Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
113 commits
Select commit Hold shift + click to select a range
9794c0d
feat: add evidence-centered HR workspace slice
seonghobae Aug 20, 2026
09a4743
docs: track workspace slice in product gaps
seonghobae Aug 20, 2026
7a57731
docs: refresh current job-analysis head
seonghobae Aug 20, 2026
dcc5283
feat: add Storybook workspace state runtime
seonghobae Aug 20, 2026
3b41f61
ci: verify Storybook build
seonghobae Aug 20, 2026
58d6d30
docs: refresh job-analysis exact head
seonghobae Aug 20, 2026
dbee54d
docs: refresh protected truth exact head
seonghobae Aug 20, 2026
fa10e78
docs: refresh current job analysis and candidate heads
seonghobae Aug 20, 2026
e38e778
docs: record exact workspace baseline head
seonghobae Aug 20, 2026
fd5d97b
docs: keep workspace baseline self-referentially safe
seonghobae Aug 20, 2026
73b79e5
docs: record current TEPP adapter head
seonghobae Aug 20, 2026
2a11d5b
docs: record current candidate evidence head
seonghobae Aug 20, 2026
422e9c7
docs: record current compensation review head
seonghobae Aug 20, 2026
79f6382
docs: refresh current review packet heads
seonghobae Aug 20, 2026
f211148
docs: record current protected truth PR head
seonghobae Aug 20, 2026
19a655a
docs: record current ADR evidence head
seonghobae Aug 20, 2026
9624b23
docs: record central scheduler ownership
seonghobae Aug 20, 2026
118284f
chore: integrate protected develop into HR workspace lane
seonghobae Aug 20, 2026
f9527e5
test(ui): require localized accessible names
seonghobae Aug 20, 2026
5ca3233
fix(ui): localize icon control accessible names
seonghobae Aug 20, 2026
cb0e4b1
fix(ui): bind accessible names to locale changes
seonghobae Aug 20, 2026
f647a3d
fix(ui): refresh accessibility manifest evidence
seonghobae Aug 20, 2026
e496a69
fix(workspace): reserve unique ADR and refresh job-analysis truth
seonghobae Aug 20, 2026
b163817
fix(workspace): remove conflicting ADR number
seonghobae Aug 20, 2026
fc00897
fix(workspace): reconcile ADR index with protected job analysis
seonghobae Aug 20, 2026
3e1f6de
Merge protected develop into workspace branch
seonghobae Aug 20, 2026
2b3f5b0
fix(workspace): index merged candidate evidence ADR
seonghobae Aug 20, 2026
eedcf1c
fix: reconcile ADR foundation manifest
seonghobae Aug 21, 2026
d4bb687
docs: refresh current product gap evidence
seonghobae Aug 21, 2026
383e1aa
docs: track current validity handoff head
seonghobae Aug 21, 2026
a9442e2
docs: refresh active PR evidence heads
seonghobae Aug 21, 2026
9fccfd2
docs: record latest workspace head
seonghobae Aug 21, 2026
84cd959
docs: pin final workspace evidence head
seonghobae Aug 21, 2026
1d66f40
fix(workspace): preserve protected job analysis contracts
seonghobae Aug 21, 2026
1880d09
docs: refresh product gap evidence
seonghobae Aug 21, 2026
48ce063
docs: record workforce review repair
seonghobae Aug 21, 2026
9bae254
docs: record local job analysis database evidence
seonghobae Aug 21, 2026
c2d3a6c
chore(workspace): integrate protected develop after #43
seonghobae Aug 21, 2026
06c8841
docs: refresh current product gap baseline
seonghobae Aug 21, 2026
0f51dc3
feat(workspace): connect governed job analysis read
seonghobae Aug 21, 2026
88f809b
docs: record connected job analysis boundary
seonghobae Aug 21, 2026
eb036d2
docs: pin final current workspace snapshot
seonghobae Aug 21, 2026
8f21f69
docs: align product gap snapshot with current head
seonghobae Aug 21, 2026
d66c7e8
feat(workspace): connect protected People read boundary
seonghobae Aug 21, 2026
b83e4a9
docs: record People API workspace boundary
seonghobae Aug 21, 2026
14622ad
docs: record pinned validity smoke evidence
seonghobae Aug 21, 2026
70b5b11
docs: pin current service evidence
seonghobae Aug 21, 2026
76759e6
feat(workspace): add Chromium browser contract
seonghobae Aug 21, 2026
dc56024
docs: record browser contract evidence
seonghobae Aug 21, 2026
8b289b7
build(job-analysis): make uv service setup reproducible
seonghobae Aug 21, 2026
186f268
docs: record reproducible service evidence
seonghobae Aug 21, 2026
c45a8a5
build(people): check in uv resolution
seonghobae Aug 21, 2026
48ce49a
docs: record locked Python service evidence
seonghobae Aug 21, 2026
d5fd195
test(hr-workspace): reproduce stale protected-read rendering
seonghobae Aug 21, 2026
3021585
fix(hr-workspace): invalidate stale protected reads
seonghobae Aug 21, 2026
3c2dd7e
fix(hr-workspace): use defined accessible style tokens
seonghobae Aug 21, 2026
8b03da0
fix(people-api): align HRIS kernel dependency
seonghobae Aug 21, 2026
860fbfc
docs: align protected develop status with evidence ledger
seonghobae Aug 21, 2026
166bbb7
docs(adr): align Job Analysis status with protected develop
seonghobae Aug 21, 2026
3c4c8f4
docs(adr): mark Job Analysis persistence protected
seonghobae Aug 21, 2026
d4cecb7
docs(adr): align offer approval with protected truth
seonghobae Aug 21, 2026
c91f37a
docs(adr): index protected offer approval decision
seonghobae Aug 21, 2026
d743c13
test(hr-workspace): reproduce stale confirmation state
seonghobae Aug 21, 2026
476529b
fix(hr-workspace): reset confirmation on each draft
seonghobae Aug 21, 2026
2005b7b
ci: expose exact manifest repair evidence
seonghobae Aug 21, 2026
16a7a7a
ci: surface manifest evidence on pull requests
seonghobae Aug 21, 2026
6581e5a
ci: remove manifest repair helper
seonghobae Aug 21, 2026
0dc84a3
fix(provenance): refresh exact workspace manifest
seonghobae Aug 21, 2026
a90f53f
test(workspace): keep unconfigured protected reads neutral
seonghobae Aug 22, 2026
5e1dfe8
revert(test): avoid manifest-breaking intermediate workspace head
seonghobae Aug 22, 2026
555003d
docs(storybook): add protected-read not-connected state
seonghobae Aug 22, 2026
f74be34
fix(workspace): keep unconfigured protected reads neutral
seonghobae Aug 22, 2026
28a5fa9
chore(manifest): refresh workspace provenance
seonghobae Aug 22, 2026
c465688
test(storybook): govern protected-read states in shared inventory
seonghobae Aug 22, 2026
00d8d9d
chore(manifest): refresh Storybook provenance
seonghobae Aug 22, 2026
4ff6c73
test: reject provenance inside ADR status cells
seonghobae Aug 24, 2026
3db5827
fix: keep ADR status cells canonical
seonghobae Aug 24, 2026
51fed93
chore: refresh ADR validation provenance
seonghobae Aug 24, 2026
ed58d1d
fix: reconcile ADR 0010 canonical status
seonghobae Aug 24, 2026
c5523d2
fix: reconcile ADR 0011 canonical status
seonghobae Aug 24, 2026
a46068f
fix: reconcile ADR 0012 canonical status
seonghobae Aug 24, 2026
b2dcfdc
fix: reconcile ADR 0025 integrated status
seonghobae Aug 24, 2026
bc5906b
fix: reconcile ADR 0006 canonical status
seonghobae Aug 24, 2026
7851896
docs: separate ADR status from live provenance
seonghobae Aug 24, 2026
43ae3c7
chore: seal ADR status repair provenance
seonghobae Aug 24, 2026
a7c9fc3
test(a11y): require locale label in accessible name
seonghobae Aug 24, 2026
baaa70f
fix(a11y): include visible locale label in name
seonghobae Aug 24, 2026
62a6602
docs: trace locale label accessibility repair
seonghobae Aug 24, 2026
32be1f2
docs: canonicalize ADR 0007 status
seonghobae Aug 24, 2026
c23b253
docs: canonicalize ADR 0014 status
seonghobae Aug 24, 2026
d3ba2ce
docs: canonicalize ADR 0026 status
seonghobae Aug 24, 2026
0557787
fix(provenance): reseal current workspace artifacts
seonghobae Aug 25, 2026
cb5bf31
fix(provenance): preserve canonical manifest entries
seonghobae Aug 25, 2026
3c41b69
fix(provenance): reseal exact workspace artifacts
seonghobae Aug 25, 2026
2e56bb5
test(workspace): require keyboard bypass navigation
seonghobae Aug 26, 2026
44d640a
fix(workspace): add keyboard bypass link
seonghobae Aug 26, 2026
a29a3a9
fix(workspace): expose bypass link on keyboard focus
seonghobae Aug 26, 2026
762364f
feat(storybook): document keyboard bypass focus state
seonghobae Aug 26, 2026
93bd796
docs(design): bind keyboard bypass to Figma baseline
seonghobae Aug 26, 2026
fdbac84
docs(storybook): add keyboard bypass accessibility contract
seonghobae Aug 26, 2026
8df53e1
test(workspace): integrate keyboard bypass regression
seonghobae Aug 26, 2026
16e407d
test(workspace): consolidate bypass regression
seonghobae Aug 26, 2026
8ba793c
docs(doctoring): cite WCAG bypass-block technique
seonghobae Aug 26, 2026
2faea7c
chore(docs): keep canonical accessibility bibliography stable
seonghobae Aug 26, 2026
f5076ba
chore(provenance): reseal keyboard bypass artifacts
seonghobae Aug 26, 2026
f997f4c
test(workspace): assert visible localized bypass label
seonghobae Aug 26, 2026
7bd2e8f
chore(provenance): reseal localized bypass regression
seonghobae Aug 26, 2026
516d943
test(hr-workspace): stabilize locale bypass assertion
seonghobae Aug 26, 2026
443cd0a
chore(provenance): reseal locale bypass regression
seonghobae Aug 26, 2026
400f470
test(ui): require distinct Job Position Assignment concepts
seonghobae Aug 27, 2026
cd2f78e
fix(ui): distinguish Job from Position and Assignment
seonghobae Aug 27, 2026
d955faf
fix(provenance): reseal HR workspace index manifest
seonghobae Aug 27, 2026
016f27e
fix(provenance): restore exact outbox artifact digest
seonghobae Aug 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/workflows/foundation-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,10 @@ jobs:
run: python -m compileall -q tests
- name: Validate foundation pack
run: npm run validate
- name: Install Node dependencies
run: npm ci
- name: Build Storybook
run: npm run build-storybook
Comment thread
seonghobae marked this conversation as resolved.
Comment thread
devin-ai-integration[bot] marked this conversation as resolved.
Comment thread
seonghobae marked this conversation as resolved.
- name: Prove Foundation CI dependency hygiene
run: bash tests/test_foundation_ci_dependency_hygiene.sh
- name: Prove HRIS kernel
Expand Down
57 changes: 57 additions & 0 deletions .github/workflows/hr-workspace-browser-e2e.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
name: HR Workspace Browser E2E

on:
pull_request:
branches:
- develop
paths:
- "apps/hr-workspace/**"
- "packages/design-tokens/**"
- "tests/e2e/**"
- "playwright.config.mjs"
- "package.json"
- "package-lock.json"
- ".github/workflows/hr-workspace-browser-e2e.yml"
- "tests/validate_repository.py"
- "scripts/foundation-contract-core.mjs"
- "manifest.json"
- "docs/STORYBOOK.md"
workflow_dispatch:

permissions:
contents: read

concurrency:
group: hr-workspace-browser-e2e-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
browser:
name: HR workspace Chromium E2E
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout exact candidate
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- name: Prove exact candidate checkout
env:
ORGMETRA_EXPECTED_HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: test "$(git rev-parse HEAD)" = "$ORGMETRA_EXPECTED_HEAD_SHA"
- name: Set up Node.js LTS
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: "24"
check-latest: false
- name: Install Node dependencies
run: npm ci
- name: Install Chromium and Linux dependencies
run: npx playwright install --with-deps chromium
- name: Run HR workspace browser E2E
run: npm run test:e2e
- name: Require clean checkout
run: |
git diff --exit-code
test -z "$(git status --porcelain)"
4 changes: 4 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@ node_modules/
dist/
coverage/
.turbo/
storybook-static/
playwright-report/
test-results/

# Rust
/target/
Expand All @@ -35,3 +38,4 @@ secrets/
artifacts/
reports/
*.log
/.codegraph/
8 changes: 8 additions & 0 deletions .storybook/main.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
/** @type { import('@storybook/web-components-vite').StorybookConfig } */
const config = {
stories: ['../apps/hr-workspace/**/*.stories.@(js|mjs)'],
framework: '@storybook/web-components-vite',
docs: { autodocs: 'tag' }
};

export default config;
13 changes: 13 additions & 0 deletions .storybook/preview.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
import '../packages/design-tokens/tokens.css';
import '../apps/hr-workspace/styles.css';

/** @type { import('storybook').Preview } */
const preview = {
parameters: {
layout: 'centered',
controls: { expanded: true }
},
decorators: [(story) => `<div class="storybook-preview">${story()}</div>`]
};

export default preview;
2 changes: 1 addition & 1 deletion ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ The initial deployment may share one physical PostgreSQL cluster. Logical isolat
|---|---|---|
| `people_core` | `people_core`: person, name, employment, assignment, compensation, and candidate-worker linkage records | `people_core_role` |
| `organization_core` | `organization_core`: organization units and position records | `organization_core_role` |
| `job_architecture` | `job_architecture`: job profiles, publication evidence, and persisted `job_analysis_snapshot` / task / KSAO rows | `job_architecture_role` |
| `job_architecture` | `job_architecture`: job profiles and publication evidence | `job_architecture_role` |
| `talent_acquisition` | `talent_acquisition`: candidate profiles, selection decisions, and decision evidence | `talent_acquisition_role` |
| `performance_management` | `performance_management`: criterion blueprints and observations | `performance_management_role` |
| `workforce_validation` | `workforce_validation`: validity-study registry and external result references | `workforce_validation_role` |
Expand Down
23 changes: 15 additions & 8 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,22 +6,27 @@ All notable changes to Orgmetra will be documented in this file.

### Added

- Dependency-free HR Home and Employee Profile fixture at `apps/hr-workspace/`, using the Figma role frames and shared tokens with explicit API-boundary, permission-denied, evidence-drawer, high-impact confirmation, exact-allocation, focus, and English/Korean states. The fixture is not connected or deployed evidence.
- Local Storybook `10.5.10` runtime using `@storybook/web-components-vite` and native HTML/CSS stories for the HR action states, field errors, permission denial, evidence drawer, high-impact confirmation, and exact assignment values. It is local component/state evidence, not connected People API or browser E2E evidence.
- Chromium Playwright browser E2E for the HR workspace, covering keyboard-accessible human review, locale changes, purpose-bound denial, host-injected People and Job Analysis reads, authorization headers, and no-fallback error behavior. The test is local/CI evidence and does not claim protected deployment.
- Product and technical gap baseline with protected-branch truth, full current open-PR inventory, buyer-priority acceptance evidence, Figma source ID, standards/research ledger, and central integration-loop contract. The baseline distinguishes shipped runtime from active PR, accepted architecture, planned, research-only, superseded, and out-of-scope work.
- Project-local `uv` source resolution and a checked lockfile for `services/people-api`, so local tests discover the owned Keyverse adapter without an undocumented `PYTHONPATH` workaround.
- Project-local `uv` source resolution, Python compatibility metadata, test extras, and a checked lockfile for `services/job-analysis-api`, so its full test command resolves owned packages without an undocumented `PYTHONPATH` workaround.
- Accepted ADRs 0001–0003 now include buyer-facing Context, Decision, and Consequences grounded in verified ISO 30400:2022, ISO 30414:2025, Uniform Guidelines (29 C.F.R. Part 1607), SIOP (2018), OpenAPI Specification v3.2.0, OpenID Connect Core 1.0 errata set 2, CloudEvents v1.0.2, Jensen and Snodgrass (1999), Snodgrass (1999), and Allen (1983) records already listed in `docs/doctoring/REFERENCES.md`. ADRs 0004 and 0005 gained APA 7th References pointers to that same bibliography without changing their Decision bodies.
- Active-PR governed Job Analysis persistence/API on the canonical `JobAnalysisSnapshot` model: migration `0013_job_analysis_snapshot.sql` stores immutable tenant-scoped snapshot, Task, KSAO, Task–KSAO, FJA and write-command evidence; `POST /v1/tenants/{tenant_record_id}/job-analysis-snapshots` and matching GET enforce purpose-bound Keyverse scope, authenticated-principal actor authority, bounded/strict JSON handling, transactional Idempotency-Key serialization, parent-scope fail-closed integrity, forced RLS, and atomic audit/outbox evidence. ADR 0014 records the persistence decision while ADR 0007 remains the domain/evidence authority; validated evidence still requires accountable human review and non-LLM provenance, and the service does not make a high-impact employment decision.
- Active-PR `orgmetra_selection_review` packet for PII-minimized, evidence-bound human selection review: canonical operational tenant identity, UUID-backed opaque candidate/Job/sealed-evidence/reviewer references, explicit purpose/reason/evidence version, deterministic canonical JSON and SHA-256 correlation, mandatory human decision state, redacted packet repr, and provenance-paired model evidence that remains `untrusted_draft`, with exact 100% owned statement and branch coverage required by its quality gate.
- Active performance-criterion scope hardening: `criterion_observation_scope_guard` rejects criterion outcomes for a Job the worker did not effectively hold at the observation date, observations before the relevant assignment, and observations outside the referenced performance cycle while preserving valid multiple-assignment cases and existing bitemporal correction semantics. The guard evaluates current-recorded facts, derives the date coordinate from `observed_at` in UTC so session `TimeZone` cannot alter the result, uses a trusted function search path, and adds no PII or automated employment decision authority. The Foundation PostgreSQL contract also rejects a closed `recorded_to` on each time-coordinate lookup and proves UTC midnight plus non-UTC session `TimeZone` boundaries.
- Protected `orgmetra_selection_review` packet for PII-minimized, evidence-bound human selection review: canonical operational tenant identity, UUID-backed opaque candidate/Job/sealed-evidence/reviewer references, explicit purpose/reason/evidence version, deterministic canonical JSON and SHA-256 correlation, mandatory human decision state, redacted packet repr, and provenance-paired model evidence that remains `untrusted_draft`, with exact 100% owned statement and branch coverage required by its quality gate.
- Protected performance-criterion scope hardening: `criterion_observation_scope_guard` rejects criterion outcomes for a Job the worker did not effectively hold at the observation date, observations before the relevant assignment, and observations outside the referenced performance cycle while preserving valid multiple-assignment cases and existing bitemporal correction semantics. The guard evaluates current-recorded facts, derives the date coordinate from `observed_at` in UTC so session `TimeZone` cannot alter the result, uses a trusted function search path, and adds no PII or automated employment decision authority. The Foundation PostgreSQL contract also rejects a closed `recorded_to` on each time-coordinate lookup and proves UTC midnight plus non-UTC session `TimeZone` boundaries.
- Bitemporal tenant-scoped organization hierarchy validation that rejects visible indirect parent cycles and reuses single-valued recorded-time reconstruction before graph traversal.
- Stacked governed job-analysis evidence contract via `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `TaskKSAOLink`, `FunctionalJobAnalysisProfile`, and `EvidenceSource`: tenant/Job-scoped observable tasks, explicit Task-to-KSAO linkage, importance/difficulty/proficiency ratings, source/version/retrieval/SHA-256 provenance, deterministic canonical snapshot bytes, current O*NET evidence support, and historical DOT Data/People/Things compatibility. Validated snapshots require accountable human review and complete non-LLM evidence; LLM-origin material remains `analysis_draft`, and the snapshot is evidence input rather than a hiring, promotion, termination, compensation, or other high-impact employment decision.
- Stacked governed audit/outbox slice via `AuditOutboxEvent`, `audit_event_record`, `outbox_delivery_record`, and `outbox_delivery_escalation_record`: CloudEvents 1.0-compatible PII-minimized metadata, exact canonical JSON bytes, database-verified SHA-256 digests, mandatory human confirmation for high-impact events, immutable audit evidence, tenant RLS, atomic audit/outbox insertion, guarded pending/leased/delivered/dead-lettered delivery state, tenant-safe `claim_outbox_delivery(...)` with deterministic due-work ordering, `FOR UPDATE ... SKIP LOCKED`, opaque worker identity, bounded future leases, immutable envelope return, and atomic takeover of genuinely expired leases only while retry attempts remain; owner-bound `complete_outbox_delivery(...)` and `retry_outbox_delivery(...)`; database-budget-governed `dead_letter_outbox_delivery(...)`; and a separately privileged `operator_dead_letter_expired_outbox_delivery(...)` recovery path for an exhausted final lease whose recorded worker identity is permanently unavailable. `maximum_attempt_count` is persisted on the delivery row, defaults to 5, is constrained to 1 through 100, and cannot be lowered by a dispatcher during finalization. Migration 0007 prevents retry or expired-lease takeover from creating attempt N+1; migration 0008 adds TRUNCATE guards, trusted function search paths, a concurrently built due-work partial index, session-independent immutable envelope validation, and operator recovery backed by separate NOLOGIN/NOBYPASSRLS owner/capability roles so the externally assignable operator role can invoke recovery without receiving direct transport-table read/write rights. Migration 0008 also rejects pre-existing reserved recovery-role names before project DDL, atomically contains the temporary schema-creation privilege used for function ownership handoff, and forces deferred escalation binding while the narrow SECURITY DEFINER owner is still active. Exponential/backoff policy selection, policy-specific producer configuration, and external delivery receipts remain subsequent work.
- Protected governed job-analysis evidence contract via `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `TaskKSAOLink`, `FunctionalJobAnalysisProfile`, and `EvidenceSource`: tenant/Job-scoped observable tasks, explicit Task-to-KSAO linkage, importance/difficulty/proficiency ratings, source/version/retrieval/SHA-256 provenance, deterministic canonical snapshot bytes, current O*NET evidence support, and historical DOT Data/People/Things compatibility. Validated snapshots require accountable human review and complete non-LLM evidence; LLM-origin material remains `analysis_draft`, and the snapshot is evidence input rather than a hiring, promotion, termination, compensation, or other high-impact employment decision.
- Protected governed audit/outbox slice via `AuditOutboxEvent`, `audit_event_record`, `outbox_delivery_record`, and `outbox_delivery_escalation_record`: CloudEvents 1.0-compatible PII-minimized metadata, exact canonical JSON bytes, database-verified SHA-256 digests, mandatory human confirmation for high-impact events, immutable audit evidence, tenant RLS, atomic audit/outbox insertion, guarded pending/leased/delivered/dead-lettered delivery state, tenant-safe `claim_outbox_delivery(...)` with deterministic due-work ordering, `FOR UPDATE ... SKIP LOCKED`, opaque worker identity, bounded future leases, immutable envelope return, and atomic takeover of genuinely expired leases only while retry attempts remain; owner-bound `complete_outbox_delivery(...)` and `retry_outbox_delivery(...)`; database-budget-governed `dead_letter_outbox_delivery(...)`; and a separately privileged `operator_dead_letter_expired_outbox_delivery(...)` recovery path for an exhausted final lease whose recorded worker identity is permanently unavailable. `maximum_attempt_count` is persisted on the delivery row, defaults to 5, is constrained to 1 through 100, and cannot be lowered by a dispatcher during finalization. Migration 0007 prevents retry or expired-lease takeover from creating attempt N+1; migration 0008 adds TRUNCATE guards, trusted function search paths, a concurrently built due-work partial index, session-independent immutable envelope validation, and operator recovery backed by separate NOLOGIN/NOBYPASSRLS owner/capability roles so the externally assignable operator role can invoke recovery without receiving direct transport-table read/write rights. Migration 0008 also rejects pre-existing reserved recovery-role names before project DDL, atomically contains the temporary schema-creation privilege used for function ownership handoff, and forces deferred escalation binding while the narrow SECURITY DEFINER owner is still active. Exponential/backoff policy selection, policy-specific producer configuration, and external delivery receipts remain subsequent work.
- `orgmetra_hris_kernel` 0.4.0 with exclusive-versus-concurrent employment, staffable position coverage, exclusive-seat capacity, and `validate_assignment_write` at 100% statement and branch coverage.
- `POST /v1/employment-records`, `POST /v1/position-records`, and `POST /v1/assignment-records` with the same Keyverse mutation context, confirmation, and versioned evidence composition as other high-impact commands.
- Protected governed People mutation and confirmed-hire materialization runtime for `POST /v1/employment-records`, `POST /v1/position-records`, `POST /v1/assignment-records`, and the tenant-bound conversion route, with purpose-bound Keyverse mutation context, explicit confirmation, versioned evidence, atomic audit/outbox persistence, and tenant-scoped idempotency.
- `employment_record_version.employment_concurrency_code` constrained to `exclusive` or `concurrent`.
- ADR 0005 for exclusive employment and staffable seats.
- `orgmetra_hris_kernel` 0.3.0 with identity-scoped bitemporal resolution, assignment-employment coverage, allocation-portfolio checks, and a Memorial Hospital RN correction case at 100% statement and branch coverage.
- `employment_record_version` and `position_record_version` so employment and position identity stay stable across retroactive corrections.
- `assignment_record.employment_record_id` bound to the same person as the covering employment.
- `orgmetra_keyverse_adapter` that binds an opaque Keyverse subject to a person and rejects passwords, passkeys, and tokens.
- Design tokens for the repeating HR actions: approve, review, correct, request evidence, compare, export, and escalate.
- Design tokens for the repeating HR actions: approve, review, correct, request evidence, compare, export, escalate.
- ADR 0004 for employment/position versions and assignment-employment binding.
- Foundation product baseline for Orgmetra as an evidence-centered HRIS/HCM.
- CWL federated integration boundary map.
Expand All @@ -37,6 +42,8 @@ All notable changes to Orgmetra will be documented in this file.

### Changed

- Aligned the English/Korean locale toggle's accessible name with its visible target-language label (`한국어` / `English`) and added exact browser assertions for both language states, following WCAG 2.2 Success Criterion 2.5.3 (Label in Name); the APA 7 W3C citation remains in `docs/doctoring/REFERENCES.md`.
- Reconciled README, traceability, ADR status/index, and changelog maturity claims with capabilities already integrated on protected `develop`; open-PR capabilities remain explicitly non-shipped.
- New predictive-validity membership must use one normalized worker-level case; the three independent validity-study decision/evidence/outcome link relations are historical read surfaces only and can no longer accept new rows. A case insert also rejects a criterion observation whose recorded interval is already closed at `linked_at`.
- Canonicalized service identifiers as two-or-more-word `snake_case` across architecture, deployment, ACL, metrics, and client contracts.
- Separated fast-mlsirm, TEPP, and Psychometrics Commons into immutable external scientific contracts.
Expand Down Expand Up @@ -73,4 +80,4 @@ All notable changes to Orgmetra will be documented in this file.

### Notes

- Protected `develop` at `e7ddb7a78a5e1460410005d10f43ebf18c5e12e4` includes normalized validity-study and criterion integrity, bitemporal workforce composition, governed candidate-to-worker conversion, purpose-bound PII authorization, GET-only People reads, governed People mutation/idempotency API, and the accepted ADR 0001–0003 source expansion integrated by #37. Job Analysis persistence/API and the selection-review packet remain active-PR truth until their unchanged exact heads satisfy fresh gates and merge.
- Protected `develop` is the shipped repository truth for integrated capability. Open PRs and draft branches are non-shipped until they integrate and satisfy fresh exact-head gates.
Loading
Loading