Skip to content

P0: Ratify and activate the OpenCoven organization governance plane #5

Description

@BunsDev

Outcome

Make OpenCoven/.github the canonical public organization governance and portfolio coordination plane while preserving repository-local implementation authority and confidential private-repository context.

This issue tracks ratification and activation of the initial governance-plane implementation. Organization metadata coordinates work and records evidence; it does not grant protected OpenCoven identity, authorization, runtime, persistence, release, or publication authority.

Initial implementation

The first implementation slice must include:

  • an accepted organization-governance ADR;
  • a machine-readable public repository registry and unique canonical-domain ownership checks;
  • repository lifecycle, retirement, exception, public/private-data, and agent-authored-change policies;
  • cross-repository initiative records with explicit decision owner, technical DRI, workstreams, dependencies, and exit criteria;
  • machine-readable controls and evidence schemas;
  • deterministic validation and generated portfolio/ownership/dependency views;
  • a read-only reusable agent-readiness workflow;
  • scheduled public-repository drift reconciliation with one deduplicated issue;
  • issue forms and a PR evidence template;
  • an explicit administrative hardening gate for branch/ruleset, Actions, bot identity, and break-glass settings.

Source-of-truth boundary

  • .github owns public organization-level repository purpose, lifecycle, ownership, cross-repository outcomes, decisions, dependency indexes, shared policy, and derived portfolio views.
  • Each implementation repository owns its code, component-specific architecture, issues, tests, release evidence, and authoritative runtime/protocol behavior.
  • GitHub Projects is an operational view, not a second manually maintained source of truth.
  • Private repository inventory and sensitive operational context must not be copied into the public registry.
  • No task text, model output, issue field, plan, registry entry, or project column may self-authorize a protected change.

Acceptance criteria

  • Governance-plane PR is reviewed and merged.
  • Deterministic ./scripts/agent-check fast passes from a clean clone.
  • Generated portfolio outputs match the registry exactly.
  • Every current public repository is either registered or reported as drift.
  • Duplicate canonical ownership, unowned active repositories, invalid successors, expired exceptions, unpinned Actions, and stale generated files fail CI.
  • The public/private boundary is documented and enforced by validation.
  • The administrative hardening issue is completed before the registry is relied on for protected repository-administration decisions.
  • Initial pilot repositories consume the reusable workflow at an immutable revision.
  • Existing duplicate planning surfaces are linked, migrated, or explicitly deprecated.

Non-goals

  • Reimplementing Familiar Contract, Threads, Psyche, Coven, runtime, SDK, Memory, Cave, or product authority in .github.
  • Publishing private repository names, incident details, credentials, prompts, memories, or user data.
  • Treating a green governance check as proof of security, privacy, continuity, interoperability, or legal compliance.
  • Automatically deleting, transferring, publishing, or changing repository visibility.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions