Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
204 commits
Select commit Hold shift + click to select a range
eb1391f
docs: add product-technical gap baseline with current PR heads
seonghobae Aug 23, 2026
d1ae16e
fix(docs): align product gap baseline with protected truth
seonghobae Aug 23, 2026
3a0fd19
docs: record 2026-08-24 loop findings and PR anchors in gap baseline
seonghobae Aug 24, 2026
bc4eee3
docs: refresh product gap baseline to live Orgmetra state
seonghobae Aug 24, 2026
626b8de
docs: append automation diagnostics to refreshed gap baseline
seonghobae Aug 24, 2026
9616df3
docs: record 2026-08-25 strix token-exchange outage rerun evidence
seonghobae Aug 25, 2026
c3cbd5a
docs: align buyer baseline with effective ruleset truth
seonghobae Aug 25, 2026
fe02c7c
docs: label product baseline references correctly
seonghobae Aug 25, 2026
c3289c8
docs: record 2026-08-25 review-triage drain and strix owning-boundary…
seonghobae Aug 25, 2026
4a07d0d
docs: refresh active buyer-gap ownership
seonghobae Aug 25, 2026
c27acdc
docs: refresh buyer-gap ownership through export and goal activation
seonghobae Aug 25, 2026
cf08981
docs: record 2026-08-26 review-triage sweep and repair ledger
seonghobae Aug 25, 2026
f41df5e
docs: refresh product gap control truth
seonghobae Aug 26, 2026
5d5748e
docs: refresh commercial gap ownership
seonghobae Aug 26, 2026
2a12138
docs(product): record protected-read UI owner lane
seonghobae Aug 27, 2026
c5c322b
docs(product): assign export delivery UI owner lane
seonghobae Aug 27, 2026
817c44e
docs: assign document retrieval UI owner and refresh central handoff …
seonghobae Aug 27, 2026
c171601
docs: assign Job grade UI owner in buyer gap baseline
seonghobae Aug 27, 2026
d4fd7a6
docs: assign Position lifecycle UI ownership
seonghobae Aug 27, 2026
b5dbbb3
docs: assign qualification review UI owner
seonghobae Aug 27, 2026
753dd35
docs(product): assign Position reporting interaction owner
seonghobae Aug 27, 2026
69898dd
docs: assign work-capacity UI owner
seonghobae Aug 27, 2026
391d302
docs: assign Employment absence UI owner
seonghobae Aug 27, 2026
333ac23
docs: register performance-goal interaction owner
seonghobae Aug 28, 2026
29e9445
docs(product): register employing-organization owner lane
seonghobae Aug 28, 2026
c8d199d
docs(product): track materialized employing-org Strix canary
seonghobae Aug 28, 2026
c2a3d68
docs: record terminal Strix failure for PR 141
seonghobae Aug 28, 2026
4aa189b
docs: refresh active PR readiness in gap baseline
seonghobae Aug 28, 2026
c536541
docs: record central Strix remediation owner
seonghobae Aug 28, 2026
f8363fb
docs: track latest central Strix head
seonghobae Aug 28, 2026
8e007d5
docs: align central Strix owner snapshot
seonghobae Aug 28, 2026
8778c98
docs: reconcile shipped capability status
seonghobae Aug 28, 2026
8267ea2
docs: index accepted ADRs
seonghobae Aug 28, 2026
57cb9e4
docs: refresh central remediation head
seonghobae Aug 28, 2026
8593779
docs: refresh central remediation head
seonghobae Aug 28, 2026
bffb186
docs: refresh central remediation head again
seonghobae Aug 28, 2026
79f13a7
docs: reconcile protected capability statuses
seonghobae Aug 28, 2026
9d212c8
docs: refresh central PR head
seonghobae Aug 28, 2026
371b571
docs: enumerate merged product anchors
seonghobae Aug 28, 2026
9114e6e
docs: refresh active PR baseline heads
seonghobae Aug 28, 2026
96011e1
docs: record current gate outcomes
seonghobae Aug 28, 2026
0e11fee
docs: refresh current central gate baseline
seonghobae Aug 28, 2026
aafcfd3
docs: mark audit outbox ADR as shipped
seonghobae Aug 28, 2026
5c69d71
docs: mark audit outbox changelog as shipped
seonghobae Aug 28, 2026
8fc6d81
docs: refresh gateway remediation head
seonghobae Aug 28, 2026
9e54ed0
docs: refresh central remediation ownership
seonghobae Aug 28, 2026
0ccdb29
docs: record central gateway follow-up merge
seonghobae Aug 28, 2026
0e3bfc2
docs: refresh current product gap baseline
seonghobae Aug 28, 2026
7e45b45
docs: refresh candidate withdrawal and employment heads
seonghobae Aug 28, 2026
62c721a
docs: record candidate withdrawal gate state
seonghobae Aug 28, 2026
5034407
docs: record resolved parent review threads
seonghobae Aug 28, 2026
7578cf2
docs: refresh terminal gate evidence
seonghobae Aug 28, 2026
878180c
docs: record cancelled Strix retry
seonghobae Aug 28, 2026
b44f1ed
docs: record leave and compensation review heads
seonghobae Aug 28, 2026
c2bee36
docs: record compensation strix blocker
seonghobae Aug 28, 2026
6908cac
chore: keep manifest compact
seonghobae Aug 28, 2026
5591bea
docs: separate Naruon intent from provider execution
seonghobae Aug 28, 2026
8e4d831
docs: refresh product gap baseline and shipped traceability
seonghobae Aug 28, 2026
8768287
docs: clarify current structured interview gate state
seonghobae Aug 28, 2026
c2aac09
docs(baseline): refresh active owner lane snapshot
seonghobae Aug 28, 2026
866a2c5
docs(baseline): record employment history lane
seonghobae Aug 28, 2026
38823bb
docs(baseline): record candidate timeline evidence
seonghobae Aug 28, 2026
981d12a
docs(baseline): record goal review gate evidence
seonghobae Aug 28, 2026
e7773c3
docs(baseline): record workspace gate evidence
seonghobae Aug 28, 2026
54a6696
docs(baseline): record assignment history evidence
seonghobae Aug 28, 2026
3d72236
docs(baseline): record qualification review evidence
seonghobae Aug 28, 2026
2a47f37
docs: reconcile shipped job analysis changelog
seonghobae Aug 28, 2026
66cb92e
docs(baseline): clarify draft base branch
seonghobae Aug 28, 2026
b5d04a9
docs(baseline): record job grade and lifecycle evidence
seonghobae Aug 28, 2026
9348aaa
docs(baseline): record position span-of-control evidence
seonghobae Aug 28, 2026
03ba7da
merge: sync baseline branch before evidence update
seonghobae Aug 28, 2026
c70d39d
docs(traceability): mark shipped kernel capabilities
seonghobae Aug 28, 2026
ac204a7
docs(baseline): record span-of-control hosted check
seonghobae Aug 28, 2026
ef1237a
docs(baseline): refresh current governance evidence
seonghobae Aug 29, 2026
0255dd9
docs(baseline): record current PR inventory
seonghobae Aug 29, 2026
75c036d
docs(traceability): reconcile shipped control maturity
seonghobae Aug 29, 2026
1501bb9
docs(traceability): mark foundation integrity shipped
seonghobae Aug 29, 2026
eebb927
docs(baseline): refresh employment history gate state
seonghobae Aug 29, 2026
7f302cb
docs(baseline): correct hosted check totals
seonghobae Aug 29, 2026
d73f2c8
docs(baseline): refresh current review evidence
seonghobae Aug 29, 2026
eb396b9
docs: refresh live PR gap evidence
seonghobae Aug 29, 2026
c963d11
docs: refresh employment history evidence count
seonghobae Aug 29, 2026
48fc1f2
docs: refresh external receipt evidence snapshot
seonghobae Aug 29, 2026
657cc9b
docs: refresh employment history PR evidence
seonghobae Aug 29, 2026
f1d1bc2
docs: refresh employment history hosted checks
seonghobae Aug 29, 2026
98a85a0
docs: refresh workforce review baseline
seonghobae Aug 29, 2026
57dd243
docs: record exact workforce aggregation head
seonghobae Aug 29, 2026
20ee463
docs: record final workforce gate state
seonghobae Aug 29, 2026
81f687d
docs: refresh validity and compensation PR evidence
seonghobae Aug 29, 2026
a4e839d
docs: record current runtime-integrity PR evidence
seonghobae Aug 29, 2026
c6e55e0
docs: refresh organization hierarchy PR evidence
seonghobae Aug 29, 2026
5f96c56
docs: record interval and position review evidence
seonghobae Aug 29, 2026
8505883
docs: record criterion chronology review evidence
seonghobae Aug 29, 2026
865379e
docs: record correction-boundary review evidence
seonghobae Aug 29, 2026
98c815f
docs: record people operability review evidence
seonghobae Aug 29, 2026
6f6bc34
docs: record governed export review evidence
seonghobae Aug 29, 2026
f393350
docs: record retention disposition review evidence
seonghobae Aug 29, 2026
46efa2c
docs: refresh correction PR exact-head evidence
seonghobae Aug 29, 2026
963c9c6
docs: record release candidate evidence status
seonghobae Aug 29, 2026
a2978fb
docs: record Kubernetes reference review evidence
seonghobae Aug 29, 2026
e804d05
docs: refresh criterion chronology evidence
seonghobae Aug 29, 2026
2f5998b
docs: record candidate offer response review evidence
seonghobae Aug 29, 2026
9c980e6
docs: record contextual orchestrator draft evidence status
seonghobae Aug 29, 2026
9431bac
docs: record outbox retry policy status
seonghobae Aug 29, 2026
e5eb4ad
docs: record semantic job evidence status
seonghobae Aug 29, 2026
3074302
docs: record psychometrics evidence PR state
seonghobae Aug 29, 2026
bbe269a
docs: record keyverse lifecycle PR state
seonghobae Aug 29, 2026
01973b2
docs: record candidate conversion PR state
seonghobae Aug 29, 2026
1e4b31d
docs: record job analysis budget PR state
seonghobae Aug 29, 2026
0646619
docs: record People telemetry PR state
seonghobae Aug 29, 2026
acf52e5
docs: reconcile live PR queue and rerun guidance
seonghobae Aug 29, 2026
b0bb17c
docs: record data-rights request PR state
seonghobae Aug 29, 2026
dc04ca0
docs: record performance goal plan PR state
seonghobae Aug 29, 2026
16ce574
docs: record performance context PR state
seonghobae Aug 29, 2026
ac384ab
docs: record position reporting PR state
seonghobae Aug 29, 2026
8e63aaf
docs: record position reporting review PR state
seonghobae Aug 29, 2026
6456da5
docs: record organization hierarchy review PR state
seonghobae Aug 29, 2026
b4a6cc3
docs: record Position vacancy PR state
seonghobae Aug 29, 2026
79fc355
docs: record document evidence PR state
seonghobae Aug 29, 2026
20ec7af
docs: record compensation PR state
seonghobae Aug 29, 2026
6345f0b
docs: record job grade review PR state
seonghobae Aug 29, 2026
0c1d308
docs: record compensation workflow repair
seonghobae Aug 29, 2026
5f7e140
docs: record compensation workflow result
seonghobae Aug 29, 2026
accb5e2
docs: record audit review PR state
seonghobae Aug 29, 2026
026161c
docs: record employment work capacity review PR state
seonghobae Aug 29, 2026
8f87329
docs: refresh compensation and work capacity evidence
seonghobae Aug 29, 2026
27fc399
docs: record qualification rule review PR state
seonghobae Aug 29, 2026
13f34eb
docs: record qualification rule persistence PR state
seonghobae Aug 29, 2026
b10a98b
docs: record position reporting persistence PR state
seonghobae Aug 29, 2026
ef68ffa
docs: record document persistence PR state
seonghobae Aug 29, 2026
9404ebb
docs: record offer-to-hire close review state
seonghobae Aug 29, 2026
1c7329b
docs: record vacancy and lifecycle review PR state
seonghobae Aug 29, 2026
2dfbd71
docs: record current stacked parent tip
seonghobae Aug 29, 2026
ef103a6
docs: record Position lifecycle application PR state
seonghobae Aug 29, 2026
1eb044a
docs: record employment absence PR state
seonghobae Aug 29, 2026
f354c91
docs: record freshness and retrieval PR state
seonghobae Aug 29, 2026
4f38e13
docs: record job analysis draft PR state
seonghobae Aug 29, 2026
dec018f
docs: record release readiness review PR state
seonghobae Aug 29, 2026
b4ffa62
docs: record hierarchy application PR state
seonghobae Aug 29, 2026
941ae86
docs: record HR export execution PR state
seonghobae Aug 29, 2026
43a0582
docs: record goal activation PR state
seonghobae Aug 29, 2026
a918da4
docs: record service portability PR state
seonghobae Aug 29, 2026
d46c379
docs: record customer copy PR state
seonghobae Aug 29, 2026
c5b82b9
docs: record acceleration ADR PR state
seonghobae Aug 29, 2026
5c1b15a
docs: record goal-plan persistence security repair
seonghobae Aug 29, 2026
d78a587
docs: record release authorization PR state
seonghobae Aug 29, 2026
afd3dda
docs: record goal-plan persistence check
seonghobae Aug 29, 2026
880c6d4
docs: record release publication check
seonghobae Aug 29, 2026
e4ca6d5
docs: record work-capacity persistence check
seonghobae Aug 30, 2026
241e6eb
docs: record separation approval boundary status
seonghobae Aug 30, 2026
507d399
docs: record protected read state status
seonghobae Aug 30, 2026
3cb956b
docs: record export delivery interaction status
seonghobae Aug 30, 2026
f092377
docs: record document retrieval interaction status
seonghobae Aug 30, 2026
df819a2
docs: refresh job grade interaction evidence
seonghobae Aug 30, 2026
1d554fd
docs: refresh position lifecycle interaction status
seonghobae Aug 30, 2026
f54802e
docs: record qualification review interaction status
seonghobae Aug 30, 2026
221138d
docs: record reporting review interaction status
seonghobae Aug 30, 2026
1599076
docs: record work capacity interaction status
seonghobae Aug 30, 2026
4e7e03b
docs: record employment absence interaction status
seonghobae Aug 30, 2026
35abc48
docs: record performance goal interaction status
seonghobae Aug 30, 2026
926178c
docs: record employing organization PR status
seonghobae Aug 30, 2026
ef150ec
docs: record assignment history review evidence
seonghobae Aug 30, 2026
4d5eaa0
docs: record assignment history ui evidence
seonghobae Aug 30, 2026
f0ddb03
docs: record candidate evidence ui evidence
seonghobae Aug 30, 2026
976e5cb
docs: record validation dashboard evidence
seonghobae Aug 30, 2026
5ad10fa
docs: record validation and job architecture evidence
seonghobae Aug 30, 2026
852544f
docs: record legal employer ui evidence
seonghobae Aug 30, 2026
3f61235
docs: record position history read evidence
seonghobae Aug 30, 2026
bcacb5f
docs: record position history adapter evidence
seonghobae Aug 30, 2026
0a60be5
docs: refresh open queue snapshot
seonghobae Aug 30, 2026
18256b8
docs: record position history HTTP read lane
seonghobae Aug 30, 2026
1ce0c1f
docs: record employment history HTTP read lane
seonghobae Aug 30, 2026
05e9357
docs: refresh exact-head product gap evidence
seonghobae Aug 30, 2026
ae5406e
docs: record employer API compatibility lane
seonghobae Aug 30, 2026
a88c8d5
docs: repair assignment adapter provenance
seonghobae Aug 30, 2026
8b714b7
docs: record workforce evidence child and live PR heads
seonghobae Aug 30, 2026
0d46d18
docs: record exact current interview-plan evidence
seonghobae Aug 30, 2026
0ff00cd
docs: record central required-review gate root cause
seonghobae Aug 31, 2026
b2ab495
fix: reseal manifest after codegraph ignore
seonghobae Sep 1, 2026
61986f8
docs(product): replace stale PR inventory with commercialization base…
seonghobae Sep 1, 2026
dbefe8c
