Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
107 commits
Select commit Hold shift + click to select a range
7640ba7
test: scaffold selection monitoring contract
seonghobae Aug 18, 2026
523f613
test: define governed selection monitoring RED contract
seonghobae Aug 18, 2026
83e23e3
feat: implement governed selection monitoring plan
seonghobae Aug 18, 2026
9fec450
feat: expose selection monitoring contract
seonghobae Aug 18, 2026
41671e3
docs: explain selection monitoring boundary
seonghobae Aug 18, 2026
4239a6c
docs: record selection monitoring package change
seonghobae Aug 18, 2026
a6fd5ef
docs: record selection monitoring architecture decision
seonghobae Aug 18, 2026
f84a1ed
docs: doctor selection monitoring evidence
seonghobae Aug 18, 2026
313a6ce
docs: trace selection monitoring contract
seonghobae Aug 18, 2026
0aea81f
ci: verify selection monitoring exact head
seonghobae Aug 18, 2026
10e104f
test: require authoritative monitoring actor separation
seonghobae Aug 19, 2026
e033229
fix: require authoritative monitoring actor separation
seonghobae Aug 19, 2026
4084637
docs: require authoritative monitoring actor separation
seonghobae Aug 19, 2026
fb1b202
docs: bind monitoring review to resolved actors
seonghobae Aug 19, 2026
66c2f96
docs: trace authoritative monitoring actor separation
seonghobae Aug 19, 2026
1398e0e
chore: reconcile selection monitoring with protected develop
seonghobae Aug 19, 2026
1794ec6
test: reject value-bearing selection monitoring references
seonghobae Aug 19, 2026
d9719d5
test: use opaque UUID actor references
seonghobae Aug 19, 2026
8d7fa50
test: use opaque UUID monitoring references
seonghobae Aug 19, 2026
5382a9b
fix: enforce opaque UUID monitoring references
seonghobae Aug 19, 2026
21fff39
docs: document opaque UUID monitoring references
seonghobae Aug 19, 2026
d65f9c3
docs: bind monitoring evidence to opaque UUID references
seonghobae Aug 19, 2026
fb47b85
docs: trace opaque monitoring reference hardening
seonghobae Aug 19, 2026
9c72d21
docs: record opaque reference hardening
seonghobae Aug 19, 2026
6cede8f
chore: reconcile selection monitoring with protected develop
seonghobae Aug 19, 2026
ed5b451
test: close selection monitoring metadata privacy boundary
seonghobae Aug 19, 2026
0e661c1
fix: close selection monitoring metadata privacy boundary
seonghobae Aug 19, 2026
ba3346e
docs: harden selection monitoring metadata guidance
seonghobae Aug 19, 2026
d37460b
Merge branch 'develop' into feat/selection-outcome-monitoring-plan
github-actions[bot] Aug 19, 2026
d81260c
test: require monitoring evidence versioning
seonghobae Aug 19, 2026
9354688
fix: version selection monitoring evidence
seonghobae Aug 19, 2026
1291078
docs: bind monitoring evidence version
seonghobae Aug 19, 2026
de95314
docs: trace monitoring evidence versioning
seonghobae Aug 19, 2026
7f12f3b
docs: record monitoring evidence version decision
seonghobae Aug 19, 2026
0f8afd4
chore: note monitoring evidence versioning
seonghobae Aug 19, 2026
3162cb1
chore: reconcile selection monitoring onto develop
seonghobae Aug 19, 2026
f3018e8
test(selection-monitoring): require tenant-scoped reference resolution
seonghobae Aug 19, 2026
d156086
fix(selection-monitoring): bind all evidence to tenant scope
seonghobae Aug 19, 2026
9681cec
docs(selection-monitoring): align tenant reference boundary
seonghobae Aug 19, 2026
91343cd
docs(selection-monitoring): require tenant-scoped evidence resolution
seonghobae Aug 19, 2026
aeda590
docs(selection-monitoring): trace tenant-scope regression
seonghobae Aug 19, 2026
25904db
docs(selection-monitoring): record tenant binding repair
seonghobae Aug 19, 2026
3886a72
merge: reconcile selection monitoring with protected develop
seonghobae Aug 19, 2026
b0ee366
test(selection-monitoring): align tenant next-action assertion
seonghobae Aug 19, 2026
072310d
chore(selection-monitoring): reconcile protected develop
seonghobae Aug 19, 2026
2207c3e
test: reject UUIDv1 selection monitoring references
seonghobae Aug 20, 2026
46d3330
fix: require UUIDv4 selection monitoring references
seonghobae Aug 20, 2026
9615799
docs: define UUIDv4 selection monitoring references
seonghobae Aug 20, 2026
a1183a6
test: reject correlating tenant UUIDv1 in selection monitoring
seonghobae Aug 20, 2026
3dca553
fix: require opaque UUIDv4 tenant identity in selection monitoring
seonghobae Aug 20, 2026
7ce805b
docs: bind selection-monitoring tenant identity to UUIDv4 opacity
seonghobae Aug 20, 2026
2ece209
docs: require UUIDv4 tenant opacity in selection monitoring ADR
seonghobae Aug 20, 2026
670645c
docs: trace UUIDv4 tenant opacity in selection monitoring
seonghobae Aug 20, 2026
28b5e9e
docs: record selection-monitoring tenant UUIDv4 hardening
seonghobae Aug 20, 2026
f7d6a3e
Merge remote-tracking branch 'refs/remotes/origin/develop' into HEAD
seonghobae Aug 20, 2026
f86c897
test: require selection monitoring to accept core tenant UUIDv7
seonghobae Aug 20, 2026
884e229
fix: honor authoritative tenant UUID contract in selection monitoring
seonghobae Aug 20, 2026
6f4b026
docs: align monitoring tenant identity with core
seonghobae Aug 20, 2026
efab4bc
docs: separate monitoring tenant and packet UUID ownership
seonghobae Aug 20, 2026
6fffea3
docs: trace monitoring tenant UUID interoperability
seonghobae Aug 20, 2026
acc3d38
docs: record monitoring tenant identity interoperability repair
seonghobae Aug 20, 2026
f891a61
chore: integrate protected develop into selection-monitoring lane
seonghobae Aug 20, 2026
345f5bf
chore: reconcile selection monitoring with current develop
seonghobae Aug 20, 2026
0eb697c
chore(selection-monitoring): integrate protected develop after #41
seonghobae Aug 20, 2026
a306d81
test(selection-monitoring): cover direct reference construction
seonghobae Aug 21, 2026
ea8f62a
chore(selection-monitoring): integrate protected develop after #43
seonghobae Aug 21, 2026
d907600
test(selection-monitoring): reject temporal evidence subclasses
seonghobae Aug 21, 2026
200c4c5
fix(selection-monitoring): require exact temporal evidence types
seonghobae Aug 21, 2026
5c40ca0
test(selection-monitoring): reject forged string evidence types
seonghobae Aug 21, 2026
3c581c5
fix(selection-monitoring): require exact string evidence types
seonghobae Aug 21, 2026
cdbc2c0
test(selection-monitoring): reject forged governance codes
seonghobae Aug 21, 2026
87a6633
fix(selection-monitoring): require exact governance-code text
seonghobae Aug 21, 2026
f318944
test(selection-monitoring): reject forged fixed governance text
seonghobae Aug 21, 2026
8a0b111
fix(selection-monitoring): protect fixed governance runtime types
seonghobae Aug 21, 2026
0cb4eda
test(selection-monitoring): detach mutable generated-time timezone
seonghobae Aug 23, 2026
f4c38d6
test(selection-monitoring): pin generation-time issuance integrity
seonghobae Aug 23, 2026
a976c91
fix(selection-monitoring): freeze generated-time evidence
seonghobae Aug 23, 2026
c130984
test(selection-monitoring): cover frozen-time fail-closed paths
seonghobae Aug 23, 2026
4f2ac38
docs(selection-monitoring): record generation-time integrity repair
seonghobae Aug 23, 2026
eb3b12b
docs(selection-monitoring): explain frozen generation time
seonghobae Aug 23, 2026
9b871a3
docs(selection-monitoring): trace generation-time integrity
seonghobae Aug 23, 2026
769bca8
test(selection-monitoring): reject post-issuance evidence rewrites
seonghobae Aug 26, 2026
26fa602
fix(selection-monitoring): seal issued canonical evidence
seonghobae Aug 26, 2026
c514370
docs(selection-monitoring): record issuance integrity repair
seonghobae Aug 26, 2026
dc6516d
docs(selection-monitoring): explain process-local issuance seal
seonghobae Aug 26, 2026
1f389c9
docs(selection-monitoring): trace issuance tamper evidence
seonghobae Aug 26, 2026
80dff1d
test(selection-monitoring): reject digest string subclasses
seonghobae Aug 26, 2026
7496d93
fix(selection-monitoring): require exact digest strings
seonghobae Aug 26, 2026
b92cfa9
docs(selection-monitoring): inventory runtime integrity regressions
seonghobae Aug 26, 2026
6edd528
docs(selection-monitoring): record exact digest runtime contract
seonghobae Aug 26, 2026
fca4041
test(selection-monitoring): cover copied issuance plans
seonghobae Aug 28, 2026
3be942d
test(selection-monitoring): reject live reference reissuance
seonghobae Aug 29, 2026
acc99ff
fix(selection-monitoring): bind live plan references
seonghobae Aug 29, 2026
5bb5fb3
revert(selection-monitoring): preserve versioned reference semantics
seonghobae Aug 29, 2026
a9823aa
revert(selection-monitoring): retain revision evidence semantics
seonghobae Aug 29, 2026
7bfc85b
test(selection-monitoring): reject issuance seal renewal
seonghobae Aug 29, 2026
051608d
fix(selection-monitoring): prevent issuance seal renewal
seonghobae Aug 29, 2026
f5d91b1
docs(selection-monitoring): bind single-use issuance seal
seonghobae Aug 29, 2026
6760e4d
test(selection-monitoring): require shared config quality triggers
seonghobae Aug 29, 2026
e4ddfa4
fix(selection-monitoring): retrigger quality on shared config
seonghobae Aug 29, 2026
08d668d
docs(selection-monitoring): record shared-config gate integrity
seonghobae Aug 29, 2026
874e004
docs(selection-monitoring): trace shared-config quality evidence
seonghobae Aug 29, 2026
a258779
test(selection-monitoring): reject seal-loss reissuance
seonghobae Aug 30, 2026
b1d03ed
fix(selection-monitoring): preserve single-use issuance after seal loss
seonghobae Aug 30, 2026
fb03c08
fix(selection-monitoring): make issuance registration atomic
seonghobae Aug 30, 2026
b357ade
ci(selection-monitoring): consolidate quality into Foundation
seonghobae Sep 6, 2026
ec35dc8
ci(foundation): discover delegated artifact contracts
seonghobae Sep 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 47 additions & 0 deletions docs/adr/0016-governed-selection-outcome-monitoring-plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# ADR 0016: Governed selection-outcome monitoring plan

