Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
101 commits
Select commit Hold shift + click to select a range
238d552
Align organization front door with presentation Reviewer Guide
raylee-hawkins Aug 6, 2026
3b6df21
Complete organization reviewer routing
raylee-hawkins Aug 10, 2026
d379b54
Harden organization reviewer verification
raylee-hawkins Aug 10, 2026
7c3097b
Bind authority roles across organization routes
raylee-hawkins Aug 10, 2026
6e9d874
Enforce organization authority boundaries
raylee-hawkins Aug 10, 2026
72430ad
Parse complete authority tables
raylee-hawkins Aug 10, 2026
87f75bc
Close organization verifier review gaps
raylee-hawkins Aug 10, 2026
700f486
Restore Hoxline authority contract role
raylee-hawkins Aug 10, 2026
c64b0a6
Bind organization door table routes
raylee-hawkins Aug 10, 2026
b1db9e6
Reject alternate Markdown authority rows
raylee-hawkins Aug 10, 2026
fceb6d4
Synchronize seven-repository governance routes
raylee-hawkins Aug 10, 2026
b03c6a2
Validate Hoxline governance gates
raylee-hawkins Aug 10, 2026
f6366aa
Bind required checks to repository owners
raylee-hawkins Aug 10, 2026
83ce7a6
Parse governance contracts structurally
raylee-hawkins Aug 10, 2026
aa1519d
Document invariant verifier dependency
raylee-hawkins Aug 10, 2026
c87de0f
Preserve Hoxline evidence handoff order
raylee-hawkins Aug 10, 2026
affab68
Fail closed on authority contract ambiguity
raylee-hawkins Aug 10, 2026
fd6813c
Bind organization reviewer contexts
raylee-hawkins Aug 10, 2026
3fe5f70
Bind Hoxline checks to current main
raylee-hawkins Aug 10, 2026
e33adcf
Require human review across promotion layers
raylee-hawkins Aug 10, 2026
ba26156
Complete required-check context bindings
raylee-hawkins Aug 10, 2026
52d0473
Fingerprint the complete promotion contract
raylee-hawkins Aug 10, 2026
645fc51
Reconcile invariant enforcement phase
raylee-hawkins Aug 10, 2026
99c915a
Align required-checks phase state
raylee-hawkins Aug 10, 2026
6760c57
Enforce governed reviewer handoffs
raylee-hawkins Aug 10, 2026
6e6179a
Parse decorated Mermaid bypass edges
raylee-hawkins Aug 10, 2026
8d95b1d
Parse Mermaid endpoint edge forms
raylee-hawkins Aug 10, 2026
b8d52d7
Bind canonical checks and Mermaid fan-out
raylee-hawkins Aug 10, 2026
b5fffdb
Reject direct Hoxline website bypasses
raylee-hawkins Aug 10, 2026
a6c46cb
Preserve required check classifications
raylee-hawkins Aug 11, 2026
f79f3a1
Fingerprint the complete required checks contract
raylee-hawkins Aug 11, 2026
576d7b1
Pin invariant routes and normalize Mermaid edges
raylee-hawkins Aug 11, 2026
f0a4fd1
Parse Mermaid edge identifiers
raylee-hawkins Aug 11, 2026
3f57558
Parse quoted Mermaid edge labels
raylee-hawkins Aug 11, 2026
195ece7
Pin topology and reject duplicate JSON keys
raylee-hawkins Aug 11, 2026
bb936fc
Normalize Mermaid fence variants
raylee-hawkins Aug 11, 2026
70ee591
Fingerprint unclosed Mermaid fences
raylee-hawkins Aug 11, 2026
ad120de
Bind visible authority and order semantics
raylee-hawkins Aug 11, 2026
de61ef2
Parse reviewer-visible Markdown consistently
raylee-hawkins Aug 11, 2026
103eb00
Filter hidden aggregate governance text
raylee-hawkins Aug 11, 2026
3395ba6
Preserve visible Markdown code in boundary scans
raylee-hawkins Aug 11, 2026
ef140cf
Handle unmatched Markdown backticks
raylee-hawkins Aug 11, 2026
e06debc
Bound Markdown code spans to paragraphs
raylee-hawkins Aug 11, 2026
dd88139
Respect Markdown block boundaries
raylee-hawkins Aug 11, 2026
96321e0
Exclude Markdown code from authority parsing
raylee-hawkins Aug 11, 2026
010d63b
Exclude raw code blocks from authority parsing
raylee-hawkins Aug 11, 2026
5fa00cb
Cover nested raw code and list markers
raylee-hawkins Aug 11, 2026
fe09a61
Scan all raw code transitions
raylee-hawkins Aug 11, 2026
41006e4
Keep nonvoid raw code blocks open
raylee-hawkins Aug 11, 2026
6b41c82
Prioritize indented Markdown code
raylee-hawkins Aug 11, 2026
1c18296
Honor CommonMark tab-stop indentation
raylee-hawkins Aug 11, 2026
7c59a2c
Classify indented code before fences
raylee-hawkins Aug 11, 2026
05d3f7b
Enforce CommonMark fence indentation
raylee-hawkins Aug 11, 2026
b3c9ed4
Parse Mermaid fence lengths exactly
raylee-hawkins Aug 11, 2026
430b828
Harden container and HTML code parsing
raylee-hawkins Aug 11, 2026
2a979b6
Fail closed on hidden Markdown structure
raylee-hawkins Aug 11, 2026
94769a2
Separate raw-text element closing
