diff --git a/docs/adr/0292-post-hire-talent-management-boundary.md b/docs/adr/0292-post-hire-talent-management-boundary.md new file mode 100644 index 000000000..cfb6e3e5b --- /dev/null +++ b/docs/adr/0292-post-hire-talent-management-boundary.md @@ -0,0 +1,341 @@ +# ADR 0292: Post-hire Talent Management bounded-context ownership + +- Status: Proposed +- Date: 2026-09-10 +- Issue: #292 +- Repair issues: #294, #396, #397, #398, #399, #400, #401, #402, #403, #404, #405, #406 +- Protected baseline reviewed: `develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f` + +## Problem + +Orgmetra describes itself as an evidence-centered HRIS/HCM platform, while the protected context map gives `talent_acquisition` only pre-hire responsibilities: requisitions, candidates, interviews, decision evidence, confirmations, and selection decisions. `people_core` owns employment and Assignment truth; `organization_core` owns Organization/Position truth; `job_architecture` owns Job/FJA/KSAO truth; `performance_management` owns criterion and observation truth; and `workforce_validation` owns validity, fairness, drift, and scientific evidence. No bounded context owns post-hire talent pools, succession planning, internal mobility, career preferences/pathways, or governed talent-review decisions. + +That omission is both a product gap and a DDD ownership gap. ISO 30414:2025 includes mobility and succession planning, as well as skills, capabilities, and development, among its human-capital reporting areas. ISO 30409:2016 remains the current confirmed workforce-planning standard. ISO 30405:2023, by contrast, is explicitly a recruitment standard. These scopes argue against silently expanding `talent_acquisition` merely because it already contains the word “talent”. + +The scientific literature also cautions against treating “talent” as a self-evident scalar. Collings and Mellahi (2009) identify persistent ambiguity in talent-management boundaries and focus strategic talent management on pivotal positions and talent pools. Gallardo-Gallardo, Dries, and González-Cruz (2013) show that “talent” can mean characteristics or people, with inclusive/exclusive interpretations. Dries (2013) identifies further tensions such as innate/acquired and transferable/context-dependent. Orgmetra therefore must not create an unversioned `potential_score`, `talent_score`, `fit_score`, or “high-potential” flag as universal HRIS truth. + +## Constraints + +1. HR domain Ubiquitous Language and authoritative employment truth remain in Orgmetra. +2. Existing bounded contexts retain their authority. A new Talent context may reference but must not copy Person, Employment, Assignment, Organization, Position, Job, FJA, KSAO, performance observations, assessment results, or validation-study truth. +3. Cross-context application SQL is prohibited. In the modular deployment, physical PostgreSQL co-location does not waive API/event/ACL boundaries. +4. Assessment results remain immutable external snapshot references under the current TRD. Assessment quality and predictive/fairness claims remain `workforce_validation`/specialist evidence, not Talent-owned truth. +5. High-impact post-hire decisions require accountable human actors, purpose, reason, exact evidence versions, explicit confirmation, and immutable audit/provenance. LLM output is draft evidence only. +6. Keyverse remains the identity/authentication backend. Authorization remains tenant-, actor-, purpose-, resource-, and lifetime-scoped. +7. No source schema, API, event, or UI is authorized by this Proposed ADR until its ownership decision is reviewed against then-current protected truth. +8. A high-impact Talent decision must preserve its actual decision-production mode as immutable provenance. Provisional values are `human_decision`, `ai_assisted_human_decision`, and `fully_automated_decision`; the value records how the outcome was produced and is not itself a legal conclusion. Presence of a human actor, confirmation button, or signature is not proof that substantive human intervention occurred. Under this Proposed contract, `fully_automated_decision` is provenance-only: it may describe an imported, historical, or externally produced outcome for reconstruction and applicable rights handling, but `talent_management` must reject any command that would finalize a high-impact Talent outcome in that mode. Finalization is allowed only for `human_decision`, or `ai_assisted_human_decision` with recorded substantive human intervention and accountable human confirmation. +9. A final decision-level mode is not sufficient when earlier steps materially constrain the reachable outcome. A **material decision stage** is any human or automated step whose output can materially determine eligibility, inclusion/exclusion, shortlist or slate membership, ordinal recommendation or ranking, recommendation suppression, thresholding, routing to or away from human review, or another downstream high-impact action. `talent_management` must preserve an immutable ordered stage history with each stage's production mode, model/tool and evidence/policy versions when used, and input/output lineage. A later human confirmation cannot relabel, erase, or overwrite an upstream fully automated material stage. +10. A fully automated material stage may exist only as non-authorizing process provenance where its effect remains inspectable and genuinely reversible before high-impact finalization. If an automated stage irreversibly excludes or suppresses an option, hides the material basis from the accountable reviewer, or leaves no actual disregard/override/reversal path before lock-in, finalization fails closed. An AI-assisted stage counts as substantive human intervention only when the reviewer receives the relevant evidence and known limitations before lock-in, has an actually available path to disregard/override/reverse the output, and records a controlled disposition such as `accepted`, `modified`, or `rejected` with a purpose-bound reason and immutable provenance. +11. Jurisdictional notice, explanation, refusal/review, correction, and response-time obligations are resolved from a versioned tenant/policy/compliance contract and then-current law. `talent_management` preserves the evidence needed to discharge applicable rights but does not hard-code a blanket legal applicability conclusion into domain truth. +12. Individual stage provenance is not a sufficient scientific denominator. For every material Talent decision stage, `talent_management` must preserve purpose-minimized immutable evidence of the exact decision opportunity set and stage transitions under the same tenant, purpose, process/version, stage/order, criteria/policy version, required evidence versions, and effective/system-time or explicit measurement window. This provenance must distinguish advancement from not-evaluable, stale/missing-evidence, authorization/owner-unavailable, policy-inapplicable, human-excluded, automated-excluded-or-suppressed, withdrawn, error/failure, and other controlled domain outcomes rather than silently dropping them. It must retain relevant multiple-membership, cross-classified, and temporal context. The denominator must also preserve the exact entry-level membership and a versioned counting/analysis unit: replay or transport attempts for one semantic opportunity cannot create extra denominator entries, while genuinely distinct opportunities involving the same worker cannot be collapsed merely because their worker reference matches. Append-only correction history is not itself a counting rule: at closed-manifest resolution, each semantic opportunity occurrence must resolve through an explicit correction/supersession chain to exactly one canonical active terminal entry. The closed-stage terminal vocabulary includes `advanced`, `not_evaluable`, `policy_inapplicable`, `human_excluded`, `automated_excluded_or_suppressed`, `withdrawn`, `unavailable`, and `failed` (plus only additional explicitly versioned domain terminal classes). `unavailable` means required evidence, authorization, or owner availability remained unresolved at closure; `failed` means an unresolved processing/domain failure was terminalized at closure; `not_evaluable` is a distinct explicit outcome that the case could not be evaluated under the governing evidence/construct contract, not a generic remapping target for unavailable or failed cases. Superseded historical entries and processing attempts remain evidence but are excluded from denominator and terminal totals. Protected demographic attributes, fairness/validity verdicts, estimand choice, and legal discrimination conclusions remain outside Talent authority. +13. Immutable replacement/reconsideration manifests require an explicit **manifest-level** lineage and temporal view contract in addition to occurrence-level correction resolution. Replacement versions representing the same material stage/cohort retain a stable opaque manifest-lineage identity; each closed manifest has an immutable version and content digest plus an explicit supersession predecessor. The content digest is itself reproducible evidence: the manifest contract versions the canonical semantic projection/bytes, deterministic serialization and ordering rules, digest algorithm/domain separator/version, and digest-metadata version, and consumers can recompute and validate the digest from the same closed manifest semantics. Equivalent manifests under the same versioned manifest-digest contract produce the same digest; presentation-only/serializer-order accidents cannot change it. The replacement graph is deterministic, acyclic, and cannot leave dangling or competing canonical successors for the same requested view/cutoff. Consumers must select an explicit reproducible view such as the exact `as_recorded` manifest that governed a stage at a stated time or a `corrected_as_of` canonical replacement at a stated correction/system-time cutoff. An unqualified `latest` or blind union of predecessor and replacement manifests is not scientific or commercial authority. A later correction cannot retroactively change the evidence identity of an already released analysis; recomputation creates a new analysis/evidence version bound to the selected manifest lineage, immutable version/digest, manifest-digest contract version, view, and as-of cutoff. +14. Manifest correction lineage and **selection-policy regime** lineage are distinct. Every material stage binds its immutable decision-policy version to a canonical material policy-semantics/regime identity or digest sufficient to distinguish a semantic procedure change from an editorial/no-op reseal. Same-lineage `corrected_as_of` traversal is permitted only when deterministic owner evidence establishes that the material selection semantics remain compatible. A material change to eligibility meaning, threshold/cut score, ranking/order method, required-evidence meaning, suppression/routing, or another rule that changes who can enter, advance, be excluded, or reach human review starts a new policy regime and must not masquerade as a denominator correction. A semantic-preserving metadata/editorial version change may remain in the same regime only when equivalence is evidenced rather than inferred from a version label. Historical `as_recorded` evidence remains bound to the policy regime actually used; re-analysis under a later materially different policy produces a new simulation/counterfactual/analysis evidence version. `workforce_validation`, not Talent, remains authoritative for whether validity/fairness evidence supports the changed procedure. +15. A policy-regime identity is provenance only when it is **owner-recomputable from a versioned canonical semantic projection that is closed over all material selection dependencies**. The projection schema must explicitly identify the local fields that influence entry, evaluability, advancement, exclusion, ordering/ranking, thresholding, suppression, routing, human-review reachability, or another material stage behavior, and explicitly exclude presentation/editorial metadata that cannot change that behavior. Every material external dependency is represented by its released owner identity plus immutable version/digest or equivalent content-addressed evidence; mutable branch refs, floating labels, unversioned external names, or live cross-service table state are invalid identity inputs. Canonical representation rules and version, digest algorithm/domain/version, and semantic-projection version are explicit. `talent_management` recomputes or verifies the identity from those inputs; a caller-supplied `policy_regime_id` or digest is never authority by assertion. Same-regime equivalence is deterministic equality or a separately versioned and auditable equivalence/migration rule whose inputs and output are provenance-bound. A digest collision or mismatch is fail-closed integrity evidence requiring explicit resolution, not a domain-equivalence verdict. +16. External artifact integrity and external selection-semantic authority are distinct evidence meanings. A released external owner may reuse one canonical digest for both only when its versioned contract explicitly defines that canonical projection as the downstream-material semantics and publishes its stability/equivalence rules. Otherwise `talent_management` consumes an owner-issued semantic-dependency receipt or equivalent ACL projection that binds owner/context, released contract/artifact/version, exact integrity identity, downstream-material semantic identity/projection, applicability/effective scope, and any deterministic versioned equivalence/migration evidence. Talent must not query, copy, or reverse-engineer foreign Job/FJA/KSAO, assessment, performance, model/tool, or validation internals to manufacture semantic equivalence. Missing, ambiguous, conflicting, stale, wrong-purpose, wrong-tenant, floating, or caller-asserted semantic authority fails closed. +17. Intended policy identity is not proof of the procedure actually executed. Every material stage occurrence must bind the governing policy-regime/projection and its external owner receipts to trusted observed-resolved immutable dependency identities/versions/digests plus every material runtime parameter not already fixed by the projection. The Talent execution boundary, rather than caller metadata, observes or verifies those resolved inputs and performs a deterministic versioned expected-versus-observed comparison before a stage effect can authorize advancement, exclusion, ranking, suppression, routing, or high-impact finalization. Stage provenance distinguishes `execution_congruent`, `execution_incongruent`, and controlled unavailable/not-verifiable states. Missing expected dependencies, extra material dependencies, stale caches, fallback artifacts, digest/semantic-receipt mismatch, alias-only provenance, or retry-to-retry dependency drift fail closed or remain non-authorizing. Only the canonical material attempt producing the terminal stage effect is bound to the outcome; historical attempts remain separate telemetry. +18. The first recorded opportunity manifest is not, by itself, evidence that it represents the complete source population or opportunity universe. Every first-stage manifest must bind a versioned **opportunity-origin/source-universe provenance** contract. A claim equivalent to `population_complete` requires a released/versioned authoritative owner receipt, snapshot, or ACL projection that identifies the source-universe owner/context, tenant and purpose, source-universe definition, effective/system-time or measurement window, enumeration rule/version, exact coverage/completeness semantics, and any unavailable/failure portion. Intentionally non-exhaustive origins such as nomination, employee opt-in, targeted discovery, or external import remain explicit and cannot later be relabeled as the complete eligible population merely because M1 is the first persisted cohort. Any human or algorithmic exposure, discovery, sourcing, nomination, eligibility, or prescreen step that materially determines who can enter **before M1 exists** is itself a material stage or a versioned source-universe transformation with policy/evidence/execution provenance. Material origin/source receipts participate in the first manifest's evidence identity/digest; correction is append-only and cannot rewrite the historical source universe used by a released decision or analysis. A materially changed enumeration/discovery rule participates in the policy-regime semantics of constraints 14–17 rather than masquerading as data correction. Talent may not reconstruct completeness through foreign application SQL, source copying, mutable queries, free-text labels such as `all eligible employees`, or protected-demographic copying. `workforce_validation` must receive enough released evidence to distinguish the declared source universe or origin scope, the first observed Talent cohort, and later stage denominators before choosing an estimand or making fairness/validity claims. +19. An intentionally non-exhaustive first-stage origin that is a **probability sample** requires more than the `non_exhaustive` label. `talent_management` must preserve a released/versioned, purpose-minimized sampling-design receipt or equivalent evidence bound to the exact authoritative source-universe receipt and sampled semantic opportunity set. The evidence identifies the target/sampling unit and design/version; whether selection is single-stage or multistage, with or without replacement, stratified, clustered, PPS, or another explicitly named design; each sampled unit's known non-zero inclusion probability or reproducible stage-wise probability inputs sufficient to derive it, with the design stage to which each probability belongs; the stratum/PSU/cluster or other design membership needed for downstream variance estimation through opaque owner references where sensitive; the trusted observed sample-selection execution including partial-frame/failure conditions; and selected-unit dispositions that distinguish participation/response, refusal or opt-out, unknown/unreachable/unavailable, post-selection ineligibility, and processing failure from never having been sampled. Retry/replay cannot mint a new sampled unit or probability for the same semantic sample occurrence, and repairs are append-only. A non-probability nomination, opt-in, ranking, quota, deterministic-percentage cutoff, or other convenience cohort must not manufacture pseudo-inclusion probabilities or be represented as probability-based. Talent owns only the provenance of a Talent-controlled sampling/origin step; authoritative frame membership stays with the source-universe owner, while `workforce_validation` owns estimand choice, design weights, variance/SE/CI, finite-population correction, calibration/nonresponse adjustment, protected-attribute joins, validity/fairness analysis, and scientific interpretation. +20. First-order inclusion-probability and complex-design provenance is not automatically sufficient to reproduce every **variance method actually claimed** for a probability-sampled origin. When downstream design-based uncertainty is supported, the released evidence must bind a versioned variance-evidence strategy to the exact source-universe receipt, #405 sampling-design version, sampled semantic occurrence set, selection execution, and correction version. A method that requires pairwise/joint inclusion information must have immutable `π_ij` evidence or a released deterministic design algorithm/parameterization that reproduces the required pairwise information; a replication method must bind its method/version, replicate count, scale/Fay-equivalent factors, construction provenance and the sampled occurrence set to which every replicate applies; and certainty units, sampling fractions/FPC-relevant inputs, or stage-specific structure are retained when required by the selected downstream method. An explicitly versioned approximation may be used, but it must be identified as approximate with its assumptions rather than represented as the exact variance of another design. Missing, ambiguous, mismatched, or non-reproducible variance evidence is non-authorizing scientific evidence, not a statistical GREEN. `talent_management` still does not choose or certify the estimator or compute final variance/SE/CI; the authoritative design owner or `workforce_validation` may issue the purpose-bound variance-design receipt, while `workforce_validation` owns estimator choice, calculation, uncertainty interpretation, FPC/calibration/nonresponse adjustment, and fairness/validity conclusions. + +## Product scope decision in this Proposed ADR + +Against the current protected PRD/TRD/ARCHITECTURE, **option C, a dedicated `talent_management` bounded context, is selected as the product-scope direction.** This selects the domain owner to design and test; it does **not** change this ADR from Proposed to Accepted and does not create protected schema/API/event/UI authority. + +The choice follows the current product truth rather than service-count convenience. The protected PRD describes an HRIS/HCM spanning the employment lifecycle and explicitly asks which evidence justified a hiring **or promotion** decision, while the protected TRD and Architecture stop `talent_acquisition` at recruitment and selection. Choosing option D would therefore require an explicit product-scope contraction and corresponding PRD/positioning change. No such contraction is currently supported by protected product truth. Options A and B would preserve the broad product promise only by moving post-hire planning into contexts whose lifecycle, aggregate invariants, privacy boundary, and mutation authority are different. + +This decision must be revalidated before acceptance if protected product scope or owner contracts change. A later scope contraction is an explicit ADR/product decision, not a silent deletion of the Talent boundary. + +## Alternatives + +### A. Expand `talent_acquisition` + +Use one context for candidate acquisition and post-hire talent management. + +**Advantages:** fewer deployable units and fewer integration edges. + +**Rejected for the selected product direction:** the lifecycle, actor set, privacy profile, and invariants change after employment. Acquisition evidence should not become post-hire talent authority, and a recruitment-focused context would accumulate unrelated succession, career, and internal-mobility semantics. + +### B. Put post-hire planning in `people_core` + +Treat talent planning as another property of people/employment. + +**Advantages:** easy access to Worker, Employment, and Assignment truth. + +**Rejected for the selected product direction:** convenience of co-location is not domain ownership. Talent pools, succession slates, and mobility decisions have versioning, evidence, fairness, expiry, and review lifecycles different from Person/Employment identity facts. Expanding `people_core` would increase aggregate and transaction scope and encourage direct coupling to HRIS identity records. + +### C. Add a dedicated `talent_management` bounded context + +Own post-hire talent-planning and talent-decision truth while consuming released references and events from existing owners. + +**Selected product direction; ADR remains Proposed.** This preserves acquisition, employment, organization, job, performance, and validation authorities while giving post-hire Talent a coherent lifecycle and audit boundary. + +### D. Declare post-hire Talent Management out of scope + +Keep Orgmetra limited to acquisition, employment, performance, and workforce validation. + +**Not selected under current protected product scope.