Skip to content

feat(separation): add authoritative human approval boundary - #129

Draft
seonghobae wants to merge 16 commits into
feat/governed-employment-separation-reviewfrom
feat/employment-separation-approval
Draft

feat(separation): add authoritative human approval boundary#129
seonghobae wants to merge 16 commits into
feat/governed-employment-separation-reviewfrom
feat/employment-separation-approval

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Buyer-visible gap

Parent PR #46 creates value-minimized, human-review-required Employment separation evidence but deliberately cannot authorize mutation or downstream execution. This dependency-first Orgmetra-only lane adds the missing accountable human-approval boundary before any later authoritative Employment/Assignment mutation or foreign-owner handoff.

Implemented approval boundary

approve_employment_separation(...) accepts only the exact governed parent packet runtime type, freezes the approval instant to built-in UTC evidence, requires the accountable reviewer as approving actor, snapshots the exact parent canonical bytes/SHA-256 around authority work, validates exact tenant/review/Person/Employment/reviewer/approval-instant authority evidence, and issues only a value-minimized receipt fixed to human_approved_for_authoritative_resolution, not_authorized_to_apply, and not_authorized_to_execute.

The receipt uses process-local HMAC-backed issuance evidence outside receipt-writable slots and is defense-in-depth only. Durable systems must persist already-issued canonical evidence through immutable audit/outbox and freshly authorize consequential mutation/external action.

Current exact stack state

  • exact child head: 4c377a35055e126a5e2435ec36bd9ac1e593456e
  • GitHub base ref: feat/governed-employment-separation-review
  • recorded GitHub base SHA: 96fe0b69e8e1bc3caa0fa206146a87c6e5027746
  • current parent feat: add governed employment separation review packet #46 exact head: 15d534fc8e36d3455523cf5d8e22e77010fc9d4b
  • current parent live base: develop@9e3e4847510e1e612b48474ba42b177b8ed824df
  • state: open · Draft · mergeable=false

The child is therefore currently based on a predecessor snapshot of parent #46 and is stale relative to the parent's live head. The earlier PR prose claiming this child had already been adapted to the current parent was incorrect. Do not restack or churn this Draft child merely to manufacture descendant evidence while #46 remains unintegrated; process the parent dependency-first. After #46 actually integrates, retarget/rebase this existing child branch onto the then-current protected develop and revalidate the resulting exact child head from scratch. Predecessor parent/child checks and reviews remain non-transferable.

Exact-current-child evidence

A fresh exact-head check inventory contains exactly one check run on 4c377a35055e126a5e2435ec36bd9ac1e593456e: Employment Separation Review Quality run 33166590078, job/check 98833356045, terminal SUCCESS. Its fresh job log proves exact checkout of this child head, compile success, 137 tests passed, owned production 388/388 statements and 86/86 branches (100.00%), and a clean-checkout gate.

That one stack-local focused workflow is the entire exact-child-head check inventory. Required OpenCode/Noema/Strix/SAST/Security/central coverage evidence is absent on this exact child head and therefore non-passing. There are no qualifying independent current-head non-author approvals; predecessor or parent evidence may not be transferred.

Parent dependency remains blocking

Parent #46 is still open · Draft · mergeable at exact head 15d534fc8e36d3455523cf5d8e22e77010fc9d4b against develop@9e3e4847510e1e612b48474ba42b177b8ed824df.

Its current exact-head Orgmetra-owned evidence is substantially healthier than the predecessor snapshot previously recorded here: Employment Separation Review Quality is terminal GREEN with 110 tests passed and 207/207 statements plus 54/54 branches (100.00%); Foundation, Recovery, and SAST are also GREEN. The remaining current blockers are central/independent-evidence boundaries rather than missing local package proof:

  • Security Dependency Review remains terminal failure because the exact public-repository dependency-graph comparison returns HTTP 403 before the pinned action can execute; existing owner handoff: ContextualWisdomLab/.github#810.
  • Required OpenCode has no authenticated exact-head formal APPROVED or CHANGES_REQUESTED verdict; existing owner handoff: ContextualWisdomLab/.github#624.
  • Required Noema fails before an actual review/verdict when the shared contextual-orchestrator sidecar exits before /healthz; existing owner handoff: ContextualWisdomLab/.github#1399.
  • Required Strix run 33278974477 is terminal CANCELLED with 0 materialized jobs; a supported unchanged-head rerun-failed-jobs attempt returns HTTP 403 This workflow run cannot be retried, so no authoritative scanner verdict exists; existing owner handoff: ContextualWisdomLab/.github#1327.
  • Parent feat: add governed employment separation review packet #46 still lacks a qualifying independent current-head non-author approval.

Consequently the child's focused GREEN result does not cure or replace the parent evidence gap, and parent checks/reviews may not be transferred to this child.

Stack governance

Keep this child Draft while #46 is unmerged. Process #46 dependency-first. Only after #46 actually integrates may this child be retargeted/revalidated against the then-current protected develop; every applicable local and central gate must then be rerun on that resulting exact child head.

Do not self-approve, use routine administrator bypass, weaken a gate, create no-op evidence churn, race another lifecycle writer, or treat queued/cancelled/absent/predecessor/status-only/model-only evidence as passing.

Scope / non-claims

This slice establishes a governed human-approval receipt only. It does not itself mutate Employment/Assignment state, execute separation, persist foreign-owner payloads, bypass authoritative tenant/identity resolution, or claim deployed production integration, certification, legal-compliance determination, or commercial release.

@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant