Governance Boundary
What Triage May Write
Triage may write only to bounded operational/staging state:
These writes are operational records, not canonical organizational truth.
What Triage May Never Write
Triage must never directly write:The Authority Law
Confidence never grants authority.A 0.99-confidence proposal and a 0.55-confidence proposal require the identical approval to become real. Confidence describes evidence quality. It is an input to human judgement, never a substitute for it.
Human Decision Boundary
ThePATCH /v1/knowledge/triage/:id endpoint is the human decision boundary. It requires:
- Authenticated principal —
x-user-idheader - Tenant authority —
x-tenant-idheader, must match triage item - Optimistic check — current state must be
pendingordeferred - Approver identity/time — recorded in metadata
- Immutable audit — decision logged with full context
- Promotion event — on approve, triggers consolidation queue
Slack as Review Channel
Slack is a review channel, not an authority bypass. A Slack reaction must become a verified approval event:- Reaction received → verify binding to triage item
- Verify tenant and principal identity
- Verify candidate version hasn’t changed
- Create approval event with full audit context
- Route to consolidation pipeline