docs: record project categories and shared SSO policy
Build and publish Corp v1 Board portal / build (push) Successful in 37s

Board-approved governance records for dedicated project categories and secret-safe shared SSO login.
This commit was merged in pull request #17.
This commit is contained in:
2026-08-27 13:54:17 -07:00
12 changed files with 156 additions and 9 deletions
+2
View File
@@ -8,6 +8,8 @@ sidebar_position: 2
| Date | Decision | Scope | Owner | Record |
|---|---|---|---|---|
| 2026-08-27 | Authorize secret-safe use of the Bitwarden-injected shared Corp v1 SSO identity for approved system tasks | Corp v1 governance and all project channels | RootAtSkic | [Shared Corp v1 system SSO credentials](/governance/decisions/shared-system-sso-credentials/) |
| 2026-08-27 | Separate each project's lifecycle channels into one dedicated Discord category | Corp v1 governance, AeroSim, Maze Next Gen, E-Shop v1 | RootAtSkic | [Dedicated Discord category per project](/governance/decisions/project-discord-category-separation/) |
| 2026-08-27 | Establish the Corp v1 Guild improvement workspace, skill, Gitea source, and portal architecture representation | Corp v1 governance and operating-model improvement | RootAtSkic | [Corp v1 Guild establishment](/governance/decisions/corp-v1-guild-establishment/) |
| 2026-08-26 | Authorize E-Shop v1 kickoff, toothbrush-commerce MVP, and bounded bootstrap autonomy | E-Shop v1 | RootAtSkic | [E-Shop v1 kickoff and bootstrap autonomy](/governance/decisions/eshopv1-kickoff-bootstrap-autonomy/) |
| 2026-08-25 | Add Piotras to the Corp v1 Board and every active project | Corp v1 governance, AeroSim, Maze Next Gen | RootAtSkic | [Piotras Board and all-project membership](/governance/decisions/piotras-board-all-project-membership/) |
@@ -0,0 +1,47 @@
---
title: Dedicated Discord category per project
---
# Dedicated Discord category per project — 2026-08-27
## Context
All Corp v1 lifecycle channels previously shared the guild-level `corp-v1` category. As the pilot expanded across AeroSim, Maze Next Gen, and E-Shop v1, that flat topology made each project's working boundary harder to scan and increased the risk of mixing project-local channels with Board governance.
## Decision
RootAtSkic (`discord:1518725627845283888`) approved one dedicated top-level Discord category per Corp v1 project in Board message `1542625777495965836`.
- Reserve `corp-v1` (`1537070242335821924`) for Board and shared governance channels.
- Name each project category `corp-v1-<code>`.
- Keep exactly seven lifecycle channels inside each project category in this order: General, Scope, Architecture, UI/UX, Kanban, Delivery, Releases.
- Preserve existing channel IDs, history, topics, pins, webhooks, permission overwrites, and delivery targets during migration.
- Apply the same topology to future kickoffs and delete only an empty project category during an approved sunset.
## Implementation
The central [`corp-v1--main`](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1--main) skill was updated to version `4.3.0` and merged through PR [8](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1--main/pulls/8) at `785e57d6381f60a0caacefdedec791aa3b1fe2fd`.
Three categories were created with the existing approved permission-overwrite model:
| Project | Category | Discord ID |
|---|---|---|
| AeroSim | `corp-v1-aerosim` | `1542627633123299359` |
| Maze Next Gen | `corp-v1-mazeng` | `1542627645441839174` |
| E-Shop v1 | `corp-v1-eshopv1` | `1542627655189270719` |
The 21 existing lifecycle channels were moved by immutable channel ID. No project channel was recreated.
## Verification
A fresh full-guild readback confirmed:
- every project category exists as a category and retains nine permission overwrites;
- all seven exact channels for each project have the expected `parent_id` and lifecycle order;
- all 21 channel IDs are unchanged and each channel retains nine permission overwrites;
- the guild-level `corp-v1` category now contains only `corp-v1-board` and `corp-v1-guild`;
- Hermes can still read recent history in every moved lifecycle channel.
## Consequences
Project navigation and the governance boundary are now explicit without losing history or changing channel-targeted integrations. Project records must include the dedicated category ID, and future provisioning must reject lifecycle channels placed directly under the governance category.
@@ -0,0 +1,40 @@
---
title: Shared Corp v1 system SSO credentials
---
# Shared Corp v1 system SSO credentials — 2026-08-27
## Context
Hermes sometimes needs to authenticate to Corp v1 systems being built or operated in order to perform an explicitly authorized task. Asking project members to retransmit credentials through Discord or storing them in project artifacts would create avoidable exposure.
## Decision
RootAtSkic (`discord:1518725627845283888`) approved use of the shared Bitwarden-injected Corp v1 SSO identity in Board message `1542636538305712199`.
Skills and records may contain only these runtime secret names:
- `HL_V1_SSO_EMAIL`
- `HL_V1_SSO_PASSWORD`
Credential values, Bitwarden object identifiers, and account metadata must not be copied into Discord, skills, repositories, prompts, command lines, URLs, files, screenshots, logs, CI output, or reports.
## Operating rules
- SSO secret availability is a capability, not authorization. Every login must serve an explicitly authorized project task and verified destination origin.
- Hermes checks only whether both runtime variables are present and uses them through a trusted login form or provider-supported secure runtime interface.
- Missing injection is reported by secret name only; no local fallback secret is created and no human is asked to paste a value into chat.
- Login does not authorize account recovery, MFA or credential changes, permission changes, billing, spending, destructive operations, or unrelated system/data access.
- Reports contain only the target system, authorized purpose, login result, and non-sensitive verification evidence.
## Implementation and verification
The central `corp-v1--main` skill was updated to version `4.4.0` and merged through PR [9](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1--main/pulls/9) at `b11b0e521dab6b7a920337feed37c5a849d507bd`.
The same secret-safe login section was published central-first to all seven `corp-v1-channel-*` reference skills, then semantically adopted into all 21 project channel skills across AeroSim, Maze Next Gen, and E-Shop v1. Every project-local authorization override was hash-checked before and after adoption, project bindings and supporting files were preserved, and every pushed default ref and `SKILL.md` marker was read back. All 21 installed Hermes runtime packages were refreshed from the resulting project repositories. The exact repository, branch, commit, and override coverage is recorded in the [shared SSO skill rollout ledger](/governance/sso-skill-rollout/).
Runtime preflight confirmed both secret names are currently injected. No credential value was read into a report, persisted, or committed.
## Consequences
Every Corp v1 channel now follows one login path and one non-disclosure policy. Authentication can support authorized delivery work without turning credential availability into broader system authority.
+8
View File
@@ -23,6 +23,14 @@ Obtain explicit Board approval. Record the approving Board member, decision evid
Maintain current status, decisions, risks, milestones, and material scope changes. Project teams retain authority within their approved project boundaries; Board approval is still required for kickoff/closure and changes to `corp-v1--main`.
### Discord topology
The guild-level `corp-v1` category is reserved for Board and shared governance channels. Every project uses one dedicated top-level category named `corp-v1-<code>` containing exactly seven lifecycle channels in this order: General, Scope, Architecture, UI/UX, Kanban, Delivery, Releases. Existing channels are moved by immutable ID so history, pins, permission overwrites, webhooks, and delivery targets remain intact.
### System login
For an explicitly authorized Corp v1 system task, Hermes may use the Bitwarden-injected runtime secrets named `HL_V1_SSO_EMAIL` and `HL_V1_SSO_PASSWORD`. Secret availability does not authorize unrelated access or account administration. Values and Bitwarden object metadata must never be printed, persisted, committed, posted, logged, placed in command lines or URLs, or requested through chat. Missing injection is reported by secret name only.
### Project-channel skill changes
A proposed change to a central project-channel reference skill (`corp-v1-channel-*`) must be presented to the Board before publication. After explicit Board approval and central publication, ask every affected project channel to review and synchronize its project-adopted channel skill (`corp-v1-channel-*--<code>`). Synchronization must preserve project-specific decisions, report conflicts for Board review, update runtime copies, and verify attached channel jobs.
+48
View File
@@ -0,0 +1,48 @@
---
title: Shared SSO skill rollout
---
# Shared SSO skill rollout — 2026-08-27
This ledger records the Board-approved secret-name-only login guidance published under Discord message `1542636538305712199`. All repositories were updated central-first, pushed to their actual default branches, and read back at the exact resulting commit. Project-local authorization override blocks were hash-compared before and after each adoption.
| Scope | Skill repository | Branch | Published commit | Preserved override blocks |
|---|---|---|---|---:|
| Central reference | [corp-v1-channel-general](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-general) | `test` | `a5e79c24dd4ec1fa0d1a3258ecc184d9808daa62` | 0 |
| Central reference | [corp-v1-channel-scope](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-scope) | `test` | `4554b78e20377863af55be3dca78cf22f1e98b75` | 0 |
| Central reference | [corp-v1-channel-architecture](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-architecture) | `test` | `c7620c804a0de210f35fc829a38a53e44d40bfd8` | 0 |
| Central reference | [corp-v1-channel-ui-ux](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-ui-ux) | `test` | `132406f061ee1f363ca575a1c3ae7488e4bfe948` | 0 |
| Central reference | [corp-v1-channel-kanban](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-kanban) | `test` | `87a50a926a7256201ce1771aad7764898f24ff60` | 0 |
| Central reference | [corp-v1-channel-delivery](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-delivery) | `test` | `20cb78ce0942b35fe6528399c22764fbfb4cf06a` | 0 |
| Central reference | [corp-v1-channel-releases](https://gitea.lego-cloud.eu/home-v1-skills-code-agent/corp-v1-channel-releases) | `test` | `94d147880f6c957967d6612cbd846f9a2f2f6c00` | 0 |
| aerosim | [corp-v1-channel-general--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-general--aerosim) | `test` | `e50dc8878ebe74b6c58601204508e4723bb7803d` | 0 |
| aerosim | [corp-v1-channel-scope--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-scope--aerosim) | `test` | `0b6cee38a12803b4a7ceefe824e6a510ea35fec3` | 1 |
| aerosim | [corp-v1-channel-architecture--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-architecture--aerosim) | `test` | `c2c379ea6875d1b2c91cd6d02da588b8cf06bcb6` | 1 |
| aerosim | [corp-v1-channel-ui-ux--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-ui-ux--aerosim) | `test` | `a985d0e4841b60290cbae888cbef6b142ada175f` | 1 |
| aerosim | [corp-v1-channel-kanban--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-kanban--aerosim) | `test` | `e75f81d559996e9cab97092bf94db33a324830d1` | 0 |
| aerosim | [corp-v1-channel-delivery--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-delivery--aerosim) | `test` | `af697f5d1ef708c66db3ab62fd1fa9094b7735a2` | 0 |
| aerosim | [corp-v1-channel-releases--aerosim](https://gitea.lego-cloud.eu/corp-v1-aerosim-skills-code-agent/corp-v1-channel-releases--aerosim) | `test` | `e85df7e82daa004bf0dc5a8db9ea09a99507583b` | 0 |
| mazeng | [corp-v1-channel-general--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-general--mazeng) | `test` | `12579704b8afad3af41b55b540ad21132e2ac299` | 1 |
| mazeng | [corp-v1-channel-scope--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-scope--mazeng) | `test` | `51ee9f4722a6ba5f9bbd13384ae8674690e070f9` | 1 |
| mazeng | [corp-v1-channel-architecture--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-architecture--mazeng) | `test` | `4c80704a0bd065accba49d523f6a83f51f8c1d2c` | 1 |
| mazeng | [corp-v1-channel-ui-ux--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-ui-ux--mazeng) | `test` | `de7807acb68e3732982cc65087126d119d7dc52b` | 2 |
| mazeng | [corp-v1-channel-kanban--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-kanban--mazeng) | `test` | `a1dcadca90ccf18da54d415c87b47b77773730b9` | 1 |
| mazeng | [corp-v1-channel-delivery--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-delivery--mazeng) | `test` | `190de977a647446510375aff1bf3192beb41f444` | 1 |
| mazeng | [corp-v1-channel-releases--mazeng](https://gitea.lego-cloud.eu/corp-v1-mazeng-skills-code-agent/corp-v1-channel-releases--mazeng) | `test` | `eddc0f9d788c28134775a70e02606a0ded326933` | 1 |
| eshopv1 | [corp-v1-channel-general--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-general--eshopv1) | `test` | `e2d6b628dbdd409cb3901384419ae69db8de256b` | 1 |
| eshopv1 | [corp-v1-channel-scope--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-scope--eshopv1) | `test` | `0b185c233a10d004a47f80b5d408cab582bbe058` | 1 |
| eshopv1 | [corp-v1-channel-architecture--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-architecture--eshopv1) | `test` | `9fcab760c09263b4432bf8a4a8028a22e4ca5532` | 1 |
| eshopv1 | [corp-v1-channel-ui-ux--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-ui-ux--eshopv1) | `test` | `1ed8d4f5b92c4ebb9501cd0d92f213aa40444eb6` | 1 |
| eshopv1 | [corp-v1-channel-kanban--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-kanban--eshopv1) | `test` | `4c96798bfe678c97c8f820000a424fbd50a74e53` | 1 |
| eshopv1 | [corp-v1-channel-delivery--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-delivery--eshopv1) | `test` | `5562b81fb3e8ad6fbc0d02039d58deaf64adbf53` | 1 |
| eshopv1 | [corp-v1-channel-releases--eshopv1](https://gitea.lego-cloud.eu/corp-v1-eshopv1-skills-code-agent/corp-v1-channel-releases--eshopv1) | `test` | `77dbd2841337bd24b642b08329bcc338d2cb44f6` | 1 |
## Coverage
- Seven central `corp-v1-channel-*` reference skills.
