Skip to main content

Governance Boundary

What Triage May Write

Triage may write only to bounded operational/staging state: These writes are operational records, not canonical organizational truth.

What Triage May Never Write

Triage must never directly write:

The Authority Law

Confidence never grants authority.
A 0.99-confidence proposal and a 0.55-confidence proposal require the identical approval to become real. Confidence describes evidence quality. It is an input to human judgement, never a substitute for it.

Human Decision Boundary

The PATCH /v1/knowledge/triage/:id endpoint is the human decision boundary. It requires:
  1. Authenticated principal — x-user-id header
  2. Tenant authority — x-tenant-id header, must match triage item
  3. Optimistic check — current state must be pending or deferred
  4. Approver identity/time — recorded in metadata
  5. Immutable audit — decision logged with full context
  6. Promotion event — on approve, triggers consolidation queue
The endpoint itself does not become a second canonical writer. It updates review state and triggers downstream processes.

Slack as Review Channel

Slack is a review channel, not an authority bypass. A Slack reaction must become a verified approval event:
  1. Reaction received → verify binding to triage item
  2. Verify tenant and principal identity
  3. Verify candidate version hasn’t changed
  4. Create approval event with full audit context
  5. Route to consolidation pipeline
The Slack integration never writes canonical memory directly.