-
Notifications
You must be signed in to change notification settings - Fork 0
docs: maintain durable product-technical gap baseline #100
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
seonghobae
wants to merge
204
commits into
develop
Choose a base branch
from
docs/product-technical-gap-baseline
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+301
−53
Draft
Changes from 6 commits
Commits
Show all changes
204 commits
Select commit
Hold shift + click to select a range
eb1391f
docs: add product-technical gap baseline with current PR heads
seonghobae d1ae16e
fix(docs): align product gap baseline with protected truth
seonghobae 3a0fd19
docs: record 2026-08-24 loop findings and PR anchors in gap baseline
seonghobae bc4eee3
docs: refresh product gap baseline to live Orgmetra state
seonghobae 626b8de
docs: append automation diagnostics to refreshed gap baseline
seonghobae 9616df3
docs: record 2026-08-25 strix token-exchange outage rerun evidence
seonghobae c3cbd5a
docs: align buyer baseline with effective ruleset truth
seonghobae fe02c7c
docs: label product baseline references correctly
seonghobae c3289c8
docs: record 2026-08-25 review-triage drain and strix owning-boundary…
seonghobae 4a07d0d
docs: refresh active buyer-gap ownership
seonghobae c27acdc
docs: refresh buyer-gap ownership through export and goal activation
seonghobae cf08981
docs: record 2026-08-26 review-triage sweep and repair ledger
seonghobae f41df5e
docs: refresh product gap control truth
seonghobae 5d5748e
docs: refresh commercial gap ownership
seonghobae 2a12138
docs(product): record protected-read UI owner lane
seonghobae c5c322b
docs(product): assign export delivery UI owner lane
seonghobae 817c44e
docs: assign document retrieval UI owner and refresh central handoff …
seonghobae c171601
docs: assign Job grade UI owner in buyer gap baseline
seonghobae d4fd7a6
docs: assign Position lifecycle UI ownership
seonghobae b5dbbb3
docs: assign qualification review UI owner
seonghobae 753dd35
docs(product): assign Position reporting interaction owner
seonghobae 69898dd
docs: assign work-capacity UI owner
seonghobae 391d302
docs: assign Employment absence UI owner
seonghobae 333ac23
docs: register performance-goal interaction owner
seonghobae 29e9445
docs(product): register employing-organization owner lane
seonghobae c8d199d
docs(product): track materialized employing-org Strix canary
seonghobae c2a3d68
docs: record terminal Strix failure for PR 141
seonghobae 4aa189b
docs: refresh active PR readiness in gap baseline
seonghobae c536541
docs: record central Strix remediation owner
seonghobae f8363fb
docs: track latest central Strix head
seonghobae 8e007d5
docs: align central Strix owner snapshot
seonghobae 8778c98
docs: reconcile shipped capability status
seonghobae 8267ea2
docs: index accepted ADRs
seonghobae 57cb9e4
docs: refresh central remediation head
seonghobae 8593779
docs: refresh central remediation head
seonghobae bffb186
docs: refresh central remediation head again
seonghobae 79f13a7
docs: reconcile protected capability statuses
seonghobae 9d212c8
docs: refresh central PR head
seonghobae 371b571
docs: enumerate merged product anchors
seonghobae 9114e6e
docs: refresh active PR baseline heads
seonghobae 96011e1
docs: record current gate outcomes
seonghobae 0e11fee
docs: refresh current central gate baseline
seonghobae aafcfd3
docs: mark audit outbox ADR as shipped
seonghobae 5c69d71
docs: mark audit outbox changelog as shipped
seonghobae 8fc6d81
docs: refresh gateway remediation head
seonghobae 9e54ed0
docs: refresh central remediation ownership
seonghobae 0ccdb29
docs: record central gateway follow-up merge
seonghobae 0e3bfc2
docs: refresh current product gap baseline
seonghobae 7e45b45
docs: refresh candidate withdrawal and employment heads
seonghobae 62c721a
docs: record candidate withdrawal gate state
seonghobae 5034407
