target-revenue/workplans/TREV-WP-0014-control-plane-extensions-breach-attestation-ui.md
tegwick bff644a4d4 chore(consistency): sync workstream/task IDs for TREV-WP-0012/0013/0014
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-30 19:36:30 +02:00

79 lines
2.9 KiB
Markdown

---
id: TREV-WP-0014
type: workplan
title: "Control Plane UI: Extension Registry, Breach Records, Conversion Attestation"
domain: infotech
repo: target-revenue
status: active
owner: claude
topic_slug: infotech
created: "2026-07-30"
updated: "2026-07-30"
state_hub_workstream_id: "9642c16e-5dd2-4bd6-881b-0eb04a8cf168"
---
# Control Plane UI: Extension Registry, Breach Records, Conversion Attestation
Spun out of `workplans/TREV-WP-0012-phase-provenance-and-policy-modeling.md`
(use cases 5, 6, 7). Unlike `workplans/TREV-WP-0013-remission-credit-automation.md`,
the backend for all three already exists and is tested
(`registry.register_extension`/`promote_extension_canonical`,
`breach_record.publish_breach_event`/`get_breach_records`,
`attestation.publish_attestation`) — this is UI-only work, extending
`service/control_plane_app.py` and its templates the same way WP-0009-T04
did for Phases and the Ledger. Not blocked on WP-0012; can start any time.
```task
id: TREV-WP-0014-T01
status: todo
priority: medium
state_hub_task_id: "8502c68b-4638-4242-9e4e-f9938dc62c9a"
```
**Extension Registry UI**: a page listing registered extensions with
their `registered`/`canonical` status, a form to register a new extension
(any authenticated tenant, per `registry.register_extension` — confirm
whether Control Plane rights-gating applies here or whether extension
registration is intentionally open, since `control_plane.py` today has no
wrapper for it at all), and a canonical-promotion action restricted to
whatever rights tier canonicalization review actually requires (check
`specs/TargetRevenueControlPlaneConcept.md` §2's rights table — this may
need its own entry there if it's missing).
```task
id: TREV-WP-0014-T02
status: todo
priority: medium
state_hub_task_id: "8ba38f04-8612-426d-b11f-0ebdd8cea2f6"
```
**Breach/Compliance Record UI**: a form to publish a breach/compliance
determination against a Phase (`breach_record.publish_breach_event`),
respecting the anonymized-by-default / named-only-with-opt-in rule
(FR-10, License V1C1 §7.4), and a read view on `phase_detail.html`
listing a Phase's published records.
```task
id: TREV-WP-0014-T03
status: todo
priority: low
state_hub_task_id: "b8c46793-c459-4890-90e6-cc112f8c8cb9"
```
**Conversion Attestation UI**: read-only — a Phase that has converted
should show its Attestation (`attestation.publish_attestation` is
idempotent/publish-on-first-observation) on `phase_detail.html`, including
Future License and the supporting ledger checkpoint, rather than requiring
a caller to hit the Trust Service's `GET /phases/{id}/attestation`
directly to see it.
```task
id: TREV-WP-0014-T04
status: todo
priority: low
state_hub_task_id: "919e48cb-92f5-49cd-aa16-19889efd258b"
```
**Tests and docs**: Docker-gated `TestClient` tests for all three (same
pattern as `tests/test_control_plane_app.py`), workplan Result sections,
`README.md` row update.