The user wants new-project to control the operating logic of both humans and
agents rather than merely describe it. A multi-step change must have auditable
intent, bounded scope and acceptance criteria in a target-repository ticket
before implementation. Once a ticket is complete, the next change receives the
next ticket number. Follow-up work reuses an unfinished ticket. Human-owned
participant files remain outside agent control.
The enforcement model needs layered trust: fast local feedback, deterministic
CI policy checks, stack-specific verification and repository rules that prevent
merging around those checks. todo2code can compare declared intent with the
actual diff, but offline deterministic output—not an LLM response—must decide
the required gate.
The follow-up request extends this model for concurrent agents whose local intentions may diverge but compose into a larger long-term capability. The project should not be split into repositories yet. Instead, the governance contract will model independent workstreams, non-overlapping write scopes and a ticket dependency DAG. Divergence that changes a shared contract is routed to an explicit integration ticket and fresh approval; it is never absorbed by retroactively widening one agent’s scope.
The current follow-up asks Koru to provide automated code review. This is a
read-only second-AI boundary: Koru orchestrates pinned Vallm checks for the
exact PR diff, produces a commit-bound attested report, and exposes a required
GitHub status. It may reject a change but may not edit it, push it or impersonate
a human APPROVE review.
The newest follow-up addresses the cause of repeated integration friction: work was path-scoped, but not bounded by delivery time, component count, interface risk or an accepted base SHA. The central standard should make one ticket/PR a single independently testable slice that fits within 30 minutes. Architecture, UI states, rollback and validation evidence are decided before coding. Crossing the time, outcome, workstream or contract boundary stops the slice and creates an explicit dependency instead of growing the current diff.
Current verified baseline:
29.1.3.ticket-017 is DONE, so project/new-ticket.sh correctly created
ticket-018 in PLAN / WAIT_FOR_APPROVAL.todo2code match the Governance Hub by SHA-256,
but are not yet published in the current HEAD;todo2code CI tests the application and optional live provider,
but has no governance job and no persistent AGENTS.md;unresolved:human.todo2code: add .governance/, a
persistent AGENTS.md, local commands and the required CI integration.todo2code intent-vs-diff analysis as an additional
gate or evidence producer; keep live LLM checks advisory/opt-in.PLAN / WAIT_FOR_APPROVAL for the multi-workstream scope
evolution before changing schemas, validators, CI or documentation. The
user explicitly approved AC-11..AC-17 in chat; transition to EDIT.todo2code and prove parallel non-overlap plus rejected overlap.PLAN / WAIT_FOR_APPROVAL for the Koru review extension before
changing workflows or external rules; record AC-18..AC-25 and the current
tool/secret/ruleset baseline.pull_request plus workflow_dispatch workflow with
stable check name koru / code-review, exact base/head resolution and
immutable action/tool pins.main ruleset requiring governance and Koru review only after
the check exists; verify direct pushes and stale evidence are rejected.WAIT_FOR_APPROVAL for AC-26..AC-35; change no central or target
policy/implementation files until the bounded-delivery plan is approved.wellmanifest/new-project, add manifest and intent contracts for one
outcome, accepted base SHA, XS|S/30-minute budget, architecture impact,
rollback, UI risk and criterion-specific validation evidence.todo2code governance files and
AGENTS.md, without changing application source or absorbing unrelated
active PRs or tickets.ticket-018 and updated the project-level
ticket index/checklist. No implementation, source, test or CI file was
changed for ticket-018.wellmanifest/new-project 0.7.0 policy-as-code: versioned
manifest/intent schemas, diagnostic catalog, stack profiles, dependency-light
validator, wrappers, safe project.sh entry point, fixture suite, reusable
workflow and enforcement documentation.intent.json before code.todo2code through .governance/, SHA-256 lock,
AGENTS.md, Make/preflight commands and the governance / enforce CI job.user-*.md file.new-project 0.8.0 workstream coordination, intent v2,
dependency/conflict/integration validation, 27-code catalog coverage,
multi-active CI routing and manager/developer/two-AI operating guidance.todo2code and synchronized the managed
validator, schemas, diagnostics and scaffolder with updated SHA-256 lock
evidence.sdk workstream. It is
non-overlapping and remains untouched; the final whole-workspace gate accepts
ticket-018 (governance) and ticket-019 (sdk) as parallel PLAN/VALIDATION
records while routing this implementation diff uniquely to ticket-018.06a2faa. No workflow, source,
test, external ruleset or human-owned file was changed in this plan phase..github/workflows/koru-code-review.yml with
immutable action pins, exact base/head selection, changed-source filtering,
one Koru/Vallm round, fail-closed credential handling, structured evidence,
bounded artifact retention and GitHub provenance attestation. The job is
read-only with respect to repository contents and cannot approve or mutate a
pull request.30703292661. Koru/Vallm rejected two TypeScript files and propagated a
failing required check while preserving an attested, commit-bound report.20186914 with no bypass actors, strict governance