docs: record resolved parent review threads
seonghobae 7578cf2
docs: refresh terminal gate evidence
seonghobae 878180c
docs: record cancelled Strix retry
seonghobae b44f1ed
docs: record leave and compensation review heads
seonghobae c2bee36
docs: record compensation strix blocker
seonghobae 6908cac
chore: keep manifest compact
seonghobae 5591bea
docs: separate Naruon intent from provider execution
seonghobae 8e4d831
docs: refresh product gap baseline and shipped traceability
seonghobae 8768287
docs: clarify current structured interview gate state
seonghobae c2aac09
docs(baseline): refresh active owner lane snapshot
seonghobae 866a2c5
docs(baseline): record employment history lane
seonghobae 38823bb
docs(baseline): record candidate timeline evidence
seonghobae 981d12a
docs(baseline): record goal review gate evidence
seonghobae e7773c3
docs(baseline): record workspace gate evidence
seonghobae 54a6696
docs(baseline): record assignment history evidence
seonghobae 3d72236
docs(baseline): record qualification review evidence
seonghobae 2a47f37
docs: reconcile shipped job analysis changelog
seonghobae 66cb92e
docs(baseline): clarify draft base branch
seonghobae b5d04a9
docs(baseline): record job grade and lifecycle evidence
seonghobae 9348aaa
docs(baseline): record position span-of-control evidence
seonghobae 03ba7da
merge: sync baseline branch before evidence update
seonghobae c70d39d
docs(traceability): mark shipped kernel capabilities
seonghobae ac204a7
docs(baseline): record span-of-control hosted check
seonghobae ef1237a
docs(baseline): refresh current governance evidence
seonghobae 0255dd9
docs(baseline): record current PR inventory
seonghobae 75c036d
docs(traceability): reconcile shipped control maturity
seonghobae 1501bb9
docs(traceability): mark foundation integrity shipped
seonghobae eebb927
docs(baseline): refresh employment history gate state
seonghobae 7f302cb
docs(baseline): correct hosted check totals
seonghobae d73f2c8
docs(baseline): refresh current review evidence
seonghobae eb396b9
docs: refresh live PR gap evidence
seonghobae c963d11
docs: refresh employment history evidence count
seonghobae 48fc1f2
docs: refresh external receipt evidence snapshot
seonghobae 657cc9b
docs: refresh employment history PR evidence
seonghobae f1d1bc2
docs: refresh employment history hosted checks
seonghobae 98a85a0
docs: refresh workforce review baseline
seonghobae 57dd243
docs: record exact workforce aggregation head
seonghobae 20ee463
docs: record final workforce gate state
seonghobae 81f687d
docs: refresh validity and compensation PR evidence
seonghobae a4e839d
docs: record current runtime-integrity PR evidence
seonghobae c6e55e0
docs: refresh organization hierarchy PR evidence
seonghobae 5f96c56
docs: record interval and position review evidence
seonghobae 8505883
docs: record criterion chronology review evidence
seonghobae 865379e
docs: record correction-boundary review evidence
seonghobae 98c815f
docs: record people operability review evidence
seonghobae 6f6bc34
docs: record governed export review evidence
seonghobae f393350
docs: record retention disposition review evidence
seonghobae 46efa2c
docs: refresh correction PR exact-head evidence
seonghobae 963c9c6
docs: record release candidate evidence status
seonghobae a2978fb
docs: record Kubernetes reference review evidence
seonghobae e804d05
docs: refresh criterion chronology evidence
seonghobae 2f5998b
docs: record candidate offer response review evidence
seonghobae 9c980e6
docs: record contextual orchestrator draft evidence status
seonghobae 9431bac
docs: record outbox retry policy status
seonghobae e5eb4ad
docs: record semantic job evidence status
seonghobae 3074302
docs: record psychometrics evidence PR state
seonghobae bbe269a
docs: record keyverse lifecycle PR state
seonghobae 01973b2
docs: record candidate conversion PR state
seonghobae 1e4b31d
docs: record job analysis budget PR state
seonghobae 0646619
docs: record People telemetry PR state
seonghobae acf52e5
docs: reconcile live PR queue and rerun guidance
seonghobae b0bb17c
docs: record data-rights request PR state
seonghobae dc04ca0
docs: record performance goal plan PR state
seonghobae 16ce574
docs: record performance context PR state
seonghobae ac384ab
docs: record position reporting PR state
seonghobae 8e63aaf
docs: record position reporting review PR state
seonghobae 6456da5
docs: record organization hierarchy review PR state
seonghobae b4a6cc3
docs: record Position vacancy PR state
seonghobae 79fc355
docs: record document evidence PR state
seonghobae 20ec7af
docs: record compensation PR state
seonghobae 6345f0b
docs: record job grade review PR state
seonghobae 0c1d308
docs: record compensation workflow repair
seonghobae 5f7e140
docs: record compensation workflow result
seonghobae accb5e2
docs: record audit review PR state
seonghobae 026161c
docs: record employment work capacity review PR state
seonghobae 8f87329
docs: refresh compensation and work capacity evidence
seonghobae 27fc399
docs: record qualification rule review PR state
seonghobae 13f34eb
docs: record qualification rule persistence PR state
seonghobae b10a98b
docs: record position reporting persistence PR state
seonghobae ef68ffa
docs: record document persistence PR state
seonghobae 9404ebb
docs: record offer-to-hire close review state
seonghobae 1c7329b
docs: record vacancy and lifecycle review PR state
seonghobae 2dfbd71
docs: record current stacked parent tip
seonghobae ef103a6
docs: record Position lifecycle application PR state
seonghobae 1eb044a
docs: record employment absence PR state
seonghobae f354c91
docs: record freshness and retrieval PR state
seonghobae 4f38e13
docs: record job analysis draft PR state
seonghobae dec018f
docs: record release readiness review PR state
seonghobae b4ffa62
docs: record hierarchy application PR state
seonghobae 941ae86
docs: record HR export execution PR state
seonghobae 43a0582
docs: record goal activation PR state
seonghobae a918da4
docs: record service portability PR state
seonghobae d46c379
docs: record customer copy PR state
seonghobae c5b82b9
docs: record acceleration ADR PR state
seonghobae 5c1b15a
docs: record goal-plan persistence security repair
seonghobae d78a587
docs: record release authorization PR state
seonghobae afd3dda
docs: record goal-plan persistence check
seonghobae 880c6d4
docs: record release publication check
seonghobae e4ca6d5
docs: record work-capacity persistence check
seonghobae 241e6eb
docs: record separation approval boundary status
seonghobae 507d399
docs: record protected read state status
seonghobae 3cb956b
docs: record export delivery interaction status
seonghobae f092377
docs: record document retrieval interaction status
seonghobae df819a2
docs: refresh job grade interaction evidence
seonghobae 1d554fd
docs: refresh position lifecycle interaction status
seonghobae f54802e
docs: record qualification review interaction status
seonghobae 221138d
docs: record reporting review interaction status
seonghobae 1599076
docs: record work capacity interaction status
seonghobae 4e7e03b
docs: record employment absence interaction status
seonghobae 35abc48
docs: record performance goal interaction status
seonghobae 926178c
docs: record employing organization PR status
seonghobae ef150ec
docs: record assignment history review evidence
seonghobae 4d5eaa0
docs: record assignment history ui evidence
seonghobae f0ddb03
docs: record candidate evidence ui evidence
seonghobae 976e5cb
docs: record validation dashboard evidence
seonghobae 5ad10fa
docs: record validation and job architecture evidence
seonghobae 852544f
docs: record legal employer ui evidence
seonghobae 3f61235
docs: record position history read evidence
seonghobae bcacb5f
docs: record position history adapter evidence
seonghobae 0a60be5
docs: refresh open queue snapshot
seonghobae 18256b8
docs: record position history HTTP read lane
seonghobae 1ce0c1f
docs: record employment history HTTP read lane
seonghobae 05e9357
docs: refresh exact-head product gap evidence
seonghobae ae5406e
docs: record employer API compatibility lane
seonghobae a88c8d5
docs: repair assignment adapter provenance
seonghobae 8b714b7
docs: record workforce evidence child and live PR heads
seonghobae 0d46d18
docs: record exact current interview-plan evidence
seonghobae 0ff00cd
docs: record central required-review gate root cause
seonghobae b2ab495
fix: reseal manifest after codegraph ignore
seonghobae 61986f8
docs(product): replace stale PR inventory with commercialization base…
seonghobae dbefe8c
docs(doctoring): trace commercialization and governance sources
seonghobae 7f2ebf7
docs(gaps): refresh live governance evidence
seonghobae f461787
docs: align commercialization governance contract
seonghobae a76df82
docs(commercialization): track owner-plane governance repair
seonghobae 8304d8d
docs(commercialization): track explicit assignment authority gap
seonghobae be380fc
docs(research): refresh accessibility and control standards
seonghobae 559ee68
test: pin LLM routing and semantic ownership guidance
seonghobae e129d72
docs: route model-backed Actions through contextual-orchestrator
seonghobae 57def8e
docs: align semantic and orchestration ownership boundaries
seonghobae 2f01935
chore: reseal foundation manifest for guidance repair
seonghobae d6f299b
test: run LLM routing policy regression in foundation validation
seonghobae e3ed61b
chore: reseal manifest for routing regression registration
seonghobae 2ca0e6a
docs(gaps): refresh governance and security owner truth
seonghobae 2f888ec
merge(develop): adopt protected CI admission fix in baseline writer
seonghobae 465abcb
docs(gaps): add assignment correction provenance gap
seonghobae 8caea75
merge(develop): adopt restored documentation contract checks
seonghobae 56887f6
docs(gaps): align protected workflow and correction time truth
seonghobae c976ab4
docs: record canonical People runtime prerequisites
seonghobae 55de0cf
docs: add canonical runner prerequisite to commercialization order
seonghobae 5e03ac2
docs: track authorization input integrity
seonghobae a79f082
docs(product): record authorization constructor provenance gap
seonghobae 2bd4810
docs(baseline): correct authorization trust boundary
seonghobae e373489
docs: align AUTH-01 with Job Analysis runtime evidence
seonghobae c0a40a4
docs: doctor commercialization baseline after workflow integration
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,141 @@ | ||
| # Product and technical gap baseline | ||
|
|
||
| Inventory date: 2026-08-25 (Asia/Seoul). Default `develop` head observed: `9e3e4847510e1e612b48474ba42b177b8ed824df`. | ||
|
|
||
| This document is a point-in-time buyer/product planning snapshot. It is **not** merge authorization, branch-protection truth, or a substitute for fresh GitHub state. Every execution loop must refetch open PRs/issues, exact heads and bases, dependency ancestry, reviews/threads, exact-head workflows, effective repository rules, releases, and changed refs before acting. | ||
|
|
||
| Orgmetra owns authoritative HRIS employment truth inside its published boundaries. Keyverse and other dedicated-writer CWL repositories remain read-only dependencies consumed only through published package/API/event contracts and existing owner-control paths. No static product-gap document may authorize a write into another dedicated-writer repository. | ||
|
|
||
| ## Repository-control truth | ||
|
|
||
| GitHub currently reports `develop` as `protected: true`, but the effective branch-protection payload observed for the same branch has `protection.enabled=false`, required-status enforcement `off`, and no required contexts/checks. Issue #89 owns that repository-settings defect. | ||