raylee-hawkins Aug 11, 2026
a97f419
Remove hidden HTML from semantic scans
raylee-hawkins Aug 11, 2026
b28efd0
Resume after container-relative HTML blanks
raylee-hawkins Aug 11, 2026
102e828
Track semantic HTML container scope
raylee-hawkins Aug 11, 2026
80df3c8
Exclude custom HTML block wrappers
raylee-hawkins Aug 11, 2026
3adcbee
Account for nested Markdown container boundaries
raylee-hawkins Aug 11, 2026
d372ad1
Preserve hidden HTML container boundaries
raylee-hawkins Aug 11, 2026
5a23dac
Track delimited Markdown HTML blocks
raylee-hawkins Aug 11, 2026
1fc0f4f
Align semantic checks with rendered HTML
raylee-hawkins Aug 11, 2026
d6d1898
Track nested hidden HTML containers
raylee-hawkins Aug 11, 2026
1bf94f7
Prevent HTML from counterfeiting authority structure
raylee-hawkins Aug 11, 2026
4174bcb
Respect nested raw text in templates
raylee-hawkins Aug 11, 2026
282f848
Normalize reviewer-visible authority claims
raylee-hawkins Aug 11, 2026
a9fef1b
Normalize reference-link authority wording
raylee-hawkins Aug 11, 2026
4289e6f
Parse visible Markdown authority links
raylee-hawkins Aug 11, 2026
42b3067
Scan wrapped reviewer authority claims
raylee-hawkins Aug 11, 2026
caed229
Preserve Markdown authority claim boundaries
raylee-hawkins Aug 11, 2026
704242c
Respect rendered authority block boundaries
raylee-hawkins Aug 11, 2026
8258b53
Honor blockquote paragraph boundaries
raylee-hawkins Aug 11, 2026
87353e4
Decode rendered authority wording
raylee-hawkins Aug 11, 2026
0a65573
Normalize invisible authority separators
raylee-hawkins Aug 11, 2026
1044c57
Normalize rejected authority examples
raylee-hawkins Aug 11, 2026
9fee6ed
Harden rejected authority example parsing
raylee-hawkins Aug 11, 2026
6667bb0
Align rejected prefixes with rendered emphasis
raylee-hawkins Aug 11, 2026
c06805f
Fail closed on unmatched inline code
raylee-hawkins Aug 11, 2026
0461dc1
Separate inline code from authority prose
raylee-hawkins Aug 11, 2026
1830771
Scope inline code to visible claim units
raylee-hawkins Aug 11, 2026
bac66dd
Respect code and link parsing precedence
raylee-hawkins Aug 11, 2026
e2e5468
Validate hidden Markdown link targets
raylee-hawkins Aug 11, 2026
119911b
Close semantic authority edge cases
raylee-hawkins Aug 11, 2026
cda6ec2
Normalize visible authority phrasing
raylee-hawkins Aug 11, 2026
8523be2
Bind public claims to rendered boundaries
raylee-hawkins Aug 11, 2026
74da326
Harden authority workflow enforcement
raylee-hawkins Aug 11, 2026
84648e5
Bind authority claims to explicit qualifiers
raylee-hawkins Aug 11, 2026
9cd90e9
Reject unrelated blocked-claim qualifiers
raylee-hawkins Aug 11, 2026
183e727
Parse workflow triggers and bounded structures
raylee-hawkins Aug 11, 2026
0c5d1a5
Close rendered-claim authority bypasses
raylee-hawkins Aug 11, 2026
55423da
Normalize authority and structured-boundary grammar
raylee-hawkins Aug 11, 2026
6477209
Bind verifier coverage to rendered workflow scope
raylee-hawkins Aug 11, 2026
22115c8
Bind structured and delegated authority qualifiers
raylee-hawkins Aug 11, 2026
821f7fa
Enforce effective workflow and boundary scope
raylee-hawkins Aug 11, 2026
ae0811d
Count rendered authority headings and grants
raylee-hawkins Aug 11, 2026
4aa4326
Bind semantic checks to rendered boundaries
raylee-hawkins Aug 11, 2026
c680b94
Parse quoted headings and pull request grants
raylee-hawkins Aug 11, 2026
4d94cd1
Preserve explicit boundary-column semantics
raylee-hawkins Aug 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@ Cross-repo work aligns by detection ID, artifact ID, proof gate, evidence refere
- Current proof gate:
- Downstream repos affected:
- [ ] .github
- [ ] hoxline
- [ ] hawkinsoperations-detections
- [ ] hawkinsoperations-validation
- [ ] hawkinsoperations-platform
Expand Down
9 changes: 5 additions & 4 deletions .github/workflows/command-center-invariants.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,7 @@ on:
- "architecture/**"
- "governance/**"
- "wiki/**"
- ".github/pull_request_template.md"
- ".github/workflows/command-center-invariants.yml"
- ".github/**"
- "scripts/verify-command-center-invariants.py"
push:
branches:
Expand All @@ -20,8 +19,7 @@ on:
- "architecture/**"
- "governance/**"
- "wiki/**"
- ".github/pull_request_template.md"
- ".github/workflows/command-center-invariants.yml"
- ".github/**"
- "scripts/verify-command-center-invariants.py"

