[Epic] Adopt the institutional governance target architecture #29

Closed
opened 2026-07-31 23:59:05 +02:00 by zemion · 6 comments
Owner

Outcome

Reconcile govoplan_concept_dev.md and software_big_picture.md with the implemented GovOPlaN platform so the product consistently acts as an institutional governance and operations layer for public institutions.

Canonical direction

Accepted reconciliation

The module runtime, versioned capability/interface graph, Workflow Engine/editor split, external-reference maturity contract, action/effect and outbox foundations, ownership recovery, Views, configured Docs, PostgreSQL Search, Datasources/Dataflow, and Encryption boundaries already exist. They are foundations to extend, not greenfield programs to reopen.

The missing semantic work is Mandates, Services, procedure Parties, formal Decisions, consistent provider source-authority declarations, governed data/register metadata, horizontal assurance, and evidence-backed product/sector packaging.

Work packages

Existing issues for Projects, Reporting, Portal, Cases, and the active reference program are amended rather than duplicated.

Acceptance criteria

  • Durable meta, Core, and owning-module documents agree on the target and current implementation state.
  • Existing issues are amended where they already own work; new issues cover only missing contracts or lifecycles.
  • Machine-readable module/provider metadata distinguishes runtime composition, maturity evidence, source authority, and integration capability.
  • One bounded journey proves mandate/authority, party/representation, formal decision, observed effect, and evidence reconstruction.
  • Configuration packages distinguish reference, product, sector, deployment, and integration profiles without gaining cross-module data ownership.
  • Gitea wiki pages mirror the canonical repository documents.
## Outcome Reconcile `govoplan_concept_dev.md` and `software_big_picture.md` with the implemented GovOPlaN platform so the product consistently acts as an institutional governance and operations layer for public institutions. ## Canonical direction - [Institutional Governance Target Architecture](https://git.add-ideas.de/GovOPlaN/govoplan/src/branch/main/docs/INSTITUTIONAL_GOVERNANCE_TARGET_ARCHITECTURE.md) - [Connected Governance Platform Roadmap](https://git.add-ideas.de/GovOPlaN/govoplan/src/branch/main/docs/CONNECTED_GOVERNANCE_PLATFORM_ROADMAP.md) - [Core Module Architecture](https://git.add-ideas.de/GovOPlaN/govoplan-core/src/branch/main/docs/MODULE_ARCHITECTURE.md) ## Accepted reconciliation The module runtime, versioned capability/interface graph, Workflow Engine/editor split, external-reference maturity contract, action/effect and outbox foundations, ownership recovery, Views, configured Docs, PostgreSQL Search, Datasources/Dataflow, and Encryption boundaries already exist. They are foundations to extend, not greenfield programs to reopen. The missing semantic work is Mandates, Services, procedure Parties, formal Decisions, consistent provider source-authority declarations, governed data/register metadata, horizontal assurance, and evidence-backed product/sector packaging. ## Work packages - [x] [Core module/provider metadata](https://git.add-ideas.de/GovOPlaN/govoplan-core/issues/279) - [x] [Core institutional reference primitives](https://git.add-ideas.de/GovOPlaN/govoplan-core/issues/280) - [x] [Mandates semantics](https://git.add-ideas.de/GovOPlaN/govoplan/issues/30) - [x] [Services semantics](https://git.add-ideas.de/GovOPlaN/govoplan/issues/31) - [x] [Parties semantics](https://git.add-ideas.de/GovOPlaN/govoplan/issues/32) - [x] [Decisions semantics](https://git.add-ideas.de/GovOPlaN/govoplan/issues/33) - [x] [Governed data/register catalogue](https://git.add-ideas.de/GovOPlaN/govoplan-datasources/issues/6) - [x] [Horizontal assurance graph](https://git.add-ideas.de/GovOPlaN/govoplan-risk-compliance/issues/7) - [x] [Product/sector package classes](https://git.add-ideas.de/GovOPlaN/govoplan/issues/34) - [x] [Configured architecture documentation](https://git.add-ideas.de/GovOPlaN/govoplan-docs/issues/19) Existing issues for Projects, Reporting, Portal, Cases, and the active reference program are amended rather than duplicated. ## Acceptance criteria - Durable meta, Core, and owning-module documents agree on the target and current implementation state. - Existing issues are amended where they already own work; new issues cover only missing contracts or lifecycles. - Machine-readable module/provider metadata distinguishes runtime composition, maturity evidence, source authority, and integration capability. - One bounded journey proves mandate/authority, party/representation, formal decision, observed effect, and evidence reconstruction. - Configuration packages distinguish reference, product, sector, deployment, and integration profiles without gaining cross-module data ownership. - Gitea wiki pages mirror the canonical repository documents. <!-- codex-institutional-governance-architecture-2026-07-31 -->
Author
Owner

Codex State: progress

Summary

  • Completed Core #279 (validated architecture/provider declarations), Core #280 (institutional context contracts), and Datasources #6 (governed catalogue).
  • Added portable Mandate, Service, Party, and Decision contracts plus a bounded Committee authority-to-decision proof; their persistence/lifecycle issues remain open.
  • Added signed package classes and provider preflight, Docs/Ops projections, staged Risk/Projects architecture declarations, and release-catalog preservation.

Verification

  • Core, Audit, Access, Datasources, Docs, Ops, Committee, Risk, Projects, release synthesis, WebUI build, and 54-manifest workspace checks pass.

Next / Blocked

  • Continue with persistent semantic lifecycles, horizontal assurance, configured provider-health projection, and evidence-backed proof packages; do not close the epic yet.

Suggested status label: status/in-progress

## Codex State: progress ### Summary - Completed Core #279 (validated architecture/provider declarations), Core #280 (institutional context contracts), and Datasources #6 (governed catalogue). - Added portable Mandate, Service, Party, and Decision contracts plus a bounded Committee authority-to-decision proof; their persistence/lifecycle issues remain open. - Added signed package classes and provider preflight, Docs/Ops projections, staged Risk/Projects architecture declarations, and release-catalog preservation. ### Verification - `Core, Audit, Access, Datasources, Docs, Ops, Committee, Risk, Projects, release synthesis, WebUI build, and 54-manifest workspace checks pass.` ### Next / Blocked - Continue with persistent semantic lifecycles, horizontal assurance, configured provider-health projection, and evidence-backed proof packages; do not close the epic yet. Suggested status label: `status/in-progress`
zemion added
status
in-progress
and removed
status
ready
labels 2026-08-01 03:35:40 +02:00
Author
Owner

Codex State: progress

Summary

  • Closed horizontal assurance (#7), package classes/proof artifacts (#34), and configured architecture documentation (#19); updated the epic checklist.
  • CalDAV now proves tenant-aware runtime binding state through Core, Access package preflight, Docs, and Ops.

Verification

  • Core 120, Calendar 119, Access 53, Docs 19, Ops 1, Risk Compliance 15 tests passed; TypeScript compile passed.

Next / Blocked

  • Mandates #30, Services #31, Parties #32, and the remaining second-domain formal Decision journey #33 remain open.

Suggested status label: status/in-progress

## Codex State: progress ### Summary - Closed horizontal assurance (#7), package classes/proof artifacts (#34), and configured architecture documentation (#19); updated the epic checklist. - CalDAV now proves tenant-aware runtime binding state through Core, Access package preflight, Docs, and Ops. ### Verification - `Core 120, Calendar 119, Access 53, Docs 19, Ops 1, Risk Compliance 15 tests passed; TypeScript compile passed.` ### Next / Blocked - Mandates #30, Services #31, Parties #32, and the remaining second-domain formal Decision journey #33 remain open. Suggested status label: `status/in-progress`
Author
Owner

Codex State: progress

Summary

  • All ten architecture work packages are now closed; Mandates, Services, Parties, and Decisions have executable bounded proofs rather than placeholder repositories.
  • Portal and Cases are now installable headless modules, and the meta matrix includes a cross-repository Service-to-Case composition test.

Verification

  • Static contracts: 56 modules, 90 providers, 46 requirements; passed

Next / Blocked

  • Keep the epic open until one reference journey carries service, party, mandate, decision, observed effect, communication/record, and evidence reconstruction end to end.

Suggested status label: status/in-progress

## Codex State: progress ### Summary - All ten architecture work packages are now closed; Mandates, Services, Parties, and Decisions have executable bounded proofs rather than placeholder repositories. - Portal and Cases are now installable headless modules, and the meta matrix includes a cross-repository Service-to-Case composition test. ### Verification - `Static contracts: 56 modules, 90 providers, 46 requirements; passed` ### Next / Blocked - Keep the epic open until one reference journey carries service, party, mandate, decision, observed effect, communication/record, and evidence reconstruction end to end. Suggested status label: `status/in-progress`
Author
Owner

Codex State: done

Summary

  • The institutional-governance reconciliation is implemented as validated Core contracts, truthful provider/module declarations, bounded owner-module consumers, product artifacts, Ops/Docs projections, and an integrated executable journey.
  • The golden journey reconstructs Service, Case, Party/representation, Mandate/jurisdiction, approval, formal Decision, confirmed communication effect, Audit record, remedy/review, and evidence provenance.

Verification

  • Core module system: 120 tests passed
  • Core institutional contract: 13 tests passed
  • Portal: 7; Cases: 7; Committee: 3 tests passed
  • Meta package/service/governance fixtures: 3 tests passed
  • Dependency boundaries and 56-module static contract graph passed
  • Targeted Gitea wiki pages synchronized and verified

Next / Blocked

  • Further product maturity remains in the owning Portal, Cases, Committee, reference-journey, and persistence issues; semantic repository extraction remains threshold-based.
## Codex State: done ### Summary - The institutional-governance reconciliation is implemented as validated Core contracts, truthful provider/module declarations, bounded owner-module consumers, product artifacts, Ops/Docs projections, and an integrated executable journey. - The golden journey reconstructs Service, Case, Party/representation, Mandate/jurisdiction, approval, formal Decision, confirmed communication effect, Audit record, remedy/review, and evidence provenance. ### Verification - `Core module system: 120 tests passed` - `Core institutional contract: 13 tests passed` - `Portal: 7; Cases: 7; Committee: 3 tests passed` - `Meta package/service/governance fixtures: 3 tests passed` - `Dependency boundaries and 56-module static contract graph passed` - `Targeted Gitea wiki pages synchronized and verified` ### Next / Blocked - Further product maturity remains in the owning Portal, Cases, Committee, reference-journey, and persistence issues; semantic repository extraction remains threshold-based.
Author
Owner

Codex State: done

Summary

  • The target architecture is implemented as an enforced vertical_slice/product architecture contract rather than a documentation-only proposal.
  • Mandates, Services, Parties, and Decisions now have independent persistent module owners with tenant isolation, immutable revisions, OCC, lifecycle validation, APIs, permissions, migrations, uninstall guards, recovery documentation, and provider capabilities.
  • Portal, Cases, and Committee consume those providers without cross-module table access. product.service-to-decision proves the complete SQL-backed path through service discovery, case intake, party representation, mandate resolution, formal decision, observed effect, audit/record evidence, and review references.
  • Provider governance, architecture metadata, package preflight, Docs/Ops projection, environment synchronization, and release tooling are machine-enforced across the workspace.
  • The canonical architecture page and all four module domain/recovery pages are synchronized to their Gitea wikis.

Verification

  • tools/checks/check-focused.sh: passed, including 35 WebUI permutations and full-product bundle budgets.
  • Architecture manifest gate: 60/60 declarations; static contract graph: 60 modules, 98 providers, 54 requirements.
  • Release migration audit: valid graph including the four new module heads.
  • SQL-backed institutional golden journey, configuration-package preflight, module tests, Ruff, and startup smoke: passed.

