ci/woodpecker/pr/ci Pipeline failed
Ratifies the Mosaic Stack PRD rev1 (Jason Woltje, 2026-09-01) as project source of truth and installs the GOV.1 lifecycle model: - docs/PRD.md becomes a permanent shim (kind: shim, current_rev -> docs/PRDs/2026-08-31_PRD_rev1/). Its path never changes again. - docs/PRDs/2026-08-26_PRD_rev0/PRD.md archives the 2026-08-26 North Star verbatim (sha256 60cc2f98...36afdf unchanged). Archive, never delete. - docs/PRDs/2026-08-31_PRD_rev1/ is the frozen rev1 bundle: 18 sectioned documents (VIS, DATA, AUTHN, AUTHZ, SEAT, ROLE, HARN, PROV, SESS, UI, CLI, GOV.1-5) consolidating rev0 D1-D15, the fleet north star, the agent-runtime L1/L2 contracts and the control-plane-surfaces lane findings, with a single decision map (GOV.3) and a closed open-questions frontier (GOV.5, grill rounds 1-8). Drafting inputs (_source-* snapshots) are not shipped. Consequences of the ratified rulings carried in the same change: - Q-T1 (ruling B, "shipped but frozen"): D3 amended in GOV.3/VIS.1; federation M1-M3 acknowledged as shipped behind tier === 'federated', excluded from the v1 bar and frozen, with a security re-audit gate before any resumption. docs/MISSION-MANIFEST.md, docs/federation/MISSION-MANIFEST.md and docs/scratchpads/mvp-20260312.md get status: superseded + banners (content preserved verbatim); docs/guides/deployment.md gains a "Relationship to the PRD (D15)" section. NORTH_STAR.yaml adds dormant workstream M (projects no goals by design); NORTH_STAR.md regenerated. - Q-G2 (distinct registry prefixes): every citation of the operator DECISION-REGISTER in the bundle reads OD-nn; the stack registry stays D1-D15; L1-Dnn/L2-Dnn untouched. Prefix rule recorded in GOV.1. Follow-ups (not in this PR): CI parity drift-gate witness (Q-C1); brain-side DECISION-REGISTER rename to OD- with redirect table on its next touch.
121 lines
8.4 KiB
Markdown
121 lines
8.4 KiB
Markdown
---
|
||
id: GOV.3
|
||
status: ratified
|
||
ratified: 2026-09-01 (Jason Woltje; PRD rev1 ratification PR)
|
||
---
|
||
|
||
# GOV.3 — Consolidated decision map
|
||
|
||
Every ratified decision set that binds this PRD, in one place, with the
|
||
collisions between their numbering spaces made explicit. This section exists
|
||
because the estate carried at least four independent decision registries whose
|
||
IDs overlap — a reader seeing "D8" could not know which law was meant.
|
||
|
||
## The registries
|
||
|
||
| Registry | IDs | Ratified | Where | Scope |
|
||
|---|---|---|---|---|
|
||
| Stack PRD registry | **D1–D15** | 2026-08-25/30 | rev0 §12 → [[GOV.3-decision-map]] (this file, below) | product north star |
|
||
| Operator decision register | **OD-01–OD-65** (renamed from D01–D65 per Q-G2, 2026-09-01; the brain-side source doc renames on its next touch and carries a redirect table) | 2026-08-28 (Q1–Q92 review) | the operator DECISION-REGISTER (estate brain `docs/guides/proposed/DECISION-REGISTER.md`, snapshot 2026-08-28, sha256 `2cc81be1…aabec`; operator-only corpus, not shipped) | roles, coordination, PRD lifecycle, configuration, checkpoints |
|
||
| L2 authorization decisions | **L2-D01–L2-D51** (+ proposed **L2-D52**) | rolling | `fleet/lanes/agent-runtime-ng/MECHANICAL-AGENT-RUNTIME-L2-AUTHORIZATION.md` | mechanical agent-runtime authorization |
|
||
| Control-plane rulings | **J1–J5** | 2026-08-23 | `fleet/lanes/docs/mosaic-control-plane/rulings-J1-J5.md` | record-class authority |
|
||
| PRD structural rulings | (unnumbered, 8 rulings) | 2026-08-31 | [[PRD.0-index]] §Structural rulings | this bundle's lifecycle |
|
||
|
||
**Collision rule:** zero-padded `D01`-form IDs = operator register; bare `D1`-form
|
||
= stack PRD registry; `L2-D` = L2; `J` = control-plane rulings. Writing a bare
|
||
"D8"-style reference without its registry name is a defect (naming register
|
||
[[GOV.2-docs-inventory]] N4).
|
||
|
||
## Stack PRD registry D1–D15 (carried from rev0 §12)
|
||
|
||
| ID | Decision (short form) |
|
||
|---|---|
|
||
| D1 | Open-source, AI-first, self-hosted platform for agentic management + life OS |
|
||
| D2 | Hierarchy company→estate→project→workspace→kanban; bubble-up; granular RBAC |
|
||
| D3 | Standalone vs Enterprise; one-way conversion; per-user brains + Vault required in Enterprise; federation deferred. **Amended 2026-09-01 (Q-T1 ruling B, "shipped but frozen")**: federation M1–M3 exist in code behind `tier === 'federated'` (M3 landed 2026-06-24/25), are excluded from the v1 bar and frozen; tracked as a dormant workstream in `docs/fleet/NORTH_STAR.yaml`; the frozen cert/auth code carries a security re-audit gate before any resumption; the design itself stays deferred and unforeclosed |
|
||
| D4 | Re-runnable, extensible, per-mode onboarding wizards |
|
||
| D5 | North star = docs/PRD.md rewrite; stack docs/ = product SSOT |
|
||
| D6 | Only product-relevant material migrates from brains; operational records stay and link |
|
||
| D7 | Spec-inventory sweep (executed; T2 baseline frozen 2026-08-25) |
|
||
| D8 | webUI sits over official framework tooling; CLI primary |
|
||
| D9 | Not a hosted business; company = organizational separation for one operator |
|
||
| D10 | better-auth is the account system of record; external IdPs via OIDC |
|
||
| D11 | Small v1 slice; ALL phases on the documented roadmap from day one |
|
||
| D12 | HARD RULE: webUI never bypasses tooling; missing tool ⇒ build the tool first |
|
||
| D13 | workspace_id stays the hard isolation unit; kanban SOT amended, not rewritten |
|
||
| D14 | Sensitive profile data in the user's own brain only |
|
||
| D15 | Tiered containerized deployment: compose standalone + phase-gated k8s |
|
||
|
||
Full texts: rev0 §12 and the operator decision log (USC estate brain,
|
||
webui-audit lane, `GRILL.md`).
|
||
|
||
## Operator register decisions this PRD leans on hardest
|
||
|
||
Full set: the operator DECISION-REGISTER (estate brain `docs/guides/proposed/DECISION-REGISTER.md`, snapshot 2026-08-28, sha256 `2cc81be1…aabec`; operator-only corpus, not shipped). Load-bearing here:
|
||
|
||
| ID | Ruling (short) | Consumed by |
|
||
|---|---|---|
|
||
| OD-02/OD-03 | one role per seat; role change = clean session, ephemeral context discarded | [[SEAT.1-seat-profile]], [[SESS.1-session-continuity]] |
|
||
| OD-08/OD-09 | coordinator service owns leases/deployment; orchestrators never deploy seats directly | [[AUTHZ.1-capability-authority]] |
|
||
| OD-16–OD-23 | PRD owns requirements; immutable accepted versions; `docs/PRD.md` = generated pointer under `docs/PRDs/`; missions pin PRD version+digest; `mosaic prdy` owns PRD creation | [[GOV.1-prd-lifecycle]] — **independently re-derived in the 2026-08-31 grill before this register was consulted; the two agree** |
|
||
| OD-48 | instance contract: `profile.json` structured identity, `overlay.json` generated composition | [[SEAT.1-seat-profile]] |
|
||
| OD-49–OD-53 | `mosaic config` desired-state engine; blueprint + host-binding split; precedence chain; **all interfaces (CLI/TUI/WebUI/API) share one CLI-backed engine** | [[DATA.1-record-authority]], [[CLI.1-parity]], [[UI.1-webui-surfaces]] |
|
||
| OD-54 | WebUI drafts are revisioned server-side desired-state; no effect until planned and applied | [[UI.1-webui-surfaces]] |
|
||
| OD-57–OD-61 | checkpoints tied to incarnation+lease; coordinator-run relaunch (checkpoint→stop→apply→clean incarnation→restore); fencing; full restart recovery | [[SESS.1-session-continuity]] — **this is the ratified mechanism for mid-stream harness/model/provider switching** |
|
||
| OD-62–OD-65 | watchdog, outage fail-closed, failure isolation/reporting | [[AUTHZ.1-capability-authority]], [[UI.1-webui-surfaces]] (audit/alerts) |
|
||
|
||
## Reconciliation notes
|
||
|
||
- Register OD-13 (repository-backed mission state canonical first, DB later behind
|
||
the same interface) and J1 (Git owns governance, PostgreSQL owns runtime
|
||
state) are compatible: OD-13 governs *mission* state migration order; J1 governs
|
||
steady-state record classes. [[DATA.1-record-authority]] carries the merged
|
||
table.
