Design Ohio government data coverage #53
No reviewers
Labels
No labels
bug
design
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
nsaspy/starintel-auto-research!53
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "design/ohio-government-data-catalog"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Consolidated scope
This PR now targets
maindirectly and contains the complete former #48 → #52 → #53 stack. PRs #48 and #52 are superseded once this aggregate PR is verified.Summary
39049) as the first complete pilotNormative protocol set
The government-data runtime protocol is reviewed as one set:
STAR-RESEARCH-PIPELINE-003 Government Data Acquisition ActorsSTAR-RESEARCH-PIPELINE-004 Government Data Revision Protocol AmendmentSTAR-RESEARCH-PIPELINE-004A Government Data Delivery and Identity ClarificationThe envelope remains
star.government-data.v1.1.PIPELINE-004Anormatively resolves the remaining cross-document mismatches without creating another envelope version.Identity and review model
Evidence-delivery model
The normative retained-artifact sequence is:
Results and checkpoints expose delivery-intent IDs and acknowledged/pending delivery-step keys.
Completion gates
A jurisdiction reaches
DONEonly through a current, independently reviewed, passedjurisdiction-completiongate. The gate includes a canonical basis hash, freshness deadline, andvalid-through.Current completion becomes false immediately after:
valid-throughpassesHistorical gates remain immutable and replayable.
Validation
The
Government Data Designworkflow runs entirely offline and verifies:derived-gate-assertionNo source, county, design, or implementation state is marked complete or approved by this PR.
Merge gate
Merge only when:
mainFull review — changes required before merge
The Ohio design pack has a strong bounded-actor and evidence-first foundation, but it is not merge-ready.
Blocking issues
4449825. Run the repository validation or document why these design paths do not trigger CI.Required before merge
Recommended follow-ups
Add a shared source-deployment/tenant record, structured jurisdiction and record-type coverage scope, a bounded OCR/manual-review outcome, and reproducible browser evidence beyond screenshot metadata.
Disposition: changes required before merge. GitHub does not allow the PR author to submit
REQUEST_CHANGESon their own PR, so this is posted as a comment review with blocking inline threads.@ -0,0 +1,178 @@:PROPERTIES:Assessedis too weak for an end-to-end pilot exit gate. This currently allows all sixteen routes to remain candidate, ambiguous, blocked, or unreviewed and still pass. Define the minimum allowed reviewed terminal state per route, require applicability decisions for missing county functions, and require exact profile revisions/search plans/gaps to be bound into the pilot decision.The set is useful demographically but overweights metro counties and does not prove platform or organizational diversity. Make this list provisional until Wave 0 fingerprinting, then select counties to maximize vendor/platform family, official-versus-delegated hosting, publication maturity, independent-office fragmentation, shared/regional services, court/health topology, geography, and size. Include an explicit mid-sized non-metro or western agricultural case unless fingerprint evidence shows the current set covers it.
Full historical acquisition can remain Wave 5, but historical identity cannot be deferred this late. Every earlier discovery/profile wave should record predecessor locators, successor relationships, archive candidates, first/last observed dates, and immediately visible coverage boundaries. Otherwise ownership verification and source identity may need to be redone during reconciliation.
These are not all safely deferable. County ordering can remain a policy choice, but negative-finding freshness, county-court scope, and Ohio Checkbook's evidentiary role directly affect route completion. Resolve them before approval: require a default
reassess-afterpolicy by route volatility; define whether local courts are part of county coverage or a linked subprogram; and state that Checkbook participation is discovery/reconciliation evidence, never proof of complete county finance coverage.@ -0,0 +1,321 @@:PROPERTIES:Route assessments need to bind the exact immutable revisions that were reviewed, not only logical profile IDs. Otherwise a later profile revision changes the apparent basis of an older assessment. Replace or supplement this with
source-profile-revision-ids, add an assessment revision/prior-assessment ID, and make route decisions append-only with explicit supersession.Blocking —
required subfamiliesis undefined. Add a versioned route-subfamily/applicability contract keyed by route and government/component kind. It must declare required versus optional subfamilies, evidence needed for:not-applicable, allowed completion states, and minimum negative-search coverage. Without this, identical evidence can produce different:verifieddecisions.This mixes acquisition/source lifecycle (
candidate,active,changed,retired) with human review lifecycle (verification-pending,reviewed) even though invariant 10 says they are separate. Define two enums and two transition tables, plus which authority may perform each transition and how a source change invalidates or reopens review.@ -47,0 +88,4 @@Actor groups:1. control and policyBlocking — dependency order is inverted. Waves 0–3 cannot satisfy their own raw-evidence, replay, review, and coverage-ledger gates before this infrastructure exists. Move source-profile persistence, immutable raw artifacts, provenance validation, the Coverage Ledger, and the review authority ahead of Wave 0/1 execution. Generic bounded probe adapters can follow the fake actors but must exist before live source probes.
@ -47,0 +88,4 @@Actor groups:1. control and policyAddressed in
807b4ec. The government-data dependency order now implements immutable profile/assessment records, raw artifacts, provenance validation, the Coverage Ledger, and independent review authority before Wave 0/1. The bounded generic probe adapters also precede live source probes, with an explicit no-live-wave prerequisite.@ -0,0 +1,321 @@:PROPERTIES:Addressed in
5a2db17.route-assessment-revisionnow has stable and immutable assessment IDs, prior/supersedes links, exactsource-profile-revision-ids, exact search-plan revisions, evidence/gap bindings, and applicability-contract versioning. Reassessment creates a superseding revision instead of mutating the old decision.@ -0,0 +1,321 @@:PROPERTIES:Addressed in
5a2db17. Added versionedroute-applicability-contractandroute-subfamily-rulerecords covering unit/component kinds, required/optional/conditional subfamilies, activation predicates, allowed terminal states, minimum search plans, state-source substitution, service-provider resolution, negative freshness, and positive evidence required for:not-applicable.@ -0,0 +1,321 @@:PROPERTIES:Addressed in
5a2db17. Source state and human review state now have separate enums, transition tables, and authorities. A detected change creates a new profile revision with reopened/invalidated review; it does not alter the previously reviewed revision. Retirement is explicitly a source-state transition that still requires reviewed evidence.@ -0,0 +1,178 @@:PROPERTIES:Addressed in
140a7e8. Franklin now requires reviewed revisions for all sixteen routes under one pinned applicability contract. Candidate, ambiguous, and unassessed states cannot pass; negative terminal states require completed search-plan revisions, gaps, and reassessment dates;:not-applicablerequires authority/service evidence; and the gate pins exact profile revisions, evidence, and gaps with deterministic replay.@ -0,0 +1,178 @@:PROPERTIES:Addressed in
140a7e8. Wave 3 is now explicitly provisional until the Wave 0 fingerprint matrix is reviewed. Selection maximizes platform/vendor, hosting authority, publication maturity, office fragmentation, shared services, court/health topology, geography, size, and migration patterns. Hancock County (39063) was added as the initial mid-sized northwest agricultural/industrial candidate, with a recorded replacement rule.@ -0,0 +1,178 @@:PROPERTIES:Addressed in
140a7e8and5a2db17. Every wave now records minimal historical identity: first/last seen, predecessor/successor locators, redirects, migrations, archive candidates, and visible coverage bounds. Locator records carry those relationships. Wave 5 is now historical expansion and reconciliation, not the first point where source identity is captured.@ -0,0 +1,178 @@:PROPERTIES:Addressed in
140a7e8and5a2db17. Checkbook participation is explicitly discovery/reconciliation evidence only; county courts and linked local-court assessments must be bound into the county route; and negative terminal results now use route-volatility defaults of 30, 90, or 180 days, with legal-versioned sources reassessed by the next effective date or 180 days. Batch ordering is the only remaining open policy choice.Review follow-up
Addressed and resolved all eight inline review threads.
Commits
807b4ec— reorder government-data implementation dependencies so durable records, evidence, provenance, ledger, review authority, and generic probes precede live waves140a7e8— strengthen Franklin and Wave 3 gates; make county selection fingerprint-driven; add cross-wave historical identity; resolve Checkbook, court, and negative-finding semantics5a2db17— add immutable profile/search-plan/assessment revisions, versioned route applicability, shared deployments, structured scope, independent source/review lifecycles, and replayable browser/OCR boundariesThe PR description now reflects the revised architecture and pilot order.
Remaining merge blockers
5a2db17has no attached GitHub Actions workflow runs or commit statuses, so repository validation is still outstanding.No source, county, design, or implementation state was marked complete or approved.
Deeper architecture pass
I kept reviewing after resolving the original eight threads and found additional contract-level problems. These are now addressed on head
136bded.Additional fixes
DONEcontract so a logical source-profile ID cannot complete a county.New blocker exposed
The Ohio design is now stricter than its parent actor protocol.
STAR-RESEARCH-PIPELINE-003still models logical source-profile IDs and does not define the Route Assessment Authority, independent review authority, revision-aware message fields, or job/attempt lease semantics required by this PR.That parent protocol must be amended before implementation. I recorded this explicitly in the Ohio documents, catalog, project index, and PR description rather than silently pretending the contracts align.
Current state
136bdedhas no Actions runs or commit statusesFinal deeper-review pass — head
cc2fea6I continued past the original eight review threads and found several additional correctness problems. They are now addressed in the branch.
Additional defects found and fixed
Parent protocol mismatch was only documented, not designed.
STAR-RESEARCH-PIPELINE-004 Government Data Revision Protocol Amendment.PIPELINE-003and defines revision-aware authorities, messages, routing, scheduling, checkpoints, leases, and migration.Independent review created a one-writer violation.
Sixteen moving route records could not form an atomic county decision.
DONEnow requires a currently valid, independently reviewed, passed jurisdiction gate.Passed gates had no deterministic expiry or hash semantics.
basis-as-of,freshness-deadline, andvalid-through.Record interpretation depended on an implied document version.
star.govdata.source-profile@1.0.0separately from design-document versions, payload schemas, envelope protocol, applicability contracts, and policy snapshots.Adapter jobs incorrectly mixed logical work with leases issued later.
Artifacts and checkpoints could race.
The catalog completion contract was generated and would be overwritten.
tools/generate-government-jurisdiction-todos.pyto generate the revised0.4.0master contract.valid-throughrequirements.Current validation state
review-state, logicalsource-profile-id, or old1.3protocol/source-contract fieldscc2fea6has no Actions runs and no commit statusesRemaining blockers
PIPELINE-003and the normativePIPELINE-004amendment require joint review/approval.Disposition remains: keep draft; do not merge yet.
Current-head review — aggregate branch
Reviewed the consolidated
main-based headb327476after merging the former #48 → #52 → #53 stack.Resolved in this head
mainand overlaying only the aggregate PR filesmainReview result
No remaining design inconsistency was found in the addressed blocker set. Merge remains gated on all applicable workflow runs completing successfully. This is a comment review because the connected account is the PR author and cannot provide an independent GitHub approval.
Final-head review refresh
Reviewed final head
022648cafter the StarLang CI boundary correction.The change removes execution of prototype files that were already deleted from this repository and replaces it with validation that:
prototypes/star-langpath.The government-data validation suite passed on the immediately preceding merged head, including contract/fixture checks and byte-for-byte offline regeneration of all 17 jurisdiction files. Final merge remains gated on workflows attached to this exact head.
Final current-head review
Reviewed final head
5655d53after resolving both Pages failures.Final CI fixes
org-idfallback when a valid file-level ID is absent from the Org-roam node tableValidation result
All workflows on this exact head completed successfully:
No unresolved review threads remain. The aggregate PR is ready to merge subject to GitHub's final mergeability check. This is a comment review because the connected account is the PR author and cannot provide an independent approval.