** It remains a valid future scope-contraction alternative, but adopting it requires the PRD and positioning to stop implying a broader employment-lifecycle HCM capability. The product must not expose succession/talent-pool UI backed only by analytics or generic records. + +## Proposed bounded context + +The provisional identifier is `talent_management`. It is not part of protected architecture until this ADR is accepted and normally integrated. + +### Owned aggregates + +`TalentPool` +- identity, tenant, purpose, lifecycle state, effective/system version; +- versioned membership criteria/evidence policy reference; +- membership is a separate effective/system-dated relation rather than an embedded worker list. + +`SuccessionPlan` +- identity, tenant, target Position or other versioned owner reference, planning horizon, lifecycle state; +- versioned slate entries with evidence references and human review state; +- no Position or Assignment mutation occurs inside this aggregate. + +`InternalMobilityCase` +- worker, source Assignment reference, target Position/opportunity reference, lifecycle state, evidence bundle, accountable actor, and decision/confirmation record; +- completion emits an intent/result contract; authoritative Assignment changes remain owned by People/Organization coordination. + +A `CareerPreference`/`CareerInterest` record may become an owned aggregate only after privacy, employee-control, retention, and intended-use requirements are explicit. It must not be inferred from private behavior or assessment results by default. + +### Value objects and references + +At minimum, tenant-qualified opaque references, purpose code, evidence-set reference/version/digest, lifecycle state, business-effective interval, system-recorded interval, actor reference, reason code, and provenance reference must be modeled explicitly. A “readiness” or “potential” classification is not a primitive value object until its construct, scale, intended decision use, evidence requirements, expiry, uncertainty, and fairness semantics are versioned. + +A proposed `MaterialDecisionStageProvenance` value object or equivalent immutable record must make the material path reconstructable without becoming legal-classification truth. It records a stage identifier and order/causal predecessor, stage purpose/type, `decision_production_mode`, input evidence references/digests, model/tool/version where used, applicable decision-policy version, output/effect reference or digest, actor identity where present, human disposition and purpose-bound reason where intervention occurs, and system-recorded time. Stage records are append-only after material effect; corrections add linked replacement/reconsideration history rather than mutating the original path. + +A proposed `DecisionOpportunitySet` / `StageCohortManifest` value object or equivalent immutable record must make the **denominator** of each material stage reconstructable without becoming protected-group or fairness truth. It binds tenant and purpose; process/case/pool/plan identity and exact version; material stage identifier/order and causal predecessor; business-effective/system-recorded time or explicit measurement window; exact eligibility/decision-policy version and required evidence versions; an immutable manifest digest/reference plus its versioned canonicalization/digest-contract metadata for the in-scope opportunity set; a versioned counting/analysis unit; controlled transition classifications and counts; failure/error denominator; and relevant multiple-membership, cross-classified, or temporal context. It links to individual stage-provenance records without copying protected demographic attributes into Talent. Once a material stage closes, the manifest is immutable; correction appends a linked replacement/reconsideration version rather than rewriting the original denominator. + +Each closed manifest must also preserve entry-level membership through a `DecisionOpportunityEntry` or equivalent UL-approved record. An entry binds the parent manifest/version, an opaque semantic opportunity occurrence identity, purpose-authorized subject/worker reference and applicable target/case/pool/plan reference/version, inherited stage/policy/evidence/time lineage, one terminal transition classification at closure, and links to the corresponding material-stage provenance or to a controlled unavailable/not-evaluable reason when no evaluable stage record can exist. The semantic opportunity occurrence identity is stable across retries/replays of the same opportunity but distinct across genuinely separate opportunities involving the same person. Processing attempts and transport/runtime retries are operational telemetry linked many-to-one to an opportunity entry; they do not create denominator rows. + +Corrections preserve the same semantic opportunity occurrence identity unless a genuinely new business opportunity occurred. They append a linked correction/supersession entry or version, never mutate the historical entry in place, and must form a deterministic acyclic chain whose resolution leaves exactly one canonical active terminal entry for the occurrence. Historical entries marked or resolved as superseded remain immutable evidence but are excluded from denominator cardinality and terminal-classification sums. The canonical closed-stage terminal set is `advanced`, `not_evaluable`, `policy_inapplicable`, `human_excluded`, `automated_excluded_or_suppressed`, `withdrawn`, `unavailable`, and `failed`, subject only to explicitly versioned domain extensions. `stale_or_missing_evidence` and `authorization_or_owner_unavailable` are retryable conditions while the stage remains open and resolve to `unavailable` if closure occurs without recovery. `error_or_failure` is retryable while open and resolves to `failed` if closure occurs without recovery. `not_evaluable` is reserved for an explicit evaluability outcome under the governing evidence/construct contract and is not used to hide unavailable or failed cases. Pre-closure attempts and failures remain telemetry and are not terminal denominator rows. + +After canonical correction resolution, closure must reconcile deterministically: `entry_count == count(unique semantic opportunity occurrence identities) == count(canonical active terminal entries) == sum(counts of every canonical active terminal classification)`. Zero or multiple canonical active terminal entries for one closed occurrence, a cyclic/dangling/ambiguous supersession chain, remapping `unavailable`/`failed` into another class, omission of any terminal class from the sum, or any inclusion of superseded/attempt rows in these counts is invalid. Scientific grouping or estimand changes such as occurrence-level to person-level are performed explicitly by `workforce_validation` from released provenance and are not hidden Talent-side deduplication. + +A manifest replacement/reconsideration version is not a new business cohort merely because an evidence item or terminal classification was corrected. Versions that represent the same material stage/cohort correction lineage share a stable opaque manifest-lineage identity and immutable version/digest, with an explicit predecessor/supersession reference. The manifest digest is computed over an owner-versioned canonical semantic representation of the closed manifest: projection/field-set version, deterministic encoding/ordering and normalization rules, digest algorithm, domain separator, digest version and metadata-contract version are explicit, and the consumer can recompute the identity independently from released manifest evidence. Resolution of that lineage must be deterministic and acyclic. A requested historical/as-recorded view selects the exact manifest that governed the stage at the specified effective/system-time or decision cutoff; a corrected-as-of view selects the deterministic canonical replacement available at the specified correction/system-time cutoff. Superseded manifests remain immutable historical evidence but are not co-counted with replacements in one denominator view. Genuinely added or removed opportunities across replacement versions require controlled semantic-occurrence-level delta provenance and reason; a genuinely new stage/cohort must not be hidden as a correction version in the old lineage. + +Manifest lineage does not imply policy-semantic compatibility. Each closed manifest additionally binds the exact material `decision_policy_version` and a canonical policy-semantics/regime identity or digest. A replacement can remain in the same correction regime only when the owner can deterministically prove semantic compatibility of the rules that determine entry, evaluability, advancement, exclusion, ordering, suppression, or routing. A material procedure change creates a new policy regime even if it reuses the same stage/cohort business subject. An editorial/no-op reseal can stay in the same regime only with explicit semantic-equivalence evidence. `corrected_as_of` resolution therefore operates inside one compatible policy regime and must fail closed rather than cross an incompatible regime. Re-running historical opportunities under a new regime creates separately versioned analysis evidence and never rewrites the original as-recorded manifest or result. + +A proposed `PolicySemanticProjection` or equivalent owner value object makes that regime identity reproducible without copying upstream source truth. It records the semantic-projection schema identifier/version; canonical representation identifier/version; digest algorithm/domain/version; the exact material local policy fields after semantic normalization; and the released owner identity, immutable version/digest, and semantic role of every external dependency capable of changing stage behavior. Presentation labels, descriptions, timestamps, authoring metadata, or serialization order are excluded unless the versioned projection schema explicitly makes them material. The owner derives or verifies the policy-regime identity from this projection. Equivalence across policy versions is either deterministic equality under the same projection rules or a separately versioned `PolicySemanticEquivalence`/migration evidence record whose source and target projections, rule version, outcome, and provenance are immutable. A manifest and every released downstream result bind the projection schema/version and dependency set needed to reproduce the regime identity independently. + +An `ExternalSemanticDependencyReceipt` or equivalent released owner contract separates exact-artifact identity from downstream semantic authority without forcing a universal serialization format. It identifies the authoritative bounded context/owner and dependency slot; released contract/artifact/version and integrity digest; versioned downstream-material semantic projection/contract identity and semantic digest or equivalent; tenant/purpose/applicability/effective window where relevant; and any owner-issued deterministic equivalence/migration rule. A generic build/package digest is not semantic authority unless that owner contract explicitly defines the addressed projection as the downstream-material semantics. Talent stores and verifies the receipt; it does not parse foreign owner state to decide what changed semantically. + +A `MaterialStageExecutionAttestation` or equivalent immutable record binds the intended `PolicySemanticProjection` and exact owner receipts to the canonical stage attempt that actually produced the material terminal effect. It records an execution/attempt identity; trusted observed-resolved dependency/receipt identities, immutable versions/digests and final concrete model/tool/artifact identities; material runtime parameters not already fixed by the policy projection; the comparison-contract version; `execution_congruent`, `execution_incongruent`, or controlled unavailable/not-verifiable status; and a controlled mismatch reason. Requested aliases, provider/model groups, cache keys, or caller-submitted resolved digests are contextual telemetry only unless the trusted boundary also records the final immutable artifact/contract actually used. Retries keep separate resolution evidence; a terminal effect cannot inherit a congruence verdict from a different attempt. + +A proposed `OpportunityOriginEvidence` / `SourceUniverseReceipt` or equivalent released provenance contract makes the formation of the **first** observed Talent cohort reproducible without moving authoritative People/Organization/Job truth into Talent. It records a versioned origin mode and coverage semantics; authoritative owner/context and released snapshot/receipt/contract identity; tenant/purpose; source-universe or opportunity-universe definition; effective/system-time or measurement window; enumeration/discovery rule identity/version; coverage/completeness claim; controlled unavailable/failure coverage; and links to every material exposure/discovery/nomination/opt-in/import/prescreen transformation that occurs before the first manifest. The first manifest binds these material origin receipts in its evidence identity/digest. An exhaustive/enumerated source may support an explicit population-complete claim only when the released owner evidence proves that scope; nomination, employee opt-in, targeted discovery, external import, or another non-exhaustive origin remains non-exhaustive evidence rather than being promoted to completeness by convention. + +A proposed `SamplingDesignEvidence` / `ProbabilitySampleReceipt` or equivalent released provenance contract refines `OpportunityOriginEvidence` only when the first-stage origin is genuinely probability-based. It binds the exact source-universe receipt and sampled semantic opportunity set; target and sampling-unit definition; design identity/version; stage structure and replacement semantics; stratification, clustering, PPS, or other declared design; per-unit known non-zero inclusion probability or versioned stage-wise probability inputs sufficient to derive it; opaque stratum/PSU/cluster references where required; trusted sample-selection execution evidence including partial-frame/failure conditions; selected-unit response/disposition evidence; and append-only correction lineage. The receipt is provenance, not an analytic weight or variance result. `talent_management` does not derive design weights, variance estimators, FPC, calibration or nonresponse adjustments and does not acquire protected stratum attributes merely to make the receipt self-contained; those remain with the authoritative source/design owner and `workforce_validation`. + +A proposed `VarianceDesignEvidence` / `VarianceDesignReceipt` or equivalent released provenance contract refines that sampling evidence only when a probability-sampled origin is expected to support design-based uncertainty. It binds the exact source-universe receipt, sampling-design version, sampled semantic occurrence set, selection execution and correction version to a controlled variance-evidence strategy. Depending on the downstream method, the evidence may carry immutable joint-inclusion information, a released deterministic algorithm/parameterization that reproduces it, a replicate-weight contract, or an explicitly named/versioned approximation. Replication evidence identifies method/version, replicate count, scale/Fay-equivalent factors, construction provenance and semantic sampled-unit binding; certainty-unit, sampling-fraction/FPC or stage-specific information is included when the declared downstream method requires it. Storage need not be quadratic when an equivalent released reproducible representation is sufficient. This receipt does not authorize Talent to choose or compute the estimator: estimator selection, variance/SE/CI calculation and scientific interpretation remain `workforce_validation` authority. + +## Buyer journeys required by the selected scope + +These are domain/product journeys, not authorization to implement UI before the ADR and contracts are accepted. Each journey must expose normal, loading, empty, stale/unavailable-evidence, permission-denied, validation/conflict, and terminal decision states where applicable. A failed prerequisite remains visible and non-authorizing rather than being converted into a generic recommendation. + +### Talent pool planning + +1. An authorized Talent/HR partner opens a purpose-scoped pool for an explicit workforce objective and selects released Organization/Job/Position references rather than copying those records. +2. The partner defines and versions membership criteria and the allowed evidence policy. Criteria identify construct/qualification meaning; they are not free-form aliases for a hidden model score. +3. Before the first pool-candidate manifest is treated as a denominator, the process binds its exact origin/source-universe evidence. A complete-population claim requires an authoritative released owner universe receipt; nomination, opt-in, targeted discovery, import, or other non-exhaustive formation remains explicitly non-exhaustive, and any material pre-manifest filter is recorded as a material stage/source transformation rather than disappearing outside the decision graph. If that non-exhaustive origin is a probability sample, the process additionally binds the exact released sampling-design receipt, sampled occurrence set, inclusion-probability provenance, relevant design structure, actual sample-selection execution, and selected-unit dispositions; `non_exhaustive` alone is not sufficient design evidence. When downstream design-based uncertainty is part of the allowed scientific use, the process also binds the exact released variance-design evidence needed to reproduce the permitted uncertainty method rather than assuming first-order inclusion probabilities alone are universally sufficient. +4. The system resolves purpose-authorized worker/evidence references and distinguishes `eligible`, `not_evaluable`, stale/missing evidence, authorization/owner unavailability, and policy inapplicability. `unknown` is not converted to `not eligible`. The material stage is bound to the exact opportunity-set manifest used under those criteria/evidence versions rather than retaining only the people who reached the proposed pool. +5. The partner reviews proposed membership with exact evidence versions, reasons, uncertainty where relevant, and multiple-membership context. A worker may legitimately belong to multiple pools when the domain permits it. If an automated material stage proposed eligibility, exclusion, ordering, suppression, or routing, the reviewer must receive that stage's evidence/limitations and retain an actual pre-lock-in path to restore, disregard, override, or reverse its effect. +6. Human confirmation publishes a new pool/membership version and immutable provenance, including the ordered material-stage history, first-cohort origin evidence, and the closed opportunity-set/stage-transition manifest. A retry with the same idempotency key cannot duplicate membership history, duplicate the same semantic opportunity occurrence, or silently reconstruct a different denominator. + +Empty state means that no membership has been confirmed for the current criteria/version; it does not mean that the workforce contains no qualified people. Permission-denied behavior must not reveal whether a restricted `TalentPool` exists: for the same unauthorized actor/purpose/resource relation, an existing restricted pool identifier and a nonexistent identifier must produce the same externally observable status, body schema, empty-result semantics, and metadata envelope, with no pool name or count side channel. Before any Talent API implementation, a RED API contract must prove that indistinguishability rather than encoding resource existence in `not found` versus `forbidden` behavior. + +### Succession planning + +1. An authorized planner selects a released target Position and planning horizon. Talent does not create or alter the Position. +2. The system assembles purpose-bound references to Job/FJA/KSAO requirements, current worker/Assignment context, approved performance evidence, and Workforce Validation evidence where a construct claim is intended. If the first succession slate is formed by manager nomination, targeted discovery, or another selective origin, that origin remains explicit and is not presented as the complete eligible workforce without authoritative source-universe evidence. +3. Candidate/slate evidence is presented without a universal `potential_score` or automatic ordinal ranking as Talent truth. If a model or rule emits a ranking, threshold, shortlist, or suppression recommendation, that output remains a material-stage recommendation with versioned evidence and stage provenance; it cannot silently redefine qualification, potential, validity, or the reachable candidate set. Every such material stage also closes against the exact upstream opportunity-set manifest so a later slate cannot become its own denominator by omission. +4. Missing, stale, inaccessible, or unverifiable required evidence blocks confirmation and identifies the missing authority. A zero-person slate remains a legitimate empty state. An option removed by an automated stage remains reconstructable and recoverable to the accountable reviewer whenever that reviewer is expected to exercise substantive oversight. +5. An accountable human records slate decisions, reasons, evidence versions, stage dispositions, and confirmation. Publication creates immutable succession-plan, material-stage, origin/source-universe, and stage-cohort history; it does not reserve Position capacity or mutate Assignment truth. +6. Later corrections append system-recorded history rather than rewriting the earlier planning state, source-universe evidence, or its denominator. + +A manager who can view a worker profile is not thereby allowed to inspect a succession slate. Restricted slate existence/counts are not disclosed through unauthorized empty/error responses. + +### Internal mobility + +1. The case begins from an explicit employee interest, an authorized nomination, or another versioned policy-allowed source. The origin, its coverage semantics, and visibility of the case are recorded. Employee opt-in or nomination is not reinterpreted as an exhaustive population merely because it is the first persisted mobility cohort. +2. Talent resolves the current Employment/Assignment, target Position/opportunity, Job/FJA/KSAO requirements, and allowed evidence through released owner contracts. +3. The system presents evidence gaps and conflicts before a human decision. A stale target Position, inaccessible evidence, changed Assignment, or capacity uncertainty yields a refresh/conflict state, not an inferred approval or rejection. Any automated screening, routing, ranking, or suppression that materially changes consideration is separately recorded as a material decision stage and cannot be hidden behind a later confirmation. Where that stage operates over more than one eligible opportunity or worker, its exact opportunity-set and transition denominator are retained under the same policy/evidence/time lineage. +4. An accountable human records the mobility decision, exact evidence versions, and any AI-assisted material-stage disposition. LLM text may summarize or draft rationale but cannot confirm the decision. +5. A confirmed mobility case emits an idempotent intent/result contract to the authoritative coordination path. `talent_management` does not decrement Position capacity and does not write Assignment rows. +6. If authoritative downstream mutation rejects the request because capacity, Assignment, policy, or protected truth changed, the Talent case records the rejection/reference and returns to a reviewable conflict state. It does not fabricate success or replay indefinitely. +7. Completion binds the downstream authoritative result reference and immutable audit/provenance so the planning decision and actual employment change can be distinguished later. + +### Employee career interest and preference + +1. An employee explicitly records, edits, limits visibility of, or withdraws a career interest under a declared purpose and retention policy. +2. The system does not infer the interest from private communications, assessment responses, browsing behavior, or model output by default. +3. Withdrawal/correction preserves required audit history while removing the interest from active decision use according to retention/legal-hold policy. +4. A planner who lacks purpose/resource authorization receives no hidden interest content or inference that an interest exists. + +Career interest is employee-controlled evidence, not a promise of mobility, a qualification fact, or a validated latent trait. + +### Decision explanation, review, and correction + +This is a cross-cutting journey for high-impact Talent outcomes. It is activated by the applicable tenant policy and jurisdictional/legal contract; the ADR does not assume that every human-assisted or automated workflow creates the same statutory right. + +1. Before finalization, the decision record binds the ordered set of material decision stages as well as the final outcome. Each material stage preserves its actual production mode, exact input evidence/policy versions, model/tool version where used, output/effect lineage, and recorded human disposition where present. A final `ai_assisted_human_decision` label cannot erase an earlier fully automated eligibility, exclusion, ranking, suppression, threshold, or routing stage. +2. The final record also binds accountable actors, reason, downstream authority references, and the final `decision_production_mode`. Under the current Proposed contract, a `fully_automated_decision` final outcome may be retained only as non-authorizing imported/historical provenance; a Talent command attempting to finalize a high-impact outcome in that mode is rejected. +3. `ai_assisted_human_decision` finalization requires effective, substantive intervention rather than actor presence. Before a material automated result becomes locked, the accountable reviewer must receive the relevant evidence and known limitations, be able in practice to inspect the affected option set, and have a real path to disregard, override, reverse, restore, or reject the automated effect. The reviewer records a controlled disposition such as `accepted`, `modified`, or `rejected` plus a purpose-bound reason and immutable provenance. A disabled, unreachable, or purely cosmetic override control does not satisfy this contract. +4. Automated exclusion or recommendation suppression must not make an affected worker or option invisible to the reviewer who is expected to provide substantive oversight. A versioned policy may define applicability or required evidence, but it cannot authorize hidden or irreversible automated effects or remove the required pre-lock-in restore/reversal path. If the material effect is hidden from the accountable reviewer, irreversible before finalization, or lacks an actually available pre-lock-in restore/reversal path, high-impact finalization fails closed. A later confirmation cannot convert such an automated exclusion into