docs: governed delivery boundaries without external CD takeover - #104
Merged
Merged
Conversation
pcvantol
deleted the
codex/governed-progression-delivery-authority-v1
branch
September 8, 2026 14:52
Owner
Author
|
Coordinated increment closure: all four documentation PRs are now squash-merged and re-read as merged. EP merge: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Coordinated architecture increment
GOVERNED_PROGRESSION_AND_DELIVERY_AUTHORITY_V1, companion to Forge #51 and the Workspace/Forge Platform documentation changes.Defines EP's boundary between Action assurance, Forge post-Action review cadence and target-owned pre-deployment/publication gates. Existing project/organization CD retains approval, credentials, deployment and rollback. Requests/triggers need their own scoped permission and cannot bypass external gates; a permitted request may start a pipeline that then waits at its own gate. No duplicate Workspace approval or direct-deployment fallback.
Adds the EP GP-E/GP-Q/GP-X roadmap and routes it from the existing canonical policy roadmap. Exact artifact/source/environment/operation identity, current authorization, restart and external-evidence requirements are documented. Full external CD and policy UI do not become first-canary requirements.
Scope and qualification
Three Markdown files only; #100 assurance/queue/SemVer code and #102 remain untouched. No runtime, workflow, database, grant, credential, package version or deployment changes. Implementation and integration qualification remain PLANNED. Owner requested architecture merges after actual checks; this is not approval of another PR or live activation. Exact-head hosted results and four-PR reconciliation will be recorded before merge.