Skip to content

ID-68 — Repo visibility and IP separation: PLAN

ID-68 — Repo visibility and IP separation: PLAN (revised)

Section titled “ID-68 — Repo visibility and IP separation: PLAN (revised)”

{68.4} PLAN artefact — REVISION authored against the ratified {68.2} PRODUCT (S317) + {68.3} TECH (S317, incl. the four recorded design-call ratifications). Supersedes the S291 PLAN in full: that document decomposed the pre-reframe scope into {68.5}{68.10} (now the existing ledger records, retained as-is) and encoded the legacy flip→purge order, reversed by PRODUCT Invariant 36 / Gate 5. This revision re-decomposes against the corrected smaller scope (TARGET-STATE-ARCHITECTURE.md §1/§5): no Invariant 41 collapsed workstream appears below.

  • Task: ID-68 “Repo visibility and IP separation — private→public readiness”
  • Authored: 06/06/2026 (fresh Planner per Q-PLANNER-2 — no carryover from the PRODUCT/TECH Planners).
  • Predecessors: PRODUCT.md (RATIFIED S317 — THE acceptance contract, 42 invariants), TECH.md (RATIFIED S317 — PC-1…42 + §Migration plan Phases 0–6), TARGET-STATE-ARCHITECTURE.md §0.1, DOC-LIFECYCLE-DESIGN.md §4, PRE-FLIP-DEID-PLAN.md ({68.13} — an ARTEFACT label, not a ledger record).
  • Grounded at: canonical-pipeline-setup HEAD 5db5eb88 (06/06/2026). The branch is actively advancing — every fact below was re-verified at that SHA; Executors re-verify at dispatch (that is also Gate 7’s purpose).

Current task-list.json state for ID-68 (verified 06/06/2026):

RecordStatusDisposition in this PLAN
5, 6, 7, 8, 11doneUntouched — their outputs (AC2 inventory, scrubbed scripts, ghcr confirmation, code-scope de-ID) feed the new records.
9 (flip)pending, HELD — Liam GOUntouched record; sequence notes in §6 — gated by the Invariant 38 nine-gate table; executes AFTER the purge per Inv 36.
10 (purge)pending, HELD — LAST, irreversibleUntouched record; sequence notes in §6 — last repo-content mutation; its current dependencies still encode the legacy flip→purge order (correction recommended to the Orchestrator, §6).
12 (relocation carrier)in_progressThe journal home for the S301a relocation work. Its residual scope is absorbed by new records 25/27/28 (§6).

There are no ledger records 1–4 or 13: prose {68.1}{68.4} are spec-chain labels; {68.13} is the PRE-FLIP-DEID-PLAN artefact label. New records number from 14 upward to avoid prose-label collision. New records: 14–30 (17 records; Task total 25 — at the soft cap, see §2).

  • Phase alignment. Subtask ordering mirrors TECH §Migration plan Phases 0–6 one-for-one (§4 map). Phase-0 records (14–20) are immediately dispatchable; 29 is Phase-5/6 prep but dispatchable early.
  • Grouping by file-ownership + PC cluster, not micro-slices. The TECH’s PC clusters are the natural seams: one record per coherent surface (eval lane, bridge, guard-CI, operators, relocation cutover, archive flow). The PC-32/33-F/34/18 de-ID work merges into one sweep record (19) with internal commit slicing (TS → Python/SQL → domain+CLAUDE.md) — it is mechanical string work over one categorised inventory.
  • 25-record soft cap: hit exactly. 8 existing + 17 new = 25. A Task split was considered and rejected: every record feeds the single Invariant 38 gate table — the flip is one acceptance unit, and splitting would force cross-Task Subtask dependencies (the §3.3 forcing function in reverse). Flagged to the Orchestrator.
  • The three Invariant 39 live-tenant items are tracked records (21, 22, 23) per the hard constraint — each carries the staging-first / Liam-sign-off discipline in its details.
  • The three HEAD-drift facts are explicit slices:
    • reference-doc-paths.json exists only on the spec branch (fe071a00/e2bd1e8a) → record 18 (cherry-pick-or-reauthor), which also closes the open PC-19 slice-1 remainder (verified at 5db5eb88: docs/generated/type-drift-report.md still tracked; ast-dataflow-cli.ts:833,840 still writes docs/generated/ — only the baseline root-move landed in 47be7899, which is verify-only).
    • Zero KH_DOCS_DIR consumers on canonical → record 16 introduces KH_PRIVATE_DOCS_DIR name-at-birth with an explicit cherry-pick prohibition on a7e087ee/f81db588 (cited for re-authoring reference only); the Phase-0a consumer surfaces are re-authored under the new name in record 25.
    • De-ID item A is branch-only — canonical still tracks phew.json + the static import (lib/client-config.ts:580,586, re-verified) → record 20 (integrate-or-reauthor the codegen seam) + record 22 (overlay, then untrack).
  • Settled TECH ratifications are baked in, not reopened: PC-31 unified KH_CLIENT_NAME_DENYLIST superset secret (record 15); PC-37 required checks from Phase 0, paid plan (record 15); PC-7 eval-gold/ relocation (record 17); PC-19 gitignored root .type-drift-report.md (record 18).
  • Guard-CI day-one reality operationalised: HEAD still carries identity matches until records 19/21/22/23/27 land, so record 15 seeds its exclusion list from record 14’s sweep inventory (guard enforces “no NEW identity sites” immediately); each de-ID record shrinks the exclusions; record 30 verifies carve-out-only at Gate 4. This is an operationalisation of the ratified “required from day one”, not a spec change.

3. Dependency graph (new records; sibling-only)

Section titled “3. Dependency graph (new records; sibling-only)”
Phase 0 Phase 1 Phase 2
14 sweep+verify ──┬─ 15 guard-CI 24 regenerate-stats deletion
├─ 19 de-ID sweep (cross-Task gate: ID-9.20/9.21)
└─ 29 purge-prep
16 bridge ──┬─ 17 eval split
├─ 23 prompt retirement (LT-iii)
├─ 25 pointer rework (also deps 14, 18)
└─ 26 operator repoint
18 refdoc manifest ── (feeds 25)
20 branding codegen ── 22 overlay + untrack (LT-ii)
21 hook cutover (LT-i; independent)
Phase 3 Phase 4 Phase 5 Phase 6 (Liam GO)
25, 26, 17, 16 ──► 27 cutover ──► 28 archive ──► 30 gate assembly ──► {68.10} purge ──► {68.9} flip
(deps: 15,17,19,21,
22,23,24,27,28,29)
TECH phaseRecordsGate
Phase 0 — immediately dispatchable14, 15, 16, 17, 18, 19, 20 (+29 early-dispatchable)none
Phase 1 — live-tenant (Inv 39)21 (i), 22 (ii), 23 (iii)explicit Liam sign-off before each live half
Phase 2 — ID-9 sequencing window24cross-Task: ID-9.20 + ID-9.21 done (or ID-9.21 acceptance formally amended)
Phase 3 — relocation cutover25, 26, 27bridge proven (16+17 green vs sibling checkout); ledger subset held back
Phase 4 — cold storage28follows 27
Phase 5 — pre-flip assembly29 (prep), 30cross-Task: ID-20 cutover for the Gate-2 ledger release
Phase 6 — irreversible tailexisting 10 (purge), then existing 9 (flip)Liam GO at each step; Inv 36 ordering (§6)

Phase 0 — foundation (parallelisable; no external gates)

Section titled “Phase 0 — foundation (parallelisable; no external gates)”
  • 14 — PC-40 sweep script + first run + Phase-0 verify+record set
  • 15 — identity-guard required check + unified denylist secret widening
  • 16 — KH_PRIVATE_DOCS_DIR bridge helpers (name-at-birth, fail-loud)
  • 17 — eval-lane split (resolver, name-swap → eval-gold/, private homing)
  • 18 — reference-doc-paths manifest + PC-19 slice-1 remainder
  • 19 — HEAD de-ID sweep (PC-32 + PC-18 + PC-33-F + PC-34)
  • 20 — branding codegen map (deploy-overlay seam)

Checkpoint 0: default bun run test + bun build green knob-unset; guard-CI red on seeded violation, green on clean branch; sweep report journalled citing its HEAD SHA.

