docs(policy-approval): classify protected procedural CAS authority - #602
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
left a comment
There was a problem hiding this comment.
Current-head review on a67b6864604962458169d79da1e5f697e19e846e: the hosted documentation RED from 3ff1d841... is causally repaired without weakening the regression. OPERABILITY, TRACEABILITY, and the product/technical gap baseline now classify protected #601 as a distinct Noema Policy / Approval CAS authority, preserve #597 State / Checkpoint ownership, retain activationAuthorized:false, and keep release/live signer trust/non-workflow lifecycle/deployed compatibility/publication/canary/outcome as separate later authorities. The accidental historical-SHA transcription drift introduced during the repair was restored before this review. I found no additional valid source/DDD/documentation finding in the current 10-file delta. This COMMENT is not approval; merge authority still requires a fresh terminal-success gate generation for this exact head.
Purpose
Post-merge docs-to-code repair after protected #601. The protected source now contains a Noema-owned Policy / Approval CAS ledger, while the canonical procedural documentation must distinguish that source authority from publication, activation, release, deployment and product-outcome authority.
Reality RED
Test-first exact
a06a2df2b798e8d7c833a28ff0687d9550454536required the canonical procedural documents to classify #601 as protected Policy / Approval source, preserve monotonic approval-version CAS and explicit revocation semantics, keepactivationAuthorized:false, and stop claiming that an independently approved promotion/revocation API was absent.A later candidate exact
3ff1d8413662a5a9df690ad17026f1060b916a60produced a second hosted reality RED in application CI run34515397969, job102999485370: exact checkout, live-base guard, install and typecheck passed, then release tests failed becausetest/documentation-current-trust-authority.test.tsrequired#601indocs/OPERABILITY.md,docs/TRACEABILITY.md, anddocs/product-technical-gap-baseline.md, but those canonical documents had not been converged.Causal repair
812f6129411f9385b63bb50c6f6e14416ac918dbclassifies feat(state-checkpoint): persist durable procedural evaluation history #597 State / Checkpoint history and feat(policy-approval): bind procedural promotion with CAS #601 Policy / Approval CAS in operability/recovery/retention while preserving no publication/activation authority.f3fbe9e76943ab44dd617f76848617145866749bconverges TRACEABILITY to the protected feat(policy-approval): bind procedural promotion with CAS #601 source, separates Noema Policy / Approval from Keyverse/foreign-owner authorities, and requires fresh publication-time cross-authority reconciliation.13a46fcdb85f93f907c541845878761480bd1573converges the commercial gap baseline to protected feat(policy-approval): bind procedural promotion with CAS #601 and moves the buyer gap beyond source-level Policy / Approval CAS.a67b6864604962458169d79da1e5f697e19e846erepairs an accidental historical-SHA transcription drift introduced while editing the baseline; historical provenance is byte-for-byte restored rather than silently rewritten.Predecessor GREEN is not merge authority for the current exact head. The current head must obtain a fresh complete gate generation.
Boundary
This remains source-classification repair only. ADR-0017 stays
Proposed. Every procedural candidate/history/approval event remainsactivationAuthorized:false. The change does not imply releasedcontext-graph-contracts, live Keyverse/owner signer trust, non-workflow lifecycle freshness, deployed Durable Object compatibility/p95/recovery, graph publication, canary/rollback, immutable release/deployment, or product outcome. It does not import Keyverse key custody, provider routing, foreign domain truth, or a second Workflow / Task or lifecycle store.Related: #584, #601.