* docs(agent-team): fold round-2 GPT-4.1 plan-review findings into P3-live-flip plan Round-2 cross-review (REQUEST CHANGES) folded: - B1 deploy-before-merge made a concrete CI-enforced gate (required status check fed by a box-exercised dispatch dry-run), not prose. - B2 added rollback for a prematurely-flipped privileged job that actually RAN (token rotate, revert opened PR/branch, audit the window) — distinct from an accidental merge. - B3 rollback is a tested, re-runnable script over ALL privileged surfaces (workflow, environment, App perms, branch protection), not a one-time manual run. - B4 Phase 3 explicitly gated on Phase 2 being fully provisioned + verified. - B5 /sh-security-review + GPT-4.1 cross-review RE-RUN on the actual enabled workflow before the flip, not only the inert version. - B6 docs/memory updated incrementally at each privileged step; Phase 6 is the final reconciliation pass. Plus FIX/NIT/QUESTION: gate-weakening pattern review, check-name discovery test, memory update on denylist change, snapshot retention in Phase 0, draft-PR notification (Phase 4) + conservative-rollout controls (Phase 5) made concrete. GH_TOKEN->GITHUB_TOKEN gate marked done (box alias added). * docs(agent-team): close B1 — deploy-before-merge is a committed hard gate, not a manual fallback Round-3 re-review resolved B2-B6 but flagged B1 still-open: the prior wording left a 'enforced by hand until the check exists' escape hatch. Reframe B1 as a REQUIRED Phase-1 build deliverable that blocks the flip (no manual fallback), with the required-status-check + admin-bypass-disabled branch protection, and a dry-run faithfulness note (same workflow file/jobs as live, only the privileged if: differs). * docs(agent-team): close B1 ordering — admin-bypass disabled before any flip via the B4 precondition Round-4 confirmatory re-review noted (c) admin-bypass-disable sits in Phase 2 while the gate is framed Phase-1. Clarify there is no ordering window: the flip (Phase 3) is gated on Phase 2 completion (B4), so branch protection incl. admin-bypass-disable is necessarily in place before any flip. The check's implementation being a Phase-1 build task (not yet physically built) is expected for a pre-build plan; it is non-optional and flip-blocking, enforced at the Phase-1 hard stop. Stopping the plan-review cycle here per the project's '3 cycles, residual is build-time' rule. |
||
|---|---|---|
| .. | ||
| provisioning | ||
| HANDOFF-2026-05-15.md | ||
| r720-agent-team-design.md | ||