substantively human-supervised provenance. +5. Where an applicable policy requires notice, explanation, refusal/review, or correction rights, the system resolves the then-current versioned policy before finalization. Missing, stale, or unverifiable required policy evidence fails closed rather than silently treating the decision as unregulated. +6. An affected worker can request the applicable explanation, review/reprocessing, correction, or other configured recourse through a purpose-scoped request. The response can reconstruct material-stage provenance without disclosing another worker's succession-slate position, assessment result, career interest, or other protected evidence. +7. Human reprocessing or reconsideration creates a new decision version linked to the original decision, original stage chain, and rights request. It never overwrites the earlier outcome or provenance. If the earlier outcome has already changed Assignment or Position truth, any corrective employment mutation is issued through the authoritative People/Organization contract rather than written by Talent. +8. Statutory or policy response periods, refusal grounds, notice contents, and jurisdictional applicability are versioned policy data, not universal Talent-domain constants. Current primary-source drivers include Korea's Personal Information Protection Act automated-decision provisions and the EU AI Act's employment/high-risk explanation and human-oversight regime. Both are conditional in scope and timing; implementation must re-check then-current law and must not infer compliance merely from a final label, reviewer identity, or confirmation event. + +The EU AI Act Article 14 human-oversight requirements are used here as design and traceability evidence where applicable, including awareness of automation bias and the ability, as appropriate and proportionate, to interpret, disregard, override, reverse, intervene in, or stop AI-system output. They do not make every Orgmetra Talent workflow legally subject to Article 14, and they do not move legal applicability from the versioned compliance-policy owner into `talent_management`. + +## Invariants + +- A Talent record never becomes the authoritative source for Person, Employment, Assignment, Organization, Position, Job/KSAO, performance, or assessment truth. +- Cross-context references are validated through released/versioned owner contracts or immutable owner events; mutable branch APIs and direct cross-schema reads are forbidden. +- Where historical reconstruction matters, membership/slate/case facts are bitemporal. Retroactive correction closes recorded history and appends replacement truth rather than overwriting protected records. +- Final talent-review, succession, or mobility decisions require an accountable human actor and immutable evidence/provenance. Model-generated text or scores cannot self-authorize a final decision. A `fully_automated_decision` final outcome is non-authorizing provenance under this Proposed contract and cannot finalize a high-impact Talent outcome; an AI-assisted final decision requires substantive human intervention plus accountable human confirmation. +- Every material decision stage is recorded separately and immutably. Its production mode, model/tool references, input evidence/policy versions, output/effect lineage, actor/disposition where present, and ordering cannot be collapsed into or rewritten by the final decision label. +- Every material decision stage also closes against an immutable opportunity-set/stage-cohort manifest bound to the same stage, policy/evidence versions and effective/system-time or measurement window. Downstream survivors cannot substitute for the original denominator, and controlled unavailable/error/exclusion/suppression outcomes cannot be silently omitted. +- Every closed opportunity manifest has exact entry-level membership, a versioned counting/analysis unit, and one semantic opportunity occurrence identity per denominator entry. The same semantic opportunity is idempotent across retries/replays; distinct legitimate opportunities involving the same worker remain distinct. Runtime processing attempts do not create denominator entries. +- Each closed semantic opportunity occurrence resolves through its append-only correction/supersession chain to exactly one canonical active terminal entry. The canonical terminal classification is explicit and mutually exclusive: `advanced`, `not_evaluable`, `policy_inapplicable`, `human_excluded`, `automated_excluded_or_suppressed`, `withdrawn`, `unavailable`, `failed`, or an explicitly versioned additional domain terminal. `unavailable` and `failed` are not silently remapped into `not_evaluable`. Superseded historical entries and processing/retry attempts remain immutable evidence but do not contribute to denominator or terminal totals. A closed manifest with zero or multiple canonical active terminal entries for one occurrence, or with a cyclic/dangling/ambiguous chain, is invalid. +- At stage closure, opportunity cardinality reconciles after canonical resolution: `entry_count`, unique semantic opportunity occurrence identities, canonical active terminal entries, and the sum of **all** canonical active terminal classifications are equal. +- Opportunity-set corrections are append-only linked versions. They cannot rewrite the original denominator after stage closure, and relevant multiple-membership, cross-classified, repeated-opportunity, and temporal structure must remain reconstructable rather than being flattened for convenience. +- Replacement/reconsideration manifests for the same material stage/cohort share one stable manifest-lineage identity. Each closed version is immutable and digest-addressable, names its predecessor when it supersedes one, and participates in a deterministic acyclic lineage. Manifest digest identity is reproducible from versioned canonical manifest semantics, deterministic serialization/ordering/normalization, explicit digest algorithm/domain/version and metadata-contract version; consumers recompute and validate it rather than accepting an opaque digest assertion. Exactly one manifest may be selected for a given lineage/view/as-of cutoff; a predecessor and its replacement are never silently unioned into one denominator. +- Historical/as-recorded and corrected-as-of views are distinct evidence semantics. A historical view binds the manifest that actually governed the stage at the requested time/cutoff; a corrected-as-of view binds the deterministic replacement available by the requested correction/system-time cutoff. Consumers cannot substitute an unqualified `latest` for either contract. +- Cross-version manifest deltas are explicit: corrected occurrences preserve semantic occurrence identity; added/removed opportunities or changed terminal outcomes carry controlled reason/provenance. A genuinely new stage/cohort uses a new lineage rather than masquerading as a correction, while a mere correction cannot mint a new lineage to evade historical reconciliation. +- Policy-semantic compatibility is independent of manifest lineage. Each manifest binds the exact decision-policy version and canonical policy-regime/semantic identity. `corrected_as_of` may traverse only replacements that are deterministically evidenced as materially semantically compatible. Material changes to eligibility, cut score/threshold, ranking/order, required-evidence meaning, suppression/routing, or equivalent entry/advancement/exclusion rules start a new regime; editorial/no-op reseals may remain in the old regime only with explicit semantic-equivalence evidence. +- Policy-regime identity is owner-derived evidence, not a caller assertion. Its versioned semantic projection explicitly includes every local rule and released external dependency that can materially affect the stage, excludes declared non-semantic presentation/editorial fields, and uses explicit canonical-representation and digest algorithm/domain/version metadata. The owner recomputes or verifies the identity before accepting it; mutable/floating dependency references and live cross-service state cannot participate. +- Same-regime equivalence is reproducible: either canonical semantic projections are deterministically equal under the same rules, or a separately versioned/auditable equivalence migration binds the exact source projection, target projection, rule version, outcome, and provenance. Free-form operator claims such as “no semantic change” are not authority. +- External dependency integrity and semantic authority are separately reproducible. Every material external dependency binds exact released bytes/object identity and an owner-issued downstream-material semantic receipt/equivalence contract. Talent cannot infer semantic sameness from version shape, labels, a generic artifact digest, or foreign source inspection. An owner may intentionally make one digest serve both roles only through an explicit released semantic contract. +- Material stage execution provenance reconciles the expected policy projection/owner receipts with trusted observed-resolved dependencies and material runtime parameters. A stage that is incongruent, unavailable to verify, resolved through an unpinned alias/fallback/stale cache, or missing a material expected dependency is non-authorizing; retries cannot borrow another attempt's congruence evidence. +- The first observed cohort has explicit origin/coverage semantics. A first manifest cannot self-certify `population_complete`: that claim requires a released/versioned source-universe receipt or equivalent authoritative evidence. Nomination, opt-in, targeted discovery, external import, and other intentionally non-exhaustive origins remain non-exhaustive unless separately supported by authoritative completeness evidence. +- Every material pre-M1 exposure/discovery/nomination/prescreen transformation appears in the material-stage/source-transformation graph with policy/evidence/execution provenance. Missing or failed enumeration/exposure remains explicit coverage evidence and cannot silently shrink the source universe. +- First-manifest origin/source receipts are purpose-minimized, immutable, versioned, time-bound, and included in the material evidence identity/digest. Later source-universe correction is append-only; a material enumeration/discovery-rule change follows policy-regime semantics rather than being mislabeled as record correction. +- A probability-sampled origin preserves the exact authoritative source-universe receipt, sampling-design identity/version, sampled semantic occurrence set, unit/stage inclusion-probability provenance, relevant stratum/PSU/cluster or other design membership, trusted actual sample-selection execution, frame/coverage failures, and selected-unit dispositions. `non_exhaustive` by itself is not a probability-sampling contract. +- Sampled refusal/opt-out, unreachable/unavailable, post-selection ineligibility, and processing failure remain distinguishable from never-sampled units. Retry/replay cannot create another sampled unit or another probability for the same semantic sample occurrence, and released sampling evidence is corrected append-only rather than overwritten. +- Non-probability nomination, opt-in, ranking, quota or deterministic-percentage cohorts cannot carry fabricated inclusion probabilities or probability-sample labels. Talent does not reconstruct strata or analytic weights through foreign SQL/source copying or protected-demographic replication; sensitive design membership is represented by purpose-bound opaque owner/design receipts when needed. +- Probability-sampling provenance is not the analysis. `workforce_validation` explicitly chooses the estimand and owns design weights, variance/SE/CI, FPC, calibration/nonresponse adjustment, protected-group joins, validity/fairness/adverse-impact methods and interpretation from released right-cleared evidence. +- A probability-sampled origin that supports design-based uncertainty also binds variance-sufficient released design evidence for the method actually claimed. First-order inclusion probabilities alone are not treated as universal variance evidence: required joint-inclusion information or an equivalent deterministic design representation, replicate-weight construction metadata, certainty/FPC inputs, or an explicitly versioned approximation is retained according to the method. Silent SRS/with-replacement substitution and presenting an approximation as another design's exact variance are acceptance failures. +- Sampling-design evidence and variance-design evidence are separately versioned but causally bound. A released result identifies both the exact #405 sampling receipt/sample/correction version and the exact variance evidence/method/version used. A mismatch between sample, design, correction, replicate construction, or variance receipt fails closed; missing variance-sufficient evidence remains `not_verifiable` rather than becoming a scientific GREEN. Estimator choice and calculation remain `workforce_validation` authority. +- Every manifest and released downstream result retains enough released source-universe/origin evidence, and, when sampling applies, exact sampling-design/disposition evidence plus any variance-design evidence required for the claimed uncertainty method, projection-schema/version, exact external semantic receipts, observed execution-congruence evidence, exact manifest-digest contract metadata and exact material dependency identities/versions/digests to reproduce both denominator identity, cohort-formation semantics, sampling design, uncertainty-method provenance, and the intended/actually executed procedure independently. A digest collision or mismatch fails closed for integrity review and does not by itself prove semantic equivalence. +- Every released `workforce_validation` or buyer/scientific result that consumes a Talent denominator records the exact first-stage source-universe/origin scope and coverage evidence; when applicable, the exact sampling-design/version, sampled occurrence set, inclusion-probability provenance, relevant design structure, response/disposition evidence, variance-design receipt and variance-method/version actually used; manifest lineage, selected immutable version/digest plus digest-contract version, requested view, as-of cutoff, governing policy-regime identity, semantic-projection schema/version, external owner receipts, execution-congruence evidence, and material dependency provenance needed to reproduce the procedure. A later correction cannot mutate that released result's evidence identity; recomputation produces a new result/evidence version. Re-analysis under a materially changed policy is a separately versioned analysis, not a retroactive correction. +- `talent_management` owns only purpose-minimized process/cohort/sampling provenance. Protected demographic attributes and fairness/validity/scientific verdicts stay with their authoritative owners; `workforce_validation` consumes released source-universe/cohort/provenance evidence, chooses the analytic estimand/grouping/design-based analysis rule explicitly, and does not reconstruct the cohort or sampling design through cross-service SQL or copied Talent/protected-attribute tables. +- An upstream fully automated material stage may contribute only while its material effect remains inspectable, reconstructable, and genuinely reversible before high-impact finalization. If it irreversibly excludes/suppresses an option or prevents the accountable reviewer from seeing the material basis or recovering the affected option, finalization fails closed. No policy approval or applicability rule may bypass this oversight invariant. +- Decision-production provenance is immutable: the recorded final mode, ordered stage modes, model/tool references, human-intervention evidence, policy versions, evidence versions, and outcome lineage cannot be relabeled after the outcome merely to change legal or governance classification. A human identifier, signature, or confirmation event alone does not prove substantive human intervention. +- Effective human intervention is demonstrated by pre-lock-in access to relevant evidence and known limitations, an actually operable disregard/override/reversal path, visibility or recoverability of materially affected options, and a recorded human disposition plus purpose-bound reason/provenance. The existence of a nominal reviewer step is not sufficient. +- Rights requests, explanations, and reconsidered decisions are append-only linked records. They preserve the original outcome and material-stage path while minimizing third-party worker information and keeping any employment correction under its authoritative owner. +- Assessment and performance evidence is purpose-bound and version-pinned. Stale, missing, inaccessible, or unverifiable evidence fails closed for decisions that require it. +- Multiple legitimate pool memberships are allowed; uniqueness rules apply only to semantically single-valued relations. Database constraints must not erase valid multiple membership. +- Internal mobility does not reserve or consume Position capacity unless a released Position-capacity contract explicitly grants that operation. It does not write Assignment truth directly. +- Idempotency, inbox/outbox, retry, compensation, event deduplication, and immutable evidence receipts are part of mutation contracts rather than UI behavior. +- Sensitive career, succession, assessment, performance, decision-stage, opportunity-set/stage-transition, source-universe/origin, sampling-design/disposition, variance-design, and rights-request references use purpose-bound minimization, explicit retention, export controls, and audit evidence. A user who may view an employee profile is not automatically authorized to view a succession slate. + +## Scientific boundary + +Talent Management may store decision policy versions and references to evidence; it does not manufacture construct validity. Any `potential`, `readiness`, `fit`, or similar claim must identify the construct definition, target decision, predictor/evidence version, criterion relationship where predictive interpretation is intended, uncertainty, transportability/generalizability limits, and fairness/adverse-impact evidence. `workforce_validation` remains the authority for validity-study linkage and scientific evaluation. + +Sampling and outcome evidence must preserve design/error/failure denominators and relevant multilevel, cross-classified, multiple-membership, repeated-opportunity, and temporal structure. For every material Talent stage, the denominator must be reconstructable from immutable entry-level opportunity membership tied to the same exact stage, criteria/policy/evidence versions, counting unit, and effective/system time or measurement window as the individual provenance. A shortlist, slate, ranking output, aggregate transition count, or final outcome set is not an acceptable substitute for the upstream opportunity set merely because it is easier to query. Repeated opportunities for one worker remain observable so `workforce_validation` can choose and document an occurrence-level, case-level, or person-level estimand instead of inheriting an implicit Talent-side deduplication rule. Superseded correction history and retry attempts remain available for audit but are excluded from the canonical denominator; each closed semantic occurrence contributes exactly one active terminal outcome from the explicit mutually exclusive terminal vocabulary, including `unavailable` and `failed` where those conditions remain unresolved at closure. When immutable manifest replacements exist, the scientific denominator is additionally bound to an explicit manifest-lineage/version/digest **and the manifest-digest contract metadata needed to recompute that digest**, plus a temporal/correction view: an as-recorded analysis preserves the denominator that governed the original decision at its cutoff, while a corrected-as-of analysis selects the deterministic replacement available at the declared correction/system-time cutoff. These views are not interchangeable, and neither may silently union predecessor and replacement manifests. + +The first recorded denominator additionally needs **origin/coverage evidence**. A first Talent manifest is an observed cohort, not proof of the population from which it arose. If the product or a scientific result claims that M1 exhausts a defined worker/opportunity universe, that claim must be bound to released/versioned owner source-universe evidence and its enumeration rule, time window, coverage semantics, and explicit failures/unavailable portions. If M1 arose through nomination, employee opt-in, targeted discovery, import, sourcing, or another selective mechanism, that selection mechanism remains part of the scientific provenance and the cohort stays conditional on that origin. Alexander et al. (2025) is used only for this narrower design implication: an upstream sourcing/prescreen can change who enters the observed pool before later selection-rate analysis begins. It is not direct empirical evidence for Orgmetra succession/internal mobility and does not create a universal legal reporting rule. `workforce_validation` receives enough released evidence to distinguish source universe/origin scope, M1, and later stage denominators before selecting an estimand or making fairness/validity claims. + +When that selective origin is a genuine **probability sample**, design-based reproducibility requires the sampling design itself rather than a generic `non_exhaustive` marker. Horvitz and Thompson (1952) are used for the narrow statistical premise that unequal-probability finite-population estimation depends on inclusion probabilities; AAPOR disclosure and Standard Definitions material is used only as provenance/reporting evidence for distinguishing probability from non-probability sampling, describing frame/coverage and design effects, and retaining selected-case dispositions. Orgmetra does not import survey-specific disposition codes or treat AAPOR guidance as an employment-law rule. `talent_management` preserves the released design and selection/disposition provenance required to identify what sample was actually drawn; `workforce_validation` determines the estimand, design weights, variance/SE/CI, FPC, calibration/nonresponse adjustment, fairness/validity methods and interpretation from right-cleared evidence. + +For probability-sampled origins that support uncertainty claims, design-based reproducibility also requires **variance-sufficient evidence for the method actually used**. Berger (2004) is used for the narrow methodological distinction that the Sen–Yates–Grundy variance estimator depends on joint inclusion probabilities while first-order-only alternatives such as Hájek are different estimators, not proof that `π_i` is universally sufficient. U.S. Census Bureau Statistical Quality Standard D1 and SIPP sampling-error guidance are used as methodological/provenance evidence that variance estimation must account for the sample design and that retained design variables, replicate weights or final variance specifications may be needed to reproduce uncertainty. Orgmetra does not mandate one variance estimator, pairwise matrix representation, or Census method. `talent_management` binds purpose-minimized released variance-design evidence when required; `workforce_validation` chooses and computes the estimator and records whether the method is exact or approximate. + +The governing selection procedure is part of the scientific evidence identity. Every denominator view also binds the exact material policy-regime/semantic identity that produced it. A material eligibility, threshold/cut-score, ranking/order, required-evidence, suppression/routing, or equivalent selection-procedure change cannot be treated as a mere data correction of the old regime. A semantic-preserving reseal can remain compatible only with explicit equivalence evidence. Historical evidence remains as-recorded under its original regime; re-analysis under a new regime creates a new simulation/counterfactual/analysis result. Talent preserves the provenance needed to identify the procedure, while `workforce_validation` retains authority for transportability, validity, fairness/adverse impact, estimand and interpretation. + +That procedure identity must be independently reproducible rather than opaque. Talent publishes the versioned semantic-projection schema, canonical representation and digest algorithm/domain/version, and the exact released material dependency identities/versions/digests used to compute or verify each regime. External-owner integrity identity and semantic authority are not conflated: `workforce_validation` receives the exact released owner semantic receipts/equivalence evidence that Talent used, rather than relying on a generic artifact digest or forcing Talent to reconstruct foreign Job/FJA/KSAO/assessment/model/tool semantics. A local policy whose bytes did not change is still a new or incompatible regime when a pinned external dependency materially changes the procedure; conversely, a presentation-only reseal does not mint a new regime merely because a timestamp, label, or serializer order changed. + +Scientific reproduction must also distinguish the procedure declared from the procedure actually executed. Each material stage supplies trusted observed-resolved dependency/receipt identities and material runtime parameters for the canonical terminal attempt, plus an explicit execution-congruence result against the intended projection. A downstream study cannot claim to evaluate policy regime A if the runtime actually used B, a stale cache, an undisclosed fallback, or an unresolved alias. Execution congruence establishes which procedure ran; it does not establish validity or fairness. `workforce_validation` retains authority for scientific support, fairness/adverse impact, transportability, estimand, and interpretation. + +Synthetic data proves mechanics only. Buyer/scientific claims require provenance-backed right-cleared data. Protected-group joins, adverse-impact/fairness calculations, estimand/grouping choices, validity inference, uncertainty analysis, and scientific conclusions remain `workforce_validation` authority and must consume released purpose-authorized source-universe/cohort/provenance evidence rather than direct Talent SQL or copied protected attributes. Each released scientific result records the exact first-stage source-universe/origin scope and coverage evidence and, where a probability sample formed the observed cohort, the exact sample-design/version, sampled occurrence set, inclusion-probability provenance, relevant design structure, selected-unit disposition evidence, and when the claimed uncertainty method requires it, the exact variance-design receipt and variance-method/version; plus Talent manifest lineage/version/digest/digest-contract/view/as-of, governing policy-regime identity, semantic-projection schema/version, external semantic receipts, execution-congruence evidence, and material dependency provenance that supplied its denominator. Later corrections or materially changed procedures require a new result/evidence version rather than rewriting the earlier result. + +## Context map + +- `people_core` → `talent_management`: released Worker/Employment/Assignment references and change events plus purpose-authorized/versioned source-universe receipts or immutable projections when a Talent process claims coverage over a defined worker/assignment universe; Talent is downstream for planning evidence and cannot write those tables. +- `organization_core` → `talent_management`: released Organization/Position references and capacity/structure evidence plus source-universe receipts where a Position/opportunity universe is material; mutation remains upstream-owned. +- `job_architecture` → `talent_management`: released Job/FJA/KSAO/qualification versions plus owner-issued semantic-dependency receipts/equivalence evidence and, where relevant, source-universe/enumeration evidence; no source copying or downstream semantic reconstruction. +- `performance_management` → `talent_management`: purpose-authorized criterion/observation references or versioned summaries and owner semantic receipts where materially composed into Talent selection policy; no raw-table access. +- assessment/model/tool owners → `talent_management`: released immutable artifact/contract identity plus owner-issued downstream-material semantic identity/equivalence evidence and, where execution indirection exists, final immutable resolution evidence; configured aliases are not authority. +- source-universe/design owners → `talent_management`: released purpose-bound source-universe receipts and, when probability sampling is used, versioned sampling-design/selection receipts sufficient to preserve known inclusion-probability and design-membership provenance without copying sensitive frame or stratum truth; when design-based uncertainty is supported, the authoritative design owner or `workforce_validation` may additionally issue a versioned purpose-bound variance-design receipt sufficient for the permitted downstream method without moving estimator choice into Talent. +- `workforce_validation` → `talent_management`: versioned validity/fairness/uncertainty evidence and assessment-result references; Talent does not re-label model scores as validated constructs. +- `talent_management` → `workforce_validation`: released/versioned purpose-minimized first-stage opportunity-origin/source-universe evidence; when sampling applies, exact sampling-design/version, sampled semantic occurrence set, inclusion-probability provenance, relevant design structure, trusted selection execution and selected-unit dispositions, plus any exact variance-design receipt required for the claimed uncertainty method; decision-opportunity entries, stage-transition, individual-stage provenance, exact selected manifest lineage/version/digest/digest-contract/view/as-of, governing material policy-regime/semantic identity, semantic-projection schema/version, exact external owner semantic receipts, stage execution-congruence evidence, and exact released material dependency identities/versions/digests sufficient for authorized independent scientific reproduction. Protected demographics and scientific verdicts do not flow back into Talent as copied source truth. +- `talent_management` → `audit_provenance`: immutable high-impact decision evidence, including first-stage origin/source-universe and sampling-design/variance-design receipts where applicable, ordered material decision-stage provenance, stage-opportunity manifests, manifest replacement lineage, external semantic receipts, actual-execution congruence, final decision-production mode, and rights/reconsideration lineage where applicable. +- `talent_management` ↔ `integration_hub`: versioned external adapters, inbox/outbox, migration/CDC contracts. +- Keyverse supplies identity/authentication and policy identity; it does not own Talent domain truth. +- Any future legal/compliance-policy owner is consumed through a released/versioned policy contract or immutable tenant policy artifact. This Proposed ADR creates no mutable cross-repository dependency and does not assign legal applicability authority to Talent. + +## Persistence and operability requirements if accepted + +Use a service-owned `talent_management` PostgreSQL schema and keep schema/migration ownership separate from runtime application principals; shared physical-cluster deployment does not permit cross-service application SQL. Normalize anchors, versions, memberships/slates/evidence links, immutable material-stage provenance, immutable stage-opportunity/transition manifests and entry-level opportunity occurrences, first-stage opportunity-origin/source-universe receipts, sampling-design/selection/disposition provenance where applicable, variance-design evidence where applicable, and decision/audit references in 3NF. Every tenant-bearing `talent_management` table must have row-level security enabled and `FORCE ROW LEVEL SECURITY` applied. Runtime application roles, including `talent_management_role`, must be `NOSUPERUSER NOBYPASSRLS`; superusers are excluded from application traffic and must never be used as the runtime principal. Tenant-qualified foreign identifiers, append-only/finalized evidence membership, exclusion/uniqueness constraints only where the domain is single-valued, and concurrent correction tests are required. PostgreSQL acceptance must prove both FORCE-RLS owner behavior and cross-tenant denial under a non-superuser, NOBYPASSRLS application role. + +Opportunity manifests are evidence records, not mutable analytics caches. Stage closure must bind a deterministic manifest/reference, explicit counting unit, exact entry membership, unique semantic opportunity occurrence identities, and controlled terminal transition counts without retaining unnecessary protected attributes. Closure resolves each occurrence's append-only correction/supersession chain to exactly one canonical active terminal entry before counting; historical superseded rows and processing/retry attempts are excluded from denominator and terminal totals. The canonical terminal set includes `advanced`, `not_evaluable`, `policy_inapplicable`, `human_excluded`, `automated_excluded_or_suppressed`, `withdrawn`, `unavailable`, and `failed`; `unavailable` is unresolved evidence/authorization/owner availability at closure, `failed` is unresolved error/failure at closure, and `not_evaluable` remains a separate explicit evaluability outcome. Closure fails unless `entry_count`, unique occurrence cardinality, canonical active terminal cardinality, and the sum of every canonical terminal classification reconcile exactly. A retry/replay of the same opportunity reuses the same semantic occurrence and cannot create another denominator row; a distinct legitimate opportunity for the same worker cannot be collapsed into the first. A correction preserves the occurrence identity and creates a linked replacement/reconsideration version unless a genuinely new opportunity occurred; it cannot update the historical denominator in place. Retryable stale/missing-evidence, authorization/owner-unavailable, and error/failure conditions remain attempt/state evidence while a stage is open; if the stage closes without recovery they resolve respectively to `unavailable` or `failed`, rather than being omitted or silently remapped. A cyclic, dangling, or ambiguous occurrence-level supersession chain is an acceptance failure. + +The first manifest also persists immutable **origin/coverage evidence**. A complete-population claim stores or references the exact released owner source-universe contract/snapshot identity, tenant/purpose, universe definition, effective/system-time window, enumeration rule/version, coverage/completeness semantics, and explicit unavailable/failure coverage. An intentionally non-exhaustive origin stores that origin classification and the material nomination/opt-in/discovery/import/exposure provenance necessary to explain who could enter. The first manifest digest includes material origin/source receipts under the same versioned digest contract. Source-universe correction appends a new linked evidence version; it cannot mutate the origin evidence that governed a historical first manifest or released result. Mutable query text, live cross-context SQL results, free-text `all employees` labels, or copied protected attributes are not persistence authority for completeness. + +If that first-stage origin is a probability sample, persistence also binds the exact source-universe receipt to a versioned sampling-design/selection receipt and the sampled semantic occurrence set. Store or reference the design/stage identity, with/without-replacement semantics, inclusion-probability or derivation inputs with stage attribution, purpose-minimized design memberships required for downstream variance estimation, trusted actual selection execution, frame/coverage failures, and selected-unit dispositions. Enforce valid probability domains where a known unit probability is required and reject missing/ambiguous/wrong-stage values. Sampling retries are idempotent at the semantic sample occurrence and cannot create a second sample unit or probability. Corrections are append-only. Sensitive strata use opaque owner/design references when possible; Talent does not persist protected demographics or analytic weights merely to make the receipt self-contained, and it never manufactures probability fields for a non-probability origin. + +When design-based uncertainty is supported for that probability sample, persistence also binds a separately versioned variance-design receipt to the exact sampling receipt/sample/correction identity. Store or reference the controlled strategy and only the purpose-minimized evidence needed to reproduce it: joint inclusion information or an equivalent deterministic design representation where required, replication method/version/count/scaling/Fay-equivalent factors and construction lineage for replicate-based methods, and certainty/FPC/stage-specific inputs when required. Exact versus approximate semantics and assumptions are explicit. A sample/design/correction mismatch, ambiguous replicate construction, missing required pairwise information, or in-place mutation of released variance evidence fails closed. Talent does not compute final variance or copy foreign protected frame/cluster/stratum truth merely to make the receipt local. + +Manifest-level replacement is independently versioned. A correction/reconsideration of the same stage/cohort retains one stable lineage identifier, writes a new immutable manifest version/digest with an explicit predecessor, and records semantic-occurrence-level additions/removals/terminal changes with controlled provenance. Digest metadata is part of the owner contract: canonical semantic field-set/projection version, deterministic serialization/ordering/normalization rules, digest algorithm/domain separator/version and metadata-contract version are stored/published so consumers can recompute and validate the digest from released manifest evidence. The manifest supersession graph must be acyclic and resolve deterministically to one selected version for the requested view and cutoff; competing canonical successors, dangling predecessors, implicit `latest`, opaque/non-recomputable digests, or blind predecessor+replacement unions fail closed. Historical/as-recorded reads select the manifest that governed the stage at the requested cutoff, while corrected-as-of reads select the canonical replacement available by the requested correction/system-time cutoff. A released downstream analysis stores that exact selection and digest-contract identity so later corrections cannot mutate its evidence identity. + +Policy-regime compatibility is persisted as provenance rather than inferred at read time. Every closed manifest stores the exact decision-policy version and canonical material policy-regime/semantic identity or digest used to produce the opportunity set and transitions. A same-regime replacement must carry deterministic semantic-compatibility evidence; a materially changed eligibility, cut-score/threshold, ranking/order, required-evidence, suppression/routing, or equivalent selection rule starts a new regime and cannot be linked as an ordinary correction traversable from the previous regime. Editorial/no-op reseals may remain compatible only with explicit equivalence evidence. Queries requesting `corrected_as_of` inside a regime fail closed on incompatible or ambiguous successors. Re-analysis under a new regime creates new analysis evidence rather than rewriting prior manifest or result identities. + +Policy-regime identity persistence is dependency-closed and reproducible. Store or publish the projection-schema identifier/version, canonical-representation identifier/version, digest algorithm/domain/version, exact owner-computed regime identity, and immutable released identity/version/digest of each material external dependency used by the projection. Do not persist a caller-supplied regime identifier as authority without recomputation/verification. Do not dereference mutable branches, floating labels, or live cross-service SQL state to reconstruct identity. Any separately versioned semantic-equivalence migration records its exact source/target projections, rule version, outcome, and provenance. Collision or mismatch fails closed and cannot silently alias two procedures. + +External semantic receipts and execution attestations are first-class immutable evidence. Persist the exact owner/context/contract/version, integrity identity, semantic identity/projection/equivalence rule and applicability scope consumed for each material dependency, without copying the owner's internal source model. Persist the expected policy projection separately from trusted observed-resolved runtime identities and parameters. The comparison contract is versioned and produces an explicit congruence state. Alias-only, caller-only, missing, extra, stale, fallback, conflicting, or unverifiable material dependencies cannot be normalized into success. Retry attempts keep separate resolution evidence; only the canonical attempt producing the terminal material effect is linked as outcome authority. + +Mutations are idempotent and safe under retry. Locks must have a documented aggregate/tenant scope; no table-wide lock is acceptable for routine buyer paths. Hot partitions, query plans, connection cleanup, and contention are measured with production-shaped data. Applicable buyer-facing API paths require realistic async/E2E/k6 p95 ≤20 ms; sample shrinking, unrepresentative warm-cache exclusions, or omitted failing requests are not accepted evidence. + +## UX requirements if accepted + +The product journey must distinguish source evidence, automated material-stage output, human review/disposition, confirmed Talent decision, and authoritative downstream application. A generic “talent score” dashboard is not an acceptable substitute. A reviewer asked to provide substantive oversight must be able to inspect the material basis and known limitations before lock-in and must have a functioning path to restore/disregard/override/reverse materially automated exclusions or recommendations; hidden suppressed options and decorative override controls are acceptance failures. Where the resolved policy grants an explanation/review/correction path, the affected-worker experience must show request state, applicable decision/process evidence, missing or redacted third-party information, review/reprocessing status, corrected outcome linkage, and terminal response without implying rights that do not apply. Material UI requires reusable objects/page composition, design-token/Figma identifiers, normal/loading/empty/error/permission/responsive/interaction states, keyboard/a11y evidence, and locale-specific KO/EN/JA/ZH/VI/ES/DE/FR Storybook/E2E including CJK and text expansion/fallback. + +## Security and privacy + +Succession, mobility, performance, assessment, career-interest, material-stage decision-production, stage-opportunity/transition, source-universe/origin, sampling-design/disposition, variance-design, and rights-request data can be highly sensitive employment information. Every field group must declare classification, purpose, permitted actor/resource relation, retention, export/delete/legal-hold behavior, and audit requirements. Bulk export and manager views require explicit authorization; “HR role” is not sufficient as a universal permission. Explanation/review responses are purpose-scoped and minimize or redact evidence about other workers; a rights path must not become a succession-slate enumeration or assessment-data exfiltration channel. Reviewer visibility needed for substantive oversight must itself remain purpose/resource authorized and must not widen access to unrelated workers. Opportunity manifests, source-universe receipts, sampling-design evidence and variance-design receipts keep only the identifiers/classifications needed to reconstruct the governed Talent process; protected demographic or sensitive stratum values are not copied into them when opaque owner/design references suffice. Logs and telemetry carry opaque references and operational metadata, not evidence payloads or credentials. + +## Consequences + +A dedicated context adds API/event coordination and operational overhead, but keeps post-hire planning separate from employment facts and acquisition. It also creates an explicit place to implement buyer-visible Talent workflows without inflating `people_core` or misusing `talent_acquisition`. + +The main cost is coordination: internal mobility depends on authoritative Person/Assignment, Position, Job/KSAO, and evidence contexts. That is intentional. The context must consume released contracts and accept temporary unavailability rather than collapse ownership boundaries for local convenience. + +Decision-rights provenance adds another coordination boundary: Talent must retain enough immutable process/evidence data to support an applicable explanation or reconsideration without becoming the legal-policy authority or duplicating authoritative employment truth. Stage-level provenance adds storage and UX complexity, but prevents a final human confirmation from laundering an upstream automated exclusion, ranking, suppression, threshold, or routing decision into apparently human-made provenance. That cost is preferable to losing the ability to reconstruct and test whether oversight was effective. + +Stage-opportunity manifests add another deliberate evidence cost. They prevent a later analysis from treating only the survivors of an upstream filter as the original population at risk, distinguish unavailable/error states from negative decisions, and make stage attrition reproducible across policy/evidence/time versions. Entry-level semantic occurrence identity and explicit counting-unit provenance add storage and reconciliation work, but they prevent retries from becoming fake observations and repeated legitimate opportunities from being silently collapsed. Canonical correction-chain resolution adds one more constraint: historical corrected outcomes remain auditable without being counted twice, and closure cannot hide unavailable/failed cases inside `not_evaluable`. Manifest-lineage/as-of selection adds a second temporal dimension to that evidence: the system must preserve both what denominator governed the original decision and what corrected denominator was authoritative by a later cutoff without conflating or unioning the two; its manifest digest must itself be reproducible rather than an opaque checksum. Policy-regime identity adds a third distinction: the system must not disguise a changed selection procedure as if only records were corrected. Reproducible semantic projection adds a fourth constraint: the regime identity itself cannot be self-certified or silently omit material released dependencies. Cross-owner semantic receipts add a fifth: exact artifact integrity cannot substitute for the authoritative owner's declaration of downstream-material semantics. Stage execution attestation adds a sixth: an intended reproducible policy is still insufficient unless the actual runtime resolution is shown to match it. First-stage source-universe provenance adds a seventh: a scientifically tidy denominator chain cannot begin from an already selected cohort whose exposure/discovery/nomination history is invisible. Probability-sampling provenance adds an eighth: a valid non-exhaustive probability sample must retain the design and selected-unit dispositions needed for downstream design-based inference rather than being flattened into a generic subset. Variance-sufficient design provenance adds a ninth: a correctly identified probability sample can still yield irreproducible or mislabeled uncertainty if the downstream method needs pairwise, replicate, FPC/certainty-unit or explicitly approximate evidence that was never retained. The cost is bounded by purpose-minimization and separation of protected-group/scientific authority: Talent preserves origin/coverage, sampling-design/selection/disposition and variance-design evidence, process denominators, manifest history, policy-semantic provenance and execution congruence; `workforce_validation` selects the analytic estimand, denominator view and variance method and owns design-based estimation and scientific interpretation. + +## Acceptance before status can become Accepted + +- Re-read then-protected PRD/TRD/ARCHITECTURE, open owner PR/issues, ADR numbers, and Context Map; resolve conflicts by ordinary integration rather than source copying. +- Revalidate the selected option C against then-current protected product scope and independent review. If protected scope has contracted, reopen the C/D decision explicitly rather than silently deleting or broadening ownership. +- Add a versioned UL/Context Map and exact aggregate/invariant model before schema/API work. +- Convert the buyer journeys above into RED domain/API/security/scientific contracts, including stale evidence, empty, permission, conflict/recovery, human-confirmation, and stage-denominator cases before production implementation. +- Add a TalentPool enumeration-resistance RED contract proving an unauthorized existing restricted pool identifier and a nonexistent identifier are indistinguishable in externally observable status, body schema, empty-result semantics, and metadata, with no name/count disclosure. +- Add RED decision-provenance contracts that distinguish `human_decision`, `ai_assisted_human_decision`, and `fully_automated_decision` at both the final-outcome and material-stage levels; reject relabeling after material effect/finalization; reject every high-impact Talent finalization command whose final outcome is `fully_automated_decision`; and require substantive-human-intervention evidence plus accountable human confirmation for `ai_assisted_human_decision`. +- Add RED material-stage contracts in which a fully automated eligibility/filtering stage excludes a worker and a later confirmation attempts to represent the material path as human-decided; an AI recommendation lacks exact evidence/model/policy version or an actual override/reversal path but finalization is attempted as substantively human-supervised; the reviewer can confirm but cannot inspect the material basis or recover an automatically suppressed option; a versioned policy attempts to authorize hiding, irreversibility, or removal of the pre-lock-in recovery path; stage mode or human disposition is changed after material effect to alter governance/legal classification; an upstream fully automated material stage is silently collapsed into a final `ai_assisted_human_decision` label; or a model-generated ranking/threshold is promoted to Talent/validity truth because a human accepted it. These cases must fail closed. +- Add RED decision-opportunity contracts that fail when a shortlist/slate/ranking exists without the exact upstream opportunity-set manifest; excluded/suppressed/error records disappear from the denominator; `not_evaluable`, stale/missing evidence, authorization/owner-unavailable or policy inapplicability is collapsed into a negative outcome; a changed criteria/policy version reuses an old denominator; a closed manifest is mutated instead of superseded; relevant multiple-membership/cross-classified/time context is flattened; `workforce_validation` needs cross-service SQL or copied protected demographics to reconstruct the cohort; or a fairness/adverse-impact claim uses synthetic-only or non-right-cleared denominator evidence. +- Extend those RED decision-opportunity contracts for #397 so they also fail when only aggregate counts/digests exist without exact entry-level membership; replay/retry of one semantic opportunity creates a second denominator entry; two distinct opportunities for the same worker are collapsed; the counting/analysis unit is missing or changes without a versioned manifest/policy change; `entry_count`, unique semantic occurrence count, and terminal transition counts do not reconcile; retry/error attempts are treated as independent opportunities or failed/unavailable opportunities disappear; repeated opportunities cannot be identified downstream; or a scientific grouping rule must be inferred rather than explicitly chosen by `workforce_validation`. +- Extend the same contracts for #398 so a closed semantic occurrence must resolve to exactly one canonical active terminal entry after correction-chain resolution. RED cases must reject two active terminal entries for one occurrence, zero active terminal entry at closure, superseded historical rows included in denominator/terminal totals, retry/failure attempts counted as opportunities or terminals, corrections that mint a new semantic occurrence without a genuinely new opportunity, cyclic/dangling/ambiguous occurrence-level supersession chains, retryable unavailable/error states counted as terminal before closure, unresolved stale/missing evidence or authorization/owner unavailability omitted rather than terminalized as `unavailable`, unresolved error/failure omitted rather than terminalized as `failed`, `unavailable` or `failed` silently remapped into `not_evaluable`, any canonical terminal class omitted from the closure sum, and any canonical cardinality mismatch. +- Extend the contracts for #399 so manifest replacement lineage and digest identity are explicit and reproducible. RED cases must reject blind M1+replacement-M2 denominator unions, an unqualified implicit `latest`, historical/as-recorded queries silently returning a newer correction, corrected-as-of queries returning a superseded predecessor, competing/cyclic/dangling manifest replacement graphs, correction that changes lineage without a genuinely new cohort/stage, a genuinely new cohort/stage hidden inside an old correction lineage, corrected occurrences that change semantic occurrence identity without a new opportunity, opportunity additions/removals without controlled delta provenance, an opaque manifest digest without canonical semantic field-set/projection version, deterministic serialization/ordering/normalization rules, digest algorithm/domain separator/version and metadata-contract version, equivalent manifests producing different digests because of serializer/presentation accidents, consumer inability to recompute/validate the digest, downstream scientific results without exact selected manifest lineage/version/digest/digest-contract/view/as-of, or later corrections that rewrite an already released result instead of producing a new result/evidence version. +- Extend the contracts for #400 so manifest replacement is also policy-regime aware. RED cases must reject an eligibility threshold/cut-score change remaining in the old correction regime, ranking/order method changes traversed by `corrected_as_of`, required-evidence changes that alter evaluability/eligibility without a new regime, suppression/routing changes that alter who reaches human review while presented as record correction, absent/ambiguous/incompatible policy-semantic identity, downstream validity/fairness results lacking the exact governing regime, historical results rewritten under a later procedure instead of new analysis evidence, semantic no-op/editorial reseals forced into a new regime without evidence, material procedure changes hidden as occurrence/manifest correction, or `workforce_validation` having to infer policy compatibility from Talent internals rather than released provenance. +- Extend the contracts for #401 so policy-regime identity and equivalence are independently reproducible and dependency-closed. RED cases must reject a caller-supplied arbitrary regime ID/digest that the owner cannot recompute; semantically identical policies that mint different identities because of map/key order, whitespace, numeric/string representation, or serializer implementation; presentation label/description/timestamp changes that alter the regime despite being excluded by the projection schema; a material eligibility/threshold/ranking/suppression/routing field omitted from the projection; a materially changed released Job/FJA/KSAO qualification or required-evidence contract that leaves the old regime identity valid because the dependency was omitted; a material model/tool/automated-stage configuration absent from the dependency set; mutable branch/floating/unversioned external references or live cross-service table state used in identity/equivalence; absent or ambiguous projection/canonicalization/digest algorithm versions; unaudited operator assertions used as semantic-equivalence migrations; downstream `workforce_validation` receiving only an opaque regime ID without the released projection/dependency provenance needed to reproduce it; a later material-dependency change retroactively mutating released manifest/result identity; or a collision/digest mismatch accepted as semantic equivalence instead of failing closed for explicit resolution. +- Extend the contracts for #402 so external artifact identity and downstream semantic authority are not conflated. RED cases must reject metadata-only/reseal byte changes forcing a new Talent regime when the external owner publishes reproducible same-semantic evidence; a material Job/FJA/KSAO/assessment/model/tool/evidence semantic change reusing the old regime because only a generic artifact/version digest is recorded; caller assertions of compatibility without an owner-issued released semantic receipt/equivalence contract; Talent reading/copying foreign application truth to calculate equivalence; mutable/floating/unreleased external semantic authority; owner/context/contract slot mismatch; integrity equality/inequality treated alone as semantic proof; unversioned operator equivalence; downstream results that cannot recover the exact owner receipts; retroactive rewrite after later owner correction; conflicting owner receipts selected opportunistically; or stale/wrong-purpose/wrong-tenant/out-of-window receipts admitted into the regime. +- Extend the contracts for #403 so intended-versus-executed procedure congruence is independently provable before material authorization. RED cases must reject expected dependency A resolving to B while the stage advances; mutable alias/provider/group/cache identity without final immutable resolution; fallback B after missing A while still claiming congruence; an extra material runtime dependency/parameter absent from the projection; caller-supplied resolved metadata without trusted observation; stale cache content differing from the pinned owner release; retry attempt 1 resolving A and terminal attempt 2 resolving B while inheriting attempt 1 evidence; routers/gateways/scorers that expose only requested aliases; FJA/KSAO/assessment/required-evidence resolution to a different owner contract than pinned; missing/ambiguous/unverifiable/digest-mismatched execution evidence with a released authorizing outcome; post-release mismatch rewriting history rather than creating correction/reconsideration evidence; or `workforce_validation` receiving only intended policy identity without the actual resolved execution provenance. +- Extend the contracts for #404 so the first recorded denominator cannot hide an unobserved selection mechanism or overstate its coverage. RED cases must reject an arbitrary M1 subset labeled `population_complete` without a released/versioned authoritative source-universe receipt; an algorithmic or human discovery/prescreen/nomination/exposure step that removes workers/options before M1 without material-stage/source-transformation provenance; nomination-only, employee-opt-in, targeted-discovery, or externally imported cohorts later analyzed as the complete eligible population; source-universe identity based only on a mutable query, branch, floating label, live cross-context SQL result, or free-text label; a material origin/source receipt omitted from the first manifest evidence/digest; stale, wrong-purpose, wrong-tenant, wrong-time, or policy-incompatible source-universe evidence; a materially changed enumeration/discovery rule that reuses the old policy regime without #400/#401-compatible evidence; partial enumeration/exposure failure that silently shrinks the source universe instead of preserving explicit unavailable/failure coverage; later source-universe correction that mutates historical M1 or a released downstream result instead of appending corrected evidence/new analysis identity; Talent reconstructing completeness by querying/copying People/Assignment/Position/Job application truth; protected demographic attributes copied into Talent to establish or reconcile the source universe; or `workforce_validation` receiving only M1 and being unable to determine whether it arose from exhaustive enumeration, nomination, opt-in, targeted discovery, import, or another materially selective origin. +- Extend the contracts for #405 so a probability-sampled origin preserves the design and post-selection dispositions needed for design-based reproduction. RED cases must reject `probability_sample` without an authoritative source-universe receipt; missing, zero, negative, greater-than-one, ambiguous, or wrong-stage inclusion probability where a known non-zero probability is required; unequal-probability sampling flattened into an unweighted/simple-random-sample representation because design inputs were dropped; stratified, clustered, PPS or multistage designs flattened so downstream variance estimation cannot identify design structure; a sampled unit that refuses, is unreachable, becomes ineligible, or fails processing becoming indistinguishable from a unit never sampled; hidden frame-coverage/partial-enumeration failure; retry/replay creating an extra sampled unit or second probability for the same semantic sample occurrence; in-place mutation of released frame/design/probability/disposition evidence; pseudo-probabilities or design weights fabricated for nomination/opt-in/ranking/non-probability origins; Talent reconstructing strata or weights through cross-context SQL/source copying/protected-demographic replication; sensitive stratum values exposed to Talent where opaque released owner/design receipts suffice; or a downstream `workforce_validation` result that cannot identify the exact source-universe receipt, sample-design/version, sampled-unit occurrence set, inclusion-probability provenance, relevant design structure and response/disposition evidence used. +- Extend the contracts for #406 so uncertainty claims are variance-evidence aware without moving estimator authority into Talent. RED cases must reject an unequal-probability without-replacement design when the claimed method requires `π_ij` or equivalent design information but the released evidence contains only `π_i`; silent SRS or with-replacement variance substitution while labeling the result as the intended exact design variance; an approximate method whose name/version/assumptions are absent or which is presented as exact; replicate weights whose replication method, scale/Fay-equivalent factor, replicate count, construction provenance or sampled-unit binding is missing; replicate/joint/design evidence produced from a different sampling-design or correction version than the point-estimation evidence; flattened multistage/stratified/cluster/PPS variance structure; dropped certainty-unit, sampling-fraction or FPC inputs required by the selected method; retry/replay minting a second variance-design identity for the same semantic sample without explicit successor provenance; in-place mutation of released pairwise/replicate/design evidence; Talent copying foreign frame/cluster/stratum/protected-demographic or weight-construction truth to calculate variance evidence locally when an owner-issued purpose-bound receipt suffices; a downstream result that cannot identify both the exact #405 sampling receipt and the separate variance-design evidence/method/version actually used; or missing variance-sufficient evidence being treated as a statistical GREEN instead of `not_verifiable`/non-authorizing scientific evidence. +- Prove that any automated material stage retained in an AI-assisted path remains inspectable, reconstructable, and genuinely reversible before lock-in, and that the reviewer records a controlled disposition (`accepted`, `modified`, `rejected`, or equivalent) plus a purpose-bound reason/provenance. Actor identity, signature, a confirmation click, or a nominal override button alone is not sufficient evidence. No policy approval may waive visibility, reversibility, or the pre-lock-in recovery path. +- Resolve a canonical versioned legal/compliance-policy contract before implementation. For a configured regulated automated-decision path, RED tests must fail closed on missing/stale applicable policy, prove purpose-scoped explanation/review/correction requests, prevent third-party worker leakage, and append reconsidered decisions without overwriting the original outcome or material-stage history. A legal/policy applicability flag does not by itself authorize `talent_management` to finalize a fully automated high-impact decision under this Proposed ADR. +- Re-check current Korean PIPA automated-decision provisions and EU AI Act employment/high-risk explanation/human-oversight scope and application dates before ADR acceptance, implementation, or release/compliance claims; do not hard-code current statutory timing as permanent Talent-domain semantics. +- Re-check ISO 30415:2021's post-systematic-review disposition before ADR acceptance or a D&I-related release/compliance claim; its public status is governance evidence, not a Talent fairness verdict. +- Define assessment/validation evidence contracts without moving psychometric numerical or validity authority into Talent. +- Define PII purpose/retention/export/legal-hold policy and threat model before exposing sensitive Talent views. +- Add RED tests for cross-tenant references, stale evidence, unauthorized succession/mobility access, conflicting bitemporal corrections, duplicate/idempotent commands, Position/Assignment non-authority, and multiple legitimate pool membership. +- Add PostgreSQL RED acceptance proving every tenant-bearing Talent table uses FORCE RLS and the runtime application role is NOSUPERUSER/NOBYPASSRLS, with cross-tenant access denied and no superuser application path. +- If production code is added, satisfy owned 100% statement/branch/docstring/edge coverage, realistic PostgreSQL concurrency, and applicable p95 ≤20 ms buyer-path evidence. +- Update PRD/TRD/ARCHITECTURE/ERD/UML/API_CONTRACT/SECURITY/THREAT_MODEL/TEST_STRATEGY/OPERABILITY/TRACEABILITY/CHANGELOG through canonical writer paths. +- Release only after normal protected integration with exact-head required workflows, governance, SBOM/provenance/reproducibility, and rollback evidence. + +## References + +See `docs/doctoring/talent-management-boundary-references.md`. \ No newline at end of file diff --git a/docs/doctoring/talent-management-boundary-references.md b/docs/doctoring/talent-management-boundary-references.md new file mode 100644 index 000000000..ee5034318 --- /dev/null +++ b/docs/doctoring/talent-management-boundary-references.md @@ -0,0 +1,230 @@ +# Talent Management boundary references + +Reference doctoring for ADR 0292, issue #292, and repair issues #294, #396, #397, #398, #399, #400, #401, #402, #403, #404, #405, and #406. Checked against public source metadata on 2026-09-17. The ISO entries below describe scope/authority only; possession of this bibliography is not a certification or evidence that Orgmetra conforms to a paid standard's complete normative text. The legal entries constrain provenance and rights-path design only; they do not establish that a particular tenant, worker, decision, stage, or deployment is legally in scope. + +## Standards and primary sources + +International Organization for Standardization. (2016). *ISO 30409:2016 Human resource management—Workforce planning*. https://www.iso.org/standard/64150.html + +- ISO currently lists Edition 1 as Published and Confirmed (stage 90.93), last confirmed in 2022. +- Architectural relevance: workforce planning is a distinct HR-management concern and can consume Organization/Job/People/Talent evidence without collapsing their ownership. + +International Organization for Standardization. (2020). *ISO 10667-2:2020 Assessment service delivery—Procedures and methods to assess people in work and organizational settings—Part 2: Requirements for service providers*. https://www.iso.org/standard/74717.html + +- ISO currently lists Edition 2 as Published but “to be revised” (stage 90.92). Its lifecycle records systematic-review closure on 2026-03-05 and stage 90.92 on 2026-05-27. +- Architectural relevance: the published scope includes work-related assessment for promotion, succession planning, and reassignment. That supports an assessment-evidence interface for Talent workflows, not transfer of assessment or employment-decision authority into a score field. + +International Organization for Standardization. (n.d.). *ISO/AWI 10667-2 Assessment service delivery—Procedures and methods to assess people in work and organizational settings—Part 2: Requirements for service providers* (Edition 3 work item). https://www.iso.org/standard/94564.html + +- ISO currently lists the Edition 3 successor work item as **Under development**, stage 20.00, under ISO/TC 260. +- This AWI is evidence that revision work exists, not normative authority for an implementation or conformance claim. Until a successor edition is published, cite ISO 10667-2:2020 for current published scope and record its “to be revised” lifecycle status. +- Re-check both the 2020 edition and the Edition 3 work item before ADR acceptance, assessment-contract changes, or release/compliance claims; do not silently import draft/work-item language into Orgmetra contracts. + +International Organization for Standardization. (2021). *ISO 30415:2021 Human resource management—Diversity and inclusion*. https://www.iso.org/standard/71164.html + +- ISO lists Edition 1 as Published. The lifecycle shows systematic review opened on 2026-04-15 and closed on 2026-09-03 at stage 90.60; the resulting confirmation/revision disposition must be re-checked before ADR acceptance or release claims. +- The public abstract describes D&I governance, accountabilities, responsibilities, recommended actions, suggested measures, and potential outcomes, while explicitly excluding country-specific legal requirements. +- Scientific/governance relevance: stage-denominator evidence can support accountable D&I analysis, but ISO 30415 does not make `talent_management` the owner of protected attributes, fairness verdicts, or jurisdiction-specific legal conclusions. + +International Organization for Standardization. (2023). *ISO 30405:2023 Human resource management—Guidelines on recruitment*. https://www.iso.org/standard/79488.html + +- ISO lists Edition 2 as the current published recruitment standard. +- Architectural relevance: its recruitment-specific scope supports retaining `talent_acquisition` as the pre-hire acquisition/recruitment boundary instead of extending it by name alone into all post-hire Talent concerns. + +International Organization for Standardization. (2025). *ISO 30414:2025 Human resource management—Requirements and recommendations for human capital reporting and disclosure*. https://www.iso.org/standard/30414 + +- Edition 2 was published in August 2025 and replaces the withdrawn 2018 edition. +- ISO's public abstract lists mobility and succession planning, workforce composition, recruitment, turnover, and skills/capabilities/development among the human-capital reporting areas. +- Architectural relevance: buyer/reporting requirements can legitimately need mobility/succession data, but reporting categories do not themselves decide which Orgmetra bounded context owns transactional truth. + +International Organization for Standardization. (2025, August 24). *ISO 30414:2025—Strengthening human capital reporting and disclosure*. ISO/TC 260. https://committee.iso.org/sites/tc260/home/news/content-left-area/news-and-updates/iso-30414-2025-strengthening-hum.html + +- Primary publication announcement for the second edition; useful for edition/date traceability. The standard page remains the authority for current lifecycle status. + +U.S. Equal Employment Opportunity Commission. (1979). *Questions and Answers to Clarify and Provide a Common Interpretation of the Uniform Guidelines on Employee Selection Procedures*. https://www.eeoc.gov/laws/guidance/questions-and-answers-clarify-and-provide-common-interpretation-uniform-guidelines + +- The EEOC page identifies this as technical assistance interpreting the 1978 Uniform Guidelines and states expressly that the document does not itself have the force and effect of law. +- It treats hiring, promotion, transfer, retention and related employment decisions as selection processes, distinguishes the total selection process from component procedures, and defines adverse impact in terms of materially different selection rates. Those rates depend on a preserved numerator and denominator rather than only on records that survive to a later stage. +- Question 47 is relevant to #400's narrower evidence-design boundary: validity evidence must correspond to the selection procedure actually used; evidence for one passing score/use does not automatically justify a substantially different passing score or ranking use. +- Scientific-design relevance: Orgmetra must retain the exact stage opportunity set and transition denominator for later `workforce_validation` analysis and identify the governing material policy regime. This is evidence-design guidance, not a universal legal-applicability declaration. + +American Association for Public Opinion Research. (2026). *Disclosure Standards*. Retrieved September 17, 2026, from https://aapor.org/standards-and-ethics/disclosure-standards/ + +- The current public disclosure page requires enough methodological information for independent review and verification. For sampling, it asks researchers to state whether selection is probability-based or non-probability, describes probability-based selection as drawing potential participants from a known frame with known non-zero probabilities, and calls for disclosure of sampling frames and coverage gaps. +- For probability samples, it also asks reporting of sampling error and whether design effects from weighting, clustering or other factors were accounted for. Its additional-disclosure section calls for summaries of study-specific sample-record dispositions so probability-sample response rates can be computed. +- #405 uses these requirements only as reporting/provenance evidence that probability-sample status, frame/coverage, design effects and sampled-case dispositions are material to reproducibility. AAPOR survey disclosure rules are not an employment-law standard, and Orgmetra does not import AAPOR's survey vocabulary as Talent domain truth. + +American Association for Public Opinion Research. (2023). *Standard definitions: Final dispositions of case codes and outcome rates for surveys* (10th ed.). https://aapor.org/standards-and-ethics/standard-definitions/ + +- AAPOR's current public Standard Definitions page identifies the tenth edition (2023) as the current main report and separately lists later 2025 supplements. The report's purpose is to define final case dispositions and survey outcome rates; the public page emphasizes that knowing the disposition of every element drawn in a sample is a critical first step for understanding potential nonresponse error. +- The tenth edition also covers complex designs including multistage samples, single-stage samples with unequal selection probabilities, and two-phase designs. +- #405 uses this only for the narrower design principle that a selected unit's response/nonresponse/ineligibility disposition must not disappear or become indistinguishable from a never-selected unit. Orgmetra defines its own purpose-bound Talent disposition vocabulary and leaves nonresponse adjustment and inferential consequences to `workforce_validation`. + +U.S. Census Bureau. (2021). *Statistical Quality Standard D1: Producing Direct Estimates from Samples*. https://www.census.gov/about/policies/quality/standards/standardd1.html + +- The current public D1 page covers direct estimates and estimates of variances from samples. D1-2 requires variance-estimation methodologies; D1-3 requires variance estimation to account for sample design, including selection probabilities, stratification and clustering; D1-4 requires retention of the final variance-estimation specifications and design parameters needed to replicate estimates and variances. +- #406 uses this as methodological/provenance evidence that a reproducible uncertainty claim may need variance-specific design evidence in addition to first-order sampling evidence. It is not a claim that Orgmetra conforms to Census standards and does not prescribe a single variance estimator or storage representation. + +U.S. Census Bureau. (2022). *Sampling Error*. Survey of Income and Program Participation. https://www.census.gov/programs-surveys/sipp/methodology/sampling-error.html + +- The page explains that SIPP's complex sample design must be reflected in variance estimation and warns that treating the survey as a simple random sample typically understates true sampling variance. It describes design variables, generalized variance functions and replicate weights as supported ways to estimate sampling error. +- #406 uses this as a practical methodological precedent for retaining design-specific variance evidence and distinguishing exact/design-specific methods from approximations. Orgmetra does not import SIPP's concrete replicate system or variance formulas as Talent-domain requirements. + +## Engineering and provenance primary sources + +Rundgren, A., Jordan, B., & Erdtman, S. (2020). *JSON Canonicalization Scheme (JCS)* (RFC 8785). RFC Editor. https://www.rfc-editor.org/rfc/rfc8785.html + +- RFC 8785 is an **Informational** RFC, not an IETF Standards Track requirement. It explains why cryptographic hashing/signing needs an invariant representation so producer and consumer can repeat the same operation over semantically identical JSON. +- #399 uses this only as engineering evidence that a manifest digest needs an explicit deterministic semantic field set/representation, ordering/normalization rules, algorithm/domain/version metadata, and consumer recomputation contract. Equivalent closed manifests under the same digest contract must not acquire different identities because of serializer or presentation accidents. +- #401 uses the same narrower engineering principle for policy-regime identity. ADR 0292 does not mandate JCS, JSON, SHA-256, or any particular digest algorithm; an owner may choose another suitable canonical representation if its semantic input set, canonicalization and algorithm/domain/version are explicit and reproducible. + +Moreau, L., & Missier, P. (Eds.). (2013). *PROV-DM: The PROV Data Model*. W3C Recommendation. World Wide Web Consortium. https://www.w3.org/TR/2013/REC-prov-dm-20130430/ + +- W3C published this Recommendation on 2013-04-30. The versioned Recommendation URI is recorded here so the cited evidence does not silently follow later W3C publication changes. +- PROV-DM models provenance through entities, activities, agents, usage and derivation relationships rather than treating an output identifier as self-explanatory. +- #401 uses PROV-DM as provenance-design evidence: a policy-regime identity retains material upstream released entities/dependencies that contributed to the selection procedure. PROV-DM does not define Orgmetra HR semantics or decide which dependency is material; that remains an owner-domain contract. + +National Institute of Standards and Technology. (n.d.). *AI Risk Management Framework Playbook: MANAGE 3.1*. AI Resource Center. Retrieved September 16, 2026, from https://airc.nist.gov/airmf-resources/playbook/manage/ + +- MANAGE 3.1 addresses monitoring, control, and documentation of risks and benefits from third-party resources. The retrieved Playbook notes that AI systems can depend on third-party data, software, hardware, tools, services, and expertise, and recommends documenting third-party systems/components and applying risk controls. +- NIST states that the Playbook is voluntary guidance rather than a checklist that must be followed in its entirety. The site is a living resource and also notes that AI RMF 1.0 is being revised; the retrieval date above is therefore part of citation reproducibility rather than a claim that the page is immutable. +- #401 uses this as dependency-provenance/risk-management evidence only. It supports pinning material released dependencies that affect a policy regime; it does not establish validity, fairness, or legal compliance for an Orgmetra Talent procedure. +- #402 and #403 reuse the narrower dependency-governance point: a third-party or separately owned dependency needs explicit owner provenance and runtime monitoring. The Playbook does not say a cryptographic artifact digest is semantic equivalence, nor does it establish that a declared dependency is the one actually consumed during a specific Talent stage. + +Supply-chain Levels for Software Artifacts. (2026). *SLSA v1.2: Provenance*. https://slsa.dev/spec/v1.2/provenance + +- SLSA v1.2 is recorded as the current Approved specification on the public SLSA site as checked on 2026-09-16. +- #403 uses SLSA only as an engineering provenance analogy. It supports distinguishing declared configuration from evidence about a concrete execution; it is not an HR selection-validity, fairness, employment-law, or Orgmetra conformance authority. + +Supply-chain Levels for Software Artifacts. (2026). *SLSA v1.2: Build provenance*. https://slsa.dev/spec/v1.2/build-provenance + +- Build Provenance distinguishes parameters declared to the build from `resolvedDependencies`, the concrete artifacts resolved or fetched during execution. That distinction is useful by analogy for Orgmetra's intended `PolicySemanticProjection` versus trusted observed-resolved dependency evidence for one material Talent stage. +- Orgmetra does not import SLSA's build schema wholesale. The domain requirement is narrower: before an outcome can authorize a material HR stage, the trusted Talent boundary binds the terminal stage attempt to the immutable owner contracts/artifacts and material parameters actually used, compares them with the intended policy projection, and preserves any mismatch explicitly. + +### Scope notes for #399, #401, #402 and #403 + +- #399's manifest digest is a content-identity contract over explicitly versioned closed-manifest semantics. RFC 8785 supplies only the general engineering rationale for deterministic representation; it does not select the manifest field set, serialization format, hash algorithm, or domain separator for Orgmetra. +- #401's policy-regime projection similarly uses RFC/W3C/NIST sources as engineering/provenance evidence, not HR-selection validity authority. +- #402 is an ownership/semantic-authority rule, not a demand for duplicate hashes. An upstream owner's existing canonical content digest can serve both integrity and downstream semantic identity only when the released owner contract explicitly defines the addressed canonical projection as the downstream-material semantics and publishes its stability/equivalence rules. Otherwise the owner supplies a narrower semantic projection/receipt or versioned equivalence evidence; Talent may not reconstruct foreign source truth. +- #403 is an execution-provenance rule. SLSA's declared-versus-resolved distinction and NIST's third-party-resource monitoring support the engineering need to record what was actually resolved, but neither source proves that an HR procedure is valid, fair, legally compliant, or scientifically transportable. `workforce_validation` retains those judgments. + +## Privacy and AI decision-rights primary sources + +대한민국. (2025). *개인정보 보호법* [시행 2025. 10. 2.; 법률 제20897호, 2025. 4. 1., 일부개정]. 국가법령정보센터. https://www.law.go.kr/법령/개인정보보호법 + +- Article 37-2 is conditional, not a blanket rule for every algorithm-assisted employment workflow. It addresses decisions made by a **fully automated system** that significantly affect a data subject's rights or obligations, subject to the statute's stated exceptions and conditions. +- The provision gives qualifying data subjects a refusal right and an explanation-request path; absent a justified refusal ground, the controller must take measures such as not applying the automated decision, human intervention/reprocessing, or explanation as required by the provision. +- Architectural relevance: Orgmetra must preserve how the outcome was actually produced. A human actor ID, confirmation click, or later label is not sufficient provenance to determine whether a decision was fully automated or meaningfully human-decided. +- Applicability remains a legal/policy determination based on the then-current decision, tenant, jurisdiction, lawful basis, and statutory conditions. ADR 0292 does not declare all Talent decisions subject to Article 37-2. + +대한민국. (2026). *개인정보 보호법 시행령* [시행 2026. 8. 20.; 대통령령 제36121호, 2026. 2. 19.]. 국가법령정보센터. https://www.law.go.kr/법령/개인정보보호법시행령 + +- Articles 44-2 through 44-4 operationalize automated-decision requests and transparency. The current decree includes an explanation request concerning criteria/process and review of whether additional information or an opinion can be reflected, and requires public disclosure of specified automated-decision information and request methods. +- Architectural relevance: explanation/review is a product workflow with versioned decision-policy evidence and response provenance, not merely a static privacy-policy link. The rights response must still protect other workers' restricted evidence. + +개인정보보호위원회. (2024). *자동화된 결정에 대한 개인정보처리자의 조치 기준* (개인정보보호위원회고시 제2024-9호, 2024. 9. 26., 제정). 국가법령정보센터. https://law.go.kr/admRulLsInfoP.do?admRulSeq=2100000247380 + +- Effective 2024-09-26. The notice supplies operational criteria for refusal/explanation requests, including response handling and justified-refusal treatment. +- Architectural relevance: time limits, refusal grounds, and response contents belong in a versioned compliance-policy contract. The current values are evidence for implementation and testing, not timeless constants in the Talent domain model. +- Re-check the notice and its legal basis before implementation/release because an administrative rule can be amended independently of the Talent aggregate contract. + +European Parliament & Council of the European Union. (2024). *Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)*. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj + +- Annex III point 4 covers specified employment and worker-management uses, including recruitment/selection and AI systems intended to make decisions affecting terms of work-related relationships, promotion/termination, task allocation, and monitoring/evaluation where the regulation's high-risk conditions are met. +- Article 86 provides, for the decisions within its scope, a right to a clear and meaningful explanation of the AI system's role in the decision-making procedure and the main elements of the decision taken. +- Article 14 requires effective human oversight for high-risk AI systems where applicable. In the consolidated text checked on 2026-09-10, the human overseer must, as appropriate and proportionate, understand relevant capacities and limitations, remain aware of automation bias, correctly interpret output, and be able not to use or to disregard, override, reverse, intervene in, or stop the AI system/output. +- Architectural relevance: a reviewer name or confirmation event is not evidence that oversight was effective. If an automated eligibility, exclusion, ranking, suppression, threshold, or routing stage materially constrains the reachable outcome, Orgmetra must preserve that stage and make any claimed human intervention operationally testable before lock-in. +- This is design/traceability evidence only. Article 14 applicability depends on the then-current legal classification, system, deployment, role, dates, and facts; ADR 0292 does not turn the Article 14 list into a universal Talent-domain legal rule. + +European Parliament & Council of the European Union. (2026). *Consolidated text of Regulation (EU) 2024/1689 as of 27 July 2026*. EUR-Lex. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727 + +- This consolidated text was re-checked for #294 because it contains the current Article 14 wording after the 2026 amendments. It is preferred over relying on the original 2024 text alone when evaluating current human-oversight wording. +- Traceability relevance: Article 14(4) explicitly addresses automation-bias awareness and practical ability, where appropriate and proportionate, to interpret, disregard, override, reverse, intervene in, or stop AI output. The ADR uses those concepts to define testable oversight properties without declaring every Talent workflow legally covered. + +European Parliament & Council of the European Union. (2026). *Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI).* Official Journal of the European Union, L 2026/1744. https://eur-lex.europa.eu/eli/reg/2026/1744/oj + +- The amendment is in force and changes the staged application of the AI Act. The consolidated timing must be checked rather than relying on the original 2024 dates; as of this doctoring pass, the relevant Annex III Chapter III Sections 1–3 high-risk regime has a later application date under the 2026 amendment. +- Architectural relevance: application dates and transitional conditions are versioned legal-policy evidence. Do not encode the currently observed date as an immutable Talent invariant, and do not claim present EU high-risk compliance merely because ADR 0292 preserves explanation or oversight provenance. +- Before ADR acceptance or a European production release, re-read the then-current consolidated Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 rather than copying this summary into a compliance claim. + +## Peer-reviewed conceptual and scientific sources + +Collings, D. G., & Mellahi, K. (2009). Strategic talent management: A review and research agenda. *Human Resource Management Review, 19*(4), 304–313. https://doi.org/10.1016/j.hrmr.2009.04.001 + +- Relevance: identifies persistent conceptual-boundary problems in talent management and frames strategic talent management around pivotal positions, talent pools, differentiated HR architecture, and organizational outcomes. ADR implication: model pivotal Position/Job references and talent-pool decisions explicitly rather than placing an undifferentiated `talent` property on Person. + +Dries, N. (2013). The psychology of talent management: A review and research agenda. *Human Resource Management Review, 23*(4), 272–285. https://doi.org/10.1016/j.hrmr.2013.05.001 + +- Relevance: synthesizes multiple psychological perspectives and tensions in the talent construct, including inclusive/exclusive, innate/acquired, input/output, and transferable/context-dependent views. ADR implication: no universal potential/readiness score becomes domain truth without an explicit construct and decision-use definition. + +Gallardo-Gallardo, E., Dries, N., & González-Cruz, T. F. (2013). What is the meaning of “talent” in the world of work? *Human Resource Management Review, 23*(4), 290–300. https://doi.org/10.1016/j.hrmr.2013.05.002 + +- Relevance: distinguishes “talent as characteristics” from “talent as people” and inclusive from exclusive approaches. ADR implication: `TalentPoolMembership` is an organizational planning relation, not proof that an individual possesses a timeless latent trait called talent. + +Horvitz, D. G., & Thompson, D. J. (1952). A generalization of sampling without replacement from a finite universe. *Journal of the American Statistical Association, 47*(260), 663–685. https://doi.org/10.1080/01621459.1952.10483446 + +- The paper develops finite-population estimation for sampling without replacement with unequal selection probabilities and explicitly treats inclusion probabilities as part of the estimator. The original article also discusses usefulness for the first stage of multistage designs. +- #405 uses only this foundational design-based premise: when a Talent origin is genuinely probability-sampled, inclusion-probability provenance and the design stage to which it belongs cannot be discarded if downstream analysis is expected to reproduce design-based inference. +- Scope limit: this paper does not prescribe an Orgmetra sampling design, response-disposition vocabulary, fairness metric, employment-law reporting unit, or analytic estimator. `workforce_validation` chooses the authorized estimand, weighting and variance method from the released design evidence. + +Berger, Y. G. (2004). A simple variance estimator for unequal probability sampling without replacement. *Journal of Applied Statistics, 31*(3), 305–315. https://doi.org/10.1080/0266476042000184046 + +- Berger distinguishes variance estimators for unequal-probability sampling without replacement and notes that the Sen–Yates–Grundy estimator requires joint inclusion probabilities, while the Hájek alternative uses first-order inclusion probabilities. The article treats the first-order-only alternative as a different estimator, not proof that pairwise information is universally unnecessary. +- #406 uses only this narrow methodological point: `π_i` and a correctly identified sample design do not, by themselves, reproduce every possible design-based variance method. A method that needs `π_ij` or equivalent information must have that evidence, while a first-order-only or other approximation must be named and versioned as the method actually used. +- Scope limit: Orgmetra does not mandate Sen–Yates–Grundy, Hájek, pairwise matrix storage, or any one variance estimator. `workforce_validation` owns estimator selection, calculation and interpretation; Talent retains only purpose-minimized released provenance needed to bind the sampling occurrence to the variance evidence. + +Dunleavy, E. M., Mueller, L. M., Buonasera, A. K., Kuang, D. C., & Dunleavy, D. G. (2008). On the consequences of frequent applicants in adverse impact analyses: A demonstration study. *International Journal of Selection and Assessment, 16*(4), 333–344. https://doi.org/10.1111/j.1468-2389.2008.00439.x + +- The demonstration study examines frequent applicants in adverse-impact analysis and shows that repeated applications by even one frequent applicant can materially create or mask statistically significant adverse-impact results under the studied conditions. +- Scientific-design relevance: a stage denominator cannot be represented only by worker identity or aggregate counts. Orgmetra must preserve an occurrence-level opportunity identity stable across retry/replay but distinct across legitimate repeated opportunities, plus an explicit counting unit. `workforce_validation` then chooses and records whether an authorized analysis estimates at opportunity/application, case, or person level. +- Scope limit: the paper demonstrates a statistical counting-unit problem; it does not prescribe Orgmetra's legal reporting unit for every tenant or jurisdiction and does not make `talent_management` the fairness-analysis owner. + +Alon-Barkat, S., & Busuioc, M. (2023). Human–AI interactions in public sector decision making: “Automation bias” and “selective adherence” to algorithmic advice. *Journal of Public Administration Research and Theory, 33*(1), 153–169. https://doi.org/10.1093/jopart/muac007 + +- The article reports three experimental studies with an aggregate sample of 2,854 participants. It did not find a general pattern of stronger automatic adherence to algorithmic advice than equivalent human-expert advice, while it did find evidence of selective adherence to advice consistent with pre-existing stereotypes in the studied settings. +- Design relevance: “human in the loop” must not be treated as a binary compliance signal. Human–algorithm interaction can depend on context and can still be selectively biased. For Orgmetra, the appropriate control is to preserve material-stage provenance and test what evidence, alternatives, limitations, override/reversal paths, and actual human disposition existed before lock-in rather than inferring effective oversight from actor presence alone. +- Scope limit: these public-sector experiments do not validate an Orgmetra employment model, quantify employment-domain automation bias, or establish legal compliance. They support the narrower human-factors claim that actual interaction behavior and decision path matter. + +Alexander, L., III, Song, Q. C., Hickman, L., & Shin, H. J. (2025). Sourcing algorithms: Rethinking fairness in hiring in the era of algorithmic recruitment. *International Journal of Selection and Assessment, 33*, e12499. https://doi.org/10.1111/ijsa.12499 + +- The article was first published online on 2 September 2024 and appears in the 2025 volume citation above. It models sourcing as an upstream first hurdle/prescreen that can identify or filter potential applicants before they know about the job opportunity. +- For #396, the study shows why applicant-only or survivor-only adverse-impact analysis can miss disparity introduced before a later stage, supporting stage-specific opportunity-set/transition provenance rather than only per-person decisions or final outcomes. +- For #404, the narrower design implication moves one step earlier: the **first observed cohort is not automatically the source population**. If exposure/discovery/sourcing/prescreen determines who can enter M1, later internally consistent denominator evidence remains conditional on that upstream mechanism unless its origin and coverage semantics are preserved. +- Scope limit: this is a recruitment-domain simulation/design study, not direct empirical evidence about Orgmetra succession, internal mobility, talent-pool nomination, or employee opt-in. It does not establish a universal legal protected-group denominator or require every Talent origin to be exhaustive. It supports explicit provenance that distinguishes an authoritative enumerated source universe from intentionally non-exhaustive nomination/opt-in/targeted-discovery/import origins. + +Xu, H., & Zhang, N. (2024). Goal orientation for fair machine learning algorithms. *Production and Operations Management*. https://doi.org/10.1177/10591478241234998 + +- The paper notes that organizational-selection ML outputs are often intermediate inputs to a broader decision process rather than the final decision itself. +- Design relevance: fairness evidence must follow the decision process and its stage-specific opportunity sets instead of treating one model score or final outcome set as the whole population at risk. + +### Scope notes for #404, #405 and #406 + +- #404 is an opportunity-origin/coverage provenance rule, not a new fairness-analysis owner and not a universal `all employees` snapshot requirement. A purpose-bound released owner receipt can define the relevant source universe for one process/version/time; an intentionally selective origin can remain valid product behavior when it is explicit and later analysis respects that limitation. +- `talent_management` owns only the evidence needed to say how the first cohort was formed and what coverage claim may be made. Authoritative Person/Employment/Assignment/Organization/Position/Job truth remains with existing Orgmetra owners, and protected-group joins plus fairness/validity/estimand judgments remain with `workforce_validation`. +- A human or algorithmic pre-M1 exposure/discovery/nomination/prescreen is material when it changes who can enter the observed cohort. Such a step belongs in the material-stage/source-transformation provenance graph instead of disappearing merely because storage begins after it. +- #405 is conditional: it applies when the origin mechanism is genuinely probability-based. It does not require every Talent cohort to be probability sampled and does not convert nomination, opt-in, ranking, quota, convenience or deterministic-percentage selection into a probability design. +- AAPOR's disclosure and disposition material is survey-research guidance, not an Orgmetra employment-law or HR-domain standard. The useful design principle is provenance: distinguish probability from non-probability selection, preserve frame/coverage and design information, and retain what happened to selected units. Orgmetra uses its own controlled, purpose-bound Talent sampling/disposition vocabulary. +- Horvitz–Thompson is cited for the statistical need to preserve inclusion-probability information under unequal-probability finite-population sampling, not to mandate one estimator. `workforce_validation`, not Talent, owns design weights, variance/SE/CI, finite-population correction, calibration/nonresponse adjustment, inferential method, fairness/validity interpretation and any legal reporting decision. +- Sampling design can itself be sensitive. Where a stratum/cluster definition is protected or unnecessarily revealing, Talent should retain an opaque released owner/design membership reference sufficient for authorized downstream reconstruction rather than copy the underlying protected attribute or