docs(agent-team): fold round-2/3/4 plan-review findings into P3-live-flip plan #33

Merged
amoussa1229 merged 3 commits from docs/p3-plan-review-fold-round2 into main 2026-06-22 21:28:38 +00:00
amoussa1229 commented 2026-06-22 21:26:28 +00:00 (Migrated from github.com)

Revises docs/provisioning/P3-LIVE-FLIP-PLAN.md per a fresh GPT-4.1 cross-family plan-review (round 2), with two confirmatory re-runs (rounds 3–4).

Folded findings

  • B1 deploy-before-merge → a concrete, CI-enforced, flip-blocking gate (required status check fed by a box-exercised dispatch dry-run; admin-bypass disabled in branch protection; no manual fallback). Ordering closed: the flip (Phase 3) is gated on Phase 2 (B4), so admin-bypass is disabled before any flip.
  • B2 rollback now covers a prematurely-flipped privileged job that actually RAN (token rotate, revert opened PR/branch, audit the window) — not only an accidental merge.
  • B3 rollback is a tested, re-runnable script over all privileged surfaces (workflow, environment, App perms, branch protection), not a one-time manual exercise.
  • B4 Phase 3 explicitly gated on Phase 2 being fully provisioned + verified.
  • B5 /sh-security-review + GPT-4.1 cross-review are re-run on the actual enabled workflow before the flip.
  • B6 docs/memory updated incrementally at each privileged step; Phase 6 is the final reconciliation.
  • FIX/NIT/QUESTION: gate-weakening pattern review, check-name discovery test across targets, memory update on denylist change, Phase-0 snapshot retention, draft-PR reviewer notification (Phase 4), conservative-rollout controls (Phase 5), dry-run faithfulness + admin-bypass settings.

Review disposition

Rounds 2→3 resolved B2–B6; round 3→4 closed B1's wording and ordering. Remaining grain is build-time (the gate's implementation, captured by the Phase-1 hard-stop), so the plan-review cycle is closed here per the project's "3 cycles, residual is build-time" rule. Docs-only change; no code.

Revises `docs/provisioning/P3-LIVE-FLIP-PLAN.md` per a fresh GPT-4.1 cross-family plan-review (round 2), with two confirmatory re-runs (rounds 3–4). ## Folded findings - **B1** deploy-before-merge → a **concrete, CI-enforced, flip-blocking gate** (required status check fed by a box-exercised dispatch dry-run; admin-bypass disabled in branch protection; no manual fallback). Ordering closed: the flip (Phase 3) is gated on Phase 2 (B4), so admin-bypass is disabled before any flip. - **B2** rollback now covers a *prematurely-flipped privileged job that actually RAN* (token rotate, revert opened PR/branch, audit the window) — not only an accidental merge. - **B3** rollback is a **tested, re-runnable script over all privileged surfaces** (workflow, environment, App perms, branch protection), not a one-time manual exercise. - **B4** Phase 3 explicitly **gated on Phase 2** being fully provisioned + verified. - **B5** `/sh-security-review` + GPT-4.1 cross-review are **re-run on the actual enabled workflow** before the flip. - **B6** docs/memory updated **incrementally** at each privileged step; Phase 6 is the final reconciliation. - FIX/NIT/QUESTION: gate-weakening pattern review, check-name discovery test across targets, memory update on denylist change, Phase-0 snapshot retention, draft-PR reviewer notification (Phase 4), conservative-rollout controls (Phase 5), dry-run faithfulness + admin-bypass settings. ## Review disposition Rounds 2→3 resolved B2–B6; round 3→4 closed B1's wording and ordering. Remaining grain is **build-time** (the gate's implementation, captured by the Phase-1 hard-stop), so the plan-review cycle is closed here per the project's "3 cycles, residual is build-time" rule. Docs-only change; no code.
This repo is archived. You cannot comment on pull requests.
No description provided.