todo2code

Ticket 049: Validator autonomy audit, operator guide and refactor plan

Goal and scope

Record what still blocks autonomous publication of governed PRs (ticket-048 / PR #66 as the concrete case), publish an operator guide that agents must follow before claiming “autonomy is configured”, and produce a refactor plan that closes the false-positive paths agents take when repo variables exist but the reviewer never runs.

This ticket is documentation and planning only. It does not change executable source, CI, or the external subactor/validator-agent repository. Implementation work is split into sibling tickets (050–052) and, where the code lives outside this repository, into explicit external follow-ups listed in AUTONOMY_AND_REFACTOR_PLAN.md.

Acceptance criteria

Participants

Architecture and bounds

Non-goals

Current blocker snapshot (2026-08-06)

Layer Expected Observed
PR #66 product checks verify, Java, koru green green
PR #66 governance structure GOV-PASS for intent/ticket GOV-PASS
PR #66 GOV-APPROVAL trusted Validator (or human) review on exact head missing — merge BLOCKED
DIRECT_PR_SCAN_ENABLED true true
DIRECT_PR_SCAN_CONFIG includes semcod/todo2code set (complete JSON)
scan-direct on validator-agent main job + matrix leg for todo2code landed via PR #8 merge 95c62a2
Live direct-pr for #66 bot review on head 95a4d91… in flight / flaky (Actions CDN 503, queue pressure)
Trust root reviewer outside reviewed repo preserved
Ticket Role
ticket-048 Active publication of the GitHub event acquisition adapter (PR #66)
ticket-050 Own or explicitly exclude unpublishable root paths
ticket-051 Wire acquisition into CI without ambient env
ticket-052 Operator checklist for external Validator App autonomy

Approval outcome

The user accepted this documentation plan on 2026-08-08. Sibling tickets may now move independently to IN_PROGRESS only after their own scope is approved and their dependency and ownership checks pass.