Release Boundary

The four source repositories are initialized locally but have not been pushed or tagged in this work. Their truthful maturity remains vertical_slice, and the package remains product; reference_ready or supported still requires the separately documented target, accessibility, privacy, security, operations, and recovery-drill evidence.

## Codex State: done ### Summary - The target architecture is implemented as an enforced `vertical_slice`/`product` architecture contract rather than a documentation-only proposal. - Mandates, Services, Parties, and Decisions now have independent persistent module owners with tenant isolation, immutable revisions, OCC, lifecycle validation, APIs, permissions, migrations, uninstall guards, recovery documentation, and provider capabilities. - Portal, Cases, and Committee consume those providers without cross-module table access. `product.service-to-decision` proves the complete SQL-backed path through service discovery, case intake, party representation, mandate resolution, formal decision, observed effect, audit/record evidence, and review references. - Provider governance, architecture metadata, package preflight, Docs/Ops projection, environment synchronization, and release tooling are machine-enforced across the workspace. - The canonical architecture page and all four module domain/recovery pages are synchronized to their Gitea wikis. ### Verification - `tools/checks/check-focused.sh`: passed, including 35 WebUI permutations and full-product bundle budgets. - Architecture manifest gate: 60/60 declarations; static contract graph: 60 modules, 98 providers, 54 requirements. - Release migration audit: valid graph including the four new module heads. - SQL-backed institutional golden journey, configuration-package preflight, module tests, Ruff, and startup smoke: passed. ### Release Boundary The four source repositories are initialized locally but have not been pushed or tagged in this work. Their truthful maturity remains `vertical_slice`, and the package remains `product`; `reference_ready` or `supported` still requires the separately documented target, accessibility, privacy, security, operations, and recovery-drill evidence.
Author
Owner

Codex State: done

Summary

  • The architecture depth pass now includes persistent Projects and governed semantic Reporting verticals, Committee workspace WebUI and aggregate-only ballot adapter boundary, case object sharing, and exact replay-safe Portal launches into Cases and Workflow Engine.
  • The canonical architecture and module docs are updated and mirrored to Gitea wikis.

Verification

  • 61/61 source manifests pass the enforced architecture gate; institutional golden journeys pass; Core institutional/module tests pass; all 37 prior WebUI permutations plus isolated Committee/Projects/Reporting and default builds pass; module bundle budgets pass.

Next / Blocked

  • Forms Runtime #1 is the only missing executable owner vertical in this architecture path: GovOPlaN/govoplan-forms-runtime#1
  • Committee #1 tracks selection and assurance of a concrete ballot provider: GovOPlaN/govoplan-committee#1
  • Reference-ready claims still require signed evidence from real target accessibility, privacy, security, operations, provider, backup/restore and recovery runs.
## Codex State: done ### Summary - The architecture depth pass now includes persistent Projects and governed semantic Reporting verticals, Committee workspace WebUI and aggregate-only ballot adapter boundary, case object sharing, and exact replay-safe Portal launches into Cases and Workflow Engine. - The canonical architecture and module docs are updated and mirrored to Gitea wikis. ### Verification - `61/61 source manifests pass the enforced architecture gate; institutional golden journeys pass; Core institutional/module tests pass; all 37 prior WebUI permutations plus isolated Committee/Projects/Reporting and default builds pass; module bundle budgets pass.` ### Next / Blocked - Forms Runtime #1 is the only missing executable owner vertical in this architecture path: https://git.add-ideas.de/GovOPlaN/govoplan-forms-runtime/issues/1 - Committee #1 tracks selection and assurance of a concrete ballot provider: https://git.add-ideas.de/GovOPlaN/govoplan-committee/issues/1 - Reference-ready claims still require signed evidence from real target accessibility, privacy, security, operations, provider, backup/restore and recovery runs.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan#29