diff --git a/docs/DECISIONS_OPEN_2026-10-04.md b/docs/DECISIONS_OPEN_2026-10-04.md index a9744fc..18f81fc 100644 --- a/docs/DECISIONS_OPEN_2026-10-04.md +++ b/docs/DECISIONS_OPEN_2026-10-04.md @@ -4,7 +4,7 @@ The single list of decisions only the owner can make, with the context each one needs. Everything else open is in [NEXT_SESSION.md](../NEXT_SESSION.md). When a decision is made, record it here and in the programme row it affects. -## 1. Model-routing data gates (OPEN) +## 1. Model-routing data gates (OPEN — terms lookup DONE 2026-10-04, awaiting operator assertion) **The architecture is right; one fact is missing.** The routing layer gates candidates on data class before any model choice: `private` data may only @@ -22,24 +22,58 @@ The routing shadow (live since 2026-10-04) records on every run: This is honest: every run today already sends private-repo data to z.ai via the gateway — the shadow makes that explicit instead of implicit. -**The open fact:** what the z.ai coding-plan endpoint actually retains -(their terms/privacy policy — a lookup, not an engineering slice). +**The lookup (done 2026-10-04, sources cited):** -**The decision, once the fact is known:** -- If retention is effectively none: set `retention: "none"` in - `/srv/ship-config/routing-policy.json` on infra-home (operator assertion - with the terms cited in this file), and the shadow selections go clean. -- If retention is unclear/lasting: keep the refusals recorded (routing `on` - stays blocked for private data) and treat hosted routing as - internal/public-data only. +- **z.ai Data Processing Addendum for API Services, §4(b)** + (docs.z.ai/legal-agreement/privacy-policy.md, appended DPA): "The Company + do not store any of the content the Customer or its End Users provide or + generate while using our Services. This includes any texts, or other data + you input. This information is processed in real-time to provide the + Customer and End Users with the API Service and is not saved on our + servers." +- **z.ai Privacy Policy, §3 purpose table**: the "improve and develop our + Services and conduct research … including when we train and improve our + models" row lists account/communication/log/usage/device/cookie data — + **User Content (prompts) is not among the training-purpose categories**; + prompts appear only under "provide … the Services" (contract basis). §5: + deleted conversations "will be removed immediately … and automatically + deleted from our back-end." +- **GLM Coding Plan usage policy** (docs.z.ai/devpack/usage-policy.md) and + subscription terms: no retention or training carve-out for the coding-plan + endpoint; the plan is provisioned on the API platform + (z.ai/manage-apikey/* console paths). -## 2. S12 browser harness — D07 (OPEN) +**Residual ambiguity (why this still needs the operator, not the agent):** +the DPA is framed for "business and enterprises users … through API +Services", and the coding plan is an individual subscription riding the API +platform's endpoint — no document states in words that the *coding-plan +endpoint specifically* retains nothing. The evidence is strong (API surface += no content storage; the consumer policy never trains on prompt content) +but the seam between the two policies is exactly where a cautious reading +keeps the refusal. + +**Recommended assertion (one line, when accepted):** in +`/srv/ship-config/routing-policy.json` on infra-home set the +`api.z.ai`/coding-plan destination to `"retention": "none"`, citing the two +clauses above, with a re-check trigger on any z.ai privacy-policy date +bump (current: 2025-09-29). Until asserted, the shadow refusals keep +recording — routing stays honest either way. + +## 2. S12 browser harness — D07 (OPEN — recommendation recorded 2026-10-04) The last undecided design call (deferred as D07). Options: keep the current harness approach and scope remaining S12 browser/interactive work on it, or run a short evaluation slice of harness options first and then build. S12 remains the least-started package; nothing blocks on it. +**Recommendation (agent, for the owner to accept or overrule): keep the +current harness; skip the evaluation slice.** Rationale: nothing blocks on +S12, so the only thing the eval buys is optionality; the eval itself costs +a full session; and any harness shortcoming will announce itself in the +first S12 interactive milestone, at which point a *targeted* swap is better +informed than an upfront bake-off. Re-open D07 only if that first milestone +lands and the harness measurably fights the work. + ## Decided 2026-10-04 (context) - **S02 batch**: A-only via the coding-plan key ($0 real); B deferred.