Skip to content

docs(rfc): propose decision policy governance - #1770

Merged
Teingi merged 4 commits into
oceanbase:masterfrom
AlexStocks:codex/decision-policy-rfc
Oct 9, 2026
Merged

Teingi merged 4 commits into
oceanbase:masterfrom
AlexStocks:codex/decision-policy-rfc

Conversation

@AlexStocks

@AlexStocks AlexStocks commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Which issue or RFC does this PR close?

Refs #1649, #1643, #1644, #1645, #1647, #1648, #1742, and #1745.

This is an RFC-only PR and closes none of those implementation or evaluation issues.

Rationale for this change

The DecisionModel foundation has landed, and several follow-up issues are now exploring narrow gates around Memory, Handoff, Experience, Skill, and conflict detection. Before adding more consumers, PowerContext needs one shared contract for policy identity, shadow/advisory/enforcing modes, audit observations, replay/rescore, privacy boundaries, and promotion criteria.

Hermes-memory research also identifies adjacent recall helpers that are useful only with clear authority boundaries. This RFC now records how query preparation, projection safety, and a non-prompt Context Receipt can support recall without becoming a DecisionModel verdict or changing authoritative evidence.

What changes are included in this PR?

  • Adds docs/en/rfcs/1770-decision-policy-governance.md.
  • Adds the synchronized Chinese version at docs/zh/rfcs/1770-decision-policy-governance.md.
  • Defines DecisionPolicy, DecisionAssessment, and DecisionObservation as design concepts.
  • Separates advisory fail-open gates from non-advisory fail-closed consumers such as RFC 1745 reranking.
  • Requires shadow/audit/replay evidence before promoting a narrow decision policy beyond observation.
  • Defines recall query preparation as an untrusted host/context-boundary transformation: the original query remains authoritative, and timeout, malformed, privacy, or model failures fall back to it.
  • Keeps projection-safety helpers from rewriting authoritative Memory, Source, or Artifact history; refusals remain unadjudicated.
  • Defines an optional, non-prompt Context Receipt sidecar for selected/omitted/truncation and policy outcomes, without adding an API, durable ledger, or raw-content exposure.

Are there any user-facing changes?

No runtime behaviour changes. This PR changes documentation only. It adds no public API, OpenAPI field, persisted schema, dependency, model-provider implementation, query rewriter, projection filter, or Context Receipt persistence.

How was this change tested?

  • git diff --check passed.
  • The synchronized RFC files have 39 Markdown headings each.
  • Every local Markdown RFC link referenced by each RFC resolves.
  • uv run --no-sync prek run --files docs/en/rfcs/1770-decision-policy-governance.md docs/zh/rfcs/1770-decision-policy-governance.md passed Markdown and whitespace hooks, then reached global ty check, which reported 32 existing Windows Unix-only diagnostics in src/powercontext/builtin/code/* and related tests, outside these Markdown files.
  • pnpm lint and pnpm test passed (11/11).
  • pnpm verify:export passed after the static build: 879 public pages and their internal links were verified (109 HTTP API, 426 Python API, 96 RFC, 23 development).
  • make docs-test remains unavailable on this host because its Git Bash shell does not resolve Windows pnpm.cmd; the direct pnpm commands above were used instead.

AI usage statement

Implemented with OpenAI Codex in the Codex desktop app, based on the Hermes/Jev/Laya/OpenClaw investigation notes and repository-local RFC/PR inspection.

Define the shared policy, shadow, audit, replay, and promotion contract for narrow DecisionModel gates before implementing additional consumers.
Rename the decision policy governance RFC files to match PR oceanbase#1770 and update the RFC PR metadata links.
AlexStocks and others added 2 commits October 9, 2026 14:20
Lore: Keep query rewriting, projection safety, and context receipts outside DecisionModel authority while requiring replayable shadow evidence before activation.

Constraint: Preserve Scope resolution, authorization, Artifact history, and domain authority; this RFC-only change adds no runtime API or provider implementation.

Tested: git diff --check; bilingual heading and local RFC-link checks; website lint and 11 tests; static export verification of 879 public pages and internal links.

Not-tested: prek reaches pre-existing Windows Unix-only ty diagnostics outside the changed Markdown files.

Co-authored-by: OmX <omx@oh-my-codex.dev>
@Teingi
Teingi merged commit 13c0144 into oceanbase:master Oct 9, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant