Outcome
Make OpenCoven/.github the canonical public organization governance and portfolio coordination plane while preserving repository-local implementation authority and confidential private-repository context.
This issue tracks ratification and activation of the initial governance-plane implementation. Organization metadata coordinates work and records evidence; it does not grant protected OpenCoven identity, authorization, runtime, persistence, release, or publication authority.
Initial implementation
The first implementation slice must include:
- an accepted organization-governance ADR;
- a machine-readable public repository registry and unique canonical-domain ownership checks;
- repository lifecycle, retirement, exception, public/private-data, and agent-authored-change policies;
- cross-repository initiative records with explicit decision owner, technical DRI, workstreams, dependencies, and exit criteria;
- machine-readable controls and evidence schemas;
- deterministic validation and generated portfolio/ownership/dependency views;
- a read-only reusable agent-readiness workflow;
- scheduled public-repository drift reconciliation with one deduplicated issue;
- issue forms and a PR evidence template;
- an explicit administrative hardening gate for branch/ruleset, Actions, bot identity, and break-glass settings.
Source-of-truth boundary
.github owns public organization-level repository purpose, lifecycle, ownership, cross-repository outcomes, decisions, dependency indexes, shared policy, and derived portfolio views.
- Each implementation repository owns its code, component-specific architecture, issues, tests, release evidence, and authoritative runtime/protocol behavior.
- GitHub Projects is an operational view, not a second manually maintained source of truth.
- Private repository inventory and sensitive operational context must not be copied into the public registry.
- No task text, model output, issue field, plan, registry entry, or project column may self-authorize a protected change.
Acceptance criteria
Non-goals
- Reimplementing Familiar Contract, Threads, Psyche, Coven, runtime, SDK, Memory, Cave, or product authority in
.github.
- Publishing private repository names, incident details, credentials, prompts, memories, or user data.
- Treating a green governance check as proof of security, privacy, continuity, interoperability, or legal compliance.
- Automatically deleting, transferring, publishing, or changing repository visibility.
Outcome
Make
OpenCoven/.githubthe canonical public organization governance and portfolio coordination plane while preserving repository-local implementation authority and confidential private-repository context.This issue tracks ratification and activation of the initial governance-plane implementation. Organization metadata coordinates work and records evidence; it does not grant protected OpenCoven identity, authorization, runtime, persistence, release, or publication authority.
Initial implementation
The first implementation slice must include:
Source-of-truth boundary
.githubowns public organization-level repository purpose, lifecycle, ownership, cross-repository outcomes, decisions, dependency indexes, shared policy, and derived portfolio views.Acceptance criteria
./scripts/agent-check fastpasses from a clean clone.Non-goals
.github.