references.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Structured interview plan references

These sources inform the active-PR structured-interview planning contract. They do not establish certification or replace organization-specific legal review, job analysis, validation, or adverse-impact monitoring.

## APA 7 references

International Organization for Standardization. (2023). *ISO 30405:2023 human resource management — Guidelines on recruitment* (2nd ed.). https://www.iso.org/standard/79488.html

U.S. Equal Employment Opportunity Commission. (1979, March 1). *Questions and answers to clarify and provide a common interpretation of the Uniform Guidelines on Employee Selection Procedures*. https://www.eeoc.gov/laws/guidance/questions-and-answers-clarify-and-provide-common-interpretation-uniform-guidelines

U.S. Office of Personnel Management. (n.d.). *Structured interviews*. Retrieved August 18, 2026, from https://www.opm.gov/policy-data-oversight/assessment-and-selection/structured-interviews/

U.S. Office of Personnel Management. (n.d.). *How do I select the competencies, or content areas, I want to assess with the structured interview?* Retrieved August 18, 2026, from https://www.opm.gov/frequently-asked-questions/assessment-policy-faq/structured-interviews/how-do-i-select-the-competencies-or-content-areas-i-want-to-assess-with-the-structured-interview/

## Applied boundary

OPM describes structured interviews as standardized, job-related assessment methods using predetermined questions and common rating standards, with competencies selected from job analysis and confirmed by subject-matter experts. The UGESP guidance emphasizes documenting job relatedness and the basis for selection procedures. ISO 30405:2023 provides current recruitment-process guidance covering assessment and stakeholder management. Orgmetra therefore binds the interview plan to exact job-analysis evidence, predetermined question/rating artifacts, and accountable human review before candidate use.
Loading
Loading