- Seven AeroSim channel-skill adoptions.
- Seven Maze Next Gen channel-skill adoptions.
- Seven E-Shop v1 channel-skill adoptions.
- Twenty-one installed Hermes runtime packages refreshed from the resulting project repositories.
Only the names `HL_V1_SSO_EMAIL` and `HL_V1_SSO_PASSWORD` are recorded. No value or Bitwarden object identifier is stored in this ledger.
+1 -1
View File
@@ -21,4 +21,4 @@ This repository is the authoritative governance workspace for starting, governin
## Operating principle
Every project has a named sponsor, accountable lead, team, explicit status, Board-approved kickoff decision, and—when closed—a Board-approved closure record with retained artifacts and lessons learned.
Every project has a named sponsor, accountable lead, team, explicit status, Board-approved kickoff decision, and—when closed—a Board-approved closure record with retained artifacts and lessons learned. Board and shared governance channels remain in `corp-v1`; each project's seven lifecycle channels live in one dedicated `corp-v1-<code>` category.
+3 -2
View File
@@ -54,16 +54,17 @@ A playable MVP covering a light trainer, commercial airliner, and fighter-style
## Discord
Exactly six same-project channels exist under category `corp-v1` (`1537070242335821924`):
Exactly seven same-project channels exist in dedicated category `corp-v1-aerosim` (`1542627633123299359`), in lifecycle order:
- `corp-v1-aerosim-general` — `1537227679374508132`
- `corp-v1-aerosim-scope` — `1537544173366943886`
- `corp-v1-aerosim-architecture` — `1537227680590733383`
- `corp-v1-aerosim-ui-ux` — `1541722108072169562`
- `corp-v1-aerosim-kanban` — `1537548579856580739`
- `corp-v1-aerosim-delivery` — `1537227683191197807`
- `corp-v1-aerosim-releases` — `1537388451501056081`
Hermes bot `1526860732917088266` successfully read and posted project guidance. The general introduction is pinned as message `1537227685657444484`; Scope purpose guidance is message `1537544176621715506`; Kanban purpose guidance is message `1537548582003933326`; Releases purpose guidance is message `1537388452658815077`. Effective access is verified for RootAtSkic (`1518725627845283888`), Panther Skeleton (`476287310627864587`), MartynasP (`773109855497093191`), and Eduard (`364383883778850827`) across all six project channels.
Hermes bot `1526860732917088266` successfully read and posted project guidance. The general introduction is pinned as message `1537227685657444484`; Scope purpose guidance is message `1537544176621715506`; Kanban purpose guidance is message `1537548582003933326`; Releases purpose guidance is message `1537388452658815077`. Effective read access was reverified across all seven project channels after the category migration; channel IDs and permission overwrites are unchanged.
Six staggered recurring synchronization jobs are active. Every job runs each hour, monitors only the other five AeroSim channels, loads its mapped adopted channel skill, proactively performs useful safe work within that channel's purpose, and records durable work in project documentation:
+1 -1
View File
@@ -35,7 +35,7 @@ RootAtSkic (`discord:1518725627845283888`) approved kickoff and override `ESHOPV
## Discord lifecycle
Exactly seven ordered channels exist under `corp-v1`; Hermes view/history/send/pin behavior was verified in each:
Exactly seven ordered channels exist in dedicated category `corp-v1-eshopv1` (`1542627655189270719`); Hermes read access was reverified after migration, and channel IDs and permission overwrites are unchanged:
1. `corp-v1-eshopv1-general` — `1542281868269985912`
2. `corp-v1-eshopv1-scope` — `1542281871642198207`
+3 -2
View File
@@ -37,16 +37,17 @@ RootAtSkic (`discord:1518725627845283888`) explicitly approved the updated six-c
## Discord
Exactly six channels exist under category `corp-v1` (`1537070242335821924`):
Exactly seven channels exist in dedicated category `corp-v1-mazeng` (`1542627645441839174`), in lifecycle order:
- `corp-v1-mazeng-general` — `1539019955738116096`; purpose `1539019957923483728`; pinned skills `1539021508326981683`
- `corp-v1-mazeng-scope` — `1539019959135633580`; purpose `1539019961329000479`; pinned skills `1539021514379370546`
- `corp-v1-mazeng-architecture` — `1539019963568758835`; purpose `1539019966857355416`; pinned skills `1539021520230162540`
- `corp-v1-mazeng-ui-ux` — `1541722112841089074`
- `corp-v1-mazeng-kanban` — `1539019969323466883`; purpose `1539019971655372911`; pinned skills `1539021525657849896`
- `corp-v1-mazeng-delivery` — `1539019973043683358`; purpose `1539019975203885068`; pinned skills `1539021530317463572`
- `corp-v1-mazeng-releases` — `1539019976977948694`; purpose `1539019979590991963`; pinned skills `1539021536621756458`
General introduction `1539019982682325132` and all six skill-guidance messages are pinned. Hermes read/post/pin operations succeeded in all channels. Harbor request message: `1539020766203617390`.
General introduction `1539019982682325132` and the recorded skill-guidance messages are pinned. Hermes read access was reverified across all seven channels after the category migration; channel IDs and permission overwrites are unchanged. Harbor request message: `1539020766203617390`.
## Synchronization jobs
+1 -1
View File
@@ -33,4 +33,4 @@ Deliver the AeroSim browser flight-simulation platform, its documentation, and t
## Communication
Exactly six AeroSim channels exist under the `corp-v1` category: `general`, `scope`, `architecture`, `kanban`, `delivery`, and `releases`. RootAtSkic, Panther Skeleton, MartynasP, Eduard, and Hermes have verified effective access. Guidance messages, the pinned general introduction, and six isolated same-project hourly synchronization jobs are verified.
Exactly seven AeroSim channels exist in dedicated category `corp-v1-aerosim` (`1542627633123299359`): `general`, `scope`, `architecture`, `ui-ux`, `kanban`, `delivery`, and `releases`. Channel IDs, permission overwrites, and history were preserved during migration; Hermes read access and lifecycle order were reverified. Existing purpose guidance, the pinned general introduction, and project automation records remain attached to the unchanged channel IDs.
+1 -1
View File
@@ -22,7 +22,7 @@ Deliver the governed E-Shop v1 toothbrush-commerce MVP, its source-evidence cata
## Communication and autonomy
Seven exact E-Shop v1 lifecycle channels and their pinned purpose/skill guidance are verified. One project-specific 30-minute General job is authorized under `ESHOPV1-BOOTSTRAP-AUTONOMY-20260826`; its authority ends at the first human-authored project-channel message.
Seven exact E-Shop v1 lifecycle channels exist in dedicated category `corp-v1-eshopv1` (`1542627655189270719`), with immutable channel IDs and permission overwrites preserved. Hermes read access and order were reverified after migration. One project-specific 30-minute General job is authorized under `ESHOPV1-BOOTSTRAP-AUTONOMY-20260826`; its authority ends at the first human-authored project-channel message.
## Remaining gates
+1 -1
View File
@@ -22,7 +22,7 @@ Deliver the Maze Next Gen multi-cloud inventory and visualization platform, docu
## Communication
Six exact Maze channels, purpose messages, pinned guidance, and six isolated staggered hourly synchronization jobs are verified.
Seven exact Maze channels exist in dedicated category `corp-v1-mazeng` (`1542627645441839174`) in lifecycle order. Channel IDs, permission overwrites, history, purpose messages, and pinned guidance remain attached to the moved channels; Hermes read access was reverified after migration.
## Remaining gate