Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 37 additions & 3 deletions config/governance/governed_document_lock_manifest.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,22 @@
{
"approval_records": [
{
"approval_id": "AI4B-GOV-DOCLOCK-INTELLIGENCE-BOUNDARY-QUALITY-CLOSURE-20260926-001",
"approval_scope": "INTELLIGENCE_BOUNDARY_AND_FULL_QUALITY_CLOSURE_DOCUMENTATION_ALIGNMENT",
"approval_status": "APPROVED",
"approved_at_utc": "2026-09-26T17:45:26Z",
"approved_by": "Huseyin",
"approved_roles": [
"GovernanceOwner"
],
"approved_principal_ids": [
"huseyin-governance-owner-principal"
],
"written_owner_approval": true,
"approved_sha256": {
"docs/compliance/registry_compliance_matrix.md": "7286ee41aa0e4ab53c5c8b409e7e928089a68fd3c5ca6384cf91fac6c6e23f71"
}
},
{
"approval_id": "AI4B-GOV-DOCLOCK-CODEX-FABRIC-ROUTING-20260918-001",
"approval_scope": "CODEX_TERMINOLOGY_NAMING_TECHNOLOGY_LANGUAGE_FABRIC_ROUTING",
Expand Down Expand Up @@ -2012,13 +2029,13 @@
"authority_scope": "compliance_matrix",
"canonical_path": "docs/compliance/registry_compliance_matrix.md",
"document_status": "ACTIVE",
"expected_hash": "925237186799fdd6b7fe4b98c271d4ed1be4c6cc02ad6a22394d50172a463477",
"expected_hash": "7286ee41aa0e4ab53c5c8b409e7e928089a68fd3c5ca6384cf91fac6c6e23f71",
"lock_state": "LOCKED",
"path": "docs/compliance/registry_compliance_matrix.md",
"sha256": "925237186799fdd6b7fe4b98c271d4ed1be4c6cc02ad6a22394d50172a463477",
"sha256": "7286ee41aa0e4ab53c5c8b409e7e928089a68fd3c5ca6384cf91fac6c6e23f71",
"source_of_truth": true,
"supersedes": [],
"version": "2.10.15"
"version": "2.10.16"
},
{
"allowed_change_process": "WRITTEN_OWNER_APPROVAL_REQUIRED",
Expand Down Expand Up @@ -3498,6 +3515,23 @@
"status": "ACTIVE",
"written_owner_approval_required": true,
"written_owner_approvals": [
{
"approval_id": "AI4B-GOV-DOCLOCK-INTELLIGENCE-BOUNDARY-QUALITY-CLOSURE-20260926-001",
"approval_scope": "INTELLIGENCE_BOUNDARY_AND_FULL_QUALITY_CLOSURE_DOCUMENTATION_ALIGNMENT",
"approval_status": "APPROVED",
"approved_at_utc": "2026-09-26T17:45:26Z",
"approved_by": "Huseyin",
"approved_roles": [
"GovernanceOwner"
],
"approved_principal_ids": [
"huseyin-governance-owner-principal"
],
"written_owner_approval": true,
"approved_sha256": {
"docs/compliance/registry_compliance_matrix.md": "7286ee41aa0e4ab53c5c8b409e7e928089a68fd3c5ca6384cf91fac6c6e23f71"
}
},
{
"approval_id": "AI4B-GOV-DOCLOCK-CODEX-FABRIC-ROUTING-20260918-001",
"approval_scope": "CODEX_TERMINOLOGY_NAMING_TECHNOLOGY_LANGUAGE_FABRIC_ROUTING",
Expand Down
4 changes: 2 additions & 2 deletions docs/compliance/registry_compliance_matrix.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
document_id: AI4B-GOV-REG-001
title: AI4BINANCE Compliance Matrix
document_type: REGISTRY
version: 2.10.15
version: 2.10.16
status: ACTIVE
owner: Enterprise Governance
authority_level: NORMATIVE
Expand Down Expand Up @@ -127,7 +127,7 @@ unverified requirement.
