Skip to content

JVNAUTOSCI-2632: implement governed ontology administration - #371

Merged
witbrock merged 1 commit into
mainfrom
codex/jvnautosci-2632-ontology-admin
Aug 13, 2026
Merged

witbrock merged 1 commit into
mainfrom
codex/jvnautosci-2632-ontology-admin

Conversation

@witbrock

@witbrock witbrock commented Aug 13, 2026 •

Copy link
Copy Markdown
Member

Summary

Implements the organisation/global ontology-administrator capability tracked by JVNAUTOSCI-2632.

  • represents organisation and global semantic authority separately from Von operational administration
  • supports exact, revocable agent delegation with durable receipts and canonical read-back
  • applies the same authority semantics across chat, workflows, internal MCP, stdio, and HTTP mutation entry points
  • adds actor-visible scope read, receipted preview, and governed scope-change execution
  • adds exact-plan identity consolidation with complete affected-context authorisation and honest partial/indeterminate outcomes
  • adds a guarded Michael-only migration that inventories all elevated holders and grants Michael operational, global semantic, and exact per-organisation authority
  • fails closed or retires ambiguous legacy mutation paths that cannot meet the governed command contract

Why

Legitimate canonical corrections were blocked when concepts carried historical or different publication scopes, while several alternate mutation entry points could bypass the conversational guard. Historical visibility was being used as a proxy for semantic authority, and Von operational control was not represented separately.

This change makes destination publication context, represented role, and exact delegation determine authority. Visibility alone no longer grants publication rights, and operational administration does not imply semantic ontology authority.

User and developer impact

Authenticated organisation administrators can govern their organisation's ontology; global administrators can maintain the shared ontology without acquiring private organisation visibility; agents can act only under an exact server-issued delegation.

Ordinary actor-owned creation and scoped assertions remain available. Generic role, visibility, membership, merge, scope, and reserved-predicate mutations are denied or routed through dedicated lifecycle commands.

No live role migration, ontology change, deployment, or activation is performed by this PR.

Validation

  • Tier-3 authority and affected integration suite: 210 passed
  • affected relationship/create families: 118 passed, 24 conditional skips
  • independent security re-audit: no deterministic stop-ship in the delivered scope
  • changed Python files: Ruff F,E9 clean and byte-compilation clean
  • git diff --check clean

One broader scholarly-upload replay reaches an existing downstream durable-workflow lock failure also present on main; the upload authority path itself passes its focused suite.

Release boundary

This is ready for review. Release still requires target-environment migration dry-run, guarded application, exact represented-role read-back, and replay of the motivating canonical outcomes.


# EXECUTION
def _raw_relation_by_id(relation_id: Any) -> dict[str, Any] | None:
raw_id = relation_id


def json_dumps_sorted(value: Any) -> str:
import json
"context": _json_safe(relation.get("context") or {}),
}
)
text_relations.sort(key=lambda item: json_dumps_sorted(item))
monkeypatch.setattr(
authority,
"resolve_live_semantic_roles",
lambda actor: (global_role,) if actor == semantic_admin else (),
Comment on lines +88 to +90
lambda actor: (
(global_role, organisation_role) if actor == "#V#semantic_admin" else ()
),
Comment on lines +121 to +131
lambda actor: (
(
_evidence(
admin,
authority.ORGANISATION_ONTOLOGY_ADMINISTRATOR_ROLE,
"#V#org_a",
),
)
if actor == admin
else ()
),
Comment on lines +183 to +192
lambda actor: (
(
_evidence(
global_admin,
authority.GLOBAL_ONTOLOGY_ADMINISTRATOR_ROLE,
),
)
if actor == global_admin
else ()
),
Comment on lines +285 to +295
lambda actor: (
(
_evidence(
actor,
authority.ORGANISATION_ONTOLOGY_ADMINISTRATOR_ROLE,
"#V#org_a",
),
)
if actor in admins
else ()
),
Comment on lines +377 to +387
lambda actor: (
(
_evidence(
admin,
authority.ORGANISATION_ONTOLOGY_ADMINISTRATOR_ROLE,
"#V#org_a",
),
)
if actor == admin
else ()
),
Comment on lines +427 to +431
lambda actor: (
(_evidence(admin, authority.GLOBAL_ONTOLOGY_ADMINISTRATOR_ROLE),)
if actor == admin
else ()
),
@witbrock
witbrock marked this pull request as ready for review August 13, 2026 10:47
@witbrock
witbrock merged commit 40d941c into main Aug 13, 2026
4 checks passed
@witbrock
witbrock deleted the codex/jvnautosci-2632-ontology-admin branch August 18, 2026 20:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant