CASAN — Phân công team 3 người (Task Allocation & Dependency Map)
Cập nhật: 2026-07-08. File này chia toàn bộ việc còn lại (từ CASAN_BACKLOG_STATUS.md
- các plan) cho 3 dev, với task nhỏ có ID, mức liên quan (dependency) giữa
các task, và link tới từng plan. Đây là file điều phối — "còn gì phải làm" vẫn lấy
chuẩn từ
CASAN_BACKLOG_STATUS.md; mục lục plan ở
CASAN_PLAN_00_INDEX.md.
Cách đọc & quy ước
- Người: A = Harness Guardian (core harness/security/CI/eval) · B = Loop & Chat
(Plan-17 + Plan-18 + nén) · C = Platform & Control Plane (13/14/15/01/06/12 + infra).
- Effort:
S ≤1 ngày · M 2–4 ngày · L ≥1 tuần.
- Cờ: 🟦 làm offline được ngay · 🔌 cần key/dịch vụ ngoài · 🔗 phụ thuộc người khác.
- Dep: task phải xong trước (ID ở cột này). "—" = không chặn, làm song song được.
- Bất biến (mọi người): giữ 218/0 core + 118/0 SEC (
CASAN_HARDENING_STATUS.md);
mỗi control mới có test đối kháng fail-able, verify WSL, nối
ci-harness-gate.sh;
không sửa app OKR; không hardcode verdict; không bypass.
1. Chia vai (mission + plan sở hữu)
| Dev |
Mission |
Plan sở hữu chính |
| A — Harness Guardian |
Giữ & siết core harness; đóng nợ security; biến CI thành bộ gác |
16 · 10 · 05 · 03/02 (phần verify) · 07 (KMS/WORM/tamper) |
| B — Loop & Chat |
Xây Agentic Loop Governance + Governed Chat Console MVP |
17 · 18 · 08 |
| C — Platform & Control Plane |
Console vận hành + multi-project reuse + infra |
13 · 14 · 15 · 01 · 06 · 12 · 07 TIER-2 |
Ưu tiên tổng thể theo CASAN_PLAN_00_INDEX.md: core harness là P1
(A giữ), TIER-2 infra là đòn bẩy điểm (C), loop/chat là hướng mới (B) nhưng đứng sau core.
2. Dev A — Harness Guardian (core/security/CI/eval)
| ID |
Task nhỏ |
Plan |
Effort |
Cờ |
Dep |
| A1 |
✅ done — SEC-26 stored-injection: quét golden-runs/redteam-corpus/traceability-map/requirement bằng H4 khi nạp prompt (stored-content-scan.sh + phase-sec26 5/0, nối CI) |
16 §2c X-01 |
M |
🟦 |
— |
| A2 |
✅ done — SEC-22: trusted-time cho JWT exp (ARCH-06) + tag proposal nguồn-không-tin (ARCH-08, self-improve untrusted→BLOCK ở prod/strict). approval-verify.sh + self-improve.py + phase-sec22 9/0, nối CI. Còn ARCH-10 (attestation ngoài) = track ngoài như TIER-2 |
16 §2c ARCH-06/08 |
M |
🟦 |
— |
| A3 |
� offline done — SEC-23 multi-tenant (MT-01..04), 6 phase / 14 bước (16 §2d). Phase 1–5 offline ✅ (tenant-store+guard · per-tenant CP/audit/telemetry · RBAC data-boundary+harness · tenant kill-switch+quota · ký registry · crypt at-rest per-tenant; 5 suite phase-sec23-* = 36/0, nối CI). Chỉ còn 23.11 (crypt qua Vault Transit 🔌) |
16 §2d MT-01..04 |
L |
✅ offline (23.11 🔌) |
— |
| A4 |
🟡 partial (offline) — SEC-24: image digest-pin lint + ký/verify CI workflow (supply-chain-integrity.sh + phase-sec24 8/0, nối CI). Còn live CVE/OSV scan + image scan thật (🔌 infra) |
16 §2c SC-04/05/06 |
M |
🟦 offline (🔌 live) |
— |
| A5 |
🟡 partial (offline) — SEC-25: build-artifact attestation tested==deployed (artifact-attest.sh + phase-sec25 5/0, nối CI). Còn signed-commit enrollment + SLSA chain (🔌 CI/key) |
16 §2c SC-07 |
M |
🟦 offline (🔌 live) |
— |
| A6 |
Plan-10 H3 eval-set độc lập (nhiều model) + enrich symbol/line refs FR-02→FR-05 |
10 |
M |
🟦 |
— |
| A7 |
KMS-anchor mặc định (Vault Transit) cho mọi head + assert non-exportable; bỏ fallback khoá local ở prod |
07 B3 · 16 SEC-02 |
M |
🔌 (Vault) |
— |
| A8 |
WORM thật S3 Object Lock/QLDB + trusted timestamp thay ledger local |
07 C5 |
M |
🔌 (AWS) |
— |
| A9 |
Plan-05 CI xanh trên runner thật + bật Docker infra-lab + xử lý A6 chậm/treo |
05 |
L |
🔌 (runner) |
— |
| A10 |
Release package fpt-casan-sdd-harness (đóng gói + version) |
05 |
M |
🟦 |
A9 |
| A11 |
Nối mọi suite mới của B/C vào CI + giữ tổng test không tụt (gác ARCH-02 test-integrity) |
05 · 16 SEC-18 |
S |
🔗 |
B*, C* |
A cung cấp cho B/C (interface): tamper-evidence + audit-chain (loop-trace dùng lại),
approval JWT thật (16 SEC-07), SEC-23 tenant-partition (Chat MVP-3, Control Plane multi-tenant).
3. Dev B — Loop & Chat (Plan-17 + Plan-18 + nén)
3.1 Loop Engineering (Plan-17)
| ID |
Task nhỏ |
Plan |
Effort |
Cờ |
Dep |
| B1 |
✅ done — Loop Budget Governor loop-governor.py + loop-policy.yaml/.schema.json + loop_common.py (deny-by-default, fail-closed; no/corrupt policy → strict ceiling/HALT; on_exceed halt/escalate; HALT audited hash-linked). phase-loop-governor 15/0, nối CI |
17 T1 (17.1–17.4) |
M |
🟦 |
— |
| B2 |
✅ done — Convergence detector loop-convergence.py (repeat/thrash → OSCILLATING; flat-progress window → STALLED; on_stall halt/escalate; corrupt stream fail-closed; verdict audited). phase-loop-convergence 15/0, nối CI |
17 T2 (17.5–17.8) |
M |
🟦 |
— |
| B3 |
✅ done — Per-iteration Verify Contract loop-gate.py (bọc H4 security-check + H3 success-criteria; injection → DENY; unmet → FAIL; correction bounded by max_corrections_per_step → ESCALATE; no self-declared DONE; artifact/gate error fail-closed). phase-loop-gate 20/0, nối CI |
17 T3 (17.9–17.12) |
M |
🟦 |
— |
| B4 |
🟡 offline done — Loop Trace/Replay loop-trace.py (append-only hash-linked per-run trace · record/show/replay/verify-chain; edited record → chain BREAK · tampered artifact → replay DRIFT · corrupt trace fail-closed). phase-loop-trace 16/0, nối CI. Còn 17.16 KMS-anchor head (🔌 Vault, dep A7) |
17 T4 (17.13–17.16) |
M |
🟦 offline (KMS 🔌) |
A7 (chỉ KMS-anchor) |
| B5 |
✅ done (offline) — Meta-loop loop-metaloop.py (propose≠apply dry-run; SoD proposer≠approver; loosen>org_ceiling refused 17.19; apply qua governed CP store → versioned+audit+rollback + đổi thật ceiling governor). phase-loop-metaloop 15/0, nối CI |
17 T5 (17.17–17.19) · 04 |
M |
🟦 (SEC-07 ✅) |
B1, A(SEC-07) ✅ |
| B6 |
🟡 offline done — Orchestrator loop-run.sh (mỗi turn: gate→governor→convergence→trace; DONE/HALT/ESCALATE; secure-by-default prod opt-out bị từ chối nếu thiếu lý do; nén giữa vòng qua context-compress.py 17.21). phase-loop-run 16/0, nối CI. Còn widget Loop/Chat chuyên sâu (17.22 = B12, dep C5 ✅ baseline) |
17 T6 (17.20–17.21) |
M |
🟦 |
B1,B2,B3,B7 (B7 opt) |
3.2 Context compression (Plan-08)
| ID |
Task nhỏ |
Plan |
Effort |
Cờ |
Dep |
| B7 |
Track 1 nén INPUT + Track 2 nén VIEW liên-bước + nối H4/H5 pipeline |
08 |
M |
🟦 |
— |
| B8 |
Track 4 abstractive (gated) |
08 |
M |
🟦 |
B7 |
3.3 Chat Console (Plan-18) — theo lát cắt MVP
| ID |
Task nhỏ |
Plan |
Effort |
Cờ |
Dep |
| B9 |
✅ done — MVP-0 Ask CASAN read-only: Prompt Router (Track 0) + Read-only Ask CASAN (Track 1) + session/audit (Track 2) + Control Panel API/UI (Track 7). H4 in/out, H5 audit hash-chain, H6 token, evidence sources; chat suites 14/0, Control Panel 23/0 + build xanh. Real model provider binding remains Track M follow-up when a provider is enabled. |
18 §1b, Track 0/1/2/7/M |
L |
✅ |
done |
| B10 |
✅ done — MVP-1 Operator mode: registered actions run tests / build pack / verify pack, no free-command, all through action-gate, action artifacts with provenance, Control Panel quick actions. phase-chat-operator 8/0; total chat suites 24/0; Control Panel 24/0 + build xanh. |
18 Track 3 |
M |
✅ |
done |
| B11 |
✅ MVP-2 done — Track 4 Agent/Skill governance + CODEGEN draft-as-loop + OPERATOR Track 5/6 chat-as-loop/draft-hold + Track 8.1/8.2 replay foundation + Track 8.3 Command Center Chat/Loop widget + Track 8.4 approvals escalation. chat-turn.py certifies OPERATOR/CODEGEN drafts through Plan-17 loop-run.sh; chat-replay.py detects evidence artifact drift and chat-chain tamper; /command shows chat loop ticker/budget/evidence; delegation escalation creates pending chat.escalate approvals. Chat suites 51/0; Control Panel 28/0 + build xanh. |
18 Track 4/5/6/8 |
L |
✅ |
B6, C7(RBAC), B10 |
| B12 |
✅ done — Widget Loop/Chat trên Command Center (chat_loop widget, loop ticker, budget gauge, replay evidence drawer) |
17 (17.22) · 18 Track 8 |
M |
✅ |
C5 ✅ baseline |
| B13 |
✅ done — MVP-3 multi-tenant chat hardening (Track 9): tenant-partitioned chat state/replay guard, encrypted audit snapshot, tenant kill-switch/quota isolation. phase-chat-tenant 8/0; Control Panel tenant replay test included in 29/0. |
18 Track 9 |
M |
✅ |
A3(SEC-23) |
4. Dev C — Platform & Control Plane
4.1 Control Plane web app (Plan-13)
| ID |
Task nhỏ |
Plan |
Effort |
Cờ |
Dep |
| C1 |
✅ done — Track 1 read-only monitoring API (NestJS) đọc telemetry/audit/traceability |
13 §4 Track 1 (13.1–13.3) |
M |
✅ |
done |
| C2 |
✅ done — Ops Console (React) verdicts/cost/drift/incident + stale-aware |
13 §4 Track 1 |
M |
✅ |
done |
| C3 |
✅ Track 2 settings API/UI + H5 audit + rollback (13.4–13.6) |
13 §4 Track 2 |
M |
✅ |
done |
| C4 |
✅ HITL surface: approvals inbox + delegation L0–L5 + oversight log (13H.1–13H.3) |
13 §3.4 |
L |
✅ |
done; local OIDC claim→role smoke pass |
| C5 |
✅ done — Command Center §8.6 baseline: GET /command, provenance envelope, executive briefing, live ticker, evidence drawer; nền cho widget của B |
13 §8.6 |
M |
✅ |
done |
| ID |
Task nhỏ |
Plan |
Effort |
Cờ |
Dep |
| C6 |
🟡 local done — IdP claim → role mapping + enforcement trong web app; còn enterprise IdP thật |
14 · 07 C4 |
M |
✅ local / 🔌 prod |
— |
| C7 |
RBAC enforcement API (expose rbac-check.py cho B/chat) + audit quyết định vào H5 |
14 |
M |
🟦 |
— |
| C8 |
RAI view trên Control Plane (retention/model-card/PII report) |
15 |
M |
🔗 |
C2 |
| ID |
Task nhỏ |
Plan |
Effort |
Cờ |
Dep |
| C9 |
Plan-01 restructure Phase 0→6 (nhánh riêng, giữ 218/0) → packages/casan-harness |
01 |
L |
🟦🔗 |
(freeze window) |
| C10 |
Plan-06 onboard dự án 2 qua verify-harness-reuse.sh (không sửa gate) |
06 |
M |
🔗 |
C9 |
| C11 |
Plan-12 Domain Pack SDK (golden/corpus/policy theo domain khai báo) |
12 |
L |
🔗 |
C9, C10 |
| C12 |
TIER-2 infra: promote local-prod Control Panel TLS/OIDC to managed host/cert/enterprise IdP + alert managed (Slack/PagerDuty) + billing API thật |
07 T2.3/2.4/2.5 |
M |
🔌 |
C2 ✅ |
5. Bản đồ phụ thuộc chéo (ai chặn ai)
Đọc nhanh: B phụ thuộc A nhiều nhất ở KMS (A7→B4), approval (SEC-07→B5) và
tenant (A3→B13); B phụ thuộc C ở RBAC (C7→B11) và Command Center (C5→B12);
C phụ thuộc A ở KMS (A7→C3) và approval (SEC-07→C4).
6. Điểm đồng bộ (sync points — họp chốt interface, tránh va nhau)
| # |
Chủ đề |
Ai |
Chốt gì |
| S1 |
Config namespace packages/casan-harness/config/* |
A/B/C |
loop-policy.yaml (B) · agent-registry.yaml/prompt-modes.yaml/model-providers.yaml (B) · settings store (C) · không trùng key/khoá |
| S2 |
Audit-chain / tamper-evidence |
A→B,C |
A định dạng head + verify-chain; B dùng cho loop-trace; C dùng cho control-plane audit — một serializer, một verifier |
| S3 |
Approval contract (JWT+SoD) |
A→B,C |
1 đường approval-verify.sh; B (meta-loop) + C (settings/approvals inbox) gọi lại, không tự chế |
| S4 |
RBAC contract |
C→A,B |
rbac-check.py là nguồn; B (chat chọn agent) gọi; A đảm bảo trong CI |
| S5 |
Command Center data-contract §8.6 |
C→B |
✅ baseline envelope {source,artifact_path,commit,run_at,verified,status} đã có; widget Loop/Chat của B mở rộng theo contract này |
| S6 |
Restructure freeze (Plan-01) |
C→A,B |
C9 chạy trên nhánh riêng; A/B đóng băng path trong cửa sổ merge để giữ 218/0 |
7. Thứ tự sóng (waves — song song hoá tối đa)
Mỗi sóng ~2–3 tuần; kết thúc sóng phải xanh CI trước khi mở sóng sau.
