Packages

development-driven-specs — the dds toolchain (protocol 2) as a Mix task. A thin shim over the bundled instruments (Python, stdlib); never a port.

Current section

Files

Jump to
dds priv toolchain canon proposing.md
Raw

priv/toolchain/canon/proposing.md

# The proposing procedure
The judgment passes over the witnessed state — performed BY THE AGENT.
Every rule below was learned live and holds whatever the sample says:
**a directive the judgment ignores twice becomes a procedural rule
here; noise from missing evidence is fixed by citing more evidence,
never by more instructions.**
## Pass 1 — cells (subject × category per store; boundary per flow)
Propose, per store: SUBJECT (whose data) and CATEGORY, using only the
org vocabularies; infrastructure/reference data → internal ×
operational. Per flow party: external vs internal.
- Weigh witnessed signals: free-text columns linking (transitively) to
a person-record = that person's CONTENT whatever the name; org-unit
links + counts = aggregate usage; lookup tables with no links =
operational. Function/db/pubsub-only parties = internal.
- Auth records belong to the people who log in; traces/histories are
OF those people, never internal.
- WITHHOLD (a sticky visible question, never a repaired answer):
internal×operational with free-text + links (contradiction); an
"internal" whose links reach a person-subject store; any
person-implying category paired with internal (coherence).
- Stickiness: an unchanged fingerprint is never re-judged.
## Pass 2 — columns (per in-scope store: dispositions + datum drafts)
Map EVERY witnessed column: datum-holding (name WHICH fact — reuse
existing keys; a copy is a holding, never a new datum) · operational ·
question. Facets per the claim-file vocabulary. Then apply the floors
and coercions — procedure, not preference:
- **PK floor**: the store's own surrogate `id` is operational — the
subject's identifier lives on FKs pointing AT the anchor.
- **Norm columns**: accessibility flags = datum (special disability);
token/otp/reset columns = the person's credential — even when the
judgment omitted them.
- **Lifecycle enums** (uploading/failed/pending…, or single-valued) =
operational; person-state value spaces never match this floor.
- **Run-config** (prompt, run_no, temperature…; `model` only in their
company) = the call's data, operational.
- **Record-bookkeeping flags** (is_dummy, has_errors, sync keys) =
operational; person flags (accessibility, preferences) stay datums.
- **FK resolution** (discovery-driven): target is the subject's
identity anchor → account-identifier holding; another person-record
→ record linkage (operational); non-person org unit → org-unit
membership when judged affiliation/identity; internal catalog →
operational; vocabulary-FK encoding health → keep as coded value.
`_by`-suffix / assessor/reviewer stems → the ONE authorship record.
- **Event timestamps** (non-identity dates) fold to ONE per-store
event-timeline datum `<subject>.<store-singular>-record` — never
doubling `-record` on stores already named `*_records`.
- **Statuses/enums about the person are never `direct`**; a datum held
only by booleans or settings columns caps at linked_only; `mixed`
only for opaque containers.
- **Provenance floors**: pipeline-written columns ≥ derived; written
from a file adjacent to an external call with a local source =
inferred. `source_party` exists ONLY on provided.
- **Name-equality rekey**: a draft whose (subject, normalized name)
equals an existing datum's IS that datum — mappings rekey to the
existing key; no variant is ever minted.
- Drafts that earn no holding are never emitted; a datum-mapping whose
key resolves nowhere is dropped (the column stays open work).
## Pass 2.5 — activities (the RoPA skeleton)
Cluster workers/triggers/events/ops/flows into the FEW activities
(4–12) a RoPA reasons in. Per activity: verb-first stable_id naming
the ACTUAL counterpart systems (never a generic stand-in), name, ONE
plain purpose sentence, function, automation, and 5–10 verbatim
evidence names. Never one activity per table/screen; an export/sync to
a named third party is its own activity. **Never draft lawful basis or
necessity.** Uncited activities are discarded; over-enumeration keeps
the best-evidenced ≤16; check the declared set first and cover only
what it misses.
## Pass 3 — bindings (datums × activities · datums × boundaries)
Bind SPARINGLY on what operations demonstrably do. Guards, in order:
- only witnessed parties bind: endpoint-witnessed AND substantive
(a flow whose only op is a rendered URL is a link, not a channel);
- direction coheres with the party: org-access = out-only (staff READ
in-app); source-role = in-only;
- **credentials never cross OUT** (checked on the coerced direction —
a password hash never rides an email or a disclosure; the real
magic-link case is a human-added crossing); credential datums bind
to activities only when the activity's evidence is auth-shaped;
- blanket drops: an activity bound to > max(3, half the datums) binds
nothing; a datum crossing >6 non-org boundaries crossed nothing
(absurdity-only — a scaling threshold both admits small blankets and
drops a blanket datum's one REAL crossing);
- existing confirmed bindings are never re-proposed; org-access
parties never re-propose (code-declared);
- basis per pair: inferred datums get their own `basis.TODO`;
otherwise the activity's declared basis; special-category pairs
need a condition (TODO).
## Rendering the register
Chips per the claim-file cube; every join sourced from THIS run marks
`°` (drafted, unratified) with a legend; ratified holdings from the
`Held by` ledgers render unmarked. GUARANTEES section: gating n/m person stores
(cell-internal stores excluded), erasure gaps, surface by pipeline
with the auth-absence witness, audit dormancy — honest truncation
throughout.