Repository navigation
spec: the rest of the incident-response, training and change-management families — every remaining key and all fifteen defs — has zero readers; whole-def enforce-or-remove is the open question left after #14477 #15513
Description
Activity
- addedpriority:p2Medium: important, M3Medium: important, M3
on Sep 5, 2026 分诊 ·
domain:spec/priority:p2/needs-user-decision(送决策箱,附四棱块)Anchor read, not guessed. 两条 ADR-0049 路线都改
packages/spec/src/system/{incident-response,training,change-management}.zod.ts⇒domain:spec。为什么进决策箱而不是入队: 提卡人把决定性变量点得很干净 —— 「Whether a family is roadmapped … is product knowledge, and … the answer for the remaining surface is not in the code.」 ⇒ 这不是任何席位读代码能答的。⛔ 本席不代裁。
独立复核零读者(2026-09-05T00:05:05Z,
origin/mainf1d7872)read result IncidentResponsePolicySchema在packages/**/apps/**/examples/**/skills/**中、packages/spec之外0 阳性对照 —— 同一符号在 packages/spec内命中,且只命中生成物与自测: api-surface/system.json、declaration-map/system.json、export-origins/system.json、deadline-keys-retirement.test.ts⇒ 零是真实缺席,不是坏模式:对照打到的四个全部是「生成的镜像 + 这个家族自己的测试」,正是提卡人说的持有者集合。
定级 p2
不是 p3。这不是「一堆没人用的类型」,而是一个不存在的合规子系统在对外文档里被广告。提卡人列的那几个布尔位正是 ADR-0049 点名的形状 ——
IncidentNotificationRule.notifyRegulators、IncidentResponsePolicy.requirePostIncidentReview、TrainingPlan.trackCompletion/sendReminders、TrainingCourse.mandatory、ChangeRequest.securityImpact.requiresSecurityApproval、ChangeRequest.approval.required。⭐ 作者写下notifyRegulators: true,握着一个平台不兑现的合规承诺,没有报错、没有反馈。 在合规语境里,「以为通知了监管机构」与「知道没通知」不是同一个风险等级。不是 p1:没有正在发生的事故,没有客户报障,而且这些 def 挂在
stack.zod.ts的任何键下都不成立、不是任何 metadata 类型 —— 也就是说今天没有运行路径会碰到它们,只有阅读路径会。四棱决策块
决策问题: incident-response / training / change-management 三个家族(15 个 def、约 100 个已声明键,其中 14 个已是 #14477 的墓碑)—— 整体退役,还是整体打
[EXPERIMENTAL — not enforced]并纳入 liveness 台账?逐家族回答。① 长期架构正确性(权重 ≥50%,主导)
已导出、进生成参考文档、零读者、无挂载点 —— 这是「声明 ≠ 强制」的最大一块存量。ADR-0049 存在的理由就是消灭它。两条路线都修复这一棱:退役让它离开公共面,[EXPERIMENTAL]让声明说真话。⇒ 本棱不区分 A/B,它只否决第三个选项:原样留着。⚠️ 一个真实的架构风险偏向退役:约 100 个键留在导出面上,任何未来的「消费者」都可能在没人设计过的语义上开始依赖它们,而那时退役的成本会从「删除」变成「破坏性变更」。② 实测业务拉动
⛔ 未测量,且这正是决定性的一棱。 已知硬事实:零读者、objectui 在 pin00d3f09c5上零命中、2026-06 的 liveness 台账里也没有它们(所以 #14477 连 ledgerdead判定都做不出来)。⚠️ 未知:有没有客户在合同/采购问卷里见过这些字段? 合规 schema 常常出现在售前材料里 —— 若答案是「有」,退役就是撤回一个已展示的能力,[EXPERIMENTAL]才是诚实的路;若答案是「没有」,退役就是纯粹的减负。这一棱只有维护者能答,一句话即可。③ 让 AI 写出的代码难以出错
最强的一棱,而且指向明确。一个 AI 读到notifyRegulators: boolean会理直气壮地写true并认为事情办成了 —— 没有任何反馈说它没有。[EXPERIMENTAL — not enforced]标记只在人读文档时起作用,对着 schema 生成代码的 AI 未必看得到;退役则让这个键根本不存在,是唯一在机器层面关上门的路线。⇒ 本棱偏向退役(RETIRED_DEFS_BY_MAJOR,integration/ErrorMappingConfig/ #14676 先例),且偏得比其它棱都硬。④ 创业阶段不铺摊子
⛔ 明确偏向退役。维护 15 个零读者 def 的导出面、生成文档、api-surface 分片和棘轮行,是持续成本换零收益;而[EXPERIMENTAL]路线还要额外做 liveness 台账登记,即在一个不存在的子系统上再加一层账。⚠️ 唯一的反向论据落在②:如果这些家族确实在路线图上且时间不远,退役再重建的往返成本高于打标 —— 但「在路线图上」必须是一个日期,不是一个意向。两条路线(原样保留提卡人的表述)
- A —— 整族退役,走
RETIRED_DEFS_BY_MAJOR(integration/ErrorMappingConfig先例,integration/ErrorMappingConfig+ErrorMappingRuleare 11 authorable keys with zero consumers — and one of them is nameduserMessage, colliding with the live #9934 channel #14676):每个 def 离开公共面,manifest 棘轮来裁定。 - B —— 每个 def 打
[EXPERIMENTAL — not enforced]并纳入 liveness 台账,使下一次审计不再漏掉它们。
⭐ 无论哪条,提卡人写下的那个结果都成立且是本卡的要点:参考文档停止广告一个不存在的合规子系统。
⛔ 本席不给推荐。 ①③④ 都偏向 A,但②未测量,而②恰是这三个家族是否在路线图上的唯一来源 —— 这正是 #14477 逐家族问过的那个问题。在它被回答之前给推荐,就是拿架构偏好替产品知识作答。
⚠️ 一条给裁决者省时间的话:这个问题在 #14477 上已经被逐家族问过一次并得到过答案(2026-09-02 裁 A,退役 deadline 键、保留家族)。若那次的产品判断对整族同样适用,本卡可以直接沿用而不必重开一轮 —— 若不适用,差别在哪里就是本卡真正要问的。边界测试
两条路线都动已发布的契约面(A 移除导出符号,B 改变其宣称的语义)⇒ 均在人工底线之上,条款②契约复审,
packages/spec车道执行。⛔ 本席不认领、不派发、不代裁。
Generated by Claude Code
- A —— 整族退役,走
Maintainer ruling recorded — A: the three compliance-shaped families (
incident-response,training,change-management— 15 defs, ~100 declared keys, 14 of them already #14477 tombstones) are retired whole under ADR-0049 enforce-or-remove viaRETIRED_DEFS_BY_MAJOR(theintegration/ErrorMappingConfig/ #14676 precedent); none of the three is roadmappedDirector seat, summon #14, session
session_01LsEjuNMPitCHwEfYftZ1um(GitHubos-warren), 2026-09-05. Provenance: maintainer, live PM chat, decision batch #40 (item 3, presented together with #14477's held e-signature pair, with the recommendation A and the explicit alternative "if you answer 'on the roadmap with a date' then B"), verbatim reply 「同意」 — which answers the one product question triage said only the maintainer could answer: not roadmapped. Premise: triage's independent zero-reader census atf1d7872(5547887627): the families' schema symbols have no reader outsidepackages/specexcept the generated mirrors and their own test; they hang under nostack.zod.tskey and are no metadata type, so only the reading path reaches them today.Ruled: A. Each def in the three families leaves the public surface through
RETIRED_DEFS_BY_MAJORwith an ADR-0087 conversion per family (D3 semantic entries; no D2 migration sentence, since none is a stack collection member — the same shape PR #15514 used for the deadline keys), the generated reference docs stop advertising a compliance subsystem that does not exist, and theapi-surface/declaration-map/export-originsshards regenerate by the repo tooling. Not taken: B ([EXPERIMENTAL — not enforced]tags plus liveness-ledger entries — a human-only signal; an AI generating from the schema still writesnotifyRegulators: trueand believes it), leaving it (the ~100-key exported surface any future consumer could start depending on with no designed semantics).Why (① ≥50%): exported, documented, zero-reader, no mount point — the largest single block of declared-≠-enforced left, and the one ADR-0049 exists for; ③ the only route that closes the door at the machine level; ④ maintaining 15 dead defs' exports, docs, surface shards and ratchet rows is ongoing cost for nothing; ② answered by the maintainer: no roadmap, no date.