|
|
||
| Consequences: | ||
|
|
||
| - a GREEN PR is not merge-authorized merely because GitHub computes it as mergeable; | ||
| - qualifying independent non-author approval is still required where the repository governance contract requires it; | ||
| - no workflow shim, author approval, predecessor check, model-only status, or manual force merge substitutes for enforceable branch protection; | ||
| - immediately before any future merge, refetch the unchanged exact head, independently resolved live base, reviews, unresolved threads, effective rules/protection, and every applicable exact-head check. | ||
|
|
||
| ## Merged buyer-visible anchors on `develop` | ||
|
|
||
| This is a selected shipped inventory, not a replacement for Git history. | ||
|
|
||
| | Merged PR | Capability | | ||
| |---|---| | ||
| | #26 | `validity_study_case_record` integrity | | ||
| | #28 | Performance-criterion Job-scope guard | | ||
| | #31 | Governed People mutation API | | ||
| | #38 | Governed Job Analysis snapshot persistence/read | | ||
| | #41 | Governed candidate evidence intake | | ||
| | #43 | Governed offer approval packet | | ||
|
seonghobae marked this conversation as resolved.
Outdated
|
||
|
|
||
| Do not revive these merged heads. Extend default-branch truth only through a current owner-scoped change when a fresh buyer gap remains. | ||
|
|
||
| ## Live open-PR control snapshot | ||
|
|
||
| The repository currently has 70 open PRs (verified 2026-08-25). The examples below are anchors only; execution order comes from a fresh oldest/dependency-root-first graph. | ||
|
seonghobae marked this conversation as resolved.
Outdated
|
||
|
|
||
| ### Oldest root gate | ||
|
|
||
| PR #40 (`8d8896b14db10a5a4981f0b9e209ea00ee3be64c`) is open, non-draft and mergeable. Structured Interview Plan, Foundation, SAST, Security, and Recovery are terminal GREEN on that exact head. Fresh reviews are COMMENTED only and the remaining unresolved threads are informational. It still has no qualifying independent non-author `APPROVE`, and issue #89's protection defect remains open, so it is intentionally unmerged. | ||
|
|
||
| ### Dependency-constrained Draft descendants | ||
|
|
||
| These descendants remain Draft. Lane-local GREEN evidence is not integrated protected-base evidence and parent checks/reviews do not transfer. | ||
|
|
||
| | PR | Exact child head | Dependency | | ||
| |---|---|---| | ||
| | #58 | `c79a6ed49627e6a47947f171aeeed2bf02a8c152` | #57 | | ||
| | #67 | `cf59b3001fa58e5a978099c2a5692a03f4849fdd` | #66 | | ||
| | #77 | `9b02cb911377a5beb9f541e9acf2eb51ff065ee9` | #76 | | ||
| | #82 | `0c3a776f2e2c6f93c25e11c5c3ce3fa66a10b5c9` | #51 | | ||
| | #105 | `168f19402b3b17762cfe60f8a0e93c649a082989` | #104 | | ||
| | #106 | `c35ad114edbce7a4ebafcea793748493f1346351` | #94 | | ||
| | #107 | `5e521fd829de313a037f45ac28227c2ae5362d37` | #98 | | ||
| | #108 | `5027c772e5588b33e953258de008f0253389e95c` | #80 | | ||
| | #109 | `1eb17d1dbfa2ec822a9c6cce52d8a92b19ed9353` | #101 | | ||
| | #112 | `4f2a003769bf8f773559ac8122702f1451f0e8c0` | #111 | | ||
|
|
||
| Do not restack these descendants merely to manufacture fresh evidence while their parents remain unintegrated. After a parent integrates, retarget/reconcile the child against the then-current `develop`, refetch the resulting exact head/base/conflict state, and rerun all applicable Foundation/SAST/Security/Recovery/product gates without transferring predecessor evidence. | ||
|
|
||
| ### Selected current root capabilities | ||
|
|
||
| The following are current open-root anchors with terminal exact-head GREEN evidence and are useful for product-gap reasoning. They remain unmerged pending live governance gates. | ||
|
|
||
| | PR | Exact head | Capability | | ||
| |---|---|---| | ||
