From 389f7e7f1dd11f94a9b95dd832c2a6931f0d832f Mon Sep 17 00:00:00 2001 From: codex Date: Tue, 8 Sep 2026 14:20:48 +0200 Subject: [PATCH] Assess factory backlog and record first implemented delivery --- ...-09-08-helixforge-factory-followthrough.md | 50 + .../2026-09-08-helixforge-factory.md | 308 +++ .../2026-09-08-helixforge-factory/README.md | 63 + .../baseline.json | 114 + .../checkout-provenance.json | 146 + .../cohorts.json | 128 + .../consistency-check.json | 37 + .../dependency-coverage.json | 610 ++++ .../human-flag-corrections.json | 66 + .../human-flags.csv | 20 + .../open-workplans.csv | 99 + .../progress-receipt.json | 7 + .../source-records.json | 2455 +++++++++++++++++ .../.repo-classification.yaml | 15 + .../prj-helixforge-factory/AGENTS.md | 38 + docs/proposals/prj-helixforge-factory/GOAL.md | 90 + .../prj-helixforge-factory/README.md | 20 + .../proposals/prj-helixforge-factory/SCOPE.md | 55 + .../prj-helixforge-factory/dependency-map.md | 44 + .../history/2026-09-08-genesis.md | 24 + ...FACT-WP-0001-establish-internal-factory.md | 320 +++ 21 files changed, 4709 insertions(+) create mode 100644 docs/assessments/2026-09-08-helixforge-factory-followthrough.md create mode 100644 docs/assessments/2026-09-08-helixforge-factory.md create mode 100644 docs/assessments/2026-09-08-helixforge-factory/README.md create mode 100644 docs/assessments/2026-09-08-helixforge-factory/baseline.json create mode 100644 docs/assessments/2026-09-08-helixforge-factory/checkout-provenance.json create mode 100644 docs/assessments/2026-09-08-helixforge-factory/cohorts.json create mode 100644 docs/assessments/2026-09-08-helixforge-factory/consistency-check.json create mode 100644 docs/assessments/2026-09-08-helixforge-factory/dependency-coverage.json create mode 100644 docs/assessments/2026-09-08-helixforge-factory/human-flag-corrections.json create mode 100644 docs/assessments/2026-09-08-helixforge-factory/human-flags.csv create mode 100644 docs/assessments/2026-09-08-helixforge-factory/open-workplans.csv create mode 100644 docs/assessments/2026-09-08-helixforge-factory/progress-receipt.json create mode 100644 docs/assessments/2026-09-08-helixforge-factory/source-records.json create mode 100644 docs/proposals/prj-helixforge-factory/.repo-classification.yaml create mode 100644 docs/proposals/prj-helixforge-factory/AGENTS.md create mode 100644 docs/proposals/prj-helixforge-factory/GOAL.md create mode 100644 docs/proposals/prj-helixforge-factory/README.md create mode 100644 docs/proposals/prj-helixforge-factory/SCOPE.md create mode 100644 docs/proposals/prj-helixforge-factory/dependency-map.md create mode 100644 docs/proposals/prj-helixforge-factory/history/2026-09-08-genesis.md create mode 100644 docs/proposals/prj-helixforge-factory/workplans/HFACT-WP-0001-establish-internal-factory.md diff --git a/docs/assessments/2026-09-08-helixforge-factory-followthrough.md b/docs/assessments/2026-09-08-helixforge-factory-followthrough.md new file mode 100644 index 0000000..1d131b7 --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory-followthrough.md @@ -0,0 +1,50 @@ +# Factory implementation return — 2026-09-08 + +The user authorized following through and selected vergabe-teilnahme as the +primary customer service/UI product. The Custodian selected reuse-surface for +the first internal capability: its existing hosted registry offers immediate +utility; Railiance Fabric’s hosted authority still adds prerequisite work. + +## Delivered + +- **REUSE-WP-0022:** explicit hosted plan-check, bounded/fresh/unwarned source + acceptance, no failure-to-NEW/local fallback, and snapshot provenance. All + 208 tests and live Forgejo CI passed. Integrated on main at `998a5ef`, with + image `main-998a5ef` published. [Change](https://forgejo.coulomb.social/coulomb/reuse-surface/pulls/1). +- **VERGABE-WP-0018-T01/T02:** product identity, hosted reuse consumer, container + application gate before publication, missing-template build fix and pinned + BuildKit setup for the actual Railiance runner. All 82 tests passed on SQLite, + disposable PostgreSQL and in the container; live CI and image publication + passed. Integrated at `fa9f082`; image `main-fa9f082` published. + [Change](https://forgejo.coulomb.social/coulomb/vergabe-teilnahme/pulls/1). +- **Portfolio hygiene:** four obsolete human-needed flags now match explicit + published `needs_human: false` in the completed Forgejo migration source. + Task statuses and historical notes were preserved. Thirteen other terminal + flags still require source/residual disposition; none was cleared by counting + it as completed. [Correction evidence](2026-09-08-helixforge-factory/human-flag-corrections.json). + +The dedicated local project is +[/home/worsch/prj-helixforge-factory](/home/worsch/prj-helixforge-factory/README.md). +It contains the accepted source-backed decision HFACT-DEC-2026-001, current +workplan, ten exact owner-return records, delivery evidence and an empty +measurement ledger. Hub decision receipt: `21159693-04b7-485e-bbab-1ed8f65aab43`. +The original staged packet is frozen pending project publication. + +## Remaining gates + +Project creation needs the routed Forgejo admin API credential, which currently +has no caller OpenBao login. Organization push-to-create is disabled. The same +login can record both already-integrated PRs as manually merged; the PR metadata +still says open, although the tested source is on main. There is no secret-value +request or additional token provision in this handoff. + +The workplan retains exact native credential/approval/audit receipts through +GLAS-WP-0015, protected runtime placement, natural worker claim/heartbeat/close, +customer deployment/data/access/recovery acceptance and the 14-day observation +window. Today’s attended source delivery does not substitute for those proofs. + +Both child workplans were registered and synchronized. The customer repository +has no consistency failures; historical warnings remain. Reuse-surface has three +archived null-ID failures (REUSE-WP-0017/0018/0019), separate from the successfully +registered new plan. HFACT-WP-0001-T02 retains their disposition; CUST-IN-0017 +continues to own the pre-existing Custodian historical consistency issues. diff --git a/docs/assessments/2026-09-08-helixforge-factory.md b/docs/assessments/2026-09-08-helixforge-factory.md new file mode 100644 index 0000000..26539a4 --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory.md @@ -0,0 +1,308 @@ +# Coulomb, HelixForge and Railiance: factory readiness assessment + +Date: 2026-09-08. Assessor: Codex acting as the-custodian. +Scope: the registered Coulomb estate, with particular attention to the HelixForge +delivery path on Railiance. This is an assessment and a proposed programme; +it does not authorize deployment, credentials, reprioritization of other owners, +or unattended execution. + +**Assessment:** the estate has enough substantial components to justify an +integration pilot. It does not yet have reviewed evidence that its current +governed execution path repeatedly delivers useful software on Railiance. +The principal constraint is completing and operating the interfaces between +existing components. Starting another general framework would increase the +coordination burden before resolving that constraint. + +The recommended outcome is an **internal, single-tenant software factory**: +human intent becomes a bounded capability contract; an authorized agent produces +a reviewable change; independent validation gates an immutable artifact and an +authorized Railiance release; outcome and cost evidence inform the next change. +Autonomous production promotion and external multi-tenant service are later +maturity levels. HelixForge's existing discovery, architecture, and reuse goals +remain part of acceptance: a bot making commits alone does not meet them. + +## What was examined, and what the numbers mean + +The live State Hub returned 135 repositories, 1,314 workplans and 7,102 tasks. +The separate task-count endpoint also totaled 7,102. Requests used canonical +`/workplans/` and `/tasks/` routes; the task list's default has no pagination +limit in the inspected OpenAPI contract. The inbox for `the-custodian` was empty. +The initial portfolio capture preceded creation of this assessment. + +All **94 non-retired open Hub workplans** were resolved to local source files +by UUID or canonical identifier, and their workplan statuses agreed. This +validates the workplan count against available checkouts, not each completion +claim or deployment. Detailed integration review covered the current owner +plans, source contracts, and recorded production evidence, particularly the +September 4–8 work. No live cluster acceptance run, credential access, or +independent security audit was performed in this assessment. + +The eighteen principal checkouts' revisions and working-copy states are captured +in [checkout provenance](2026-09-08-helixforge-factory/checkout-provenance.json). +Their cached tracking branches showed no ahead/behind difference; no fetch was +performed. State Hub had existing local changes. Under +[ADR-012](../../canon/architecture/adr-012-projection-source-and-preliminary-overlay.md), +local evidence cannot substitute for a fresh Forge-derived production baseline. + +Raw Hub counts are **98 open plans: 44 active, 28 blocked, 15 proposed, six ready, +five backlog**. Four open rows have explicitly retired identities. Excluding +those rows gives the following planning baseline; it is not a silent repair of +the Hub or a claim that all remaining effort is necessary. + +| Workplan status | Non-retired count | +| --- | ---: | +| Active | 41 | +| Blocked | 27 | +| Proposed | 15 | +| Ready | 6 | +| Backlog | 5 | +| **Open total** | **94** | + +The raw 98 span 49 registered repos. The 94 canonical open plans contain +**264 open tasks: 136 todo, 28 progress, 100 wait**. Across *all* Hub workplans +there are 287 open tasks, including seven attached to retired open identities +and sixteen attached to terminal workplans. Those extra 23 must not be treated +automatically as new implementation demand. + +One additional local active record, `kings-guard/KG-WP-0005`, was absent from the +captured Hub workplan list. The wider local scan encountered historic terminal +spellings (`done`, `completed`), shared paths, unavailable registered paths and +legacy YAML dialects. Accordingly, this report uses the verified Hub cohort, +not a purported complete source-only fleet census. Age of a declared update or +sync is not elapsed blocker time; blocker transition history was not measured. + +Evidence and reproducible definitions: [baseline](2026-09-08-helixforge-factory/baseline.json), +[98-row inventory](2026-09-08-helixforge-factory/open-workplans.csv), +[source records](2026-09-08-helixforge-factory/source-records.json), and +[methodology](2026-09-08-helixforge-factory/README.md). + +## Where the load sits + +These are disjoint analytical cohorts, not a proposed repository reclassification. +All statuses in this table exclude retired identities. + +| Cohort | Open plans | Active | Blocked | Open tasks | +| --- | ---: | ---: | ---: | ---: | +| Identity, policy, custody and audit | 35 | 14 | 13 | 93 | +| Railiance runtime, packages and recovery | 23 | 10 | 10 | 43 | +| Agent execution and coordination | 9 | 7 | 2 | 15 | +| Hub consolidation and work projection | 7 | 2 | 1 | 26 | +| Publishing and community | 7 | 4 | 0 | 38 | +| Other product, commercial and research work | 13 | 4 | 1 | 49 | +| **Total** | **94** | **41** | **27** | **264** | + +Identity/security and Railiance account for **58/94 open plans and 23/27 blocked +plans**. The direct agent-execution cohort has only fifteen open tasks spread +across nine plans. This concentration suggests that dependency closure and live +integration offer more immediate value than expanding the runtime feature list. +It does not establish engineering effort: task counts have no common size. + +There is additional intake load: **54 open and eight routed intakes**, including +31 open intakes marked `origin: residual`. Routed intakes may already have +child workplans; adding them to the 94 would double-count some demand. +The [cohort membership](2026-09-08-helixforge-factory/cohorts.json) and full +inventory make the boundaries and individual blocked plans inspectable. + +## Existing capabilities worth building on + +| Capability | Evidence and practical limit | +| --- | --- | +| HelixForge intent and reusable operating prompts | [INTENT](../../../helix-forge/INTENT.md) defines discovery, capability contracts, architecture validation, realization and evolution. [HF-WP-0005](../../../helix-forge/workplans/HF-WP-0005-reusable-prompt-collection.md) delivered seven prompt packages and two fragments. All five HelixForge workplans are terminal; none owns factory acceptance. Its [SCOPE](../../../helix-forge/SCOPE.md) still describes a concept repository and references the retired Inter-Hub/nested State Hub structure. | +| Forgejo CI and artifact publication | [Runner substrate](../../../railiance-forge/docs/forgejo-actions-runner-substrate.md) records an in-cluster Railiance runner. [Enablement templates](../../../railiance-enablement/docs/forgejo-actions-workflow-templates.md) provide existing build/publish patterns. REINAH-WP-0003 records a recent real CI contract gate. There is no need to propose installing a forge or generic CI from scratch. | +| Scheduled work and repository mutation | [rein-aharness SCOPE](../../../rein-aharness/SCOPE.md) records the real railiance01 user-service claim loop, transaction acceptance and durable terminal-close outbox. Its Kubernetes Deployment runs `sleep infinity`; pod existence is not worker execution evidence. Historical Claude and deterministic clone/commit proofs do not certify the present profile. | +| Governed profile and sandbox boundary | [SAND-WP-0015](../../../sand-boxer/workplans/SAND-WP-0015-bwrap-runtime-and-private-state.md) records real bwrap startup, private state, constrained proxy transport, synthetic credential delivery and a pinned Claude candidate. The candidate remains a local `/tmp` artifact; startup is not a provider request or production installation. | +| Shared runtime substrate | [RMASTER-WP-0020](../../../railiance-master/workplans/RMASTER-WP-0020-openbao-migration-to-reef-railiance.md) records completed OpenBao restore, consumer migration, cutover and reversible source retirement. [RPF-WP-0038](../../../railiance-platform/workplans/RPF-WP-0038-forgejo-scaleway-primary-coverage.md) records successful isolated Forgejo recovery. Remaining cleanup, scheduled custody and retention work must be distinguished from initial deployment. | + +## Inefficiencies to tackle + +### 1. The queue describes work better than it dispatches it + +Only **four of 94** dependency queries returned structured edges, four edges in +total. The owner plans contain many more dependencies in prose. Every one of +the **105 waiting tasks** in the fleet has an empty structured `blocking_reason`. +All 287 open tasks have no API `assignee`; workplans often name owners in +frontmatter or prose, so this is a dispatchability gap, not proof of ownerless work. +**23 of 41 active plans have no task in progress**. That is a review signal, +not an automatic instruction to close or demote them. + +All 94 canonical plans show `manual` execution and launch metadata. This does +**not** mean no automation exists: [STATE-WP-0079](../../../state-hub/workplans/STATE-WP-0079-retirement-strangler.md) +records that the old workplan launch route was retired because Activity Core +never consumed it. Factory work must enter the supported ActivityDefinition / +`ops_run` route with explicit admission. Toggling a Hub workplan flag cannot +create an execution path. + +**Remedy:** initially normalize only the selected factory chain. Each blocking +task needs the supplying owner task, precise return evidence, next action, +review/expiry condition and whether human action is actually required. Preserve +that information in owning source files and project dependency references; use +existing projection support where available. Do not add another scheduler or +permanent queue to the retiring State Hub. Generate views from those records. + +### 2. Human attention is consumed by stale and incomplete signals + +Of nineteen `needs_human` flags, **seventeen are terminal tasks** (sixteen done, +one cancelled). Only two are on open tasks. Meanwhile the current owner records +describe real attended custody and verification needs that do not appear in +that queue. Thirteen canonical open plans have no `backing_synced_at`; another +27 have a recorded sync older than seven days. Source status agreement makes +this a provenance/freshness problem, not proof that forty plans are wrong. + +Four retired open rows inflate the portfolio: three historical Railiance +Platform identities and the Custodian's retired August 25 ad-hoc identity. +Three non-retired terminal plans also contain open tasks (`SAND-WP-0003`, +`SAND-WP-0005`, `REUSE-WP-0019`); verify source and residual disposition before +changing anything. + +The session-close `statehub fix-consistency` check independently returned +**13 assessment failures and 63 warnings** in existing Custodian records: +ten archived CUST-WP-0054 task UUID references, two archived workplan UUID +references, and the retired open ad-hoc identity account for the failures. +It reported zero automation errors and synchronized 75/77 bindings, but it did +**not** pass. The [check receipt](2026-09-08-helixforge-factory/consistency-check.json) +is additional evidence that a healthy API and matching open-plan statuses are +insufficient to establish full historical projection consistency. Existing live +intake [CUST-IN-0017](../../intakes.md) already owns these exact failures and the +prefix conflict; return this observation there during adoption rather than +creating another cleanup workplan. + +**Remedy:** review terminal flags and retired identities once through the owning +reconciliation path; preserve history. Present a small, prepared human queue of +actual decisions and attended actions. Batch compatible owner ceremonies when +their prerequisites are ready, with separate grants and receipts. Measure +operator minutes and repeated handoffs, not just the number of closed plans. + +### 3. Integration contracts are proved too late + +[SECRETS-WP-0009](../../../secrets-engine/workplans/SECRETS-WP-0009-glas-claude-native-delivery.md) +records three concrete discoveries from real owner integration: a missing +tenant, disagreement over normalized request digests, and fixtures that rebuilt +inputs from the expected enriched output. The September 7 correction says the +digest normalization rule was already published; that issue is resolved and +must not be charged again as an outstanding flex-auth dependency. + +[AUDIT-WP-0009-T09](../../../audit-core/workplans/AUDIT-WP-0009-evidence-role-conformance.md) +was reprioritized after an inverted dependency was recognized: approval-engine +could not start without its audit sender, although the task had been described +as nonblocking because approval-engine was not yet emitting. The correction is +already recorded. Retelling it as a current unresolved priority dispute would +create more coordination work. + +**Remedy:** pin a small cross-owner compatibility set and test real request, +response, credential, admission and completion artifacts early. Require both a +successful path and meaningful denial/retry cases. Consume the existing Glas +handoff packet; do not open a second round of generic owner interviews. + +### 4. Locally finished components obscure the missing operating result + +[GLAS-WP-0012](../../../glas-harness/workplans/GLAS-WP-0012-first-local-profile-production-proof.md) +is still blocked on first real-profile acceptance; [GLAS-WP-0015](../../../glas-harness/workplans/GLAS-WP-0015-production-dependency-coordination.md) +already coordinates its seven owner interfaces. [APPROVAL-WP-0002](../../../approval-engine/workplans/APPROVAL-WP-0002-production-readiness-and-consumer-adoption.md) +has a published immutable image, but its September 7 review records no deployed +service and outstanding identity/audit inputs. + +**Remedy:** use one acceptance ledger linking existing child work and three +distinct evidence levels: source implemented, deployed and exercised, useful +outcome accepted. Close the project only at the third level with repeated +operating evidence. A model-created `SMOKE.md` is a boundary proof; follow it +with a user-valued capability change, release and reuse evidence. + +### 5. Concurrent migrations and presentation work compete with the factory path + +Hub replacement, security-layer amendments, repository renames, HA, retained +CoulombCore cleanup and publication have legitimate owners and goals. They are +not all prerequisites for one internal factory. The community/publication +cohort alone has 38 open tasks; its commercial importance should be evaluated +explicitly alongside the fifteen direct execution tasks, rather than inferred +from a shared HelixForge name. + +**Remedy:** adopt a factory work-in-progress limit: one integrated delivery +item plus at most two prerequisite closures at a time, with an explicit incident +exception. Keep essential operations and security response running. Defer +optional factory expansion, broad renames, full HA, additional model/runtime +families and community automation until the pilot demonstrates delivery. Retain +the current healthy State Hub service while owner migrations meet their own +gates. Avoid another all-estate rename or documentation cleanup programme. + +## The actual critical path + +This graph is the proposed acceptance sequence, reconstructed from the owner +records. It is not a claim that all these edges are already represented in the +Hub. The local Glas proof must be followed by deployment-specific Railiance +proof; its localhost profile cannot be promoted by changing a label. + +```mermaid +flowchart TD + C[Admit service-client custody] --> K[Prove KeyCape approval clients] + A[Admit audit sender and delivery] --> P[Deploy and verify approval-engine] + K --> P + P --> S[Activate native credential lane] + S --> G[Accept real Glas profile] + R[Install pinned runtime and owner policy] --> G + G --> H[Prove current worker on Railiance] + Q[Deploy queue and repository contracts] --> H + H --> D[Useful capability change and independent CI] + D --> B[Immutable artifact and governed Railiance release] + B --> O[Repeat deliveries, recovery and cost observation] +``` + +| Priority / gate | Existing ownership | Required return and boundary | +| --- | --- | --- | +| Immediate operational risk | `NK-WP-0033`, `NK-WP-0034`, `RPF-WP-0027` | Finish the repaired identity verification receipt and explicit predecessor disposition. Assess overlap before extending a privileged factory lane. The recorded defect is concrete; do not claim the full credential exposure incident closed. | +| Factory identity and audit admission | `KEY-WP-0013-T02`, `AUDIT-WP-0009-T09`, `APPROVAL-WP-0002-T01/T03`; custody owner `railiance-platform` | Exact service clients and consumer-side delivery, agreed audit tenant/redaction policy, admitted sender credential, rollout and restart/restore proof. Glas's platform handoff still lacks a recorded custody return. Link the exact custody record before activation; do not invent a grant from a generic routing match. | +| Native execution credentials | `SECRETS-WP-0009-T03`, linked `SECRETS-WP-0007/0008` | September 7 evidence narrows the remaining external dependency to the approval claim endpoint. Verify claim/consume and actual protected delivery once the service exists. Keep broader engine conformance separate unless its acceptance actually gates this action. | +| Profile acceptance | `SAND-WP-0015-T04`, `GLAS-WP-0012-T02–T06`; coordinator `GLAS-WP-0015-T03` | Protected installation, exact actor/project/profile binding, real provider execution, artifact, denial and teardown receipts. Pinned binary startup and owner transport are already evidenced at candidate level. | +| Railiance worker closure | `REINAH-WP-0003-T05/T06`, `ACTIVITY-WP-0032-T05`, `ACTIVITY-WP-0035-T08`, `ACTIVITY-WP-0036-T04` | Current deployed versions, natural claim/heartbeat/close, controlled late-close rejection, repository acceptance and replay/cleanup. Source heartbeat timing was corrected; return the production trace. | +| Repeated software delivery | HelixForge acceptance owner; source repo; `railiance-enablement`, `railiance-forge`, concrete `rapp-*` / `reef-*` owners | Adopt a bounded implementation record for the chosen pilot after scope selection. Join intent → granted change → CI → immutable artifact → authorized release → service smoke and reuse record. Existing plans do not yet own this whole result. | + +Admission does not require completing