Phase 1 — live-tenant items (staging-first; Liam-gated live halves)

Section titled “Phase 1 — live-tenant items (staging-first; Liam-gated live halves)”
  • 21 — signup-hook cutover (OQ-G(a); OQ-G(b) stays open)
  • 22 — branding deploy-overlay wired, deployed site verified, THEN untrack
  • 23 — classification-prompt retirement-or-relocation decision + mechanics

Checkpoint 1: AC-E4 staging evidence; AC-E3 deployed branding; Gate-3 prompt disposition journalled.

  • 24 — regenerate-stats lane deletion (one atomic change; bun run knip after)
  • 25 — pointer rework + Phase-0a surface re-authoring + cmux-brief consolidation
  • 26 — operator repoint to docs-site repo + public-side removal
  • 27 — 15-folder disposition execution (holdbacks: ledger subset / OQ-E ontology row / continuation-prompts / test-data)

Checkpoint 3: AC-C3 on a fresh clone, knob unset; git ls-files 'docs/**' = holdback set only; AC-C5 sweep zero dangling refs; AC-B1 space list.

  • 28 — Class-4 archive flow + AC-A4 index verification
  • 29 — purge prep (inventory generator, DRAFT redaction map, runbook)
  • 30 — Invariant 38 gate-artefact assembly + Gate-2 ledger release

Checkpoint 5: every gate row 1–8 has its artefact in the {68.9} journal (AC-F1).

Phase 6 — irreversible tail (existing records; Liam GO at each step)

Section titled “Phase 6 — irreversible tail (existing records; Liam GO at each step)”
  • {68.10} purge — backup → fresh-mirror rewrite → verification clone → force-push → fleet re-clone/re-index (consumes record 29’s artefacts; AC-E2/E5)
  • {68.9} flip — PC-36 all-refs re-verification first; then gh repo edit --visibility public + security-suite enablement (scanning runs over already-cleaned history)

6. Sequence notes for existing records 9 / 10 / 12 (no replacements)

Section titled “6. Sequence notes for existing records 9 / 10 / 12 (no replacements)”
  • {68.10} stays LAST and irreversible among repo-content mutations: it runs only after records 14–30 land and verify, on explicit Liam GO, with the pre-id68-purge mirror backup as mandatory first action (AC-E5).
  • {68.9} is gated by the Invariant 38 nine-gate table — record 30 assembles the artefacts; Gate 9 (Liam GO) is recorded in the ledger journal, never assumed.
  • Ordering correction (Inv 36 / PC-36): history is clean before exposure — the purge + verification clone complete before the flip. The current ledger encodes the legacy order ({68.10}.dependencies includes 9). Recommended Orchestrator ledger action: remove 9 from {68.10}.dependencies; append [10, 30] to {68.9}.dependencies. This PLAN does not perform that mutation.
  • {68.12} (carrier): its residual relocation scope is absorbed by records 25, 27 and 28; recommend the Orchestrator journals this supersession on 12 and closes it once its in-flight work lands.

7. Cross-Task dependency notes (expressed as NOTES, never dependencies[])

Section titled “7. Cross-Task dependency notes (expressed as NOTES, never dependencies[])”
RecordCross-Task gateHandling
24ID-9.20 + ID-9.21 done (or ID-9.21 acceptance formally amended — it asserts the regenerate-stats job runs)Hold blocked until then; STOP-on-breach line in details
25ID-9.21’s atomic CLAUDE.md edit lands firstCLAUDE.md commits sequential, never interleaved; hold the CLAUDE.md commit if ID-9.21 mid-flight
30ID-20 patch-server cutover (Gate 2) before the ledger-subset releaseHold blocked for the release step; other gates assemble meanwhile
23kb_pipeline retirement execution may be owned by the ID-66 Curator carryRecord owns the DECISION + ID-68-side mechanics only; escalate rather than absorb
27Ledger guard tests move with ID-20, not this TaskHoldback encoded in details

8. Negative scope (Invariant 41 — AC-G1 checklist)

Section titled “8. Negative scope (Invariant 41 — AC-G1 checklist)”

This PLAN contains no: third repo as a docs destination; per-space routing matrix; de-ID of reference/runbooks/product-functionality/specs (private — never public); ledger sanitisation-for-public; internal-repo harness build-out (docs-site harness strip is ID-9’s); KH_PUBLIC_REPO_DIR use beyond the record-26 docubot lane (where it is introduced private-side only — zero public-repo occurrences). Invariant 42 boundaries appear only as references/notes (ID-20, ID-69, ID-80.2, workflow review, ID-9 lineage, ID-9.20/9.21).

9. Open-question discipline (none resolved here)

Section titled “9. Open-question discipline (none resolved here)”
  • OQ-E (ontology subset): carried as a ratification-gated conditional row inside record 27; evidence seeded by records 14/30 (form-type-parity.test.ts:32 reads docs/ontology/26-form-type.md — verified at 5db5eb88).
  • OQ-G(b) (seeded legal-name row): noted open in record 21; both dispositions kept alive (supersede-migration vs accept-as-data + history redaction via record 29’s map).
  • OQ-H (redaction map): record 29 supplies the draft only, flagged OPEN; migration-file treatment conditional on OQ-H/OQ-G(b) with a staging supabase db reset replay proof.
  • OQ-A/OQ-B remain boundaries (ID-80.2 / workflow review) — nothing here pre-empts them.

10. Risks (delta over TECH §Risks — which governs)

Section titled “10. Risks (delta over TECH §Risks — which governs)”
RiskMitigation in this decomposition
Guard-CI required-from-day-one reds every PR while HEAD is still dirtyRecord 15’s exclusion-list seed/shrink protocol; record 30 verifies carve-out-only at Gate 4
Fixture move reds default CIRecord 17 ships the eval-fixture-sync rework in the same commit as the moves
Branding loss on client deployUntrack lives inside record 22, hard-sequenced after overlay verification
CLAUDE.md collision with ID-9.21Records 19/25 carry the sequential-commit discipline + hold rules
HEAD drift during the long middleRecord 14’s sweep is scripted/repeatable; record 30 re-runs it citing the SHA (Gate 7)
Live job regenerates deleted artefacts before record 24 landsKnown, bounded — job output is a reviewable PR; reject citing record 24

Canonical TM-shape JSON (17 records, ids 14–30) is returned in the Planner→Orchestrator block for ledger-cli add-subtasks — this PLAN does not write task-list.json. Summary:

idTitleDepsPhase
14Author PC-40 sweep script + run first sweep and Phase-0 verify+record set0
15Stand up identity-guard required check + widen KH_CLIENT_NAME_DENYLIST secret140
16Introduce KH_PRIVATE_DOCS_DIR bridge helpers (name-at-birth, fail-loud)0
17Split eval lane — resolver, public name-swap to eval-gold/, private homing160
18Integrate reference-doc-paths manifest guard + finish PC-19 slice-1 remainder0
19Execute HEAD de-ID sweep — parameterise, synthetic-swap, delete, regenerate140
20Replace static branding map with build-prestep codegen (deploy-overlay seam)0
21Cut over signup-domain hook to generic function (staging-first, Liam-gated)1
22Wire branding deploy-overlay into client deploy, then untrack phew branding201
23Resolve classification-prompt exposure — kb_pipeline retirement or relocation161
24Delete regenerate-stats lane atomically after ID-9.20/9.21 complete— (cross-Task note)2
25Rework docs/ pointers to bridge/private/delete + consolidate cmux-briefs14, 16, 183
26Repoint docs operators to the docs-site repo + remove public-side lane163
27Execute relocation cutover — 15-folder disposition, space check, holdbacks16, 17, 25, 263
28Archive Class-4 corpus to knowledge-hub-archive + verify index isolation274
29Prepare history-purge artefacts — path inventory, draft redaction map, runbook145/6-prep
30Assemble Inv 38 gate artefacts — sweep re-run, Dependabot, ledger release15, 17, 19, 21, 22, 23, 24, 27, 28, 295

Each record’s details carries: the verbatim worktree-first-action line, Implements (TECH PC-refs), PRODUCT invariants covered, spec references, ALLOWED-files boundary, effort estimate, and — for code-touching records — the Inv 2/Inv 3 code-intelligence discipline block (gitnexus_impact before symbol edits with HIGH/CRITICAL stop-and-escalate; gitnexus_detect_changes before commit; ast-dataflow for TS, plain grep for Python/SQL). Docs-only records state the exemption explicitly.