permissions:
Expand All @@ -34,5 +32,8 @@ jobs:
- name: Checkout
uses: actions/checkout@v4

- name: Install structural YAML verifier dependency
run: python -m pip install --disable-pip-version-check PyYAML==6.0.2
Comment thread
raylee-hawkins marked this conversation as resolved.

- name: Verify command-center invariants
run: python scripts/verify-command-center-invariants.py
23 changes: 14 additions & 9 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,27 +27,31 @@ Evidence and source flow stay separated:

| Time | Start | What to confirm |
|---:|---|---|
| 30 sec | [profile/START_HERE.md](profile/START_HERE.md) | What HawkinsOperations is, which repo owns truth, and what remains blocked. |
| 3 min | [profile/README.md](profile/README.md) -> [Control Status Matrix](governance/CONTROL_STATUS_MATRIX.md) | Command-center route, proof ceiling, and standing controls. |
| 10 min | [Reproducible Reviewer Path](architecture/REPRODUCIBLE_REVIEWER_PATH.md) | Clone-runnable source, validation, proof, and rendering review without private runtime access. |
| 30 sec | [Website Reviewer Guide](https://hawkinsoperations.com/) | What HawkinsOperations is and how the complete system works. |
| 3 min | [profile/START_HERE.md](profile/START_HERE.md) | Website, Hoxline, source, validation, proof, and authority boundaries. |
| 10 min | [Focused reviewer path](profile/START_HERE.md#10-minute-reviewer-path) | Run Hoxline's local fixture-based demo, then inspect the HO-DET-001 source, validation, and proof handoffs. |
| Extended | [Reproducible Reviewer Path](architecture/REPRODUCIBLE_REVIEWER_PATH.md) | Full seven-repository source, validation, proof, control, and rendering review without private runtime access. |

## README / Repo Makeover Order
## Seven-Repository Authority

This is the README/governance cleanup order, not evidence-generation order.
Each repository owns one bounded role. The order below is an authority map, not an evidence-strength ranking.

| Order | Repo | Truth surface | Boundary |
|---:|---|---|---|
| 1 | `.github` | Route / governance truth | Routes reviewers and explains authority boundaries; does not prove claims. |
| 2 | `hawkinsoperations-proof` | Claim / proof truth | Owns proof records, proof ceilings, evidence-boundary records, and blocked-claim status. |
| 3 | `hawkinsoperations-platform` | Contract / guardrail truth | Owns schemas, contracts, ledger guardrails, runtime-route guardrails, and non-promotional platform controls. |
| 2 | `hoxline` | Product / ProofOps control | Governs the review path and Claim Authority experience; does not own proof records or final approval. |
| 3 | `hawkinsoperations-detections` | Source truth | Owns detection source, metadata, source reviewability, and source-level eligibility routing. |
| 4 | `hawkinsoperations-validation` | Behavior truth | Owns controlled validation checks, case packets, replay scope, and recorded validation outputs. |
| 5 | `hawkinsoperations-detections` | Source truth | Owns detection source, metadata, source reviewability, and source-level eligibility routing. |
| 6 | `hawkinsoperations-website` | Render truth | Renders public reviewer navigation and bounded wording; rendering is not proof. |
| 5 | `hawkinsoperations-platform` | Contract / guardrail truth | Owns schemas, contracts, ledger guardrails, runtime-route guardrails, and non-promotional platform controls. |
| 6 | `hawkinsoperations-proof` | Claim / proof truth | Owns proof records, proof ceilings, evidence-boundary records, and blocked-claim status. |
| 7 | `hawkinsoperations-website` | Render truth | Renders the public Reviewer Guide and bounded reviewer navigation; rendering is not proof. |

## Command Center Routes

| Need | Route | Boundary |
|---|---|---|
| Visual system presentation | [Website Reviewer Guide](https://hawkinsoperations.com/) | Explains and presents the system; website rendering is not proof. |
| Product / ProofOps control | [Hoxline](https://github.com/HawkinsOperations/hoxline) | Product control surface; not proof authority or final approval. |
| First reviewer path | [profile/START_HERE.md](profile/START_HERE.md) | Click path for review and demo; does not promote claims. |
| Org front door | [profile/README.md](profile/README.md) | Reviewer routing only; does not create proof. |
| Repository authority map | [architecture/REPO_AUTHORITY_MAP.md](architecture/REPO_AUTHORITY_MAP.md) | Repository ownership map; source does not prove runtime. |
Expand Down Expand Up @@ -90,6 +94,7 @@ This surface does not claim runtime-active public proof, signal-observed public

| Repo | Truth surface | Boundary |
|---|---|---|
| [hoxline](https://github.com/HawkinsOperations/hoxline) | Product / ProofOps control | Owns the product control experience; does not own proof records, runtime proof, or approval. |
| [hawkinsoperations-proof](https://github.com/HawkinsOperations/hawkinsoperations-proof) | Claim / proof truth | Owns proof records, claim ceilings, and blocked-claim status. |
| [hawkinsoperations-platform](https://github.com/HawkinsOperations/hawkinsoperations-platform) | Contract / guardrail truth | Owns schemas, contracts, and non-promotional platform controls. |
| [hawkinsoperations-validation](https://github.com/HawkinsOperations/hawkinsoperations-validation) | Behavior truth | Owns controlled validation and recorded validation outputs. |
Expand Down
11 changes: 6 additions & 5 deletions architecture/REPO_AUTHORITY_MAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,11 +24,11 @@ Total HawkinsOperations system repos remain seven:
- `hawkinsoperations-platform` = contracts/mechanics
- `hawkinsoperations-proof` = proof records/claim ceilings
- `hawkinsoperations-website` = public rendering
- `hoxline` = current Hoxline product/front-door repo
- `hoxline` = current Hoxline product and ProofOps control repo

No eighth repo may be added without explicit approval.

