Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 45 additions & 11 deletions docs/DECISIONS_OPEN_2026-10-04.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ The single list of decisions only the owner can make, with the context each
one needs. Everything else open is in [NEXT_SESSION.md](../NEXT_SESSION.md).
When a decision is made, record it here and in the programme row it affects.

## 1. Model-routing data gates (OPEN)
## 1. Model-routing data gates (OPEN — terms lookup DONE 2026-10-04, awaiting operator assertion)

**The architecture is right; one fact is missing.** The routing layer gates
candidates on data class before any model choice: `private` data may only
Expand All @@ -22,24 +22,58 @@ The routing shadow (live since 2026-10-04) records on every run:
This is honest: every run today already sends private-repo data to z.ai via
the gateway — the shadow makes that explicit instead of implicit.

**The open fact:** what the z.ai coding-plan endpoint actually retains
(their terms/privacy policy — a lookup, not an engineering slice).
**The lookup (done 2026-10-04, sources cited):**

**The decision, once the fact is known:**
- If retention is effectively none: set `retention: "none"` in
`/srv/ship-config/routing-policy.json` on infra-home (operator assertion
with the terms cited in this file), and the shadow selections go clean.
- If retention is unclear/lasting: keep the refusals recorded (routing `on`
stays blocked for private data) and treat hosted routing as
internal/public-data only.
- **z.ai Data Processing Addendum for API Services, §4(b)**
(docs.z.ai/legal-agreement/privacy-policy.md, appended DPA): "The Company
do not store any of the content the Customer or its End Users provide or
generate while using our Services. This includes any texts, or other data
you input. This information is processed in real-time to provide the
Customer and End Users with the API Service and is not saved on our
servers."
- **z.ai Privacy Policy, §3 purpose table**: the "improve and develop our
Services and conduct research … including when we train and improve our
models" row lists account/communication/log/usage/device/cookie data —
**User Content (prompts) is not among the training-purpose categories**;
prompts appear only under "provide … the Services" (contract basis). §5:
deleted conversations "will be removed immediately … and automatically
deleted from our back-end."
- **GLM Coding Plan usage policy** (docs.z.ai/devpack/usage-policy.md) and
subscription terms: no retention or training carve-out for the coding-plan
endpoint; the plan is provisioned on the API platform
(z.ai/manage-apikey/* console paths).

## 2. S12 browser harness — D07 (OPEN)
**Residual ambiguity (why this still needs the operator, not the agent):**
the DPA is framed for "business and enterprises users … through API
Services", and the coding plan is an individual subscription riding the API
platform's endpoint — no document states in words that the *coding-plan
endpoint specifically* retains nothing. The evidence is strong (API surface
= no content storage; the consumer policy never trains on prompt content)
but the seam between the two policies is exactly where a cautious reading
keeps the refusal.

**Recommended assertion (one line, when accepted):** in
`/srv/ship-config/routing-policy.json` on infra-home set the
`api.z.ai`/coding-plan destination to `"retention": "none"`, citing the two
clauses above, with a re-check trigger on any z.ai privacy-policy date
bump (current: 2025-09-29). Until asserted, the shadow refusals keep
recording — routing stays honest either way.

## 2. S12 browser harness — D07 (OPEN — recommendation recorded 2026-10-04)

The last undecided design call (deferred as D07). Options: keep the current
harness approach and scope remaining S12 browser/interactive work on it, or
run a short evaluation slice of harness options first and then build. S12
remains the least-started package; nothing blocks on it.

**Recommendation (agent, for the owner to accept or overrule): keep the
current harness; skip the evaluation slice.** Rationale: nothing blocks on
S12, so the only thing the eval buys is optionality; the eval itself costs
a full session; and any harness shortcoming will announce itself in the
first S12 interactive milestone, at which point a *targeted* swap is better
informed than an upfront bake-off. Re-open D07 only if that first milestone
lands and the harness measurably fights the work.

## Decided 2026-10-04 (context)

- **S02 batch**: A-only via the coding-plan key ($0 real); B deferred.
Expand Down
Loading