DR-129: ast-dataflow public docs are authored fresh; private ledger artefacts do not migrate
Context
Section titled “Context”DR-128 moved the tool’s backlog to tool-repo GitHub issues but said nothing about the documentation set: the id-50 spec family (PRODUCT/TECH/ROADMAP), the id-375/id-377 research and trials, and the sidecar contract (DR-102). The S533 owner board ruled on the full inventory (31 docs: 3 migrate-class, 4 split, 24 stay). Three facts shaped the ruling: two recent sessions leaked client identity into public history; the docs-site ROADMAP was stale twice over and carried a denylist token; and the S533 invariant audit found PRODUCT.md no longer describes the shipped binary (8 invariants broken, 5 reinterpreted without amendment, 3 queries with no invariant — tool-repo issue #7).
Decision
Section titled “Decision”Public-facing ast-dataflow documentation is authored fresh in the tool repo
from measured shipped behaviour — never migrated as files from the docs-site.
Shipped under this ruling: the tool-repo ROADMAP, docs/gap-register.md, and
docs/SIDECAR.md (the DR-102 contract restated on its own authority). The
docs-site artefacts stay private: the id-50 spec family (ROADMAP retired in
place), trials Part 2, the id-375 research set including the market scan, and
the 25-hard-case oracle. Anything crossing the private→public boundary gets a
ledger-identifier + denylist-token scrub and lands as a PR the owner reviews —
the scrub is best-effort by construction (agents cannot hold the private
denylist), so owner review is the gate, not a courtesy. PRODUCT.md (id-50) is
no longer the spec of record; a future public spec is authored fresh against
the shipped envelope (issue #7). The tool repo is licensed Apache-2.0 (S533
owner pick, tool-repo PR #6).
Alternatives Considered
Section titled “Alternatives Considered”- Migrate the files as-is — rejected: stale content (ROADMAP wrong on OPS-T1; PRODUCT.md fails its own invariants) and denylist tokens in the migration path.
- Publish nothing beyond the README — rejected: the README’s “Known caveats” already forward-referenced gap numbers the public could not read, and the sidecar extension point had no public contract.
Consequences
Section titled “Consequences”- Remaining origin-repo identifier residue in the public repo is tracked as
tool-repo issue #10, including the owner-held UNDECIDABLE on whether
bid_projects/bids/feed_articlesare the same leak class. - The docs-site id-50 ROADMAP carries a retirement banner (654483e1); its client token and R-WP12’s six were redacted per the id-115 map.
research/market.mdand the 25-case oracle remain private; revisit only if third-party sidecar demand materialises (S533 board D4/D5).