Hoxline by HawkinsOperations is the current product/front-door repo and ProofOps control surface. Hoxline provides ProofOps control for the AI security era and governs how AI-assisted security work becomes tested, reviewed, blocked, or safe to claim. Current repository path: HawkinsOperations/hoxline. AevumGuard was a prior working name. Hoxline is the current product name. Claim Firewall is the first Claim Authority enforcement capability inside Hoxline; it is not the product, platform, front-door repo, an eighth repo, proof authority, runtime proof, or signal proof.
Hoxline by HawkinsOperations is the product and ProofOps control surface. Hoxline provides ProofOps control for the AI security era and governs how AI-assisted security work becomes tested, reviewed, blocked, or safe to claim. Current repository path: HawkinsOperations/hoxline. Claim Firewall is the first Claim Authority enforcement capability inside Hoxline; it is not the product, platform, an eighth repo, proof authority, runtime proof, or signal proof.
## Authority Summary

| Repository | Authority plane | Owns | Boundary |
Expand All @@ -39,14 +39,15 @@ Hoxline by HawkinsOperations is the current product/front-door repo and ProofOps
| `hawkinsoperations-platform` | Contracts / orchestration / control logic | Runtime contracts, interface boundaries, and non-promotional guardrails. | Contracts do not prove public proof, production readiness, or current runtime state. |
| `hawkinsoperations-proof` | Proof records / evidence truth | Proof records, claim ceilings, evidence boundary records, and cited case packets. | Proof records do not publish raw private evidence or raise ceilings by presentation. |
| `hawkinsoperations-website` | Public rendering only | Public reviewer navigation and rendered wording. | Rendering is not proof and cannot approve a claim. |
| `hoxline` | Product / front door | Hoxline product surface and Claim Authority capabilities, starting with Claim Firewall. | Product framing does not prove runtime, signal, evidence, public-safe status, production readiness, or approval. |
| `hoxline` | Product / ProofOps control | Hoxline product surface and Claim Authority capabilities, starting with Claim Firewall. | Product framing does not prove runtime, signal, evidence, public-safe status, production readiness, or approval. |

## Command Center Operating Surfaces

| Surface | Route | Owns | Does not own |
| --- | --- | --- | --- |
| Organization front door | [profile/README.md](../profile/README.md) | High-level reviewer orientation and demo routing. | Proof, runtime, signal, or public-safe approval. |
| Product front door | [hoxline](https://github.com/HawkinsOperations/hoxline) | Hoxline product experience and Claim Authority capability surface. | Proof authority, runtime truth, signal truth, public-safe approval, or repo expansion approval. |
| Website / Reviewer Guide | [hawkinsoperations.com](https://hawkinsoperations.com/) | Visual walkthrough and presentation of the complete system. | Source, validation, runtime, signal, proof, or public-safe approval. |
| Product / ProofOps control | [hoxline](https://github.com/HawkinsOperations/hoxline) | Hoxline product experience and Claim Authority capability surface. | Proof authority, runtime truth, signal truth, public-safe approval, or repo expansion approval. |
| Reviewer start path | [profile/START_HERE.md](../profile/START_HERE.md) | First-click review sequence and claim-boundary reminders. | Stronger claim status than proof records allow. |
| Operating cockpit | [private org Control Board route](https://github.com/orgs/HawkinsOperations/projects/2) | Current work visibility and queue coordination for the canonical private HawkinsOperations Control Board; Project #1 is not an active reviewer route. | Source truth, validation truth, runtime truth, signal truth, proof, public-safe status, merge approval, or project metadata authority. |
| Proof ledger route | [Lifetime Case Ledger public summary](https://github.com/HawkinsOperations/hawkinsoperations-proof/blob/main/proof/records/lifetime-case-ledger-v1-public-summary.json) | Bounded count summary owned by proof records and platform manifests; this map does not copy changing counts. | Runtime activity, signal observation, public proof, public-safe runtime proof, case closure, or disposition authority. |
Expand All @@ -62,7 +63,7 @@ Hoxline by HawkinsOperations is the current product/front-door repo and ProofOps
| `hawkinsoperations-platform` | Platform architecture, stack truth tracking, and environment boundary documentation. | Detection proof, public proof, sensitive runtime exports, private host details. | Architecture-oriented until runtime evidence is reviewed. | Platform docs prove current deployment state. |
| `hawkinsoperations-proof` | Proof contracts, evidence indexes, public-safe records, and claim linkage structure. | Raw private evidence publication, runtime operation, source ownership for other repos. | Proof-oriented only for reviewed and scoped records. | Evidence-linked material is automatically public-safe. |
| `hawkinsoperations-website` | Public rendering of approved content. | Source truth, runtime truth, evidence truth, claim approval. | Rendering-oriented after public claim review. | Website presentation proves a claim by itself. |
| `hoxline` | Current Hoxline product/front-door repo and Claim Authority capability UX. | Proof authority, runtime status, signal observation, public-safe approval, or repo expansion. | Product-oriented until proof records approve stronger claims. | A product page or capability label proves a claim by itself. |
| `hoxline` | Current Hoxline product and Claim Authority capability UX. | Proof authority, runtime status, signal observation, public-safe approval, or repo expansion. | Product-oriented until proof records approve stronger claims. | A product page or capability label proves a claim by itself. |

