Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 23 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,15 @@ WorkIntel is a single Laravel 13 + React/TypeScript workforce operations platfor
## AI Development Progress

- **Repo:** `Vertex-Systems-Network/workforce-intelligence`
- **Current Work:** PR #144 governance fix is under exact-head certification; third-party Windows trust-signing provider work is deferred by owner and does not block safe repository maintenance.
- **Current Work:** PR #146 README M14 subtask table is open; exact-head CI and Windows Certification exposed a failing README/compact-state synchronization contract, and the docs/state repair is in progress.
- **Current Module:** M14 — Production Release Trust & Real-Target Readiness
- **Module Progress:** [███████░░░] **70%**
- **Overall Progress:** [██████████] **100%** — active release-scope modular maturity
- **Active Issue:** #62
- **Active PR:** #144
- **Active Branch:** `governance/no-recursive-state-sync`
- **Last Completed:** PR #145 merged to protected main at dfb4fc7ec9536a304b7df582027968dc60f3e53a after all six exact-head checks passed on dab1ad7af440334d6ed7a7847665659216fedb69; zero unresolved review threads.
- **Next Action:** Finish PR #144 exact-head certification and merge only if all required checks pass at the unchanged head. Defer third-party Windows trust-signing provider qualification/integration until future owner authorization; it is not a blocker for safe repository maintenance. Continue the next safe authorized repository lane without buying/configuring signing material or claiming trusted signatures. M14 remains 70% until external evidence gates actually pass; do not deploy, restore, publish or run Runner tasks without separate authority. Issue #70 remains evidence-gated and Apple remains deferred under Issue #123.
- **Active PR:** #146
- **Active Branch:** `docs/m14-readme-subtask-progress-20261008`
- **Last Completed:** PR #144 merged to protected main as 33411a06b2585705880181f056d7b42d3bdf7458 after all six required PR-head checks passed on 989ededc74ce6bc72191ca740ae313aae64babde.
- **Next Action:** Synchronize the README AI progress block with compact state in PR #146, then require exact-head CI, Code Quality and Windows Certification to pass before merge. Keep M14 at 70%; external release-policy, signing, publication, real-target and restore evidence remain unverified, deferred or not run.

> Apple/macOS release trust is deferred to future Issue #123 and is not represented as complete. Overall progress is scoped to active release-scope modular maturity.
<!-- AI-PROGRESS:END -->
Expand Down Expand Up @@ -89,6 +89,24 @@ The table below is the repository-level roadmap view. `Progress` represents acce
| M13 | Agent Lifecycle Reliability — Batches 1–6 | Complete | `██████████` 100% | 2026-08-22 | 2026-08-24 | Managed update, deterministic packaging, immutability, transactional publication, browser version authority and runtime-bound deployment accepted |
| M14 | Production Release Trust & Real-Target Readiness | **VERIFYING / PARTIALLY COMPLETE** | `███████░░░` **70%** | 2026-08-31 | **Active** | GitHub release-control and real-target/recovery evidence remain separate gates. Third-party Windows signing and Apple/macOS trust are deferred; no trusted signature or publication is claimed |

### M14 subtask progress

The bars below show closure of each stated subtask against its own acceptance evidence; they are **not averaged** to calculate the roadmap's M14 70%. A source implementation can be complete while real signing, publication, or target evidence is still not verified.

| M14 subtask | Status | Progress | Evidence / remaining work |
|---|---|---|---|
| Trusted-release workflow source: protected-main source binding, fail-closed trust jobs, receipts, and publication safeguards | Implemented | `[██████████]` **100%** | Source contract and CI coverage are merged. This does not claim an actual trusted release. |
| Linux checksum/provenance candidate evidence | Not run | `[░░░░░░░░░░]` **0%** | Run an authorized release-candidate workflow and retain its exact-source digest/provenance receipt. |
| `agent-v*` tag update/deletion protection and separate creation-authority attestation (Gate A/A2) | Verified | `[██████████]` **100%** | Live ruleset 23938765 and the VERIFIED attestation match; zero bypass actors and update/deletion restrictions are recorded. |
| `production-release` environment protection and least-privilege policy-read token (Gate B) | Not Verified | `[░░░░░░░░░░]` **0%** | Requires administrator-visible environment protection and secret-scope evidence. |
| GitHub immutable-release policy and protected read-back (Gate C) | Not Verified | `[░░░░░░░░░░]` **0%** | Connector cannot read the required admin setting; no enablement is assumed. |
| Windows approved signer material, signer fingerprint, and actual Authenticode/timestamp evidence | Deferred | `[░░░░░░░░░░]` **0%** | Owner deferred third-party provider qualification/integration to future authorization; no trusted Windows signature is claimed. |
| Apple Developer ID signing and accepted notarization | Deferred | `[░░░░░░░░░░]` **0%** | Parked under Issue #123 pending owner authorization and required subscription/tooling. |
| Trusted release publication and immutable asset-integrity postcondition | Not run | `[░░░░░░░░░░]` **0%** | Requires the applicable release-policy and signer gates plus separately authorized publication; no release is claimed. |
| Real-target readiness evidence (revision, health, database, queue, scheduler, storage, download, auth/workspace smoke) | Not Verified | `[░░░░░░░░░░]` **0%** | Requires an approved target and captured target-specific evidence; no target run is claimed. |
| Isolated/disposable backup-to-restore verification | Not run | `[░░░░░░░░░░]` **0%** | Requires separate recovery/target authority and actual restore evidence. |


