Skip to content

docs: make README product-first and integrator-friendly - #160

Open
seonghobae wants to merge 13 commits into
developfrom
docs/readme-product-refresh-20260901
Open

docs: make README product-first and integrator-friendly#160
seonghobae wants to merge 13 commits into
developfrom
docs/readme-product-refresh-20260901

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Outcome

Refresh Orgmetra's protected-develop landing page around its code-current HRIS/HCM responsibility instead of mixing the product story with stale active-PR state.

  • lead with evidence-centered HRIS/HCM value and buyer-visible jobs;
  • keep Person / Employment / Organization / Job / Position / Assignment distinctions explicit;
  • provide a copy-paste validation path aligned with Foundation CI (Node 24 / Python 3.14, npm ci, npm run validate);
  • explain federated integration ownership without presenting planned boundaries as shipped behavior;
  • make protected-branch versus active-PR authority explicit;
  • provide a navigable documentation map and the existing Apache-2.0 / NOTICE boundary.

Evidence and licensing

The README is grounded in docs/PRD.md, ARCHITECTURE.md, docs/TRACEABILITY.md, package metadata, repository workflows, and the existing root LICENSE/NOTICE. The Apache-2.0 grant applies to Orgmetra-owned source; third-party packages and external systems retain their own terms. No certification, production deployment, employment-decision authority, or customer claim is invented.

Repair chain

Fresh hosted validation first proved that the README manifest record was stale; the branch resealed it from the exact README bytes instead of weakening repository integrity. Fresh review then found an unsealed docs/index.md public landing candidate outside the validator's closed required-artifact set. That candidate was removed rather than widening the public surface without a publication/integrity contract, leaving the governed root README as the landing source.

Current README maturity labels distinguish protected-main implementation, accepted architecture, and planned/active-PR boundaries, including separate Psychometrics Commons versus fast-mlsirm responsibilities. Validation scope is explicit so npm run validate is not represented as complete PostgreSQL/package verification.

The README also separates Orgmetra-local controls/trust-boundary documentation from vulnerability disclosure. Suspected vulnerabilities are directed to the organization-owned ContextualWisdomLab/.github@main:SECURITY.md reporting policy. No claim is made that repository-private vulnerability reporting is enabled unless live repository evidence establishes it.

The current manifest seal matches the exact README bytes after that reporting repair (sha256=10f4ad947efee5e54166cd31e18cf30d34489b7c13fd05cb565363c1a86271c5, 9,344 bytes, 141 lines). All currently returned inline review threads are resolved.

Exact-head authority — 2026-09-02

  • protected base recorded by GitHub: develop@9e3e4847510e1e612b48474ba42b177b8ed824df;
  • exact current head: a7d9e1aa0fb6e007e3b0cb8f495f4d4dc512e9e8;
  • GitHub reports the PR open, non-Draft and mechanically mergeable;
  • exact-head Foundation CI 33586731896, Recovery Rehearsal Quality 33586731888, and Job-Analysis API Quality 33586731749 are terminal-success;
  • exact-head Security Scan 33586731818 is terminal-failure only at dependency-review job 100112343570: exact checkout succeeded, the support probe failed, and the pinned Dependency Review action was skipped; sibling Trivy, OSV, and Scorecard jobs are terminal-success;
  • exact-head SAST Semgrep 33586731773 remains queued and therefore non-passing;
  • the Dependency Review failure is the shared central availability/authorization incident owned by ContextualWisdomLab/.github#810, not an Orgmetra README/runtime defect;
  • every predecessor-head run/review is historical after the final README/manifest repair.

Scope

Current diff is exactly README.md and manifest.json. No runtime, dependency, schema, API, workflow, release, certification, employment-decision, UI, or ecosystem-ownership behavior is changed.

Merge boundary

Do not merge or enable auto-merge until this unchanged exact head has terminal applicable repository/security/recovery checks, current review/thread evidence, fresh base ancestry/mergeability, and then-live protected-branch rules. No self-approval, routine administrator bypass, force-push, no-op retrigger churn, or predecessor-evidence transfer is requested.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: e867d905-b812-4d16-8fcd-03056e0293a2

📥 Commits

Reviewing files that changed from the base of the PR and between cdfbbf1 and d5f95be.

📒 Files selected for processing (1)
  • manifest.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • manifest.json

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

README가 증거 중심 HRIS/HCM 제품 범위, bounded context, 아키텍처 경계, 검증 절차, PII 보호 계약, 현재 상태, 문서 맵, 기여 지침 및 라이선스를 설명하도록 확장되었습니다. manifest.json의 README 메타데이터도 갱신되었습니다.

Changes

README 제품 및 저장소 기준

Layer / File(s) Summary
제품 범위와 핵심 컨텍스트
README.md
제품 설명이 증거 중심 HRIS/HCM 범위로 확장되었습니다. 핵심 bounded context와 저장소 검증 절차가 정리되었습니다.
아키텍처와 보안 계약
README.md
연합형 아키텍처, API·이벤트·패키지·어댑터 경계, 외부 제품 책임 및 PII 보호 규칙이 추가되었습니다.
검증과 저장소 운영 기준
README.md, manifest.json
현재 제공 범위, 문서 맵, 기여·결함·보안 보고, 라이선스 정보 및 README 매니페스트 메타데이터가 갱신되었습니다.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to d5f95

This PR updates documentation and its integrity record without changing runtime, dependency, schema, API, workflow, release, permission, or product behavior; no actionable merge-blocking risk remains beyond normal checks and review.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 README를 제품 중심 및 통합자 친화적으로 개편한 주요 변경 사항을 정확하고 간결하게 설명합니다.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/readme-product-refresh-20260901

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae seonghobae added documentation Improvements or additions to documentation priority: medium status: needs-review labels Sep 1, 2026 — with ChatGPT Codex Connector
devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant