feat: harden chat state by tenant

This commit is contained in:
thanhnv
2026-07-08 23:38:22 +09:00
parent b3b0544ba8
commit c800f7edf7
20 changed files with 380 additions and 54 deletions
+3 -3
View File
@@ -24,11 +24,11 @@ package "DONE - Plan 13 Control Panel" #E8F5E9 {
component "Loop/Chat widget\nbudget + replay drawer + chat ticker\nextends Command Center contract" as loop_widgets_done #D5F5E3
component "Approvals escalation\nturn ESCALATED -> inbox\nJWT + SoD + reason" as approvals_done #D5F5E3
component "CODEGEN-as-loop\nH4 guarded codegen\nloop-certified artifacts" as codegen_done #D5F5E3
component "Chat multi-tenant hardening\nper-tenant state + quotas + crypto" as chat_mt_done #D5F5E3
}
package "NEXT - offline platform follow-ups" #FFF8E1 {
component "RAI / Data Gov view\nretention + model-card + PII report" as rai #F9E79F
component "Chat multi-tenant hardening\nper-tenant state + quotas + crypto" as chat_mt #F9E79F
}
package "EXTERNAL / MANAGED PROD" #FDEDEC {
@@ -46,10 +46,10 @@ command_done --> gov_core : provenance + audit state
loop_widgets_done --> command_done : specialized widget
approvals_done --> gov_core : proposals + SoD
codegen_done --> gov_core : guarded loop-run
chat_mt_done --> gov_core : tenant boundaries
lead --> rai : next if staying offline
rai --> gov_core : read RAI + policy artifacts
chat_mt --> gov_core : tenant boundaries
managed_oidc ..> local_prod : replace mock IdP/cert
alerts ..> gov_core : route real incidents
@@ -57,7 +57,7 @@ billing ..> command_done : ground-truth FinOps
note right of rai
Recommended next:
1. If no external infra: build RAI view or Plan-18 tenant hardening.
1. If no external infra: build RAI view or next backlog item.
2. If infra is available: promote local-prod OIDC to managed prod.
3. Keep chat widgets on the existing Command envelope.
4. Keep every metric evidence-backed with provenance.