Skip to content

Production hardening backlog: exact official source-file assurance for Waves 5A–5I #143

Description

@hrtechifyed

Purpose

Track future production-grade exact-source assurance for active substantive Waves 5A–5I. This is no longer a blocker for a clearly labelled research-grade prototype release.

Prototype release disposition — 11 Aug 2026

For v0.20.3-prototype.1 and other explicitly labelled research prototypes:

  • structured secondary research with controlled provenance is an accepted source basis;
  • exact official-file verification is supplementary assurance, not a release prerequisite;
  • active legal catalogues remain needs-legal-review;
  • secondary-research provenance must not be presented as official/counsel-approved provenance;
  • draft/research/portal/guidance classifications must remain explicit;
  • deterministic rules remain the product decision authority within the prototype contract;
  • RAG/provider output remains post-decision and explanation-only;
  • Wave 5J and Wave 5M remain outside substantive runtime.

The existing 11 Aug Exact File Reconciliation and the 31 mapped files remain useful audit evidence, but the prototype release does not depend on a runtime migration to those official-file hashes.

Existing supplementary assurance

The canonical Drive Source Register records 31 exact-file matches to existing Source IDs, including SHA-256 from stored bytes, byte length and physical page count. Existing curated source-identity fingerprints were deliberately preserved. One misleading Maharashtra Shops Rules-labelled duplicate was quarantined because it was byte-identical to the Shops Act.

This supplementary evidence must not be interpreted as legal approval or as a requirement to publish the prototype.

Future production-hardening work

Before GrowWithHR is represented as production-grade legal/compliance certification, review each relevant source identity and classify it as one of:

  1. exact controlled official file;
  2. official portal/register snapshot;
  3. guidance/context only;
  4. research-only/not runtime;
  5. intentionally out of scope.

Where exact controlled official-file status is claimed:

  • store the exact original bytes;
  • compute SHA-256 and byte length from those bytes;
  • determine physical page count where applicable;
  • record official URL and controlled storage path;
  • preserve draft/portal/guidance/research distinctions;
  • do not overwrite validated source-identity fingerprints without a separately reviewed source-manifest/catalogue migration;
  • rerun catalogue/source integrity and complete Legal RAG regression after any runtime metadata migration.

Current release effect

Non-blocking for the research-grade prototype. Keep this issue open as a production-hardening backlog. Production certification remains separately governed under #142.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions