Skip to content

docs: make README product-first and integrator-friendly - #160

Draft
seonghobae wants to merge 13 commits into
developfrom
docs/readme-product-refresh-20260901
Draft

docs: make README product-first and integrator-friendly#160
seonghobae wants to merge 13 commits into
developfrom
docs/readme-product-refresh-20260901

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Outcome

Refresh Orgmetra's protected-develop landing page around its code-current HRIS/HCM responsibility instead of mixing the product story with stale active-PR state.

  • lead with evidence-centered HRIS/HCM value and buyer-visible jobs;
  • keep Person / Employment / Organization / Job / Position / Assignment distinctions explicit;
  • provide a copy-paste validation path aligned with Foundation CI (Node 24 / Python 3.14, npm ci, npm run validate);
  • explain federated integration ownership without presenting planned boundaries as shipped behavior;
  • make protected-branch versus active-PR authority explicit;
  • provide a navigable documentation map and the existing Apache-2.0 / NOTICE boundary.

Evidence and licensing

The README is grounded in docs/PRD.md, ARCHITECTURE.md, docs/TRACEABILITY.md, package metadata, repository workflows, and the existing root LICENSE/NOTICE. The Apache-2.0 grant applies to Orgmetra-owned source; third-party packages and external systems retain their own terms. No certification, production deployment, employment-decision authority, or customer claim is invented.

Repair chain

Fresh hosted validation first proved that the README manifest record was stale; the branch resealed it from the exact README bytes instead of weakening repository integrity. Fresh review then found an unsealed docs/index.md public landing candidate outside the validator's closed required-artifact set. That candidate was removed rather than widening the public surface without a publication/integrity contract, leaving the governed root README as the landing source.

Current README maturity labels distinguish protected-main implementation, accepted architecture, and planned/active-PR boundaries, including separate Psychometrics Commons versus fast-mlsirm responsibilities. Validation scope is explicit so npm run validate is not represented as complete PostgreSQL/package verification.

The README also separates Orgmetra-local controls/trust-boundary documentation from vulnerability disclosure. Suspected vulnerabilities are directed to the organization-owned ContextualWisdomLab/.github@main:SECURITY.md reporting policy. No claim is made that repository-private vulnerability reporting is enabled unless live repository evidence establishes it.

The feature snapshot's manifest seal matches its README bytes after that reporting repair (sha256=10f4ad947efee5e54166cd31e18cf30d34489b7c13fd05cb565363c1a86271c5, 9,344 bytes, 141 lines). That seal is historical source evidence only and must be regenerated after protected-parent reconciliation.

Live authority and lifecycle repair

  • exact feature head: a7d9e1aa0fb6e007e3b0cb8f495f4d4dc512e9e8;
  • PR recorded base snapshot: develop@9e3e4847510e1e612b48474ba42b177b8ed824df;
  • current protected truth: develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f;
  • live state: open · Draft · currently non-mergeable after GitHub recomputation.

The earlier non-Draft/mergeable wording is superseded. Protected develop has advanced through #161 repository-quality workflow consolidation, so this README/manifest lane must reconcile that protected truth rather than overwrite it with either historical tree. A conflict or non-mergeable result is a repair finding, not a close condition.

Historical exact-source evidence on a7d9e1a... remains non-transferable: Foundation CI 33586731896, Recovery Rehearsal 33586731888, and Job-Analysis API Quality 33586731749 were terminal-success; Security Scan 33586731818 failed at Dependency Review support; SAST 33586731773 was non-terminal at the recorded snapshot. Those results cannot authorize a reconciled head.

Required non-force reconciliation

Preserve the valid product-first README content, non-force adopt the then-current protected develop, and resolve README/provenance conflicts semantically. Do not resurrect workflows removed by #161. After the final README bytes are chosen, regenerate manifest.json from those exact bytes rather than selecting either stale manifest wholesale. Then reacquire every applicable exact-head Foundation/recovery/Security/SAST/CodeQL/review gate before Ready.

Current diff intent remains README plus deterministic manifest only; no runtime, dependency, schema, API, workflow, release, certification, employment-decision, UI, or ecosystem-ownership behavior is claimed by this lane.

Do not force-rebase, self-approve, use routine administrator bypass, enable auto-merge on stale evidence, add no-op retrigger churn, transfer predecessor evidence, or treat temporary mergeability as authorization.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: e867d905-b812-4d16-8fcd-03056e0293a2

📥 Commits

Reviewing files that changed from the base of the PR and between cdfbbf1 and d5f95be.

📒 Files selected for processing (1)
  • manifest.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • manifest.json

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

README가 증거 중심 HRIS/HCM 제품 범위, bounded context, 아키텍처 경계, 검증 절차, PII 보호 계약, 현재 상태, 문서 맵, 기여 지침 및 라이선스를 설명하도록 확장되었습니다. manifest.json의 README 메타데이터도 갱신되었습니다.

Changes

README 제품 및 저장소 기준

Layer / File(s) Summary
제품 범위와 핵심 컨텍스트
README.md
제품 설명이 증거 중심 HRIS/HCM 범위로 확장되었습니다. 핵심 bounded context와 저장소 검증 절차가 정리되었습니다.
아키텍처와 보안 계약
README.md
연합형 아키텍처, API·이벤트·패키지·어댑터 경계, 외부 제품 책임 및 PII 보호 규칙이 추가되었습니다.
검증과 저장소 운영 기준
README.md, manifest.json
현재 제공 범위, 문서 맵, 기여·결함·보안 보고, 라이선스 정보 및 README 매니페스트 메타데이터가 갱신되었습니다.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to d5f95

This PR updates documentation and its integrity record without changing runtime, dependency, schema, API, workflow, release, permission, or product behavior; no actionable merge-blocking risk remains beyond normal checks and review.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 README를 제품 중심 및 통합자 친화적으로 개편한 PR의 주요 변경 사항을 정확하고 간결하게 설명합니다.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/readme-product-refresh-20260901

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae seonghobae added documentation Improvements or additions to documentation priority: medium status: needs-review labels Sep 1, 2026 — with ChatGPT Codex Connector
devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae
seonghobae marked this pull request as draft September 5, 2026 21:02

Copy link
Copy Markdown
Contributor Author

Lifecycle repair — live state is now Draft and supersedes the stale non-Draft/old-base authority in the body. Current protected truth is develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f; this README/manifest feature remains exact a7d9e1aa0fb6e007e3b0cb8f495f4d4dc512e9e8 on recorded base 9e3e4847510e1e612b48474ba42b177b8ed824df, and GitHub now reports it non-mergeable after recomputation. Preserve the valid product-first README delta, non-force adopt the then-current protected tree (including #161 repository-quality consolidation), resolve the manifest/content conflict semantically, reseal manifest.json from the final exact bytes, then reacquire every applicable exact-head gate/review before Ready. Do not choose either stale manifest wholesale, force-rebase, admin-bypass, or churn a no-op commit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant