This was generated by AI while filing the follow-ups handed over by the #1657 design audit.
Context
Whether an externally-filed issue reaches the untrusted-provenance work class is unspecified. The
governing prose arguably covers it, but the executable tests for that class read pull-request fields an
issue does not have, and plugins/autonomy/reference/routines.md affirmatively carves third-party text
already inside the org's own tracker out of the provenance trigger, deferring it to admission instead.
Admission's own axes encode neither author trust nor content trust, so the deferral target does not
implement the control the carve-out defers to it. The same carve-out is repeated verbatim across five
sibling routines, leaving the org's own issue-triage routine deriving the lowest class in the taxonomy
while a routine reading a vendor changelog derives the highest.
Citations for both halves, and the five routines, are in the #1657 design audit — see
the determination comment
(gaps G2 and G3, follow-up 3). Not restated here.
Proposed work
- Decide the question one way and record the decision: either give
admission-policy.md an author-trust
axis so "admission-governed" is a real deferral target, or drop the routines.md carve-out so
third-party tracker text derives the untrusted-provenance class the way external changelog prose
already does.
- Re-derive the affected routine rows from whichever answer lands, rather than leaving them at their
current class by inertia.
Acceptance criteria
References
Metadata
| Field |
Value |
| Category |
autonomy / guardrails |
| Area |
security |
| Ecosystem |
markdown |
This was generated by AI while filing the follow-ups handed over by the #1657 design audit.
Context
Whether an externally-filed issue reaches the untrusted-provenance work class is unspecified. The
governing prose arguably covers it, but the executable tests for that class read pull-request fields an
issue does not have, and
plugins/autonomy/reference/routines.mdaffirmatively carves third-party textalready inside the org's own tracker out of the provenance trigger, deferring it to admission instead.
Admission's own axes encode neither author trust nor content trust, so the deferral target does not
implement the control the carve-out defers to it. The same carve-out is repeated verbatim across five
sibling routines, leaving the org's own issue-triage routine deriving the lowest class in the taxonomy
while a routine reading a vendor changelog derives the highest.
Citations for both halves, and the five routines, are in the #1657 design audit — see
the determination comment
(gaps G2 and G3, follow-up 3). Not restated here.
Proposed work
admission-policy.mdan author-trustaxis so "admission-governed" is a real deferral target, or drop the
routines.mdcarve-out sothird-party tracker text derives the untrusted-provenance class the way external changelog prose
already does.
current class by inertia.
Acceptance criteria
(
plugins/autonomy/reference/guardrails/admission-policy.mdorplugins/autonomy/reference/routines.md), so a classifier no longer has to guess.together without one pointing at a control the other does not have.
issue-triage-sweep,backlog-readiness-check,duplicate-detection-sweep,pr-queue-tending,doc-freshness-sweep)each have their derived work class and isolation floor re-derived under the new answer — updated
where the answer changes them, explicitly confirmed where it does not.
justified in writing.
References
item is about how the class is derived for third-party tracker text.
Metadata