|
||
- Register OD-18's "generated pointer" is stricter than the 2026-08-31 grill's
|
||
hand-maintained shim: **adopted** — the shim should be generated by tooling,
|
||
not hand-edited ([[GOV.1-prd-lifecycle]] inherits this).
|
||
- Proposed, not yet ratified: **L2-D52** (least-privilege Assignment issuance),
|
||
staged at `proposed/docs/MECHANICAL-AGENT-RUNTIME-L2-AUTHORIZATION--least-privilege-issuance.md`.
|
||
## Extraction cross-check notes (2026-08-31)
|
||
|
||
- Five highly product-normative operator drafts carry **no decision-register
|
||
citations at all** (seat-identity, vault, adapter-contract,
|
||
SPECIALIZATION-MODEL, prd-registry). Their rules were pulled into sections on
|
||
their merits; before E6 they must be cross-checked against the register
|
||
rather than assumed pre-vetted.
|
||
- The intended-state-reconciler spec uses a **file-local D1–D6 numbering** that
|
||
is neither the stack registry nor the operator register — a live instance of
|
||
the N4 prefix-collision defect. Do not conflate when compiling
|
||
cross-references.
|
||
- The session-lifecycle draft is the densest register consumer (OD-03/OD-04/OD-08,
|
||
OD-56–OD-65) and is likely the canonical drafting source for OD-56–OD-65; its
|
||
one-relaunch-path gap is Q-S4.
|
||
|
||
## Re-ratified orphaned decisions (Q-T2, Jason 2026-09-01)
|
||
|
||
Ratified once in archived planning docs, absent from every live document until
|
||
this map; re-ratified as live constraints:
|
||
|
||
- **No Python in the monorepo** (source:
|
||
`archive/planning/monorepo-consolidation/board-review.md:742`).
|
||
- **Matrix/MACP: exactly three supported install modes, Mode A (split-domain)
|
||
primary** (source: `archive/planning/matrix-macp/rfc-002:133`). Its
|
||
DNS/domain prerequisite ruling remains open — [[GOV.5-open-questions]] Q-T6
|
||
blocks Matrix install work, not this map.
|
||
- **OpenBrain excluded from WP1/WP2 consolidation scope** (source:
|
||
`board-review.md:611`).
|
||
|
||
## Registry prefix ruling (Q-G2, Jason 2026-09-01)
|
||
|
||
Distinct prefixes at source: stack keeps **D1–D15**; the operator
|
||
DECISION-REGISTER renames to **OD-01…OD-65** with a redirect table in the
|
||
source doc. Applied in this bundle: every stack-side citation of the operator
|
||
register now reads **OD-nn**; the brain-side source doc itself still carries
|
||
its old zero-padded `D01`–`D65` numbering and renames (with the redirect
|
||
table) on its next touch. File-local D-numbering in drafts (the live N4
|
||
instance: the reconciler spec's D1–D6) is prohibited — every decision doc
|
||
declares a unique registry prefix. For any text predating 2026-09-01 not yet
|
||
swept into this bundle, the old reading rule still applies: a zero-padded bare
|
||
`Dnn` is the operator register (now read as `OD-nn`); a bare `Dn`/`Dnn` in the
|
||
1–15 range without a zero pad is the stack registry.
|