You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Expose repository/query APIs that require both a valid-time cut and a knowledge-position cut where history matters.
Remove ambiguous as_of/capture-time substitution and reject naive or semantically unclassified timestamps.
Update in-force selection, supersession/correction, freshness, qualification, materialization keys, context snapshots, and replay to use the correct axis.
Add indexes and exclusion/uniqueness constraints needed by the approved interval semantics without treating recordedAt as total order.
Pin both temporal cuts in every derived snapshot, review decision, and output receipt.
Add tests for future-effective, expired, late-arriving, corrected, equal-wall-clock, interval-boundary, whole-batch visibility, rollback, cross-tenant, historical replay, pre-binding no-tenant invariance, and the post-binding refusal switch.
Boundaries
Implement #170 exactly. Do not implement or invent the #192 audit lane, infer tenant attribution, reuse a tenant table for pre-binding failures, invent missing domain dates, change law/contracts, activate profiles, alter manifests/active sets, or raise capability claims.
Bounded first-delivery path — 2026-09-11
Renewed canonical Phase A approval at exact PR #11 head 4494924998183fe3fa7bc1b63b76a85893335044 is the canonical planning basis, not executable authority. The current path is a working pending-review operation claim with truthful result recovery and current authorized readback, followed by one separately specified temporal write/read child. The precursor does not satisfy this epic: the later child must bind the exact domain-time carrier and prove independent valid-time and knowledge-position cuts.
Authorization, shared transaction coordination, compatible successor command/selection and exact temporal/read bindings remain dependencies. #170/#173/#174/#192 are completed foundations, not work to reopen. Keep #180/#181/#182/#183/#185 responsibilities separate. No epic acceptance criterion, label or status is changed and no ready Delivery child is claimed by this note.
The initial authorization scope is exactly ASSERT_OPERATION_CLAIM and RECEIVE_READ_DATA, with full unchanged rules and all required dependencies. History completeness/historical-admission verification under CP2A-DEP01 remains unresolved; an inactive writer, empty lookup or permanent UNAVAILABLE is not closure. No new qualifying action, read target, writer, schema, runtime or public activation is introduced.
What is next: complete the separately governed claim/read prerequisites, then select the exact temporal Delivery boundary and tests. Do not close #176 with a record lookup or idempotency replay.
Parent: #167
Depends on: #170, #173, #174, #192
Outcome
Implement the accepted ADR so every historical answer is pinned independently to domain-valid time and tenant knowledge order.
Acceptance criteria
as_of/capture-time substitution and reject naive or semantically unclassified timestamps.recordedAtas total order.Boundaries
Implement #170 exactly. Do not implement or invent the #192 audit lane, infer tenant attribution, reuse a tenant table for pre-binding failures, invent missing domain dates, change law/contracts, activate profiles, alter manifests/active sets, or raise capability claims.
Bounded first-delivery path — 2026-09-11
Renewed canonical Phase A approval at exact PR #11 head
4494924998183fe3fa7bc1b63b76a85893335044is the canonical planning basis, not executable authority. The current path is a working pending-review operation claim with truthful result recovery and current authorized readback, followed by one separately specified temporal write/read child. The precursor does not satisfy this epic: the later child must bind the exact domain-time carrier and prove independent valid-time and knowledge-position cuts.Authorization, shared transaction coordination, compatible successor command/selection and exact temporal/read bindings remain dependencies. #170/#173/#174/#192 are completed foundations, not work to reopen. Keep #180/#181/#182/#183/#185 responsibilities separate. No epic acceptance criterion, label or status is changed and no ready Delivery child is claimed by this note.
The initial authorization scope is exactly ASSERT_OPERATION_CLAIM and RECEIVE_READ_DATA, with full unchanged rules and all required dependencies. History completeness/historical-admission verification under CP2A-DEP01 remains unresolved; an inactive writer, empty lookup or permanent UNAVAILABLE is not closure. No new qualifying action, read target, writer, schema, runtime or public activation is introduced.
What is next: complete the separately governed claim/read prerequisites, then select the exact temporal Delivery boundary and tests. Do not close #176 with a record lookup or idempotency replay.