Skip to content

Latest commit

 

History

History
99 lines (87 loc) · 27.9 KB

File metadata and controls

99 lines (87 loc) · 27.9 KB

Knowledge Classification And Processing 보호 리소스 완결성 매트릭스

Status: Draft

이 문서는 보호 리소스 기능 완결성 기준에 따라 ADR-0065의 정책 산출물과 후속 구현 책임을 구분한다. MBA-305는 정책과 문서 계약만 확정하며, 아래 동작 경계를 구현 완료로 간주하지 않는다.

대상

항목 내용
기능/이슈 MBA-305 정책 설계, MBA-335 control-plane, MBA-304 processing runtime, MBA-310 contextual representation, MBA-311 diversification, MBA-309 confirmatory benchmark
보호 리소스 Organization taxonomy/topic, classification assignment revision, Processing Profile revision, profile policy/override, processing decision/build artifact, suggestion provenance
durable reference 위치 후속 구현의 Knowledge DB schema와 job/receipt payload. MBA-305에서는 physical schema나 durable reference를 추가하지 않는다.
실행 진입점 후속 management API/UI, reindex admission, Knowledge worker와 retrieval runtime. MBA-305에서는 endpoint, worker 또는 runtime을 추가하지 않는다.
외부 I/O 후속 DB/storage/embedding 및 승인 요건 충족 뒤 별도 이슈로 도입할 classifier provider. 현재 classifier adapter와 provider 호출은 없다.
권위 문서 ADR-0065, Knowledge requirements/API/component/test 문서, 이 매트릭스

현재 안전 상태

  • Taxonomy, classification assignment와 Processing Profile을 위한 신규 table, API, UI 또는 worker가 없으므로 미구현 reference를 저장하거나 실행하지 않는다.
  • 기존 documents.meta_info.classification 보안 분류와 character 기반 chunk 설정은 그대로 유지하며 document type, taxonomy topic 또는 token 기반 Processing Profile로 재해석하지 않는다.
  • 새 profile, contextual representation과 diversification은 production default로 활성화하지 않는다.
  • AI classifier는 published taxonomy, manual review UI, labeled calibration/test split, provider egress gate와 abstention policy가 준비되기 전에는 issue를 생성하거나 provider를 호출하지 않는다.

경계 상태

경계 상태 계약 증거 구현 위치 검증 증거 해당 없음 사유 또는 후속 이슈
정책·식별자·organization scope 후속 이슈 ADR-0065 Decision 1-7, Knowledge FR-134~FR-146e 없음 없음 MBA-335. 정책 계약은 exact current-validation reason/content gate, tagged generator provenance, override/policy의 strict scoped profile revision reference, published policy의 optional Organization/required Platform general 및 null-policy용 non-null exact Platform default까지 확정됐지만 서버의 identity·ownership·permission enforcement가 없어 동작 경계는 완료가 아니다. 현재 신규 ID 입력 경로는 없다.
관리 API command/query 후속 이슈 Knowledge API specification의 classification/taxonomy/profile 계약 없음 없음 MBA-335. Complete taxonomy cap과 pre/post-normalization label bound, server-issued topic ID와 current-tree bounded draft recovery mapping, exact empty-object first profile create/response와 successor base_revision_id, active-ready legacy/no-decision을 보수적으로 세고 `purging
Suggestion accept impact preview 후속 이슈 Knowledge FR-140a와 API/component accept-preview 계약 없음 없음 MBA-335. Fresh source gate, actor-bound max-10-minute accept_preview_revision, current resolver/materialization snapshot과 nullable current Processing Decision/active Artifact Build identity·fingerprint·availability 결속, same-boolean identity change의 stale rollback 및 preview 만료 뒤에도 가능한 exact authorized terminal retry를 구현해야 한다. 현재 endpoint/token이 없어 stale preview로 mutation할 경로도 없다.
Profile/profile-policy request schema와 bound 후속 이슈 Knowledge FR-146a~FR-146e와 API strict schema 없음 없음 MBA-335. First create의 exact {}와 null config/base revision-0 draft shell, complete first PATCH, successor의 required exact same-identity published base_revision_id, processing_profile_schema_v1 token bound, processing_profile_policy_v1 matcher union/raw 2,000-rule cap, required nullable general fields와 versioned non-null Platform default pointer를 구현해야 한다. Default 초기화·변경·deprecate 직렬화와 unavailable fail-closed도 포함하며 현재 신규 profile/policy write가 없다.
Reindex idempotency wire validation 후속 이슈 Knowledge FR-145g와 API Idempotency-Key 계약 없음 없음 MBA-304. Required single canonical UUID header를 DB 접근 전 검증하고 raw key 대신 scoped SHA-256 digest와 별도 typed request digest만 저장해야 한다. 현재 신규 admission endpoint/receipt가 없어 raw key가 저장될 경로도 없다.
관리 UI·catalog·picker 후속 이슈 Knowledge component specification의 manager/reviewer flow 없음 없음 MBA-335. Override picker는 server-issued scoped profile reference 전체를 보존하고 Platform default ref/catalog revision은 Organization manager에게 read-only로 투영하며 Organization UI에 mutation control을 두지 않아야 한다. 현재 UI가 없어 미구현 capability를 노출하지 않는다.
저장 schema·GraphMutation·redaction 후속 이슈 ADR-0065 Decision 1-7, Knowledge data model/API 계약 없음 없음 MBA-335가 taxonomy/assignment/control-plane schema, override의 catalog_scope+profile_revision_id와 deterministic/AI tagged suggestion provenance를, MBA-304가 decision/build/job/receipt schema를 additive migration으로 확정한다. 현재 신규 reference write는 없다.
Deployment preflight 해당 없음 ADR-0065 profile resolution과 reindex admission 계약 해당 없음 문서 구조 검토 Workflow graph/deployment는 taxonomy/profile ID를 직접 저장하지 않는다. 기존 KB reference preflight는 유지하고 새 정책 vector는 admission/runtime에서 resolve한다.
Runtime/background 재검증 또는 capability validity 후속 이슈 ADR-0065 Decision 4-9, Knowledge FR-139FR-149 및 FR-145dFR-145f 없음 없음 MBA-304가 receipt lookup 전 admission source gate, null-policy Platform default ref/catalog revision을 포함한 resolver vector, physical build의 LLM Credentials-owned exact-one embedding binding, unavailable zero-write, return/commit 직전 revision 검증과 job_created execution actor/binding의 external-batch/finalization gate를 구현한다. MBA-310과 MBA-311은 representation/diversification 소비 경계를 구현하며 현재 새 runtime path는 비활성이다.
Transaction·session·TOCTOU 후속 이슈 ADR-0065 atomic assignment/publish/activation 계약 없음 없음 MBA-335가 source-managed assignment/validation/lock/override mutation의 external authorization session 종료와 commit-time source revision/current KB authority 재검증을 포함한 control-plane CAS/transaction을, MBA-304가 admission/finalization transaction을 구현한다. 현재 신규 mutation은 없다.
Retry·idempotency·terminal acknowledgement 후속 이슈 Knowledge FR-145d, FR-147a~FR-147c 없음 없음 MBA-304가 admission receipt, retry 수렴과 artifact cleanup acknowledgement를 구현한다. 현재 신규 job/effect는 없다.
Background lease·claim·fencing 후속 이슈 Knowledge FR-147b~FR-147c 없음 없음 MBA-304. 현재 신규 processing worker/job은 없어 stale worker가 새 artifact를 finalize할 경로가 없다.
Revoke/delete/expire/rotation lifecycle 후속 이슈 ADR-0065 profile deprecate, Platform default pointer, suggestion expiry와 artifact purge 계약 없음 없음 MBA-335가 taxonomy/profile/default/suggestion lifecycle을 구현하고 current Platform default target은 pointer를 먼저 옮기기 전 deprecate하지 못하게 한다. MBA-304는 pre-delete purging fence/intent와 external delete, tombstone+purged+knowledge.processing_artifact.purged completion transaction을 분리하고 completion 실패를 ready rollback이 아닌 same-generation reconciliation으로 복구해야 한다. 현재 신규 lifecycle row는 없다.
오류·resource hiding·reason code 후속 이슈 Knowledge API specification의 safe 404, 403, 409와 fixed reason 계약 없음 없음 MBA-335와 MBA-304가 각 소유 endpoint/runtime에 적용한다. 현재 신규 ID를 수용하는 경로가 없어 존재 정보가 노출되지 않는다.
Audit event 생성·action/status·중복 방지 후속 이슈 ADR-0008, ADR-0065 Decision 4-7, 9와 Knowledge FR-145f, FR-150~FR-150b 없음 없음 MBA-335가 control-plane audit을, MBA-304가 최초 reindex result의 knowledge.processing_reindex.admitted atomic audit와 exact replay 중복 방지 및 physical deletion 확인 뒤 tombstone과 원자적인 knowledge.processing_artifact.purged completion audit을 구현한다. Purge completion 실패는 ready rollback 없이 retry하고 action을 중복 생성하지 않아야 한다. 현재 신규 mutation이 없어 누락될 신규 event도 없다.
Audit·trace·secret/PII redaction 후속 이슈 ADR-0065 Decision 9, Knowledge FR-144, FR-150~FR-150b 없음 없음 MBA-335와 MBA-304. 구현 전까지 raw content/provider payload, credential identity/candidate count, credential config/secret와 relation/permission detail을 새 suggestion, response, audit, trace 또는 job payload에 저장하지 않는다. Safe refs/revisions는 server-owned embedding binding row에만 둔다.
Canonical audit action registry 후속 이슈 ADR-0008과 Knowledge FR-150b 없음 없음 MBA-335와 MBA-304. MBA-305가 확정한 22개 action을 exact string으로 AuditAction, audit 검색/UI filter와 계약 테스트에 함께 등록하고 alias를 만들지 않아야 한다. 현재 신규 mutation endpoint가 없어 해당 action을 생성할 구현도 없다.
Legacy migration·scrub·호환성 종료 후속 이슈 ADR-0065 Consequences, Knowledge FR-134, FR-136i, FR-146, FR-146f, FR-151 없음 없음 MBA-335가 classification inventory/migration과 active-ready legacy artifact/no-current-decision의 보수적 impact counting을, MBA-304가 character-setting legacy adapter와 rollout을 담당한다. 현재 legacy 의미를 변경하거나 impact preview에서 안전하지 않게 제외하지 않는다.
Derived representation·citation lineage 후속 이슈 ADR-0065 Decision 8, Knowledge FR-147~FR-148 없음 없음 MBA-310. 현재 contextual representation은 생성·검색에 사용하지 않고 canonical evidence가 citation source다.
Candidate diversification·ranking 후속 이슈 ADR-0065 Decision 10, Knowledge FR-149 없음 없음 MBA-311. 현재 diversification을 production ranking에 추가하지 않는다.
Production default evidence gate 후속 이슈 ADR-0065 Decision 10, Knowledge FR-152 없음 없음 MBA-309. Confirmatory benchmark 승인 전 새 profile/retrieval strategy를 production default로 활성화하지 않는다.
AI classifier/provider egress 해당 없음 ADR-0065 Decision 4, 9 및 Follow-up Review Notes 해당 없음 provider adapter 부재와 문서 범위 정적 검토 선행 조건이 충족되지 않아 현재 구현 wave의 기능이 아니다. 별도 승인 이슈 전까지 provider 호출과 자동 적용을 금지한다.
공식 문서 정합성 완료 ADR-0065과 Knowledge requirements/API/component/test 문서 docs/ 문서 링크, ADR 번호, 용어와 계약 추적성 정적 검사 동작 구현 완료를 의미하지 않는다.

후속 테스트 시나리오

ID 시나리오 기대 결과 권장 계층 증거/상태
AUTH-01 같은 Organization의 권한 있는 actor가 taxonomy/profile 또는 KB assignment를 조회·변경한다. 문서에 정의된 KB grant 또는 ADR-0034 Organization manager override로만 허용되고 exact organization resource만 resolve된다. Source-managed KB-scoped classification/override/resolve operation은 모두 fresh source/display gate를 요구하고, content-confirming current-validation만 effective content_read/raw policy를 추가로 요구하며 Manager override도 이를 우회하지 않는다. service/API MBA-335
AUTH-02 다른 Organization 또는 권한 없는 actor가 opaque resource ID를 제출한다. ownership-first safe hiding 또는 same-scope 403으로 닫히고 identity가 노출되지 않는다. service/API MBA-335
AUTH-03 Source-managed reindex admission 또는 exact receipt replay 전에 source authorization이 회수되거나 gate 뒤 commit 전 revision이 바뀐다. Receipt lookup/result projection보다 먼저 safe 404로 닫고 receipt/decision/satisfaction/job 및 knowledge.processing_reindex.admitted audit identity를 노출·변경하지 않는다. Gate 뒤 revoke가 serialization winner여도 같은 admission zero-write 결과다. Optional request-scoped security audit는 target/source ID와 admission result identity 없이 ADR-0017 allowlist만 사용한다. service/PostgreSQL MBA-304
AUTH-04 Source-managed KB의 classification GET/options, assignment PUT/current-validation/lock/unlock, override GET/options/set/clear 또는 resolve-preview caller에게 필요한 KB action/Manager override는 있지만 source authorization/display gate가 stale/revoked/denied다. Protected assignment/lock/override/resolver lookup·projection·mutation 전에 safe 404 resource.hidden으로 닫고 type/topic/security classification, axis source/lock, profile/resolver identity/status, option count와 estimate를 노출하거나 변경하지 않는다. Manual KB는 source gate 비적용이다. service/API MBA-335
AUTH-05 Source-managed assignment/validation/lock/override mutation의 initial source gate 뒤 commit 전에 revoke revision/watermark가 전진한다. External authorization session은 DB transaction과 겹쳐 유지하지 않고 commit-time current KB authority+bounded source revision 재검증에서 revoke winner를 safe 404 zero-write로 닫는다. Assignment/lock/override, impact revision, canonical audit와 reindex projection은 모두 없다. service/PostgreSQL MBA-335
PREVIEW-01 Suggestion accept-preview를 발급한 뒤 actor, accepted axes, candidate/state, assignment/content, taxonomy/registry, policy/catalog/override, resolved scoped profile ref/materialization, nullable current Processing Decision ref/fingerprints 또는 active Artifact Build ref/generation/availability/fingerprints를 바꾸거나 source authorization을 회수한다. Preview는 최대 10분 actor-bound opaque revision만 반환하고 response boolean이 같아도 bound identity/vector 변화, expiry, wrong scope 또는 revoke에서는 fresh non-terminal accept가 fixed stale 또는 safe 404로 assignment/outcome/audit/reindex intent 없이 종료된다. Fresh authorization과 stored request fingerprint가 일치하는 terminal retry는 expiry 뒤에도 기존 결과를 먼저 복구하며 raw token/digest를 저장하지 않는다. service/API/PostgreSQL MBA-335
IMPACT-01 Taxonomy impact preview 뒤 explicit profile override, current Processing Decision 또는 active artifact pointer/availability를 바꾸거나 staging-only/no-op을 수행한다. Authoritative impact input 변화는 같은 transaction에서 assignment_impact_snapshot_revision을 전진시켜 old preview를 stale로 만들고 staging-only/no-op은 전진시키지 않는다. Publish와 경합하면 winner 하나만 commit한다. service/PostgreSQL MBA-335, MBA-304
IMPACT-02 Profile-policy impact preview에 assignment가 없는 general-fallback target, valid/invalid override, active artifact 부재, active-ready legacy/no-current-decision artifact, `purging purged` artifact와 lifecycle 제외 target을 섞고 이후 snapshot을 변경한다. profile_policy_impact_bucket_v1 predicate와 bounded threshold가 deterministic하다. Active-ready legacy/no-decision target은 보수적 reindex candidate, active artifact 부재와 `purging purged`는 resolver 차이가 있으면 affected-only이며 archived/deleted/processing-ineligible만 두 count에서 제외한다. Fingerprint가 같음이 증명된 target은 reindex에서 제외한다. Publish는 exact token/contract/acknowledgement를 요구하고 stale은 policy/current pointer/audit 없이 닫으며 success도 assignment/reindex job을 자동 생성하지 않는다.
PROFILE-CREATE-01 First profile create에 exact {}, missing body, non-object와 unknown-field object를 제출하고 audit failure도 주입한다. Exact request만 identity와 null config/base revision-0 draft 및 create audit를 원자 생성하고 catalog revision은 그대로다. 다른 shape와 audit failure는 zero-write이며 complete config PATCH 전 validate/publish할 수 없다. schema/service/API/PostgreSQL MBA-335
PROFILE-SUCCESSOR-01 같은 profile identity에 config가 다른 published revision A/B가 있을 때 B를 exact base로 successor draft를 만들고 wrong owner/identity/lifecycle base도 제출한다. B의 normalized config와 base_revision_id만 복제해 draft_revision=0을 만들며 list/latest ordering을 authority로 사용하지 않는다. Cross-owner/identity는 safe 404, draft/deprecated/non-published는 fixed 409이고 실패에서 draft/catalog/audit가 없다. service/API MBA-335
PROFILE-DEFAULT-01 Current profile-policy가 없는 Organization에서 Platform default를 resolve한 뒤 default pointer 변경, current target deprecate 또는 target unavailable을 유발한다. Exact default/source가 read-only projection된다. Pointer 변경은 platform registry owner/system actor의 required expected catalog revision을 검증하고 pointer/catalog revision/knowledge.processing_profile_default.changed audit를 원자적으로 확정해 old preview/override/admission을 stale로 만든다. Stale CAS 또는 audit 실패는 전체 rollback하고 current target deprecate는 pointer 이동 전 in-use다. Valid override가 없는 default-required unavailable은 GET/options 200 recovery projection을 유지하고 preview/reindex/clear를 fixed 503 zero-write로 닫으며 selectable override set/change recovery와 기존 active-ready 유지를 보장한다. service/API/PostgreSQL MBA-335, MBA-304
STORE-01 taxonomy, assignment, suggestion, profile/profile-policy/override, Platform default pointer, processing decision reference와 embedding execution binding을 저장하고 다시 읽는다. Exact immutable revision, first-draft null config/base, successor base_revision_id, server-issued topic ID와 draft-local key recovery mapping, versioned impact contract, assignment axis별 source/lock/changed-dimension provenance, tagged generator field, default ref/catalog revision, receipt source revision, credential/model/provider safe refs와 lifecycle/relation/permission/provider-routing revision 및 nullable precondition 의미가 round-trip 뒤 유지된다. Raw credential/config는 없다. schema/API MBA-335, MBA-304
SCHEMA-01 Processing Profile과 profile-policy draft의 lower/upper boundary, 잘못된 scalar type, matcher union, duplicate와 raw rule count를 table-driven으로 검증한다. V1 strict integer와 inclusive token bound, overlap half-size bound, current capability 축소, complete PATCH, required nullable general field 및 raw 2,000-rule cap을 정확히 적용한다. Coercion, unknown union field, dedupe 뒤 cap 우회, partial merge와 cross-organization ref는 mutation/audit 없이 거부된다. schema/service/API MBA-335
RUNTIME-01 admission 뒤 execution actor membership/KB authority/source authorization, taxonomy/profile revision 또는 canonical content가 바뀐다. 다음 external batch/finalize 전에 cancelled 또는 stale로 판정하고 기존 active-ready artifact를 유지한다. runtime/PostgreSQL MBA-304
RUNTIME-02 Knowledge processor/finalizer를 endpoint 없이 직접 호출하거나 다른 actor가 active job을 reuse한다. Immutable job execution actor의 current authorization, resolver, permission, lease/fence와 readiness 검증을 우회하거나 actor를 교체하지 못한다. worker/runtime MBA-304
RUNTIME-03 Permission/source revoke가 external batch gate 전 또는 in-flight call 뒤 commit된다. Gate 전에는 adapter가 호출되지 않고, in-flight call 뒤에는 다음 adapter와 pointer swap이 없으며 authorized serialization winner만 commit한다. worker/PostgreSQL MBA-304
RUNTIME-CREDENTIAL-01 Physical build admission의 eligible embedding credential 후보를 0/1/2개로 만들고, binding issue와 job commit 사이 및 admission 뒤 각 provider batch/finalization 직전에 lifecycle/relation/use/provider-routing revision을 변경한다. 1개만 immutable binding과 provider 실행을 허용한다. 0/복수와 commit-before-change race loser는 fixed 409 zero-write이고 fallback하지 않는다. Bound revision revoke/change 뒤 다음 provider call/pointer swap은 없고 fixed terminal cancellation과 owned cleanup만 남으며 job_reused가 다른 actor/credential로 기존 job을 rebind하지 않는다. Credential identity/count/config/detail은 응답·audit·trace에 없다. service/worker/PostgreSQL MBA-304
TX-01 같은 nullable pointer/revision에 concurrent publish, selected-axis assignment, lock, profile deprecate, Platform default pointer 또는 override mutation을 수행한다. Winner 하나만 commit하고 loser는 partial row/audit 없이 fixed conflict로 종료한다. Manual PUT은 unselected locked/source axis를 보존하고 lock은 assignment/content snapshot을 함께 검증한다. Profile-policy publish, default mutation과 Organization/Platform deprecate는 공통 lock order로 deprecated current reference/default와 deadlock을 만들지 않는다. service/PostgreSQL MBA-335
LEASE-01 lease 만료 뒤 새 worker가 claim하고 이전 worker가 finalize한다. stale finalize와 pointer swap이 fencing으로 거부된다. worker/PostgreSQL MBA-304
LIFE-01 deprecated profile 또는 expired suggestion을 신규 policy/accept에 사용하거나 current Platform default target을 직접 deprecate한다. 신규 사용은 차단되고 current default deprecate는 pointer 이동 전 in-use이며 authorized history/recovery와 기존 active-ready 경로는 유지된다. service/API/runtime MBA-335
LIFE-02 Artifact purge의 pre-delete transaction, physical delete와 completion transaction 각 경계에서 crash/audit failure를 주입하고 same generation으로 retry한다. External delete 전 실패는 purging/intent/impact revision을 rollback한다. Delete 후 실패는 ready로 복원하지 않고 non-retrievable purging을 유지하며 reconciler가 tombstone/purged/impact revision/knowledge.processing_artifact.purged를 원자적으로 정확히 한 번 완성한다. service/worker/PostgreSQL MBA-304
HIDE-01 malformed, missing, cross-organization와 same-scope denied ID의 응답·audit를 비교한다. 계약된 safe error만 반환하고 label, provider, owner와 revision을 노출하지 않는다. API/audit MBA-335, MBA-304
AUDIT-01 taxonomy/profile publish, Platform default pointer 변경, assignment, suggestion review, override, reindex admission 네 result와 purge를 실행하고 exact receipt/completion replay를 반복한다. 일반 mutation과 canonical audit가 원자적으로 정확히 한 번 기록된다. 최초 reindex result는 knowledge.processing_reindex.admitted success audit와 receipt/result mutation을 같은 transaction에서 확정하고 replay는 중복 audit가 없다. Purge는 physical deletion 확인 뒤 tombstone/purged/impact revision과 knowledge.processing_artifact.purged를 completion transaction에서 확정한다. Completion audit 실패는 삭제를 rollback하지 않고 purging에서 retry해 정확히 한 action으로 수렴한다. service/PostgreSQL MBA-335, MBA-304
ACTION-01 MBA-305가 확정한 22개 canonical action 전체를 registry, mutation audit, audit search와 UI filter에서 table-driven으로 대조한다. ADR-0008의 22개 exact string을 빠짐없이 사용하고 alias, combined wildcard와 과거형 변형이 없다. Authoritative completion mutation과 audit는 같은 Unit of Work이며 terminal/idempotent retry는 duplicate action을 만들지 않는다. knowledge.processing_artifact.purged는 physical deletion 확인 뒤에만 생성된다. unit/service/component MBA-335, MBA-304
IDEMP-01 Reindex admission에 canonical lower-case UUID, header name case variant, missing/duplicate/nil/upper-case/whitespace/braces/URN/comma-joined/malformed 값과 body-only key를 제출한다. Header name만 case-insensitive이고 canonical 36자 값 하나만 허용한다. Invalid wire는 receipt 조회 전 422, valid key는 canonical ASCII bytes의 SHA-256 digest만 scoped 저장하며 exact typed tuple replay와 different-request conflict가 결정적으로 수렴한다. schema/API/PostgreSQL MBA-304
REDACT-01 성공·거부·provider/storage 실패의 response, job, audit와 trace를 검사한다. raw content, prompt, provider payload, secret, token과 내부 fingerprint가 남지 않는다. API/worker/audit MBA-335, MBA-304
UI-01 관리자 catalog와 reviewer UI에서 taxonomy/profile 및 assignment를 관리한다. API와 같은 권한·revision·safe error를 사용하고 complete taxonomy cap과 draft key mapping을 복구하며 versioned bucket만 표시한다. Edited manual_axes만 선택하고 current-validation/content gate, generator provenance, 두 profile catalog revision과 read-only Platform default/source를 보존하며 stale state를 자동 merge하거나 Organization default mutation control을 만들지 않는다. component/E2E MBA-335
LEGACY-01 legacy security classification과 character chunk 설정을 읽고 새 정책을 단계적으로 도입한다. 기존 의미를 보존하고 신규 token/profile write와 명시적으로 분리한다. migration/API/runtime MBA-335, MBA-304
KNOW-01 Derived representation으로 검색한 근거를 citation과 prompt에 전달한다. Canonical evidence lineage와 permission을 최종 근거 경계에서 다시 검증하고 derived text를 원문으로 오인하지 않는다. retrieval/runtime MBA-310
RETRIEVAL-01 Current/history duplicate 후보가 같은 context budget을 경쟁한다. Stable identity로 중복을 제한하되 relevance와 canonical evidence를 보존한다. retrieval/evaluation MBA-311
EVAL-01 새 profile 또는 retrieval strategy를 production default 후보로 평가한다. 사전 등록된 품질·위험·coverage·latency·cost gate를 모두 통과하기 전에는 활성화하지 않는다. evaluation/release MBA-309

갱신 규칙

  • 동작 경계를 완료로 바꾸려면 계약 증거뿐 아니라 실제 판정 소유 코드와 실행 가능한 테스트 증거를 함께 기록한다.
  • 후속 구현 PR은 자신이 소유한 행과 시나리오를 갱신하고, 미완료 필수 경계의 안전한 현재 상태를 다시 확인한다.
  • 권한 우회, source authorization 우회, 외부 I/O 전 fail-closed 실패, 중복 finalize, raw content/provider payload 노출 또는 기존 관리·복구 경로 단절을 남기는 구현은 후속 이슈 상태로 병합하지 않는다.