8b70e3240b
tracker-policy-pr / check-pr (pull_request) Successful in 6s
Formalizes the design settled in issue #423: one forge subrole identity per bottled agent (author + forge account + SSH signing key), reused across all repos/forges. Vouched attribution via sign-at-commit-time in the git-gate boundary (forwarded ssh-agent; private key never in the bottle; no SHA divergence). Forge "Verified" badges abandoned in favor of local git verify-commit plus durable console audit records and commit-status badges. Reprovision-per-activation credential lifecycle (0048 discipline), fail-loud teardown, public-key-fingerprint-only audit trail on bottled_agent. Successor to PRD 0027 (claimed-not-vouched, ADR 0002) and PRD 0048 (host-side minting lifecycle). Issue: #423 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Docs
How this project records what it builds and why — and a guide to picking the right document for what you're capturing.
When to write which document
| Artifact | For |
|---|---|
Glossary (docs/glossary.md) |
Canonical term definitions — what words mean in this project. |
PRD (docs/prds/) |
A feature: what to build, scope, success criteria. |
Research note (docs/research/) |
A landscape/tradeoff investigation. |
Decision record (docs/decisions/) |
A decision that isn't itself a feature — a policy, a convention, a "we will / won't do this," or a load-bearing choice made inside a larger PRD that deserves to be discoverable on its own. |
A decision that's fully specified by a PRD doesn't need duplicating in a decision record. Write one when the decision would otherwise be buried in prose, lost in an issue thread, or have no in-repo home at all (small requests that don't merit a PRD; non-feature choices like merge strategy or a trust posture).