\* The canonical M0–M12 maturity record stores per-phase completion state but not precise per-phase start/end timestamps. M0–M11 therefore use the repository's initial implementation/certification evidence window instead of inventing unsupported day-level precision. M12, M13 and M14 dates are tied to explicit repository/PR authority and closure records.

**Current roadmap state:** M0–M13 are accepted complete. M14 is the active authorized phase and must not be labeled `DONE` or `PRODUCTION_VERIFIED` until its owner-authorized AI-only review gate and external evidence gates are actually satisfied. See `docs/architecture/MODULAR_MATURITY_STATUS.md`, `docs/architecture/M13_AGENT_LIFECYCLE_RELIABILITY.md`, `docs/architecture/M14_RELEASE_TRUST_READINESS.md`, and `docs/status/AI_CHECKPOINT.md`.
Expand Down
15 changes: 12 additions & 3 deletions docs/ai-state/COORDINATION-QUEUE.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"schema_version": 1,
"non_authoritative_resume_index": true,
"repository": "Vertex-Systems-Network/workforce-intelligence",
"observed_main_sha": "dfb4fc7ec9536a304b7df582027968dc60f3e53a",
"observed_main_sha": "33411a06b2585705880181f056d7b42d3bdf7458",
"reconciled_at": "2026-10-08",
"issues": [
{
Expand All @@ -25,13 +25,22 @@
}
],
"pull_requests": [
{
"number": 146,
"title": "docs(m14): track release-trust subtasks in README",
"state": "open",
"draft": false,
"head_ref": "docs/m14-readme-subtask-progress-20261008",
"head_sha": "d9793944dde9fdada1cf3041bc01bf1160504796",
"action": "repair-readme-compact-state-sync-before-recertification"
},
{
"number": 144,
"title": "governance: prevent recursive state-only reconciliation loops",
"state": "open",
"state": "merged",
"draft": false,
"head_ref": "governance/no-recursive-state-sync",
"action": "owner-defers-provider-signing; exact-head-certification-pending"
"action": "merged-as-33411a06b2585705880181f056d7b42d3bdf7458"
},
{
"number": 145,
Expand Down
19 changes: 10 additions & 9 deletions docs/ai-state/CURRENT-STATE.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,14 @@
"schema_version": 1,
"compact_state_path": "docs/ai-state",
"repository": "Vertex-Systems-Network/workforce-intelligence",
"observed_main_sha": "dfb4fc7ec9536a304b7df582027968dc60f3e53a",
"observed_main_sha": "33411a06b2585705880181f056d7b42d3bdf7458",
"active_issue": 62,
"active_pr": 144,
"active_branch": "governance/no-recursive-state-sync",
"active_pr": 146,
"active_branch": "docs/m14-readme-subtask-progress-20261008",
"current_milestone": "M14 Windows/Linux release trust — provider-based signing deferred; real-target evidence remains separate",
"milestone_status": "WAITING_EXTERNAL",
"last_completed_milestone": "PR #145 merged to protected main at dfb4fc7ec9536a304b7df582027968dc60f3e53a after all six exact-head checks passed on dab1ad7af440334d6ed7a7847665659216fedb69; zero unresolved review threads.",
"exact_next_safe_action": "Finish PR #144 exact-head certification and merge only if all required checks pass at the unchanged head. Defer third-party Windows trust-signing provider qualification/integration until future owner authorization; it is not a blocker for safe repository maintenance. Continue the next safe authorized repository lane without buying/configuring signing material or claiming trusted signatures. M14 remains 70% until external evidence gates actually pass; do not deploy, restore, publish or run Runner tasks without separate authority. Issue #70 remains evidence-gated and Apple remains deferred under Issue #123.",
"milestone_status": "VERIFYING",
"last_completed_milestone": "PR #144 merged to protected main as 33411a06b2585705880181f056d7b42d3bdf7458 after all six required PR-head checks passed on 989ededc74ce6bc72191ca740ae313aae64babde.",
"exact_next_safe_action": "Synchronize the README AI progress block with compact state in PR #146, then require exact-head CI, Code Quality and Windows Certification to pass before merge. Keep M14 at 70%; external release-policy, signing, publication, real-target and restore evidence remain unverified, deferred or not run.",
"pending_runner_ids": [
"RB-001",
"RB-002",
Expand All @@ -28,7 +28,8 @@
"Public-trust Windows private signing keys must not be treated as portable GitHub PFX secrets; existing PFX secrets remain unset for the public-trust path.",
"Live GitHub readback on 2026-10-08 confirms active main branch ruleset 21176050 with zero bypass actors and active `agent-v-release-tags` ruleset 23938765 for `refs/tags/agent-v*` with zero bypass actors plus update/deletion restrictions; the VERIFIED attestation matches updated_at `2026-09-24T17:49:27.650+05:00`. `production-release` environment protection, token placement/least privilege, and immutable-releases setting remain Not Verified because the connector cannot read those admin endpoints.",
"Issue #70 remains open; RB-005 remains not-authorized/blocked.",
"Apple/macOS signing and notarization are intentionally deferred to future Issue #123 and are not an active M14 execution blocker; do not claim Apple completion."
"Apple/macOS signing and notarization are intentionally deferred to future Issue #123 and are not an active M14 execution blocker; do not claim Apple completion.",
"PR #146 exact-head Code Quality passed, but WorkIntel CI and Windows Certification failed because README AI progress fields did not match docs/ai-state/CURRENT-STATE.yaml. Repair the synchronized source files before another exact-head certification."
],
"timeout_control": {
"max_consolidated_status_refreshes_per_milestone": 1,
Expand All @@ -47,11 +48,11 @@
"last_reconciled_at": "2026-10-08",
"response_status": {
"repository_name": "Vertex-Systems-Network/workforce-intelligence",
"current_work": "PR #144 governance fix is under exact-head certification; third-party Windows trust-signing provider work is deferred by owner and does not block safe repository maintenance.",
"current_work": "PR #146 README M14 subtask table is open; exact-head CI and Windows Certification exposed a failing README/compact-state synchronization contract, and the docs/state repair is in progress.",
"current_module": "M14 — Production Release Trust & Real-Target Readiness",
"module_progress": {
"percent": 70,
"basis": "Third-party provider-based trusted signing is deferred by owner for future scope. No provider, signing, publication or real-target evidence is claimed; M14 remains 70% until its authorized evidence gates pass."
"basis": "Provider-based trusted signing is deferred by owner; Gate A/A2 is verified, while release-policy, trusted-artifact and real-target evidence remain open. M14 remains 70% until its authorized external evidence gates pass."
},
"overall_progress": {
"percent": 100,
Expand Down
10 changes: 5 additions & 5 deletions docs/ai-state/LAST-CHECKPOINT.md
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
# Last AI Engineering Supervisor Checkpoint

