feat(governance)!: make the post-merge decision report opt-in and off by default - #368
Conversation
…in key BREAKING CHANGE: the post-merge decision report is now opt-in and off by default. Set HIVEMIND_ENABLE_DECISION_REPORT in the env block of .claude/settings.json or .claude/settings.local.json to restore it. While off, awaiting runs are marked done without any GitHub call.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: debb35b36d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Per tests/policy/README.md rule 3, safety-decision-report-toggle.json pinned copied implementation prose at its consumers, so truthful rewording of the overlord's environment, ordering, or marker wording failed --strict while the canonical contract stayed intact. Move every behavioral claim onto plugin/governance/decision-autonomy.md (key identity + channel + presence test; unconditional off-path marker touch) and reduce plugin/agents/overlord.md to its pointer-only assertion. Drop the CLAUDE.md pin, which carries no canonical pointer and could only be copied claim prose. Rewrite the description to state the new division of labor and its residuals. Bite-proven both directions per rule 4: mutating each pinned canonical clause and the pointer sentence turns SAFETY red; reverting is green; rewording the now-unpinned agent prose stays green. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018P3FsvsiiYroMetYGtMDQs
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: caa0a813bc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018P3FsvsiiYroMetYGtMDQs
Summary
The post-merge decision report is now opt-in and off by default. It is gated behind a new operator env key,
HIVEMIND_ENABLE_DECISION_REPORT, set in theenvblock of.claude/settings.json(committed) or.claude/settings.local.json(gitignored). The key is checked by presence with a simple non-empty test, the same operator-override channel asHIVEMIND_SKIP_PR_WATCHandHIVEMIND_LOCAL_REVIEW_MODEL, and it inherits into brood worktrees.hivemind:decision-report, and makes no GitHub call. It still derives the awaiting-report set from local ledger reads and touches the zero-byte.decision-report-donemarker for each awaiting run, so enabling the key later reports only runs that finish after it is enabled.event.outputs.decisions[]) is still written, and Tier-B autonomy is unchanged. Only the chat report is gated.The key is named
HIVEMIND_ENABLE_DECISION_REPORTrather thanHIVEMIND_DECISION_REPORTbecause the check is presence-only: with a bare noun,=offwould enable the report.Accepted residual
When the key is off, the marker is touched without checking PR state. A run whose PR is still open while the report is off is therefore marked done and will not report if the operator enables the key before it merges. Checking PR state would put a per-run GitHub call back on the disabled path, which is the cost the toggle removes. The run's decision journal stays readable in its ledger. Recorded in ADR-0030.
Changes
plugin/governance/decision-autonomy.md:## Post-Merge Decision Report Triggeris the canonical source for the gate (header unchanged).plugin/agents/overlord.md: Resume-On-Start gate, fail-open note for the off path, and an opt-in note on thehivemind:decision-reportskills entry.plugin/references/run-ledger-schema.md: notes the report is config-gated and the marker's wider meaning. No schema change.CONTEXT.md,README.md,CLAUDE.md: opt-in wording and operator docs for the key.docs/adr/0030-config-gated-post-merge-decision-report.md: new ADR amending ADR-0026's always-report rule.tests/policy/safety-decision-report-toggle.json: new P3 fixture pinning the default-off rule, the key, the presence test, and the off-path marker rule. Confirmed that mutating the pinned source clause turns the suite red, and that restoring it turns the suite green.Validation
bash tools/validate.sh --changed: pass.policy_check.sh --strict67/68 checks, 0 new findings;json-manifestspass.Versioning
BREAKING: 3.1.0 -> 4.0.0. A documented default behavior is turned off. The CHANGELOG entry names the migration (set
HIVEMIND_ENABLE_DECISION_REPORTto restore the report) and the backlog behavior: the first session after upgrading with the key off marks existing awaiting runs done.Unresolved issues
None.