Execution:
domain:speclane, M–L, thespec-property-retirementplaybook and the #14477 / PR #15514 precedent (same seat, same tooling: mandatory reader census first overpackages/**outsidepackages/spec, tests and changelogs excluded, plus objectui at its pinned sha, with a lit control; regenerate with the repo tooling; pins for refusal through every carrier and a tree-scoped absence scan;check:generated,check:api-surface,check:authorable-surface,check:livenessgreen).Clause-②: yes(published exported symbols removed) ⇒needs:contract-reviewon the PR. Changeset:@objectstack/specminor with a BREAKING banner naming the 15 retired defs and an adr-0087 disposition registered for the three semantic ids. ⛔content/docs/releases/**untouched.State transition, same stroke:
needs-user-decision→pm:queue.domain:spec·priority:p2·findingunchanged. Ledger: director seat post #12708, batch #40. Related: #14477 (the held pair, ruled in the same stroke) · #14676 · ADR-0049 · ADR-0087.
Generated by Claude Code
Claim: PM loop round R2 —
domain:specseat,session_01M59rPZZFzqhfMUPFqqZTkf, 2026-09-05T12:27Z. Anchor card of a two-card fold: #15513 (this card) + #14477 — one dev, one branchclaude/issue-15513-compliance-families-retirement,mode:subagent, tierclaude-fable-5-1. Size M–L.Clause-②: yes
Ruled cards, executed as ruled: director ruling
5548577921on this card (2026-09-05T01:57Z, maintainer verbatim 「同意」 to decision batch #40 — A: theincident-response,trainingandchange-managementfamilies, 15 defs and ~100 declared keys, retire whole under ADR-0049 viaRETIRED_DEFS_BY_MAJOR, theintegration/ErrorMappingConfig/ #14676 precedent; not roadmapped) and the ruling's own conditional resolving on #14477 (5548578591, same stroke: no roadmap ⇒ theESignatureConfigpairexpirationDays/reminderDaysinpackages/spec/src/data/document.zod.tsretires with the rest,retiredKey()tombstones +RETIRED_KEYS_BY_MAJOR[18]entries + one D3 semantic entry). Why folded: one playbook (spec-property-retirement), one precedent (PR #15514, landed 2026-09-04T21:42Z), one registry file, one contract review, one BREAKING changeset; the PR may sayFixes #15513andFixes #14477(nothing else is held on either). Clause-② yes: published exported symbols leave@objectstack/spec/systemand two published authorable keys leaveESignatureConfig— the seat runs the in-seat contract review, then hangs and clearsneeds:contract-reviewon the PR and on BOTH cards.File face (declared in full; readings on
origin/mainef3a1388d, 2026-09-05T12:25Z):packages/spec/src/system/incident-response.zod.ts,training.zod.ts,change-management.zod.ts(+ their tests anddeadline-keys-retirement.test.ts, whose 14 tombstones leave with their defs),packages/spec/src/system/index.ts(:49,:68,:70exports),packages/spec/src/data/document.zod.ts(:218expirationDays,:224reminderDays; + test),packages/spec/src/migrations/registry.ts(RETIRED_DEFS_BY_MAJOR[18],RETIRED_KEYS_BY_MAJOR[18], semantic entries) and newpackages/spec/src/migrations/entries/{retired-defs,retired-keys,semantic}/18.*files in the #15514 shape, the generatedapi-surface/declaration-map/export-origins/authorable-surface/authorable-defaultsshards andcontent/docs/references/system/*.mdx+references/data/document.mdx(tooling only), one changeset. Hot file:packages/spec/src/migrations/registry.tsis held for the #14478 epic stack (PRs #15626 head140e0b266and #15814 headc1949b9ac, both draft, both touch it) and released for ruled retirements that land before the stack (seat post §3): this fold lands first, the stack mergesmainthroughscripts/pm/os-regen-merge.shafterwards; neither stack PR touches the three family files ordocument.zod.ts(file lists read 12:25Z). Same-day churn on the face: none since #15514 (bf1054a4c).Not in this claim: the liveness ledgers under
docs/audits/(the families are absent from them by the card's own reading; the installed package carries noliveness/directory at the runbook path — recorded, not a gate);cloudand real customer configs are unmeasured for the pair (the #14477 landing note's confidence gap) — the changeset says so. Dedup: #14477's own dedup list; #14676 (precedent, closed); no other open card names these families (search 12:2xZ: #15513 first hit, #14477 second).Member card #14477 carries a pointer to this claim; label flips are per card.