the entire audit roadmap: AUDIT-WP-0009 +explicitly separates sender admission from attestation freshness, heartbeat and +reconciliation claims. Full operating acceptance must address those later +obligations or accurately bound its claims. Likewise OpenBao source deletion, +public UI retraction and factory credential delivery are distinct gates. + +## Proposed workplan and first operating target + +The complete draft is [HFACT-WP-0001](../proposals/prj-helixforge-factory/workplans/HFACT-WP-0001-establish-internal-factory.md), +with [goal and measurable gates](../proposals/prj-helixforge-factory/GOAL.md). +It is prepared as a dedicated project-repository packet, following +[ADR-005](../../canon/architecture/adr-005-cross-repo-workplans-project-repos.md). +The packet is retained here for review; it has not been instantiated or +registered as another live programme. Existing owner statuses remain intact. +Project adoption is its first task. The permanent product home remains +`helix-forge`; the temporary project coordinates only the missing factory outcome. + +Suggested sequencing, with estimates rather than commitments: + +| Stage | Completion condition | Rough effort | +| --- | --- | --- | +| Select and normalize | One internal tenant, one pilot service/capability, acceptance owner, execution/spend envelope and exact prerequisite records | 2–3 engineering days | +| Close owner prerequisites | Identity/audit/approval/native delivery and installed runtime proven through current contracts | 4–8 engineering days, plus owner/attended waiting time | +| Prove delivery on Railiance | Current profile and worker, useful code change, independent CI, artifact, authorized release and rollback | 5–8 engineering days | +| Establish operation | Recovery and observability proof, repeatable intake, measurements and acceptance review | 3–5 engineering days plus a 14-calendar-day observation window | + +This is roughly **14–24 engineering days plus observation and external waiting**. +A 4–6-week planning window is plausible with two coordinated implementation +tracks and available owners; there is no measured delivery rate or capacity +commitment that makes it a forecast. Do not translate 264 task rows into dates. + +Proposed exit: at least five genuinely useful accepted changes across two +repositories during fourteen days, at least one software service release on +Railiance, and a capability reused or consumed by the second repository. +Record every admitted attempt; target ≥80% accepted without operator repair, +≤30 minutes median human handling per accepted change, and ≤30 minutes/day +routine factory operation. Measure security/recovery ceremonies separately and +also include them in total founder load. These are proposed targets, not current +performance. Use `UPC-WP-0003` for the broader company-load objective; a short +factory pilot cannot prove its ≥30-day commercial/company gates. + +The first next action is therefore a **prepared custody and audit admission +closure through GLAS-WP-0015**, while the factory owner selects the first useful +capability and its acceptance test. Neither action requires reopening resolved +tenant/digest questions or completing all 94 open plans. + + +Execution subsequently authorized on 2026-09-08: see the +[implementation return](2026-09-08-helixforge-factory-followthrough.md) and +[current project pointer](../proposals/prj-helixforge-factory/README.md). The +baseline above remains the dated assessment, not a refreshed fleet total. diff --git a/docs/assessments/2026-09-08-helixforge-factory/README.md b/docs/assessments/2026-09-08-helixforge-factory/README.md new file mode 100644 index 0000000..ee2e902 --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/README.md @@ -0,0 +1,63 @@ +# Assessment evidence and reproduction + +Snapshot: 2026-09-08, before this assessment was authored. Exact HTTP retrieval +times and SHA-256 hashes of the temporary raw responses are in `baseline.json`. +Raw responses remain outside the repository; this folder retains selected +non-secret metadata and source fingerprints rather than full task/message bodies. +This is a dated assessment snapshot, not another live backlog. + +Files: + +- `baseline.json`: fleet totals, normalization, quality signals and capture provenance. +- `open-workplans.csv`: all 98 raw open workplans, including the four explicitly + retired identities; local source resolution, statuses and task counts. +- `source-records.json`: 94 canonical open records plus local KG-WP-0005, + with exact source paths, hashes and parsed task counts. +- `cohorts.json`: disjoint repo membership and aggregated load. +- `dependency-coverage.json`: all 94 dependency responses, including empty ones. +- `human-flags.csv`: the nineteen flagged tasks' lifecycle metadata. +- `checkout-provenance.json`: principal source revisions and pre-existing dirty state. +- `consistency-check.json`: session-close consistency result, including thirteen + existing-record assessment failures; this check did not pass. + +Read-only reproduction against the current Hub will produce a **new snapshot**: + +1. Fetch `/openapi.json`, `/repos/`, `/workplans/`, `/tasks/`, `/tasks/counts`, + `/intakes/` from `http://127.0.0.1:8000`. Send + `X-StateHub-Component: the-custodian.factory-assessment` on follow-up requests. + Inspect the API contract for pagination and drain all pages if required. + The captured contract had no limit for `/workplans/` or `/repos/`; `/tasks/` + defaults to no limit and accepts explicit limit/offset. Verify list totals + against `/tasks/counts`. The initial capture did not set the attribution header. +2. Open workplans are statuses `proposed`, `ready`, `active`, `blocked`, `backlog`. + Raw terminal statuses are `finished`, `archived`. Canonical planning counts + additionally exclude slugs containing the explicit `@retired-` marker. + Do not infer retirement from title similarity or age. +3. Join tasks by `workplan_id`. Open tasks have status `wait`, `todo`, `progress`. + Count terminal-parent and retired-parent tasks separately. Raw open tasks: + 287 = 264 canonical-open-parent + 7 retired-open-parent + 16 terminal-parent. +4. Resolve local sources from registered paths and file UUIDs, falling back to + canonical workplan identifiers within the same repo. Parse frontmatter and + all fenced `task` blocks (including multiple blocks under a heading). + Compare statuses; retain file hashes. Legacy `done`/`completed` workplan + statuses are terminal in historic files, not hundreds of additional open plans. + Invalid historic YAML, missing paths and registry aliases prevent claiming a + complete independently validated source-only census. +5. For each canonical open plan fetch `/workplans/{uuid}/dependencies/`. + Report returned edges and empty responses. Coverage measures this API view, + not dependency mentions in source or intake/message relationships; do not + assume edge direction without inspecting `from_workplan_id`/`to_workplan_id`. +6. Group repositories exactly as in `cohorts.json`. Each canonical open plan + occurs once. Railiance membership is `railiance-*`, `rail-*`, `rapp-*`, + `reef-*`; the other named sets are explicit. No portfolio-wide priority or + classification was modified to construct these analytical groups. +7. Ages use 2026-09-08 minus the declared date. Report missing timestamps + separately. Sync dates can refresh without progress; source `updated` can be + stale despite recent body additions. Neither measures blocked duration. + +Validation performed: task-count reconciliation; 98 = 94 + 4; all six cohort +totals sum to 94 plans/264 tasks/27 blocked; 94 canonical source statuses match; +19 human flags split into 17 terminal and two open; all dependency requests +succeeded. Principal checkouts were compared with **cached** upstream refs only. +Runtime outcomes cited in the report are owner-recorded evidence, not a fresh +live acceptance test by this assessment. diff --git a/docs/assessments/2026-09-08-helixforge-factory/baseline.json b/docs/assessments/2026-09-08-helixforge-factory/baseline.json new file mode 100644 index 0000000..b80613a --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/baseline.json @@ -0,0 +1,114 @@ +{ + "as_of_date": "2026-09-08", + "hub_repos": 135, + "hub_workplans": 1314, + "hub_workplan_statuses": { + "finished": 1164, + "active": 44, + "proposed": 15, + "ready": 6, + "blocked": 28, + "archived": 52, + "backlog": 5 + }, + "hub_tasks": 7102, + "hub_task_statuses": { + "done": 6552, + "cancel": 263, + "todo": 150, + "wait": 105, + "progress": 32 + }, + "hub_open_workplans": 98, + "hub_open_workplan_repos": 49, + "retired_open_identities": 4, + "canonical_open_workplans": 94, + "canonical_open_workplan_statuses": { + "active": 41, + "proposed": 15, + "ready": 6, + "blocked": 27, + "backlog": 5 + }, + "canonical_open_workplan_tasks": 264, + "open_tasks_in_terminal_workplans": 16, + "tasks_without_workplan_row": 0, + "human_flag_statuses": { + "todo": 1, + "done": 16, + "cancel": 1, + "wait": 1 + }, + "open_tasks_human_flagged": 2, + "open_tasks_unassigned": 287, + "open_tasks_with_blocking_reason": 0, + "wait_tasks_with_blocking_reason": 0, + "canonical_active_without_progress_task": 23, + "canonical_active_without_open_task": 0, + "canonical_open_zero_tasks": 1, + "canonical_open_execution_states": { + "manual": 94 + }, + "canonical_open_launch_modes": { + "manual": 94 + }, + "canonical_open_missing_sync": 13, + "canonical_open_sync_older_7d": 27, + "canonical_local_open_age_ge_30d": 6, + "canonical_open_task_statuses": { + "todo": 136, + "progress": 28, + "wait": 100 + }, + "all_canonical_open_resolve_locally": true, + "all_canonical_open_statuses_agree": true, + "additional_local_open_record": { + "repo": "kings-guard", + "id": "KG-WP-0005", + "status": "active", + "included_in_hub_baseline": false + }, + "human_flags_terminal": 17, + "task_counts_endpoint_total": 7102, + "intakes": { + "open": 54, + "routed": 8, + "closed": 5, + "open_origin_residual": 31 + }, + "dependency_queries": 94, + "dependency_queries_with_edges": 4, + "dependency_edges_returned": 4, + "capture_inputs": { + "repos": { + "endpoint": "/repos/", + "retrieved_at_utc": "2026-09-08T07:46:47.060627+00:00", + "sha256": "a167d316d609550df085881e475813f3a3ddd0b4bfb3f290867e4a145376422f" + }, + "workplans": { + "endpoint": "/workplans/", + "retrieved_at_utc": "2026-09-08T07:46:50.096102+00:00", + "sha256": "3cfcc721e96b50dd42f2f42e9f4535fa848ff3d958d336135887dcc47705ced9" + }, + "tasks": { + "endpoint": "/tasks/", + "retrieved_at_utc": "2026-09-08T07:46:52.369959+00:00", + "sha256": "5484cb5f35be0590892db23ddf7d24b37211d34a7e4b1d3e1e4d9356e7d379d2" + }, + "dependencies": { + "endpoint": "/workplans/{id}/dependencies/", + "retrieved_at_utc": "2026-09-08T07:51:46.695216+00:00", + "sha256": "c41cbf67b4c51ca248e815578a3552a5829a38a68a1f30568c490a81a9d96f41" + }, + "intakes": { + "endpoint": "/intakes/", + "retrieved_at_utc": "2026-09-08T07:51:51.435028+00:00", + "sha256": "2bd84af826a13456033b951ca7717e334135ec488a3e7157beadff3fd03a7278" + }, + "task-counts": { + "endpoint": "/tasks/counts", + "retrieved_at_utc": "2026-09-08T07:51:46.819089+00:00", + "sha256": "dfcec41a55200302494261352d541cbbca4317875a5b605978cfd7c975d71106" + } + } +} diff --git a/docs/assessments/2026-09-08-helixforge-factory/checkout-provenance.json b/docs/assessments/2026-09-08-helixforge-factory/checkout-provenance.json new file mode 100644 index 0000000..6342c4c --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/checkout-provenance.json @@ -0,0 +1,146 @@ +[ + { + "repo": "the-custodian", + "head": "4df570ac799bdaa67bc21d1b74e97be94c86bb6c", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "helix-forge", + "head": "fdf5af121ca906df6c657aac6b89c5b07b5818f2", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "glas-harness", + "head": "57b98df52c7bc5115047300d94bdaad24b3b4730", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "sand-boxer", + "head": "174dba17b640c7a168707654f92d991910b28093", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "secrets-engine", + "head": "3a19069b4b56049a9c92c2662479099827b17c36", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "key-cape", + "head": "2ab70924a167b628acf27a49a7c849262d1c2585", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "approval-engine", + "head": "d5d1e410359d6a3580e049b7daa9838b1bae332a", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "audit-core", + "head": "633f68b81b264d3a39dd56e0ad9a48bf8fd03de7", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "activity-core", + "head": "4083f3195a1e84c2f0deeeadaa49c0cc58b43358", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "rein-aharness", + "head": "1429db5ad4c83331b6375349ffde1eb13af9575b", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "railiance-master", + "head": "5ffd7d1b40d56249f490a318e728047fd3517c4c", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "railiance-platform", + "head": "805e0e5a2b6263e4601c39230eb76d2f1bc7243a", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "railiance-forge", + "head": "e395e5e9c196fe7cea9cd2be513554e493e675ee", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "railiance-enablement", + "head": "f91a5298cb9ad07b7bc9c488a7429f89c55f651d", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "net-kingdom", + "head": "46455439cfbb24fc5d187403c8f9f4465fccc274", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "coordination-engine", + "head": "628f984a10110904e412d038fc43ecc775a61086", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "state-hub", + "head": "ccb285fc40d66125e485723fda851bbf75b90d14", + "branch": "main", + "status": "?? docs/evidence/legacy-meter-weekly-review-20260906.json\n?? docs/evidence/legacy-meter-weekly-review-20260907.json\n?? docs/evidence/legacy-meter-weekly-review-20260908.json", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + }, + { + "repo": "prj-unattended-progress-company", + "head": "2901cc98b6c3d3bbaeae6081e2c4f2b5b95ebb6d", + "branch": "main", + "status": "", + "upstream": "origin/main", + "ahead_behind_cached": "0\t0" + } +] diff --git a/docs/assessments/2026-09-08-helixforge-factory/cohorts.json b/docs/assessments/2026-09-08-helixforge-factory/cohorts.json new file mode 100644 index 0000000..d4ea9bf --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/cohorts.json @@ -0,0 +1,128 @@ +[ + { + "cohort": "Identity, policy, custody and audit", + "workplans": 35, + "statuses": { + "active": 14, + "proposed": 4, + "ready": 2, + "blocked": 13, + "backlog": 2 + }, + "open_tasks": 93, + "repos": [ + "approval-engine", + "audit-core", + "flex-auth", + "gate-house", + "key-cape", + "net-kingdom", + "ops-mason", + "ops-warden", + "secrets-engine", + "tenant-engine", + "whitehat-security" + ] + }, + { + "cohort": "Agent execution and coordination", + "workplans": 9, + "statuses": { + "active": 7, + "blocked": 2 + }, + "open_tasks": 15, + "repos": [ + "activity-core", + "coordination-engine", + "glas-harness", + "rein-aharness", + "sand-boxer" + ] + }, + { + "cohort": "Hub consolidation and work projection", + "workplans": 7, + "statuses": { + "backlog": 1, + "blocked": 1, + "proposed": 2, + "active": 2, + "ready": 1 + }, + "open_tasks": 26, + "repos": [ + "core-hub", + "hub-core", + "issue-core", + "state-hub" + ] + }, + { + "cohort": "Publishing and community", + "workplans": 7, + "statuses": { + "active": 4, + "proposed": 2, + "ready": 1 + }, + "open_tasks": 38, + "repos": [ + "fluid-core", + "fluid-telegram", + "hall-of-helix", + "pqrst-practice" + ] + }, + { + "cohort": "Railiance runtime, packages and recovery", + "workplans": 23, + "statuses": { + "active": 10, + "blocked": 10, + "ready": 1, + "proposed": 2 + }, + "open_tasks": 43, + "repos": [ + "railiance-cluster", + "railiance-fabric", + "railiance-infra", + "railiance-master", + "railiance-platform", + "railiance-telemetry", + "rapp-canned-prompts", + "rapp-core-hub", + "rapp-openbao", + "rapp-postgres", + "rapp-qonto", + "rapp-telemetry", + "rapp-tenant-engine", + "reef-railiance", + "reef-storage" + ] + }, + { + "cohort": "Other product, commercial and research work", + "workplans": 13, + "statuses": { + "blocked": 1, + "active": 4, + "proposed": 5, + "ready": 1, + "backlog": 2 + }, + "open_tasks": 49, + "repos": [ + "adaptive-pricing", + "fin-hub", + "info-tech-canon", + "markitect-main", + "prj-forgejo-org-refactor", + "prj-unattended-progress-company", + "reuse-surface", + "soul-frame", + "test-driver" + ] + } +] diff --git a/docs/assessments/2026-09-08-helixforge-factory/consistency-check.json b/docs/assessments/2026-09-08-helixforge-factory/consistency-check.json new file mode 100644 index 0000000..82956fc --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/consistency-check.json @@ -0,0 +1,37 @@ +{ + "checked_at_utc": "2026-09-08T08:04:44.373626+00:00", + "command": "statehub fix-consistency", + "repo": "the-custodian", + "exit_code": 1, + "result": "ASSESSMENT FAIL", + "automation_errors": 0, + "assessment_failures": 13, + "warnings": 63, + "infos": 6, + "failure_groups": [ + { + "code": "C-03", + "count": 10, + "records": "CUST-WP-0054-T01 through T10", + "reason": "archived file task UUIDs absent from DB" + }, + { + "code": "C-03", + "count": 2, + "records": "CUST-WP-0057 and CUST-WP-0058", + "reason": "archived file workplan UUIDs absent from DB" + }, + { + "code": "C-07", + "count": 1, + "record": "adhoc-2026-08-25@retired-20260827", + "reason": "nonclosed retired DB identity without matching source record" + } + ], + "reported_actions": [ + "bindings synced 75/77", + "three finished-workplan missing task UUID creations skipped", + "push: pushed" + ], + "scope": "Reported diagnostics concern existing root/archived Custodian records, not the staged project packet. The proposed factory workplan was not registered." +} diff --git a/docs/assessments/2026-09-08-helixforge-factory/dependency-coverage.json b/docs/assessments/2026-09-08-helixforge-factory/dependency-coverage.json new file mode 100644 index 0000000..4671240 --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/dependency-coverage.json @@ -0,0 +1,610 @@ +[ + { + "workplan_id": "63665674-6880-593e-96e6-bab3211b1352", + "repo": "net-kingdom", + "slug": "nk-wp-0033", + "dependencies": [] + }, + { + "workplan_id": "804c588c-f47a-50c4-bdd7-51b24bbf9539", + "repo": "flex-auth", + "slug": "flex-wp-0022", + "dependencies": [ + { + "id": "19de567a-5058-42fa-bfb2-955df489cdc8", + "from_workplan_id": "804c588c-f47a-50c4-bdd7-51b24bbf9539", + "to_workplan_id": "b01f655e-f71a-50ae-b110-178557f07c63", + "to_task_id": null, + "relationship_type": "blocks", + "description": null, + "created_at": "2026-09-06T19:38:41.487199Z", + "updated_at": "2026-09-06T19:38:41.487199Z" + } + ] + }, + { + "workplan_id": "ad011f92-786c-51ad-b3f6-c06ad77e7af7", + "repo": "flex-auth", + "slug": "flex-wp-0023", + "dependencies": [ + { + "id": "047f24b0-8689-4221-b2fd-2a47677707c8", + "from_workplan_id": "ad011f92-786c-51ad-b3f6-c06ad77e7af7", + "to_workplan_id": "b01f655e-f71a-50ae-b110-178557f07c63", + "to_task_id": null, + "relationship_type": "blocks", + "description": null, + "created_at": "2026-09-06T20:45:23.668474Z", + "updated_at": "2026-09-06T20:45:23.668474Z" + } + ] + }, + { + "workplan_id": "90577acd-6910-548d-a13e-1dbfdfb8ed27", + "repo": "flex-auth", + "slug": "flex-wp-0024", + "dependencies": [ + { + "id": "f23fdf85-03b6-4e3e-bbc9-9478576cff51", + "from_workplan_id": "90577acd-6910-548d-a13e-1dbfdfb8ed27", + "to_workplan_id": "b01f655e-f71a-50ae-b110-178557f07c63", + "to_task_id": null, + "relationship_type": "blocks", + "description": null, + "created_at": "2026-09-06T21:36:47.780484Z", + "updated_at": "2026-09-06T21:36:47.780484Z" + } + ] + }, + { + "workplan_id": "f9a657ce-67b4-5d25-9933-e0fcb2c20b1c", + "repo": "flex-auth", + "slug": "flex-wp-0025", + "dependencies": [] + }, + { + "workplan_id": "965ad365-6b81-50a1-a2a3-2d0c1fcce0b4", + "repo": "net-kingdom", + "slug": "nk-wp-0027", + "dependencies": [] + }, + { + "workplan_id": "9d7b04f9-3803-5613-b7a5-8bd606c77f5a", + "repo": "net-kingdom", + "slug": "nk-wp-0031", + "dependencies": [] + }, + { + "workplan_id": "04685f94-1991-5e62-80d2-5669913e99fc", + "repo": "net-kingdom", + "slug": "net-kingdom-nk-wp-0035", + "dependencies": [] + }, + { + "workplan_id": "ae3ff76f-883d-5e2f-b6aa-144d61e8fdef", + "repo": "ops-warden", + "slug": "warden-wp-0034", + "dependencies": [ + { + "id": "31553846-82b1-4ca8-8ba9-5fd363f3f22d", + "from_workplan_id": "ae3ff76f-883d-5e2f-b6aa-144d61e8fdef", + "to_workplan_id": "da3367d5-890c-52c6-aa54-1bdd0f277342", + "to_task_id": null, + "relationship_type": "blocks", + "description": null, + "created_at": "2026-08-31T22:49:17.609862Z", + "updated_at": "2026-08-31T22:49:17.609862Z" + } + ] + }, + { + "workplan_id": "a660ed65-700e-5b54-8d91-a556b73518f0", + "repo": "fluid-telegram", + "slug": "ft-wp-0001", + "dependencies": [] + }, + { + "workplan_id": "291005a5-d474-5c94-8abd-819f682dde9f", + "repo": "fluid-core", + "slug": "fluid-wp-0008", + "dependencies": [] + }, + { + "workplan_id": "d4d02dbf-3974-502d-8b87-b776fc63e17e", + "repo": "net-kingdom", + "slug": "nk-wp-0009", + "dependencies": [] + }, + { + "workplan_id": "b6459dd0-fc4f-54a4-a2e9-d7b83cff6c6e", + "repo": "fluid-core", + "slug": "fluid-wp-0009", + "dependencies": [] + }, + { + "workplan_id": "21528e8d-a049-523d-9ae1-da7a27cb8bbf", + "repo": "ops-warden", + "slug": "warden-wp-0027", + "dependencies": [] + }, + { + "workplan_id": "0d003df3-f7d3-5063-8ca0-e1e33f7df74a", + "repo": "key-cape", + "slug": "key-wp-0014", + "dependencies": [] + }, + { + "workplan_id": "c1a9b1cc-2ff0-566a-b544-1a2ef967fc0d", + "repo": "key-cape", + "slug": "key-wp-0009", + "dependencies": [] + }, + { + "workplan_id": "6e815d88-b0e3-5ce0-be5d-13ab15917f7f", + "repo": "key-cape", + "slug": "key-wp-0013", + "dependencies": [] + }, + { + "workplan_id": "11874f32-ac36-5bb9-a0a5-e7a259f5972c", + "repo": "rapp-canned-prompts", + "slug": "rcp-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "5e0db595-2f0e-5388-9413-7d4d5a4a2ef5", + "repo": "hall-of-helix", + "slug": "hoh-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "e861bad8-8b92-5963-b554-e9b6fa043acb", + "repo": "rapp-postgres", + "slug": "rapp-postgres-wp-0006", + "dependencies": [] + }, + { + "workplan_id": "31f7f8ea-7f73-516c-8877-f03a13f1db82", + "repo": "secrets-engine", + "slug": "secrets-wp-0006", + "dependencies": [] + }, + { + "workplan_id": "9c9e5164-b2f5-5ea2-a557-5368d65e9fe0", + "repo": "secrets-engine", + "slug": "secrets-wp-0008", + "dependencies": [] + }, + { + "workplan_id": "40ccc3b4-d046-5a58-8649-e7935f45c974", + "repo": "secrets-engine", + "slug": "secrets-wp-0009", + "dependencies": [] + }, + { + "workplan_id": "68a39be1-bd9c-5133-ad64-e7bca892aaf3", + "repo": "secrets-engine", + "slug": "secrets-wp-0007", + "dependencies": [] + }, + { + "workplan_id": "bf08c283-0f43-5a8d-9e63-17c4b96ded11", + "repo": "coordination-engine", + "slug": "coordination-wp-0004", + "dependencies": [] + }, + { + "workplan_id": "4fa25ad5-f5d0-5592-aa59-085f8ee3edaf", + "repo": "approval-engine", + "slug": "approval-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "cb7387d0-431d-56a2-bb7b-86a024aeeefb", + "repo": "tenant-engine", + "slug": "ten-wp-0012", + "dependencies": [] + }, + { + "workplan_id": "516ee5b9-685b-5986-88d2-bde66c2ba96c", + "repo": "net-kingdom", + "slug": "nk-wp-0032", + "dependencies": [] + }, + { + "workplan_id": "d76ddccc-00c8-548a-b141-2cd660fa38da", + "repo": "net-kingdom", + "slug": "nk-wp-0022", + "dependencies": [] + }, + { + "workplan_id": "c87e142c-4eda-5c1b-84a9-ee5a848f3f63", + "repo": "net-kingdom", + "slug": "nk-wp-0034", + "dependencies": [] + }, + { + "workplan_id": "1075448f-d533-5f9e-94b7-c3adfe151a07", + "repo": "net-kingdom", + "slug": "nk-wp-0011", + "dependencies": [] + }, + { + "workplan_id": "99a661a8-b36c-5c1c-b78b-1e8930bcd0a9", + "repo": "flex-auth", + "slug": "flex-wp-0020", + "dependencies": [] + }, + { + "workplan_id": "94c02b1f-66ed-588d-bdd7-7158107b85fb", + "repo": "glas-harness", + "slug": "glas-wp-0015", + "dependencies": [] + }, + { + "workplan_id": "170bf1ae-337f-5553-8d1e-03b07100e08f", + "repo": "glas-harness", + "slug": "glas-wp-0012", + "dependencies": [] + }, + { + "workplan_id": "d3f12387-fd23-58f0-b979-9c811507614d", + "repo": "sand-boxer", + "slug": "sand-wp-0015", + "dependencies": [] + }, + { + "workplan_id": "b616d1cd-208f-5ecf-a4a0-a028396422c4", + "repo": "sand-boxer", + "slug": "sand-wp-0014", + "dependencies": [] + }, + { + "workplan_id": "f4640325-e89c-591d-b58e-ec6b087900ac", + "repo": "railiance-platform", + "slug": "rpf-wp-0015", + "dependencies": [] + }, + { + "workplan_id": "bb326ebb-a313-549e-b35f-1bf17e1c58fd", + "repo": "railiance-platform", + "slug": "rpf-wp-0029", + "dependencies": [] + }, + { + "workplan_id": "975db491-5412-5e27-8e34-14a2417bb039", + "repo": "railiance-platform", + "slug": "rpf-wp-0035", + "dependencies": [] + }, + { + "workplan_id": "b2c25a01-4a80-55c1-90cf-8538000f7e0e", + "repo": "railiance-platform", + "slug": "rpf-wp-0027", + "dependencies": [] + }, + { + "workplan_id": "6dda6039-295e-5cac-aef6-3183c3218649", + "repo": "railiance-platform", + "slug": "rpf-wp-0025", + "dependencies": [] + }, + { + "workplan_id": "7beec1a7-aa82-5a36-9a66-6b60008a2455", + "repo": "railiance-platform", + "slug": "rpf-wp-0038", + "dependencies": [] + }, + { + "workplan_id": "ca639c3d-3a87-5fa4-ad13-6f2e014b0c84", + "repo": "railiance-platform", + "slug": "rpf-wp-0036", + "dependencies": [] + }, + { + "workplan_id": "13305ba8-33d8-56a4-af79-165092a02677", + "repo": "rapp-telemetry", + "slug": "rapp-telemetry-wp-0001", + "dependencies": [] + }, + { + "workplan_id": "54655357-74da-5f7f-8fa6-647d4c969f21", + "repo": "audit-core", + "slug": "audit-wp-0010", + "dependencies": [] + }, + { + "workplan_id": "a9a248b2-d26c-503e-a8fc-4f3675e6ed51", + "repo": "audit-core", + "slug": "audit-wp-0008", + "dependencies": [] + }, + { + "workplan_id": "46a96b03-bc08-53b5-9c93-4071adabf734", + "repo": "audit-core", + "slug": "audit-wp-0009", + "dependencies": [] + }, + { + "workplan_id": "08a5db92-7293-50d3-b589-55287b9850b3", + "repo": "railiance-telemetry", + "slug": "rtel-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "a331dc88-c9bc-5d2a-9ff1-2aa7e837c3bb", + "repo": "gate-house", + "slug": "gh-wp-0003", + "dependencies": [] + }, + { + "workplan_id": "b29261ba-c1e4-5533-8185-ab2d5b433685", + "repo": "info-tech-canon", + "slug": "info-wp-0019", + "dependencies": [] + }, + { + "workplan_id": "0d1beafd-e638-5bb9-b91d-13543ac42a04", + "repo": "reuse-surface", + "slug": "reuse-wp-0021", + "dependencies": [] + }, + { + "workplan_id": "6a875b19-5a76-55c1-bd1f-2f5005cd416b", + "repo": "pqrst-practice", + "slug": "pqrst-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "ccb87fa4-6381-5f22-b097-6e026f56a9c1", + "repo": "state-hub", + "slug": "cust-wp-0038", + "dependencies": [] + }, + { + "workplan_id": "ed077b62-7048-5752-bf65-f90471f45854", + "repo": "state-hub", + "slug": "state-wp-0079", + "dependencies": [] + }, + { + "workplan_id": "626cb2d7-9525-5712-be9e-93c1ed840fc5", + "repo": "rapp-core-hub", + "slug": "rappcorehub-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "b73f1e1a-efaf-5f2f-b916-2a3040e0242e", + "repo": "rapp-core-hub", + "slug": "rappcorehub-wp-0003", + "dependencies": [] + }, + { + "workplan_id": "3c8034fc-fd90-58f5-99bc-99b4f93e5ee1", + "repo": "hub-core", + "slug": "hub-wp-0011", + "dependencies": [] + }, + { + "workplan_id": "0d6e94f3-fd15-5f57-af41-60f0b862da5e", + "repo": "hub-core", + "slug": "hub-wp-0009", + "dependencies": [] + }, + { + "workplan_id": "05ebd06e-4af8-5f6c-918c-c143c1520e00", + "repo": "hub-core", + "slug": "hub-wp-0006", + "dependencies": [] + }, + { + "workplan_id": "6152c89b-a4f3-55b6-af0b-d57462b3c6f7", + "repo": "rapp-qonto", + "slug": "rapp-qonto-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "42a097db-1c24-558e-a724-030bb2b4443e", + "repo": "ops-warden", + "slug": "warden-wp-0037", + "dependencies": [] + }, + { + "workplan_id": "4015b46d-02f1-56ac-853e-87e8542cf0dd", + "repo": "ops-mason", + "slug": "mason-wp-0003", + "dependencies": [] + }, + { + "workplan_id": "e5656747-a974-581a-a3d4-4e6bb7262f4c", + "repo": "ops-mason", + "slug": "mason-wp-0004", + "dependencies": [] + }, + { + "workplan_id": "483e56d6-6601-5377-9066-66225214c046", + "repo": "ops-mason", + "slug": "mason-wp-0005", + "dependencies": [] + }, + { + "workplan_id": "f2373858-c932-5a4d-81b6-db9a3595135a", + "repo": "fluid-telegram", + "slug": "ft-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "eba2eff1-10a7-50a3-a70b-14e7d398f27f", + "repo": "rein-aharness", + "slug": "reinah-wp-0003", + "dependencies": [] + }, + { + "workplan_id": "b5c231e1-9d06-5772-95a7-01cc0bf62051", + "repo": "fluid-core", + "slug": "fluid-wp-0001", + "dependencies": [] + }, + { + "workplan_id": "256dad13-28b4-5361-ab8a-7d1373a5d14b", + "repo": "activity-core", + "slug": "activity-wp-0032", + "dependencies": [] + }, + { + "workplan_id": "fbcc10a9-bc1e-50b2-ba86-47adcb18666d", + "repo": "activity-core", + "slug": "activity-wp-0035", + "dependencies": [] + }, + { + "workplan_id": "01e6d5d4-6e1a-5f0d-81f0-ded97e0f71cd", + "repo": "activity-core", + "slug": "activity-wp-0036", + "dependencies": [] + }, + { + "workplan_id": "94b71ba3-998d-5166-9730-6beb5f595923", + "repo": "whitehat-security", + "slug": "whitehat-wp-0008", + "dependencies": [] + }, + { + "workplan_id": "fe26f070-70ca-55ba-92b3-3378929ba90f", + "repo": "whitehat-security", + "slug": "whitehat-wp-0006", + "dependencies": [] + }, + { + "workplan_id": "58a56363-3bda-50f7-8240-1e45131bc7d9", + "repo": "railiance-fabric", + "slug": "rail-fab-wp-0028", + "dependencies": [] + }, + { + "workplan_id": "e8b432af-43ae-517f-a69b-80d4f0db976d", + "repo": "fin-hub", + "slug": "fin-wp-0004", + "dependencies": [] + }, + { + "workplan_id": "e9413a20-5b11-50ff-ba21-15215841cf11", + "repo": "fin-hub", + "slug": "fin-wp-0006", + "dependencies": [] + }, + { + "workplan_id": "58432770-da19-5b72-a946-cacbe1eb24ca", + "repo": "fin-hub", + "slug": "fin-wp-0005", + "dependencies": [] + }, + { + "workplan_id": "c730a7e2-244e-558c-9ec1-66d04e275ff8", + "repo": "soul-frame", + "slug": "soul-wp-0008", + "dependencies": [] + }, + { + "workplan_id": "a7d0c934-75d7-53cc-a35b-6a789a2e0f14", + "repo": "railiance-master", + "slug": "rmaster-wp-0020", + "dependencies": [] + }, + { + "workplan_id": "81b17b8a-4b22-5510-8830-a8d19aed821e", + "repo": "prj-unattended-progress-company", + "slug": "upc-wp-0003", + "dependencies": [] + }, + { + "workplan_id": "8d47ba5f-0608-5f83-8b4b-7dee53ada6f6", + "repo": "prj-unattended-progress-company", + "slug": "upc-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "a6cf0a20-a3d5-56c6-8fc7-8cb167c71d66", + "repo": "prj-unattended-progress-company", + "slug": "upc-wp-0004", + "dependencies": [] + }, + { + "workplan_id": "c1dcd349-1a7a-51ae-8827-4ce96cfe0008", + "repo": "prj-forgejo-org-refactor", + "slug": "orgref-wp-0001", + "dependencies": [] + }, + { + "workplan_id": "8ac413ad-2f57-53e6-b586-c5bec9cfbd1f", + "repo": "reef-railiance", + "slug": "reef-railiance-wp-0003", + "dependencies": [] + }, + { + "workplan_id": "df859d65-c6ee-5058-a662-ad74eb82d3d2", + "repo": "rapp-openbao", + "slug": "rapp-openbao-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "16da36fe-5a10-522b-b6d6-02dbb6de6c14", + "repo": "railiance-cluster", + "slug": "three-phoenix-ha-cluster", + "dependencies": [] + }, + { + "workplan_id": "9cc1abf3-2ab0-54a4-a250-83f382a49441", + "repo": "core-hub", + "slug": "core-wp-0010", + "dependencies": [] + }, + { + "workplan_id": "5ea28f8f-376c-5230-8bb7-ca871c1a75f4", + "repo": "railiance-infra", + "slug": "rail-ho-wp-0012", + "dependencies": [] + }, + { + "workplan_id": "5738f113-1c4e-5d27-95b2-b6655e0b7279", + "repo": "railiance-infra", + "slug": "rail-ho-wp-0011", + "dependencies": [] + }, + { + "workplan_id": "543e6398-d2cb-5105-977e-b90461adac3e", + "repo": "adaptive-pricing", + "slug": "adaptive-wp-0010", + "dependencies": [] + }, + { + "workplan_id": "ec2896aa-9226-5516-a537-2de02138949f", + "repo": "rapp-tenant-engine", + "slug": "rapp-tenant-engine-wp-0001", + "dependencies": [] + }, + { + "workplan_id": "36a082df-1288-567d-9a0b-f2e0f292786c", + "repo": "test-driver", + "slug": "td-wp-0003", + "dependencies": [] + }, + { + "workplan_id": "af6ed97f-fc45-5fc0-b8e9-6010c217808f", + "repo": "reef-storage", + "slug": "reef-storage-wp-0002", + "dependencies": [] + }, + { + "workplan_id": "e03ef262-5284-5dd3-92d2-dbd85c6b6159", + "repo": "markitect-main", + "slug": "testdrive-jsui-publication", + "dependencies": [] + }, + { + "workplan_id": "4d465264-cbe1-56ba-84ed-bd580b649b76", + "repo": "issue-core", + "slug": "issue-wp-0006", + "dependencies": [] + } +] \ No newline at end of file diff --git a/docs/assessments/2026-09-08-helixforge-factory/human-flag-corrections.json b/docs/assessments/2026-09-08-helixforge-factory/human-flag-corrections.json new file mode 100644 index 0000000..59b3f19 --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/human-flag-corrections.json @@ -0,0 +1,66 @@ +{ + "at": "2026-09-08T12:04:21.089343+00:00", + "scope": "Correct four human-needed projection flags to explicit published source; task status and historical notes retained. Other 13 terminal flags require source/residual disposition and were not cleared.", + "changes": [ + { + "task_id": "RAIL-HO-WP-0005-T02", + "hub_id": "f88115bf-4f99-49ef-a415-0b23750141b3", + "source_url": "https://forgejo.coulomb.social/coulomb/railiance-infra/raw/branch/main/workplans/archived/260714-RAIL-HO-WP-0005-forgejo-production-migration.md", + "source_status": "done", + "source_needs_human": false, + "before": { + "needs_human": true, + "intervention_note": "Hostname decided: forgejo.coulomb.social on railiance01 (2026-07-03). Remaining T02: SMTP, package scope, Actions runner model, backup/retention, cutover mode. See the-custodian/docs/forgejo-production-decisions.md" + }, + "after": { + "needs_human": false, + "status": "done" + } + }, + { + "task_id": "RAIL-HO-WP-0005-T06", + "hub_id": "417faa4d-eab8-4247-9485-4f80e5d5b7ff", + "source_url": "https://forgejo.coulomb.social/coulomb/railiance-infra/raw/branch/main/workplans/archived/260714-RAIL-HO-WP-0005-forgejo-production-migration.md", + "source_status": "done", + "source_needs_human": false, + "before": { + "needs_human": true, + "intervention_note": "Needs approved SMTP credentials/sender domain and a controlled account to verify password reset, account recovery, and emergency admin access." + }, + "after": { + "needs_human": false, + "status": "done" + } + }, + { + "task_id": "RAIL-HO-WP-0005-T11", + "hub_id": "b1b66687-ca33-4971-b312-743c8e059c5e", + "source_url": "https://forgejo.coulomb.social/coulomb/railiance-infra/raw/branch/main/workplans/archived/260714-RAIL-HO-WP-0005-forgejo-production-migration.md", + "source_status": "done", + "source_needs_human": false, + "before": { + "needs_human": true, + "intervention_note": "Requires explicit production cutover approval after probe, backup restore, package registry, email recovery, Actions, and migration drill gates pass." + }, + "after": { + "needs_human": false, + "status": "done" + } + }, + { + "task_id": "RAIL-HO-WP-0005-T12", + "hub_id": "a63147b0-31d5-4705-89ea-40c10faf779f", + "source_url": "https://forgejo.coulomb.social/coulomb/railiance-infra/raw/branch/main/workplans/archived/260714-RAIL-HO-WP-0005-forgejo-production-migration.md", + "source_status": "done", + "source_needs_human": false, + "before": { + "needs_human": true, + "intervention_note": "Requires explicit approval after stabilization: confirm no active remotes, webhooks, packages, dashboards, or rollback procedures still depend on legacy Gitea." + }, + "after": { + "needs_human": false, + "status": "done" + } + } + ] +} diff --git a/docs/assessments/2026-09-08-helixforge-factory/human-flags.csv b/docs/assessments/2026-09-08-helixforge-factory/human-flags.csv new file mode 100644 index 0000000..cf44801 --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/human-flags.csv @@ -0,0 +1,20 @@ +uuid,record_id,workplan_uuid,status,needs_human,has_blocking_reason +57412aef-f47a-5b58-b0a3-ca066d05ca09,CUST-WP-0038-T08,ccb87fa4-6381-5f22-b097-6e026f56a9c1,todo,True,False +f88115bf-4f99-49ef-a415-0b23750141b3,RAIL-HO-WP-0005-T02,84e17675-0d15-4268-a8bd-540124d37018,done,True,False +417faa4d-eab8-4247-9485-4f80e5d5b7ff,RAIL-HO-WP-0005-T06,84e17675-0d15-4268-a8bd-540124d37018,done,True,False +b1b66687-ca33-4971-b312-743c8e059c5e,RAIL-HO-WP-0005-T11,84e17675-0d15-4268-a8bd-540124d37018,done,True,False +a63147b0-31d5-4705-89ea-40c10faf779f,RAIL-HO-WP-0005-T12,84e17675-0d15-4268-a8bd-540124d37018,done,True,False +7cbf0a35-71a1-47ac-afc2-f51ad2180fd0,ACTIVITY-WP-0006-T03,5646e13a-13af-4724-bca6-3c0d86f96733,done,True,False +267db6a7-67d2-48af-b3e8-7588f8684957,IHUB-WP-0022-T04,bd086c41-287d-4a4e-8ac5-9ab270f14d72,cancel,True,False +7012e4fd-2530-49b7-9c2f-1d949809a144,ACTIVITY-WP-0009-T01,d64cfbba-6da7-4737-afb9-866afa0e9cda,done,True,False +ae8af00a-c14f-4b76-933c-46d06cd360ae,RAILIANCE-WP-0014-T03,a152ddda-d60a-4a65-9b9c-59e2db9ff2b7,done,True,False +10e0df77-c230-4a82-b720-23c66bd17c0a,ACTIVITY-WP-0010-T03,f2c73ac6-13f0-4005-82cc-76c7c9f9c8b9,done,True,False +96b14cdb-364f-4eab-a80e-dd8b3859c694,ISSUE-WP-0003-T06,896ace77-21b3-450b-8fb7-254aefc8c570,done,True,False +d8498e3b-b2fb-47b7-ab88-cd6592c1807e,,2731fece-6c49-45b8-ab8a-4ea6c04ac603,done,True,True +0c543cb3-36cb-4b25-9a58-de8efc1216c9,,2731fece-6c49-45b8-ab8a-4ea6c04ac603,done,True,True +1269bb58-0699-43ef-aa4f-43bc49c61a49,,2731fece-6c49-45b8-ab8a-4ea6c04ac603,done,True,True +4571d4c9-d4de-4ee9-97e0-ff03e49e65ec,,2731fece-6c49-45b8-ab8a-4ea6c04ac603,done,True,True +78d1db83-12fb-4ac2-95eb-54c91ac125b5,,2731fece-6c49-45b8-ab8a-4ea6c04ac603,done,True,True +44ce4082-fa8f-44d0-8f86-172d14ecfb0e,,2731fece-6c49-45b8-ab8a-4ea6c04ac603,done,True,True +c881500b-5459-4620-81c0-b176971e989f,ACTIVITY-WP-0016-T05,4ef0d53b-1777-41ae-80c6-1b69fdb34726,done,True,False +a8b1b855-ab34-5835-b9fd-5f48bc0b6817,WARDEN-WP-0037-T03,42a097db-1c24-558e-a724-030bb2b4443e,wait,True,False diff --git a/docs/assessments/2026-09-08-helixforge-factory/open-workplans.csv b/docs/assessments/2026-09-08-helixforge-factory/open-workplans.csv new file mode 100644 index 0000000..00436a3 --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/open-workplans.csv @@ -0,0 +1,99 @@ +repo,slug,uuid,title,status,owner,retired_identity,task_count,open_tasks,todo,progress,wait,human_open,execution_state,launch_mode,planning_priority,backing_synced_at,backing_sync_age_days,local_matches,local_id,local_status,local_path,local_update_age_days,status_disagreement +net-kingdom,nk-wp-0033,63665674-6880-593e-96e6-bab3211b1352,Contain and rotate the exposed KeyCape credential bundle,active,codex,False,5,2,0,2,0,0,manual,manual,P0,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0033,active,/home/worsch/net-kingdom/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md,16,False +flex-auth,flex-wp-0022,804c588c-f47a-50c4-bdd7-51b24bbf9539,Tenant scoping is unstated in tenant-engine and untested in two more packages,proposed,claude,False,3,3,2,0,1,0,manual,manual,P1,2026-09-07T11:43:59.199522Z,1,1,FLEX-WP-0022,proposed,/home/worsch/flex-auth/workplans/FLEX-WP-0022-tenant-scope-coverage.md,2,False +flex-auth,flex-wp-0023,ad011f92-786c-51ad-b3f6-c06ad77e7af7,Operator caller access path and caller identity in the decision record,active,claude,False,5,1,1,0,0,0,manual,manual,P1,2026-09-07T11:43:59.199522Z,1,1,FLEX-WP-0023,active,/home/worsch/flex-auth/workplans/FLEX-WP-0023-operator-caller-access-path.md,2,False +flex-auth,flex-wp-0024,90577acd-6910-548d-a13e-1dbfdfb8ed27,Sign the decision envelope: the response channel is unauthenticated,active,claude,False,4,2,1,0,1,0,manual,manual,P1,2026-09-07T11:43:59.199522Z,1,1,FLEX-WP-0024,active,/home/worsch/flex-auth/workplans/FLEX-WP-0024-decision-envelope-authenticity.md,2,False +flex-auth,flex-wp-0025,f9a657ce-67b4-5d25-9933-e0fcb2c20b1c,A policy cannot tell a registry fact from a caller assertion,ready,claude,False,3,3,2,0,1,0,manual,manual,P1,,,1,FLEX-WP-0025,ready,/home/worsch/flex-auth/workplans/FLEX-WP-0025-fact-versus-assertion.md,1,False +net-kingdom,nk-wp-0027,965ad365-6b81-50a1-a2a3-2d0c1fcce0b4,Reconcile reef placement and security-zone canon dependencies,blocked,net-kingdom,False,6,3,0,0,3,0,manual,manual,P1,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0027,blocked,/home/worsch/net-kingdom/workplans/NK-WP-0027-reef-placement-reconciliation.md,17,False +net-kingdom,nk-wp-0031,9d7b04f9-3803-5613-b7a5-8bd606c77f5a,Implement deterministic posture and evidence feedback,blocked,codex,False,5,1,0,0,1,0,manual,manual,P1,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0031,blocked,/home/worsch/net-kingdom/workplans/NK-WP-0031-deterministic-posture-feedback.md,16,False +net-kingdom,net-kingdom-nk-wp-0035,04685f94-1991-5e62-80d2-5669913e99fc,Publish the NetKingdom emission-cadence security profile,blocked,codex,False,5,1,0,0,1,0,manual,manual,P1,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0035,blocked,/home/worsch/net-kingdom/workplans/NK-WP-0035-emission-cadence-security-profile.md,1,False +ops-warden,warden-wp-0034,ae3ff76f-883d-5e2f-b6aa-144d61e8fdef,"Layer model v0.7 conformance — state the deadline, bind the agent boundary, steward the estate's newest rule",active,ops-warden,False,5,1,0,0,1,0,manual,manual,P1,2026-09-04T23:19:50.429557Z,4,1,WARDEN-WP-0034,active,/home/worsch/ops-warden/workplans/WARDEN-WP-0034-layer-model-v07-conformance.md,3,False +fluid-telegram,ft-wp-0001,a660ed65-700e-5b54-8d91-a556b73518f0,Establish HelixForge's Telegram identity and publish the Hall of Helix,active,worsch,False,13,13,13,0,0,0,manual,manual,high,2026-09-04T10:49:38.886525Z,4,1,FT-WP-0001,active,/home/worsch/fluid-telegram/workplans/FT-WP-0001-telegram-identity-and-hall-channel.md,4,False +fluid-core,fluid-wp-0008,291005a5-d474-5c94-8abd-819f682dde9f,Handover: HelixForge Telegram identity and hall-of-helix channel,active,worsch,False,9,3,3,0,0,0,manual,manual,high,2026-09-04T10:45:13.787584Z,4,1,FLUID-WP-0008,active,/home/worsch/fluid-core/workplans/FLUID-WP-0008-fluid-telegram-handover.md,4,False +net-kingdom,nk-wp-0009,d4d02dbf-3974-502d-8b87-b776fc63e17e,NetKingdom Security Pattern Tutorials,backlog,codex,False,6,6,6,0,0,0,manual,manual,medium,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0009,backlog,/home/worsch/net-kingdom/workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md,62,False +fluid-core,fluid-wp-0009,b6459dd0-fc4f-54a4-a2e9-d7b83cff6c6e,Establish the pr- campaign repository pattern and reduce hall-of-helix to an example,active,worsch,False,5,4,3,1,0,0,manual,manual,medium,2026-09-04T10:45:13.787584Z,4,1,FLUID-WP-0009,active,/home/worsch/fluid-core/workplans/FLUID-WP-0009-campaign-repos-and-example-separation.md,4,False +ops-warden,warden-wp-0027,21528e8d-a049-523d-9ae1-da7a27cb8bbf,Tamper-resistant credential governance + mass rotation/lockdown (Strand B),active,codex,False,3,1,0,1,0,0,manual,manual,medium,2026-09-04T23:19:50.429557Z,4,1,WARDEN-WP-0027,active,/home/worsch/ops-warden/workplans/WARDEN-WP-0027-credential-governance-lockdown.md,16,False +key-cape,key-wp-0014,0d003df3-f7d3-5063-8ca0-e1e33f7df74a,Review native login and client credential lane handoffs,blocked,codex,False,4,1,0,0,1,0,manual,manual,,2026-09-08T07:44:58.687850Z,0,1,KEY-WP-0014,blocked,/home/worsch/key-cape/workplans/KEY-WP-0014-native-credential-lane-handoff.md,3,False +key-cape,key-wp-0009,c1a9b1cc-2ff0-566a-b544-1a2ef967fc0d,Provider capability declarations and bounded service identities,blocked,codex,False,4,1,0,0,1,0,manual,manual,,2026-09-08T07:44:58.687850Z,0,1,KEY-WP-0009,blocked,/home/worsch/key-cape/workplans/KEY-WP-0009-provider-capabilities-and-service-identities.md,16,False +key-cape,key-wp-0013,6e815d88-b0e3-5ce0-be5d-13ab15917f7f,Approval-engine resource audience and client registrations,blocked,codex,False,4,1,0,0,1,0,manual,manual,,2026-09-08T07:44:58.687850Z,0,1,KEY-WP-0013,blocked,/home/worsch/key-cape/workplans/KEY-WP-0013-approval-engine-resource-audience.md,2,False +rapp-canned-prompts,rcp-wp-0002,11874f32-ac36-5bb9-a0a5-e7a259f5972c,First deployment of canned-prompts on Railiance,active,codex,False,5,2,0,1,1,0,manual,manual,,2026-09-08T07:01:15.398238Z,0,1,RCP-WP-0002,active,/home/worsch/rapp-canned-prompts/workplans/RCP-WP-0002-first-deployment.md,2,False +hall-of-helix,hoh-wp-0002,5e0db595-2f0e-5388-9413-7d4d5a4a2ef5,Publish the hall at helix.coulomb.social with selectable renderers,active,claude-code,False,6,6,4,0,2,0,manual,manual,,2026-09-05T20:40:32.802158Z,3,1,HOH-WP-0002,active,/home/worsch/hall-of-helix/workplans/HOH-WP-0002-published-hall-and-renderers.md,3,False +rapp-postgres,rapp-postgres-wp-0006,e861bad8-8b92-5963-b554-e9b6fa043acb,Admit canned-prompts on the PostgreSQL overflow cell,active,claude,False,3,1,1,0,0,0,manual,manual,,2026-09-07T22:04:53.016381Z,1,1,RAPP-POSTGRES-WP-0006,active,/home/worsch/rapp-postgres/workplans/RAPP-POSTGRES-WP-0006-canned-prompts-admission.md,1,False +secrets-engine,secrets-wp-0006,31f7f8ea-7f73-516c-8877-f03a13f1db82,Adopt concrete OpenBao credential lanes from ops-warden,active,codex,False,6,2,0,0,2,0,manual,manual,,2026-09-07T21:27:31.066695Z,1,1,SECRETS-WP-0006,active,/home/worsch/secrets-engine/workplans/SECRETS-WP-0006-catalog-lane-adoption.md,2,False +secrets-engine,secrets-wp-0008,9c9e5164-b2f5-5ea2-a557-5368d65e9fe0,Evolve the Lifecycle engine to the accepted security layer model,active,grok,False,6,2,0,0,2,0,manual,manual,,2026-09-07T21:27:31.066695Z,1,1,SECRETS-WP-0008,active,/home/worsch/secrets-engine/workplans/SECRETS-WP-0008-layer-model-lifecycle-conformance.md,2,False +secrets-engine,secrets-wp-0009,40ccc3b4-d046-5a58-8649-e7935f45c974,Activate native Claude credential delivery for Glas,blocked,codex,False,3,1,0,0,1,0,manual,manual,,2026-09-07T21:27:31.066695Z,1,1,SECRETS-WP-0009,blocked,/home/worsch/secrets-engine/workplans/SECRETS-WP-0009-glas-claude-native-delivery.md,3,False +secrets-engine,secrets-wp-0007,68a39be1-bd9c-5133-ad64-e7bca892aaf3,"Production-safe provisioning, authorization, and lifecycle hardening",active,codex,False,7,2,0,0,2,0,manual,manual,,2026-09-07T21:27:31.066695Z,1,1,SECRETS-WP-0007,active,/home/worsch/secrets-engine/workplans/SECRETS-WP-0007-production-lifecycle-hardening.md,2,False +coordination-engine,coordination-wp-0004,bf08c283-0f43-5a8d-9e63-17c4b96ded11,OrwellLoggingDiagnostics canon review,active,codex,False,2,2,1,0,1,0,manual,manual,,2026-09-07T14:42:38.804512Z,1,1,COORDINATION-WP-0004,active,/home/worsch/coordination-engine/workplans/COORDINATION-WP-0004-orwell-canon-review.md,1,False +approval-engine,approval-wp-0002,4fa25ad5-f5d0-5592-aa59-085f8ee3edaf,Production readiness and consumer adoption,active,codex,False,5,4,0,1,3,0,manual,manual,,2026-09-07T11:48:23.960489Z,1,1,APPROVAL-WP-0002,active,/home/worsch/approval-engine/workplans/APPROVAL-WP-0002-production-readiness-and-consumer-adoption.md,2,False +tenant-engine,ten-wp-0012,cb7387d0-431d-56a2-bb7b-86a024aeeefb,Track the two external dispositions tenant-engine is waiting on,blocked,claude,False,2,2,0,0,2,0,manual,manual,,2026-09-07T11:47:31.515322Z,1,1,TEN-WP-0012,blocked,/home/worsch/tenant-engine/workplans/TEN-WP-0012-external-conformance-waits.md,1,False +net-kingdom,nk-wp-0032,516ee5b9-685b-5986-88d2-bde66c2ba96c,Admit the operator-tunneled OpenBao browser callback,blocked,codex,False,4,2,0,0,2,0,manual,manual,,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0032,blocked,/home/worsch/net-kingdom/workplans/NK-WP-0032-openbao-operator-loopback-callback.md,16,False +net-kingdom,nk-wp-0022,d76ddccc-00c8-548a-b141-2cd660fa38da,Cut over NetKingdom identity to railiance01 and retire CoulombCore,blocked,codex,False,8,1,0,0,1,0,manual,manual,,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0022,blocked,/home/worsch/net-kingdom/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md,31,False +net-kingdom,nk-wp-0034,c87e142c-4eda-5c1b-84a9-ee5a848f3f63,Make the SSO/MFA verification actually verify,blocked,codex,False,4,1,0,0,1,0,manual,manual,,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0034,blocked,/home/worsch/net-kingdom/workplans/NK-WP-0034-verification-that-verifies.md,3,False +net-kingdom,nk-wp-0011,1075448f-d533-5f9e-94b7-c3adfe151a07,Enterprise Federation & SAML — Expanded-Mode Keycloak Identity Broker,backlog,worsch,False,8,8,8,0,0,0,manual,manual,,2026-09-07T11:45:13.259898Z,1,1,NK-WP-0011,backlog,/home/worsch/net-kingdom/workplans/NK-WP-0011-enterprise-federation-saml.md,62,False +flex-auth,flex-wp-0020,99a661a8-b36c-5c1c-b78b-1e8930bcd0a9,Repository identity migration from flex-auth to access-engine,proposed,codex,False,11,11,5,0,6,0,manual,manual,,2026-09-07T11:43:59.199522Z,1,1,FLEX-WP-0020,proposed,/home/worsch/flex-auth/workplans/FLEX-WP-0020-repository-identity-migration.md,10,False +glas-harness,glas-wp-0015,94c02b1f-66ed-588d-bdd7-7158107b85fb,Drive owner returns for the first production Glas profile,active,codex,False,3,1,0,1,0,0,manual,manual,,2026-09-06T21:47:27.945742Z,2,1,GLAS-WP-0015,active,/home/worsch/glas-harness/workplans/GLAS-WP-0015-production-dependency-coordination.md,2,False +glas-harness,glas-wp-0012,170bf1ae-337f-5553-8d1e-03b07100e08f,Prove the first local rein profile end to end,blocked,codex,False,6,4,0,0,4,0,manual,manual,,2026-09-06T21:47:27.945742Z,2,1,GLAS-WP-0012,blocked,/home/worsch/glas-harness/workplans/GLAS-WP-0012-first-local-profile-production-proof.md,2,False +sand-boxer,sand-wp-0015,d3f12387-fd23-58f0-b979-9c811507614d,Provide a pinned bwrap rein runtime and private state,blocked,codex,False,5,1,0,0,1,0,manual,manual,,2026-09-06T21:47:26.874002Z,2,1,SAND-WP-0015,blocked,/home/worsch/sand-boxer/workplans/SAND-WP-0015-bwrap-runtime-and-private-state.md,2,False +sand-boxer,sand-wp-0014,b616d1cd-208f-5ecf-a4a0-a028396422c4,Owner-mediated governed bwrap execution,active,codex,False,5,1,0,0,1,0,manual,manual,,2026-09-06T21:47:26.874002Z,2,1,SAND-WP-0014,active,/home/worsch/sand-boxer/workplans/SAND-WP-0014-owner-mediated-execution.md,3,False +railiance-platform,rpf-wp-0015,f4640325-e89c-591d-b58e-ec6b087900ac,Coordinate audit-core temporary custody and recovery exercises,blocked,codex,False,4,2,0,0,2,0,manual,manual,,2026-08-26T17:46:26.500879Z,13,1,RPF-WP-0015,blocked,/home/worsch/railiance-platform/workplans/RPF-WP-0015-audit-core-custody-and-recovery-coordination.md,3,False +railiance-platform,rpf-wp-0029,bb326ebb-a313-549e-b35f-1bf17e1c58fd,Remove backup credential default and verify governed replacement,blocked,codex,False,3,1,0,0,1,0,manual,manual,,,,1,RPF-WP-0029,blocked,/home/worsch/railiance-platform/workplans/RPF-WP-0029-backup-credential-default-removal.md,2,False +railiance-platform,rpf-wp-0035,975db491-5412-5e27-8e34-14a2417bb039,Implement reviewed credential lanes with separate owner gates,blocked,codex,False,4,2,0,0,2,0,manual,manual,,,,1,RPF-WP-0035,blocked,/home/worsch/railiance-platform/workplans/RPF-WP-0035-credential-lane-implementation.md,2,False +railiance-platform,rpf-wp-0027,b2c25a01-4a80-55c1-90cf-8538000f7e0e,Coordinate KeyCape live Secret exposure recovery,blocked,codex,False,6,3,0,0,3,0,manual,manual,,2026-08-26T17:46:26.500879Z,13,1,RPF-WP-0027,blocked,/home/worsch/railiance-platform/workplans/RPF-WP-0027-keycape-live-secret-exposure-recovery.md,3,False +railiance-platform,rpf-wp-0025,6dda6039-295e-5cac-aef6-3183c3218649,Retract public OpenBao listener behind operator-only access,blocked,codex,False,3,1,0,0,1,0,manual,manual,,2026-08-26T17:46:26.500879Z,13,1,RPF-WP-0025,blocked,/home/worsch/railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md,2,False +railiance-platform,rpf-wp-0038,7beec1a7-aa82-5a36-9a66-6b60008a2455,Close Forgejo primary backup coverage on Scaleway,active,codex,False,4,1,0,1,0,0,manual,manual,,,,1,RPF-WP-0038,active,/home/worsch/railiance-platform/workplans/RPF-WP-0038-forgejo-scaleway-primary-coverage.md,2,False +railiance-platform,rpf-wp-0036,ca639c3d-3a87-5fa4-ad13-6f2e014b0c84,Close S3 service assurance and ownership gaps,blocked,codex,False,7,3,0,0,3,0,manual,manual,,,,1,RPF-WP-0036,blocked,/home/worsch/railiance-platform/workplans/RPF-WP-0036-platform-service-assurance.md,2,False +rapp-telemetry,rapp-telemetry-wp-0001,13305ba8-33d8-56a4-af79-165092a02677,Establish and activate the managed telemetry package on railiance01,active,codex,False,5,2,0,0,2,0,manual,manual,,,,1,RAPP-TELEMETRY-WP-0001,active,/home/worsch/rapp-telemetry/workplans/RAPP-TELEMETRY-WP-0001-foundation.md,2,False +audit-core,audit-wp-0010,54655357-74da-5f7f-8fa6-647d4c969f21,Admit tenant-engine as an attributive sender,ready,claude,False,5,5,5,0,0,0,manual,manual,,2026-09-06T20:32:30.591292Z,2,1,AUDIT-WP-0010,ready,/home/worsch/audit-core/workplans/AUDIT-WP-0010-tenant-engine-sender-admission.md,10,False +audit-core,audit-wp-0008,a9a248b2-d26c-503e-a8fc-4f3675e6ed51,Tenancy posture declaration and read-path enforcement,active,claude,False,8,1,0,1,0,0,manual,manual,,2026-09-06T20:32:30.591292Z,2,1,AUDIT-WP-0008,active,/home/worsch/audit-core/workplans/AUDIT-WP-0008-tenancy-posture-alignment.md,17,False +audit-core,audit-wp-0009,46a96b03-bc08-53b5-9c93-4071adabf734,Evidence-role conformance under Security Layer Model v0.7,active,claude,False,10,7,5,1,1,0,manual,manual,,2026-09-06T20:32:30.591292Z,2,1,AUDIT-WP-0009,active,/home/worsch/audit-core/workplans/AUDIT-WP-0009-evidence-role-conformance.md,10,False +railiance-telemetry,rtel-wp-0002,08a5db92-7293-50d3-b589-55287b9850b3,Provide the Q2 receiving contract and prove signal delivery,active,codex,False,4,1,0,0,1,0,manual,manual,,2026-09-06T18:26:40.127324Z,2,1,RTEL-WP-0002,active,/home/worsch/railiance-telemetry/workplans/RTEL-WP-0002-signal-contract.md,2,False +gate-house,gh-wp-0003,a331dc88-c9bc-5d2a-9ff1-2aa7e837c3bb,Security layer model v0.8 amendment set,active,codex,False,9,1,0,1,0,0,manual,manual,,,,1,GH-WP-0003,active,/home/worsch/gate-house/workplans/GH-WP-0003-statute-v08-amendment-set.md,3,False +info-tech-canon,info-wp-0019,b29261ba-c1e4-5533-8185-ab2d5b433685,"Conformance, reproducible consumption, and maintenance",blocked,codex,False,6,1,0,0,1,0,manual,manual,,2026-09-06T06:06:19.107555Z,2,1,INFO-WP-0019,blocked,/home/worsch/info-tech-canon/workplans/INFO-WP-0019-conformance-and-maintenance.md,3,False +reuse-surface,reuse-wp-0021,0d1beafd-e638-5bb9-b91d-13543ac42a04,Follow the CommerceCanon repository rename in federation sources,active,codex,False,2,1,0,0,1,0,manual,manual,,,,1,REUSE-WP-0021,active,/home/worsch/reuse-surface/workplans/REUSE-WP-0021-commerce-canon-source-rename.md,2,False +pqrst-practice,pqrst-wp-0002,6a875b19-5a76-55c1-bd1f-2f5005cd416b,Validate spec v0.1 in real session closes and land PQRST in hall-of-helix,proposed,claude-code,False,5,3,3,0,0,0,manual,manual,,2026-09-05T20:34:40.611197Z,3,1,PQRST-WP-0002,proposed,/home/worsch/pqrst-practice/workplans/PQRST-WP-0002-validate-v01-against-real-sessions.md,3,False +state-hub,cust-wp-0038,ccb87fa4-6381-5f22-b097-6e026f56a9c1,State Hub Full ThreePhoenix HA Migration,backlog,custodian,False,8,8,8,0,0,1,manual,manual,,2026-09-04T20:26:55.609511Z,4,1,CUST-WP-0038,backlog,/home/worsch/state-hub/workplans/CUST-WP-0038-state-hub-threephoenix-ha.md,31,False +state-hub,state-wp-0079,ed077b62-7048-5752-bf65-f90471f45854,State Hub retirement strangler and disposition execution,blocked,codex,False,9,5,0,0,5,0,manual,manual,,2026-09-04T20:26:55.609511Z,4,1,STATE-WP-0079,blocked,/home/worsch/state-hub/workplans/STATE-WP-0079-retirement-strangler.md,3,False +rapp-core-hub,rappcorehub-wp-0002,626cb2d7-9525-5712-be9e-93c1ed840fc5,Hub-core candidate and production cutover,active,codex,False,5,1,0,1,0,0,manual,manual,,2026-08-25T21:18:57.117826Z,14,1,RAPPCOREHUB-WP-0002,active,/home/worsch/rapp-core-hub/workplans/RAPPCOREHUB-WP-0002-hub-core-candidate-and-cutover.md,18,False +rapp-core-hub,rappcorehub-wp-0003,b73f1e1a-efaf-5f2f-b916-2a3040e0242e,Forgejo-backed repository classification publisher,active,codex,False,4,1,0,0,1,0,manual,manual,,,,1,RAPPCOREHUB-WP-0003,active,/home/worsch/rapp-core-hub/workplans/RAPPCOREHUB-WP-0003-forgejo-repository-publisher.md,7,False +hub-core,hub-wp-0011,3c8034fc-fd90-58f5-99bc-99b4f93e5ee1,State Hub inbox freshness and reader cutover,proposed,codex,False,3,3,1,0,2,0,manual,manual,,,,1,HUB-WP-0011,proposed,/home/worsch/hub-core/workplans/HUB-WP-0011-statehub-inbox-freshness-and-cutover.md,3,False +hub-core,hub-wp-0009,0d6e94f3-fd15-5f57-af41-60f0b862da5e,Complete the hub-extension conformance profile,proposed,codex,False,4,4,4,0,0,0,manual,manual,,2026-08-31T22:51:17.666789Z,8,1,HUB-WP-0009,proposed,/home/worsch/hub-core/workplans/HUB-WP-0009-extension-conformance-gaps.md,8,False +hub-core,hub-wp-0006,05ebd06e-4af8-5f6c-918c-c143c1520e00,Repository classification aggregation and navigation,active,codex,False,6,1,0,0,1,0,manual,manual,,2026-08-31T22:51:17.666789Z,8,1,HUB-WP-0006,active,/home/worsch/hub-core/workplans/HUB-WP-0006-repository-classification-navigation.md,17,False +rapp-qonto,rapp-qonto-wp-0002,6152c89b-a4f3-55b6-af0b-d57462b3c6f7,Publish rapp-qonto usage and cost evidence,ready,codex,False,3,3,3,0,0,0,manual,manual,,2026-09-05T08:17:35.132106Z,3,1,RAPP-QONTO-WP-0002,ready,/home/worsch/rapp-qonto/workplans/RAPP-QONTO-WP-0002-resource-usage-and-cost-evidence.md,24,False +ops-warden,warden-wp-0037,42a097db-1c24-558e-a724-030bb2b4443e,Repoint the whynot-design npm lane to Forgejo,active,codex,False,3,1,0,0,1,1,manual,manual,,2026-09-04T23:19:50.429557Z,4,1,WARDEN-WP-0037,active,/home/worsch/ops-warden/workplans/WARDEN-WP-0037-whynot-design-forgejo-npm-lane.md,4,False +ops-mason,mason-wp-0003,4015b46d-02f1-56ac-853e-87e8542cf0dd,Forge read lane so central can derive private repositories,active,codex,False,6,1,0,1,0,0,manual,manual,,2026-09-04T21:53:09.450932Z,4,1,MASON-WP-0003,active,/home/worsch/ops-mason/workplans/MASON-WP-0003-state-hub-forge-read-lane.md,13,False +ops-mason,mason-wp-0004,e5656747-a974-581a-a3d4-4e6bb7262f4c,Describe every stored credential so the store is navigable,proposed,codex,False,4,4,2,0,2,0,manual,manual,,2026-09-04T21:53:09.450932Z,4,1,MASON-WP-0004,proposed,/home/worsch/ops-mason/workplans/MASON-WP-0004-credential-inventory-descriptions.md,,False +ops-mason,mason-wp-0005,483e56d6-6601-5377-9066-66225214c046,Construct the fluid-telegram operator credential lane,proposed,codex,False,6,6,5,0,1,0,manual,manual,,,,1,MASON-WP-0005,proposed,/home/worsch/ops-mason/workplans/MASON-WP-0005-fluid-telegram-operator-credential-lane.md,4,False +fluid-telegram,ft-wp-0002,f2373858-c932-5a4d-81b6-db9a3595135a,Provision the Telegram presence from a declared specification,proposed,worsch,False,8,6,2,4,0,0,manual,manual,,,,1,FT-WP-0002,proposed,/home/worsch/fluid-telegram/workplans/FT-WP-0002-declared-presence-provisioning.md,4,False +rein-aharness,reinah-wp-0003,eba2eff1-10a7-50a3-a70b-14e7d398f27f,Governed runtime integrity and intent convergence,active,codex,False,6,3,0,1,2,0,manual,manual,,2026-09-04T19:23:15.572915Z,4,1,REINAH-WP-0003,active,/home/worsch/rein-aharness/workplans/REINAH-WP-0003-governed-runtime-integrity.md,4,False +fluid-core,fluid-wp-0001,b5c231e1-9d06-5772-95a7-01cc0bf62051,Bootstrap State Hub integration,ready,worsch,False,3,3,3,0,0,0,manual,manual,,2026-09-04T10:45:13.787584Z,4,1,FLUID-WP-0001,ready,/home/worsch/fluid-core/workplans/FLUID-WP-0001-statehub-bootstrap.md,4,False +activity-core,activity-wp-0032,256dad13-28b4-5361-ab8a-7d1373a5d14b,Adopt the Glas profile-driven execution contract,active,claude,False,5,1,0,0,1,0,manual,manual,,2026-09-04T19:09:07.981785Z,4,1,ACTIVITY-WP-0032,active,/home/worsch/activity-core/workplans/ACTIVITY-WP-0032-glas-profile-execution-contract.md,4,False +activity-core,activity-wp-0035,fbcc10a9-bc1e-50b2-ba86-47adcb18666d,Make the execution boundary enforceable and the review contract truthful,active,codex,False,8,1,0,1,0,0,manual,manual,,2026-09-04T19:09:07.981785Z,4,1,ACTIVITY-WP-0035,active,/home/worsch/activity-core/workplans/ACTIVITY-WP-0035-intent-boundary-guardrails.md,4,False +activity-core,activity-wp-0036,01e6d5d4-6e1a-5f0d-81f0-ded97e0f71cd,Bind queue mutations to worker identity and active leases,active,codex,False,4,1,0,1,0,0,manual,manual,,2026-09-04T19:09:07.981785Z,4,1,ACTIVITY-WP-0036,active,/home/worsch/activity-core/workplans/ACTIVITY-WP-0036-queue-identity-and-lease-integrity.md,4,False +whitehat-security,whitehat-wp-0008,94b71ba3-998d-5166-9730-6beb5f595923,Authorized live ASM residuals after WHITEHAT-WP-0007,blocked,net-kingdom,False,1,1,0,0,1,0,manual,manual,,2026-09-02T13:47:27.990834Z,6,1,WHITEHAT-WP-0008,blocked,/home/worsch/whitehat-security/workplans/WHITEHAT-WP-0008-live-asm-residuals.md,6,False +whitehat-security,whitehat-wp-0006,fe26f070-70ca-55ba-92b3-3378929ba90f,Authorized live residuals after WHITEHAT-WP-0001,blocked,net-kingdom,False,3,3,0,0,3,0,manual,manual,,2026-09-02T13:47:27.990834Z,6,1,WHITEHAT-WP-0006,blocked,/home/worsch/whitehat-security/workplans/WHITEHAT-WP-0006-authorized-live-residuals.md,7,False +railiance-fabric,rail-fab-wp-0028,58a56363-3bda-50f7-8240-1e45131bc7d9,Host and operate the financial Fabric authority,proposed,codex,False,4,4,1,0,3,0,manual,manual,,,,1,RAIL-FAB-WP-0028,proposed,/home/worsch/railiance-fabric/workplans/RAIL-FAB-WP-0028-hosted-financial-fabric-authority.md,8,False +fin-hub,fin-wp-0004,e8b432af-43ae-517f-a69b-80d4f0db976d,Establish the resource cost evidence contract,active,codex,False,9,1,0,0,1,0,manual,manual,,2026-08-31T20:19:47.415652Z,8,1,FIN-WP-0004,active,/home/worsch/fin-hub/workplans/FIN-WP-0004-resource-cost-evidence-contract.md,24,False +fin-hub,fin-wp-0006,e9413a20-5b11-50ff-ba21-15215841cf11,Consume resource-control internal transfer settlement,proposed,codex,False,1,1,1,0,0,0,manual,manual,,2026-08-31T20:19:47.415652Z,8,1,FIN-WP-0006,proposed,/home/worsch/fin-hub/workplans/FIN-WP-0006-internal-transfer-settlement.md,25,False +fin-hub,fin-wp-0005,58432770-da19-5b72-a946-cacbe1eb24ca,DATEV accounting adapter operations,active,codex,False,4,4,1,0,3,0,manual,manual,,2026-08-31T20:19:47.415652Z,8,1,FIN-WP-0005,active,/home/worsch/fin-hub/workplans/FIN-WP-0005-datev-accounting-adapter-operations.md,28,False +soul-frame,soul-wp-0008,c730a7e2-244e-558c-9ec1-66d04e275ff8,Phase VII — Soul Frame research paper,ready,grok,False,4,4,4,0,0,0,manual,manual,,2026-08-25T21:19:05.481426Z,14,1,SOUL-WP-0008,ready,/home/worsch/soul-frame/workplans/SOUL-WP-0008-phase-vii-paper.md,27,False +railiance-master,rmaster-wp-0020,a7d0c934-75d7-53cc-a35b-6a789a2e0f14,Migrate authoritative OpenBao from CoulombCore to reef-railiance,blocked,codex,False,9,2,0,1,1,0,manual,manual,,2026-08-29T12:23:56.530808Z,10,1,RMASTER-WP-0020,blocked,/home/worsch/railiance-master/workplans/RMASTER-WP-0020-openbao-migration-to-reef-railiance.md,16,False +prj-unattended-progress-company,upc-wp-0003,81b17b8a-4b22-5510-8830-a8d19aed821e,Unattended dogfood acceptance and founder-load envelope (G3–G4),proposed,bernd,False,3,3,3,0,0,0,manual,manual,,2026-08-25T21:18:50.462138Z,14,1,UPC-WP-0003,proposed,/home/worsch/prj-unattended-progress-company/workplans/UPC-WP-0003-unattended-and-load.md,28,False +prj-unattended-progress-company,upc-wp-0002,8d47ba5f-0608-5f83-8b4b-7dee53ada6f6,Company vessel close-out (G1 + residual G2/G8),active,bernd,False,4,4,0,4,0,0,manual,manual,,2026-08-25T21:18:50.462138Z,14,1,UPC-WP-0002,active,/home/worsch/prj-unattended-progress-company/workplans/UPC-WP-0002-company-vessel-closeout.md,23,False +prj-unattended-progress-company,upc-wp-0004,a6cf0a20-a3d5-56c6-8fc7-8cb167c71d66,First external offer and paid revenue path (G5–G6),proposed,bernd,False,3,3,3,0,0,0,manual,manual,,2026-08-25T21:18:50.462138Z,14,1,UPC-WP-0004,proposed,/home/worsch/prj-unattended-progress-company/workplans/UPC-WP-0004-first-offer-and-revenue.md,28,False +prj-forgejo-org-refactor,orgref-wp-0001,c1dcd349-1a7a-51ae-8827-4ce96cfe0008,"Foundation, blast-radius inventory, and execution entry gate",backlog,codex,False,5,5,5,0,0,0,manual,manual,,2026-08-25T21:18:50.033731Z,14,1,ORGREF-WP-0001,backlog,/home/worsch/prj-forgejo-org-refactor/workplans/ORGREF-WP-0001-foundation-and-entry-gate.md,20,False +reef-railiance,reef-railiance-wp-0003,8ac413ad-2f57-53e6-b586-c5bec9cfbd1f,Complete rapp-qonto production gates,blocked,codex,False,4,1,0,0,1,0,manual,manual,,2026-08-31T11:34:33.556198Z,8,1,REEF-RAILIANCE-WP-0003,blocked,/home/worsch/reef-railiance/workplans/REEF-RAILIANCE-WP-0003-rapp-qonto-production-gates.md,18,False +rapp-openbao,rapp-openbao-wp-0002,df859d65-c6ee-5058-a662-ad74eb82d3d2,Replace public OpenBao UI exposure with operator-only access,blocked,codex,False,3,2,0,1,1,0,manual,manual,,2026-08-25T21:18:57.538722Z,14,1,RAPP-OPENBAO-WP-0002,blocked,/home/worsch/rapp-openbao/workplans/RAPP-OPENBAO-WP-0002-operator-only-ui-exposure.md,16,False +railiance-cluster,three-phoenix-ha-cluster,16da36fe-5a10-522b-b6d6-02dbb6de6c14,ThreePhoenix - HA Cluster Implementation,blocked,railiance,False,7,5,5,0,0,0,manual,manual,,2026-08-26T06:05:51.003696Z,13,1,RCLUSTER-WP-0007,blocked,/home/worsch/railiance-cluster/workplans/RCLUSTER-WP-0007-threephoenix-ha-cluster.md,17,False +the-custodian,adhoc-2026-08-25@retired-20260827,1c53d3db-6633-5e2d-987f-10706d73be9e,Ad hoc tasks 2026-08-25,active,codex,True,1,0,0,0,0,0,manual,manual,,2026-08-26T19:06:34.014659Z,13,0,,,,,False +railiance-platform,railiance-wp-0029@retired-20260826,038bc3c0-4492-5b91-95eb-ae515ca205df,Coordinate KeyCape live Secret exposure recovery,active,codex,True,6,4,0,2,2,0,manual,manual,,2026-08-25T18:21:22.107650Z,14,0,,,,,False +railiance-platform,railiance-wp-0024@retired-20260826,88c4ef7f-0af8-580e-90dc-a2bae2675a4d,Coordinate audit-core temporary custody and recovery exercises,active,codex,True,4,2,0,2,0,0,manual,manual,,2026-08-25T18:21:22.107650Z,14,0,,,,,False +railiance-platform,railiance-wp-0027@retired-20260826,6f8a6cbc-c076-5f0a-ade2-281a7ec71360,Retract public OpenBao listener behind operator-only access,blocked,codex,True,3,1,0,0,1,0,manual,manual,,2026-08-25T18:21:22.107650Z,14,0,,,,,False +core-hub,core-wp-0010,9cc1abf3-2ab0-54a4-a250-83f382a49441,Runtime absorption into hub-core and archive,active,codex,False,5,1,0,1,0,0,manual,manual,,2026-08-25T21:18:27.250392Z,14,1,CORE-WP-0010,active,/home/worsch/core-hub/workplans/CORE-WP-0010-runtime-absorption-and-archive.md,18,False +railiance-infra,rail-ho-wp-0012,5ea28f8f-376c-5230-8bb7-ca871c1a75f4,Close the encrypted S1 backup and recovery loop,active,codex,False,6,2,0,1,1,0,manual,manual,,2026-08-25T21:18:55.174513Z,14,1,RAIL-HO-WP-0012,active,/home/worsch/railiance-infra/workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md,16,False +railiance-infra,rail-ho-wp-0011,5738f113-1c4e-5d27-95b2-b6655e0b7279,Make the S1 declaration reproducible and the handoff verifiably green,active,codex,False,8,2,0,0,2,0,manual,manual,,2026-08-25T21:18:55.174513Z,14,1,RAIL-HO-WP-0011,active,/home/worsch/railiance-infra/workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md,16,False +adaptive-pricing,adaptive-wp-0010,543e6398-d2cb-5105-977e-b90461adac3e,Plan-derived guardrail spend ceilings,proposed,codex,False,4,4,1,0,3,0,manual,manual,,2026-08-25T21:18:21.901262Z,14,1,ADAPTIVE-WP-0010,proposed,/home/worsch/adaptive-pricing/workplans/ADAPTIVE-WP-0010-plan-derived-guardrail-ceilings.md,21,False +rapp-tenant-engine,rapp-tenant-engine-wp-0001,ec2896aa-9226-5516-a537-2de02138949f,Bootstrap rapp-tenant-engine,proposed,,False,0,0,0,0,0,0,manual,manual,,2026-08-25T21:18:58.519129Z,14,1,RAPP-TENANT-ENGINE-WP-0001,proposed,/home/worsch/rapp-tenant-engine/workplans/RAPP-TENANT-ENGINE-WP-0001-bootstrap.md,,False +test-driver,td-wp-0003,36a082df-1288-567d-9a0b-f2e0f292786c,Generalise the model and settle the open questions,proposed,codex,False,8,8,7,0,1,0,manual,manual,,2026-08-25T21:19:09.961330Z,14,1,TD-WP-0003,proposed,/home/worsch/test-driver/workplans/TD-WP-0003-generalise-and-settle.md,16,False +reef-storage,reef-storage-wp-0002,af6ed97f-fc45-5fc0-b8e9-6010c217808f,Fill Scaleway attributes after purchase,active,grok,False,2,1,0,0,1,0,manual,manual,,2026-08-25T21:18:59.097663Z,14,1,REEF-STORAGE-WP-0002,active,/home/worsch/reef-storage/workplans/REEF-STORAGE-WP-0002-fill-after-purchase.md,24,False +markitect-main,testdrive-jsui-publication,e03ef262-5284-5dd3-92d2-dbd85c6b6159,TestDrive-JSUI — npm Publication,backlog,markitect,False,10,10,10,0,0,0,manual,manual,,2026-08-25T21:18:41.347842Z,14,1,MARKITECT-WP-0002,backlog,/home/worsch/markitect-main/workplans/MARKITECT-WP-0002-testdrive-jsui-publication.md,78,False +issue-core,issue-wp-0006,4d465264-cbe1-56ba-84ed-bd580b649b76,Forgejo-only forge + projection boundary (not ops queue),ready,grok,False,4,4,4,0,0,0,manual,manual,,2026-08-25T21:18:38.044289Z,14,1,ISSUE-WP-0006,ready,/home/worsch/issue-core/workplans/ISSUE-WP-0006-forgejo-only-projection-boundary.md,36,False diff --git a/docs/assessments/2026-09-08-helixforge-factory/progress-receipt.json b/docs/assessments/2026-09-08-helixforge-factory/progress-receipt.json new file mode 100644 index 0000000..22eb3fd --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/progress-receipt.json @@ -0,0 +1,7 @@ +{ + "http_status": 201, + "id": "3a34a7c5-b85a-4fa8-9251-c99d4fb93c8b", + "recorded_at_utc": "2026-09-08T08:07:52.093162+00:00", + "event_type": "note", + "author": "codex" +} diff --git a/docs/assessments/2026-09-08-helixforge-factory/source-records.json b/docs/assessments/2026-09-08-helixforge-factory/source-records.json new file mode 100644 index 0000000..8ef127e --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/source-records.json @@ -0,0 +1,2455 @@ +[ + { + "repo": "coordination-engine", + "id": "COORDINATION-WP-0004", + "uuid": "bf08c283-0f43-5a8d-9e63-17c4b96ded11", + "title": "OrwellLoggingDiagnostics canon review", + "status": "active", + "owner": "codex", + "created": "2026-09-07", + "updated": "2026-09-07", + "record_age_days": 1, + "declared_update_age_days": 1, + "path": "/home/worsch/coordination-engine/workplans/COORDINATION-WP-0004-orwell-canon-review.md", + "source_sha256": "0bfb9f454deeb39fc9f4b8ce13a7f956823cc7c5061d5dc90ab883a892de7101", + "task_counts": { + "todo": 1, + "wait": 1 + }, + "open_tasks": 2, + "task_ids": [ + "COORDINATION-WP-0004-T01", + "COORDINATION-WP-0004-T02" + ] + }, + { + "repo": "info-tech-canon", + "id": "INFO-WP-0019", + "uuid": "b29261ba-c1e4-5533-8185-ab2d5b433685", + "title": "Conformance, reproducible consumption, and maintenance", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-05", + "record_age_days": 3, + "declared_update_age_days": 3, + "path": "/home/worsch/info-tech-canon/workplans/INFO-WP-0019-conformance-and-maintenance.md", + "source_sha256": "b552a710f0670dfc5406cf1ecddee4e5b8ce2fcac8d04e8236ac7f9d556eb433", + "task_counts": { + "done": 5, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "INFO-WP-0019-T01", + "INFO-WP-0019-T02", + "INFO-WP-0019-T03", + "INFO-WP-0019-T04", + "INFO-WP-0019-T05", + "INFO-WP-0019-T06" + ] + }, + { + "repo": "key-cape", + "id": "KEY-WP-0009", + "uuid": "c1a9b1cc-2ff0-566a-b544-1a2ef967fc0d", + "title": "Provider capability declarations and bounded service identities", + "status": "blocked", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-08-23", + "record_age_days": 16, + "declared_update_age_days": 16, + "path": "/home/worsch/key-cape/workplans/KEY-WP-0009-provider-capabilities-and-service-identities.md", + "source_sha256": "6bcb9b75a248237157951892ab248816f9134995edf37cc60ba2b756971757ac", + "task_counts": { + "done": 3, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "KEY-WP-0009-T01", + "KEY-WP-0009-T02", + "KEY-WP-0009-T03", + "KEY-WP-0009-T04" + ] + }, + { + "repo": "key-cape", + "id": "KEY-WP-0013", + "uuid": "6e815d88-b0e3-5ce0-be5d-13ab15917f7f", + "title": "Approval-engine resource audience and client registrations", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-06", + "record_age_days": 3, + "declared_update_age_days": 2, + "path": "/home/worsch/key-cape/workplans/KEY-WP-0013-approval-engine-resource-audience.md", + "source_sha256": "3a37662116fb0b329776396b6038ab829c4d9e2a5b5b00d52958eb5b00de8290", + "task_counts": { + "done": 3, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "KEY-WP-0013-T01", + "KEY-WP-0013-T02", + "KEY-WP-0013-T03", + "KEY-WP-0013-T04" + ] + }, + { + "repo": "key-cape", + "id": "KEY-WP-0014", + "uuid": "0d003df3-f7d3-5063-8ca0-e1e33f7df74a", + "title": "Review native login and client credential lane handoffs", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-05", + "record_age_days": 3, + "declared_update_age_days": 3, + "path": "/home/worsch/key-cape/workplans/KEY-WP-0014-native-credential-lane-handoff.md", + "source_sha256": "a2efe1bffa87e192b5bb0df5ec0ce7b81b492a957a9c447d9cacc79d924e8e9b", + "task_counts": { + "done": 3, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "KEY-WP-0014-T01", + "KEY-WP-0014-T02", + "KEY-WP-0014-T03", + "KEY-WP-0014-T04" + ] + }, + { + "repo": "markitect-main", + "id": "MARKITECT-WP-0002", + "uuid": "e03ef262-5284-5dd3-92d2-dbd85c6b6159", + "title": "TestDrive-JSUI \u2014 npm Publication", + "status": "backlog", + "owner": "codex", + "created": "2026-06-22", + "updated": "2026-06-22", + "record_age_days": 78, + "declared_update_age_days": 78, + "path": "/home/worsch/markitect-main/workplans/MARKITECT-WP-0002-testdrive-jsui-publication.md", + "source_sha256": "4bd9e2fe864857613cfc4aba59108d61195436662fbd8faf8679721686b9fabb", + "task_counts": { + "todo": 1 + }, + "open_tasks": 1, + "task_ids": [ + "MARKITECT-WP-0002-T01" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0009", + "uuid": "d4d02dbf-3974-502d-8b87-b776fc63e17e", + "title": "NetKingdom Security Pattern Tutorials", + "status": "backlog", + "owner": "codex", + "created": "2026-05-17", + "updated": "2026-07-08", + "record_age_days": 114, + "declared_update_age_days": 62, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md", + "source_sha256": "6da33755594f9bbecded0c5ca53b29de92260684c05a08dbba98223bb6937470", + "task_counts": { + "todo": 6 + }, + "open_tasks": 6, + "task_ids": [ + "NK-WP-0009-T01", + "NK-WP-0009-T02", + "NK-WP-0009-T03", + "NK-WP-0009-T04", + "NK-WP-0009-T05", + "NK-WP-0009-T06" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0011", + "uuid": "1075448f-d533-5f9e-94b7-c3adfe151a07", + "title": "Enterprise Federation & SAML \u2014 Expanded-Mode Keycloak Identity Broker", + "status": "backlog", + "owner": "worsch", + "created": "2026-05-20", + "updated": "2026-07-08", + "record_age_days": 111, + "declared_update_age_days": 62, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0011-enterprise-federation-saml.md", + "source_sha256": "9c259caadfe2f9f5fbeabd29f437a9d174e0b1d580da3a2865bd1b0a808c1d63", + "task_counts": { + "todo": 8 + }, + "open_tasks": 8, + "task_ids": [ + "NK-WP-0011-T01", + "NK-WP-0011-T02", + "NK-WP-0011-T03", + "NK-WP-0011-T04", + "NK-WP-0011-T05", + "NK-WP-0011-T06", + "NK-WP-0011-T07", + "NK-WP-0011-T08" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0022", + "uuid": "d76ddccc-00c8-548a-b141-2cd660fa38da", + "title": "Cut over NetKingdom identity to railiance01 and retire CoulombCore", + "status": "blocked", + "owner": "codex", + "created": "2026-07-27", + "updated": "2026-08-08", + "record_age_days": 43, + "declared_update_age_days": 31, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md", + "source_sha256": "7a05491a3bc6a01c34bf7f94a42baa14f840689577c6526ee119e688eafb558c", + "task_counts": { + "done": 7, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "NK-WP-0022-T01", + "NK-WP-0022-T02", + "NK-WP-0022-T03", + "NK-WP-0022-T04", + "NK-WP-0022-T05", + "NK-WP-0022-T06", + "NK-WP-0022-T07", + "NK-WP-0022-T08" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0027", + "uuid": "965ad365-6b81-50a1-a2a3-2d0c1fcce0b4", + "title": "Reconcile reef placement and security-zone canon dependencies", + "status": "blocked", + "owner": "net-kingdom", + "created": "2026-08-19", + "updated": "2026-08-22", + "record_age_days": 20, + "declared_update_age_days": 17, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0027-reef-placement-reconciliation.md", + "source_sha256": "27137e0c113f1cbec5c3a4ddc0b9872e103a86bff79cefe7817ab78826df6217", + "task_counts": { + "done": 3, + "wait": 3 + }, + "open_tasks": 3, + "task_ids": [ + "NK-WP-0027-T01", + "NK-WP-0027-T02", + "NK-WP-0027-T03", + "NK-WP-0027-T04", + "NK-WP-0027-T05", + "NK-WP-0027-T06" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0031", + "uuid": "9d7b04f9-3803-5613-b7a5-8bd606c77f5a", + "title": "Implement deterministic posture and evidence feedback", + "status": "blocked", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-08-23", + "record_age_days": 16, + "declared_update_age_days": 16, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0031-deterministic-posture-feedback.md", + "source_sha256": "2b12eb6cbb5f07ee5c4925886504c9ad420eab39b8ccf5551be46be146d37d8d", + "task_counts": { + "done": 4, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "NK-WP-0031-T01", + "NK-WP-0031-T02", + "NK-WP-0031-T03", + "NK-WP-0031-T04", + "NK-WP-0031-T05" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0032", + "uuid": "516ee5b9-685b-5986-88d2-bde66c2ba96c", + "title": "Admit the operator-tunneled OpenBao browser callback", + "status": "blocked", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-08-23", + "record_age_days": 16, + "declared_update_age_days": 16, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0032-openbao-operator-loopback-callback.md", + "source_sha256": "0c57a87bef40acf5c75a70939b1a27c2f94c2fe31a0293e5d9ad14419fbec316", + "task_counts": { + "done": 2, + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "NK-WP-0032-T01", + "NK-WP-0032-T02", + "NK-WP-0032-T03", + "NK-WP-0032-T04" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0033", + "uuid": "63665674-6880-593e-96e6-bab3211b1352", + "title": "Contain and rotate the exposed KeyCape credential bundle", + "status": "active", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-08-23", + "record_age_days": 16, + "declared_update_age_days": 16, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md", + "source_sha256": "9efd8686e71e4c1745ae62a1df3e5cf69db419dc48d554ae7dd2e0377c3e54f0", + "task_counts": { + "done": 3, + "progress": 2 + }, + "open_tasks": 2, + "task_ids": [ + "NK-WP-0033-T01", + "NK-WP-0033-T02", + "NK-WP-0033-T03", + "NK-WP-0033-T04", + "NK-WP-0033-T05" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0034", + "uuid": "c87e142c-4eda-5c1b-84a9-ee5a848f3f63", + "title": "Make the SSO/MFA verification actually verify", + "status": "blocked", + "owner": "codex", + "created": "2026-08-28", + "updated": "2026-09-05", + "record_age_days": 11, + "declared_update_age_days": 3, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0034-verification-that-verifies.md", + "source_sha256": "ae289cc75d27af38a481a892ad1f4c31e19d88ee059ea258b0af277259e5de8d", + "task_counts": { + "wait": 1, + "done": 3 + }, + "open_tasks": 1, + "task_ids": [ + "NK-WP-0034-T01", + "NK-WP-0034-T02", + "NK-WP-0034-T03", + "NK-WP-0034-T04" + ] + }, + { + "repo": "net-kingdom", + "id": "NK-WP-0035", + "uuid": "04685f94-1991-5e62-80d2-5669913e99fc", + "title": "Publish the NetKingdom emission-cadence security profile", + "status": "blocked", + "owner": "codex", + "created": "2026-09-04", + "updated": "2026-09-07", + "record_age_days": 4, + "declared_update_age_days": 1, + "path": "/home/worsch/net-kingdom/workplans/NK-WP-0035-emission-cadence-security-profile.md", + "source_sha256": "e602991278f745e7876db673386341c9dcb08d5c843ed6b29d37c007226fa92d", + "task_counts": { + "done": 4, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "NK-WP-0035-T01", + "NK-WP-0035-T02", + "NK-WP-0035-T03", + "NK-WP-0035-T04", + "NK-WP-0035-T05" + ] + }, + { + "repo": "state-hub", + "id": "CUST-WP-0038", + "uuid": "ccb87fa4-6381-5f22-b097-6e026f56a9c1", + "title": "State Hub Full ThreePhoenix HA Migration", + "status": "backlog", + "owner": "custodian", + "created": "2026-05-02", + "updated": "2026-08-08", + "record_age_days": 129, + "declared_update_age_days": 31, + "path": "/home/worsch/state-hub/workplans/CUST-WP-0038-state-hub-threephoenix-ha.md", + "source_sha256": "84f93ba1bf6805155166c86ba626831a753e9df81d1b06f8f71cd7322cf21ee9", + "task_counts": { + "todo": 8 + }, + "open_tasks": 8, + "task_ids": [ + "CUST-WP-0038-T01", + "CUST-WP-0038-T02", + "CUST-WP-0038-T03", + "CUST-WP-0038-T04", + "CUST-WP-0038-T05", + "CUST-WP-0038-T06", + "CUST-WP-0038-T07", + "CUST-WP-0038-T08" + ] + }, + { + "repo": "state-hub", + "id": "STATE-WP-0079", + "uuid": "ed077b62-7048-5752-bf65-f90471f45854", + "title": "State Hub retirement strangler and disposition execution", + "status": "blocked", + "owner": "codex", + "created": "2026-08-09", + "updated": "2026-09-05", + "record_age_days": 30, + "declared_update_age_days": 3, + "path": "/home/worsch/state-hub/workplans/STATE-WP-0079-retirement-strangler.md", + "source_sha256": "82a32d69da0fc85cdce25bdcde7d215665b7a2519fa20759b92b7451c77d5270", + "task_counts": { + "done": 4, + "wait": 5 + }, + "open_tasks": 5, + "task_ids": [ + "STATE-WP-0079-T01", + "STATE-WP-0079-T02", + "STATE-WP-0079-T03", + "STATE-WP-0079-T04", + "STATE-WP-0079-T05", + "STATE-WP-0079-T06", + "STATE-WP-0079-T07", + "STATE-WP-0079-T08", + "STATE-WP-0079-T09" + ] + }, + { + "repo": "activity-core", + "id": "ACTIVITY-WP-0032", + "uuid": "256dad13-28b4-5361-ab8a-7d1373a5d14b", + "title": "Adopt the Glas profile-driven execution contract", + "status": "active", + "owner": "claude", + "created": "2026-08-21", + "updated": "2026-09-04", + "record_age_days": 18, + "declared_update_age_days": 4, + "path": "/home/worsch/activity-core/workplans/ACTIVITY-WP-0032-glas-profile-execution-contract.md", + "source_sha256": "2293b1c93547fe4a0e69efd3a8cdcc7f41b5c54e743a731f23672dd22d807314", + "task_counts": { + "done": 4, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "ACTIVITY-WP-0032-T01", + "ACTIVITY-WP-0032-T02", + "ACTIVITY-WP-0032-T03", + "ACTIVITY-WP-0032-T04", + "ACTIVITY-WP-0032-T05" + ] + }, + { + "repo": "activity-core", + "id": "ACTIVITY-WP-0035", + "uuid": "fbcc10a9-bc1e-50b2-ba86-47adcb18666d", + "title": "Make the execution boundary enforceable and the review contract truthful", + "status": "active", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-09-04", + "record_age_days": 16, + "declared_update_age_days": 4, + "path": "/home/worsch/activity-core/workplans/ACTIVITY-WP-0035-intent-boundary-guardrails.md", + "source_sha256": "7866e57e5a1a52d7d7e223c3a10ebf86dcfd57255c954637797e32940495bfa7", + "task_counts": { + "done": 7, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "ACTIVITY-WP-0035-T01", + "ACTIVITY-WP-0035-T02", + "ACTIVITY-WP-0035-T03", + "ACTIVITY-WP-0035-T04", + "ACTIVITY-WP-0035-T05", + "ACTIVITY-WP-0035-T06", + "ACTIVITY-WP-0035-T07", + "ACTIVITY-WP-0035-T08" + ] + }, + { + "repo": "activity-core", + "id": "ACTIVITY-WP-0036", + "uuid": "01e6d5d4-6e1a-5f0d-81f0-ded97e0f71cd", + "title": "Bind queue mutations to worker identity and active leases", + "status": "active", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-09-04", + "record_age_days": 16, + "declared_update_age_days": 4, + "path": "/home/worsch/activity-core/workplans/ACTIVITY-WP-0036-queue-identity-and-lease-integrity.md", + "source_sha256": "b6147789fd50739945e3bae9b6d05348f36e0f6bc28d60022ff5cb08eac0e477", + "task_counts": { + "done": 3, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "ACTIVITY-WP-0036-T01", + "ACTIVITY-WP-0036-T02", + "ACTIVITY-WP-0036-T03", + "ACTIVITY-WP-0036-T04" + ] + }, + { + "repo": "adaptive-pricing", + "id": "ADAPTIVE-WP-0010", + "uuid": "543e6398-d2cb-5105-977e-b90461adac3e", + "title": "Plan-derived guardrail spend ceilings", + "status": "proposed", + "owner": "codex", + "created": "2026-08-18", + "updated": "2026-08-18", + "record_age_days": 21, + "declared_update_age_days": 21, + "path": "/home/worsch/adaptive-pricing/workplans/ADAPTIVE-WP-0010-plan-derived-guardrail-ceilings.md", + "source_sha256": "0d46a4005f734139bcf71206f9398d57ef982b7953f153ce9d876cda4811c6b8", + "task_counts": { + "todo": 1, + "wait": 3 + }, + "open_tasks": 4, + "task_ids": [ + "ADAPTIVE-WP-0010-T01", + "ADAPTIVE-WP-0010-T02", + "ADAPTIVE-WP-0010-T03", + "ADAPTIVE-WP-0010-T04" + ] + }, + { + "repo": "approval-engine", + "id": "APPROVAL-WP-0002", + "uuid": "4fa25ad5-f5d0-5592-aa59-085f8ee3edaf", + "title": "Production readiness and consumer adoption", + "status": "active", + "owner": "codex", + "created": "2026-09-01", + "updated": "2026-09-06", + "record_age_days": 7, + "declared_update_age_days": 2, + "path": "/home/worsch/approval-engine/workplans/APPROVAL-WP-0002-production-readiness-and-consumer-adoption.md", + "source_sha256": "fe87ef0896373e88cd33efd67ce24d94f5ef01a38532d3b04b5ff0e71ee0ebe9", + "task_counts": { + "progress": 1, + "done": 1, + "wait": 3 + }, + "open_tasks": 4, + "task_ids": [ + "APPROVAL-WP-0002-T01", + "APPROVAL-WP-0002-T02", + "APPROVAL-WP-0002-T03", + "APPROVAL-WP-0002-T04", + "APPROVAL-WP-0002-T05" + ] + }, + { + "repo": "audit-core", + "id": "AUDIT-WP-0008", + "uuid": "a9a248b2-d26c-503e-a8fc-4f3675e6ed51", + "title": "Tenancy posture declaration and read-path enforcement", + "status": "active", + "owner": "claude", + "created": "2026-08-17", + "updated": "2026-08-22", + "record_age_days": 22, + "declared_update_age_days": 17, + "path": "/home/worsch/audit-core/workplans/AUDIT-WP-0008-tenancy-posture-alignment.md", + "source_sha256": "547426b1a53e2a46c33bfb894950e68ba4a78a9fa17139882a6b9ab3aaa9cd6d", + "task_counts": { + "done": 7, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "AUDIT-WP-0008-T01", + "AUDIT-WP-0008-T02", + "AUDIT-WP-0008-T03", + "AUDIT-WP-0008-T04", + "AUDIT-WP-0008-T05", + "AUDIT-WP-0008-T06", + "AUDIT-WP-0008-T07", + "AUDIT-WP-0008-T08" + ] + }, + { + "repo": "audit-core", + "id": "AUDIT-WP-0009", + "uuid": "46a96b03-bc08-53b5-9c93-4071adabf734", + "title": "Evidence-role conformance under Security Layer Model v0.7", + "status": "active", + "owner": "claude", + "created": "2026-08-29", + "updated": "2026-08-29", + "record_age_days": 10, + "declared_update_age_days": 10, + "path": "/home/worsch/audit-core/workplans/AUDIT-WP-0009-evidence-role-conformance.md", + "source_sha256": "6c33f1dd21372a55d420bc8dfc1a1e2264bd3ea9b58dc7ed1688c88d18bfe0ff", + "task_counts": { + "done": 3, + "todo": 5, + "wait": 1, + "progress": 1 + }, + "open_tasks": 7, + "task_ids": [ + "AUDIT-WP-0009-T01", + "AUDIT-WP-0009-T02", + "AUDIT-WP-0009-T03", + "AUDIT-WP-0009-T04", + "AUDIT-WP-0009-T05", + "AUDIT-WP-0009-T06", + "AUDIT-WP-0009-T07", + "AUDIT-WP-0009-T08", + "AUDIT-WP-0009-T09", + "AUDIT-WP-0009-T10" + ] + }, + { + "repo": "audit-core", + "id": "AUDIT-WP-0010", + "uuid": "54655357-74da-5f7f-8fa6-647d4c969f21", + "title": "Admit tenant-engine as an attributive sender", + "status": "ready", + "owner": "claude", + "created": "2026-08-29", + "updated": "2026-08-29", + "record_age_days": 10, + "declared_update_age_days": 10, + "path": "/home/worsch/audit-core/workplans/AUDIT-WP-0010-tenant-engine-sender-admission.md", + "source_sha256": "376c2cf6bc655bd21300969888d178a20d5c781a4eed08461b23d134a6f9da5a", + "task_counts": { + "todo": 5 + }, + "open_tasks": 5, + "task_ids": [ + "AUDIT-WP-0010-T01", + "AUDIT-WP-0010-T02", + "AUDIT-WP-0010-T03", + "AUDIT-WP-0010-T04", + "AUDIT-WP-0010-T05" + ] + }, + { + "repo": "core-hub", + "id": "CORE-WP-0010", + "uuid": "9cc1abf3-2ab0-54a4-a250-83f382a49441", + "title": "Runtime absorption into hub-core and archive", + "status": "active", + "owner": "codex", + "created": "2026-08-09", + "updated": "2026-08-21", + "record_age_days": 30, + "declared_update_age_days": 18, + "path": "/home/worsch/core-hub/workplans/CORE-WP-0010-runtime-absorption-and-archive.md", + "source_sha256": "62c494ca2694589779f29fa54c9b2e41c5488f68bee221117791273eed23ee1a", + "task_counts": { + "done": 4, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "CORE-WP-0010-T01", + "CORE-WP-0010-T02", + "CORE-WP-0010-T03", + "CORE-WP-0010-T04", + "CORE-WP-0010-T05" + ] + }, + { + "repo": "fin-hub", + "id": "FIN-WP-0004", + "uuid": "e8b432af-43ae-517f-a69b-80d4f0db976d", + "title": "Establish the resource cost evidence contract", + "status": "active", + "owner": "codex", + "created": "2026-08-10", + "updated": "2026-08-15", + "record_age_days": 29, + "declared_update_age_days": 24, + "path": "/home/worsch/fin-hub/workplans/FIN-WP-0004-resource-cost-evidence-contract.md", + "source_sha256": "b10c9fb5d834613ef5cca3a79fba86481578bfcf988a75a0c22e545caf391c31", + "task_counts": { + "done": 8, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "FIN-WP-0004-T01", + "FIN-WP-0004-T02", + "FIN-WP-0004-T03", + "FIN-WP-0004-T04", + "FIN-WP-0004-T05", + "FIN-WP-0004-T06", + "FIN-WP-0004-T07", + "FIN-WP-0004-T08", + "FIN-WP-0004-T09" + ] + }, + { + "repo": "fin-hub", + "id": "FIN-WP-0005", + "uuid": "58432770-da19-5b72-a946-cacbe1eb24ca", + "title": "DATEV accounting adapter operations", + "status": "active", + "owner": "codex", + "created": "2026-08-11", + "updated": "2026-08-11", + "record_age_days": 28, + "declared_update_age_days": 28, + "path": "/home/worsch/fin-hub/workplans/FIN-WP-0005-datev-accounting-adapter-operations.md", + "source_sha256": "024ebafba0cd7afe41626687a65f84add9b003ab517b9f5ed7d3b4486840e209", + "task_counts": { + "todo": 1, + "wait": 3 + }, + "open_tasks": 4, + "task_ids": [ + "FIN-WP-0005-T01", + "FIN-WP-0005-T02", + "FIN-WP-0005-T03", + "FIN-WP-0005-T04" + ] + }, + { + "repo": "fin-hub", + "id": "FIN-WP-0006", + "uuid": "e9413a20-5b11-50ff-ba21-15215841cf11", + "title": "Consume resource-control internal transfer settlement", + "status": "proposed", + "owner": "codex", + "created": "2026-08-14", + "updated": "2026-08-14", + "record_age_days": 25, + "declared_update_age_days": 25, + "path": "/home/worsch/fin-hub/workplans/FIN-WP-0006-internal-transfer-settlement.md", + "source_sha256": "44ee59e55049601a5ccd8e8e4fb125bdf2c9d5da0313fcd9d9942aa672e926d7", + "task_counts": { + "todo": 1 + }, + "open_tasks": 1, + "task_ids": [ + "FIN-WP-0006-T01" + ] + }, + { + "repo": "flex-auth", + "id": "FLEX-WP-0020", + "uuid": "99a661a8-b36c-5c1c-b78b-1e8930bcd0a9", + "title": "Repository identity migration from flex-auth to access-engine", + "status": "proposed", + "owner": "codex", + "created": "2026-08-29", + "updated": "2026-08-29", + "record_age_days": 10, + "declared_update_age_days": 10, + "path": "/home/worsch/flex-auth/workplans/FLEX-WP-0020-repository-identity-migration.md", + "source_sha256": "05a68afddf9a3bc56ae31ea3f11f29c5dcf970dc366ede405210e1fc332e8482", + "task_counts": { + "todo": 5, + "wait": 6 + }, + "open_tasks": 11, + "task_ids": [ + "FLEX-WP-0020-T01", + "FLEX-WP-0020-T02", + "FLEX-WP-0020-T03", + "FLEX-WP-0020-T04", + "FLEX-WP-0020-T05", + "FLEX-WP-0020-T06", + "FLEX-WP-0020-T07", + "FLEX-WP-0020-T08", + "FLEX-WP-0020-T09", + "FLEX-WP-0020-T10", + "FLEX-WP-0020-T11" + ] + }, + { + "repo": "flex-auth", + "id": "FLEX-WP-0022", + "uuid": "804c588c-f47a-50c4-bdd7-51b24bbf9539", + "title": "Tenant scoping is unstated in tenant-engine and untested in two more packages", + "status": "proposed", + "owner": "claude", + "created": "2026-09-06", + "updated": "2026-09-06", + "record_age_days": 2, + "declared_update_age_days": 2, + "path": "/home/worsch/flex-auth/workplans/FLEX-WP-0022-tenant-scope-coverage.md", + "source_sha256": "da34a2450873f8c7589423ca94074725f5e2c4041978489be748865371317775", + "task_counts": { + "todo": 2, + "wait": 1 + }, + "open_tasks": 3, + "task_ids": [ + "FLEX-WP-0022-T01", + "FLEX-WP-0022-T02", + "FLEX-WP-0022-T03" + ] + }, + { + "repo": "flex-auth", + "id": "FLEX-WP-0023", + "uuid": "ad011f92-786c-51ad-b3f6-c06ad77e7af7", + "title": "Operator caller access path and caller identity in the decision record", + "status": "active", + "owner": "claude", + "created": "2026-09-06", + "updated": "2026-09-06", + "record_age_days": 2, + "declared_update_age_days": 2, + "path": "/home/worsch/flex-auth/workplans/FLEX-WP-0023-operator-caller-access-path.md", + "source_sha256": "231bf151b55cd656fb43ce46e05798e9242134af3ad56d88d6f14e8ab47866c7", + "task_counts": { + "done": 4, + "todo": 1 + }, + "open_tasks": 1, + "task_ids": [ + "FLEX-WP-0023-T01", + "FLEX-WP-0023-T02", + "FLEX-WP-0023-T03", + "FLEX-WP-0023-T04", + "FLEX-WP-0023-T05" + ] + }, + { + "repo": "flex-auth", + "id": "FLEX-WP-0024", + "uuid": "90577acd-6910-548d-a13e-1dbfdfb8ed27", + "title": "Sign the decision envelope: the response channel is unauthenticated", + "status": "active", + "owner": "claude", + "created": "2026-09-06", + "updated": "2026-09-06", + "record_age_days": 2, + "declared_update_age_days": 2, + "path": "/home/worsch/flex-auth/workplans/FLEX-WP-0024-decision-envelope-authenticity.md", + "source_sha256": "bb2d04c8772d9180461241fe0379500322f17fbbbcb1533e2be20c116c1347a7", + "task_counts": { + "done": 2, + "todo": 1, + "wait": 1 + }, + "open_tasks": 2, + "task_ids": [ + "FLEX-WP-0024-T01", + "FLEX-WP-0024-T02", + "FLEX-WP-0024-T03", + "FLEX-WP-0024-T04" + ] + }, + { + "repo": "flex-auth", + "id": "FLEX-WP-0025", + "uuid": "f9a657ce-67b4-5d25-9933-e0fcb2c20b1c", + "title": "A policy cannot tell a registry fact from a caller assertion", + "status": "ready", + "owner": "claude", + "created": "2026-09-07", + "updated": "2026-09-07", + "record_age_days": 1, + "declared_update_age_days": 1, + "path": "/home/worsch/flex-auth/workplans/FLEX-WP-0025-fact-versus-assertion.md", + "source_sha256": "fb9ef07b4f027576eaafbdb19b07f0d37fad25339009ad41641fc0a7b6eafa69", + "task_counts": { + "todo": 2, + "wait": 1 + }, + "open_tasks": 3, + "task_ids": [ + "FLEX-WP-0025-T01", + "FLEX-WP-0025-T02", + "FLEX-WP-0025-T03" + ] + }, + { + "repo": "fluid-core", + "id": "FLUID-WP-0001", + "uuid": "b5c231e1-9d06-5772-95a7-01cc0bf62051", + "title": "Bootstrap State Hub integration", + "status": "ready", + "owner": "worsch", + "created": "2026-09-04", + "updated": "2026-09-04", + "record_age_days": 4, + "declared_update_age_days": 4, + "path": "/home/worsch/fluid-core/workplans/FLUID-WP-0001-statehub-bootstrap.md", + "source_sha256": "76272eb110e2e63f3532008164551775c0944864e959716276488d12da17ad04", + "task_counts": { + "todo": 3 + }, + "open_tasks": 3, + "task_ids": [ + "FLUID-WP-0001-T01", + "FLUID-WP-0001-T02", + "FLUID-WP-0001-T03" + ] + }, + { + "repo": "fluid-core", + "id": "FLUID-WP-0008", + "uuid": "291005a5-d474-5c94-8abd-819f682dde9f", + "title": "Handover: HelixForge Telegram identity and hall-of-helix channel", + "status": "active", + "owner": "worsch", + "created": "2026-09-04", + "updated": "2026-09-04", + "record_age_days": 4, + "declared_update_age_days": 4, + "path": "/home/worsch/fluid-core/workplans/FLUID-WP-0008-fluid-telegram-handover.md", + "source_sha256": "df7a361acdbcdf025ef1e5126a7132448976c633cc1194734f29b8d165d314cc", + "task_counts": { + "done": 6, + "todo": 3 + }, + "open_tasks": 3, + "task_ids": [ + "FLUID-WP-0008-T01", + "FLUID-WP-0008-T02", + "FLUID-WP-0008-T03", + "FLUID-WP-0008-T04", + "FLUID-WP-0008-T05", + "FLUID-WP-0008-T06", + "FLUID-WP-0008-T07", + "FLUID-WP-0008-T08", + "FLUID-WP-0008-T09" + ] + }, + { + "repo": "fluid-core", + "id": "FLUID-WP-0009", + "uuid": "b6459dd0-fc4f-54a4-a2e9-d7b83cff6c6e", + "title": "Establish the pr- campaign repository pattern and reduce hall-of-helix to an example", + "status": "active", + "owner": "worsch", + "created": "2026-09-04", + "updated": "2026-09-04", + "record_age_days": 4, + "declared_update_age_days": 4, + "path": "/home/worsch/fluid-core/workplans/FLUID-WP-0009-campaign-repos-and-example-separation.md", + "source_sha256": "9b45d09e45ac7cc7c9f574bac29ac48e8c84700418c145e2996dbb7ea80b2107", + "task_counts": { + "done": 1, + "progress": 1, + "todo": 3 + }, + "open_tasks": 4, + "task_ids": [ + "FLUID-WP-0009-T01", + "FLUID-WP-0009-T02", + "FLUID-WP-0009-T03", + "FLUID-WP-0009-T04", + "FLUID-WP-0009-T05" + ] + }, + { + "repo": "fluid-telegram", + "id": "FT-WP-0001", + "uuid": "a660ed65-700e-5b54-8d91-a556b73518f0", + "title": "Establish HelixForge's Telegram identity and publish the Hall of Helix", + "status": "active", + "owner": "worsch", + "created": "2026-09-04", + "updated": "2026-09-04", + "record_age_days": 4, + "declared_update_age_days": 4, + "path": "/home/worsch/fluid-telegram/workplans/FT-WP-0001-telegram-identity-and-hall-channel.md", + "source_sha256": "a3067bb26834a7458e263bfec277ad81aec898ad2d531d2d481291e67b016a2a", + "task_counts": { + "todo": 13 + }, + "open_tasks": 13, + "task_ids": [ + "FT-WP-0001-T01", + "FT-WP-0001-T02", + "FT-WP-0001-T03", + "FT-WP-0001-T04", + "FT-WP-0001-T05", + "FT-WP-0001-T06", + "FT-WP-0001-T07", + "FT-WP-0001-T08", + "FT-WP-0001-T09", + "FT-WP-0001-T10", + "FT-WP-0001-T11", + "FT-WP-0001-T12", + "FT-WP-0001-T13" + ] + }, + { + "repo": "fluid-telegram", + "id": "FT-WP-0002", + "uuid": "f2373858-c932-5a4d-81b6-db9a3595135a", + "title": "Provision the Telegram presence from a declared specification", + "status": "proposed", + "owner": "worsch", + "created": "2026-09-04", + "updated": "2026-09-04", + "record_age_days": 4, + "declared_update_age_days": 4, + "path": "/home/worsch/fluid-telegram/workplans/FT-WP-0002-declared-presence-provisioning.md", + "source_sha256": "a1ccb51116bbe57eb0ffd5d0324bcbd3d512eefaa59a869642447887a5548065", + "task_counts": { + "progress": 4, + "done": 2, + "todo": 2 + }, + "open_tasks": 6, + "task_ids": [ + "FT-WP-0002-T01", + "FT-WP-0002-T02", + "FT-WP-0002-T03", + "FT-WP-0002-T04", + "FT-WP-0002-T05", + "FT-WP-0002-T06", + "FT-WP-0002-T07", + "FT-WP-0002-T08" + ] + }, + { + "repo": "gate-house", + "id": "GH-WP-0003", + "uuid": "a331dc88-c9bc-5d2a-9ff1-2aa7e837c3bb", + "title": "Security layer model v0.8 amendment set", + "status": "active", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-05", + "record_age_days": 3, + "declared_update_age_days": 3, + "path": "/home/worsch/gate-house/workplans/GH-WP-0003-statute-v08-amendment-set.md", + "source_sha256": "0e7f7c5576e7450b7385c343b8966fb3856fa8cea7be9f2424d2c536d5237485", + "task_counts": { + "done": 8, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "GH-WP-0003-T01", + "GH-WP-0003-T02", + "GH-WP-0003-T03", + "GH-WP-0003-T04", + "GH-WP-0003-T05", + "GH-WP-0003-T06", + "GH-WP-0003-T07", + "GH-WP-0003-T08", + "GH-WP-0003-T09" + ] + }, + { + "repo": "glas-harness", + "id": "GLAS-WP-0012", + "uuid": "170bf1ae-337f-5553-8d1e-03b07100e08f", + "title": "Prove the first local rein profile end to end", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-06", + "record_age_days": 3, + "declared_update_age_days": 2, + "path": "/home/worsch/glas-harness/workplans/GLAS-WP-0012-first-local-profile-production-proof.md", + "source_sha256": "9c33bbfe9d5a9894a8028dfa81e830b3e770dba77b133a7dd48c2e9c39b0baa5", + "task_counts": { + "done": 2, + "wait": 4 + }, + "open_tasks": 4, + "task_ids": [ + "GLAS-WP-0012-T01", + "GLAS-WP-0012-T02", + "GLAS-WP-0012-T03", + "GLAS-WP-0012-T04", + "GLAS-WP-0012-T05", + "GLAS-WP-0012-T06" + ] + }, + { + "repo": "glas-harness", + "id": "GLAS-WP-0015", + "uuid": "94c02b1f-66ed-588d-bdd7-7158107b85fb", + "title": "Drive owner returns for the first production Glas profile", + "status": "active", + "owner": "codex", + "created": "2026-09-06", + "updated": "2026-09-06", + "record_age_days": 2, + "declared_update_age_days": 2, + "path": "/home/worsch/glas-harness/workplans/GLAS-WP-0015-production-dependency-coordination.md", + "source_sha256": "493979a18cccab93c7d6e0f794f3f2cfe24abed8f14bda0993dadd9fad7172d0", + "task_counts": { + "done": 2, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "GLAS-WP-0015-T01", + "GLAS-WP-0015-T02", + "GLAS-WP-0015-T03" + ] + }, + { + "repo": "hall-of-helix", + "id": "HOH-WP-0002", + "uuid": "5e0db595-2f0e-5388-9413-7d4d5a4a2ef5", + "title": "Publish the hall at