- **Status:** Proposed — active PR only
- **Decision scope:** Selection validity / workforce intelligence governance

## Context

Orgmetra already owns Job-scoped selection and post-hire evidence boundaries, but protected `develop` does not define a buyer-facing contract for planning recurring selection-outcome monitoring without copying candidate-level protected-attribute values or turning a screening heuristic into an automated legal or employment decision. Different opaque requester/reviewer references also do not prove that the authoritative actor boundary resolves them to different accountable people, and valid UUID-backed references alone do not prove that all referenced evidence belongs to the packet tenant. Packet-owned UUIDv1 trust references additionally embed timestamp/node-derived correlation metadata. The authoritative tenant identifier is different: it is issued by Orgmetra core, so this leaf package must accept the canonical non-sentinel operational UUID contract owned by that boundary rather than silently imposing a second version policy.

The EEOC's common interpretation of the Uniform Guidelines directs users to examine the total selection process first for each job, describes the four-fifths rule as a rule of thumb rather than a legal definition, and notes that small samples, statistical significance, practical significance, and other evidence can matter. ISO 30405:2023 also treats reviewing and learning as part of recruitment practice. SIOP's fifth-edition Principles provide the professional validation framework for personnel selection procedures.

## Decision

Orgmetra will expose a transport-neutral `SelectionOutcomeMonitoringPlan` that binds:

- one canonical non-sentinel operational tenant under the authoritative Orgmetra core contract and one authoritative Job;
- one total selection-process reference;
- exact aggregate population and selection-outcome snapshot references and SHA-256 digests;
- exact protected-attribute handling, small-sample interpretation, and statistical-analysis plan references and digests;
- an accountable requester reference and an accountable reviewer reference;
- fixed purpose and reviewed reason metadata plus a bounded positive `evidence_version` that is part of canonical evidence;
- an explicit monitoring business-date window and evidence-generation instant.

`tenant_record_id` must be canonical and non-sentinel under Orgmetra's authoritative operational UUID contract. The package does not reinterpret its UUID version because tenant identity generation and migration policy belong to the authoritative HRIS boundary. Packet-owned namespaced trust-bearing references separately require canonical non-sentinel UUIDv4 plus their expected prefix. UUIDv1 and other non-v4 suffixes fail closed for those references. Human-readable, value-bearing, sentinel, and noncanonical reference suffixes are also rejected so labels, policy values, protected-attribute concepts, or actor names cannot be carried through fields represented as opaque identifiers. `evidence_version` must be a true integer from 1 through 2147483647; changing it changes canonical JSON and the packet SHA-256, so revisions to actor/purpose/reason-bound evidence cannot silently collide.

UUID syntax is not tenant authority. Before review, the host must re-resolve **every packet reference** within the exact `tenant_record_id` through the relevant authoritative boundary and reject review use if any reference belongs to another tenant or cannot be authoritatively resolved. The packet also rejects identical requester/reviewer references as an early syntactic guard; after tenant-scoped resolution, the host must prove that the two references resolve to distinct actor identities. Reference inequality alone is not separation-of-duties evidence.

The contract is aggregate-only and carries no candidate identity, protected-attribute value, individual assessment score, individual employment decision, or free-form model output. It fixes `analysis_scope` to `total_selection_process_by_job`, `decision_authority` to `human_review_only`, and state to `requires_human_review`. It does not calculate selection rates, mechanically apply the four-fifths heuristic, test statistical significance, infer discrimination, or authorize a process change.

Each live plan identity receives one process-local construction seal over its exact canonical bytes. Seal registration is one-shot: a repeated `__post_init__()` call cannot overwrite the original seal, including after low-level mutation to another syntactically valid value. Canonical export therefore continues to compare the live payload with the original construction evidence instead of permitting reinitialization to renew trust. This runtime mechanism is defense-in-depth only and does not replace durable immutable audit/outbox evidence, persistence uniqueness, or cross-process authorization.

Any later analytics or persistence boundary must independently enforce purpose-bound authorization, authoritative tenant-scoped reference and actor resolution, minimum-necessary protected-attribute access, small-sample controls, provenance, immutable audit evidence, and accountable human interpretation. Results are evidence for review, not an automated high-impact employment decision or certification/legal conclusion.

## Consequences

- Buyers obtain a deterministic, explicitly versioned governance envelope for recurring selection monitoring without creating a second psychometrics/statistics engine inside Orgmetra.
- The total-process-by-Job scope is explicit before any future component drill-down.
- Privacy risk is reduced because individual protected-attribute values and candidate records remain outside the plan envelope and packet-owned trust references reject UUIDv1 timestamp/node metadata and value-bearing suffixes without making the leaf package incompatible with authoritative Orgmetra tenant UUIDs.
- Cross-tenant evidence mixing is fail-closed at the host review boundary because every opaque reference must be re-resolved in the exact packet tenant.
- Requester/reviewer separation is proven from authoritative resolved actor identities rather than inferred from different opaque strings.
- A valid-value low-level rewrite cannot be legitimized by re-running dataclass initialization because process-local seal registration is single-use for the live identity.
- The four-fifths rule cannot be represented as an automatic pass/fail legal rule by this contract; interpretation remains with authorized analysts and accountable humans.
- Psychometric/statistical production compute remains owned by the appropriate Psychometrics Commons / fast-mlsirm / TEPP contract when those kernels are needed.

## References

See `docs/doctoring/selection-outcome-monitoring-references.md`.
17 changes: 17 additions & 0 deletions docs/doctoring/selection-outcome-monitoring-references.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Selection-outcome monitoring references

These references support ADR 0016 and the bounded selection-monitoring contract. They do not convert Orgmetra into a legal-advice, certification, or automated adverse-impact decision service.