| | #53 | `43ae3c73c0abef8f23d1c14f4e41d25b8c9b14df` | Evidence-centered HR workspace / Storybook slice | | ||
| | #75 | `282ff0966add47a80a2edd76f84c4c65a868fedb` | Governed HR data-export review | | ||
| | #80 | `5070f34cd13814f09d74162347f837cb34d76a57` | Candidate offer-response evidence | | ||
| | #81 | `78a9cb1e047db5c79ca855b992d44749b9214992` | Contextual Orchestrator draft-evidence boundary | | ||
| | #98 | `9aeeb204acce429f85b028029c9531a5b05f37e1` | Governed HR document evidence | | ||
| | #99 | `fff082f56e34e47cb83a19316d132c5638d3b633` | Employment-scoped bitemporal base compensation | | ||
| | #101 | `13c4cf8ee7e91ffa0ac1a33fdc9461e4c31d5fb2` | Governed Job-grade design review | | ||
| | #102 | `d87cb05f723f106c653f2ea07680872fd9c62ada` | Purpose-bound audit-evidence review | | ||
| | #104 | `d92ac4cb798b3bd32b632c0ab677c03f944070e4` | Governed Job qualification-rule review | | ||
| | #110 | `bc84eaa145166a3f77a57f0c94c6d7459cfc65f3` | Vacancy-to-Assignment fill orchestration | | ||
| | #111 | `cfff42f5cf884ff67169ddeff645c6933e19337a` | Governed Position lifecycle-change review | | ||
|
|
||
| This table intentionally does not assert that every root is merge-authorized. Fresh review and effective-rule state remain authoritative. | ||
|
|
||
| ## Buyer-visible progress since the previous snapshot | ||
|
|
||
| Several items that were previously listed as unresolved product gaps now have active owner lanes and must no longer be described as absent: | ||
|
|
||
| 1. **Job grade/band governance:** #101 provides reviewed Job-grade design evidence; #109 is the dependency-first bitemporal persistence descendant. | ||
| 2. **Offer-to-hire close:** #80 owns candidate offer-response evidence; #108 is the dependency-first bridge to the authoritative confirmed-hire boundary. | ||
| 3. **Vacancy-to-Assignment fill:** #110 owns the current orchestration slice and delegates final persistence to the authoritative People mutation boundary. | ||
| 4. **Position lifecycle:** #111 owns human-reviewed lifecycle-change evidence; #112 is the dependency-first authoritative application descendant. | ||
| 5. **HR document evidence:** #98 owns the value-minimized evidence packet; #107 is the dependency-first immutable persistence descendant. | ||
|
|
||
| These are active-PR capabilities, **not protected-main truth** until integrated. | ||
|
|
||
| ## Highest-value buyer gaps after the current queue | ||
|
|
||
| Do not open withholding, payroll-pay, statutory accounting, year-end settlement, or foreign-service application tables inside Orgmetra without an accepted owner contract. | ||
|
|
||
| 1. **Purpose-bound HR document retrieval/export execution.** #75 reviews export intent and #98/#107 govern document evidence/persistence, but a customer still needs an authorized document read/egress execution boundary that re-resolves tenant/Person/Employment scope, purpose, permitted fields/artifact, retention/legal-hold state, delivery destination, human approval, and immutable audit before bytes leave the owner boundary. | ||
| 2. **Authoritative Employment leave/absence truth.** #47 provides a governed leave review packet, but protected `develop` still lacks a normalized bitemporal leave/absence application/persistence boundary that preserves Employment scope, business time, system-recorded time, human review, correction-not-rewrite history, tenant isolation, and audit/outbox evidence without turning policy review into payroll or scheduling authority. | ||
| 3. **Job-Analysis-specific model-assisted draft workflow.** #81 provides the generic Contextual Orchestrator draft-evidence contract; a later Job Analysis slice should bind semantic-unit Task/FJA/KSAO draft provenance to an exact Job Analysis snapshot workflow and require explicit human confirmation before authoritative persistence. Model output remains untrusted draft evidence. | ||
| 4. **Accessible buyer interaction for the newer HRIS cores.** Job-grade, document, Position lifecycle/reporting, and qualification-rule capabilities need cohesive Figma/Product Design handoff, Storybook coverage, keyboard/focus/ARIA evidence, and customer-facing next-action copy when UI work is material. #53 is a useful existing workspace anchor rather than permission to invent protected-main API behavior. | ||
| 5. **Integrated release readiness.** Source SBOM/provenance, probes, telemetry and Kubernetes reference lanes exist, but no release/version/tag should be created until one exact integrated protected head satisfies applicable build/package/SBOM/provenance/reproducibility/compatibility/review/migration/rollback/recovery/accessibility/operational gates together and source/artifact hashes are reverified. | ||
|
|
||
| External finance/accounting and billing/collection integration remains planned/out-of-scope until an owner publishes a contract accepted into Orgmetra architecture/traceability. Orgmetra must not create statutory-account truth or direct cross-service application-table SQL as a shortcut. | ||
|
|
||
| ## Technical non-negotiables | ||
|
|
||
| - Exact 100% owned production statement/branch coverage where tooling exposes it, plus beginner-readable public docs/docstrings and realistic security/privacy/concurrency/migration/recovery/accessibility cases. | ||
| - Descriptive two-or-more-word `snake_case` database objects and 3NF by default. | ||
| - Job, Position, Assignment, Employment, Organization, and Person remain distinct authoritative concepts. | ||
| - Business/effective time and system-recorded time remain separate; correction is correction-not-rewrite. | ||
| - Tenant/context isolation, opaque public correlation, least privilege, field minimization, encryption/retention/export controls, and immutable audit/outbox remain mandatory. | ||
|
seonghobae marked this conversation as resolved.
Outdated
|
||
| - Necessary PII remains usable only through purpose-bound authorization; indiscriminate masking is not a substitute for access control. | ||
| - High-impact employment decisions require accountable human confirmation with actor/purpose/reason/evidence versioning. LLM output remains untrusted draft evidence only. | ||
| - Preserve modular MSA extraction boundaries; do not introduce direct cross-service application-table SQL. | ||
| - Design toward CSAP and SOC 2 evidence readiness without claiming certification. | ||
| - Queued, pending, cancelled, skipped-required, neutral, absent, stale, predecessor, status-only, or model-only evidence is non-passing. | ||
|
|
||
| ## Execution loop | ||
|
|
||
| Each run: refetch `develop`, all open PRs/issues and exact heads/bases, dependency ancestry, reviews/threads, exact-head workflows, releases and effective rules; process oldest/dependency-root first; repair verified Orgmetra defects at the owning boundary test-first when practicable; rerun exact-head evidence; resolve only addressed threads; and merge only with qualifying independent non-author approval plus actually enforceable protection. Refresh this document only after material state changes and never use its recorded SHAs as current control-plane truth. | ||
|
|
||
| ## 2026-08-24/25 automation findings (operator diagnostics) | ||
|
|
||
| 1. **Strix failures were infrastructure, not source defects.** Repeated `strix` failures traced to NVIDIA NIM `429 Too Many Requests` during scanner LLM connection (three primary attempts plus fallback exhausted, no report artifact, fail-closed). Local exact-head verification reproduced all owned package suites green at 100% statement/branch coverage; the scan lane, not the code, was failing. Remediation: staggered same-head re-scan dispatch (`repository_dispatch strix-scan`) instead of concurrent bursts. | ||
