Skip to content

naruon: KG-mediated email style/tone correction #995

Description

@seonghobae

Buyer outcome

Naruon should provide context-aware email writing guidance that uses the authorized current draft, recipient/thread/project evidence, and explicit writing policy without turning generic lexical heuristics into semantic judgments. Guidance is advisory: review availability or model failure must never disable ordinary editing or sending.

This issue is the buyer-facing umbrella for the active Inkspan-based LLM email-writing stack. Refetch every PR/head/base before action; the identities below are observations, not durable constants.

Current implementation stack — observed 2026-09-02

Dependency-root order currently resolves as:

The remaining intended order is immutable fast-mlsirm pinning/current-stack reconstruction → immutable Inkspan consumer → EmailDetail composer → feedback/benchmark/live evaluation → release. Parent movement invalidates predecessor checks/reviews and requires an ordinary non-destructive restack/retarget with fresh exact-head evidence.

Current focused workflow evidence for #1524, #1530, #1535 and #1536 is queued before checkout/runner assignment or otherwise non-terminal and is therefore non-passing. For #1536 current head, push run 33607253315 / job 100173968479 is queued with runner ID 0 and no steps; same-head pull-request sibling 33607253379 was cancelled before runner assignment while concurrency retained the push run. The central runner-acquisition owner path remains ContextualWisdomLab/.github#712; product heads must not be churned merely to retrigger that condition.

Ownership boundary

  • Inkspan owns revision-bound editor/diagnostic UI, W3C TextPositionSelector binding, Focus/Apply/Ignore/Dismiss/Explain, stale rejection, normal undo, Yjs/browser/accessibility/package behavior.
  • Naruon owns authorized email/thread/recipient/project context, review API, prompt/rubric/policy consumption, privacy-minimized persistence/feedback, and the mail workflow.
  • contextual-orchestrator owns provider-neutral production model routing, capability handling, fallback policy, and test-time compute allocation.
  • fast-mlsirm owns the independent criterion-level LLM-as-a-Judge contract, response-matrix/IRT bridge, calibration, DIF, reliability, drift, and publishable measurement evidence.
  • Candidate Reviewer and Judge are always separate roles/calls. Candidate confidence is not Judge evidence.

No mutable Git branch, source copy, local stub, or workspace path from Inkspan or fast-mlsirm is an acceptable production dependency.

Semantic judgment contract

Spelling, grammar, clarity, concision, tone, workplace pragmatics, audience fit, technical precision, actionability, and intent-preservation judgments must originate from contextual LLM workflows through contextual-orchestrator. Production code must not synthesize these judgments from keyword/regex/phrase lists, dictionaries, sender domain, recipient count, language name, sentiment tables, nearest-text search, or text position.

Deterministic code may validate transport, schema, selector bounds, revision/hash identity, Unicode safety, authorization, and other non-semantic invariants. Provider/model/Judge failure, unsupported profile, malformed output, or insufficient evidence returns abstain / review_unavailable; there is no lexical semantic fallback.

Writing-quality contract

Guidance must preserve the source draft's facts, actors, deadlines, technical requirements, and request strength. Over-softening a legitimate firm request is an error, not a successful tone correction. Contrast evidence must cover same words with different meaning, the same problem paraphrased differently, legitimate firm requests, quotations/code/product names, technical errors without rude vocabulary, Korean/English/mixed/CJK/emoji/hostile Unicode, prompt injection, negative controls, and fact/intent/deadline/request-strength preservation.

Guidance remains advisory. Editing and sending stay available when review is disabled, unavailable, abstained, incomplete, or invalid. Stale/revision-invalid diagnostics fail closed and are never reattached by nearest-text search.

Privacy boundary

Use context-required PII only under purpose-bound authorization, least privilege, tenant/context isolation, approved provider/region policy, encrypted credentials, no-training/no-secondary-use contract where required, bounded/no retention, and auditable access/export handling. Do not destructively blanket-mask recipient/thread facts that are required to make the writing judgment. Ordinary logs/telemetry must not contain raw email/draft/replacement/explanation/prompt/model/Judge output.

Immutable dependency gates

fast-mlsirm

Latest verified immutable release is v0.9.1, source commit 09f762ded35786dd1078222a4577ff09d649816f, and the tagged public package exports the required Judge symbols. The GitHub release is currently assetless, so runtime consumption remains blocked on a real wheel/sdist or approved immutable package source with version, integrity digest, source provenance, Python 3.14 install/import/execution evidence, and Naruon hash lock. #1385 is the canonical Naruon dependency gate. Owner publication RCA is advanced to ContextualWisdomLab/fast-mlsirm#1691.

Inkspan

Latest verified immutable release remains v0.3.1; it has no released writing-diagnostics public package surface. The live Draft implementation still begins at #248 and continues through the strict contract, selector/decorations/controller/UI/actions/collaboration/package/assurance stack, including package owner #282 and browser/hostile-input assurance #285. These branches remain read-only from Naruon and must not be consumed before an immutable release exposes the required public subpath with integrity and source provenance.

Measurement/admission gate

User-facing diagnostics require a preregistered protocol before holdout labels are accessed, human/adjudicated reference evidence, sealed holdout/protocol hashes, fixed criterion identity/order, category-count ablation, calibration/Brier evidence, test-retest evidence, language/recipient-role/thread-depth DIF analysis, temporal drift monitoring, and comparison of single-model versus reviewer → Judge → adjudicator designs. Same-model Candidate/Judge use requires an explicitly published compatible calibration policy; otherwise adjudicate or abstain. Only artifacts with publish_decision=publish may become user-facing diagnostics; evaluation_only and withhold remain evidence-only.

Review API boundary

The current Task-10 Draft defines POST /api/email-writing/review as a thin Naruon-owned transport over the Task-9 service. It reuses the strict EmailWritingReviewRequest / EmailWritingReviewResponse contracts, passes server-authenticated scope and the scoped DB session into the review service, and has no send or editor-mutation authority. Missing source email is masked as stable 404, missing owner scope as 403, and allowlisted runtime/evidence/provider failures as bounded 503 codes. A typed EmailWritingReviewErrorResponse is declared for 403/404/503. Any non-allowlisted service error code collapses to review_unavailable, so a future internal causal string does not become browser-visible merely by being wrapped in the service error type. Invalid request transport is rejected before service execution.

The current runtime provider deliberately returns no assembled service while the immutable Judge dependency is unresolved. This is a fail-closed preparatory boundary, not a fake review implementation: the endpoint returns review_runtime_unavailable, while the existing mail edit/send paths remain independent and usable. The runtime provider must be replaced by the admitted immutable assembly during dependency-root reconstruction before this lane can become integration-current.

UI acceptance

After an immutable Inkspan release is available, EmailDetail must consume the public editor package rather than fork it. Production-like browser evidence must cover inline diagnostics, Focus/Apply/Ignore/Dismiss/Explain, undo, stale revisions, empty/loading/error/degraded states, keyboard/screen reader/touch, mobile/intermediate/desktop layouts, WCAG 2.2 AA, no source-text leakage into ARIA labels, and uninterrupted send-path behavior. Material UI work uses the repository's design tokens/Figma/Storybook where available and action-specific customer copy.

Done

Close only after the protected product can open an authorized email draft, obtain context-bound Candidate + independent Judge guidance through contextual-orchestrator, display revision-bound Inkspan diagnostics through an immutable package, preserve facts/intent/request strength, remain usable during review failure, record privacy-minimized feedback/evidence, and demonstrate preregistered calibration/admission evidence on one exact integrated protected release head.

Exact-head CI/security/coverage/docstrings/package/SBOM/provenance/review/recovery/accessibility/operability gates remain mandatory. Pending, queued, skipped, cancelled, absent, neutral, failed, stale, predecessor, synthetic, model-only, status-only, and author-only evidence is non-passing.


Roadmap item — CWL Project #1. Phase P2 · Component naruon. Canonical platform plan: #974 (docs/planning/naruon-platform-plan.md).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractenhancementNew feature or requestpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capability

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions