ID-68 — Repo visibility and IP separation: PLAN
ID-68 — Repo visibility and IP separation: PLAN (revised)
Section titled “ID-68 — Repo visibility and IP separation: PLAN (revised)”{68.4} PLAN artefact — REVISION authored against the ratified {68.2} PRODUCT
(S317) + {68.3} TECH (S317, incl. the four recorded design-call ratifications).
Supersedes the S291 PLAN in full: that document decomposed the pre-reframe scope into
{68.5}–{68.10} (now the existing ledger records, retained as-is) and encoded the
legacy flip→purge order, reversed by PRODUCT Invariant 36 / Gate 5. This revision
re-decomposes against the corrected smaller scope (TARGET-STATE-ARCHITECTURE.md §1/§5):
no Invariant 41 collapsed workstream appears below.
- Task: ID-68 “Repo visibility and IP separation — private→public readiness”
- Authored: 06/06/2026 (fresh Planner per Q-PLANNER-2 — no carryover from the PRODUCT/TECH Planners).
- Predecessors:
PRODUCT.md(RATIFIED S317 — THE acceptance contract, 42 invariants),TECH.md(RATIFIED S317 — PC-1…42 + §Migration plan Phases 0–6),TARGET-STATE-ARCHITECTURE.md§0.1,DOC-LIFECYCLE-DESIGN.md§4,PRE-FLIP-DEID-PLAN.md({68.13}— an ARTEFACT label, not a ledger record). - Grounded at:
canonical-pipeline-setupHEAD5db5eb88(06/06/2026). The branch is actively advancing — every fact below was re-verified at that SHA; Executors re-verify at dispatch (that is also Gate 7’s purpose).
1. Ledger reconciliation
Section titled “1. Ledger reconciliation”Current task-list.json state for ID-68 (verified 06/06/2026):
| Record | Status | Disposition in this PLAN |
|---|---|---|
| 5, 6, 7, 8, 11 | done | Untouched — their outputs (AC2 inventory, scrubbed scripts, ghcr confirmation, code-scope de-ID) feed the new records. |
| 9 (flip) | pending, HELD — Liam GO | Untouched record; sequence notes in §6 — gated by the Invariant 38 nine-gate table; executes AFTER the purge per Inv 36. |
| 10 (purge) | pending, HELD — LAST, irreversible | Untouched record; sequence notes in §6 — last repo-content mutation; its current dependencies still encode the legacy flip→purge order (correction recommended to the Orchestrator, §6). |
| 12 (relocation carrier) | in_progress | The journal home for the S301a relocation work. Its residual scope is absorbed by new records 25/27/28 (§6). |
There are no ledger records 1–4 or 13: prose {68.1}–{68.4} are spec-chain
labels; {68.13} is the PRE-FLIP-DEID-PLAN artefact label. New records number from
14 upward to avoid prose-label collision. New records: 14–30 (17 records; Task
total 25 — at the soft cap, see §2).
2. Decomposition decisions
Section titled “2. Decomposition decisions”- Phase alignment. Subtask ordering mirrors TECH §Migration plan Phases 0–6 one-for-one (§4 map). Phase-0 records (14–20) are immediately dispatchable; 29 is Phase-5/6 prep but dispatchable early.
- Grouping by file-ownership + PC cluster, not micro-slices. The TECH’s PC clusters are the natural seams: one record per coherent surface (eval lane, bridge, guard-CI, operators, relocation cutover, archive flow). The PC-32/33-F/34/18 de-ID work merges into one sweep record (19) with internal commit slicing (TS → Python/SQL → domain+CLAUDE.md) — it is mechanical string work over one categorised inventory.
- 25-record soft cap: hit exactly. 8 existing + 17 new = 25. A Task split was considered and rejected: every record feeds the single Invariant 38 gate table — the flip is one acceptance unit, and splitting would force cross-Task Subtask dependencies (the §3.3 forcing function in reverse). Flagged to the Orchestrator.
- The three Invariant 39 live-tenant items are tracked records (21, 22, 23) per the
hard constraint — each carries the staging-first / Liam-sign-off discipline in its
details. - The three HEAD-drift facts are explicit slices:
reference-doc-paths.jsonexists only on the spec branch (fe071a00/e2bd1e8a) → record 18 (cherry-pick-or-reauthor), which also closes the open PC-19 slice-1 remainder (verified at5db5eb88:docs/generated/type-drift-report.mdstill tracked;ast-dataflow-cli.ts:833,840still writesdocs/generated/— only the baseline root-move landed in47be7899, which is verify-only).- Zero
KH_DOCS_DIRconsumers on canonical → record 16 introducesKH_PRIVATE_DOCS_DIRname-at-birth with an explicit cherry-pick prohibition ona7e087ee/f81db588(cited for re-authoring reference only); the Phase-0a consumer surfaces are re-authored under the new name in record 25. - De-ID item A is branch-only — canonical still tracks
phew.json+ the static import (lib/client-config.ts:580,586, re-verified) → record 20 (integrate-or-reauthor the codegen seam) + record 22 (overlay, then untrack).
- Settled TECH ratifications are baked in, not reopened: PC-31 unified
KH_CLIENT_NAME_DENYLISTsuperset secret (record 15); PC-37 required checks from Phase 0, paid plan (record 15); PC-7eval-gold/relocation (record 17); PC-19 gitignored root.type-drift-report.md(record 18). - Guard-CI day-one reality operationalised: HEAD still carries identity matches until records 19/21/22/23/27 land, so record 15 seeds its exclusion list from record 14’s sweep inventory (guard enforces “no NEW identity sites” immediately); each de-ID record shrinks the exclusions; record 30 verifies carve-out-only at Gate 4. This is an operationalisation of the ratified “required from day one”, not a spec change.
3. Dependency graph (new records; sibling-only)
Section titled “3. Dependency graph (new records; sibling-only)”Phase 0 Phase 1 Phase 214 sweep+verify ──┬─ 15 guard-CI 24 regenerate-stats deletion ├─ 19 de-ID sweep (cross-Task gate: ID-9.20/9.21) └─ 29 purge-prep16 bridge ──┬─ 17 eval split ├─ 23 prompt retirement (LT-iii) ├─ 25 pointer rework (also deps 14, 18) └─ 26 operator repoint18 refdoc manifest ── (feeds 25)20 branding codegen ── 22 overlay + untrack (LT-ii)21 hook cutover (LT-i; independent)
Phase 3 Phase 4 Phase 5 Phase 6 (Liam GO)25, 26, 17, 16 ──► 27 cutover ──► 28 archive ──► 30 gate assembly ──► {68.10} purge ──► {68.9} flip (deps: 15,17,19,21, 22,23,24,27,28,29)4. Phase → subtask map
Section titled “4. Phase → subtask map”| TECH phase | Records | Gate |
|---|---|---|
| Phase 0 — immediately dispatchable | 14, 15, 16, 17, 18, 19, 20 (+29 early-dispatchable) | none |
| Phase 1 — live-tenant (Inv 39) | 21 (i), 22 (ii), 23 (iii) | explicit Liam sign-off before each live half |
| Phase 2 — ID-9 sequencing window | 24 | cross-Task: ID-9.20 + ID-9.21 done (or ID-9.21 acceptance formally amended) |
| Phase 3 — relocation cutover | 25, 26, 27 | bridge proven (16+17 green vs sibling checkout); ledger subset held back |
| Phase 4 — cold storage | 28 | follows 27 |
| Phase 5 — pre-flip assembly | 29 (prep), 30 | cross-Task: ID-20 cutover for the Gate-2 ledger release |
| Phase 6 — irreversible tail | existing 10 (purge), then existing 9 (flip) | Liam GO at each step; Inv 36 ordering (§6) |
5. Task list with checkpoints
Section titled “5. Task list with checkpoints”Phase 0 — foundation (parallelisable; no external gates)
Section titled “Phase 0 — foundation (parallelisable; no external gates)”- 14 — PC-40 sweep script + first run + Phase-0 verify+record set
- 15 — identity-guard required check + unified denylist secret widening
- 16 —
KH_PRIVATE_DOCS_DIRbridge helpers (name-at-birth, fail-loud) - 17 — eval-lane split (resolver, name-swap →
eval-gold/, private homing) - 18 — reference-doc-paths manifest + PC-19 slice-1 remainder
- 19 — HEAD de-ID sweep (PC-32 + PC-18 + PC-33-F + PC-34)
- 20 — branding codegen map (deploy-overlay seam)
Checkpoint 0: default bun run test + bun build green knob-unset; guard-CI red
on seeded violation, green on clean branch; sweep report journalled citing its HEAD SHA.
Phase 1 — live-tenant items (staging-first; Liam-gated live halves)
Section titled “Phase 1 — live-tenant items (staging-first; Liam-gated live halves)”- 21 — signup-hook cutover (OQ-G(a); OQ-G(b) stays open)
- 22 — branding deploy-overlay wired, deployed site verified, THEN untrack
- 23 — classification-prompt retirement-or-relocation decision + mechanics
Checkpoint 1: AC-E4 staging evidence; AC-E3 deployed branding; Gate-3 prompt disposition journalled.
Phase 2 — ID-9 sequencing window
Section titled “Phase 2 — ID-9 sequencing window”- 24 — regenerate-stats lane deletion (one atomic change;
bun run knipafter)
Phase 3 — relocation cutover
Section titled “Phase 3 — relocation cutover”- 25 — pointer rework + Phase-0a surface re-authoring + cmux-brief consolidation
- 26 — operator repoint to docs-site repo + public-side removal
- 27 — 15-folder disposition execution (holdbacks: ledger subset / OQ-E ontology row / continuation-prompts / test-data)
Checkpoint 3: AC-C3 on a fresh clone, knob unset; git ls-files 'docs/**' =
holdback set only; AC-C5 sweep zero dangling refs; AC-B1 space list.
Phase 4 — cold storage
Section titled “Phase 4 — cold storage”- 28 — Class-4 archive flow + AC-A4 index verification
Phase 5 — pre-flip assembly
Section titled “Phase 5 — pre-flip assembly”- 29 — purge prep (inventory generator, DRAFT redaction map, runbook)
- 30 — Invariant 38 gate-artefact assembly + Gate-2 ledger release
Checkpoint 5: every gate row 1–8 has its artefact in the {68.9} journal (AC-F1).
Phase 6 — irreversible tail (existing records; Liam GO at each step)
Section titled “Phase 6 — irreversible tail (existing records; Liam GO at each step)”-
{68.10}purge — backup → fresh-mirror rewrite → verification clone → force-push → fleet re-clone/re-index (consumes record 29’s artefacts; AC-E2/E5) -
{68.9}flip — PC-36 all-refs re-verification first; thengh repo edit --visibility public+ security-suite enablement (scanning runs over already-cleaned history)
6. Sequence notes for existing records 9 / 10 / 12 (no replacements)
Section titled “6. Sequence notes for existing records 9 / 10 / 12 (no replacements)”{68.10}stays LAST and irreversible among repo-content mutations: it runs only after records 14–30 land and verify, on explicit Liam GO, with thepre-id68-purgemirror backup as mandatory first action (AC-E5).{68.9}is gated by the Invariant 38 nine-gate table — record 30 assembles the artefacts; Gate 9 (Liam GO) is recorded in the ledger journal, never assumed.- Ordering correction (Inv 36 / PC-36): history is clean before exposure — the
purge + verification clone complete before the flip. The current ledger encodes
the legacy order (
{68.10}.dependenciesincludes 9). Recommended Orchestrator ledger action: remove 9 from{68.10}.dependencies; append[10, 30]to{68.9}.dependencies. This PLAN does not perform that mutation. {68.12}(carrier): its residual relocation scope is absorbed by records 25, 27 and 28; recommend the Orchestrator journals this supersession on 12 and closes it once its in-flight work lands.
7. Cross-Task dependency notes (expressed as NOTES, never dependencies[])
Section titled “7. Cross-Task dependency notes (expressed as NOTES, never dependencies[])”| Record | Cross-Task gate | Handling |
|---|---|---|
| 24 | ID-9.20 + ID-9.21 done (or ID-9.21 acceptance formally amended — it asserts the regenerate-stats job runs) | Hold blocked until then; STOP-on-breach line in details |
| 25 | ID-9.21’s atomic CLAUDE.md edit lands first | CLAUDE.md commits sequential, never interleaved; hold the CLAUDE.md commit if ID-9.21 mid-flight |
| 30 | ID-20 patch-server cutover (Gate 2) before the ledger-subset release | Hold blocked for the release step; other gates assemble meanwhile |
| 23 | kb_pipeline retirement execution may be owned by the ID-66 Curator carry | Record owns the DECISION + ID-68-side mechanics only; escalate rather than absorb |
| 27 | Ledger guard tests move with ID-20, not this Task | Holdback encoded in details |
8. Negative scope (Invariant 41 — AC-G1 checklist)
Section titled “8. Negative scope (Invariant 41 — AC-G1 checklist)”This PLAN contains no: third repo as a docs destination; per-space routing matrix;
de-ID of reference/runbooks/product-functionality/specs (private — never public);
ledger sanitisation-for-public; internal-repo harness build-out (docs-site harness
strip is ID-9’s); KH_PUBLIC_REPO_DIR use beyond the record-26 docubot lane (where it
is introduced private-side only — zero public-repo occurrences). Invariant 42
boundaries appear only as references/notes (ID-20, ID-69, ID-80.2, workflow review,
ID-9 lineage, ID-9.20/9.21).
9. Open-question discipline (none resolved here)
Section titled “9. Open-question discipline (none resolved here)”- OQ-E (ontology subset): carried as a ratification-gated conditional row inside
record 27; evidence seeded by records 14/30 (
form-type-parity.test.ts:32readsdocs/ontology/26-form-type.md— verified at5db5eb88). - OQ-G(b) (seeded legal-name row): noted open in record 21; both dispositions kept alive (supersede-migration vs accept-as-data + history redaction via record 29’s map).
- OQ-H (redaction map): record 29 supplies the draft only, flagged OPEN;
migration-file treatment conditional on OQ-H/OQ-G(b) with a staging
supabase db resetreplay proof. - OQ-A/OQ-B remain boundaries (ID-80.2 / workflow review) — nothing here pre-empts them.
10. Risks (delta over TECH §Risks — which governs)
Section titled “10. Risks (delta over TECH §Risks — which governs)”| Risk | Mitigation in this decomposition |
|---|---|
| Guard-CI required-from-day-one reds every PR while HEAD is still dirty | Record 15’s exclusion-list seed/shrink protocol; record 30 verifies carve-out-only at Gate 4 |
| Fixture move reds default CI | Record 17 ships the eval-fixture-sync rework in the same commit as the moves |
| Branding loss on client deploy | Untrack lives inside record 22, hard-sequenced after overlay verification |
| CLAUDE.md collision with ID-9.21 | Records 19/25 carry the sequential-commit discipline + hold rules |
| HEAD drift during the long middle | Record 14’s sweep is scripted/repeatable; record 30 re-runs it citing the SHA (Gate 7) |
| Live job regenerates deleted artefacts before record 24 lands | Known, bounded — job output is a reviewable PR; reject citing record 24 |
11. Subtask records
Section titled “11. Subtask records”Canonical TM-shape JSON (17 records, ids 14–30) is returned in the Planner→Orchestrator
block for ledger-cli add-subtasks — this PLAN does not write task-list.json.
Summary:
| id | Title | Deps | Phase |
|---|---|---|---|
| 14 | Author PC-40 sweep script + run first sweep and Phase-0 verify+record set | — | 0 |
| 15 | Stand up identity-guard required check + widen KH_CLIENT_NAME_DENYLIST secret | 14 | 0 |
| 16 | Introduce KH_PRIVATE_DOCS_DIR bridge helpers (name-at-birth, fail-loud) | — | 0 |
| 17 | Split eval lane — resolver, public name-swap to eval-gold/, private homing | 16 | 0 |
| 18 | Integrate reference-doc-paths manifest guard + finish PC-19 slice-1 remainder | — | 0 |
| 19 | Execute HEAD de-ID sweep — parameterise, synthetic-swap, delete, regenerate | 14 | 0 |
| 20 | Replace static branding map with build-prestep codegen (deploy-overlay seam) | — | 0 |
| 21 | Cut over signup-domain hook to generic function (staging-first, Liam-gated) | — | 1 |
| 22 | Wire branding deploy-overlay into client deploy, then untrack phew branding | 20 | 1 |
| 23 | Resolve classification-prompt exposure — kb_pipeline retirement or relocation | 16 | 1 |
| 24 | Delete regenerate-stats lane atomically after ID-9.20/9.21 complete | — (cross-Task note) | 2 |
| 25 | Rework docs/ pointers to bridge/private/delete + consolidate cmux-briefs | 14, 16, 18 | 3 |
| 26 | Repoint docs operators to the docs-site repo + remove public-side lane | 16 | 3 |
| 27 | Execute relocation cutover — 15-folder disposition, space check, holdbacks | 16, 17, 25, 26 | 3 |
| 28 | Archive Class-4 corpus to knowledge-hub-archive + verify index isolation | 27 | 4 |
| 29 | Prepare history-purge artefacts — path inventory, draft redaction map, runbook | 14 | 5/6-prep |
| 30 | Assemble Inv 38 gate artefacts — sweep re-run, Dependabot, ledger release | 15, 17, 19, 21, 22, 23, 24, 27, 28, 29 | 5 |
Each record’s details carries: the verbatim worktree-first-action line, Implements
(TECH PC-refs), PRODUCT invariants covered, spec references, ALLOWED-files boundary,
effort estimate, and — for code-touching records — the Inv 2/Inv 3 code-intelligence
discipline block (gitnexus_impact before symbol edits with HIGH/CRITICAL
stop-and-escalate; gitnexus_detect_changes before commit; ast-dataflow for TS, plain
grep for Python/SQL). Docs-only records state the exemption explicitly.