Live owner-to-buyer gap — 2026-09-21
Protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f assigns validity studies, exact decision/evidence/outcome linkage, subgroup diagnostics, drift monitoring, selection utility and scientific adapters to workforce_validation. PRD P0 includes a validity-study registry/FR-007; the protected product baseline also already names a P1 Validation dashboard shell.
The executable owner-to-buyer path is still incomplete, but its dependency graph is not one linear branch chain. Fresh live review found an existing Validation presentation owner that earlier #428 wording had missed: Draft PR #145 at exact 45accc8f2405013e4520e76fa70d01cbebf3c5cc. #145 must remain the single-writer source lane for the existing shell. #428 is corrected to own only the later commercial convergence of that protected UI lineage with the protected/released Workforce Validation API.
This umbrella stays open until both owner paths converge into protected buyer truth. Do not create parallel HR/scientific ownership, normalize direct public-schema/cross-service SQL, source-copy mutable branches, or infer scientific authority from UI/HTTP transport.
Backend/scientific/API owner path
#235 — canonical application owner
#235 remains the canonical workforce_validation in-process application/service lane on exact 202d9d87d6a45529497279b881169aab127727f8, open · Draft · mechanically mergeable against protected develop@eb9757....
It retains the governed owner/provenance/currentness/authorization/view-integrity/scientific-reproducibility contracts accumulated through #411–#424. #423 rejects material final-weight adjustments without released/versioned deterministic owner evidence; #424 requires every admitted governed adjustment binding sequence to be contiguous and one-based. Resolver-issued Python views/proof seals remain data/defense-in-depth, not durable authorization; consequential actions re-authorize and re-resolve owner truth.
ValidityStudyRecord.study_status_code currently validates only a stored lower-snake-case code. 01c3da48... repaired the lifecycle-governance docstring overclaim; actual state vocabulary/transitions remain #426 scope. recorded_from / recorded_to remain bitemporal knowledge time, not business lifecycle.
Predecessor 03bf5040... reached 1,441 tests, 5,186/5,186 owned statements, 1,116/1,116 branches and isolated PostgreSQL contracts before the final read-only gate detected untracked wheel-build output. Current 202d9d87... causally moves wheel construction to a disposable pytest area; predecessor counts do not transfer. Exact-head Foundation 35507388584, Security 35507388575, SAST 35507388588, CodeQL 35507388573 remain non-terminal at the latest fresh read, so #235 stays Draft.
#248 — durable owner-schema adoption
#248 remains source-untouched at d54d44d795444df572efbb301a667d74ac574d58 on stale parent snapshot 656a0c41..., Draft/non-mergeable by design until #235 integrates normally. It owns forward PostgreSQL adoption, least-privilege runtime/read roles and durable adapters; it must not copy mutable #235/#57 source, mint resolver views/seals locally, infer owner identity from a digest or persist sparse component bindings.
After #235 protected integration, #248 non-force adopts current develop, preserves the valid persistence delta, and reacquires exact-head PostgreSQL/quality/security/review evidence.
#426 — governed registration/lifecycle
#426 follows durable persistence and owns versioned lifecycle vocabulary/legal transitions, stable study/version registration receipts, actor/purpose/policy provenance, optimistic concurrency, replay-safe idempotency, append-only correction/supersession and legacy-status census/quarantine. Business lifecycle remains orthogonal to recorded-time currentness; unknown legacy strings are not silently mapped.
#425 — scientific design lineage
#425 begins only after #426 is protected truth (or a verified successor fully carries it). Each governed study version must reconstructably bind predictor/assessment/scoring-model version, criterion definition/version, sampling design/frame and denominator/time/failure evidence, decision-policy version, analysis-plan/protocol provenance, FJA/KSAO job-relatedness evidence and immutable specialist scientific-result locations. A digest alone is not a released owner locator.
Psychometrics Commons / fast-mlsirm / TEPP or equivalent numerical owners remain released/versioned dependencies; no raw person-level scientific payload or mutable source is normalized into Orgmetra for convenience.
#427 — buyer HTTP/OpenAPI
#427 follows protected #425 and owns the versioned buyer-reachable network boundary: current OpenAPI baseline reconciliation, least-privilege Workforce Validation scopes, request validation, replay-safe idempotency, one canonical optimistic-concurrency representation, controlled Problem Details semantics, authenticated PostgreSQL-backed E2E and applicable p95 evidence. The current in-process package name ending in -api does not itself prove a network product boundary.
UI/presentation owner path — existing stack, not #428 source ownership
Fresh review found the pre-existing executable Validation shell at #145. Its valid delta includes the bounded Validation dashboard presentation states, Storybook/Figma correlation, exact-value-table requirement, non-authorizing scientific copy, fail-closed permission/stale/error handling and focused exact-coverage tests.
That UI source is not currently adoptable as protected truth because its root stack is stale:
#145 still carries .github/workflows/hr-workspace-validation-dashboard.yml, and its focused test/traceability currently name that leaf workflow. The leaf must not simply be deleted while it is the only executor of the focused contract; nor may it survive final adoption and resurrect obsolete feature-local quality ownership. The eventual #145 adoption must first admit its focused UI acceptance into the then-current canonical Foundation/product-browser path, then retire the leaf, reconcile provenance and reacquire exact-head browser/accessibility/security/review evidence.
#428 — convergence/commercial completeness only
#428 no longer claims to be a second UI source owner. It starts source implementation only after both:
Then #428 extends/integrates the protected #145 shell against the released #427 API into the complete buyer workspace: study index/detail; Design/Evidence/Results/History composition; exact study/version/lifecycle/result evidence; predictor/criterion/sample/frame/policy/protocol/FJA-KSAO/specialist-result provenance; correction/as-recorded semantics; governed actions and stale-write conflicts; scientific anti-false-GREEN states; Keyverse-backed auth journey; KO/EN/JA/ZH/VI/ES/DE/FR localization; Figma/design-token/Storybook reuse; responsive/accessibility/browser E2E and browser-runtime evidence.
verification_pending, not_verifiable, unavailable, superseded/corrected and permission-denied remain distinct from successful/negative scientific evidence. HTTP 200/current-recorded rows are never scientific/lifecycle GREEN. Every chart requires exact values and material denominator/method/time/evidence context.
Correct dependency graph
Backend/API path:
#235 → #248 → #426 → #425 → #427
UI/presentation path:
#53 → #130 → #145
Commercial convergence:
(#427 protected/released) + (#145 protected/released) → #428
Scientific #57 remains independently integrable; it becomes a consumer dependency only through an exact released contract, never via mutable source.
Documentation / scientific authority / completion
#51 remains canonical protected-truth documentation writer where its owned files apply; #100 remains sole writer for docs/product-technical-gap-baseline.md. Metadata may describe this live graph, but active PR/Issue contracts are not shipped truth.
Current normative/scientific sources recorded by the owner lanes continue to govern interpretation (including relevant ISO 10667, AERA/APA/NCME testing standards, SIOP Principles and current HTTP/OpenAPI standards); they do not certify an individual study or UI.
Keep #234 open until the canonical application owner, durable persistence, governed lifecycle/registration, scientific design lineage, buyer network contract, existing Validation presentation owner and final API-backed buyer workspace all reach normal protected integration with code-current PRD/TRD/ARCHITECTURE/ERD/UML/UX/STORYBOOK/API_CONTRACT/SECURITY/THREAT_MODEL/TEST_STRATEGY/OPERABILITY/TRACEABILITY/baseline evidence as applicable. Source, issue prose, Figma/Storybook artifacts or an OpenAPI document alone are not completion.