## Cross-Repository Rules

Expand Down
37 changes: 21 additions & 16 deletions architecture/REPRODUCIBLE_REVIEWER_PATH.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Reproducible Reviewer Path

Status: PHASE_1_DOCUMENTED_CONTRACT_ONLY
Status: PHASE_2B_REVIEWER_PATH_WITH_LOCAL_INVARIANT_CHECK
Control type: reviewer reproduction path
Trust class: SOURCE_EXISTS after merge

Expand Down Expand Up @@ -67,7 +67,7 @@ Read:
```powershell
cd ..\hawkinsoperations-detections
git status -sb
python .\scripts\verify_detection_contract.py
python -B .\scripts\verify_detection_contract.py
```

Review current detection source and boundaries in:
Expand Down Expand Up @@ -119,7 +119,7 @@ python -B -m hoxline demo verify --input .hoxline\demo-runs\self-test\run-summar
python -B -m hoxline gauntlet verify --input examples\gauntlet\ho-det-001-full-loop-run-v0.json
```

Hoxline by HawkinsOperations is the product/front-door repo for ProofOps control. The one-command reviewer demo is deterministic, local, and fixture-based; it routes reviewers through the Hoxline loop without publishing private evidence, mutating runtime systems, or promoting public proof. Hoxline governs how AI-assisted security work becomes tested, reviewed, blocked, or safe to claim. Claim Firewall is the first Claim Authority enforcement capability inside Hoxline; it is not the product, platform, front-door repo, an eighth repo, proof authority, runtime proof, or signal proof.
Hoxline by HawkinsOperations is the product and ProofOps control surface. The one-command reviewer demo is deterministic, local, and fixture-based; it routes reviewers through the Hoxline loop without publishing private evidence, mutating runtime systems, or promoting public proof. Hoxline governs how AI-assisted security work becomes tested, reviewed, blocked, or safe to claim. Claim Firewall is the first Claim Authority enforcement capability inside Hoxline; it is not the product, platform, front-door repo, an eighth repo, proof authority, runtime proof, or signal proof.

### Platform Boundary and Visibility Plane
```powershell
Expand All @@ -142,28 +142,31 @@ Platform output is status/plan visibility unless the relevant proof record and p
```powershell
cd ..\hawkinsoperations-proof
git status -sb
python scripts\verify_proof_integrity.py
python -B scripts\verify_proof_integrity.py
```

Expected Phase 1 gap:
Current proof route:

- ID-DET-002, ID-DET-003, and ID-DET-004 proof index entries and proof records are pending.
- HO-DET-012 proof parity is pending if public routing is desired.
- ID-DET-002, ID-DET-003, and ID-DET-004 have proof records and entries in `proof/indexes/DETECTION_PROOF_STATUS_INDEX.yml`, each bounded to its recorded controlled-test scope.
- HO-DET-012 has a proof record, proof card, and indexed `CONTROLLED_TEST_VALIDATED` ceiling; runtime, signal, and public-safe promotion remain separate.
Comment thread
raylee-hawkins marked this conversation as resolved.

### Website Rendering Plane

```powershell
cd ..\hawkinsoperations-website
git status -sb
npm install
npm ci
npm run typecheck
npm run check:site
npm run public-status:verify
npm run build
```

Expected Phase 1 gap:
Current presentation gap:

- ID-DET-002, ID-DET-003, and ID-DET-004 public website routes are pending.
- HO-DET-012 appears in current website source data, but proof and website parity remain required before any public proof or public-safe wording can be claimed.
- HO-DET-012 appears in current website source data with its proof record, proof card, indexed `CONTROLLED_TEST_VALIDATED` ceiling, and bounded website summary present; runtime, signal, and public-safe promotion remain separately gated.
- Inspect the [Website Reviewer Guide](https://hawkinsoperations.com/) in ordinary and presentation modes as rendering QA only; visual success does not promote source, validation, runtime, signal, or proof status.

