feat: govern bounded project bootstrap autonomy

Merge PR #2; Board approval evidence Discord 1542278257833939087.
This commit was merged in pull request #2.
This commit is contained in:
2026-08-26 14:10:44 -07:00
+14 -3
View File
@@ -1,7 +1,7 @@
--- ---
name: corp-v1-channel-general name: corp-v1-channel-general
description: "Use when operating or synchronizing a Corp v1 project's general channel. Correlates verified activity across the project's general, scope, architecture, kanban, delivery, and releases channels; reports overall status, surfaces issues, and maintains project-level guidance." description: "Use when operating or synchronizing a Corp v1 project's general channel. Correlates verified activity across the project's general, scope, architecture, kanban, delivery, and releases channels; reports overall status, surfaces issues, and maintains project-level guidance."
version: 1.6.1 version: 1.7.0
author: Hermes Agent author: Hermes Agent
license: MIT license: MIT
metadata: metadata:
@@ -27,13 +27,21 @@ Load the global `corp-v1--glossary` skill from `https://gitea.lego-cloud.eu/home
Use this skill when: Use this skill when:
- operating in `corp-v1-<code>-general`; - operating in `corp-v1-<code>-general`;
- running the recurring synchronization job mapped to that channel; - running an explicitly Board-approved recurring bootstrap job mapped to that channel;
- preparing an overall project update; - preparing an overall project update;
- detecting cross-channel issues, ownership gaps, or conflicting direction; - detecting cross-channel issues, ownership gaps, or conflicting direction;
- proposing, refining, or documenting Epics, Features, and project improvements; - proposing, refining, or documenting Epics, Features, and project improvements;
- maintaining general-channel project guidance from verified team decisions. - maintaining general-channel project guidance from verified team decisions.
Do not use it to approve architecture decisions, merge or release code, deploy, or override the authority of another mapped channel. Do not use it to approve architecture decisions, merge or release code, deploy, or override the authority of another mapped channel unless a preserved project-local authorization override explicitly delegates those exact actions during a bounded bootstrap phase.
## Governed bootstrap autonomy
The Corp v1 default is no project scheduler. One 30-minute General-channel bootstrap job is permitted only when the project's approved kickoff decision and adopted General skill contain the same preserved project-local authorization override.
The override must identify the Board evidence, project, delegator, delegate, exact seven channels, autonomous actions, safety exclusions, and a **first-human-message stop condition**. Before every mutation, the job must scan all seven project channels after its frozen high-watermarks and distinguish human authors from bots, webhooks, and Hermes. If any human-authored project-channel message exists after bootstrap began, the job must make no further autonomous mutation, cite the message and channel, post one stop report in General, and pause or remove itself.
During an active approved bootstrap phase, the job may load the mapped project channel and engineering skills and advance approved MVP artifacts across Scope, Architecture, UI/UX, Kanban, Delivery, and Releases. It must preserve canonical ownership, exact-head validation, remote readback, and review evidence. It may not expose or change secret values, spend money, purchase goods, enable production payments, alter vendor accounts, make legal/commercial commitments, perform unrelated infrastructure work, or execute destructive/irreversible actions.
## Approved Information Boundary ## Approved Information Boundary
@@ -225,6 +233,8 @@ Must request approval before:
- changing permissions, secrets, costs, or external systems; - changing permissions, secrets, costs, or external systems;
- deleting resources or performing irreversible/high-impact work. - deleting resources or performing irreversible/high-impact work.
An exact project-local bootstrap override may delegate specified approval items above until its stop condition. Generic autonomy never does. The override cannot waive credential safety, spending, legal/commercial, destructive-operation, production-payment, or external-account gates.
## Evidence Requirements ## Evidence Requirements
For completed work include exact evidence such as Discord message IDs, repository URLs, branch names, commit SHAs, documentation paths, CI run IDs, or check output. Mark uncertain conclusions as proposals. For completed work include exact evidence such as Discord message IDs, repository URLs, branch names, commit SHAs, documentation paths, CI run IDs, or check output. Mark uncertain conclusions as proposals.
@@ -260,3 +270,4 @@ For completed work include exact evidence such as Discord message IDs, repositor
- [ ] Guidance changes derive from verified team decisions. - [ ] Guidance changes derive from verified team decisions.
- [ ] Completed activities include exact evidence. - [ ] Completed activities include exact evidence.
- [ ] Approval-required actions remain proposals. - [ ] Approval-required actions remain proposals.
- [ ] When a bootstrap job is active, its override, seven-channel boundary, frozen high-watermarks, human-message check, General delivery target, and scheduler state are verified.