Live owner-to-buyer gap — 2026-09-21
Protected
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4fassigns validity studies, exact decision/evidence/outcome linkage, subgroup diagnostics, drift monitoring, selection utility and scientific adapters toworkforce_validation. PRD P0 includes a validity-study registry/FR-007; the protected product baseline also already names a P1 Validation dashboard shell.The executable owner-to-buyer path is still incomplete, but its dependency graph is not one linear branch chain. Fresh live review found an existing Validation presentation owner that earlier #428 wording had missed: Draft PR #145 at exact
45accc8f2405013e4520e76fa70d01cbebf3c5cc. #145 must remain the single-writer source lane for the existing shell. #428 is corrected to own only the later commercial convergence of that protected UI lineage with the protected/released Workforce Validation API.This umbrella stays open until both owner paths converge into protected buyer truth. Do not create parallel HR/scientific ownership, normalize direct
public-schema/cross-service SQL, source-copy mutable branches, or infer scientific authority from UI/HTTP transport.Backend/scientific/API owner path
#235 — canonical application owner
#235 remains the canonical
workforce_validationin-process application/service lane on exact202d9d87d6a45529497279b881169aab127727f8, open · Draft · mechanically mergeable against protecteddevelop@eb9757....It retains the governed owner/provenance/currentness/authorization/view-integrity/scientific-reproducibility contracts accumulated through #411–#424. #423 rejects material final-weight adjustments without released/versioned deterministic owner evidence; #424 requires every admitted governed adjustment binding sequence to be contiguous and one-based. Resolver-issued Python views/proof seals remain data/defense-in-depth, not durable authorization; consequential actions re-authorize and re-resolve owner truth.
ValidityStudyRecord.study_status_codecurrently validates only a stored lower-snake-case code.01c3da48...repaired the lifecycle-governance docstring overclaim; actual state vocabulary/transitions remain #426 scope.recorded_from/recorded_toremain bitemporal knowledge time, not business lifecycle.Predecessor
03bf5040...reached 1,441 tests, 5,186/5,186 owned statements, 1,116/1,116 branches and isolated PostgreSQL contracts before the final read-only gate detected untracked wheel-build output. Current202d9d87...causally moves wheel construction to a disposable pytest area; predecessor counts do not transfer. Exact-head Foundation35507388584, Security35507388575, SAST35507388588, CodeQL35507388573remain non-terminal at the latest fresh read, so #235 stays Draft.#248 — durable owner-schema adoption
#248 remains source-untouched at
d54d44d795444df572efbb301a667d74ac574d58on stale parent snapshot656a0c41..., Draft/non-mergeable by design until #235 integrates normally. It owns forward PostgreSQL adoption, least-privilege runtime/read roles and durable adapters; it must not copy mutable #235/#57 source, mint resolver views/seals locally, infer owner identity from a digest or persist sparse component bindings.After #235 protected integration, #248 non-force adopts current
develop, preserves the valid persistence delta, and reacquires exact-head PostgreSQL/quality/security/review evidence.#426 — governed registration/lifecycle
#426 follows durable persistence and owns versioned lifecycle vocabulary/legal transitions, stable study/version registration receipts, actor/purpose/policy provenance, optimistic concurrency, replay-safe idempotency, append-only correction/supersession and legacy-status census/quarantine. Business lifecycle remains orthogonal to recorded-time currentness; unknown legacy strings are not silently mapped.
#425 — scientific design lineage
#425 begins only after #426 is protected truth (or a verified successor fully carries it). Each governed study version must reconstructably bind predictor/assessment/scoring-model version, criterion definition/version, sampling design/frame and denominator/time/failure evidence, decision-policy version, analysis-plan/protocol provenance, FJA/KSAO job-relatedness evidence and immutable specialist scientific-result locations. A digest alone is not a released owner locator.
Psychometrics Commons / fast-mlsirm / TEPP or equivalent numerical owners remain released/versioned dependencies; no raw person-level scientific payload or mutable source is normalized into Orgmetra for convenience.
