- README: orientation, doc map, target package layout (pointers only, no duplicated architecture content) - CLAUDE.md: agent operating manual — invariants as code-review rules, conventions, do-not list, task reading order - ROADMAP: M1-M5 with verifiable acceptance criteria, phase-2 fence - GLOSSARY: canonical Chinese-term → code-name mapping - docs/adr/: eight ADRs recording settled decisions and rejected alternatives - docs/open-questions.md: consolidated TODO(业务) tracker by owner and blocking milestone - .gitignore; untrack .DS_Store Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019u5SLNweVio6ozJX7yfxQr 🔮 View transcript: https://logs.lojong.info/s/e8u90k3t33w590r7b5y7yzqh
18 lines
792 B
Markdown
18 lines
792 B
Markdown
# ADR-0005: Safety chain as one proposal-lifecycle workflow
|
|
|
|
**Status**: accepted · 2026-09
|
|
|
|
**Context**: Every proposal type (bid, invitation, control plan, dispatch plan)
|
|
must pass rule check → simulation → envelope gate → fresh check → permit.
|
|
|
|
**Decision**: One `proposal-lifecycle` workflow implements the state machine for
|
|
all types. Business workflows end by submitting a Proposal; the lifecycle
|
|
workflow takes over. Approval resume, timeout escalation, and audit target this
|
|
single code path.
|
|
|
|
**Alternatives**: Inline safety steps in each business workflow — rejected:
|
|
five slightly-divergent safety chains are how audit gaps are born.
|
|
|
|
**Consequences**: Type-specific behavior (which simulation, which policy pack)
|
|
is data/config on the Proposal, not workflow structure.
|