docs(plans): slice 1 data model note and prototype; lead decision 46

Darkwing's design note and SQLite prototype as records. Sage accepts
seven of eight open questions; the PM launching sessions goes to Jason.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-04 14:19:14 -05:00
co-authored by Claude Opus 5.5
parent 9c69f2fba3
commit bb7e37dda2
8 changed files with 727 additions and 0 deletions
+37
View File
@@ -692,3 +692,40 @@ which stay with him. Each item names who decided it and what happened.
Code. Sage reads Jason's ruling as covering those T3 Claude sessions.
The first launch under it is a Researcher thread on Sonnet 5.5
(9bac0794), researching Vikunja and Pocket ID.
46. **Sage's rulings on the slice 1 data model's open questions
(2026-10-04).** Source: Darkwing's note
`agents/darkwing/work/slice1-data-model-2026-10-04.md` (sha256
948b94ce…), section 6.
- 6.1, business files: accepted. A business file at
`~/.config/mosaic-dev/businesses/<id>.json` is a separate layer, not
a second system config. The user writes it, the stack never writes
it, and a missing or invalid file fails closed. `config.json`
doesn't change. Invariant 2 holds as written.
- 6.2, claims and events in `bus.sqlite`: accepted. They fall under
decision 44, item 7, with the same append-only rule.
- 6.3, human resolution: accepted. Stack-launched agents reach the bus
only through a broker that stamps role and run from the launch
record. A human resolution comes only from a `mosaic` CLI session
started outside any agent run. The brief will say plainly that
today's T3 seats, running as the same user, are advisory, not a
boundary.
- 6.4, tamper evidence: accepted. Triggers plus a schema check at
open. Hash chaining waits until a measure needs it.
- 6.5, coder vs. the worker invariant: accepted. Role agents are a new
kind of seat, launched with a role binding. Workers keep "no git, no
credentials".
- 6.6, the PM launching sessions: goes to Jason in PRDY round 3. It
changes who starts work (relaunch constraint 4). Decisions 42 and 45
cover Sage launching T3 roster seats, not a product role.
- 6.7, revoking a role: accepted. A revoke is gated in slice 1 and
cites a resolved decision.
- 6.8, Vikunja concurrency: accepted, provisionally. Compare, then
write. Only the assigned role writes a task's mutable fields, and
people's edits arrive as `task.changed.external` events. Revisit if
Researcher finds Vikunja supports conditional updates.
Also adopted from the note: credential scope is the hard boundary for
gated actions, and harness hooks are logging plus early stops. The
brief won't call hooks enforcement. A plain append-only rule isn't
enough: `INSERT OR REPLACE` overwrote a row in the prototype despite
UPDATE and DELETE triggers. Each table also needs a BEFORE INSERT
guard, which the prototype verified.