docs(doctoring): trace commercialization and governance sources
seonghobae Sep 1, 2026
7f2ebf7
docs(gaps): refresh live governance evidence
seonghobae Sep 1, 2026
f461787
docs: align commercialization governance contract
seonghobae Sep 1, 2026
a76df82
docs(commercialization): track owner-plane governance repair
seonghobae Sep 2, 2026
8304d8d
docs(commercialization): track explicit assignment authority gap
seonghobae Sep 2, 2026
be380fc
docs(research): refresh accessibility and control standards
seonghobae Sep 2, 2026
559ee68
test: pin LLM routing and semantic ownership guidance
seonghobae Sep 2, 2026
e129d72
docs: route model-backed Actions through contextual-orchestrator
seonghobae Sep 2, 2026
57def8e
docs: align semantic and orchestration ownership boundaries
seonghobae Sep 2, 2026
2f01935
chore: reseal foundation manifest for guidance repair
seonghobae Sep 2, 2026
d6f299b
test: run LLM routing policy regression in foundation validation
seonghobae Sep 2, 2026
e3ed61b
chore: reseal manifest for routing regression registration
seonghobae Sep 2, 2026
2ca0e6a
docs(gaps): refresh governance and security owner truth
seonghobae Sep 2, 2026
2f888ec
merge(develop): adopt protected CI admission fix in baseline writer
seonghobae Sep 3, 2026
465abcb
docs(gaps): add assignment correction provenance gap
seonghobae Sep 3, 2026
8caea75
merge(develop): adopt restored documentation contract checks
seonghobae Sep 3, 2026
56887f6
docs(gaps): align protected workflow and correction time truth
seonghobae Sep 3, 2026
c976ab4
docs: record canonical People runtime prerequisites
seonghobae Sep 3, 2026
55de0cf
docs: add canonical runner prerequisite to commercialization order
seonghobae Sep 3, 2026
5e03ac2
docs: track authorization input integrity
seonghobae Sep 3, 2026
a79f082
docs(product): record authorization constructor provenance gap
seonghobae Sep 3, 2026
2bd4810
docs(baseline): correct authorization trust boundary
seonghobae Sep 3, 2026
e373489
docs: align AUTH-01 with Job Analysis runtime evidence
seonghobae Sep 3, 2026
c0a40a4
docs: doctor commercialization baseline after workflow integration
seonghobae Sep 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,6 @@ secrets/
artifacts/
reports/
*.log

# Local code-intelligence index (colbymchenry/codegraph); never committed
.codegraph/
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ Build Orgmetra as a commercial-grade, evidence-centered HRIS and HCM platform th

- Never bypass branch protection, required checks, independent review, OpenCode, Noema, Strix, SAST, or Security Scan gates.
- Never self-approve or manufacture approval evidence.
- Never use `COPILOT_GITHUB_TOKEN` as a development model credential. Use `NVIDIA_NIM_API_KEY` for model-backed tests and OpenCode development paths.
- Model-backed GitHub Actions request only `orchestrator/free` through the released contextual-orchestrator gateway token. Consumer workflows must not select a provider, provider group, paid fallback, or use `COPILOT_GITHUB_TOKEN` or provider API keys directly.
- Never make LLM output an autonomous high-impact employment decision.
- Never copy another CWL product into Orgmetra when an adapter/package/API/event boundary is sufficient.
- Never directly query another service's application database.
Expand Down
8 changes: 4 additions & 4 deletions CHANGELOG.md
Comment thread
seonghobae marked this conversation as resolved.
Comment thread
seonghobae marked this conversation as resolved.
Original file line number Diff line number Diff line change
Expand Up @@ -7,12 +7,12 @@ All notable changes to Orgmetra will be documented in this file.
### Added

- Accepted ADRs 0001–0003 now include buyer-facing Context, Decision, and Consequences grounded in verified ISO 30400:2022, ISO 30414:2025, Uniform Guidelines (29 C.F.R. Part 1607), SIOP (2018), OpenAPI Specification v3.2.0, OpenID Connect Core 1.0 errata set 2, CloudEvents v1.0.2, Jensen and Snodgrass (1999), Snodgrass (1999), and Allen (1983) records already listed in `docs/doctoring/REFERENCES.md`. ADRs 0004 and 0005 gained APA 7th References pointers to that same bibliography without changing their Decision bodies.
- Active-PR governed Job Analysis persistence/API on the canonical `JobAnalysisSnapshot` model: migration `0013_job_analysis_snapshot.sql` stores immutable tenant-scoped snapshot, Task, KSAO, Task–KSAO, FJA and write-command evidence; `POST /v1/tenants/{tenant_record_id}/job-analysis-snapshots` and matching GET enforce purpose-bound Keyverse scope, authenticated-principal actor authority, bounded/strict JSON handling, transactional Idempotency-Key serialization, parent-scope fail-closed integrity, forced RLS, and atomic audit/outbox evidence. ADR 0014 records the persistence decision while ADR 0007 remains the domain/evidence authority; validated evidence still requires accountable human review and non-LLM provenance, and the service does not make a high-impact employment decision.
- Active-PR `orgmetra_selection_review` packet for PII-minimized, evidence-bound human selection review: canonical operational tenant identity, UUID-backed opaque candidate/Job/sealed-evidence/reviewer references, explicit purpose/reason/evidence version, deterministic canonical JSON and SHA-256 correlation, mandatory human decision state, redacted packet repr, and provenance-paired model evidence that remains `untrusted_draft`, with exact 100% owned statement and branch coverage required by its quality gate.
- Protected-main governed Job Analysis persistence/API on the canonical `JobAnalysisSnapshot` model: migration `0013_job_analysis_snapshot.sql` stores immutable tenant-scoped snapshot, Task, KSAO, Task–KSAO, FJA and write-command evidence; `POST /v1/tenants/{tenant_record_id}/job-analysis-snapshots` and matching GET enforce purpose-bound Keyverse scope, authenticated-principal actor authority, bounded/strict JSON handling, transactional Idempotency-Key serialization, parent-scope fail-closed integrity, forced RLS, and atomic audit/outbox evidence. ADR 0014 records the persistence decision while ADR 0007 remains the domain/evidence authority; validated evidence still requires accountable human review and non-LLM provenance, and the service does not make a high-impact employment decision.
- Protected-main `orgmetra_selection_review` packet for PII-minimized, evidence-bound human selection review: canonical operational tenant identity, UUID-backed opaque candidate/Job/sealed-evidence/reviewer references, explicit purpose/reason/evidence version, deterministic canonical JSON and SHA-256 correlation, mandatory human decision state, redacted packet repr, and provenance-paired model evidence that remains `untrusted_draft`, with exact 100% owned statement and branch coverage required by its quality gate.
- Active performance-criterion scope hardening: `criterion_observation_scope_guard` rejects criterion outcomes for a Job the worker did not effectively hold at the observation date, observations before the relevant assignment, and observations outside the referenced performance cycle while preserving valid multiple-assignment cases and existing bitemporal correction semantics. The guard evaluates current-recorded facts, derives the date coordinate from `observed_at` in UTC so session `TimeZone` cannot alter the result, uses a trusted function search path, and adds no PII or automated employment decision authority. The Foundation PostgreSQL contract also rejects a closed `recorded_to` on each time-coordinate lookup and proves UTC midnight plus non-UTC session `TimeZone` boundaries.
- Bitemporal tenant-scoped organization hierarchy validation that rejects visible indirect parent cycles and reuses single-valued recorded-time reconstruction before graph traversal.
- Stacked governed job-analysis evidence contract via `JobAnalysisSnapshot`, `TaskEvidence`, `KSAORequirement`, `TaskKSAOLink`, `FunctionalJobAnalysisProfile`, and `EvidenceSource`: tenant/Job-scoped observable tasks, explicit Task-to-KSAO linkage, importance/difficulty/proficiency ratings, source/version/retrieval/SHA-256 provenance, deterministic canonical snapshot bytes, current O*NET evidence support, and historical DOT Data/People/Things compatibility. Validated snapshots require accountable human review and complete non-LLM evidence; LLM-origin material remains `analysis_draft`, and the snapshot is evidence input rather than a hiring, promotion, termination, compensation, or other high-impact employment decision.
- Stacked governed audit/outbox slice via `AuditOutboxEvent`, `audit_event_record`, `outbox_delivery_record`, and `outbox_delivery_escalation_record`: CloudEvents 1.0-compatible PII-minimized metadata, exact canonical JSON bytes, database-verified SHA-256 digests, mandatory human confirmation for high-impact events, immutable audit evidence, tenant RLS, atomic audit/outbox insertion, guarded pending/leased/delivered/dead-lettered delivery state, tenant-safe `claim_outbox_delivery(...)` with deterministic due-work ordering, `FOR UPDATE ... SKIP LOCKED`, opaque worker identity, bounded future leases, immutable envelope return, and atomic takeover of genuinely expired leases only while retry attempts remain; owner-bound `complete_outbox_delivery(...)` and `retry_outbox_delivery(...)`; database-budget-governed `dead_letter_outbox_delivery(...)`; and a separately privileged `operator_dead_letter_expired_outbox_delivery(...)` recovery path for an exhausted final lease whose recorded worker identity is permanently unavailable. `maximum_attempt_count` is persisted on the delivery row, defaults to 5, is constrained to 1 through 100, and cannot be lowered by a dispatcher during finalization. Migration 0007 prevents retry or expired-lease takeover from creating attempt N+1; migration 0008 adds TRUNCATE guards, trusted function search paths, a concurrently built due-work partial index, session-independent immutable envelope validation, and operator recovery backed by separate NOLOGIN/NOBYPASSRLS owner/capability roles so the externally assignable operator role can invoke recovery without receiving direct transport-table read/write rights. Migration 0008 also rejects pre-existing reserved recovery-role names before project DDL, atomically contains the temporary schema-creation privilege used for function ownership handoff, and forces deferred escalation binding while the narrow SECURITY DEFINER owner is still active. Exponential/backoff policy selection, policy-specific producer configuration, and external delivery receipts remain subsequent work.
- Governed audit/outbox slice on protected `develop` via `AuditOutboxEvent`, `audit_event_record`, `outbox_delivery_record`, and `outbox_delivery_escalation_record`: CloudEvents 1.0-compatible PII-minimized metadata, exact canonical JSON bytes, database-verified SHA-256 digests, mandatory human confirmation for high-impact events, immutable audit evidence, tenant RLS, atomic audit/outbox insertion, guarded pending/leased/delivered/dead-lettered delivery state, tenant-safe `claim_outbox_delivery(...)` with deterministic due-work ordering, `FOR UPDATE ... SKIP LOCKED`, opaque worker identity, bounded future leases, immutable envelope return, and atomic takeover of genuinely expired leases only while retry attempts remain; owner-bound `complete_outbox_delivery(...)` and `retry_outbox_delivery(...)`; database-budget-governed `dead_letter_outbox_delivery(...)`; and a separately privileged `operator_dead_letter_expired_outbox_delivery(...)` recovery path for an exhausted final lease whose recorded worker identity is permanently unavailable. `maximum_attempt_count` is persisted on the delivery row, defaults to 5, is constrained to 1 through 100, and cannot be lowered by a dispatcher during finalization. Migration 0007 prevents retry or expired-lease takeover from creating attempt N+1; migration 0008 adds TRUNCATE guards, trusted function search paths, a concurrently built due-work partial index, session-independent immutable envelope validation, and operator recovery backed by separate NOLOGIN/NOBYPASSRLS owner/capability roles so the externally assignable operator role can invoke recovery without receiving direct transport-table read/write rights. Migration 0008 also rejects pre-existing reserved recovery-role names before project DDL, atomically contains the temporary schema-creation privilege used for function ownership handoff, and forces deferred escalation binding while the narrow SECURITY DEFINER owner is still active. Exponential/backoff policy selection, policy-specific producer configuration, and external delivery receipts remain subsequent work.
- `orgmetra_hris_kernel` 0.4.0 with exclusive-versus-concurrent employment, staffable position coverage, exclusive-seat capacity, and `validate_assignment_write` at 100% statement and branch coverage.
- `POST /v1/employment-records`, `POST /v1/position-records`, and `POST /v1/assignment-records` with the same Keyverse mutation context, confirmation, and versioned evidence composition as other high-impact commands.
- `employment_record_version.employment_concurrency_code` constrained to `exclusive` or `concurrent`.
Expand Down Expand Up @@ -73,4 +73,4 @@ All notable changes to Orgmetra will be documented in this file.

### Notes

- Protected `develop` at `e7ddb7a78a5e1460410005d10f43ebf18c5e12e4` includes normalized validity-study and criterion integrity, bitemporal workforce composition, governed candidate-to-worker conversion, purpose-bound PII authorization, GET-only People reads, governed People mutation/idempotency API, and the accepted ADR 0001–0003 source expansion integrated by #37. Job Analysis persistence/API and the selection-review packet remain active-PR truth until their unchanged exact heads satisfy fresh gates and merge.
- Protected `develop` at `e7ddb7a78a5e1460410005d10f43ebf18c5e12e4` includes normalized validity-study and criterion integrity, bitemporal workforce composition, governed candidate-to-worker conversion, purpose-bound PII authorization, GET-only People reads, governed People mutation/idempotency API, and the accepted ADR 0001–0003 source expansion integrated by #37. Subsequent protected-develop merges recorded governed Job Analysis persistence/API and the selection-review packet as shipped capabilities; current active hardening and exact protected-head status are tracked in the README, TRACEABILITY, and product gap baseline rather than this historical anchor.
5 changes: 3 additions & 2 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,9 +11,10 @@ Do not treat Orgmetra as a resume parser, ATS-only system, psychometric engine,
- Psychometrics Commons owns assessment operations and immutable assessment result snapshots.
- fast-mlsirm owns psychometric numerical kernels.
- TEPP owns temporal/event/multilevel analysis artifacts.
- Semantic Data Portal owns occupation/skill/ability ontology and semantic catalog.
- ConceptWeave owns ontology and semantic-layer observe/discover/propose/align/validate/review/publish workflows and immutable semantic releases.
- semantic-data-portal owns catalog, governance, search, serving, and consumption of released semantic resources; it does not author Orgmetra domain truth.
- Naruon owns mail/calendar/file control-plane integrations.
- Contextual Orchestrator owns bounded LLM orchestration traces.
- contextual-orchestrator owns bounded LLM orchestration traces, provider discovery, capability-aware routing, and gateway contracts; Orgmetra consumes only released APIs and schemas.

## Writing guidance

Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,4 +78,4 @@ Job evidence

## Status

Protected `develop` includes the employment-truth kernel, governed candidate-to-worker conversion, purpose-bound PII authorization, normalized worker-bound validity studies, criterion-observation scope, bitemporal workforce-composition evidence, the governed Naruon intent adapter, and requisition review packets. This active PR adds durable purpose-bound People mutation and confirmed-hire materialization paths for Employment, Position, and Assignment with atomic audit/outbox evidence and tenant-scoped idempotency; treat those write paths as active-PR truth until this exact head passes all fresh protected-base gates and merges.
Protected `develop` includes the employment-truth kernel, durable purpose-bound People mutation and confirmed-hire materialization paths for Employment, Position, and Assignment with atomic audit/outbox evidence and tenant-scoped idempotency, governed Job Analysis snapshot persistence/read, candidate evidence intake, offer approval packets, governed candidate-to-worker conversion, purpose-bound PII authorization, normalized worker-bound validity studies, criterion-observation scope, bitemporal workforce-composition evidence, the governed Naruon intent adapter, and requisition review packets. Active PRs remain separate from this protected-branch shipped truth until their exact heads pass all fresh protected-base gates and merge.
Loading
Loading