helix.coulomb.social with selectable renderers", + "status": "active", + "owner": "claude-code", + "created": "2026-09-05", + "updated": "2026-09-05", + "record_age_days": 3, + "declared_update_age_days": 3, + "path": "/home/worsch/hall-of-helix/workplans/HOH-WP-0002-published-hall-and-renderers.md", + "source_sha256": "12a703b7230a58001ebd6586564ea480c048b4fd349e6e788ec49629061e3b1c", + "task_counts": { + "todo": 4, + "wait": 2 + }, + "open_tasks": 6, + "task_ids": [ + "HOH-WP-0002-T01", + "HOH-WP-0002-T02", + "HOH-WP-0002-T03", + "HOH-WP-0002-T04", + "HOH-WP-0002-T05", + "HOH-WP-0002-T06" + ] + }, + { + "repo": "hub-core", + "id": "HUB-WP-0006", + "uuid": "05ebd06e-4af8-5f6c-918c-c143c1520e00", + "title": "Repository classification aggregation and navigation", + "status": "active", + "owner": "codex", + "created": "2026-08-22", + "updated": "2026-08-22", + "record_age_days": 17, + "declared_update_age_days": 17, + "path": "/home/worsch/hub-core/workplans/HUB-WP-0006-repository-classification-navigation.md", + "source_sha256": "6ff18fa22bec1f88d1037559e2ba1272d974ee2ebae7be7fd8990c7cf1b4a6dc", + "task_counts": { + "done": 5, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "HUB-WP-0006-T01", + "HUB-WP-0006-T02", + "HUB-WP-0006-T03", + "HUB-WP-0006-T04", + "HUB-WP-0006-T05", + "HUB-WP-0006-T06" + ] + }, + { + "repo": "hub-core", + "id": "HUB-WP-0009", + "uuid": "0d6e94f3-fd15-5f57-af41-60f0b862da5e", + "title": "Complete the hub-extension conformance profile", + "status": "proposed", + "owner": "codex", + "created": "2026-08-31", + "updated": "2026-08-31", + "record_age_days": 8, + "declared_update_age_days": 8, + "path": "/home/worsch/hub-core/workplans/HUB-WP-0009-extension-conformance-gaps.md", + "source_sha256": "4a21ff8c2ff80aeded7c5a3ffaf3da11d08e9ab7c73f1feeb7e6f771fe334100", + "task_counts": { + "todo": 4 + }, + "open_tasks": 4, + "task_ids": [ + "HUB-WP-0009-T01", + "HUB-WP-0009-T02", + "HUB-WP-0009-T03", + "HUB-WP-0009-T04" + ] + }, + { + "repo": "hub-core", + "id": "HUB-WP-0011", + "uuid": "3c8034fc-fd90-58f5-99bc-99b4f93e5ee1", + "title": "State Hub inbox freshness and reader cutover", + "status": "proposed", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-05", + "record_age_days": 3, + "declared_update_age_days": 3, + "path": "/home/worsch/hub-core/workplans/HUB-WP-0011-statehub-inbox-freshness-and-cutover.md", + "source_sha256": "837221810a2c5a238b09d1fc712b3b27b354e6c5e34dfba04153aa26476a71e3", + "task_counts": { + "todo": 1, + "wait": 2 + }, + "open_tasks": 3, + "task_ids": [ + "HUB-WP-0011-T01", + "HUB-WP-0011-T02", + "HUB-WP-0011-T03" + ] + }, + { + "repo": "issue-core", + "id": "ISSUE-WP-0006", + "uuid": "4d465264-cbe1-56ba-84ed-bd580b649b76", + "title": "Forgejo-only forge + projection boundary (not ops queue)", + "status": "ready", + "owner": "grok", + "created": "2026-08-03", + "updated": "2026-08-03", + "record_age_days": 36, + "declared_update_age_days": 36, + "path": "/home/worsch/issue-core/workplans/ISSUE-WP-0006-forgejo-only-projection-boundary.md", + "source_sha256": "7d17becc3f937a617854578cbe609b572da93260cdf1462f2b7e41d2b8814756", + "task_counts": { + "todo": 4 + }, + "open_tasks": 4, + "task_ids": [ + "ISSUE-WP-0006-T01", + "ISSUE-WP-0006-T02", + "ISSUE-WP-0006-T03", + "ISSUE-WP-0006-T04" + ] + }, + { + "repo": "kings-guard", + "id": "KG-WP-0005", + "uuid": null, + "title": "Admit and validate qonto-assistant source completeness evidence", + "status": "active", + "owner": "codex", + "created": "2026-09-04", + "updated": "2026-09-05", + "record_age_days": 4, + "declared_update_age_days": 3, + "path": "/home/worsch/kings-guard/workplans/KG-WP-0005-qonto-source-cadence-admission.md", + "source_sha256": "b583c702efeb0a04a78c5e555afb86d142a9215265dce5234c1968f1f9d0e33a", + "task_counts": { + "done": 2, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "KG-WP-0005-T01", + "KG-WP-0005-T02", + "KG-WP-0005-T03" + ] + }, + { + "repo": "ops-mason", + "id": "MASON-WP-0003", + "uuid": "4015b46d-02f1-56ac-853e-87e8542cf0dd", + "title": "Forge read lane so central can derive private repositories", + "status": "active", + "owner": "codex", + "created": "2026-08-26", + "updated": "2026-08-26", + "record_age_days": 13, + "declared_update_age_days": 13, + "path": "/home/worsch/ops-mason/workplans/MASON-WP-0003-state-hub-forge-read-lane.md", + "source_sha256": "bb43081015dcf5e9be037664e51da785fde5e9584f545f1107d1543d8a8dc49d", + "task_counts": { + "done": 2, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "MASON-WP-0003-T01", + "MASON-WP-0003-T02", + "MASON-WP-0003-T03" + ] + }, + { + "repo": "ops-mason", + "id": "MASON-WP-0004", + "uuid": "e5656747-a974-581a-a3d4-4e6bb7262f4c", + "title": "Describe every stored credential so the store is navigable", + "status": "proposed", + "owner": "codex", + "created": "2026-08-28", + "updated": "", + "record_age_days": 11, + "declared_update_age_days": null, + "path": "/home/worsch/ops-mason/workplans/MASON-WP-0004-credential-inventory-descriptions.md", + "source_sha256": "07bae6138175c3d2939e0ec55f09dda4682c80a848a91558ddaaad0d1c5f96c2", + "task_counts": { + "todo": 2, + "wait": 2 + }, + "open_tasks": 4, + "task_ids": [ + "MASON-WP-0004-T01", + "MASON-WP-0004-T02", + "MASON-WP-0004-T03", + "MASON-WP-0004-T04" + ] + }, + { + "repo": "ops-mason", + "id": "MASON-WP-0005", + "uuid": "483e56d6-6601-5377-9066-66225214c046", + "title": "Construct the fluid-telegram operator credential lane", + "status": "proposed", + "owner": "codex", + "created": "2026-09-04", + "updated": "2026-09-04", + "record_age_days": 4, + "declared_update_age_days": 4, + "path": "/home/worsch/ops-mason/workplans/MASON-WP-0005-fluid-telegram-operator-credential-lane.md", + "source_sha256": "03560755c64292a4c52f65f9816d39412274dd41ffeafff935c0c232d2b7b099", + "task_counts": { + "wait": 1, + "todo": 5 + }, + "open_tasks": 6, + "task_ids": [ + "MASON-WP-0005-T01", + "MASON-WP-0005-T02", + "MASON-WP-0005-T03", + "MASON-WP-0005-T04", + "MASON-WP-0005-T05", + "MASON-WP-0005-T06" + ] + }, + { + "repo": "ops-warden", + "id": "WARDEN-WP-0027", + "uuid": "21528e8d-a049-523d-9ae1-da7a27cb8bbf", + "title": "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)", + "status": "active", + "owner": "codex", + "created": "2026-07-16", + "updated": "2026-08-23", + "record_age_days": 54, + "declared_update_age_days": 16, + "path": "/home/worsch/ops-warden/workplans/WARDEN-WP-0027-credential-governance-lockdown.md", + "source_sha256": "bc40a4a3339fe359e2afa03545d3078b08e8765faf06d8322449e57063241d02", + "task_counts": { + "cancel": 2, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "WARDEN-WP-0027-T01", + "WARDEN-WP-0027-T02", + "WARDEN-WP-0027-T03" + ] + }, + { + "repo": "ops-warden", + "id": "WARDEN-WP-0034", + "uuid": "ae3ff76f-883d-5e2f-b6aa-144d61e8fdef", + "title": "Layer model v0.7 conformance \u2014 state the deadline, bind the agent boundary, steward the estate's newest rule", + "status": "active", + "owner": "ops-warden", + "created": "2026-08-29", + "updated": "2026-09-05", + "record_age_days": 10, + "declared_update_age_days": 3, + "path": "/home/worsch/ops-warden/workplans/WARDEN-WP-0034-layer-model-v07-conformance.md", + "source_sha256": "5188050eaedbe0799679c92a128fdb9ce96189747ab03e4ea09860cadf586547", + "task_counts": { + "done": 4, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "WARDEN-WP-0034-T01", + "WARDEN-WP-0034-T02", + "WARDEN-WP-0034-T03", + "WARDEN-WP-0034-T04", + "WARDEN-WP-0034-T05" + ] + }, + { + "repo": "ops-warden", + "id": "WARDEN-WP-0037", + "uuid": "42a097db-1c24-558e-a724-030bb2b4443e", + "title": "Repoint the whynot-design npm lane to Forgejo", + "status": "active", + "owner": "codex", + "created": "2026-09-04", + "updated": "2026-09-04", + "record_age_days": 4, + "declared_update_age_days": 4, + "path": "/home/worsch/ops-warden/workplans/WARDEN-WP-0037-whynot-design-forgejo-npm-lane.md", + "source_sha256": "93a70c25978b69828cf295d659e89a6cba3dc6b5403fa5d84b23e8a083207195", + "task_counts": { + "done": 2, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "WARDEN-WP-0037-T01", + "WARDEN-WP-0037-T02", + "WARDEN-WP-0037-T03" + ] + }, + { + "repo": "pqrst-practice", + "id": "PQRST-WP-0002", + "uuid": "6a875b19-5a76-55c1-bd1f-2f5005cd416b", + "title": "Validate spec v0.1 in real session closes and land PQRST in hall-of-helix", + "status": "proposed", + "owner": "claude-code", + "created": "2026-09-05", + "updated": "2026-09-05", + "record_age_days": 3, + "declared_update_age_days": 3, + "path": "/home/worsch/pqrst-practice/workplans/PQRST-WP-0002-validate-v01-against-real-sessions.md", + "source_sha256": "99f1d05458b9157bf0405964177889e827628c2f58c21a57859078201573183e", + "task_counts": { + "todo": 3, + "done": 2 + }, + "open_tasks": 3, + "task_ids": [ + "PQRST-WP-0002-T01", + "PQRST-WP-0002-T02", + "PQRST-WP-0002-T03", + "PQRST-WP-0002-T04", + "PQRST-WP-0002-T05" + ] + }, + { + "repo": "prj-forgejo-org-refactor", + "id": "ORGREF-WP-0001", + "uuid": "c1dcd349-1a7a-51ae-8827-4ce96cfe0008", + "title": "Foundation, blast-radius inventory, and execution entry gate", + "status": "backlog", + "owner": "codex", + "created": "2026-08-11", + "updated": "2026-08-19", + "record_age_days": 28, + "declared_update_age_days": 20, + "path": "/home/worsch/prj-forgejo-org-refactor/workplans/ORGREF-WP-0001-foundation-and-entry-gate.md", + "source_sha256": "b1219d4e1725da9695c4fad60832a118e4e94e63c293d13714ef3c5800e020a4", + "task_counts": { + "todo": 5 + }, + "open_tasks": 5, + "task_ids": [ + "ORGREF-WP-0001-T01", + "ORGREF-WP-0001-T02", + "ORGREF-WP-0001-T03", + "ORGREF-WP-0001-T04", + "ORGREF-WP-0001-T05" + ] + }, + { + "repo": "prj-unattended-progress-company", + "id": "UPC-WP-0002", + "uuid": "8d47ba5f-0608-5f83-8b4b-7dee53ada6f6", + "title": "Company vessel close-out (G1 + residual G2/G8)", + "status": "active", + "owner": "bernd", + "created": "2026-08-11", + "updated": "2026-08-16", + "record_age_days": 28, + "declared_update_age_days": 23, + "path": "/home/worsch/prj-unattended-progress-company/workplans/UPC-WP-0002-company-vessel-closeout.md", + "source_sha256": "90abfdd68d39ec39121c1e05d8da987d34607bef15966180ba15ab9d3831d101", + "task_counts": { + "progress": 4 + }, + "open_tasks": 4, + "task_ids": [ + "UPC-WP-0002-T01", + "UPC-WP-0002-T02", + "UPC-WP-0002-T03", + "UPC-WP-0002-T04" + ] + }, + { + "repo": "prj-unattended-progress-company", + "id": "UPC-WP-0003", + "uuid": "81b17b8a-4b22-5510-8830-a8d19aed821e", + "title": "Unattended dogfood acceptance and founder-load envelope (G3\u2013G4)", + "status": "proposed", + "owner": "bernd", + "created": "2026-08-11", + "updated": "2026-08-11", + "record_age_days": 28, + "declared_update_age_days": 28, + "path": "/home/worsch/prj-unattended-progress-company/workplans/UPC-WP-0003-unattended-and-load.md", + "source_sha256": "551903b654af8c4b71bfe2cf4d75c4ad163b47e3c13c65527e7d96b2f1d171b2", + "task_counts": { + "todo": 3 + }, + "open_tasks": 3, + "task_ids": [ + "UPC-WP-0003-T01", + "UPC-WP-0003-T02", + "UPC-WP-0003-T03" + ] + }, + { + "repo": "prj-unattended-progress-company", + "id": "UPC-WP-0004", + "uuid": "a6cf0a20-a3d5-56c6-8fc7-8cb167c71d66", + "title": "First external offer and paid revenue path (G5\u2013G6)", + "status": "proposed", + "owner": "bernd", + "created": "2026-08-11", + "updated": "2026-08-11", + "record_age_days": 28, + "declared_update_age_days": 28, + "path": "/home/worsch/prj-unattended-progress-company/workplans/UPC-WP-0004-first-offer-and-revenue.md", + "source_sha256": "5604acd3d4592448944b8c9f9c7031e0e20b5ac133aad3b54d91b9aa2db687a9", + "task_counts": { + "todo": 3 + }, + "open_tasks": 3, + "task_ids": [ + "UPC-WP-0004-T01", + "UPC-WP-0004-T02", + "UPC-WP-0004-T03" + ] + }, + { + "repo": "railiance-cluster", + "id": "RCLUSTER-WP-0007", + "uuid": "16da36fe-5a10-522b-b6d6-02dbb6de6c14", + "title": "ThreePhoenix - HA Cluster Implementation", + "status": "blocked", + "owner": "codex", + "created": "2026-02-25", + "updated": "2026-08-22", + "record_age_days": 195, + "declared_update_age_days": 17, + "path": "/home/worsch/railiance-cluster/workplans/RCLUSTER-WP-0007-threephoenix-ha-cluster.md", + "source_sha256": "cd1c1b20a4d9756844009917dc9bb59fccc562d69fb2c9925cdc6b9094f3b26b", + "task_counts": { + "todo": 5, + "cancel": 2 + }, + "open_tasks": 5, + "task_ids": [ + "RCLUSTER-WP-0007-T01", + "RCLUSTER-WP-0007-T02", + "RCLUSTER-WP-0007-T03", + "RCLUSTER-WP-0007-T04", + "RCLUSTER-WP-0007-T05", + "RCLUSTER-WP-0007-T06", + "RCLUSTER-WP-0007-T07" + ] + }, + { + "repo": "railiance-fabric", + "id": "RAIL-FAB-WP-0028", + "uuid": "58a56363-3bda-50f7-8240-1e45131bc7d9", + "title": "Host and operate the financial Fabric authority", + "status": "proposed", + "owner": "codex", + "created": "2026-08-31", + "updated": "2026-08-31", + "record_age_days": 8, + "declared_update_age_days": 8, + "path": "/home/worsch/railiance-fabric/workplans/RAIL-FAB-WP-0028-hosted-financial-fabric-authority.md", + "source_sha256": "742b8ca25b794391366aafffb462a0df753bc9ec9d00b4caea829029eeb5419c", + "task_counts": { + "todo": 1, + "wait": 3 + }, + "open_tasks": 4, + "task_ids": [ + "RAIL-FAB-WP-0028-T01", + "RAIL-FAB-WP-0028-T02", + "RAIL-FAB-WP-0028-T03", + "RAIL-FAB-WP-0028-T04" + ] + }, + { + "repo": "railiance-infra", + "id": "RAIL-HO-WP-0011", + "uuid": "5738f113-1c4e-5d27-95b2-b6655e0b7279", + "title": "Make the S1 declaration reproducible and the handoff verifiably green", + "status": "active", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-08-23", + "record_age_days": 16, + "declared_update_age_days": 16, + "path": "/home/worsch/railiance-infra/workplans/RAIL-HO-WP-0011-reproducible-s1-declaration-and-handoff.md", + "source_sha256": "8d20bb36eededd4b550f2d885bca97ebb3dee9184263ff2136523ff513913d2b", + "task_counts": { + "done": 6, + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "RAIL-HO-WP-0011-T01", + "RAIL-HO-WP-0011-T02", + "RAIL-HO-WP-0011-T03", + "RAIL-HO-WP-0011-T04", + "RAIL-HO-WP-0011-T05", + "RAIL-HO-WP-0011-T06", + "RAIL-HO-WP-0011-T07", + "RAIL-HO-WP-0011-T08" + ] + }, + { + "repo": "railiance-infra", + "id": "RAIL-HO-WP-0012", + "uuid": "5ea28f8f-376c-5230-8bb7-ca871c1a75f4", + "title": "Close the encrypted S1 backup and recovery loop", + "status": "active", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-08-23", + "record_age_days": 16, + "declared_update_age_days": 16, + "path": "/home/worsch/railiance-infra/workplans/RAIL-HO-WP-0012-s1-backup-recovery-loop.md", + "source_sha256": "eccfd1b3a0b89701074c7afdc23250824338901648742367d2dbf0db6d9dd78c", + "task_counts": { + "done": 4, + "progress": 1, + "wait": 1 + }, + "open_tasks": 2, + "task_ids": [ + "RAIL-HO-WP-0012-T01", + "RAIL-HO-WP-0012-T02", + "RAIL-HO-WP-0012-T03", + "RAIL-HO-WP-0012-T04", + "RAIL-HO-WP-0012-T05", + "RAIL-HO-WP-0012-T06" + ] + }, + { + "repo": "railiance-master", + "id": "RMASTER-WP-0020", + "uuid": "a7d0c934-75d7-53cc-a35b-6a789a2e0f14", + "title": "Migrate authoritative OpenBao from CoulombCore to reef-railiance", + "status": "blocked", + "owner": "codex", + "created": "2026-07-30", + "updated": "2026-08-23", + "record_age_days": 40, + "declared_update_age_days": 16, + "path": "/home/worsch/railiance-master/workplans/RMASTER-WP-0020-openbao-migration-to-reef-railiance.md", + "source_sha256": "11bb0eda69fa8484936b8dca7daacf028178a3307d410642e04d0e224a19bde4", + "task_counts": { + "done": 7, + "wait": 1, + "progress": 1 + }, + "open_tasks": 2, + "task_ids": [ + "RMASTER-WP-0020-T01", + "RMASTER-WP-0020-T02", + "RMASTER-WP-0020-T03", + "RMASTER-WP-0020-T04", + "RMASTER-WP-0020-T05", + "RMASTER-WP-0020-T06", + "RMASTER-WP-0020-T07", + "RMASTER-WP-0020-T08", + "RMASTER-WP-0020-T09" + ] + }, + { + "repo": "railiance-platform", + "id": "RPF-WP-0015", + "uuid": "f4640325-e89c-591d-b58e-ec6b087900ac", + "title": "Coordinate audit-core temporary custody and recovery exercises", + "status": "blocked", + "owner": "codex", + "created": "2026-08-22", + "updated": "2026-09-05", + "record_age_days": 17, + "declared_update_age_days": 3, + "path": "/home/worsch/railiance-platform/workplans/RPF-WP-0015-audit-core-custody-and-recovery-coordination.md", + "source_sha256": "79126d5e18fc72730296c8bf2a833f75243dc31cceee383c3ccb6f91eeaa471f", + "task_counts": { + "done": 2, + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "RPF-WP-0015-T01", + "RPF-WP-0015-T02", + "RPF-WP-0015-T03", + "RPF-WP-0015-T04" + ] + }, + { + "repo": "railiance-platform", + "id": "RPF-WP-0025", + "uuid": "6dda6039-295e-5cac-aef6-3183c3218649", + "title": "Retract public OpenBao listener behind operator-only access", + "status": "blocked", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-09-06", + "record_age_days": 16, + "declared_update_age_days": 2, + "path": "/home/worsch/railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md", + "source_sha256": "5a32c904ba272ef59303293bd863cf1f812397b3713ebf1bef0e2f30eca0026a", + "task_counts": { + "done": 2, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "RPF-WP-0025-T01", + "RPF-WP-0025-T02", + "RPF-WP-0025-T03" + ] + }, + { + "repo": "railiance-platform", + "id": "RPF-WP-0027", + "uuid": "b2c25a01-4a80-55c1-90cf-8538000f7e0e", + "title": "Coordinate KeyCape live Secret exposure recovery", + "status": "blocked", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-09-05", + "record_age_days": 16, + "declared_update_age_days": 3, + "path": "/home/worsch/railiance-platform/workplans/RPF-WP-0027-keycape-live-secret-exposure-recovery.md", + "source_sha256": "0e7e7cd112a9f7c786b61f31466519b3bd0db9d359a4c7abb1fc57d09f69df44", + "task_counts": { + "done": 3, + "wait": 3 + }, + "open_tasks": 3, + "task_ids": [ + "RPF-WP-0027-T01", + "RPF-WP-0027-T02", + "RPF-WP-0027-T03", + "RPF-WP-0027-T04", + "RPF-WP-0027-T05", + "RPF-WP-0027-T06" + ] + }, + { + "repo": "railiance-platform", + "id": "RPF-WP-0029", + "uuid": "bb326ebb-a313-549e-b35f-1bf17e1c58fd", + "title": "Remove backup credential default and verify governed replacement", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-06", + "record_age_days": 3, + "declared_update_age_days": 2, + "path": "/home/worsch/railiance-platform/workplans/RPF-WP-0029-backup-credential-default-removal.md", + "source_sha256": "ca51d268c34bd0634d208850b4e48c2d19ab10148d03881923e308551d341244", + "task_counts": { + "done": 2, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "RPF-WP-0029-T01", + "RPF-WP-0029-T02", + "RPF-WP-0029-T03" + ] + }, + { + "repo": "railiance-platform", + "id": "RPF-WP-0035", + "uuid": "975db491-5412-5e27-8e34-14a2417bb039", + "title": "Implement reviewed credential lanes with separate owner gates", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-06", + "record_age_days": 3, + "declared_update_age_days": 2, + "path": "/home/worsch/railiance-platform/workplans/RPF-WP-0035-credential-lane-implementation.md", + "source_sha256": "78324b192f5d8c4f2cff2f24d34ed97cf3a1a31393e506b50008f854c257e90f", + "task_counts": { + "done": 2, + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "RPF-WP-0035-T01", + "RPF-WP-0035-T02", + "RPF-WP-0035-T03", + "RPF-WP-0035-T04" + ] + }, + { + "repo": "railiance-platform", + "id": "RPF-WP-0036", + "uuid": "ca639c3d-3a87-5fa4-ad13-6f2e014b0c84", + "title": "Close S3 service assurance and ownership gaps", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-06", + "record_age_days": 3, + "declared_update_age_days": 2, + "path": "/home/worsch/railiance-platform/workplans/RPF-WP-0036-platform-service-assurance.md", + "source_sha256": "9a05c96ada5330ca2450cac9ab457396bb764d730bd0c49d21b8c3e8cbf0c489", + "task_counts": { + "done": 4, + "wait": 3 + }, + "open_tasks": 3, + "task_ids": [ + "RPF-WP-0036-T01", + "RPF-WP-0036-T02", + "RPF-WP-0036-T03", + "RPF-WP-0036-T04", + "RPF-WP-0036-T05", + "RPF-WP-0036-T06", + "RPF-WP-0036-T07" + ] + }, + { + "repo": "railiance-platform", + "id": "RPF-WP-0038", + "uuid": "7beec1a7-aa82-5a36-9a66-6b60008a2455", + "title": "Close Forgejo primary backup coverage on Scaleway", + "status": "active", + "owner": "codex", + "created": "2026-09-06", + "updated": "2026-09-06", + "record_age_days": 2, + "declared_update_age_days": 2, + "path": "/home/worsch/railiance-platform/workplans/RPF-WP-0038-forgejo-scaleway-primary-coverage.md", + "source_sha256": "3548ae766fe3afbc14ca1ab9482f0dedd88d37f4c2edb499e1829e3134dbfdc9", + "task_counts": { + "done": 3, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "RPF-WP-0038-T01", + "RPF-WP-0038-T02", + "RPF-WP-0038-T03", + "RPF-WP-0038-T04" + ] + }, + { + "repo": "railiance-telemetry", + "id": "RTEL-WP-0002", + "uuid": "08a5db92-7293-50d3-b589-55287b9850b3", + "title": "Provide the Q2 receiving contract and prove signal delivery", + "status": "active", + "owner": "codex", + "created": "2026-09-06", + "updated": "2026-09-06", + "record_age_days": 2, + "declared_update_age_days": 2, + "path": "/home/worsch/railiance-telemetry/workplans/RTEL-WP-0002-signal-contract.md", + "source_sha256": "95c810a2b027adccdcfb4cee9cac06af968613f22a924299e5bc4e5c4d288e76", + "task_counts": { + "done": 3, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "RTEL-WP-0002-T01", + "RTEL-WP-0002-T02", + "RTEL-WP-0002-T03", + "RTEL-WP-0002-T04" + ] + }, + { + "repo": "rapp-canned-prompts", + "id": "RCP-WP-0002", + "uuid": "11874f32-ac36-5bb9-a0a5-e7a259f5972c", + "title": "First deployment of canned-prompts on Railiance", + "status": "active", + "owner": "codex", + "created": "2026-09-06", + "updated": "2026-09-06", + "record_age_days": 2, + "declared_update_age_days": 2, + "path": "/home/worsch/rapp-canned-prompts/workplans/RCP-WP-0002-first-deployment.md", + "source_sha256": "792080084eabab13df3a2f98a42bb6fe09ec0092f95333fc0afaa600ede21c7f", + "task_counts": { + "done": 3, + "progress": 1, + "wait": 1 + }, + "open_tasks": 2, + "task_ids": [ + "RCP-WP-0002-T01", + "RCP-WP-0002-T02", + "RCP-WP-0002-T03", + "RCP-WP-0002-T04", + "RCP-WP-0002-T05" + ] + }, + { + "repo": "rapp-core-hub", + "id": "RAPPCOREHUB-WP-0002", + "uuid": "626cb2d7-9525-5712-be9e-93c1ed840fc5", + "title": "Hub-core candidate and production cutover", + "status": "active", + "owner": "codex", + "created": "2026-08-21", + "updated": "2026-08-21", + "record_age_days": 18, + "declared_update_age_days": 18, + "path": "/home/worsch/rapp-core-hub/workplans/RAPPCOREHUB-WP-0002-hub-core-candidate-and-cutover.md", + "source_sha256": "123cd456fe4115bca27b14faa61f3956692f5f40a799863ca5ac321aea48a30f", + "task_counts": { + "done": 4, + "progress": 1 + }, + "open_tasks": 1, + "task_ids": [ + "RAPPCOREHUB-WP-0002-T01", + "RAPPCOREHUB-WP-0002-T02", + "RAPPCOREHUB-WP-0002-T03", + "RAPPCOREHUB-WP-0002-T04", + "RAPPCOREHUB-WP-0002-T05" + ] + }, + { + "repo": "rapp-core-hub", + "id": "RAPPCOREHUB-WP-0003", + "uuid": "b73f1e1a-efaf-5f2f-b916-2a3040e0242e", + "title": "Forgejo-backed repository classification publisher", + "status": "active", + "owner": "codex", + "created": "2026-09-01", + "updated": "2026-09-01", + "record_age_days": 7, + "declared_update_age_days": 7, + "path": "/home/worsch/rapp-core-hub/workplans/RAPPCOREHUB-WP-0003-forgejo-repository-publisher.md", + "source_sha256": "9697442d36d6ea22b11f13ea554a284e84b2b882a25ff02b1b50cdf2a5c8bd3e", + "task_counts": { + "done": 3, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "RAPPCOREHUB-WP-0003-T01", + "RAPPCOREHUB-WP-0003-T02", + "RAPPCOREHUB-WP-0003-T03", + "RAPPCOREHUB-WP-0003-T04" + ] + }, + { + "repo": "rapp-openbao", + "id": "RAPP-OPENBAO-WP-0002", + "uuid": "df859d65-c6ee-5058-a662-ad74eb82d3d2", + "title": "Replace public OpenBao UI exposure with operator-only access", + "status": "blocked", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-08-23", + "record_age_days": 16, + "declared_update_age_days": 16, + "path": "/home/worsch/rapp-openbao/workplans/RAPP-OPENBAO-WP-0002-operator-only-ui-exposure.md", + "source_sha256": "2c1a46daae3be100a6f0773d5603e120e742bed8fc8e7bbae5cff9d849ee3c76", + "task_counts": { + "done": 1, + "progress": 1, + "wait": 1 + }, + "open_tasks": 2, + "task_ids": [ + "RAPP-OPENBAO-WP-0002-T01", + "RAPP-OPENBAO-WP-0002-T02", + "RAPP-OPENBAO-WP-0002-T03" + ] + }, + { + "repo": "rapp-postgres", + "id": "RAPP-POSTGRES-WP-0006", + "uuid": "e861bad8-8b92-5963-b554-e9b6fa043acb", + "title": "Admit canned-prompts on the PostgreSQL overflow cell", + "status": "active", + "owner": "claude", + "created": "2026-09-07", + "updated": "2026-09-07", + "record_age_days": 1, + "declared_update_age_days": 1, + "path": "/home/worsch/rapp-postgres/workplans/RAPP-POSTGRES-WP-0006-canned-prompts-admission.md", + "source_sha256": "abc06e0a0a41269103b3f2ca84e194c393fae5e2577912ac202344ee20974bd4", + "task_counts": { + "done": 2, + "open": 1 + }, + "open_tasks": 1, + "task_ids": [ + "RAPP-POSTGRES-WP-0006-T01", + "RAPP-POSTGRES-WP-0006-T02", + "RAPP-POSTGRES-WP-0006-T03" + ] + }, + { + "repo": "rapp-qonto", + "id": "RAPP-QONTO-WP-0002", + "uuid": "6152c89b-a4f3-55b6-af0b-d57462b3c6f7", + "title": "Publish rapp-qonto usage and cost evidence", + "status": "ready", + "owner": "codex", + "created": "2026-08-11", + "updated": "2026-08-15", + "record_age_days": 28, + "declared_update_age_days": 24, + "path": "/home/worsch/rapp-qonto/workplans/RAPP-QONTO-WP-0002-resource-usage-and-cost-evidence.md", + "source_sha256": "f311e2276d1bcad06f5fdf92487ee9efcad68098e585f326ee48890856186fea", + "task_counts": { + "todo": 3 + }, + "open_tasks": 3, + "task_ids": [ + "RAPP-QONTO-WP-0002-T01", + "RAPP-QONTO-WP-0002-T02", + "RAPP-QONTO-WP-0002-T03" + ] + }, + { + "repo": "rapp-telemetry", + "id": "RAPP-TELEMETRY-WP-0001", + "uuid": "13305ba8-33d8-56a4-af79-165092a02677", + "title": "Establish and activate the managed telemetry package on railiance01", + "status": "active", + "owner": "codex", + "created": "2026-09-06", + "updated": "2026-09-06", + "record_age_days": 2, + "declared_update_age_days": 2, + "path": "/home/worsch/rapp-telemetry/workplans/RAPP-TELEMETRY-WP-0001-foundation.md", + "source_sha256": "928261789758e08b23d4e7c35ad3c4de420eea5f2a9bee6c81e95b2205bac60c", + "task_counts": { + "done": 3, + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "RAPP-TELEMETRY-WP-0001-T01", + "RAPP-TELEMETRY-WP-0001-T02", + "RAPP-TELEMETRY-WP-0001-T03", + "RAPP-TELEMETRY-WP-0001-T04", + "RAPP-TELEMETRY-WP-0001-T05" + ] + }, + { + "repo": "rapp-tenant-engine", + "id": "RAPP-TENANT-ENGINE-WP-0001", + "uuid": "ec2896aa-9226-5516-a537-2de02138949f", + "title": "Bootstrap rapp-tenant-engine", + "status": "proposed", + "owner": null, + "created": "", + "updated": "", + "record_age_days": null, + "declared_update_age_days": null, + "path": "/home/worsch/rapp-tenant-engine/workplans/RAPP-TENANT-ENGINE-WP-0001-bootstrap.md", + "source_sha256": "77d8c246401204a83f4028a90ed4f61b5eda3839dbc3a0bfe55c31ec5a6b6416", + "task_counts": {}, + "open_tasks": 0, + "task_ids": [] + }, + { + "repo": "reef-railiance", + "id": "REEF-RAILIANCE-WP-0003", + "uuid": "8ac413ad-2f57-53e6-b586-c5bec9cfbd1f", + "title": "Complete rapp-qonto production gates", + "status": "blocked", + "owner": "codex", + "created": "2026-07-26", + "updated": "2026-08-21", + "record_age_days": 44, + "declared_update_age_days": 18, + "path": "/home/worsch/reef-railiance/workplans/REEF-RAILIANCE-WP-0003-rapp-qonto-production-gates.md", + "source_sha256": "d402495156c5b8ce59de2a4fbb1e874bf2fe347904db79a57be3015e248eba4a", + "task_counts": { + "done": 3, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "REEF-RAILIANCE-WP-0003-T01", + "REEF-RAILIANCE-WP-0003-T02", + "REEF-RAILIANCE-WP-0003-T03", + "REEF-RAILIANCE-WP-0003-T04" + ] + }, + { + "repo": "reef-storage", + "id": "REEF-STORAGE-WP-0002", + "uuid": "af6ed97f-fc45-5fc0-b8e9-6010c217808f", + "title": "Fill Scaleway attributes after purchase", + "status": "active", + "owner": "grok", + "created": "2026-08-14", + "updated": "2026-08-15", + "record_age_days": 25, + "declared_update_age_days": 24, + "path": "/home/worsch/reef-storage/workplans/REEF-STORAGE-WP-0002-fill-after-purchase.md", + "source_sha256": "831ff1989b839b00e08b44056264d4d67245d6918eee1fe389e103b78e824b7e", + "task_counts": { + "done": 1, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "REEF-STORAGE-WP-0002-T01", + "REEF-STORAGE-WP-0002-T02" + ] + }, + { + "repo": "rein-aharness", + "id": "REINAH-WP-0003", + "uuid": "eba2eff1-10a7-50a3-a70b-14e7d398f27f", + "title": "Governed runtime integrity and intent convergence", + "status": "active", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-09-04", + "record_age_days": 16, + "declared_update_age_days": 4, + "path": "/home/worsch/rein-aharness/workplans/REINAH-WP-0003-governed-runtime-integrity.md", + "source_sha256": "d9567a1200fd999f25c3de6f26a342a7037ed76dc6a821fdac2c8530d2392bf7", + "task_counts": { + "done": 3, + "wait": 2, + "progress": 1 + }, + "open_tasks": 3, + "task_ids": [ + "REINAH-WP-0003-T01", + "REINAH-WP-0003-T02", + "REINAH-WP-0003-T03", + "REINAH-WP-0003-T04", + "REINAH-WP-0003-T05", + "REINAH-WP-0003-T06" + ] + }, + { + "repo": "reuse-surface", + "id": "REUSE-WP-0021", + "uuid": "0d1beafd-e638-5bb9-b91d-13543ac42a04", + "title": "Follow the CommerceCanon repository rename in federation sources", + "status": "active", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-06", + "record_age_days": 3, + "declared_update_age_days": 2, + "path": "/home/worsch/reuse-surface/workplans/REUSE-WP-0021-commerce-canon-source-rename.md", + "source_sha256": "e280efa73aa9517d01b870cc61c95507f28446fe0d906d46ce7303aa78c5ec9b", + "task_counts": { + "done": 1, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "REUSE-WP-0021-T01", + "REUSE-WP-0021-T02" + ] + }, + { + "repo": "sand-boxer", + "id": "SAND-WP-0014", + "uuid": "b616d1cd-208f-5ecf-a4a0-a028396422c4", + "title": "Owner-mediated governed bwrap execution", + "status": "active", + "owner": "codex", + "created": "2026-09-04", + "updated": "2026-09-05", + "record_age_days": 4, + "declared_update_age_days": 3, + "path": "/home/worsch/sand-boxer/workplans/SAND-WP-0014-owner-mediated-execution.md", + "source_sha256": "f877775cb121cbcac8996d733b25c48d7f649f93a05e5ebbf2b1dc05b0806c82", + "task_counts": { + "done": 4, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "SAND-WP-0014-T01", + "SAND-WP-0014-T02", + "SAND-WP-0014-T03", + "SAND-WP-0014-T04", + "SAND-WP-0014-T05" + ] + }, + { + "repo": "sand-boxer", + "id": "SAND-WP-0015", + "uuid": "d3f12387-fd23-58f0-b979-9c811507614d", + "title": "Provide a pinned bwrap rein runtime and private state", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-06", + "record_age_days": 3, + "declared_update_age_days": 2, + "path": "/home/worsch/sand-boxer/workplans/SAND-WP-0015-bwrap-runtime-and-private-state.md", + "source_sha256": "e6a12a1fd55795f84a8b063c5c2844612c4211e546aa00cc6ab06bb1f8867ee9", + "task_counts": { + "done": 4, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "SAND-WP-0015-T01", + "SAND-WP-0015-T02", + "SAND-WP-0015-T03", + "SAND-WP-0015-T04", + "SAND-WP-0015-T05" + ] + }, + { + "repo": "secrets-engine", + "id": "SECRETS-WP-0006", + "uuid": "31f7f8ea-7f73-516c-8877-f03a13f1db82", + "title": "Adopt concrete OpenBao credential lanes from ops-warden", + "status": "active", + "owner": "codex", + "created": "2026-08-21", + "updated": "2026-09-06", + "record_age_days": 18, + "declared_update_age_days": 2, + "path": "/home/worsch/secrets-engine/workplans/SECRETS-WP-0006-catalog-lane-adoption.md", + "source_sha256": "332ecc127b311651e350ede3a6e16548bead2d6852204a86ad9862830a02e63c", + "task_counts": { + "done": 4, + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "SECRETS-WP-0006-T01", + "SECRETS-WP-0006-T02", + "SECRETS-WP-0006-T03", + "SECRETS-WP-0006-T04", + "SECRETS-WP-0006-T05", + "SECRETS-WP-0006-T06" + ] + }, + { + "repo": "secrets-engine", + "id": "SECRETS-WP-0007", + "uuid": "68a39be1-bd9c-5133-ad64-e7bca892aaf3", + "title": "Production-safe provisioning, authorization, and lifecycle hardening", + "status": "active", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-09-06", + "record_age_days": 16, + "declared_update_age_days": 2, + "path": "/home/worsch/secrets-engine/workplans/SECRETS-WP-0007-production-lifecycle-hardening.md", + "source_sha256": "f0535eb6b52334d975dcb8f3cfd5a8ca5b13f1c16df156fcbbff970765493856", + "task_counts": { + "done": 5, + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "SECRETS-WP-0007-T01", + "SECRETS-WP-0007-T02", + "SECRETS-WP-0007-T03", + "SECRETS-WP-0007-T04", + "SECRETS-WP-0007-T05", + "SECRETS-WP-0007-T06", + "SECRETS-WP-0007-T07" + ] + }, + { + "repo": "secrets-engine", + "id": "SECRETS-WP-0008", + "uuid": "9c9e5164-b2f5-5ea2-a557-5368d65e9fe0", + "title": "Evolve the Lifecycle engine to the accepted security layer model", + "status": "active", + "owner": "grok", + "created": "2026-08-29", + "updated": "2026-09-06", + "record_age_days": 10, + "declared_update_age_days": 2, + "path": "/home/worsch/secrets-engine/workplans/SECRETS-WP-0008-layer-model-lifecycle-conformance.md", + "source_sha256": "86639f33fec9f093b3ab33c7f3a4626601e39c7170227ba48642cb6dc9cdccc9", + "task_counts": { + "done": 4, + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "SECRETS-WP-0008-T01", + "SECRETS-WP-0008-T02", + "SECRETS-WP-0008-T03", + "SECRETS-WP-0008-T04", + "SECRETS-WP-0008-T05", + "SECRETS-WP-0008-T06" + ] + }, + { + "repo": "secrets-engine", + "id": "SECRETS-WP-0009", + "uuid": "40ccc3b4-d046-5a58-8649-e7935f45c974", + "title": "Activate native Claude credential delivery for Glas", + "status": "blocked", + "owner": "codex", + "created": "2026-09-05", + "updated": "2026-09-05", + "record_age_days": 3, + "declared_update_age_days": 3, + "path": "/home/worsch/secrets-engine/workplans/SECRETS-WP-0009-glas-claude-native-delivery.md", + "source_sha256": "df246fdc6b8f83388a044ec195a44c1d07574ca6d0657255182b95242125fc60", + "task_counts": { + "done": 2, + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "SECRETS-WP-0009-T01", + "SECRETS-WP-0009-T02", + "SECRETS-WP-0009-T03" + ] + }, + { + "repo": "soul-frame", + "id": "SOUL-WP-0008", + "uuid": "c730a7e2-244e-558c-9ec1-66d04e275ff8", + "title": "Phase VII \u2014 Soul Frame research paper", + "status": "ready", + "owner": "grok", + "created": "2026-08-09", + "updated": "2026-08-12", + "record_age_days": 30, + "declared_update_age_days": 27, + "path": "/home/worsch/soul-frame/workplans/SOUL-WP-0008-phase-vii-paper.md", + "source_sha256": "e1ee9aaf67e2491059a60b87771d86a77dc1e4523f94694bc8943c0d99b5f568", + "task_counts": { + "todo": 4 + }, + "open_tasks": 4, + "task_ids": [ + "SOUL-WP-0008-T01", + "SOUL-WP-0008-T02", + "SOUL-WP-0008-T03", + "SOUL-WP-0008-T04" + ] + }, + { + "repo": "tenant-engine", + "id": "TEN-WP-0012", + "uuid": "cb7387d0-431d-56a2-bb7b-86a024aeeefb", + "title": "Track the two external dispositions tenant-engine is waiting on", + "status": "blocked", + "owner": "claude", + "created": "2026-09-07", + "updated": "2026-09-07", + "record_age_days": 1, + "declared_update_age_days": 1, + "path": "/home/worsch/tenant-engine/workplans/TEN-WP-0012-external-conformance-waits.md", + "source_sha256": "d72728c06028e248d5e9c1b576a82f1b8b4c124e2a3e9e14d50f7ad1b06263ca", + "task_counts": { + "wait": 2 + }, + "open_tasks": 2, + "task_ids": [ + "TEN-WP-0012-T01", + "TEN-WP-0012-T02" + ] + }, + { + "repo": "test-driver", + "id": "TD-WP-0003", + "uuid": "36a082df-1288-567d-9a0b-f2e0f292786c", + "title": "Generalise the model and settle the open questions", + "status": "proposed", + "owner": "codex", + "created": "2026-08-23", + "updated": "2026-08-23", + "record_age_days": 16, + "declared_update_age_days": 16, + "path": "/home/worsch/test-driver/workplans/TD-WP-0003-generalise-and-settle.md", + "source_sha256": "673f9d65c56433c942e881e529bda711d086759b1251a841d7affbaf0a7552b0", + "task_counts": { + "todo": 7, + "wait": 1 + }, + "open_tasks": 8, + "task_ids": [ + "TD-WP-0003-T01", + "TD-WP-0003-T02", + "TD-WP-0003-T03", + "TD-WP-0003-T04", + "TD-WP-0003-T05", + "TD-WP-0003-T06", + "TD-WP-0003-T07", + "TD-WP-0003-T08" + ] + }, + { + "repo": "whitehat-security", + "id": "WHITEHAT-WP-0006", + "uuid": "fe26f070-70ca-55ba-92b3-3378929ba90f", + "title": "Authorized live residuals after WHITEHAT-WP-0001", + "status": "blocked", + "owner": "net-kingdom", + "created": "2026-09-01", + "updated": "2026-09-01", + "record_age_days": 7, + "declared_update_age_days": 7, + "path": "/home/worsch/whitehat-security/workplans/WHITEHAT-WP-0006-authorized-live-residuals.md", + "source_sha256": "e766ab5e4b965922586dc5627b109c14bf086a1d10ae2a57409a7b7f00b3bb14", + "task_counts": { + "wait": 3 + }, + "open_tasks": 3, + "task_ids": [ + "WHITEHAT-WP-0006-T01", + "WHITEHAT-WP-0006-T02", + "WHITEHAT-WP-0006-T03" + ] + }, + { + "repo": "whitehat-security", + "id": "WHITEHAT-WP-0008", + "uuid": "94b71ba3-998d-5166-9730-6beb5f595923", + "title": "Authorized live ASM residuals after WHITEHAT-WP-0007", + "status": "blocked", + "owner": "net-kingdom", + "created": "2026-09-02", + "updated": "2026-09-02", + "record_age_days": 6, + "declared_update_age_days": 6, + "path": "/home/worsch/whitehat-security/workplans/WHITEHAT-WP-0008-live-asm-residuals.md", + "source_sha256": "0de48476c29ab8e2337f062adb1ff522015629e5381cc67ba23dd86694bf3934", + "task_counts": { + "wait": 1 + }, + "open_tasks": 1, + "task_ids": [ + "WHITEHAT-WP-0008-T01" + ] + } +] diff --git a/docs/proposals/prj-helixforge-factory/.repo-classification.yaml b/docs/proposals/prj-helixforge-factory/.repo-classification.yaml new file mode 100644 index 0000000..573f7f7 --- /dev/null +++ b/docs/proposals/prj-helixforge-factory/.repo-classification.yaml @@ -0,0 +1,15 @@ +repo_classification: + standard: Repo Classification Standard + version: "1.1" + classified_at: "2026-09-08" + classified_by: codex + category: project + domain: infotech + secondary_domains: [agents] + capability_tags: [governance, coordination, automation, operations] + business_stake: [technology, operations, execution, intelligence] + business_mechanics: [intention, coordination, operation, control, adaptation] + notes: >- + Proposed temporary coordination project for a bounded internal HelixForge + software factory on Railiance. Implementations remain in functional repos; + archive after accepted delivery, operating evidence and residual handoff. diff --git a/docs/proposals/prj-helixforge-factory/AGENTS.md b/docs/proposals/prj-helixforge-factory/AGENTS.md new file mode 100644 index 0000000..f28f9dc --- /dev/null +++ b/docs/proposals/prj-helixforge-factory/AGENTS.md @@ -0,0 +1,38 @@ +# Proposed project agent instructions + +This packet is staged in the Custodian. Until project adoption, changes here +prepare the proposal only; do not register it as an unrelated Custodian workplan +or claim it is an active project. + +After adoption, repo slug is `prj-helixforge-factory`; proposed workplan prefix +`HFACT-WP-` must be checked with the authoritative registrar before first index. + +Orient with `GOAL.md`, `SCOPE.md`, genesis, source workplans and `dependency-map.md`. +Read the generated `.custodian-brief.md` when available. Use State Hub HTTP at +`http://127.0.0.1:8000` locally, `http://10.43.68.154:8000` on railiance01; +use an enabled edge relay only with its explicit configuration. Direct requests +carry `X-StateHub-Component: prj-helixforge-factory` and canonical `/workplans/` +and `/tasks/?workplan_id=...` routes. + +Check this project's unread inbox and mark reviewed messages read. Do not send +messages to other owners without user authorization. Refer to existing +GLAS-WP-0015 threads and receipts to avoid repeated requests. + +Implementation remains in participating repos under their instructions. +Advance only within existing grants and session authorization. Do not infer +permission for secrets, publication, deployment or paid execution from this +proposed programme. Before any credential need, run `warden route find` and +`warden route show`; ops-warden issues SSH certificates, while OpenBao/platform, +KeyCape and the relevant policy/approval owners retain other responsibilities. +Never place secret values in work records or logs. + +Update source task statuses as work progresses. Record significant decisions +as source-backed decision records and the supported Hub decision projection. +At session close log a concise `POST /progress/` event and run +`statehub fix-consistency` after workplan edits. If the CLI/API is unavailable, +retain evidence of the failed sync and request operator recovery; do not claim +queued or failed writes are central success. + +Before finishing or archiving, create live owner records for actionable +residuals, name their IDs in the completion record, and verify synchronization. +No production implementation belongs in this coordination repository. diff --git a/docs/proposals/prj-helixforge-factory/GOAL.md b/docs/proposals/prj-helixforge-factory/GOAL.md new file mode 100644 index 0000000..98ac3e9 --- /dev/null +++ b/docs/proposals/prj-helixforge-factory/GOAL.md @@ -0,0 +1,90 @@ +--- +repo: prj-helixforge-factory +repo_flavor: project +project_status: draft +started: "2026-09-08" +reviewed: "2026-09-08" +--- + +# Goal + +## Outcome + +Establish an internal HelixForge software factory that repeatedly turns bounded +Coulomb demands into validated, reusable capabilities, with agent execution and +at least one resulting software service running on Railiance. Humans retain +capability acceptance and the release decisions required by existing policy. + +The first factory serves one explicitly admitted internal tenant. A second +repository demonstrates reuse; it does not introduce a second tenant. The +existing Glas proof's `tenant:platform`, `actor: agt`, `project: glas-local-proof` +remain scoped to that proof. The pilot gets its own reviewed binding where +needed; no identity or authorization transfers merely by copying a profile. + +## Invariants + +1. Source files and their published revisions own work. Existing owners retain + code, deployment and policy authority. The project links their records. +2. An admitted task states capability intent, scope, tests, allowed repository + effects, actor/tenant, runtime/profile pins, timeout, spend envelope and review + disposition before execution. Repo instructions/prompts cannot expand grants. +3. Repository-changing agents execute inside the demonstrated isolation and + repository transaction boundary. The first pilot permits one active mutator. +4. Source tests, deployed operation and accepted usefulness are separate claims. + A local stub, startup probe or historical profile does not prove the current + production route. The localhost proof is not Railiance admission. +5. Credential custody, policy decisions, approval consumption, audit delivery + and publication use existing admitted owner paths. No secret material goes + into Git, messages or progress evidence. +6. Build/test workers and release authority remain separated by their existing + credential and trust boundaries. An accepted commit grants no implicit push, + package publication or deployment authority. +7. Preserve working coordination and recovery services during migrations. + Source deletion, public exposure changes and broader tenant admission retain + their existing independent gates. +8. No new permanent service or generic framework is established in this project + or in the retiring State Hub. Product implementations remain with owners. + +## Success gates + +Targets below are proposed for T01 acceptance; they are not measured baselines +or spending approval. Any revision must be decided before its observation window. + +| Gate | Required evidence | +| --- | --- | +| G0 — A bounded operating contract | Named capability acceptance owner, operational owner, internal tenant, pilot service, two participating repos, exact grants, budget, allowed release lane, test oracle and source-backed owner dependencies. All pilot dependencies have an owner, return evidence and next review/action. | +| G1 — Real governed model execution | Current GLAS-WP-0012 candidate produces its real artifact with protected owner credentials, correct attribution, declared egress, denial and teardown proof. Only the demonstrated profile becomes ready. | +| G2 — Railiance execution | Admitted installed runtime and worker on railiance01 execute through Activity Core with a current versioned profile and repository grant. Natural claim/heartbeat/close, accepted changed paths, clean source baseline, durable evidence/replay and controlled lease-loss refusal are demonstrated. | +| G3 — Useful delivered capability | One bounded real service/library change has intent and contract, relevant OAS structural/semantic checks, independent tests, accepted review, immutable Forgejo artifact identity, authorized Railiance release, service smoke and rollback proof. A second repo consumes or reuses the capability. Documentation-only or smoke-only output is insufficient for this gate. | +| G4 — Controlled operation | Budget/timeout and grant violations stop work; worker crash, Hub/queue outage, terminal-close replay and sandbox cleanup are exercised without duplicate accepted mutations. Backup and recovery evidence covers the actual worker state, source/artifact path and pilot workload. No stale evidence claim is presented as current. | +| G5 — Repeatability and founder load | Over 14 consecutive calendar days, at least five useful accepted changes across two repos, at least one service release, ≥80% of admitted delivery attempts accepted without operator repair, median human handling ≤30 minutes per accepted change, routine operation ≤30 minutes/day. All attempts, retries, rejects, costs and interventions retained. Report setup and attended security/recovery time separately and in total founder load. | + +Suggested initial hard limits for T01: one mutating run; 30 minutes wall clock +per run; EUR 5 equivalent maximum model spend per run; EUR 25 equivalent per +day and EUR 150 total pilot model spend. The admitted provider/runtime must be +able to enforce the selected envelope; token counts alone do not establish a +currency cap. If enforcement is unavailable, adopt and prove an enforceable +conservative limit before admitting paid execution. Infrastructure costs are +measured separately; adding capacity requires an owner decision. + +G5 counts one admitted capability-change request as one delivery attempt; +retries consume the same attempt's cost and handling time and must not inflate +the denominator. Cancellation/refusal after admission remains an unsuccessful +attempt with a reason. A human's planned review/release approval is expected; +manual repair, re-prompting to rescue output, or bypassing a failed gate prevents +that attempt from counting as accepted without repair. Five clean trivial runs +cannot stand in for five useful changes with predeclared acceptance criteria. + +## Project retirement + +Archive only when G0–G5 have accepted evidence, the permanent owners have +accepted operating responsibility, and every actionable residual has a live +owner record outside the closing narrative. Update HelixForge's durable +capability/operating documentation and owning repos' runbooks; retain links to +merged/published revisions, deployment evidence, decisions and residual IDs in +a completion record. Do not archive or shut down any participating service as +part of retiring this coordination repository. + +External tenant onboarding, autonomous production release, additional rein/model +families, full HA and commercial-company success are outside these gates. +`UPC-WP-0003` retains its separate ≥30-day company-load objective. diff --git a/docs/proposals/prj-helixforge-factory/README.md b/docs/proposals/prj-helixforge-factory/README.md new file mode 100644 index 0000000..9b2aa08 --- /dev/null +++ b/docs/proposals/prj-helixforge-factory/README.md @@ -0,0 +1,20 @@ +# Factory project — adoption pointer + +The user authorized implementation on 2026-09-08. The dedicated Git project now +lives at [/home/worsch/prj-helixforge-factory](/home/worsch/prj-helixforge-factory/README.md). +Its [current workplan](/home/worsch/prj-helixforge-factory/workplans/HFACT-WP-0001-establish-internal-factory.md) +and [delivery evidence](/home/worsch/prj-helixforge-factory/evidence/2026-09-08-delivery.md) +own ongoing coordination. Forgejo repository creation and central registration +await the routed OpenBao caller login. + +The other files in this directory are the **frozen original proposal**, retained +until canonical project publication succeeds. Do not update them as a second +programme. HFACT-WP-0001 in the dedicated project is the current source. + +Internal capability: **reuse-surface** (REUSE-WP-0022, completed and published). +Customer service/UI product: **vergabe-teilnahme** (VERGABE-WP-0018; source and +release checks complete, admitted deployment still waiting). +Railiance Fabric retains medium-term topology and placement work. + +- [Original assessment](../../assessments/2026-09-08-helixforge-factory.md) +- [Execution return](../../assessments/2026-09-08-helixforge-factory-followthrough.md) diff --git a/docs/proposals/prj-helixforge-factory/SCOPE.md b/docs/proposals/prj-helixforge-factory/SCOPE.md new file mode 100644 index 0000000..487fddf --- /dev/null +++ b/docs/proposals/prj-helixforge-factory/SCOPE.md @@ -0,0 +1,55 @@ +# Scope + +## Project authority + +This proposed project owns factory success gates, sequencing, integration +acceptance, the dependency map and consolidated evidence. The Custodian +coordinates; `helix-forge` owns the durable product and capability acceptance. +Accountable people/agents and allocated capacity are confirmed in T01, not +assigned to other repositories by writing this proposal. + +## Participating repositories + +| Owner | Responsibility retained | +| --- | --- | +| helix-forge | Human intent, reusable capability contract, architecture fit and value acceptance | +| the-custodian | Governance, source-record conventions, portfolio assessment and project oversight | +| repo-manager / current State Hub projection | Canonical repository/work identity, files, registration and derived coordination views | +| activity-core | Admitted definitions, ops_run queue, worker identity and leases | +| rein-aharness | Claim worker, repository transaction/acceptance, terminal-close delivery | +| glas-harness | Versioned profile selection and real-profile acceptance; existing owner coordination GLAS-WP-0015 | +| sand-boxer | Runtime provisioning, isolated execution, constrained egress, private state and teardown | +| key-cape, flex-auth (access-engine), approval-engine, secrets-engine, audit-core | Identity, decision, approval, native credential delivery and evidence contracts respectively | +| railiance-platform | Admitted credential custody and shared-service dependencies | +| railiance-master and concrete rail/rapp/reef owners | Execution/workload admission, placement, package deployment and recoverability | +| railiance-forge / railiance-enablement | Runner/artifact operations and existing reusable CI/release paths | +| Chosen source and workload repositories | Pilot code, meaningful tests, release, consumer integration and operating evidence | +| kaizen-agentic / coulomb-loop | Existing improvement definitions and demand/feedback context where appropriate | +| prj-unattended-progress-company | Receives relevant factory-load evidence; retains independent company/revenue gates | + +Names above are current checkout identities. This project does not rename +`flex-auth`, replace `coordination-engine`, or create a parallel ownership model. + +## In scope + +- One internal factory lane and its exact prerequisite closures. +- Two-repository capability delivery and reuse, including a Railiance service release. +- Minimal work-record hygiene needed for dispatch and accountability. +- Fresh operating evidence, recovery, cost and founder-load measurement. + +## Out of scope + +- Production code or credential material in this repository. +- Clearing the entire estate backlog as an entry gate. +- Full HA, wholesale hub retirement, broad renaming or global schema redesign. +- External tenant onboarding, community campaign expansion or revenue operations. +- Any implicit authorization from a proposed workplan or from another owner's + historic session authorization. + +## Work-record rule + +The project workplan contains acceptance/handoff tasks and references existing +owner work. It does not duplicate child implementation task lists. A newly +discovered implementation gap receives an owning source-backed task or intake +before it is counted as assigned. Dependencies are current records, not just +messages; an acknowledgement is not a completion receipt. diff --git a/docs/proposals/prj-helixforge-factory/dependency-map.md b/docs/proposals/prj-helixforge-factory/dependency-map.md new file mode 100644 index 0000000..59c7153 --- /dev/null +++ b/docs/proposals/prj-helixforge-factory/dependency-map.md @@ -0,0 +1,44 @@ +# Proposed factory dependency map + +Date: 2026-09-08. This is a source proposal for acceptance sequencing. Actual +owner task statuses remain in their repositories and the derived Hub. +Stage/receipt is not inferred from the existence of a message or package. + +| Project gate | Supplying record(s) | Current return / next evidence | Factory effect | +| --- | --- | --- | --- | +| T03 identity admission | KEY-WP-0013-T02; platform custody record to be resolved through the existing Glas request | Two service clients and protected consumer delivery remain unproven. Tenant choice is resolved. Identify the exact admitted custody record; do not substitute a generic database lane. | Blocks approval service acceptance | +| T03 audit admission | AUDIT-WP-0009-T03/T09; APPROVAL-WP-0002-T01 | Evidence kind is implemented; sender scope/secret policy and credential admission need owner returns. T09 is already high priority/progress. | Blocks approval startup | +| T03 approval | APPROVAL-WP-0002-T01/T03/T05 | Published image is pinned. Latest recorded production review found no deployed service. Need identity, audit, rollout, claim/consume and restart/restore receipts. | Blocks native credential action | +| T03 credentials | SECRETS-WP-0009-T03; SECRETS-WP-0007-T04 and SECRETS-WP-0008-T02/T06 as applicable | September 7 decision-path proof resolved digest normalization; remaining external dependency is the approval claim endpoint. Need real scoped activation/delivery evidence. | Blocks paid real-model proof | +| T04 runtime/profile | SAND-WP-0015-T04; GLAS-WP-0012-T02–T06 | Pinned startup candidate and synthetic transport exist. Need protected placement, native credentials, real model, exact binding, teardown and negative evidence. | Blocks current local profile readiness | +| T05 worker | REINAH-WP-0003-T05/T06; ACTIVITY-WP-0032-T05, ACTIVITY-WP-0035-T08, ACTIVITY-WP-0036-T04 | Queue and repository boundaries exist; current source heartbeat correction needs deployed natural trace and controlled late-close evidence. | Blocks governed production lane | +| T05 placement | railiance-master admission contracts; concrete runtime/reef owner record selected in T01 | Existing user-service worker on railiance01 is the starting point. Require explicit ownership and admitted profile/credential/recovery contract for this host. | Blocks claim that the local proof operates on Railiance | +| T06 delivery | Chosen source repo record and consuming repo record selected in T01; existing forge/enablement contracts | No existing end-to-end HelixForge factory acceptance owner was found. Adopt bounded useful-change/release work, with independent tests and actual consumer. | Blocks useful factory result | +| T07 recovery | REINAH-WP-0003-T05; RPF-WP-0038-T04 and actual pilot workload/package owner | Restore demonstrations exist; scheduled caller, inventory/retention and current worker/pilot recovery still need exact coverage. | Bounds operating readiness | +| T08 value/load | HelixForge acceptance; UPC-WP-0003 as receiving context | No current fourteen-day factory delivery/load evidence was established by this assessment. | Blocks repeatability claim | + +GLAS-WP-0015 is the existing owner-handoff coordinator for T03/T04. The factory +project consumes its results and adds the software-delivery/operating acceptance +that it does not own. Do not create parallel identity/audit/runtime coordination. + +When adopting the map, record canonical task IDs, accountable contact, required +receipt, source revision and next review condition in each owner handoff. Set +structured dependency fields/edges only with the supported source/projection +semantics; do not invent an API convention or overwrite source UUIDs. + +Separate lanes retained outside the factory critical path: + +- `NK-WP-0033/0034` and `RPF-WP-0027`: known incident/verification closure. + Resolve impact on the proposed privilege boundary before expansion; ordinary + incident priority is not displaced by factory WIP limits. +- `RMASTER-WP-0020-T08`: retained CoulombCore cleanup, with recovery and explicit + destructive-approval gates. It is not a prerequisite to installing the factory. +- `RMASTER-WP-0020-T09`, `RPF-WP-0025`, `RAPP-OPENBAO-WP-0002`, `NK-WP-0032`: + public listener/private login migration. Preserve existing requirements; do not + merge it into native service delivery unless an owner demonstrates dependency. +- `STATE-WP-0079`, `CORE-WP-0010`, relevant `HUB-*` and `RAPPCOREHUB-*` work: + staged hub migration, with receiver and quiet-window gates. Keep existing + coordination operational while the factory consumes stable contracts. +- `CUST-WP-0038`, ThreePhoenix HA, enterprise federation, broad repository + renames, extra rein/model profiles and publication campaigns: separate benefit + decisions; no blanket factory dependency. diff --git a/docs/proposals/prj-helixforge-factory/history/2026-09-08-genesis.md b/docs/proposals/prj-helixforge-factory/history/2026-09-08-genesis.md new file mode 100644 index 0000000..f7b4f1b --- /dev/null +++ b/docs/proposals/prj-helixforge-factory/history/2026-09-08-genesis.md @@ -0,0 +1,24 @@ +# Genesis — 2026-09-08 + +The operator asked the Custodian to assess the Coulomb, HelixForge and Railiance +ecosystem, especially blocked/open workplan load, and provide a plan for an +agentic software factory. + +The pre-proposal Hub snapshot contained 98 open workplan rows. Four explicitly +retired identities reduced the canonical baseline to 94 plans, 27 blocked, +containing 264 open tasks. All 94 matched local source workplan status. The +direct execution cohort contained nine plans and fifteen open tasks; much of +the remaining dependency load concerned identity/custody/audit and Railiance. + +The proposal consumes existing GLAS-WP-0015 coordination and implementation +work. Its distinct deliverable is a useful, repeatable capability delivery loop +on Railiance with operating evidence and measurable human load. This avoids +mistaking either source-complete components or the HelixForge publication +programme for a functioning software factory. + +Source assessment: +`the-custodian/docs/assessments/2026-09-08-helixforge-factory.md`. +Captured baseline and provenance live beside that report. This packet remains a +draft in the Custodian until HFACT-WP-0001-T01 establishes its dedicated project +source and verifies the prefix with the registrar. No factory work was activated +and no owner was contacted by this assessment. diff --git a/docs/proposals/prj-helixforge-factory/workplans/HFACT-WP-0001-establish-internal-factory.md b/docs/proposals/prj-helixforge-factory/workplans/HFACT-WP-0001-establish-internal-factory.md new file mode 100644 index 0000000..941bb8f --- /dev/null +++ b/docs/proposals/prj-helixforge-factory/workplans/HFACT-WP-0001-establish-internal-factory.md @@ -0,0 +1,320 @@ +--- +id: HFACT-WP-0001 +type: workplan +title: "Establish the internal HelixForge software factory on Railiance" +domain: infotech +repo: prj-helixforge-factory +status: proposed +owner: the-custodian +topic_slug: infotech +created: "2026-09-08" +updated: "2026-09-08" +related: + - GLAS-WP-0012 + - GLAS-WP-0015 + - SAND-WP-0015 + - REINAH-WP-0003 + - ACTIVITY-WP-0032 + - ACTIVITY-WP-0035 + - ACTIVITY-WP-0036 + - KEY-WP-0013 + - APPROVAL-WP-0002 + - SECRETS-WP-0009 + - AUDIT-WP-0009 + - RPF-WP-0038 + - UPC-WP-0003 +--- + +# Establish the internal factory + +**Proposal only.** Prepared in the Custodian on 2026-09-08; not yet a registered +project or an execution authorization. Prefix allocation and adoption are T01. +The assessment is complete; the eight tasks below are future factory work. + +The [goal](../GOAL.md) defines success. The [dependency map](../dependency-map.md) +identifies existing work to consume. This workplan owns integration acceptance +and handoff; it neither replaces nor copies child implementation plans. + +Recommended sequence: + +```text +T01 → T02 +T01 → T03 ─┐ +T01 → T04 ─┴→ T05 → T06 → T08 +T01 → T07 ───────────────→ T08 +``` + +T04 runtime preparation can advance before T03 finishes; real model acceptance +cannot. T07 recovery preparation can advance early; its live proof depends on +the deployed T05/T06 configuration. T02 is complete before regular scheduling. + +## T01 — Adopt the project and select the first valuable capability + +```task +id: HFACT-WP-0001-T01 +status: todo +priority: high +assignee: the-custodian +``` + +Coordinator: the-custodian. Acceptance: the HelixForge product owner and the +operator responsible for Railiance. Estimated effort: 1–2 engineering days. + +Review this packet against current published owner revisions, confirm a unique +prefix, establish the dedicated project repo under ADR-005, publish/register it +through the authorized path, and sync its source records. Retain a pointer from +the Custodian rather than two editable copies of the programme. + +Select a **small, useful software service or library capability** with a +repeatable independent test, a known release path and a second consuming repo. +Prefer an existing internal workload and existing CI. Avoid beginning with +identity, credential or production-control code as the agent's pilot target. +HelixForge owns the demand/contract; the actual source and consumer owners +accept the bounded implementation records. Record why this capability matters +and the expected reuse before selecting a convenient task from the queue. + +Confirm one internal tenant, exact actor/project/repository/profile tuple, +human acceptance and operating owners, allowed branch/push/release effects, +the proposed G0–G5 targets, capacity allocation and an enforceable spend/time +envelope. Assess the outstanding NK-WP-0033/0034 verification incident against +the proposed privilege path; require applicable closure or an explicit scoped +owner disposition before expanding it. + +Done when G0 is accepted in a source-backed decision, the project and concrete +pilot work are registered, and a future operator can determine who may run, +review and release it without reconstructing this assessment. Recording a +proposal does not grant execution or spending rights. + +## T02 — Make the selected backlog actionable + +```task +id: HFACT-WP-0001-T02 +status: wait +priority: high +assignee: the-custodian +depends_on: [HFACT-WP-0001-T01] +blocking_reason: "Await project adoption and selection of the pilot dependency chain in T01." +``` + +Dependency: T01. Coordinator: the-custodian with source/projection owners. +Estimated effort: 1 engineering day, plus genuinely necessary projection fixes. + +Use the 94-plan/264-task baseline as the dated starting point. Review the four +retired open identities, seventeen terminal human flags, terminal-parent tasks +and the unmatched local KG-WP-0005 through their existing owning paths. Do not +bulk-delete history or set statuses to improve a dashboard total. +Existing CUST-IN-0017 owns the thirteen Custodian historical consistency +failures and prefix conflict; reuse it rather than duplicate its triage. + +For the pilot chain, ensure every waiting task has a supplying task/record, +accountable contact, precise return evidence, actual next action and review +condition; set human-needed only for real human dependencies. Capture published +source revision and freshness. Check projections without making the retiring +State Hub a new permanent owner. Refer off-path cleanup to existing owners; +it does not hold up the factory after its own records are trustworthy. + +Adopt a factory WIP limit of one integrated delivery item plus two prerequisite +closures, with a named incident exception. Any wider portfolio reprioritization +remains a recommendation until owners accept it. + +Done when the selected chain has complete actionable dependencies, a short +prepared human queue and a repeatable next-pick view; retired/terminal evidence +is excluded from current demand without losing residual ownership. + +## T03 — Accept the existing identity, audit, approval and credential chain + +```task +id: HFACT-WP-0001-T03 +status: wait +priority: high +assignee: the-custodian +depends_on: [HFACT-WP-0001-T01] +blocking_reason: "Await T01 adoption; live returns are owed by KEY-WP-0013-T02, AUDIT-WP-0009-T09, APPROVAL-WP-0002 and SECRETS-WP-0009-T03." +``` + +Dependency: T01. Existing coordinator: GLAS-WP-0015. Supplying owners: +KEY-WP-0013-T02, AUDIT-WP-0009-T09, APPROVAL-WP-0002-T01/T03/T05, +SECRETS-WP-0009-T03 and exact linked custody/authorization records. +Rough shared effort with T04: 4–8 engineering days plus owner waiting. + +Consume the existing seven-owner handoff packet. Identify the exact custody +record for both service clients and the audit sender; first-provision authority +cannot depend on the unprovisioned service. Keep the accepted tenant spelling +and proved policy/digest behavior pinned. Distinguish service-only admission +from a human callback requirement with owner evidence, not assumption. + +Accept the real identity/custody, audit admission, deployed approval claim and +consume, and native credential delivery receipts from the owners. Evidence must +include successful binding and relevant wrong-tenant/scope, denied/reused action +and out-of-scope read rejection, plus revocation/expiry and non-secret audit +references. An image digest or a delivered message alone closes no live gate. + +Done when native credential delivery for the exact proof tuple is verified +through the current owner contracts, with no bypass and no outstanding startup +prerequisite. Record later audit freshness/detection obligations separately; +admission success is not a completeness or tamper-evidence claim. + +## T04 — Accept the real profile and prepare its Railiance placement + +```task +id: HFACT-WP-0001-T04 +status: wait +priority: high +assignee: the-custodian +depends_on: [HFACT-WP-0001-T01] +blocking_reason: "Await T01 adoption for preparation; the real-model portion also requires T03 native credential acceptance." +``` + +Dependency: T01; real model execution also requires T03. Supplying owners: +SAND-WP-0015-T04, GLAS-WP-0012-T02–T06 and concrete Railiance admission owners. + +Accept protected installation of the already pinned runtime candidate and its +owner configuration. Reuse the existing real-rein acceptance contract: exact +profile/actor/project, provider path, model-created artifact, declared effects, +denial, cleanup and rollback to the retained blocked selection on failure. +Review changed pins as a new compatibility set. Do not re-prove resolved +candidate startup unless the artifact, environment or contract changed. + +Then define the production-specific railiance01 placement, runtime owner, +profile/grant, credential path, service restart behavior and recovery inventory. +Start from the evidenced host user-service worker. Satisfy the owning +Railiance rail/rapp/reef admission contract; if the current host service needs +an ownership/admission record, create it in that owner rather than assuming +Kubernetes packaging is the production process. A localhost-only profile needs +explicit target-specific acceptance. + +Done when G1 passes, the local result has acknowledged owner receipts, and the +Railiance configuration is concrete and admissible for T05. G2 is not closed +by this task's local proof. + +## T05 — Close the current worker and queue loop on Railiance + +```task +id: HFACT-WP-0001-T05 +status: wait +priority: high +assignee: the-custodian +depends_on: [HFACT-WP-0001-T02, HFACT-WP-0001-T03, HFACT-WP-0001-T04] +blocking_reason: "Await actionable admission records, owner credential chain and accepted profile/placement from T02-T04." +``` + +Dependencies: T02–T04. Supplying work: REINAH-WP-0003-T05/T06, +ACTIVITY-WP-0032-T05, ACTIVITY-WP-0035-T08, ACTIVITY-WP-0036-T04. +Estimated effort: 2–3 engineering days excluding upstream changes. + +Join the admitted task to the existing ActivityDefinition / ops_run intake and +current versioned profile/repository-grant contract. If a small intake adapter +is missing, record it in the proper owner and implement only that bounded gap; +the retired workplan launch endpoint is not a shortcut. Keep the definition +disabled until the owner's live readiness gates are accepted. + +Accept the deployed pin and a natural claim → immediate heartbeat → execution +→ accepted terminal close trace. Require a controlled late-close/lease-loss +negative case, correct changed paths and commit ancestry, external metrics, +clean source state and sandbox teardown. Exercise the current durable close +outbox without duplicate mutation. A healthy API poll is not an executed task. + +Done when G2 passes under the exact Railiance artifact/configuration and the +Activity Core, rein and Glas owners accept the same run evidence. Return it to +their existing tasks rather than leaving source-complete/live-wait tails open. + +## T06 — Deliver and reuse a useful capability through the existing release path + +```task +id: HFACT-WP-0001-T06 +status: wait +priority: high +assignee: the-custodian +depends_on: [HFACT-WP-0001-T05] +blocking_reason: "Await the current governed Railiance worker proof in T05." +``` + +Dependency: T05; capability and owning implementation records selected in T01. +Acceptance: HelixForge product owner, source/consumer maintainers and workload +operator. Estimated effort: 3–5 engineering days. + +Drive the selected human demand through capability intent, contract and relevant +OAS structural/semantic validation. The bounded agent change must satisfy an +independent predeclared test oracle and normal maintainer review. Record reuse +search and why an existing capability is extended or a new one is justified. + +Use the source repo's current Forgejo workflow, or adopt the existing +railiance-enablement template where needed. Join source commit, CI evidence, +artifact digest/package version and release configuration revision. Apply only +the separately authorized release through the actual workload owner. Validate +the service behavior on Railiance and exercise the agreed rollback. Have the +second repo consume/reuse the capability and retain its acceptance evidence. + +Done when G3 passes and the evidence chain links demand → contract → task/run +→ accepted change → CI → immutable artifact → authorized release → operational +result → reuse. Update the durable HelixForge capability/operating entry. A +generated document, empty commit or deterministic smoke alone is insufficient. + +## T07 — Establish recoverable, measurable operation + +```task +id: HFACT-WP-0001-T07 +status: wait +priority: high +assignee: the-custodian +depends_on: [HFACT-WP-0001-T01] +blocking_reason: "Await T01 adoption for design; final live recovery proof requires the deployed T05/T06 configuration." +``` + +Dependency: T01 for design; T05/T06 for final deployed proof. Supplying owners: +REINAH-WP-0003-T05, the selected workload/package/reef owner and applicable +RPF-WP-0038-T04 recovery/custody coverage. Estimated effort: 2–3 engineering days. + +Consolidate existing receipts for timeout/spend enforcement, worker death, +lease conflict, pending terminal-close replay, credential failure and sandbox +cleanup. Use disposable work and the current deployed configuration. Include +proof that a queue/Hub outage cannot produce duplicate accepted changes and +that restarting restores the right pending evidence. Bind backups and recovery +inventory to the actual host service, forge/artifacts and pilot workload. + +Record per attempt queue wait, execution time, accepted/rejected result, +retries, failure class, human handling, model cost, relevant infrastructure cost +and release result. Include refused/admitted failures in denominators. Use +existing evidence and cost owners; start with a small generated scorecard if +automated aggregation is absent. Monitoring must distinguish a stale receipt +from a healthy current worker and alert the responsible operator through an +already authorized channel. + +Done when G4 passes, rollback/recovery is executable by the named owner, costs +are bounded, and the measurement process can sustain G5 without reconstructing +individual agent sessions. Required audit claims are either freshly proved or +accurately degraded; unresolved detection work retains live owner records. + +## T08 — Accept repeated delivery, transfer ownership and retire the project + +```task +id: HFACT-WP-0001-T08 +status: wait +priority: high +assignee: the-custodian +depends_on: [HFACT-WP-0001-T06, HFACT-WP-0001-T07] +blocking_reason: "Await useful delivery and operational controls from T06/T07, then the complete fourteen-day observation window." +``` + +Dependencies: T06 and T07. Reviewers: HelixForge acceptance owner, Railiance +operating owner and the-custodian. Effort: 1–2 engineering days for review and +handoff plus fourteen calendar days of observation. + +Run the accepted fourteen-day G5 window. Admit at least five useful changes +across two repositories and preserve all attempts, costs, failure/repair events +and human time. If a target is missed, classify the limiting defect, create or +update its owner work record, and repeat the affected acceptance window after +correction. Do not redefine the metrics retrospectively to mark the project done. + +Publish the operating runbook and capability/contract references in permanent +homes, including correction of HelixForge's stale Inter-Hub/nested State Hub +orientation where relevant. Hand the measured factory evidence to the company +project's UPC-WP-0003 acceptance context without claiming its longer window or +commercial goals complete. Additional tenants, model families, HA or unattended +release receive new benefit/authority decisions, not automatic activation. + +Done when G0–G5 are accepted, durable owners acknowledge handoff, all actionable +residuals are live records, and the completion record lists owning repos, +merged/published revisions, deployment/rollback evidence and residual IDs. +Only then finish this workplan, synchronize it and archive the project as +read-only provenance. Participant services continue under their owners.