Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
54 commits
Select commit Hold shift + click to select a range
e10bd56
test(job-analysis): reject temporal evidence subclasses
seonghobae Aug 21, 2026
4297396
fix(job-analysis): protect canonical temporal evidence types
seonghobae Aug 21, 2026
e6fe899
test(audit): reject canonical-evidence runtime subclasses
seonghobae Aug 21, 2026
3058ff9
fix(audit): protect canonical identity and chronology types
seonghobae Aug 21, 2026
36fe981
test(job-analysis): reject identity runtime subclasses
seonghobae Aug 21, 2026
4a541a5
fix(job-analysis): protect canonical identity types
seonghobae Aug 21, 2026
58a6c78
fix(core): refresh foundation manifest after audit hardening
seonghobae Aug 21, 2026
943c2dc
test(core): reject forged job-analysis primitive types
seonghobae Aug 22, 2026
05d04db
fix(core): reject forged job-analysis codes and levels
seonghobae Aug 22, 2026
7ae6331
test(core): complete adversarial level ordering
seonghobae Aug 22, 2026
9a1bbd3
fix(core): close canonical evidence runtime gaps
seonghobae Aug 28, 2026
5c52509
fix(job-analysis): reject nested evidence subclasses
seonghobae Aug 29, 2026
f222934
chore(core): non-force restack runtime integrity on protected develop
seonghobae Sep 4, 2026
9ff8b4e
test(audit): reject post-construction governance mutation
seonghobae Sep 4, 2026
b95ff0a
fix(audit): revalidate captured canonical evidence
seonghobae Sep 4, 2026
a36e1b6
chore(manifest): reseal audit runtime-integrity evidence
seonghobae Sep 4, 2026
c088d97
fix(audit): preserve detached-time fail-closed canonicalization
seonghobae Sep 4, 2026
08a9cad
chore(manifest): reseal corrected audit canonicalization
seonghobae Sep 4, 2026
24ff2a1
test(audit): reject valid canonical evidence reissuance
seonghobae Sep 4, 2026
970bae7
fix(audit): bind canonical export to creation evidence
seonghobae Sep 4, 2026
7f6a2ab
chore(manifest): seal audit creation identity repair
seonghobae Sep 4, 2026
cd25ace
fix(audit): keep issuance seal outside mutable event slots
seonghobae Sep 4, 2026
fd18a83
chore(manifest): reseal external audit issuance proof
seonghobae Sep 4, 2026
72ec4ec
test(audit): cover issuance registry failure modes
seonghobae Sep 4, 2026
8cddbf7
merge(core): adopt protected workflow consolidation
seonghobae Sep 4, 2026
6d4dabf
merge(core): preserve #161 changelog delta after restack
seonghobae Sep 4, 2026
b929661
fix(ci): reseal shared-kernel manifest after protected restack
seonghobae Sep 4, 2026
f1447a8
test(core): reject reintroduced audit timezone before callback
seonghobae Sep 4, 2026
6f26acd
fix(core): validate canonical audit timestamp before snapshot comparison
seonghobae Sep 4, 2026
ac31f28
fix(core): reseal audit runtime manifest after callback guard
seonghobae Sep 4, 2026
38c3fde
fix(core): restore unrelated migration manifest digest
seonghobae Sep 4, 2026
5d7eef3
fix(core): restore LICENSE manifest digest after reseal repair
seonghobae Sep 4, 2026
50a7dbe
test(core): prove audit event cannot reseal after issuance
seonghobae Sep 4, 2026
d076d1f
fix(core): make audit issuance identity single-use
seonghobae Sep 4, 2026
ddc41be
fix(core): use unique marker for audit issuance identity
seonghobae Sep 4, 2026
423cf66
build(core): reseal single-use audit runtime evidence
seonghobae Sep 4, 2026
31fabb5
test(core): cover audit issuance lifetime cleanup
seonghobae Sep 4, 2026
701a179
test(audit): hide issuance authority storage from consumers
seonghobae Sep 4, 2026
7b6cb6f
test(audit): exercise private issuance runtime without mutable globals
seonghobae Sep 4, 2026
70bdd6d
fix(audit): hide issuance authority in closure-private state
seonghobae Sep 4, 2026
cd3b2f5
test(audit): use valid isolated creation snapshot for cleanup
seonghobae Sep 4, 2026
03d1b8b
chore(manifest): reseal audit runtime authority source
seonghobae Sep 4, 2026
48bfaf7
test(audit): cover private issuance marker and duplicate guards
seonghobae Sep 4, 2026
c17af48
test(audit): reject closure-exported issuance authority
seonghobae Sep 4, 2026
8b20c53
test(audit): require structural immutability instead of mutable issua…
seonghobae Sep 4, 2026
1b80534
test(audit): require immutable timestamp evidence after construction
seonghobae Sep 4, 2026
e5d4303
test(audit): enforce structural immutability at canonical boundary
seonghobae Sep 4, 2026
e29d180
fix(audit): make canonical evidence structurally immutable
seonghobae Sep 4, 2026
1d24cef
test(core): reject executable audit timezones before callbacks
seonghobae Sep 4, 2026
7216153
fix(core): exact-gate audit timezone providers
seonghobae Sep 4, 2026
c9f7de3
test(core): align audit timezone contract with inert providers
seonghobae Sep 4, 2026
0607d00
refactor(core): remove unreachable custom-timezone branches
seonghobae Sep 4, 2026
16dce30
chore(manifest): reseal audit timezone owner artifacts
seonghobae Sep 4, 2026
72070cb
test(core): cover audit structural rejection branches
seonghobae Sep 5, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,13 +12,14 @@ All notable changes to Orgmetra will be documented in this file.
- Active performance-criterion scope hardening: `criterion_observation_scope_guard` rejects criterion outcomes for a Job the worker did not effectively hold at the observation date, observations before the relevant assignment, and observations outside the referenced performance cycle while preserving valid multiple-assignment cases and existing bitemporal correction semantics. The guard evaluates current-recorded facts, derives the date coordinate from `observed_at` in UTC so session `TimeZone` cannot alter the result, uses a trusted function search path, and adds no PII or automated employment decision authority. The Foundation PostgreSQL contract also rejects a closed `recorded_to` on each time-coordinate lookup and proves UTC midnight plus non-UTC session `TimeZone` boundaries.
- Bitemporal tenant-scoped organization hierarchy validation that rejects visible indirect parent cycles and reuses single-valued recorded-time reconstruction before graph traversal.
- Stacked governed job-analysis evidence contract via `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `TaskKSAOLink`, `FunctionalJobAnalysisProfile`, and `EvidenceSource`: tenant/Job-scoped observable tasks, explicit Task-to-KSAO linkage, importance/difficulty/proficiency ratings, source/version/retrieval/SHA-256 provenance, deterministic canonical snapshot bytes, current O*NET evidence support, and historical DOT Data/People/Things compatibility. Validated snapshots require accountable human review and complete non-LLM evidence; LLM-origin material remains `analysis_draft`, and the snapshot is evidence input rather than a hiring, promotion, termination, compensation, or other high-impact employment decision.
- Active-PR core evidence hardening now rejects caller-controlled built-in-type subclasses at audit and job-analysis trust boundaries and detaches accepted timestamps from mutable timezone providers before canonical serialization.
- Stacked governed audit/outbox slice via `AuditOutboxEvent`, `audit_event_record`, `outbox_delivery_record`, and `outbox_delivery_escalation_record`: CloudEvents 1.0-compatible PII-minimized metadata, exact canonical JSON bytes, database-verified SHA-256 digests, mandatory human confirmation for high-impact events, immutable audit evidence, tenant RLS, atomic audit/outbox insertion, guarded pending/leased/delivered/dead-lettered delivery state, tenant-safe `claim_outbox_delivery(...)` with deterministic due-work ordering, `FOR UPDATE ... SKIP LOCKED`, opaque worker identity, bounded future leases, immutable envelope return, and atomic takeover of genuinely expired leases only while retry attempts remain; owner-bound `complete_outbox_delivery(...)` and `retry_outbox_delivery(...)`; database-budget-governed `dead_letter_outbox_delivery(...)`; and a separately privileged `operator_dead_letter_expired_outbox_delivery(...)` recovery path for an exhausted final lease whose recorded worker identity is permanently unavailable. `maximum_attempt_count` is persisted on the delivery row, defaults to 5, is constrained to 1 through 100, and cannot be lowered by a dispatcher during finalization. Migration 0007 prevents retry or expired-lease takeover from creating attempt N+1; migration 0008 adds TRUNCATE guards, trusted function search paths, a concurrently built due-work partial index, session-independent immutable envelope validation, and operator recovery backed by separate NOLOGIN/NOBYPASSRLS owner/capability roles so the externally assignable operator role can invoke recovery without receiving direct transport-table read/write rights. Migration 0008 also rejects pre-existing reserved recovery-role names before project DDL, atomically contains the temporary schema-creation privilege used for function ownership handoff, and forces deferred escalation binding while the narrow SECURITY DEFINER owner is still active. Exponential/backoff policy selection, policy-specific producer configuration, and external delivery receipts remain subsequent work.
- `orgmetra_hris_kernel` 0.4.0 with exclusive-versus-concurrent employment, staffable position coverage, exclusive-seat capacity, and `validate_assignment_write` at 100% statement and branch coverage.
- `POST /v1/employment-records`, `POST /v1/position-records`, and `POST /v1/assignment-records` with the same Keyverse mutation context, confirmation, and versioned evidence composition as other high-impact commands.
- `employment_record_version.employment_concurrency_code` constrained to `exclusive` or `concurrent`.
- ADR 0005 for exclusive employment and staffable seats.
- `orgmetra_hris_kernel` 0.3.0 with identity-scoped bitemporal resolution, assignment-employment coverage, allocation-portfolio checks, and a Memorial Hospital RN correction case at 100% statement and branch coverage.
- `employment_record_version` and `position_record_version` so employment and position identity stay stable across retroactive corrections.
- `employment_record_version` and `position_record_version` so corrections no longer mint a new employment or position identifier.
- `assignment_record.employment_record_id` bound to the same person as the covering employment.
- `orgmetra_keyverse_adapter` that binds an opaque Keyverse subject to a person and rejects passwords, passkeys, and tokens.
- Design tokens for the repeating HR actions: approve, review, correct, request evidence, compare, export, and escalate.
Expand Down
18 changes: 9 additions & 9 deletions manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -29,9 +29,9 @@
},
{
"path": "CHANGELOG.md",
"sha256": "f2d2e0b488c0440533effa821808f2f17e37d92f8fb586174c2fdb594f760ca5",
"bytes": 17539,
"lines": 77
"sha256": "791d0d29d9b27223e86331d91dd0743b48761818b76db0468caa7e90b812ec10",
"bytes": 17761,
"lines": 78
},
{
"path": "CLAUDE.md",
Expand Down Expand Up @@ -341,15 +341,15 @@
},
{
"path": "packages/hris-kernel/src/orgmetra_hris_kernel/audit.py",
"sha256": "3e5b7190cf857dc8c1fc7e898cef303060f34aabee6c27a9034d4d9650e33190",
"bytes": 7707,
"lines": 160
"sha256": "dcc7f78fbbe9cf0cf0207e3d18c6173bb1ad3ed133aeb7b578ef3657af49a192",
"bytes": 12593,
"lines": 307
},
{
"path": "packages/hris-kernel/tests/test_audit_outbox.py",
"sha256": "5928dd7b97fe38d6b7472ce62966437e339058a59c3b301a93a7b5c05432b40c",
"bytes": 7556,
"lines": 200
"sha256": "6dd86c98e3b4667e47d99cb009f8aa3fc410a6c1c6e59fee7f198dd52331b412",
"bytes": 9228,
"lines": 253
},
{
"path": "schemas/openapi.yaml",
Expand Down
Loading
Loading