## APA 7 references

Equal Employment Opportunity Commission, Office of Personnel Management, Department of Justice, Department of Labor, & Department of the Treasury. (1979, March 2). *Questions and answers to clarify and provide a common interpretation of the Uniform Guidelines on Employee Selection Procedures*. U.S. Equal Employment Opportunity Commission. https://www.eeoc.gov/laws/guidance/questions-and-answers-clarify-and-provide-common-interpretation-uniform-guidelines

International Organization for Standardization. (2023). *ISO 30405:2023 Human resource management—Guidelines on recruitment* (2nd ed.). https://www.iso.org/standard/79488.html

Society for Industrial and Organizational Psychology. (2018). Principles for the validation and use of personnel selection procedures (5th ed.). *Industrial and Organizational Psychology, 11*(S1), 1–97. https://doi.org/10.1017/iop.2018.195

## Applied evidence boundary

The EEOC source says adverse impact is examined first for the overall selection process for each job and describes the four-fifths/eighty-percent rule as a practical rule of thumb rather than a legal definition. It also explains that small samples and statistical/practical significance can change interpretation. Consequently, the Orgmetra contract binds a Job-scoped total-process monitoring plan, a separate small-sample policy, and a separate statistical plan but does not itself calculate or adjudicate adverse impact.

ISO 30405:2023 is the current published second edition and includes reviewing and learning among recruitment practices. SIOP's fifth-edition Principles are used as the professional selection-validation frame; Orgmetra does not duplicate its psychometric methods in this package.
32 changes: 32 additions & 0 deletions docs/traceability/selection-outcome-monitoring.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
# Selection-outcome monitoring traceability

## Status

**Active PR / proposed capability.** This file does not describe protected-`develop` behavior until the owning PR is integrated. The protected-parent reconciliation snapshot is `develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f`; merge readiness still requires a fresh protected-head read and exact-head acceptance.

## Buyer need → contract evidence

| Buyer / governance need | Owned contract evidence | Explicit non-claim |
|---|---|---|
| Monitor the correct hiring/promotion process | Canonical non-sentinel `tenant_record_id` under the Orgmetra core operational-UUID contract, exact UUIDv4-backed `job_profile_reference` and `selection_process_reference`; fixed `analysis_scope=total_selection_process_by_job`; immutable next action requires every packet reference to be re-resolved within exact `tenant_record_id` | UUID syntax alone is not tenant authority or component-level causality evidence |
| Reproduce the monitored population and outcomes | Exact UUIDv4-backed aggregate population/outcome snapshot references plus independent SHA-256 digests | No candidate-level record or protected-attribute value in the packet |
| Preserve privacy and interpretation rules | Exact UUIDv4-backed protected-attribute handling and small-sample policy references/digests | No blanket authorization to expose protected-attribute data |
| Prevent semantic/value/correlation smuggling through packet-owned references without duplicating tenant identity policy | `tenant_record_id` is canonical/non-sentinel under the authoritative core contract; every packet-owned governed reference requires canonical non-sentinel UUIDv4 plus its expected prefix; digest and governance text evidence require exact built-in strings before validation | UUID syntax does not prove source truth, tenant membership, or authorization |
| Prevent cross-tenant evidence mixing | `test_actor_separation.py` requires the governed next action to re-resolve every packet reference within `tenant_record_id` before actor separation, Job scope verification, or accountable review | The packet does not itself query authoritative stores |
| Bind the analysis method before interpretation | Exact UUIDv4-backed statistical-plan reference/digest | No statistics are calculated by this package |
| Version actor/purpose/reason evidence explicitly | `evidence_version` is a true positive integer through signed-int32 max and participates in canonical JSON/SHA-256 | `test_evidence_version.py` proves presence, digest separation, bounds, and `dataclasses.replace(...)` revalidation |
| Prove accountable requester/reviewer separation | Different opaque actor references as a syntactic guard plus tenant-scoped authoritative resolution requiring distinct resolved actor identities | Reference inequality alone is not identity or separation-of-duties evidence |
| Prevent automated high-impact action | Exact boolean human confirmation, `human_review_only`, `requires_human_review`, governed next action | No automated employment-process change or legal conclusion |
| Preserve replayable audit correlation without caller-owned timezone behavior | `generated_at` is resolved once to a built-in UTC instant at issuance; future instants, missing/raising offsets and normalization overflow fail closed; canonical JSON and SHA-256 reuse only the detached UTC value | The packet timestamp proves evidence chronology/correlation, not source truth or scientific/legal validity |
| Prevent valid-value evidence rewrites after issuance | A process-local HMAC seal is stored outside packet-writable slots over the exact construction-time canonical JSON; seal registration is single-use per live identity, so repeated `__post_init__()` cannot renew trust; export verifies the current snapshot against the original seal and fails closed if evidence changed or issuance state is unavailable | The process-local seal is defense-in-depth only and is not durable cross-process authorization, persistence uniqueness, or immutable audit/outbox evidence |
| Keep package-quality evidence current under the protected workflow-ownership model | Canonical `Foundation CI` invokes `tests/test_foundation_ci_dependency_hygiene.sh`, which discovers and executes `tests/test_foundation_ci_*_artifact.sh` contracts; Selection Monitoring is owned by `tests/test_foundation_ci_selection_monitoring_artifact.sh`. The isolated hash-locked package contract runs the package pytest configuration, whose 100% statement and branch coverage thresholds remain authoritative. `test_quality_workflow_trigger.py` fails if the retired leaf workflow reappears or this canonical delegation disappears. | There is no package-local Selection Monitoring workflow and no transfer of historical GREEN across a successor head |

## Executable evidence

`packages/selection-monitoring/tests/test_plan.py` exercises direct-constructor and builder validation, operational tenant identity, UUID-backed reference namespaces, SHA-256 digests, requester/reviewer syntactic separation, monitoring-window boundaries, governance codes, timezone handling, fractional-second evidence identity, immutable review/authority state, aggregate-only enforcement, canonical JSON, and deterministic packet hashing. `packages/selection-monitoring/tests/test_temporal_evidence_integrity.py` proves caller-defined datetime subclasses are rejected, mutable timezone providers are detached at issuance, future generation times and missing/raising offsets fail closed, UTC-normalization overflow is normalized to validation failure, and post-construction non-UTC reinjection is rejected before evidence export. `packages/selection-monitoring/tests/test_issuance_integrity.py` proves a low-level valid-value rewrite after issuance cannot emit a second canonical truth, repeated `__post_init__()` cannot overwrite the original construction seal, and missing process-local issuance evidence fails closed. `packages/selection-monitoring/tests/test_fixed_governance_runtime_integrity.py` proves fixed governance fields reject hostile runtime string subclasses before equality-based policy checks. `packages/selection-monitoring/tests/test_string_runtime_evidence_integrity.py` proves tenant, reference, purpose, reason, and SHA-256 digest evidence reject caller-defined string subclasses before canonical evidence binding. `packages/selection-monitoring/tests/test_actor_separation.py` requires the immutable next action to re-resolve every packet reference in the exact tenant before Job-scope/accountable-review use, and separately requires requester/reviewer resolution through the authoritative tenant-scoped actor boundary with distinct resolved identities. `packages/selection-monitoring/tests/test_reference_privacy.py` is the RED→GREEN privacy/interoperability contract for accepting the authoritative core UUIDv7 tenant form while rejecting human-readable/value-bearing, sentinel, noncanonical, and non-v4 packet-owned opaque-reference suffixes through both public construction and replacement paths. `packages/selection-monitoring/tests/test_evidence_version.py` requires explicit bounded evidence revision identity in canonical evidence and proves that version changes alter the packet hash. `packages/selection-monitoring/tests/test_quality_workflow_trigger.py` proves the retired package-local workflow stays absent and canonical Foundation ownership continues to discover and execute the package contract without another edit to the shared Foundation workflow.

The package contract is reached only through canonical `.github/workflows/foundation-ci.yml`. `tests/test_foundation_ci_dependency_hygiene.sh` discovers delegated artifact contracts by the `tests/test_foundation_ci_*_artifact.sh` naming contract, so later packages can add an isolated artifact proof without competing edits to the shared dispatcher. The Selection Monitoring contract creates an isolated virtual environment, installs the repository's hash-locked reviewed test toolchain, compiles the package and tests, runs the selection-monitoring package under its own pytest configuration, and removes the temporary environment on exit. This preserves the existing 100% owned statement/branch threshold without restoring `.github/workflows/selection-monitoring-quality.yml`. Organization-required central review/security workflows remain separate required controls.

## Ownership boundary

This slice writes only Orgmetra and introduces no database migration or cross-service SQL. Future statistical computation must use the appropriate published psychometric/statistical service contract rather than duplicating foreign kernels, and future access to protected-attribute data must remain purpose-bound and minimum-necessary. Tenant UUID generation/privacy policy and authoritative tenant-scoped reference/actor resolution remain at the host/core boundary; this packet fails closed by requiring that proof before human review use. The process-local issuance registry is deliberately not a distributed attestation store: durable uniqueness, authorization, retention, and immutable audit/outbox remain responsibilities of authoritative Orgmetra persistence/host boundaries.
Loading
Loading