feat: implement institutional governance and recovery architecture
Dependency Audit / dependency-audit (push) Failing after 10s
Deployment Installer / deployment-installer (push) Successful in 6s
Security Audit / security-audit (push) Failing after 9s

This commit is contained in:
2026-08-01 17:46:53 +02:00
parent 3c658fa32d
commit d78b13f9d3
45 changed files with 4388 additions and 262 deletions
@@ -0,0 +1,42 @@
# Governed Service To Decision
This product package composes independently owned institutional semantics into
one reconstructable administrative journey:
```text
Service discovery -> Case intake -> Party and representation -> Mandate
resolution -> approval/deliberation -> formal Decision -> observed delivery
effect -> record and review references
```
An installed Forms and Forms Runtime pair adds an alternative governed entry
path before case/workflow handoff:
```text
Service discovery -> exact Form revision -> validated draft/submission
-> receipt and handoff evidence -> Case or Workflow owner
```
Services, Cases, Parties, Mandates, Committee, and Decisions retain immutable
provider-owned revisions for the parts they own. Portal, Cases, and Committee
consume capabilities for cross-module semantics only. The package does not
grant cross-module table access and can omit optional presentation, work,
deliberation, delivery, or records modules while retaining explicit references
to externally performed steps.
## Security And Recovery
Every provider is tenant-bound. Missing or conflicting authority fails closed.
Protected Decision content has a separate permission. Writes are replay-safe
and OCC-guarded. Database restore is the semantic-state recovery unit; file and
communication effects remain governed by their owning providers and are linked
through requested/observed effect, evidence, and audit references.
The executable fixture in
`tests/test_institutional_governance_journey.py` proves SQL-backed Service,
Case, Party, Mandate, Committee meeting/agendum/vote/minute, and Decision state.
`tests/test_institutional_service_journey.py` separately proves exact Portal
Form launch, persisted submission provenance, and idempotent replay.
Target-environment accessibility, security, operator, privacy,
delivery-provider, and recovery evidence are still required before this product
package may claim `reference_ready` maturity.
@@ -0,0 +1,59 @@
{
"package_id": "product.service-to-decision",
"name": "Governed Service To Decision",
"version": "0.1.0",
"package_class": "product",
"description": "Carry one exact institutional context from service discovery and case intake through parties, authority, formal outcome, communication evidence, and review.",
"publisher": "GovOPlaN",
"category": "institutional-governance",
"license": "AGPL-3.0-or-later",
"required_modules": [
{"module_id": "audit"},
{"module_id": "cases"},
{"module_id": "decisions"},
{"module_id": "mandates"},
{"module_id": "parties"},
{"module_id": "policy"},
{"module_id": "portal"},
{"module_id": "services"}
],
"required_capabilities": [
"cases.party_context",
"cases.service_intake",
"decisions.registry",
"mandates.resolver",
"parties.resolver",
"portal.service_directory",
"services.availability",
"services.definitions"
],
"optional_modules": [
{"module_id": "approvals"},
{"module_id": "committee"},
{"module_id": "files"},
{"module_id": "forms"},
{"module_id": "forms_runtime"},
{"module_id": "postbox"},
{"module_id": "records"},
{"module_id": "tasks"},
{"module_id": "workflow_engine"}
],
"evidence": [
{
"kind": "documentation",
"reference": "packages/product/service-to-decision/README.md",
"summary": "Defines the package boundary, authority path, recovery contract, and known operational limits."
},
{
"kind": "target_test",
"reference": "tests/test_institutional_governance_journey.py",
"summary": "Executes the SQL-backed provider composition from service discovery through persisted formal Decision reconstruction."
},
{
"kind": "target_test",
"reference": "tests/test_institutional_service_journey.py",
"summary": "Executes Portal delegation from an exact Service revision through an exact immutable Form revision to a replay-safe persisted submission."
}
],
"tags": ["service", "case", "mandate", "party", "decision", "public-sector"]
}