| Virtual Market DGE application boundary | `docs/governance/framework_decision_governance_engine.md`, `src/ai4binance/core/contracts/virtual_governance.py`, `src/ai4binance/application/research.py`, `src/ai4binance/governance/adapters.py`, `src/ai4binance/governance/dge_engine.py`, `src/ai4binance/governance/rules.py`, `src/ai4binance/governance/replay.py`, `src/ai4binance/governance/shadow.py`, `src/ai4binance/research/virtual_runtime_request.py`, `src/ai4binance/research_runtime.py`, `tests/test_research_application.py`, `tests/test_dge_recovery_replay_shadow.py` | PARTIAL | `VirtualGovernanceResult` is the dependency-neutral result contract; the application layer owns only the evaluator port, `VirtualMarketDgeAdapter` owns deterministic candidate/context conversion and canonical DGE invocation, and `research_runtime.py` binds the concrete adapter at the composition boundary. The adapter derives the independent validation handoff from the validated analysis result; recovery input remains fail-closed when no independent validation result exists. Only `APPROVED_PAPER_ONLY` without DGE blockers can enter bounded Virtual Market simulation. This route reuses canonical virtual execution and accounting, remains fail-closed, and never grants live authority. Fresh FULL evidence and distinct C3 approval replay remain required; `RESEARCH_ONLY` and `LIVE_ORDER_BLOCKED` are mandatory. |
| MCP Gateway policy route | `src/ai4binance/governance/mcp_gateway.py`, `src/ai4binance/governance/tool_policy.py`, `tests/test_governance_tool_gateway.py`, `docs/contracts/interface_contract_read_only_evidence_mcp.md` | COMPLETED | Agent -> MCP shortcut is disabled. Canonical route is `Agent -> Tool Policy -> Authorization -> MCP Gateway -> Tool`; Filesystem/GitHub/PostgreSQL/Research/future Binance READ-ONLY surfaces are consolidated under the default-deny contract. `filesystem.delete`, `shell.admin`, `exchange.place_order` remain denied; trading/live authority is not generated. |
| Constitutional change control | `src/ai4binance/governance/framework.py`, `src/ai4binance/governance/gate.py`, `src/ai4binance/governance/lean.py`, `src/ai4binance/governance_primitives.py`, `tests/test_governance_framework_v2.py`, `tests/test_governance_gate.py`, `tests/test_governance_primitives.py`, `docs/governance/framework_core_vnext_governance.md`, `docs/governance/instruction_core_custom_instructions.md`, `AGENTS.md`, `docs/providers/instruction_codex_provider.md`, `docs/registries/registry_documentation_index.md`, `config/governance/governed_document_lock_manifest.json` | COMPLETED | Constitutional authority is split into three primitives: `DETERMINISTIC_QUALITY_GATE=TECHNICAL_TRUTH`, `DETERMINISTIC_GOVERNANCE_GATE=POLICY_ELIGIBILITY`, and `HUMAN_GOVERNANCE=CONSEQUENTIAL_AUTHORITY`. `risk-tiered human governance` applies only to consequential changes. `src/ai4binance/governance_primitives.py` is the canonical lifecycle and authority primitive surface, and `src/ai4binance/governance/gate.py` plus `src/ai4binance/governance/lean.py` consume that same first-class lifecycle primitive across deterministic quality evidence, governance eligibility, approval-verification payloads, and poka-yoke gate checks. `approval_verification` is a hard veto, not an informational check: if the approval packet is missing, unauthorized, expired, revoked, scope-mismatched, evidence-mismatched, lifecycle-definition-mismatched, authority-family-mismatched, or blocker-tainted, consequential transitions remain vetoed and `LIVE_ORDER_BLOCKED` stays true. `C2_BEHAVIORAL` changes require an ELI10-backed `Approval Packet`; `C3_GOVERNED` changes require explicit review of the relevant policy/instructions plus double approval and same-diff constitution sync; `C4_CONSEQUENTIAL` changes require explicit high-assurance approval. Code-constitution conflict is not considered complete. |
| Governance alignment / loose-code audit | `AGENTS.md`, `src/ai4binance/governance/audit.py`, `src/ai4binance/governance/constitution_sync.py`, `src/ai4binance/governance/gate.py`, `src/ai4binance/governance/lean.py`, `src/ai4binance/governance_primitives.py`, `src/ai4binance/ops/repository_cleanup_audit.py`, `src/ai4binance/storage/jsonl.py`, `tests/test_dge_recovery_replay_shadow.py`, `tests/test_governance_constitution_sync.py`, `tests/test_governance_gate.py`, `tests/test_governance_primitives.py`, `tests/test_repository_cleanup_audit.py`, `tests/test_docs_hygiene.py`, `tests/test_kaizen_quality.py`, `tests/test_quality_gate_profiles.py`, `tests/test_storage.py`, `scripts/quality.ps1`, `config/quality/gates.yaml`, `config/governance/governed_document_lock_manifest.json`, `runtime/artifacts/quality/gate/approval_record_latest.json`, `runtime/artifacts/quality/gate/latest.json` | COMPLETED | Core documentation, root `AGENTS.md`, Custom Instructions, Codex, and the compliance matrix must carry the same `TECHNICAL_TRUTH` / `POLICY_ELIGIBILITY` / `CONSEQUENTIAL_AUTHORITY` agreement. A mismatch across core/root/custom/codex/compliance appears as `CONSTITUTION_FAMILY_MISMATCH`. An empty-source-file change that does not carry test, compliance, or written rule evidence results in `RUNNING_WITH_BLOCKERS`. Governed cleanup audit registry records must jointly display source, test, compliance matrix, and core documentation evidence, plus written owner approval lineage when governed Markdown changes. The request "Expand the scope of governance" requires an aggressive yet realistic gap analysis using secure tools, current CPU/RAM/GPU capacity, extensive testing, and parallel read-only analysis. Capability OOS/operational evidence gaps remain visible as `RESEARCH_ONLY` / `PARTIAL` / `MISSING`. Full technical quality evidence does not produce the claim COMPLETE unless the current quality evidence carries `TECHNICAL_QUALITY_PASS`, `pytest_pass_count`, `coverage_percent`, and `coverage_source`, and the same evidence envelope reports `full_assurance_status=FULL_ASSURANCE_GREEN`. The approval loader fallback consumes `runtime/artifacts/quality/gate/approval_record_latest.json` as the first-class approval artifact for the same scope/evidence envelope, binds `evidence_hash`, `authority_family_sha256`, and `lifecycle_definition_sha256`, and never downgrades to lower-authority defaults; if approval verification fails, the same envelope must remain `RUNNING_WITH_BLOCKERS`, `consequential_change_allowed=false`, and `LIVE_ORDER_BLOCKED`. Governance and replay-ready DGE decision journals now use the same first-class tamper-evident JSONL audit primitive with durable write-through, read-back verification, and fail-closed chain validation before append; coverage rate cannot be inferred from outside full quality_gate evidence. Human governance is consequential authority, not generic bureaucracy; `execution_allowed=false`, `RESEARCH_ONLY`, and `LIVE_ORDER_BLOCKED` are constants. |
| Governance alignment / loose-code audit | `AGENTS.md`, `src/ai4binance/governance/audit.py`, `src/ai4binance/governance/constitution_sync.py`, `src/ai4binance/governance/gate.py`, `src/ai4binance/governance/lean.py`, `src/ai4binance/governance_primitives.py`, `src/ai4binance/ops/repository_cleanup_audit.py`, `src/ai4binance/storage/jsonl.py`, `src/ai4binance/intelligence/derivatives.py`, `src/ai4binance/intelligence/trading.py`, `tests/test_dge_recovery_replay_shadow.py`, `tests/test_governance_constitution_sync.py`, `tests/test_governance_gate.py`, `tests/test_governance_primitives.py`, `tests/test_repository_cleanup_audit.py`, `tests/test_docs_hygiene.py`, `tests/test_kaizen_quality.py`, `tests/test_quality_gate_profiles.py`, `tests/test_storage.py`, `tests/test_trading_intelligence.py`, `tests/test_virtual_runtime.py`, `tests/test_lowest_coverage_boundary_contracts.py`, `scripts/quality.ps1`, `config/quality/gates.yaml`, `config/governance/governed_document_lock_manifest.json`, `runtime/artifacts/quality/gate/approval_record_latest.json`, `runtime/artifacts/quality/gate/latest.json` | COMPLETED | Core documentation, root `AGENTS.md`, Custom Instructions, Codex, and the compliance matrix must carry the same `TECHNICAL_TRUTH` / `POLICY_ELIGIBILITY` / `CONSEQUENTIAL_AUTHORITY` agreement. A mismatch across core/root/custom/codex/compliance appears as `CONSTITUTION_FAMILY_MISMATCH`. An empty-source-file change that does not carry test, compliance, or written rule evidence results in `RUNNING_WITH_BLOCKERS`. `src/ai4binance/intelligence/derivatives.py` rejects malformed derivatives metrics with a fail-closed result, and `src/ai4binance/intelligence/trading.py` revalidates cost-model inputs before completing the intelligence result; neither path grants execution authority. The named intelligence tests cover those boundaries, including the virtual-runtime risk rejection path. Governed cleanup audit registry records must jointly display source, test, compliance matrix, and core documentation evidence, plus written owner approval lineage when governed Markdown changes. The request "Expand the scope of governance" requires an aggressive yet realistic gap analysis using secure tools, current CPU/RAM/GPU capacity, extensive testing, and parallel read-only analysis. Capability OOS/operational evidence gaps remain visible as `RESEARCH_ONLY` / `PARTIAL` / `MISSING`. Full technical quality evidence does not produce the claim COMPLETE unless the current quality evidence carries `TECHNICAL_QUALITY_PASS`, `pytest_pass_count`, `coverage_percent`, and `coverage_source`, and the same evidence envelope reports `full_assurance_status=FULL_ASSURANCE_GREEN`. The approval loader fallback consumes `runtime/artifacts/quality/gate/approval_record_latest.json` as the first-class approval artifact for the same scope/evidence envelope, binds `evidence_hash`, `authority_family_sha256`, and `lifecycle_definition_sha256`, and never downgrades to lower-authority defaults; if approval verification fails, the same envelope must remain `RUNNING_WITH_BLOCKERS`, `consequential_change_allowed=false`, and `LIVE_ORDER_BLOCKED`. Governance and replay-ready DGE decision journals now use the same first-class tamper-evident JSONL audit primitive with durable write-through, read-back verification, and fail-closed chain validation before append; coverage rate cannot be inferred from outside full quality_gate evidence. Human governance is consequential authority, not generic bureaucracy; `execution_allowed=false`, `RESEARCH_ONLY`, and `LIVE_ORDER_BLOCKED` are constants. |
| Universal governed-object enforcement fabric | `docs/standards/standard_governed_object_enforcement.md`, `src/ai4binance/governance/enforcement/__init__.py`, `src/ai4binance/governance/enforcement/contracts.py`, `src/ai4binance/governance/enforcement/engine.py`, `src/ai4binance/governance/enforcement/registry.py`, `src/ai4binance/governance/enforcement/adapters.py`, `src/ai4binance/governance/enforcement/inventory.py`, `config/governance/enforcement_profiles.yaml`, `config/governance/enforcement_inventory.yaml`, `tests/test_governed_object_enforcement.py` | COMPLETED | The governed-object enforcement capability now exposes one shared `GovernedObjectEnvelope -> EnforcementRequest -> EnforcementDecision` contract, deterministic gate ordering, profile coverage checks, adapter reuse for repository/governed knowledge, and a machine-readable inventory of consequential entrypoints. Every consequential inventory entrypoint is now classified as either canonical `ROUTED` or explicit fail-closed `BLOCKED`, `ADAPTER_REQUIRED` and `REPORT_ONLY` exit gaps have been removed from the canonical inventory, and routed consequential paths do not retain a documented bypass route. Lower-level helper surfaces may still exist as implementation primitives, but they are non-authoritative for promotion or execution claims unless their inventory entrypoint is `ROUTED`. `execution_allowed=false`, `RESEARCH_ONLY`, and `LIVE_ORDER_BLOCKED` remain unchanged. |
| Repository & File Governance Standard | `docs/standards/standard_repository_file_governance.md`, `src/ai4binance/governance/repository_validator.py`, `tests/test_repository_validator.py`, `tests/test_artifact_hygiene_scripts.py`, `scripts/quality.ps1` | COMPLETED | The `AI4B-GOV-REPO-001` standard has been transitioned to a permanent governance standard. The file/folder structure is not a one-time Codex cleanup decision; it is continuously enforced using the triple of `RepositoryPolicy + RepositoryArtifact schema + deterministic repository_validator`. The validator operates in report-only and fail-closed modes; it makes visible findings such as unknown top-level paths, unsafe Python naming, source filename versioning, source/runtime mixing, generated artifacts under src, and unapproved absolute paths. It cannot mitigate health score hard blockers; `execution_allowed=false`, `RESEARCH_ONLY`, and `LIVE_ORDER_BLOCKED` are constants. |
| Documentation & Knowledge Governance Standard | `AGENTS.md`, `docs/providers/instruction_codex_provider.md`, `docs/governance/instruction_core_custom_instructions.md`, `docs/governance/framework_core_vnext_governance.md`, `docs/compliance/registry_compliance_matrix.md`, `docs/standards/standard_documentation_knowledge_governance.md`, `docs/controls/control_repository_validation_rules.md`, `src/ai4binance/governance/repository_validator.py`, `tests/test_repository_validator.py`, `tests/test_docs_hygiene.py`, `tests/test_governance_constitution_sync.py`, `scripts/quality.ps1` | COMPLETED | The `AI4B-GOV-DKG-001` standard has been transitioned to the active knowledge-governance standard. Critical system knowledge is not free Markdown; core/root/custom/codex/compliance and active standards carry `GovernedKnowledgeObject` metadata. The `RepositoryPolicy + RepositoryArtifact schema + deterministic repository_validator` chain enforces full quality gate within. Missing/broken document_id, semver, lifecycle, authority_level, content_role, owner, source_of_truth, duplicate knowledge_id, duplicate active source-of-truth concept, or lower-authority reuse of an active higher-authority `authority_scope` generates `RUNNING_WITH_BLOCKERS`. The validator now resolves concept ownership by `authority_scope`, emits `KNOWLEDGE_AUTHORITY_OVERRIDE_CONFLICT` when a lower layer attempts to weaken/contradict/override the higher owner scope, and allows operational specialization only through a narrower derived `authority_scope` plus matching derived `source_of_truth_scope`; governed repository/file standards and machine governance contracts are locked to professional English (`en-US`) and language drift in those controlled surfaces is `NON_CODE_CONTENT_LANGUAGE_VIOLATION`; `RESEARCH_ONLY` and `LIVE_ORDER_BLOCKED` remain constant. |
Expand Down
Loading
Loading