target-revenue/workplans/TREV-WP-0014-control-plane-extensions-breach-attestation-ui.md
tegwick 3064c0fe0c Go-live T05 + WP-0013/0014: first Phase and Control Plane completion
Accept WP-0008-T05 for trsl:phase:info-tech-canon-service-surface
(history/260805-T05-GoLive-info-tech-canon.md). Finish WP-0013 remission
automation and WP-0014 extension/breach/attestation Control Plane UI.
Update SCOPE, README, and pilot-candidate notes for pilot Stage 1.
2026-08-05 16:00:06 +02:00

4.3 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
TREV-WP-0014 workplan Control Plane UI: Extension Registry, Breach Records, Conversion Attestation infotech target-revenue finished claude infotech 2026-07-30 2026-08-05 9642c16e-5dd2-4bd6-881b-0eb04a8cf168

Control Plane UI: Extension Registry, Breach Records, Conversion Attestation

Spun out of workplans/TREV-WP-0012-phase-provenance-and-policy-modeling.md (use cases 5, 6, 7). Unlike workplans/TREV-WP-0013-remission-credit-automation.md, the backend for all three already exists and is tested (registry.register_extension/promote_extension_canonical, breach_record.publish_breach_event/get_breach_records, attestation.publish_attestation) — this is UI-only work, extending service/control_plane_app.py and its templates the same way WP-0009-T04 did for Phases and the Ledger. Not blocked on WP-0012; can start any time.

id: TREV-WP-0014-T01
status: done
priority: medium
state_hub_task_id: "8502c68b-4638-4242-9e4e-f9938dc62c9a"

Extension Registry UI: a page listing registered extensions with their registered/canonical status, a form to register a new extension (any authenticated tenant, per registry.register_extension — confirm whether Control Plane rights-gating applies here or whether extension registration is intentionally open, since control_plane.py today has no wrapper for it at all), and a canonical-promotion action restricted to whatever rights tier canonicalization review actually requires (check specs/TargetRevenueControlPlaneConcept.md §2's rights table — this may need its own entry there if it's missing).

Result (2026-08-05): Rights decided and recorded in concept §2 and control_plane.py module comments:

  • Register extension: Operator+ (same tier as Phase registration).
  • Promote to canonical: Admin only (governance, never automated).

UI: GET/POST /extensions, POST /extensions/promote, template extensions.html, nav link for all signed-in users (read). Wrappers control_plane.register_extension / control_plane.promote_extension_canonical with audit log. registry.list_extensions added for the listing.

id: TREV-WP-0014-T02
status: done
priority: medium
state_hub_task_id: "8ba38f04-8612-426d-b11f-0ebdd8cea2f6"

Breach/Compliance Record UI: a form to publish a breach/compliance determination against a Phase (breach_record.publish_breach_event), respecting the anonymized-by-default / named-only-with-opt-in rule (FR-10, License V1C1 §7.4), and a read view on phase_detail.html listing a Phase's published records.

Result: Operator+ form on phase_detail.html posts to POST /phases/{id}/breach via control_plane.publish_breach_event. Anonymized default; named path requires named_disclosure_authorized affirmation. Published records listed on the same page (read for all signed-in tiers).

id: TREV-WP-0014-T03
status: done
priority: low
state_hub_task_id: "b8c46793-c459-4890-90e6-cc112f8c8cb9"

Conversion Attestation UI: read-only — a Phase that has converted should show its Attestation (attestation.publish_attestation is idempotent/publish-on-first-observation) on phase_detail.html, including Future License and the supporting ledger checkpoint, rather than requiring a caller to hit the Trust Service's GET /phases/{id}/attestation directly to see it.

Result: phase_detail loads control_plane.get_or_publish_attestation (idempotent publish on first observation of Outstanding Target = 0) and renders Future License, final credits, ledger checkpoint, and signature when present; empty state when not converted.

id: TREV-WP-0014-T04
status: done
priority: low
state_hub_task_id: "919e48cb-92f5-49cd-aa16-19889efd258b"

Tests and docs: Docker-gated TestClient tests for all three (same pattern as tests/test_control_plane_app.py), workplan Result sections, README.md row update.

Result: Four new tests in tests/test_control_plane_app.py (extension register/promote rights, anonymized breach, named breach CUA gate, attestation after conversion). Concept §2 rights table updated; README active-work row for WP-0014 marked finished; PhaseLifecycleUseCases use case 6 open question closed by reference to the concept update.