Accept WP-0008-T05 for trsl:phase:info-tech-canon-service-surface (history/260805-T05-GoLive-info-tech-canon.md). Finish WP-0013 remission automation and WP-0014 extension/breach/attestation Control Plane UI. Update SCOPE, README, and pilot-candidate notes for pilot Stage 1.
4.3 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | state_hub_workstream_id |
|---|---|---|---|---|---|---|---|---|---|---|
| TREV-WP-0014 | workplan | Control Plane UI: Extension Registry, Breach Records, Conversion Attestation | infotech | target-revenue | finished | claude | infotech | 2026-07-30 | 2026-08-05 | 9642c16e-5dd2-4bd6-881b-0eb04a8cf168 |
Control Plane UI: Extension Registry, Breach Records, Conversion Attestation
Spun out of workplans/TREV-WP-0012-phase-provenance-and-policy-modeling.md
(use cases 5, 6, 7). Unlike workplans/TREV-WP-0013-remission-credit-automation.md,
the backend for all three already exists and is tested
(registry.register_extension/promote_extension_canonical,
breach_record.publish_breach_event/get_breach_records,
attestation.publish_attestation) — this is UI-only work, extending
service/control_plane_app.py and its templates the same way WP-0009-T04
did for Phases and the Ledger. Not blocked on WP-0012; can start any time.
id: TREV-WP-0014-T01
status: done
priority: medium
state_hub_task_id: "8502c68b-4638-4242-9e4e-f9938dc62c9a"
Extension Registry UI: a page listing registered extensions with
their registered/canonical status, a form to register a new extension
(any authenticated tenant, per registry.register_extension — confirm
whether Control Plane rights-gating applies here or whether extension
registration is intentionally open, since control_plane.py today has no
wrapper for it at all), and a canonical-promotion action restricted to
whatever rights tier canonicalization review actually requires (check
specs/TargetRevenueControlPlaneConcept.md §2's rights table — this may
need its own entry there if it's missing).
Result (2026-08-05): Rights decided and recorded in concept §2 and
control_plane.py module comments:
- Register extension: Operator+ (same tier as Phase registration).
- Promote to canonical: Admin only (governance, never automated).
UI: GET/POST /extensions, POST /extensions/promote, template
extensions.html, nav link for all signed-in users (read). Wrappers
control_plane.register_extension /
control_plane.promote_extension_canonical with audit log.
registry.list_extensions added for the listing.
id: TREV-WP-0014-T02
status: done
priority: medium
state_hub_task_id: "8ba38f04-8612-426d-b11f-0ebdd8cea2f6"
Breach/Compliance Record UI: a form to publish a breach/compliance
determination against a Phase (breach_record.publish_breach_event),
respecting the anonymized-by-default / named-only-with-opt-in rule
(FR-10, License V1C1 §7.4), and a read view on phase_detail.html
listing a Phase's published records.
Result: Operator+ form on phase_detail.html posts to
POST /phases/{id}/breach via control_plane.publish_breach_event.
Anonymized default; named path requires named_disclosure_authorized
affirmation. Published records listed on the same page (read for all
signed-in tiers).
id: TREV-WP-0014-T03
status: done
priority: low
state_hub_task_id: "b8c46793-c459-4890-90e6-cc112f8c8cb9"
Conversion Attestation UI: read-only — a Phase that has converted
should show its Attestation (attestation.publish_attestation is
idempotent/publish-on-first-observation) on phase_detail.html, including
Future License and the supporting ledger checkpoint, rather than requiring
a caller to hit the Trust Service's GET /phases/{id}/attestation
directly to see it.
Result: phase_detail loads control_plane.get_or_publish_attestation
(idempotent publish on first observation of Outstanding Target = 0) and
renders Future License, final credits, ledger checkpoint, and signature
when present; empty state when not converted.
id: TREV-WP-0014-T04
status: done
priority: low
state_hub_task_id: "919e48cb-92f5-49cd-aa16-19889efd258b"
Tests and docs: Docker-gated TestClient tests for all three (same
pattern as tests/test_control_plane_app.py), workplan Result sections,
README.md row update.
Result: Four new tests in tests/test_control_plane_app.py
(extension register/promote rights, anonymized breach, named breach CUA
gate, attestation after conversion). Concept §2 rights table updated;
README active-work row for WP-0014 marked finished; PhaseLifecycleUseCases
use case 6 open question closed by reference to the concept update.