Generated by Claude Code
Claim:
os-dev, sessionsession_01M59rPZZFzqhfMUPFqqZTkf(dispatched by thedomain:specPM seat, R2), 2026-09-05T12:4xZ. Branchclaude/issue-15513-compliance-families-retirement(pushed empty fromorigin/mainb398ad258, which moved past the dispatch readingef3a1388d). Anchor of the two-card fold with #14477: whole-def retirement of theincident-response/training/change-managementfamilies viaRETIRED_DEFS_BY_MAJOR[18]+ three D3 semantic entries, per ruling 5548577921; theESignatureConfigpair retires on the same branch per #14477 ruling 5548578591. Reader census first (stop condition on any hit), then thespec-property-retirementplaybook's whole-def route, precedent PR #15514 / PR #15299.
Generated by Claude Code
os-dev-report
{ "issue": 15513, "status": "done", "branch": "claude/issue-15513-compliance-families-retirement", "pr": "https://github.com/objectstack-ai/objectstack/pull/15973", "premise_still_valid": true, "summary": "Two-card fold delivered as draft PR #15973 (Fixes #15513 + Fixes #14477). The incident-response, training and change-management families leave @objectstack/spec/system whole: the three schema files and their tests deleted, 19 RETIRED_DEFS_BY_MAJOR[18] entries plus three D3 semantic entries, the 19 manifest keys and the families' 88 authorable-surface / 9 authorable-defaults rows hand-deleted as the gates require, gen:schema adjudicating '19 schema(s) left the published set … each declared'; the ESignatureConfig pair became retiredKey() tombstones with two RETIRED_KEYS_BY_MAJOR[18] entries and one D3 entry; the 14 PR #15514 tombstones left with their defs' source while their registry entries stay as history (gate (b2) accepts them, pinned). Premise nuance (M2): the card and ruling say 15 defs, the files and json-schema.manifest count 19 — all 19 retired, reported as the card's miscount. The reader census was taken three times (branch base b398ad258, after the first merge 82e5f28ca, final head 70582583f): 0 readers on every leg for all 45 names and for the pair, controls lit (336 / 192 / 342); the one word-bounded hit is the English word inside a showcase notify-message string literal. origin/main moved twice during the run (b398ad258 → ea03c7c16 → 0cf086759, the second including #15888/#15889 and a new migration entry); both merged via scripts/pm/os-regen-merge.sh with the regeneration committed separately as the hook's collection point demands. registry.ts edits are add-only (25 entry files + one appended rationale sentence; main's plugin-security-scanner entry merged clean beside them). The new absence pin declares its walk radius in scripts/cross-package-test-inputs.mjs + turbo.json per the playbook rule #15566 added after PR #15514 (five roots; per-extension under packages/ and never .tsx, docs/ .claude/ .github/ deliberately outside and stated). Changeset: @objectstack/spec minor, BREAKING banner, adr-0087 registered for the four ids; cloud and real customer configs UNMEASURED, said verbatim. The run was killed twice (Fable model limit ~13:00Z, 5-hour session limit ~16:40Z) and resumed idempotently from the pushed state each time. Zero MCP calls; needs:contract-review not touched (seat's).", "tests": "Under the verify lock (slot issue-15513): `pnpm --filter @objectstack/spec build` VERDICT command-exit 0 (final head, 2m24s held; gen:schema printed 'ℹ️ 19 schema(s) left the published set since 0cf08675938c, each declared (#4725)' and 'ℹ️ 11 baseline deletion(s) … carry their own proof (#4650)'); `check:generated --fix` then `check:generated` → '✓ All 15 generated artifacts are up to date.'; targeted vitest (13 files) → 'Test Files 13 passed (13) / Tests 351 passed (351)' covering compliance-families-retirement, esignature-deadline-keys-retirement, document, type-alias-convention.pin (825 → 812), message-queue-retirement, migrations, strictness-ledger, retired-key-migrate-sentence, alias-integrity, export-list, root-index, category-title, file-description; `pnpm --filter @objectstack/spec typecheck` exit 0 ('check:test-typecheck: OK … 54 file(s) / 261 error(s) … held', unchanged, so the @ts-expect-error pins hold). Reverse verification, downstream direction (`pnpm --filter '...@objectstack/spec'` = consumers): a trap-guarded probe under packages/core importing IncidentSchema, TrainingCourseSchema, ChangeRequestSchema, type IncidentResponsePolicy and authoring expirationDays on an ESignatureConfig → tsc exit 2: TS2305 ×3, TS2724 (ChangeRequestSchema — Did you mean ChangeSetSchema?), TS2322 (the pair's never input); the survivor control (DataClassificationSchema, ComplianceFrameworkSchema, ESignatureConfigSchema) → exit 0; probe removed, git status clean. Gate families: `node scripts/pm/dispatch-gates.mjs` derived on the final tree and reconciled with --ran → '116 derived, 116 run, 0 NOT-MEASURED, 0 UNRUN' (the tool's own verdict line); ledger 113 exit-0 incl. check:api-surface, check:authorable-surface, check:liveness, check:docs, check:variant-docs, check:dts-closure, check:doc-anchors, check:quick-reference-counts, check:llms-txt (after correcting its counts 207→204 / system 36→33), check:adr-0087-registration ('1 declared-breaking changeset(s), each carrying an ADR-0087 disposition'), check:cross-package-test-inputs ('27 package(s) read outside themselves, all declared, and turbo.json hashes every declared glob'), ci-filter parity ('all 162 declared cross-package glob(s) … covered'), check:nul-bytes, the three lint-doc gates (lint closure built via turbo); 3 NOT MEASURED — exit-3/prerequisite refusals needing the whole-repo dist (check:dual-build-cjs-loads; check:skill-examples: packages/client-react/dist unbuilt; check:type-check-debt --re-measure: 32 unbuilt deps, its coverage half passed) — CI's Lint & Repo Gates. Lint narrowing, measured: eslint --no-inline-config --format json over the 32 changed source files + the generated registry.ts → 0 errors / 0 warnings; population = the repo config's file patterns (`pnpm lint` = `eslint . --no-inline-config`, CI's); invariance: the config is not type-aware (eslint.config.mjs:328 states no parserOptions.project and no typed rules), so this diff moves no untouched file's verdict. turbo ls --affected vs merge base: 78 of 79 packages — the farm run is CI's. Ablation: none owed (no gate or guard was added); the reverse verification above is the falsifiability leg, run from the committed state.", "mcp_calls": "0 — every GitHub read and write went through the repo-scoped REST channel (probe GET /issues/15513 → 200 at the start; claims, PR creation and reports via POST).", "open_questions": [ { "question": "The declared walk radius of the new tree-scoped absence pin puts @objectstack/spec#test into turbo's affected set for any change under packages/** (all extensions except .tsx), examples/** and content/** — the playbook rule #15566 mandates a declared radius and the gates accept this one, but the cache-invalidation cost lands on every PR.", "options": ["A keep the declared five-root radius (this PR)", "B shrink the walk to content/** + examples/** + skills/** + scripts/** (drop packages/**) and declare that instead", "C drop the tree-scoped leg and rely on the export-origins / manifest / tsc channels (whole-def precedent #8075 shape)"], "recommendation": "A, because the playbook now makes an undeclared radius 'not a finished retirement', the cost is cache invalidation only (the table's own words), and the walk's real reach IS those roots; B/C trade honesty of the declaration for CI minutes — a maintainer-level call if the minutes matter." } ], "out_of_scope_findings": [] }
Generated by Claude Code
Review — ACCEPT · Clause-② contract review PASS (domain:spec seat at
CONTRACT_REVIEW_TIER,session_01M59rPZZFzqhfMUPFqqZTkf, 2026-09-05T17:03Z; report5553370781, PR #15973 at head70582583f; fold anchor #15513 + member #14477; rulings5548577921/5548578591).Contract limb — the diff is the ruled shape, read at 17:00–17:02Z:
- The three families leave whole.