| Sóng |
Dev A |
Dev B |
Dev C |
| Wave 1 (offline, không cần infra) |
A1 SEC-26 · A2 SEC-22 · A3 SEC-23 · A6 H3 eval |
B1 Governor · B2 Convergence · B3 Verify · B7 nén T1/T2 |
C1 monitoring API ✅ · C2 console ✅ · C5 Command Center ✅ · C7 RBAC API |
| Wave 2 |
A7 KMS · A9 CI runner · A11 nối suite mới |
B4 Loop-trace · B6 Orchestrator · B9 Chat MVP-0 · B8 nén T4 |
C3 settings store · C6 IdP→role · C4 approvals inbox · C9 restructure |
| Wave 3 |
A4 SEC-24 · A5 SEC-25 · A8 WORM · A10 release |
B5 Meta-loop · B10 MVP-1 · B11 MVP-2 · B12 widget · B13 MVP-3 |
C8 RAI view · C10 onboard · C11 domain pack · C12 TIER-2 infra |
Song song trong Wave 1: A/B/C độc lập hoàn toàn (không dep chéo) ⇒ khởi động nhanh nhất.
Nút cổ chai Wave 2: A7 (KMS) mở khoá B4 + C3; C7 (RBAC) + C5 (Command Center) chuẩn bị cho B ở Wave 3.
Wave 3 hội tụ: B11 cần B6+C7; B12 cần C5; B13 cần A3 → giữ đúng thứ tự.
8. Mốc hoàn thành theo sóng (Definition of Done)
- W1 done: core harness vẫn 218/0 + 118/0 SEC; +SEC-22/23/26 xanh; Loop T1–T3 xanh WSL; Control Plane read-only chạy + Command Center có data-contract.
- W2 done: KMS-anchor mặc định + CI xanh trên runner thật; Loop-trace/replay + Orchestrator; Chat MVP-0 (Ask CASAN read-only) demo được; settings store + approvals inbox + restructure merge (giữ 218/0).
- W3 done: SEC-24/25 + WORM + release package; Meta-loop; Chat MVP-1/2 (operator + chat-as-loop) + widget; RAI view + onboard dự án 2 + domain pack + TIER-2 infra (nơi có key).
9. Rủi ro & ghi chú bàn giao
- Chống lan man: B bám lát cắt MVP của Plan-18 §1b — MVP-0 làm được ngay,
không nhảy vào chat-as-loop/tenant trước khi Loop core (B6) + RBAC (C7) + SEC-23 (A3) sẵn sàng.
- Đơn người-điểm: A là nguồn đơn cho tamper-evidence/approval/tenant → nếu A chậm,
B4/B5/B13 + C3/C4 chậm theo. Ưu tiên A7 (KMS) + SEC-07 sớm trong Wave 1–2.
- Restructure (C9) rủi ro cao: đụng nhiều path → nhánh riêng + freeze window (S6) +
chạy full
ci-harness-gate.sh trước khi merge.
- Cần key/infra (🔌): A4/A5/A7/A8/A9, C6/C12, Plan-03 live smoke — gom vào Wave 2–3,
không chặn Wave 1. Nếu chưa có key: giữ Docker local-prod lab (
infra-lab.sh) làm bằng chứng.
- Bất biến bàn giao: mỗi task đóng lại phải kèm test đối kháng fail-able + cập nhật
CASAN_HARDENING_STATUS.md (tổng test) + CASAN_BACKLOG_STATUS.md (trạng thái).
Liên quan: CASAN_PLAN_00_INDEX.md (mục lục + ưu tiên) ·
CASAN_BACKLOG_STATUS.md (nguồn "còn gì phải làm") ·
CASAN_HARDENING_STATUS.md (control đã có + tổng test).