| 2. **Org review-dispatch budget was zero.** `ORG_SWEEP_REVIEW_DISPATCH_LIMIT` was `0`, so the org queue sweep could never dispatch an OpenCode review anywhere. Restored to `2` with `ORG_SWEEP_BRANCH_UPDATE_LIMIT=1`; `ContextualWisdomLab/Orgmetra` added to the central targeted-dispatch allowlist. Diagnose future zero-review stalls against this variable first. | ||
| 3. **Strix gate semantics after a completed scan.** A real reported vulnerability fails the required check by design. PR #52's first completed scan surfaced one legitimate MEDIUM IDOR-shaped finding (cross-field reference validation missing in `TeppAnalysisRequestPacket`); repaired at head `e068df7` with temporal ordering, distinct workspace/snapshot identifiers, and a scope digest binding every retry-stable correlation. Scanner finding -> test-first root repair -> fresh full-head evidence is the intended loop. | ||
| 4. **Shared-credential saturation is the remaining systemic constraint.** The OpenCode GitHub App installation token hits GitHub API rate limits mid-sweep before reaching later repositories, and NVIDIA NIM 429s arrive org-wide because one key is shared. Both are transient retryable infra states, never source defects; a scan can complete with zero vulnerabilities yet fail closed on one transient backend signal in its console output. | ||
| 5. **2026-08-25 second Strix failure mode: OpenCode app-token exchange outage (distinct from NIM 429).** Twelve PR heads (#80, #85, #95, #97, #98, #99, #102, #103, #104, #110, #111, #113) showed terminal `strix=FAILURE` where the job log shows `curl: (22) ... error: 500` against `https://api.opencode.ai` followed by "OpenCode app token exchange unavailable: app token request did not complete." six times, then the fail-closed provider-unavailable error; the scanner never produced findings, so no source defect is implied. Remediation applied: provider health re-verified (`/health` → 200) and each failed run re-executed on its identical head via the authenticated REST endpoint `POST /repos/{owner}/{repo}/actions/runs/{id}/rerun` (`--failed` rerun), preserving exact-head semantics without transferring predecessor evidence. | ||
|
seonghobae marked this conversation as resolved.
Outdated
|
||
| 6. **Hourly review-repair heartbeat survived a transient GitHub read failure.** Run 32805870622 failed once inside `fetch_open_prs` when `gh api graphql` returned non-JSON text ("invalid character ' ' in literal false"), an upstream/API hiccup the scheduler script does not yet retry; the next heartbeat succeeded. Candidate hardening at the owning central boundary: bounded retry/backoff around `run_github_read` for non-deterministic CLI failures. | ||
| 7. **Review pipeline state at this snapshot:** the only qualifying review submission found was `opencode-agent CHANGES_REQUESTED` on PR #54 (coverage-evidence blocker on head `cc6784ec…`, workflow run 32790319079); Devin/CodeRabbit/github-code-quality comments do not satisfy approval gates. All other open PRs await current-head dispatch through the restored org sweep budget (finding 2). Nothing here authorizes a merge while issue #89's effective-protection defect remains open. | ||
|
|
||
| ## Doctoring (APA 7th) | ||
|
seonghobae marked this conversation as resolved.
Outdated
|
||
|
|
||
| American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). *Standards for educational and psychological testing*. | ||
|
|
||
| Equal Employment Opportunity Commission. (1978). *Uniform guidelines on employee selection procedures* (29 C.F.R. Part 1607). | ||
|
|
||
| International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management — Requirements and recommendations for human capital reporting and disclosure*. ISO. | ||
|
|
||
| Society for Industrial and Organizational Psychology. (2018). *Principles for the validation and use of personnel selection procedures* (5th ed.). | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.