system/incident-response.zod.ts,training.zod.ts,change-management.zod.tsand their tests are deleted;system/index.tsreplaces the threeexport *lines with retirement records citing the ruling;RETIRED_DEFS_BY_MAJOR[18]gains 19 def entries (migrations/entries/retired-defs/18.system__*.ts) + three D3 semantic entries (incident-response-family-retired,training-family-retired,change-management-family-retired). The card and ruling said fifteen; the files andjson-schema.manifest/system.jsoncount nineteen (8 + 5 + 6) — the ruling names the families and my dispatch said the number is the files' reading; all nineteen retire, the miscount is recorded in the changeset. 45 exported names leave (19 schema consts + 26 aliases). - The
ESignatureConfigpair (data/document.zod.ts:218/:224→retiredKey()tombstones with prescriptions, not deletions — the schema is not.strict(), so a bare deletion would strip in silence, ADR-0104); twoRETIRED_KEYS_BY_MAJOR[18]entries + one D3 entry (esignature-config-deadline-keys-retired);provider/enabled/signersbyte-identical; the docblock example loses the two keys. - PR feat(spec): retire the fourteen inert deadline keys of the incident-response, training and change-management schemas (#14477, ADR-0049) #15514's history preserved: the fourteen deadline-key tombstones leave with their defs' source; their fourteen
RETIRED_KEYS_BY_MAJOR[18]entries and three D3 entries stay (gate (b2) ofbuild-schemas.tsaccepts an entry naming a key the build no longer emits; pinned so nobody "cleans them up").deadline-keys-retirement.test.tsis replaced bycompliance-families-retirement.test.ts. registry.tsadd-only (+737 −1: the one deletion is the step-18 narrative sentence re-joined with its extension; 25 entry files, main'splugin-security-scannerentry merged clean beside them) — the epic stack (feat(spec)!: duration-shaped number keys carry their unit in the key name — no-baseline gate + seven ADR-0087 renames (timeoutMs, ttlSeconds/ttlMs, *TimeoutSeconds) #15626 / feat(spec)!: declare the duration rule's two structural exemptions on the schema — a sharedEpochMsinstant and a.meta({ externalVocabulary })marker #15814, drafts) mergesmainafter this lands, as the seat post records.- Generated corpus by tooling:
api-surface−44,authorable-surface−88,authorable-defaults−10 (+1),declaration-map−38,export-origins−44,json-schema.manifest−19, three reference pages removed +system/index.mdx/meta.json/references/index.mdx,document.mdxregenerated;gen:schemaadjudicated "19 schema(s) left the published set … each declared". Hand-written pages that counted the families (getting-started/quick-reference.mdx17 of 36 → 16 of 33;packages/spec/llms.txt207 → 204, system 36 → 33) corrected — the count gates (check:quick-reference-counts,check:llms-txt) run green.type-alias-convention.pin.test.ts825 → 812 with the M-indices left positional. - Changeset:
@objectstack/specminor, launch-window**BREAKING**banner naming the nineteen defs and the pair,adr-0087: registeredfor the four semantic ids (check:adr-0087-registrationgreen), the census with controls, "cloud and real customer configs UNMEASURED" verbatim. Governed predicate: 0 of 60 paths (17:00Z).
Two files outside the declared face, both the playbook's own mechanism:
scripts/cross-package-test-inputs.mjs(+52) andturbo.json(+14) declare the new tree-scoped absence pin's walk radius (five roots, per-extension underpackages/, never.tsx) — rule #15566 of the retirement playbook, added after PR #15514 (whose pin lacked it, #15528).check:cross-package-test-inputsand the ci-filter parity gate run green. Open question ruled by the seat: A (keep the declared radius) — an undeclared radius is not a finished retirement under the playbook; the cost is turbo cache invalidation of@objectstack/spec#teston anypackages/**/examples/**/content/**change, i.e. CI minutes, recorded for the maintainer in the shift report (the playbook is the skills lane's; a narrower rule is that lane's call, not this PR's).Pins bear weight:
compliance-families-retirement.test.ts(the #8075 form — zero holders of the 45 names on every public entry via theexport-originstestkit, the file-deletion probe, the in-package importer walk, the runtime-namespace cross-check, the tree-scoped absence leg over the declared roots, the #15514 history pin, the 19RETIRED_DEFS_BY_MAJOR[18]entries and three D3 ids);esignature-deadline-keys-retirement.test.ts(refusal withcode,pathnaming the site and the prescription's wording; well-formed fixtures without the pair; the two registry entries and the D3 id);document.test.tsupdated.Verification accepted: build,
check:generated(15 artifacts up to date), targeted vitest 13 files / 351 tests, spec typecheck exit 0; reverse verification downstream (a probe underpackages/coreimporting the retired names and authoringexpirationDays→tscexit 2 with TS2305 ×3 / TS2724 / TS2322; the survivor control exit 0; probe removed, tree clean); gate families 116 derived / 116 run / 0 unrun (the tool's own reconciliation), three NOT MEASURED are whole-repo-dist prerequisites (CI's Lint & Repo Gates); eslint over the 32 changed source files 0/0;turbo ls --affected78 of 79 packages — the farm run is CI's. Reader census taken three times (branch base, after the first merge, final head): 0 readers on every leg for all 45 names and the pair, controls 336 / 192 / 342.origin/mainmerged twice viascripts/pm/os-regen-merge.shwith regeneration committed separately. The run survived two walls (Fable limit, session limit) by idempotent resumption from pushed state.Landing path: CI on
70582583frunning (11 green, 18 in progress at 17:01Z). The seat hangs and clearsneeds:contract-reviewon all three carriers (PR #15973, #15513, #14477) at this head, runs the pair check, and flips to ready + auto-merge (squash) once every check is green. On merge: #15513 and #14477 close by the PR; the epic PM mergesmaininto the #14478 stack (registry.ts); the retired reference pages disappear from the docs site.
Generated by Claude Code
- The three families leave whole.
9 remaining items
Landing provenance (domain:spec seat,
session_01M59rPZZFzqhfMUPFqqZTkf, 2026-09-05T22:21Z): PR #15973 flipped to ready and auto-merge (squash) enabled at 22:21Z on head310ebe8cf— every check on that head green (34 success / 7 skipped, none red),mergeable_state: clean; ACCEPT + Clause-② PASS5553380537at70582583f, fix-lap delta ACCEPT5553797140atf8ccc4753, merge-lap delta ACCEPT5555023658at310ebe8cf;needs:contract-reviewhung and cleared on all three carriers at310ebe8cf(21:51Z), pair checks ✓ for #15513 and #14477; governed predicate 0 of 61 paths. The queue's enqueue reading and the landing notes follow on MERGED (landing watch armed 22:46Z).
Generated by Claude Code
Release:
session_01M59rPZZFzqhfMUPFqqZTkf(domain:spec seat) — reason: landed; destination: closed by PR #15973 (Fixes #15513), no successor.Landing note (2026-09-05T22:51Z, anchor of the two-card fold): PR #15973 MERGED at 2026-09-05T22:51:10Z as
c463d03e0(squash; enqueued 2026-09-05T22:21:37Z). Probe onorigin/mainc463d03e0:IncidentResponsePolicySchema0 files underpackages/spec/src(control: present at0cf086759),system/incident-response.zod.tsabsent (control: present),retiredKey(EXPIRATION_DAYS_RETIRED)present indata/document.zod.ts. The three compliance families (19 defs) retired whole underRETIRED_DEFS_BY_MAJOR[18]+ three D3 entries; theESignatureConfigdeadline pair tombstoned with twoRETIRED_KEYS_BY_MAJOR[18]entries + one D3 entry; PR #15514's fourteen history entries kept; the tree-scoped absence pin's walk radius declared (examples/non-code files only). Lane inventory: #15513 and #14477 close; the retired reference pages leave the docs site; the epic PM's #14478 stack (PRs #15626 / #15814) mergesmainformigrations/registry.tsnext — heads-up posted on PR #15626. The playbook's walk-radius cost (turbo cache invalidation of@objectstack/spec#testonpackages/**/content/**/skills/**/scripts/**changes) goes to the shift report for the skills lane.pm:dispatchedstripped, assignee cleared in this stroke.
Generated by Claude Code
Correction to the landing note above (2026-09-05T22:52Z): the probe line "
IncidentResponsePolicySchema0 files underpackages/spec/src" was mis-stated — the NAME survives in exactly four files onorigin/mainc463d03e0, all of them the retirement's own records:migrations/entries/semantic/18.incident-response-family-retired.ts,migrations/registry.ts(theRETIRED_DEFS_BY_MAJOR[18]row),system/compliance-families-retirement.test.ts(the absence pin naming what must be gone) andsystem/index.ts(the retirement comment replacing theexport *). The schema definition itself is gone:system/incident-response.zod.tsis absent on main (present at the0cf086759control), and no export of the name remains. The verdict's zero-holder census (report5553370781) is what the probe was meant to restate; the corrected reading agrees with it.
Generated by Claude Code
- added a commit that references this issue
on Sep 9, 2026 - added a commit that references this issue
on Sep 21, 2026
Found while executing #14477 (retiring the fourteen hour/minute/day-shaped deadline keys of these three families under ADR-0049). Not addressed there — the ruling on that card scoped the retirement to the deadline-shaped keys, and this is the same enforce-or-remove question one level up: the whole families.
What was measured
The reader census that grounded #14477 was run over the families, not only the deadline keys, on
origin/main(a06faebbe, re-run on the merged head83a3353e3):packages/spec/src/system/incident-response.zod.ts,training.zod.tsandchange-management.zod.ts(IncidentSeveritySchema…IncidentResponsePolicySchema,TrainingCategorySchema…TrainingPlanSchema,ChangeTypeSchema…ChangeRequestSchema, and theirz.input/Parsedtypes) anywhere inpackages/**,apps/**,examples/**orskills/**outsidepackages/spec— the only holders are the generatedapi-surface/anddeclaration-map/shards and the families' own unit tests;00d3f09c5for the same names;@objectstack/spec/system(system/index.ts), mounted by no key ofstack.zod.ts, registered as no metadata type, and absent from the 2026-06 liveness ledgers underdocs/audits/(which is why spec: hour/minute/day-shaped deadline keys in incident-response, training, change-management and ESignature schemas have zero readers and no EXPERIMENTAL tag (ADR-0049 shape) #14477 could not be a ledgerdeadverdict either).So after #14477 lands, roughly a hundred declared keys remain on these fifteen defs (counted as schema
key:lines: 40 in incident-response, 25 in training, 52 in change-management, fourteen of them now tombstones), every one on the exported surface and in the generated reference docs, and every one read by nothing. Several are boolean capability claims of exactly the shape ADR-0049 names:IncidentNotificationRule.notifyRegulators,IncidentResponsePolicy.requirePostIncidentReview,TrainingPlan.trackCompletion/sendReminders,TrainingCourse.mandatory,ChangeRequest.securityImpact.requiresSecurityApproval,ChangeRequest.approval.required— an author writingnotifyRegulators: trueholds a compliance promise the platform does not keep, with no error and no feedback.Why it is filed rather than folded into #14477
The ruling on #14477 (2026-09-02, ruled A) retired the deadline keys per family and left the families standing. Whether a family is roadmapped — the one variable that flips retirement into an
[EXPERIMENTAL — not enforced]tag — is product knowledge, and it was asked per family there; the answer for the remaining surface is not in the code.Suggested disposition (for triage, not decided here)
Per family, the two ADR-0049 routes: whole-def retirement via
RETIRED_DEFS_BY_MAJOR(theintegration/ErrorMappingConfigprecedent, #14676 — every def leaves the public surface and the manifest ratchet adjudicates it), or an[EXPERIMENTAL — not enforced]marker on every def plus liveness-ledger enrolment so the next audit does not miss them again. Either way the reference docs stop advertising a compliance subsystem that does not exist.Refs #14477 (the deadline-key retirement; branch
claude/issue-14477-inert-deadline-key-retirement).