#427 — buyer HTTP/OpenAPI
#427 follows protected #425 and owns the versioned buyer-reachable network boundary: current OpenAPI baseline reconciliation, least-privilege Workforce Validation scopes, request validation, replay-safe idempotency, one canonical optimistic-concurrency representation, controlled Problem Details semantics, authenticated PostgreSQL-backed E2E and applicable p95 evidence. The current in-process package name ending in
-apidoes not itself prove a network product boundary.UI/presentation owner path — existing stack, not #428 source ownership
#53 → #130 → #145
Fresh review found the pre-existing executable Validation shell at #145. Its valid delta includes the bounded Validation dashboard presentation states, Storybook/Figma correlation, exact-value-table requirement, non-authorizing scientific copy, fail-closed permission/stale/error handling and focused exact-coverage tests.
That UI source is not currently adoptable as protected truth because its root stack is stale:
016f27e13f7a47cb78a1c936aa533cc8daa2c66cis now 113 ahead / 3 behind protecteddevelop@eb9757..., merge base9e3e484..., and GitHub reportsmergeable=false.#145 still carries
.github/workflows/hr-workspace-validation-dashboard.yml, and its focused test/traceability currently name that leaf workflow. The leaf must not simply be deleted while it is the only executor of the focused contract; nor may it survive final adoption and resurrect obsolete feature-local quality ownership. The eventual #145 adoption must first admit its focused UI acceptance into the then-current canonical Foundation/product-browser path, then retire the leaf, reconcile provenance and reacquire exact-head browser/accessibility/security/review evidence.#428 — convergence/commercial completeness only
#428 no longer claims to be a second UI source owner. It starts source implementation only after both:
Then #428 extends/integrates the protected #145 shell against the released #427 API into the complete buyer workspace: study index/detail; Design/Evidence/Results/History composition; exact study/version/lifecycle/result evidence; predictor/criterion/sample/frame/policy/protocol/FJA-KSAO/specialist-result provenance; correction/as-recorded semantics; governed actions and stale-write conflicts; scientific anti-false-GREEN states; Keyverse-backed auth journey; KO/EN/JA/ZH/VI/ES/DE/FR localization; Figma/design-token/Storybook reuse; responsive/accessibility/browser E2E and browser-runtime evidence.
verification_pending,not_verifiable, unavailable, superseded/corrected and permission-denied remain distinct from successful/negative scientific evidence. HTTP 200/current-recorded rows are never scientific/lifecycle GREEN. Every chart requires exact values and material denominator/method/time/evidence context.Correct dependency graph
Backend/API path:
#235 → #248 → #426 → #425 → #427UI/presentation path:
#53 → #130 → #145Commercial convergence:
(#427 protected/released) + (#145 protected/released) → #428Scientific #57 remains independently integrable; it becomes a consumer dependency only through an exact released contract, never via mutable source.
Documentation / scientific authority / completion
#51 remains canonical protected-truth documentation writer where its owned files apply; #100 remains sole writer for
docs/product-technical-gap-baseline.md. Metadata may describe this live graph, but active PR/Issue contracts are not shipped truth.Current normative/scientific sources recorded by the owner lanes continue to govern interpretation (including relevant ISO 10667, AERA/APA/NCME testing standards, SIOP Principles and current HTTP/OpenAPI standards); they do not certify an individual study or UI.
Keep #234 open until the canonical application owner, durable persistence, governed lifecycle/registration, scientific design lineage, buyer network contract, existing Validation presentation owner and final API-backed buyer workspace all reach normal protected integration with code-current PRD/TRD/ARCHITECTURE/ERD/UML/UX/STORYBOOK/API_CONTRACT/SECURITY/THREAT_MODEL/TEST_STRATEGY/OPERABILITY/TRACEABILITY/baseline evidence as applicable. Source, issue prose, Figma/Storybook artifacts or an OpenAPI document alone are not completion.