**Repository:** `Vertex-Systems-Network/workforce-intelligence`
**Observed protected main:** `dfb4fc7ec9536a304b7df582027968dc60f3e53a`
**Observed protected main:** `33411a06b2585705880181f056d7b42d3bdf7458`
**Active Issue:** #62
**Deferred Future Issue:** #123 — Apple signing, notarization and macOS release trust
**Active PR:** #144 — governance/no-recursive-state-sync
**Active branch:** `governance/no-recursive-state-sync`
**Active PR:** #146 — M14 README subtask progress
**Active branch:** `docs/m14-readme-subtask-progress-20261008`
**Milestone:** M14 Windows/Linux release trust — provider-based signing deferred; real-target evidence remains separate
**Status:** PR #144 exact-head certification pending; provider-based Windows trust signing deferred by owner; M14 remains 70%.
**Status:** PR #146 is being repaired after exact-head checks found README/compact-state drift; provider-based Windows signing is deferred; M14 remains 70%.

## Completed

Expand Down Expand Up @@ -38,4 +38,4 @@

## Next Action

Finish PR #144 exact-head certification and merge only if all required checks pass at the unchanged head. Defer third-party Windows trust-signing provider qualification/integration until future owner authorization; continue safe authorized repository work independently. Keep M14 at 70% until real external evidence gates pass. Do not deploy, restore, publish, sign or run Runner tasks without separate authority.
Synchronize the README AI progress block with compact state in PR #146, then require exact-head CI, Code Quality and Windows Certification to pass before merge. Keep M14 at 70%; external release-policy, signing, publication, real-target and restore evidence remain unverified, deferred or not run. Do not deploy, restore, publish, sign or run Runner tasks without separate authority.
Loading