feat(postbox): reconcile lifecycle notifications

This commit is contained in:
2026-08-20 04:58:34 +02:00
parent 41ea8d8e23
commit 8a21876634
8 changed files with 765 additions and 9 deletions
+10
View File
@@ -108,6 +108,16 @@ an independently readable copy in the next frozen function Postbox. The
`govoplan.postbox.dispatch_routes` periodic Core worker drains due routes when
Celery beat and a worker consuming the `postbox` queue are enabled.
That worker also reconciles current IDM incumbencies in batches against a
durable metadata-only cursor. Assignment, delegation, vacancy, and
reassignment changes emit versioned platform events and optional in-app
Notifications for newly eligible current holders. Delivery, action-required,
escalation-due, read, and acknowledgement events link back to Postbox-owned
resources without copying message subjects, bodies, or attachment details into
lifecycle events. Notification preferences, quiet periods, and future external
channel policy remain owned by Notifications; every deep link rechecks current
Postbox access.
Postboxes expose three configurable content-protection profiles. The recommended
`server_envelope_v1` profile stores message bodies as ciphertext through an
institution-controlled Encryption vault and fails closed if its capability or