Code · PRs · CI · Evidence
OPERATING ARCHITECTURE
Operating Model
How GitHub, Codex, Claude Code A–F and Replit cooperate without crossing trust boundaries.Verified snapshot — GitHub not connected
MA
Live GitHub is not connected. Refresh can only revalidate the snapshot stamped 2026-08-27 23:26 UTC; it will not claim that unchanged data is live.
ACCOUNTABILITY ARCHITECTURE
One delivery system with explicit authority
SOURCE PRECEDENCE
What wins when records disagree
- Owner RED / HOLD decisionsExplicit authority and scope constraints
- Live GitHubMainline, PR heads, diffs, reviews, migrations and exact-head CI
- Canonical program controlMaster Plan and A–F Expanded Execution Pack
- Architecture and current reportsMandates, workstreams and final evidence reports
COLLISION CONTROL
Execution rules
One concern per PROne semantic owner and one evidence chain
Mainline owns migration indexThe later branch refreshes and yields
REUSE → EXTEND → ADAPT → CREATENo parallel importer or duplicate contract
Exact reviewed head onlySuperseded and swallowed runs do not count
ARCHITECTURE INTEGRITY
Five-layer assurance spine
Identity, tenant isolation, audit, migrations and operations.
AI, RAG, MCP, providers, connectors and event boundaries.
Catalog, controls, evidence, assessments and risk semantics.
Privacy, regulatory change, AI governance and adoption.
Drift, findings, actions, reassessment and executive evidence.
Boundary contract Vendor Console and Client Space remain separate, as do Vendor AI and Client AI, Global Catalog RAG and Tenant RAG, Vendor MCP and Client MCP.
Delivery sourcemeshal236/NexGen / NexGen
Plan sourceMaster Plan v2.3.0 · blob 67dc1f0
Last delivery verification2026-08-27 23:26 UTC
Data modeVerified snapshot — GitHub not connected