and Koru status checks, mandatory pull requests, stale-evidence dismissal and
force-push/deletion prevention. It remains disabled solely for the final
bootstrap evidence merge and will be activated afterward.pytest for a
TypeScript diff and received OpenRouter 401. Updated the semantic judge to
benchmark-qualified Gemini 3.1 Pro Preview, left regression ownership with
the required Node verify job, and did not read or overwrite the external
Actions secret.30714664770 reached
Gemini with no credential/provider error and returned pass for both files;
aggregate enforcement still rejected the parser warning and advisory
whole-file findings. No secret value was read back or logged.30746421293 then passed the exact pull request #3 range in 1 minute
24 seconds. The attested Gemini report records both expected files, 2/2 pass,
zero blocking/parser/provider findings and all five semantic observations as
advisory; its final Koru exit is 0 while preserving Vallm’s original exit 2.todo2code/AGENTS.md is an adoption
of wellmanifest/new-project policy and template material. No central policy,
schema, validator, template, workflow, ruleset or application file changed in
this plan phase.1ae86a1. Kept enforcement disabled only for migration because applying the
five-file hard limit retroactively to the accumulated ticket-018 branch would
make the standard reject its own bootstrap. No application file changed.test/cli*.test.ts is owned by test/cli* without treating
unrelated test/mcp*.test.ts as owned; this removed the false ticket-020
workstream finding.npm run verify passes all deterministic checks and 334/335 tests with
one JDK skip. Docker e2e-core passes 328/335 tests with seven expected
toolchain skips, both gold datasets, CLI, MCP, A2A and examples. Docker
e2e-full independently reproduces the out-of-scope stale Rust lock failure
at cargo fetch --locked with exit 101.main@c0bb63e and
feat/bounded-delivery-contract@1ae86a1 expose different contracts under the
same 0.9.0 version. Direct copying from either branch would therefore lose
either safe adoption/lifecycle semantics or bounded delivery.0.10.0; no managed governance file has been changed for this
follow-up yet.openrouter/google/gemini-3.1-pro-preview to
openrouter/z-ai/glm-5.2. Historical Gemini reports remain audit evidence
and will not be rewritten as if GLM produced them.IN_PROGRESS / EDIT before managed governance or workflow implementation.REVIEW_MODEL with
openrouter/z-ai/glm-5.2; retained historical Gemini evidence and made no
provider request.npm run verify passes: 335 tests, 334 passed, zero failed and one explicit
JDK skip. make governance, workflow YAML and diff checks pass.BLOCKED / VALIDATION rather than generating a false published
lock or self-approving the governance source SHA.--check against PR head e0a8e5c... stopped before writes on the
expected 0.9.0 -> 0.10.0 target-manifest version precondition. The explicit
upgrade must update that local contract only after the source SHA is trusted.ifuri-validator-agent[bot]
for exact head 346895b... and merged as published commit 5267cf3....
Resumed the approved target adoption in IN_PROGRESS / EDIT; the lock will
bind to the merge commit rather than the former review branch or PR head.IN_PROGRESS is active, while PLAN, BACKLOG and BLOCKED are
explicitly non-active. GitHub App review is a configured trusted source with
exact repository/PR/head/ticket/actor bindings.--check, target governance, workflow YAML, full npm run verify
(334 passed, one JDK skip) and Docker smoke. No live LLM request was made.30934859353 used GLM 5.2 and produced an attested
fail-closed report with semantic.parse_error: Vallm requested JSON only in
prose, not through the provider response contract. Reopened AC-39/AC-40 and
will constrain the existing compatibility boundary to JSON output with
optional reasoning disabled, then require a successful exact-head rerun.a01816b identified two approval-evidence hardening
concerns. Confirmed the trust-projection concern and treated the path-race
concern as defence-in-depth instead of merging on a formal approval alone.wellmanifest/new-project ticket-005 and PR #4;
exact reviewed head 898041d merged as 9706e63 after both hosted CI runs.9706e63 into the target lock and replaced the local duplicated
approval resolver with the reusable workflow from the same SHA.
TRUSTED_VALIDATOR_APPS is now a protected repository variable containing
the exact App login; the PR cannot expand its own authority set.30937911350
approved exact target head d716c6e, protected governance passed, and PR #4
merged as 6ad85bd. Post-merge CI 30938509879 is green.GOV-INTENT-003: concurrent commit 5f1f4bd placed the ticket intent and
implementation in the same commit; correcting this requires an authorized
history/commit split.GOV-SCOPE-001: the same commit contains eight implementation/generated
paths not allowed by ticket-018. They must be routed to their actual ticket,
not retroactively claimed here.new-project 0.9.0 is pinned at 1ae86a1 and the exact commit is
published on origin/feat/bounded-delivery-contract; it remains unmerged on
upstream main, so it is evidence for a remote branch, not a released tag.9928699 bumped the Rust SDK manifest to 0.5.1, but
the ignored local Cargo lock still identifies the root package as 0.5.0.
Official full Docker E2E fails closed at cargo fetch --locked (exit 101).
Fixing or tracking that lock is an sdk/integration change outside this
ticket’s approved governance workstream.IN_PROGRESS / VALIDATION for AC-26..AC-35.unresolved:human.