feat: add governed candidate withdrawal evidence - #67
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| | [0017](0017-governed-offer-approval.md) | Governed offer approval evidence | Proposed | | ||
| | [0025](0025-governed-candidate-evidence-intake.md) | Governed candidate evidence intake | Proposed | |
There was a problem hiding this comment.
📝 Info: Indexed ADRs 0017/0025 are not manifest-tracked
The new index rows point at 0017 and 0025, which exist and carry 'Status: Proposed', so link and index checks pass. Neither appears in REQUIRED_FILES or manifest.json, so their contents are not integrity-tracked and can drift undetected. CI stays green because the drift check only compares those two sets.
Was this helpful? React with 👍 or 👎 to provide feedback.
There was a problem hiding this comment.
Verified against current #67 head 65d86274d3c244344feab6811f236ffdc6ffcb18: ADR 0017/0025 are inherited protected-develop documents, not withdrawal-lane files. The owning protected-truth repair is PR #51, current head e8d94fd039377af0dcf2c9e75094c977f2854aae, which now adds both ADRs to the Python/Node required inventories and regenerated manifest; its hosted suite is re-running. Leaving this thread unresolved until that owner lane is merged and #67 is retargeted/revalidated; no current #67 manifest coverage is claimed.
There was a problem hiding this comment.
Update against current protected-truth owner state: PR #51 is now at aa33f8f9f2a7c0a72c91947e3edac90334bcaabf; its required inventories and regenerated manifest include ADR 0017/0025, and its exact-head hosted suite is still running. This remains intentionally unresolved until #51 integrates and #67 is retargeted/revalidated against protected develop; no manifest coverage is claimed by #67 while it is based on the feature parent.
…ation' into HEAD # Conflicts: # manifest.json
|
Lifecycle authority correction: #67 is now Draft. Parent #66 is still unintegrated and #67 also depends on #51’s protected-truth/ADR provenance repair before its inherited manifest-provenance observation can be revalidated. The body’s earlier |
Buyer-visible gap
PR #66 deliberately removes bare
withdrawnfrom raw candidate-application stage persistence because that shape cannot prove candidate initiation. This stacked lane adds the missing governed candidate-withdrawal boundary without reintroducing a staff-controlled shadow rejection.Implemented withdrawal contract
The branch adds separate tenant-qualified, append-only
candidate_withdrawal_recordevidence rather than a raw pipeline stage. It binds candidate actor/identity-resolution provenance, withdrawal evidence version/digest, chronology, immutable audit/outbox correlation, one-withdrawal cardinality, and rejects staff-actor shadow rejection, evidence mismatch, duplicate withdrawal, destructive rewrite, and foreign-tenant visibility.candidate:syntax is correlation, not authentication; Keyverse remains read-only through the published identity contract.Migration repair
The original withdrawal envelope extension edited already-deployed migration
0008, which would leave databases that had already applied0008with the legacy validator. That defect was repaired forward-only: current exact headee5a56db3f64d972a08fab367fbed3f5005fa8f7retains0016_candidate_withdrawal_audit_envelope.sql, whose source explicitly extends the already-deployed validator without editing0008.test_candidate_withdrawal_migration_upgrade_postgres.shproves the upgrade path: the legacy0008validator rejects a withdrawal envelope, then0016accepts it. The persistence and anti-forgery/tenant-isolation PostgreSQL contracts remain part of the current lane.No dedicated-writer dependency repository is modified.
Exact-current-head state
ee5a56db3f64d972a08fab367fbed3f5005fa8f7.feat/normalized-candidate-application@04c60a6d485c1af32973959c37c9133ae928f59b.develop. The older non-Draft wording is superseded by the live lifecycle state; mechanical mergeability is not integration evidence.Candidate withdrawal PostgreSQL contract: run33251808179, job99098654692, terminal SUCCESS.Candidate withdrawal migration upgrade contract: run33251808179, job99098654852, terminal SUCCESS.aa33f8f9f2a7c0a72c91947e3edac90334bcaabf, and docs: reconcile canonical protected product truth #51 has not integrated into protecteddevelop.Stack and merge governance
Process PR #66 dependency-first. Independently, PR #51 must integrate before the inherited ADR 0017/0025 manifest-provenance thread can be revalidated and resolved here. After #66 integrates, retarget #67 to fresh protected
develop, reconcile the then-current #51/protected truth and migration ordering with other active migration lanes, refetch exact head/base/rules/reviews/threads, and rerun every applicable Foundation, Recovery, Security/SAST, product-quality, OpenCode, Noema, Strix, provenance and approval gate on the resulting exact head. Parent, predecessor, status-only, or model-only evidence never transfers.Do not self-approve, use routine administrator bypass, weaken a gate, race another writer, transfer predecessor evidence, or mutate a dedicated-writer dependency.