## Private-Only Commands Excluded

Expand All @@ -185,8 +188,10 @@ Private evidence can inform future review only after privacy review, stale revie
The `.github` command-center route has a local invariant verifier for reviewer-route and claim-boundary checks:

```powershell
cd .github
python scripts\verify-command-center-invariants.py
cd ..\.github
$env:PYTHONDONTWRITEBYTECODE = "1"
python -m pip install --disable-pip-version-check PyYAML==6.0.2
python -B scripts\verify-command-center-invariants.py
```

Expected output fields:
Expand All @@ -202,10 +207,10 @@ This verifier proves only that checked command-center route files and invariant

| Item | Current routed state | Remaining gap |
| --- | --- | --- |
| ID-DET-002 | Source, controlled-test validation, and platform status/plan visibility are documented as carried by PRs #27, #46, and #29. | Proof record/index and website route are pending. |
| ID-DET-003 | Source, controlled-test validation, and platform status/plan visibility are documented as carried by PRs #27, #46, and #29. | Proof record/index and website route are pending. |
| ID-DET-004 | Source, controlled-test validation, and platform status/plan visibility are documented as carried by PRs #27, #46, and #29. | Proof record/index and website route are pending. |
| HO-DET-012 | Source, validation, and platform progress exist. | Proof and website parity are still required if public routing is desired. |
| ID-DET-002 | Source, controlled-test validation, platform visibility, proof record, proof card, and proof-index entry exist in their owning repositories. | Dedicated website presentation routes are not established; current public rendering data requires a separate freshness review. |
| ID-DET-003 | Source, controlled-test validation, platform visibility, proof record, proof card, and proof-index entry exist in their owning repositories. | Dedicated website presentation routes are not established; current public rendering data requires a separate freshness review. |
| ID-DET-004 | Source, controlled-test validation, platform visibility, proof record, proof card, and proof-index entry exist in their owning repositories. | Dedicated website presentation routes are not established; current public rendering data requires a separate freshness review. |
| HO-DET-012 | Source, controlled validation, platform controls, proof record, proof card, and bounded website summary exist. | Runtime, signal, and public-safe promotion remain separately gated. |
| Cross-repo parity | Report-only scanner exists in validation. | Fail-closed promotion requires separate approval. |

## Claim Boundary
Expand Down
13 changes: 13 additions & 0 deletions governance/COMMAND_CENTER_INVARIANTS.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,16 @@
{
"schema": "hawkinsoperations-command-center-invariants-v1",
"scope": "HawkinsOperations/.github reviewer routing and governance shell",
"system_repository_order_semantics": "Stable front-door inventory display order; promotion flow is separately governed by PROMOTION_LADDER_CONTRACT.yml.",
"system_repositories": [
".github",
"hoxline",
"hawkinsoperations-detections",
"hawkinsoperations-validation",
"hawkinsoperations-platform",
"hawkinsoperations-proof",
"hawkinsoperations-website"
],
"required_route_files": [
"README.md",
"profile/README.md",
Expand All @@ -17,6 +27,9 @@
],
"invariants": {
"github_repo_role": ".github is reviewer routing and governance shell only",
"presentation_route": "hawkinsoperations.com is the Website Reviewer Guide and presentation surface",
"seven_repository_authority": "HawkinsOperations has exactly seven system repositories with separate authority roles",
"hoxline_role": "Hoxline is the product and ProofOps control surface, not proof authority",
Comment thread
raylee-hawkins marked this conversation as resolved.
"project_2_role": "Project #2 is the canonical private HawkinsOperations Control Board operating cockpit",
"project_1_boundary": "Project #1 is not an active reviewer route",
"project_metadata_boundary": "Project metadata is coordination only, not proof, approval, merge authority, runtime truth, signal truth, or public-safe status",
Expand Down
Loading
Loading