Align the HawkinsOperations organization front door with the Reviewer Guide - #59
Align the HawkinsOperations organization front door with the Reviewer Guide#59raylee-hawkins wants to merge 101 commits into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3b6df21575
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d379b54685
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7c3097ba0d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6e9d874156
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 72430ad756
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 87f75bc359
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 700f486d6c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c64b0a6d81
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b1db9e6200
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review current head |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 74da326acf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 84648e54ab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9cd90e9f48
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0c5d1a5c6c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 22115c86f9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 821f7fa82c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ae0811d491
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c680b943d0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| html_heading_source, | ||
| re.IGNORECASE | re.DOTALL, | ||
| ): | ||
| rendered_heading = re.sub(r"<[^>]+>", "", html_heading.group(1)) |
There was a problem hiding this comment.
Parse nested tags in rendered authority headings
Fresh evidence after the quoted-heading fix is that only the outer <h2> tag is quote-aware; this substitution still truncates a nested inline tag at a > inside its quoted attribute. Appending <h2>Seven-Repository <span title="a>b">Authority</span></h2> with a contradictory authority table to README.md still produces COMMAND_CENTER_INVARIANTS=PASS, although the browser renders an exact duplicate governed heading. Strip nested tags with the same quote-aware parsing before comparing the rendered heading.
Useful? React with 👍 / 👎.
| r"(?:is|are|was|were)(?:\s+being)?\s+|" | ||
| r"(?:has|have|had)(?:\s+been)?\s+)?" | ||
| r"(?:(?:approv|authoriz)(?:e|es|ed|ing)\s+" | ||
| r"(?:merges?|pull\s+requests?)|" |
There was a problem hiding this comment.
Recognize PR abbreviations in approval claims
Fresh evidence after adding pull requests is that the guarded object alternatives still omit the repository's commonly used PR/PRs shorthand. Appending Hoxline can approve PRs. to README.md produces COMMAND_CENTER_INVARIANTS=PASS, despite granting the same non-human approval authority as the now-rejected Hoxline can approve pull requests. form; include the abbreviation in the active, delegated, granted, possessive, and passive patterns.
Useful? React with 👍 / 👎.
Objective Align the HawkinsOperations GitHub organization front door with the Website Reviewer Guide while preserving the seven-repository authority model and current proof ceilings. ## First-30-second improvement - Leads with one high-level HawkinsOperations thesis. - Distinguishes three doors immediately: Website / Reviewer Guide, Hoxline product / ProofOps control, and GitHub source / receipts. - Aligns the public profile and START_HERE on the same four-step 30-second route: Website → Hoxline → HO-DET-001 proof → Repository Authority Map. - Moves the 30-second, 3-minute, and focused 10-minute routes ahead of governance detail. - Labels the full seven-repository sweep as an extended reproducible review. ## Website / Hoxline / GitHub distinction - Website / Reviewer Guide: visual walkthrough and presentation surface; rendering is not proof. - Hoxline: product and ProofOps control surface; Claim Firewall is a capability, not another authority repository. - GitHub organization: source, validation, proof records, contracts, governance, and reviewer receipts; Markdown rendering is not proof. - Doctrine: AI produces labor. Evidence and human review authorize claims. ## Seven-repository authority preservation The profile, START_HERE, Repository Authority Map, reviewer path, contracts, and invariant manifest preserve exactly seven system repositories: .github, hoxline, detections, validation, platform, proof, and Website. No eighth repository or authority collapse is created. Historical six-repository audit context is explicitly separated from the current exact seven-repository model. ## Fast reviewer routes - 30 seconds: Reviewer Guide → Hoxline → HO-DET-001 proof → Repository Authority Map. - 3 minutes: source → controlled validation → proof record → Proof Pack → Claim Firewall → Control Status. - 10 minutes: fixture-based Hoxline demo plus source, validation, proof, and claim-boundary inspection. - Extended: clone all seven repositories and run their public checks. ## Duplicate material compressed - The public profile now orients before presenting proof ceilings, governance detail, or repository mechanics. - START_HERE owns the executable route; the profile owns the fast orientation. - Volatile metrics are not copied into the front door; links route to source-owned records. ## Files changed - README.md - profile/README.md - profile/START_HERE.md - architecture/REPO_AUTHORITY_MAP.md - architecture/REPRODUCIBLE_REVIEWER_PATH.md - governance/CONTROL_STATUS_MATRIX.md - governance/ORG_CI_CD_AUTHORITY_CONTRACT.md - governance/COMMAND_CENTER_INVARIANTS.json - scripts/verify-command-center-invariants.py ## Validation - python -B scripts/verify-command-center-invariants.py — PASS; COMMAND_CENTER_INVARIANTS=PASS, checked_files=18. - GitHub command-center-invariants check — PASS on current head 4d94cd1 (6s). - git diff --check — PASS. - Local Markdown links — 64 checked, 0 missing. - Critical detection-source, validation-result, proof-record, proof-index, platform-manifest, validation-registry, and Proof Pack routes exist. - Changed-term scan — no private-term violation or unsupported affirmative claim; matching public-safe/runtime/signal text is explicit negative-boundary language. - Banned six-repo, Podcast, AevumGuard, and TEST_VALIDATED_SYNTHETIC_SCOPE terms — absent from the proposed organization change. - In-memory negative mutation tests — swapped roles, altered ownership/boundary cells, missing or eighth rows, retargeted doors, weakened manifest values, missing Hoxline surfaces, copied ledger counts, and stale proof-state wording are rejected. - YAML parsing — PASS for promotion-ladder and required-checks contracts. ## Website dependency Website PR HawkinsOperations/hawkinsoperations-website#83 is ready for review at 2feec98c47ae33d176b2f0a93e389ae467418230. Governance Gate and Cloudflare passed. Exact preview: https://8c92c050.hawkinsoperations-website.pages.dev. The Website must merge before this routing PR. ## Read-only deferred findings - Current Hoxline and validation landing pages retain banned synthetic terminology; those repositories are outside this PR’s write scope and need a separately scoped controlled-test terminology correction. - Hoxline, detections, validation, platform, and proof landing pages lack a consistent direct return link to the Website Reviewer Guide or organization START_HERE route; address in a separately scoped cross-repository landing-page alignment. - Public Control Board metadata still contains stale naming/routing; Project mutation remains outside this PR. - Repository descriptions, homepage URLs, topics, pins, and settings remain separately scoped. ## PR review remediation All material P1/P2 findings from iterative internal and GitHub review are fixed at the current head: - The 10-minute path now clones .github and Hoxline side by side and explicitly returns to ...github before running the organization verifier. - The invariant verifier binds exact repository-role rows rather than checking an unordered phrase set. - That exact binding now covers all four authority tables: README.md, profile/README.md, profile/START_HERE.md, and architecture/REPO_AUTHORITY_MAP.md. - Authority-table parsing now binds each exact boundary header and boundary cell, preventing contradictory ownership claims from passing CI. - The primary Website / Reviewer Guide label is bound to its stable hawkinsoperations.com URL inside the Choose the right door table. - Authority Summary ownership cells are compared exactly, not skipped. - Every Markdown authority-table row is parsed and the complete table must equal the exact seven expected rows, so alternate-format or eighth-repository rows fail closed. - The extended reviewer path returns from the Website sibling checkout with ..\.github before running the organization verifier. - The machine-readable invariant manifest must equal the complete reviewed invariant mapping; weakened or contradictory values fail closed. - The organization CI/CD authority contract now includes Hoxline in its seven-repository ladder, bounded ownership table, evidence chain, and verifier coverage. - The full three-door table is compared exactly, preventing a correct link elsewhere in the section from masking a retargeted primary Reviewer Guide door. - Contiguous Markdown tables are parsed whether or not rows use outer pipes, so a valid GFM eighth row cannot evade exact-seven enforcement. - Hoxline is synchronized across the promotion ladder, cross-repo map, pull request template, CI/CD contract, and organization system map, with verifier coverage. - The required-checks matrix now reflects source-owned proof records/cards/index entries and the existing bounded HO-DET-012 website summary without promoting runtime or signal truth. - The system map routes current ledger values to the platform manifest, labels the proof summary historical, and no longer copies volatile counts. - The required-checks matrix now includes Hoxline's observed ci / hoxline-trust-boundaries context without claiming ruleset enforcement. - The verifier validates the exact seven matrix repositories and the complete Hoxline promotion layer, including human review, statuses, gates, and boundaries. - Each required-checks repository name is bound to its expected truth surface and repository-specific workflow/job metadata, so swapped labels fail closed. - Promotion and required-checks contracts are parsed structurally with pinned PyYAML; malformed YAML and quoted or unquoted eighth entries fail closed. - The clone-runnable reviewer paths install the same pinned PyYAML version before invoking the structural verifier. - The organization system map now preserves the declared Hoxline → platform → proof handoff, and the verifier rejects the reversed platform → Hoxline edge. - The reviewer navigation chain includes platform between Hoxline and proof; direct Hoxline-to-proof authority routing is rejected. - Structural YAML parsing rejects duplicate mapping keys instead of accepting last-key-wins ambiguity. - HO-DET-012 reviewer-path state is synchronized with its existing proof record, proof card, indexed ceiling, and bounded Website summary. - Required-check metadata binds workflow names and job IDs as exact pairs, preventing a job from being attributed to the wrong workflow. - Hoxline required-check metadata is bound to the current Hoxline main workflow (
ci / test); the unmerged draft-onlyhoxline-trust-boundariesjob is not presented as current source truth. - The verifier requireshuman_review_requirement: trueon every promotion layer, not only Hoxline, so proof or Website layers cannot bypass human authority. - Every declared required or explicitly non-required workflow/job pair now has one matching structured context; missing, duplicate, or unexplained contexts fail closed. - A normalized fingerprint protects the complete reviewed promotion contract, including every layer and all top-level parity, blocked-claim, status, and current-state gates, so any reviewed contract drift fails CI. - The authority contract now records the narrowly active Phase 2B repo-local invariant workflow; the original Phase 1 workflow-edit prohibition is superseded only for this scoped existing check, without creating reusable workflows or settings enforcement. - The required-checks matrix now carries the same Phase 2B current-state marker and exact non-promotional boundary; the verifier rejects stale phase or widened authority fields. - The 3-minute, 10-minute, and concrete HO-DET-001 routes now preserve source → validation → Hoxline/Claim Firewall → platform → proof ordering, with the fast paths order-checked. - Every repository's complete declared workflow-file set is exact-bound; a missing, extra, or retargeted workflow path fails closed. - Direct Hoxline-to-proof Mermaid bypasses are rejected across plain, dotted, thick, variable-length, labeled, pipe-labeled, decorated-node, classed-node, circle-endpoint, cross-endpoint, and compound fan-out forms. - Every structured workflow/job pair is compared with the complete canonical pair set for its owning repository; self-consistent but invented pairs fail closed. - Direct Hoxline bypasses to theweborwebsitepublic-rendering endpoint are rejected, including circle/cross and compound fan-out forms. - Required and explicitly non-required workflow/job pairs are compared against separate canonical sets; moving a check between enforcement classifications fails closed. - A normalized fingerprint binds the complete required-checks matrix, including every verifier command, display field, enforcement classification, and documented boundary. - A normalized manifest fingerprint pins the complete reviewed required-route list and seven-repository authority order. - Mermaid edge inspection enumerates compound endpoint groups in both directions, rejecting reverse-spelled and fan-in/fan-out Hoxline bypasses while allowing the governed Hoxline → platform → proof chain. - Optional Mermaid edge identifiers are normalized before endpoint inspection, so named edges cannot hide a bypass. - Quoted inline and pipe edge labels are parsed as complete label atoms, so embedded>or|punctuation cannot suppress endpoint inspection. - A normalized fingerprint pins all six reviewed Mermaid blocks, so endpoint aliases or additional topology cannot silently alter the governed graph. - Mermaid fingerprint extraction normalizes backtick/tilde fences, fence length, info-string casing, and unclosed blocks extending to EOF; alternate Markdown fence syntax cannot add unreviewed topology. A deterministic extractor now requires every closing fence to match the opener marker and meet or exceed its exact run length, while skipping non-Mermaid fences. - Invariant-manifest JSON parsing rejects duplicate keys before normalization and fingerprinting. - Reviewer-visible Markdown is parsed after closed or EOF-unclosed HTML comments are removed, while valid fenced, paragraph-bounded matched inline, and indented code remains visible; Markdown block boundaries interrupt unmatched inline spans, invalid backtick fence info cannot mask reviewer-visible content, escaped/unmatched/mismatched/later-paragraph backticks cannot hide a real comment, and JSON/YAML are never stripped. - The manifest explicitly distinguishes stable front-door inventory display order from the separately governed promotion-ladder sequence; both exact sequences remain independently verified. - Semantic authority-heading and table scans exclude fenced and indented code, preventing code examples from masquerading as reviewer-visible ownership contracts while literal code checks remain intact. Tag-only custom type-7 HTML blocks use the same container-scoped suppression as type-6 blocks, while visible inline tag text is preserved. Type-7 activation now respects open paragraphs and later paragraph interrupts, accepts exactly one complete CommonMark tag, and records marker-leading list indentation so container exit cannot suppress outside text. Renderer-visible HTML body wording remains available to claim checks but is neutralized as Markdown structure, so raw HTML cannot masquerade as an authority heading or table. Type-6 HTML state records blockquote depth and list continuation indentation, resuming when that container exits with or without a blank line. Type-6 HTML blocks terminate on both ordinary and blockquote-container-relative blank lines. Type-6 HTML blocks are recognized through list/blockquote prefixes, and a quote-aware final tag pass removes non-rendered type-7 tag names and attributes while preserving visible text. Fences nested directly in list or blockquote containers fail closed before semantic authority parsing. Multiline inline-code delimiters and type-6 Markdown HTML blocks also fail closed before structural parsing. - Raw pre, script, style, textarea, and intrinsically hidden template containers are also excluded from semantic authority parsing, closing the raw-HTML version of the same bypass. Script, style, and textarea use matching raw-text end-tag detection rather than interpreting their content as HTML attributes. Raw HTML tags are tokenized with cross-line quote state, so closing-tag text inside attributes cannot terminate the container. Recognized raw opening tags activate before their multiline attributes finish, and unterminated non-quoted tag-like text cannot consume a later real close. Nested raw-code tags inside HTML wrappers are detected as well. Every same-line open/close/reopen transition is consumed deterministically before semantic parsing resumes. These non-void elements remain active even when their opening tag carries a trailing slash, until a matching end tag appears. Indented Markdown code is removed before inactive raw-tag discovery so code examples cannot open semantic state. - Ordered-list paragraph interruption follows the CommonMark numeric start rule, including zero-padded representations of start value 1 without misclassifying later numeric starts. - Inline-code visibility follows Markdown block interruptions including Setext headings and type 1-6 HTML blocks, and only ordered lists beginning with 1 interrupt a paragraph. CommonMark four-column indented code includes zero-to-three spaces followed by a tab in both literal and semantic scans. Indented-code classification precedes inactive fence and raw-tag discovery. Fence opening and closing permit only zero-to-three spaces, never a tab counted as one character. Negative mutation checks confirm swapped roles, weakened boundary headers/cells, and a retargeted primary Reviewer Guide door are rejected. All review threads are resolved. Exact-head CI and independent review pass after aligning raw-HTML semantic parsing with GitHub-rendered body visibility, neutralizing inline-HTML structural promotion, enforcing decoded and anchored rejected-example context across HTML-entity-decoded and Unicode-format-normalized, emphasized, balanced-link, reference-link, and soft-wrapped claims with list, heading, blockquote/container-blank, thematic-break, raw-HTML, and paragraph scope preserved, resetting paragraph interruption state, and tracking nested template/raw-text depth. P0/P1/P2: none. - Rendered HTML authority-heading uniqueness is quote-aware, including greater-than characters inside quoted attributes. - Non-human approval guards cover pull-request approval in active, delegated, granted, possessive, and passive forms. - Renderer-visible HTML block boundaries and structured table status ownership prevent unrelated rejected/status context from exempting affirmative claims. Exact Boundary and Claim boundary columns remain valid governing contexts while unrelated status columns remain non-authoritative. ## Proof ceiling This PR establishes organization-front-door presentation and reviewer-routing alignment plus repository-supported validation for the checked scope. It does not establish runtime activity, signal observation, production/customer deployment, SOCaaS operation, public-safe runtime evidence, disposition authority, case closure, proof promotion, human approval, or merge authority. Website and GitHub rendering remain reviewer-routing surfaces. ## Human review order 1. First screen and three-door distinction. 2. 30-second, 3-minute, 10-minute, and extended reviewer routes. 3. Seven-repository ownership and Hoxline/Claim Firewall separation. 4. Source-owned metric routing and proof ceiling. 5. Invariant-manifest and verifier changes. 6. Deferred read-only landing-page findings. ## Merge gate Automated and internal review gates pass. Visible eligible human GitHub review and the exact standalone phrase MERGE_APPROVED remain required. Merge order is Website PR #83 first, then this organization routing PR.