source frame. +- #406 is conditional on a design-based uncertainty claim. It does not require every probability sample to materialize an O(n²) pairwise-inclusion matrix. A released deterministic design algorithm/parameterization, replicate-weight contract, compressed sufficient representation, or explicitly named/versioned approximation can be valid if it is sufficient to reproduce the variance method actually claimed and is bound to the exact #405 sample/design/correction identity. +- Berger (2004) supplies the narrow distinction between variance estimators that require joint inclusion probabilities and first-order-only alternatives. Census D1 and SIPP materials supply practical provenance/reproducibility precedent. None of these sources transfers estimator choice, uncertainty calculation, employment-law authority, or fairness interpretation from `workforce_validation` into Talent. +- Exact versus approximate uncertainty is evidence semantics, not presentation copy. An approximation may be scientifically appropriate, but its method/version/assumptions must be explicit; a silent SRS/with-replacement substitution or an approximation labeled as another design's exact variance is not reproducible evidence. + +## Evidence-handling notes + +- These references constrain terminology, scope, measurement claims, provenance, human-oversight testability, first-stage opportunity-origin/source-universe coverage, probability-sampling design/disposition provenance, variance-sufficient design evidence, denominator preservation, counting-unit traceability, canonical terminal closure, manifest replacement/digest reproducibility, policy-regime compatibility, reproducible policy-semantic identity, cross-owner semantic authority, and intended-versus-actual execution provenance. They do not replace Orgmetra's protected PRD/TRD/ARCHITECTURE or an accepted owner ADR. +- ISO public abstracts are sufficient to support the scope statements recorded here, but implementation must not claim full conformance to normative requirements that have not been reviewed from licensed/current standard text. +- Re-check current ISO lifecycle/edition status when ADR 0292 is proposed for acceptance or when release/compliance documentation is produced. For ISO 10667-2, inspect both the current published 2020 edition and the active Edition 3 work item. For ISO 30415:2021, re-check the post-review disposition after the recorded 2026-09-03 close of review. +- The Korean and EU legal sources are jurisdiction- and fact-dependent. They justify a versioned decision-production, material-stage provenance, effective-oversight, and rights-response boundary; they do not establish that a particular Orgmetra decision is fully automated, high-risk, adverse, subject to Article 14/86, or otherwise legally covered. +- A compliance-policy owner must resolve then-current jurisdiction, effective dates, lawful exceptions, deadlines, and response/oversight obligations. `talent_management` consumes that released/versioned determination and preserves the evidence needed to execute it; it does not infer legal applicability from a score, model call, human name, UI event, or final decision label. +- A stage-level `fully_automated_decision` marker is process provenance, not itself a statutory classification. An upstream automated stage can remain in an AI-assisted path only if its material effect remains inspectable, reconstructable, and genuinely reversible before high-impact finalization under the Proposed product contract. +- Opportunity-set and stage-transition provenance belongs to the Talent process owner only to the extent required to reconstruct that process. Exact entry membership and counting-unit evidence must be retained without copying protected-group attributes; retry/replay attempts cannot become extra observations, and distinct legitimate repeated opportunities cannot be silently collapsed. At closure, unresolved evidence/authorization/owner availability is represented explicitly as `unavailable`, unresolved error/failure as `failed`, and `not_evaluable` remains a separate evaluability outcome; every canonical terminal class participates in the closure sum. Protected-group attributes and fairness/validity verdicts remain outside Talent and must be joined through purpose-authorized released contracts or approved analysis snapshots. +- #404 adds a boundary before that stage-denominator chain: the first persisted manifest cannot be used as its own proof of source-population completeness. A `population_complete` claim needs released/versioned owner coverage evidence; nomination, opt-in, targeted discovery, import, or other selective origin remains explicitly selective. Material pre-M1 exposure/discovery/prescreen belongs in provenance, source-enumeration failure remains visible, and `workforce_validation` must be able to distinguish source universe/origin scope from M1 and later denominators without foreign SQL or copied protected attributes. +- #405 refines the intentionally non-exhaustive branch when it is probability-based. Talent retains enough immutable design evidence to identify the authoritative source universe, sampled occurrence set, known non-zero inclusion probability or reproducible stage-wise probability inputs, design memberships/structure, actual selection execution and selected-unit dispositions. A sampled refusal/unreachable/ineligible/failure case remains different from a never-sampled unit; retries do not mint observations. Talent does not invent pseudo-probabilities for non-probability cohorts or compute analytic weights/variance from foreign source truth. +- #406 refines #405 only for downstream uncertainty claims. Talent binds, but does not choose or calculate, a variance-evidence strategy sufficient for the method actually claimed. Joint inclusion information may be required for some estimators; deterministic design algorithms, replicate-weight systems or explicit approximations can be valid alternatives. Replicate method/count/scaling/construction and exact sample binding, certainty/FPC inputs when required, and exact-versus-approximate semantics are versioned. Missing or mismatched evidence is `not_verifiable`, not a GREEN. +- Manifest identity is also evidence, not an opaque checksum. The owner versions the canonical semantic field set/projection, deterministic encoding/order/normalization, digest algorithm/domain separator/version and metadata contract; consumers recompute and validate it. RFC 8785 is only the engineering precedent for deterministic representation, not a mandate for Orgmetra's concrete serialization or algorithm. +- Manifest-correction provenance and policy-semantic provenance are separate. An immutable replacement lineage can resolve record corrections without establishing that a materially changed eligibility, cut-score, ranking, evidence, suppression/routing or equivalent procedure is scientifically the same procedure. Talent must expose the exact governing policy-regime/semantic identity; `workforce_validation` decides whether scientific evidence supports transport or comparison across procedures. +- #401's RFC/W3C/NIST sources are engineering/provenance evidence, not HR-selection validity standards. They support deterministic canonical representation, material upstream dependency provenance, and documented third-party-resource control. They do not decide which Talent fields are material, whether a changed procedure is valid or fair, or whether two regimes are scientifically transportable. +- #402 further limits that interpretation: an immutable artifact/version digest proves identity/integrity only to the extent its owner contract defines. Semantic compatibility across bounded contexts must come from the authoritative owner's released semantic projection/receipt or equivalence evidence; Talent must not infer it from generic digests or foreign source internals. +- #403 uses SLSA v1.2 and NIST MANAGE 3.1 only as engineering precedents for separating declared configuration from actual resolved execution and monitoring external resources. They do not establish HR-selection validity, fairness, legal applicability, or compliance. The domain contract requires trusted observed-resolved evidence because `workforce_validation` must be able to distinguish the intended procedure from the one actually executed. +- Psychometric or predictive claims require study-specific evidence. Conceptual talent-management papers, repeated-applicant demonstrations, sourcing simulations, sampling-method references, fairness-optimization research, and human–algorithm interaction studies do not establish validity, fairness, utility, or transportability of any particular Orgmetra decision rule. \ No newline at end of file diff --git a/docs/traceability/talent-management-boundary.md b/docs/traceability/talent-management-boundary.md new file mode 100644 index 000000000..b85a69f72 --- /dev/null +++ b/docs/traceability/talent-management-boundary.md @@ -0,0 +1,143 @@ +# Talent Management boundary traceability + +- Issue: #292 +- Repair issues: #294, #396, #397, #398, #399, #400, #401, #402, #403, #404, #405, #406 +- ADR: `docs/adr/0292-post-hire-talent-management-boundary.md` +- Status: Proposed; the product-scope direction selects a dedicated `talent_management` bounded context, but no protected service/schema/API/event/UI authority exists yet. +- Protected baseline reviewed: `develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f` + +| Requirement / claim | Protected or external authority | Proposed implementation owner | Acceptance evidence | +|---|---|---|---| +| Orgmetra's current HCM architecture has no post-hire Talent owner | `docs/PRD.md`; `ARCHITECTURE.md`; `docs/TRD.md`; protected `services/` tree | ADR 0292 / #292 | Then-current protected docs and service inventory re-read before acceptance | +| Current product scope supports post-hire Talent rather than an explicit scope contraction | Protected PRD describes an evidence-centered HRIS/HCM across the employment lifecycle and asks which evidence justified hiring or promotion; protected TRD/ARCHITECTURE stop `talent_acquisition` at recruitment/selection | Selected option C: dedicated `talent_management`; ADR remains Proposed | Independent review revalidates C against then-current protected product truth; any later choice of D requires explicit PRD/positioning contraction | +| Recruitment is a distinct lifecycle from post-hire mobility/succession | ISO 30405:2023 recruitment scope; ISO 30414:2025 explicitly lists mobility and succession planning separately | `talent_acquisition` remains recruitment/selection; proposed `talent_management` owns post-hire planning | Context Map + UL + API/event contracts prove no semantic expansion of `talent_acquisition` | +| Mobility/succession and workforce planning are legitimate HCM concerns | ISO 30414:2025; ISO 30409:2016 | Proposed `talent_management` plus existing `organization_core`/`people_core`/`workforce_validation` owners | Buyer journeys and versioned cross-context contracts | +| Talent-pool planning must distinguish no confirmed membership from no qualified people | ADR 0292 selected buyer journey; purpose-bound access baseline | Proposed `TalentPool` / membership relation | RED contracts cover empty, unknown/not-evaluable, stale evidence, legitimate multiple membership, idempotent confirmation, and enumeration-resistant denial where an unauthorized existing restricted pool and a nonexistent pool have the same externally observable status/body schema/empty-result/metadata contract with no name/count leakage | +| Succession planning must preserve Position and evidence authority | ADR 0292 selected buyer journey; protected Organization/Job/Performance/Validation ownership | Proposed `SuccessionPlan`, downstream of owner contracts | RED contracts cover target Position version, stale/missing evidence, restricted slate visibility, human confirmation, no Position-capacity mutation | +| Internal mobility planning must not become Assignment execution authority | ADR 0292 selected buyer journey; protected People/Organization ownership | Proposed `InternalMobilityCase`; authoritative mutation remains People/Organization coordination | RED contracts cover changed Assignment/Position, downstream rejection/recovery, idempotent intent, no local capacity decrement or Assignment write | +| Career interest is explicit employee-controlled evidence, not inferred latent truth | ADR 0292 selected buyer journey; purpose-bound PII baseline | Candidate `CareerPreference`/`CareerInterest` aggregate only after retention/control contract | Tests prove explicit create/edit/visibility/withdrawal; no default inference from communications, assessments, browsing, or model output | +| “Talent” is not a universal scalar construct | Collings & Mellahi (2009); Gallardo-Gallardo et al. (2013); Dries (2013) | Decision-policy/evidence references only; scientific authority remains `workforce_validation` | No unversioned universal potential/readiness/fit score; construct/evidence/version/uncertainty/fairness contract tests | +| Work-related assessment can inform promotion, succession and reassignment without becoming HRIS mutation authority | ISO 10667-2:2020, currently marked by ISO as to be revised; existing Orgmetra TRD assessment-snapshot rule | Assessment results stay immutable external references; Talent consumes purpose-authorized evidence | Version-pinned assessment evidence + human confirmation + immutable provenance; stale/missing evidence fails closed | +| Person/Employment/Assignment remain authoritative outside Talent | `docs/TRD.md`, `ARCHITECTURE.md` | `people_core`; proposed Talent is downstream | No cross-service application SQL; contract tests reject Talent direct mutation | +| Position and Organization remain authoritative outside Talent | `docs/TRD.md`, `ARCHITECTURE.md`; position-capacity ADR owner stack | `organization_core`; proposed Talent is downstream | Mobility/succession planning cannot reserve or consume Position capacity without a released owner contract | +| Job/FJA/KSAO remain authoritative outside Talent | `docs/TRD.md`, `ARCHITECTURE.md` | `job_architecture` | Opaque/versioned references; no Job/KSAO source copy | +| Performance and validity/fairness evidence remain separate authorities | `docs/TRD.md`, `ARCHITECTURE.md` | `performance_management`, `workforce_validation` | Versioned evidence references; no local reclassification of a model score as validated potential/readiness | +| Talent high-impact decisions are human-accountable and purpose-bound | Orgmetra TRD/API/security baseline; ADR 0292 | Proposed `talent_management` + `audit_provenance` | Actor/purpose/reason/evidence/confirmation/provenance fields mandatory; LLM draft evidence cannot finalize; a final `fully_automated_decision` is non-authorizing provenance and cannot finalize a high-impact Talent outcome | +| Actual final decision-production mode must be reconstructable rather than inferred from an actor flag | ADR 0292; Korea PIPA Article 37-2 conditional automated-decision regime; EU AI Act employment/high-risk decision scope | Proposed `talent_management` decision provenance; legal applicability remains a versioned policy/compliance responsibility | RED contracts distinguish human, AI-assisted-human, and fully automated production; preserve model/tool and substantive-human-intervention evidence; reject post-finalization relabeling; reject high-impact finalization in final `fully_automated_decision` mode; permit AI-assisted finalization only with recorded substantive human intervention and accountable human confirmation | +| Every material decision stage must remain reconstructable when it can constrain the reachable high-impact outcome | ADR 0292 / #294; EU AI Act Article 14 used as conditional design evidence; Alon-Barkat & Busuioc (2023) | Proposed `talent_management` stage provenance + `audit_provenance`; legal applicability stays outside Talent | Ordered immutable stage records preserve stage production mode, model/tool version, exact evidence/policy versions, input/output lineage, actor/disposition where present, and material effect; later final labels cannot erase upstream automated filtering, exclusion, ranking, suppression, thresholding, or routing | +| Every material stage must preserve the exact decision-opportunity denominator needed to reconstruct who was actually in scope and how they transitioned | #396; EEOC Uniform Guidelines Q&A used as design evidence; Alexander et al. (2025); Xu & Zhang (2024); ISO 30415:2021 governance context | Proposed `talent_management` owns purpose-minimized immutable `DecisionOpportunitySet` / `StageCohortManifest` provenance; `workforce_validation` owns fairness/validity analysis and protected-group joins | RED contracts fail when an upstream opportunity-set manifest is absent, excluded/suppressed records disappear, unavailable/not-evaluable states collapse into negative outcomes, stale criteria/policy reuse an old denominator, finalized manifests mutate, relevant multiple-membership/cross-classified/time structure is flattened, or `workforce_validation` must reconstruct the denominator via cross-service SQL/copied protected demographics | +| Exact denominator membership and counting unit must remain reconstructable across retry and repeated opportunities | #397; Dunleavy et al. (2008); EEOC Uniform Guidelines Q&A | Proposed `DecisionOpportunityEntry` or equivalent UL-approved entry under each closed Talent opportunity manifest; `workforce_validation` owns analytic estimand/grouping choice | Each denominator entry has a semantic opportunity occurrence identity stable across retry/replay but distinct across legitimate repeated opportunities for the same worker; counting/analysis unit is versioned; processing attempts are many-to-one telemetry and cannot create denominator rows | +| Corrected opportunity history must resolve to one countable terminal outcome per semantic occurrence | #398; ADR 0292 append-only provenance and cardinality contract | Proposed `DecisionOpportunityEntry` correction/supersession chain under `talent_management`; `workforce_validation` consumes the released canonical entry set | At closed-manifest resolution each semantic occurrence has exactly one canonical active terminal entry. The mutually exclusive terminal set explicitly includes `advanced`, `not_evaluable`, `policy_inapplicable`, `human_excluded`, `automated_excluded_or_suppressed`, `withdrawn`, `unavailable`, and `failed`; unresolved evidence/authorization/owner availability becomes `unavailable`, unresolved error/failure becomes `failed`, and `not_evaluable` remains a distinct evaluability outcome. Superseded historical rows and processing/retry attempts are excluded from denominator/terminal totals; `entry_count == unique occurrence count == canonical active terminal count == sum(all canonical terminal classes)`; RED contracts reject zero/multiple active terminals, ambiguous/cyclic/dangling chains, retryable states counted before closure, terminal-class omission/remapping, or closed unavailable/failed/not-evaluable outcomes omitted from the denominator | +| Replacement opportunity manifests must resolve to an explicit reproducible denominator view rather than an implicit `latest` or union | #399; ADR 0003 bitemporal history principle; #396–#398 denominator provenance; RFC 8785 used only as canonicalization engineering evidence | Proposed immutable manifest-lineage/version contract under `talent_management`; `workforce_validation` binds the selected released view | Stable manifest lineage identity, immutable version+digest and explicit supersession preserve both as-recorded history and corrected-as-of views. Manifest digest identity is independently reproducible from a versioned canonical semantic field-set/projection, deterministic serialization/ordering/normalization rules, digest algorithm/domain separator/version and metadata-contract version; consumers recompute/validate it. RED contracts reject opaque/non-recomputable digests, serializer/presentation accidents changing identity, blind M1+M2 union, historical queries rewritten by later correction, superseded versions returned for corrected-as-of analysis, unqualified `latest`, ambiguous/cyclic/dangling replacement lineages, silent cross-version opportunity drift, or scientific results without exact lineage/version/digest/digest-contract/view/as-of provenance | +| A manifest correction must not cross a materially different selection-policy regime | #400; EEOC Uniform Guidelines Q&A Q47 used as design evidence; #396–#399 denominator provenance | Proposed `talent_management` records immutable decision-policy identity plus a canonical material policy-semantics/regime identity; `workforce_validation` owns whether evidence supports the changed procedure | Same-regime correction requires explicit semantic-compatibility evidence. Material changes to eligibility meaning, threshold/cut score, ranking/order method, required-evidence meaning, suppression/routing, or another rule that changes who can enter/advance/be excluded start a new policy regime and are not reachable by ordinary `corrected_as_of` traversal. RED contracts reject missing/ambiguous semantic identity, material changes hidden as corrections, semantic no-op/editorial reseals split without evidence, downstream results lacking policy-regime provenance, or historical results retroactively rewritten under a later procedure | +| Policy-regime identity must be owner-recomputable and closed over material dependencies rather than caller-declared | #401; RFC 8785 used only as canonicalization engineering evidence; W3C PROV-DM provenance model; NIST AI RMF Playbook MANAGE 3.1 third-party-resource provenance | Proposed `talent_management` owns a versioned canonical material-policy semantic projection and immutable dependency provenance; authoritative Job/FJA/KSAO, assessment, model/tool, performance and validation truth remains with released owners | The owner recomputes the regime identity from an explicit projection-schema/version, deterministic canonical representation, digest algorithm/domain/version, and exact released material dependency identities/versions/digests. Caller-supplied regime IDs/digests, mutable branch/floating refs, live cross-service table state, serializer-order accidents, presentation metadata, or unaudited operator assertions cannot establish equivalence. Every manifest and downstream result binds the projection schema/version and dependency set needed for independent reproduction; integrity collision/mismatch fails closed and is not treated as semantic equivalence | +| External artifact integrity and external selection-semantic authority must remain distinct across bounded contexts | #402; protected `JobAnalysisSnapshot` deterministic content identity; W3C PROV-DM; NIST AI RMF Playbook MANAGE 3.1 | Each external owner publishes a released/versioned semantic-dependency receipt or equivalent ACL projection; `talent_management` consumes it without reconstructing foreign truth | Each receipt binds owner/context, released contract/artifact/version, exact integrity identity, downstream-material semantic identity/projection, applicability/effective scope, and owner-issued deterministic equivalence/migration evidence where used. An existing artifact digest may serve both meanings only when the owner contract explicitly defines it as the downstream-material semantic projection. Missing, ambiguous, conflicting, stale, wrong-purpose, wrong-tenant, floating, or caller-asserted semantic authority fails closed; Talent never queries/copies upstream internals to manufacture equivalence | +| A material stage must prove that the actually resolved procedure is congruent with the intended policy regime before its effect can authorize progression | #403; SLSA v1.2 provenance/build-provenance used only as engineering analogy for declared parameters versus resolved dependencies; NIST AI RMF Playbook MANAGE 3.1 | Proposed `talent_management` owns trusted stage-resolution / execution-congruence evidence; upstream owners retain source truth and `workforce_validation` retains scientific interpretation | Each material stage binds the governing policy projection and owner receipts to trusted observed-resolved immutable dependency identities/versions/digests plus material runtime parameters. Deterministic expected-versus-observed comparison yields explicit congruent/incongruent/unavailable status before advancement/exclusion/ranking/suppression/routing/finalization can authorize. Stale caches, fallback artifacts, extra material dependencies, alias-only provenance, retry dependency drift, missing verification, or caller-supplied resolved metadata fail closed; released manifests/results bind the canonical terminal attempt's execution evidence | +| The first recorded Talent denominator must preserve its opportunity-origin/source-universe semantics rather than begin after an opaque pre-cohort selection step | #404; Alexander et al. (2025) used only for the upstream-sourcing scientific-design analogy; existing People/Assignment/Position/Job owner boundaries | Proposed `talent_management` owns purpose-minimized first-stage origin/coverage provenance while People/Organization/Job owners remain authoritative for source-universe truth; `workforce_validation` owns estimand/fairness/validity interpretation | A `population_complete` first manifest is accepted only with a released/versioned owner source-universe receipt or equivalent immutable evidence identifying scope, tenant/purpose, time window, enumeration rule/version, and coverage semantics. Nomination, employee opt-in, targeted discovery, external import, or other intentionally non-exhaustive origins stay explicit and cannot be relabeled complete. Any material pre-M1 discovery/prescreen/nomination/prefilter is recorded as a material stage or versioned source-universe transformation with policy/evidence/execution provenance; partial enumeration failures remain visible; later source-universe corrections are append-only; no cross-context SQL, foreign source copy, or protected-attribute copy is used to reconstruct completeness; `workforce_validation` can distinguish source universe/origin scope, first observed cohort, and later stage denominators | +| Probability-sampled first-stage origins must preserve the sampling design and selected-unit dispositions needed for design-based reproduction | #405; Horvitz & Thompson (1952); AAPOR Disclosure Standards and Standard Definitions used only as sampling-provenance/reporting evidence | Proposed `talent_management` owns purpose-minimized sample-selection provenance for Talent-controlled origins; authoritative frame/source-universe truth stays with its owner; `workforce_validation` owns estimand, design weights, variance/SE/CI, FPC, calibration/nonresponse, protected-group joins, validity/fairness and scientific interpretation | Exact source-universe receipt, sampling-design identity/version, sampled semantic occurrence set, known non-zero inclusion probability or reproducible stage-wise probability inputs, relevant stratum/PSU/cluster/PPS/multistage structure, trusted sample-selection execution and explicit selected-unit dispositions are recoverable. RED contracts reject missing/invalid/wrong-stage probabilities, flattened complex design, sampled nonresponse/ineligibility/failure made indistinguishable from never-sampled units, hidden coverage failure, retry-created sample units, mutable design evidence, fabricated probabilities for non-probability origins, Talent-side reconstruction of strata/weights from foreign SQL/source/protected attributes, sensitive-strata leakage where opaque receipts suffice, or downstream results missing the exact design evidence used | +| Probability-sampled origins that support design-based uncertainty must preserve variance-sufficient evidence for the method actually claimed | #406; Berger (2004); U.S. Census Bureau Statistical Quality Standard D1; SIPP Sampling Error, used only as sampling-method/provenance evidence | Proposed `talent_management` binds a purpose-minimized released variance-design receipt or equivalent owner evidence; authoritative design owners or `workforce_validation` may issue it; `workforce_validation` retains estimator choice, calculation and scientific interpretation | Exact binding to the #405 source-universe/sampling receipt, sampled semantic occurrence set, selection execution and correction version; a versioned evidence strategy supplies joint inclusion information or a deterministic reproducible design representation when required, replicate method/version/count/scale/Fay-equivalent/construction metadata for replication methods, certainty/FPC/stage inputs when required, or an explicitly named/versioned approximation. Exact versus approximate semantics are explicit. RED contracts reject silent SRS/with-replacement substitution, ambiguous replicate construction, mismatched sample/design/variance versions, approximation presented as exact, or downstream results that cannot identify both the sampling receipt and the variance evidence/method/version used | +| Human presence is not sufficient evidence of effective oversight | EU AI Act Article 14 where applicable; Alon-Barkat & Busuioc (2023); ADR 0292 / #294 | Proposed Talent review/disposition contract | Before lock-in, reviewer receives relevant evidence and limitations, can inspect materially affected options, has an actually operable disregard/override/reversal/restore path, and records a controlled disposition plus purpose-bound reason/provenance; disabled, cosmetic, or unreachable controls fail acceptance | +| Automated exclusion or suppression cannot be laundered by a later confirmation | ADR 0292 / #294 | Proposed material-stage provenance and finalization policy | RED cases prove an upstream fully automated exclusion remains visible in provenance; if its effect is irreversible or hidden from the accountable reviewer, high-impact finalization fails closed instead of becoming `ai_assisted_human_decision` by a later click | +| Model-generated ranking/threshold remains recommendation/process evidence rather than Talent or validity truth | ADR 0292 scientific boundary; `workforce_validation` authority; #294 | Proposed Talent stage record consumes external construct/validation evidence | RED cases reject promotion of a model ranking/threshold into qualification, potential, readiness, or validity truth merely because a human accepted the output | +| Applicable automated-decision explanation/review/correction rights must be executable without leaking other workers' Talent evidence | Korea PIPA Article 37-2; Enforcement Decree Articles 44-2–44-4; PIPC Notice 2024-9; EU AI Act Article 86 where applicable | Proposed Talent rights-request/reconsideration records consuming a released/versioned tenant legal-policy contract | Policy-version-bound request/response tests; missing/stale applicable policy fails closed for configured regulated automated-decision handling; explanation redacts third-party slate/assessment/career data; reconsideration appends a new decision version and links the original material-stage chain rather than overwriting it; policy applicability never authorizes fully automated high-impact Talent finalization under this Proposed ADR | +| Current legal scope and dates are evidence to re-check, not permanent Talent-domain constants | Current Korean PIPA/Enforcement Decree and PIPC action criteria; consolidated Regulation (EU) 2024/1689 including Regulation (EU) 2026/1744 timing amendments | Canonical legal/compliance-policy owner to be resolved before implementation; Talent is a consumer | Release/ADR acceptance re-checks then-current law and policy; statutory deadlines/grounds and Article 14/86 applicability are versioned policy data, not hard-coded universal domain semantics | +| Talent history must remain reconstructable when the business fact is time-varying | Orgmetra bitemporal baseline; ADR 0003 | Proposed Talent persistence owner | Effective/system-time regressions, correction history, concurrent-write tests | +| Multiple legitimate talent-pool memberships must not be collapsed by a single-valued model | ADR 0292; Orgmetra multiple-membership modeling principle | Proposed `TalentPoolMembership` relation | Tests allow legitimate concurrent memberships while rejecting duplicate contradictory membership within one pool/version | +| Talent persistence must enforce tenant RLS without superuser application bypass | PostgreSQL row-security semantics; ADR 0292 persistence boundary | Future `talent_management` persistence adapter/migrations | Every tenant-bearing Talent table ENABLEs and FORCEs RLS; runtime roles are NOSUPERUSER/NOBYPASSRLS; PostgreSQL RED/GREEN proves owner-path enforcement and foreign-tenant denial; superusers are excluded from application traffic | +| Sensitive TalentPool/succession/career/assessment/performance evidence requires narrower access than a generic employee profile | ADR 0008 purpose-bound PII; ADR 0292 | Talent authorization boundary + Keyverse identity | tenant/actor/purpose/resource/lifetime tests, field minimization, enumeration-resistant restricted-resource denial, export/retention/legal-hold evidence | +| Material Talent UI must expose evidence/review/decision state, not a generic score dashboard | ADR 0292; repository UX/accessibility policy | future Talent workspace | normal/loading/empty/error/permission/stale/conflict/responsive/interaction/a11y and KO/EN/JA/ZH/VI/ES/DE/FR Storybook/E2E; materially automated exclusions/recommendations remain inspectable/recoverable to an authorized accountable reviewer before lock-in; applicable affected-worker explanation/review/correction states are included without implying unavailable legal rights | +| Buyer/scientific claims require real right-cleared evidence and reconstructable denominators | ADR 0292; #396; #397; #398; #399; #400; #401; #402; #403; #404; #405; #406; workforce-validation scientific policy | `talent_management` emits released purpose-minimized canonical opportunity-entry/cohort/origin/sampling/provenance evidence; `workforce_validation` owns estimand/grouping/design-based analysis and interpretation | provenance-backed production-shaped data; explicit first-stage source-universe/origin scope and coverage evidence; when sampling applies exact sampling-design/version, sampled occurrence set, inclusion-probability provenance, relevant design structure, selection execution and selected-unit dispositions, plus the exact variance-design evidence/method/version needed for any claimed uncertainty; exact stage entry membership, counting unit, canonical correction resolution and complete terminal classes; explicit manifest-lineage/version/digest/digest-contract/view/as-of selection; exact governing policy-regime/semantic identity plus reproducible semantic-projection schema/version; exact external owner semantic receipts; observed execution-congruence evidence; pinned material dependency set; opportunity-set/transition/error/failure denominators; relevant multilevel/cross-classified/multiple-membership/repeated-opportunity/time structure; no synthetic-only scientific acceptance | + +## Negative traceability + +The following are explicitly **not** evidence that ADR 0292 has been accepted or delivered: + +- selection of option C inside a Draft/Proposed ADR without normal protected integration; +- an issue, mockup, dashboard, or analytics query containing the word “talent”; +- a generic `potential_score`, `fit_score`, `readiness_score`, or “high-potential” flag without a versioned construct and validity boundary; +- direct reads of `people_core`, `organization_core`, `job_architecture`, `performance_management`, or `workforce_validation` application tables; +- mutable sibling branch contracts or copied source from another CWL repository; +- synthetic-only tests used as buyer/scientific acceptance; +- a later-stage shortlist, slate, ranking, or outcome set treated as the scientific denominator when the exact upstream opportunity set and transition classifications were not preserved; +- aggregate stage counts or a manifest digest treated as sufficient denominator evidence when exact entry-level membership and the counting unit cannot be reconstructed; +- a retry/replay attempt counted as another opportunity, or distinct legitimate opportunities for the same worker silently deduplicated into one denominator row; +- a superseded correction row counted alongside its replacement, two active terminal rows retained for one semantic occurrence, or a processing/failure attempt counted as a terminal denominator row; +- unresolved evidence/authorization/owner availability or error/failure at closure omitted, silently remapped into `not_evaluable`, or otherwise excluded from the complete canonical terminal-classification sum; +- an opaque manifest digest accepted without a versioned canonical semantic field set, deterministic encoding/order/normalization, digest algorithm/domain/version and consumer recomputation contract, or equivalent manifests receiving different digests because of serializer/presentation accidents; +- a superseded manifest blindly unioned with its replacement, an implicit unqualified `latest` used as denominator authority, or a historical as-recorded denominator silently rewritten by a later correction; +- a material eligibility, threshold/cut-score, ranking/order, required-evidence, suppression/routing, or equivalent selection-procedure change presented as an ordinary correction in the old policy regime; +- a semantic-preserving editorial/no-op policy reseal forced into a new regime solely because the version label changed, without explicit semantic evidence; +- a caller-supplied `policy_regime_id` or semantic digest accepted without owner recomputation from canonical policy/dependency evidence; +- a policy-regime digest whose value changes because of serializer key order, whitespace, presentation labels, timestamps, or another field excluded from the versioned semantic projection; +- a materially changed Job/FJA/KSAO qualification, evidence contract, assessment/model/tool configuration, or other released owner dependency omitted from the policy-semantic projection while the old regime identity is reused; +- a mutable branch ref, floating label, unversioned external identifier, or live cross-service table lookup used as policy-regime identity/equivalence evidence; +- semantic equivalence asserted by operator text without a deterministic equality rule or a versioned/auditable equivalence migration; +- an external owner artifact digest/version treated by itself as proof of downstream selection-semantic equivalence when the owner contract does not define that meaning; +- Talent parsing, copying, or querying foreign Job/FJA/KSAO/assessment/performance internals to manufacture a local semantic-equivalence verdict instead of consuming released owner semantic authority; +- a material stage recording only the intended policy regime, requested alias, configured model group, or caller-supplied resolved dependency metadata while the immutable dependency actually used at execution is unobserved or different; +- a stale cache, fallback, retry with a different dependency set, or extra material runtime parameter silently inheriting an `execution_congruent` result from the declared procedure; +- a first persisted manifest treated as population-complete merely because it is the first stored cohort, without released/versioned source-universe coverage authority; +- a nomination-only, employee-opt-in, targeted-discovery, or externally imported first cohort relabeled as the complete eligible population; +- a material discovery, sourcing, nomination, exposure, or prescreen step occurring before M1 and disappearing outside the stage/source-transformation graph; +- a free-text or mutable label such as `all eligible employees`, a live cross-context query, or copied protected attributes used as first-stage completeness authority; +- partial source enumeration/exposure failure silently shrinking the source universe rather than remaining explicit unavailable/failure coverage evidence; +- a genuine probability sample represented only as a generic `non_exhaustive` first cohort without its source-universe receipt, sampling-design/version and sampled occurrence evidence; +- a probability-sampled unit with missing, invalid, ambiguous or wrong-stage inclusion-probability provenance, or an unequal-probability design later treated as simple random sampling because the design inputs were dropped; +- a stratified, clustered, PPS or multistage sample flattened so the downstream analyst cannot reconstruct the design structure needed for variance estimation; +- a sampled refusal/opt-out, unreachable/unavailable unit, post-selection ineligible unit or processing failure made indistinguishable from a unit that was never sampled; +- a retry/replay that creates another sampled unit or probability for the same semantic sample occurrence, or a released sampling frame/design/probability/disposition record mutated in place; +- a nomination, opt-in, ranking, quota or deterministic-percentage non-probability cohort assigned fabricated inclusion probabilities or weights to make it appear probability-based; +- Talent querying/copying foreign frame, stratum or protected-demographic truth to reconstruct sampling design or analytic weights when a released opaque owner/design receipt is the correct boundary; +- a probability sample treated as variance-reproducible merely because `π_i` exists even though the claimed method requires joint inclusion information or another design-specific input; +- a complex without-replacement design silently analyzed with SRS or with-replacement variance while the result is labeled as the intended exact design variance; +- replicate weights whose method/version, replicate count, scale/Fay-equivalent factor, construction provenance or sampled-unit binding is missing or ambiguous; +- an approximation used without a versioned method/assumption contract or presented as the exact variance of another design; +- variance evidence produced from a different sampling-design or correction version than the point-estimation evidence, or later variance evidence mutated in place; +- a scientific result that cannot identify both the exact #405 sampling receipt and the separate #406 variance-design evidence/method/version actually used; +- a scientific or buyer result whose denominator cannot identify the exact source-universe/origin scope and, when probability sampling applies, exact design/version, sampled occurrence set, inclusion-probability provenance, relevant design structure, selected-unit dispositions and required variance-design evidence, plus the exact manifest lineage/version/digest/digest-contract/view/as-of cutoff, governing policy-semantics regime, semantic-projection schema/version, exact external owner semantic receipts, and actual execution-congruence provenance that supplied it; +- a historical result retroactively reinterpreted under a later policy regime instead of preserving the original evidence identity and emitting a new analysis/evidence version; +- a retryable stale/missing-evidence, owner/authorization-unavailable, or error/failure condition counted as terminal before closure, or a closed unavailable/not-evaluable/failed occurrence omitted instead of receiving one canonical active terminal classification; +- a fairness/adverse-impact percentage produced after silently dropping `not_evaluable`, stale/missing evidence, authorization/owner unavailability, suppression, withdrawal, or other controlled stage outcomes; +- a scientific analysis whose person/case/opportunity grouping rule is inferred after the fact because the versioned counting unit was not retained; +- a cohort rebuilt after the fact by cross-service SQL or copied protected attributes instead of consuming released purpose-authorized provenance; +- model/bot output used as final succession or mobility authority; +- a final `fully_automated_decision` provenance value, or a legal/policy applicability flag, used as authorization to finalize a high-impact Talent outcome under this Proposed ADR; +- a final `ai_assisted_human_decision` label used to erase or collapse an upstream fully automated eligibility, exclusion, ranking, suppression, thresholding, or routing stage; +- a human actor ID, signature, confirmation button, later label, or nominal override control used by itself as proof that a material decision stage was substantively human-supervised; +- an automated exclusion or suppressed option hidden from the very reviewer expected to exercise oversight, when that reviewer has no pre-lock-in way to inspect and restore/reverse the material effect; +- an AI recommendation presented without exact evidence/model/policy provenance, then accepted as Talent or validity truth because a human clicked confirm; +- an explanation/review path that reveals another worker's slate position, assessment result, career interest, or protected evidence; +- current statutory response periods, refusal grounds, jurisdictional scope, or EU AI Act Article 14/86 applicability hard-coded as timeless universal Talent semantics rather than versioned policy evidence; +- green workflow names whose underlying canonical evidence contract is missing, stale, neutral, synthetic, or untrusted; +- a permission-denied path that reveals whether a restricted Talent resource exists through status, body schema, empty-result semantics, metadata, names, or counts; +- runtime Talent application access through a superuser or BYPASSRLS role; +- Draft-path OpenCode/Noema success that explicitly skipped substantive review; +- routine administrator bypass or self-approval. + +## Next executable evidence + +The product-scope decision selects option C at the Proposed ADR layer. The next owner action is independent ADR review against then-current protected truth, followed by RED domain/API/security/scientific contracts for the four domain buyer journeys plus the cross-cutting decision-explanation/review/correction path before production schema/API/UI work. TalentPool denial contracts must compare an unauthorized existing restricted identifier with a nonexistent identifier and prove identical externally observable status/body/empty-result/metadata behavior; persistence contracts must separately prove FORCE RLS table behavior and NOSUPERUSER/NOBYPASSRLS runtime-role isolation. + +Decision-provenance contracts must preserve both final outcome mode and the ordered material-stage path. RED acceptance must fail when a fully automated eligibility/filtering stage excludes a worker and a later confirmation represents the path as human-decided; when a recommendation lacks exact evidence/model/policy version or a real override/reversal path but finalization is accepted as substantively human-supervised; when the reviewer can confirm but cannot inspect the material basis or recover an automatically suppressed option; when stage mode or human disposition is rewritten after material effect; when an upstream fully automated stage is silently collapsed into final `ai_assisted_human_decision`; or when a model-generated ranking/threshold becomes Talent or validity truth merely because a human accepted it. Any automated material stage retained in an AI-assisted path must remain inspectable, reconstructable, and genuinely reversible before lock-in, with a recorded controlled human disposition plus purpose-bound reason/provenance. + +Decision-opportunity contracts must separately prove that every material stage closes against an immutable, versioned opportunity-set/cohort manifest bound to the same tenant, purpose, process/version, stage/order, effective/system time or measurement window, criteria/policy version, and required evidence versions as the individual stage records. The manifest must contain exact entry-level membership with a semantic opportunity occurrence identity and explicit versioned counting unit. A semantic occurrence is stable across retry/replay but distinct from another legitimate opportunity involving the same worker; processing attempts are linked telemetry rather than denominator rows. Corrections are append-only but preserve the semantic occurrence identity and resolve through an acyclic, deterministic supersession chain to exactly one canonical active terminal entry. Superseded history and attempt telemetry are excluded from denominator/terminal totals. The mutually exclusive closed-stage terminal vocabulary includes `advanced`, `not_evaluable`, `policy_inapplicable`, `human_excluded`, `automated_excluded_or_suppressed`, `withdrawn`, `unavailable`, and `failed`: unresolved stale/missing evidence or authorization/owner availability becomes `unavailable`; unresolved error/failure becomes `failed`; `not_evaluable` remains a distinct explicit evaluability outcome. Closure must reconcile `entry_count == unique semantic opportunity occurrence count == canonical active terminal count == sum(all canonical active terminal classifications)` without omission or remapping. + +Manifest-replacement contracts must additionally prove deterministic authority across immutable replacement/reconsideration versions. The same corrected material-stage/cohort lineage retains a stable opaque lineage identity; every closed version has an immutable version+digest and explicit supersession predecessor; the lineage is acyclic and resolves one selected manifest for an explicit view/cutoff. The manifest digest contract itself is versioned and reproducible: it defines the canonical semantic field set/projection, deterministic serialization/ordering/normalization, digest algorithm, domain separator, digest version and metadata-contract version, and consumers recompute/validate the digest from released manifest evidence. Historical/as-recorded analysis binds the exact version that governed the stage at the requested time, while corrected-as-of analysis binds the deterministic canonical replacement as of the requested correction/system-time cutoff. Superseded manifests remain evidence but are not co-counted with replacements. Opportunity additions/removals or terminal changes across manifest versions require controlled semantic-occurrence-level delta provenance. Every released `workforce_validation` result binds the exact manifest lineage/version/digest/digest-contract/view/as-of so a later correction produces a new analysis/evidence version rather than rewriting an earlier result. + +Policy-regime contracts must additionally prove that same-lineage correction does not silently change the selection procedure. Each material stage binds immutable `decision_policy_version` plus a canonical policy-semantics/regime identity or digest sufficient to distinguish semantic change from an editorial/no-op reseal. Same-regime correction is permitted only when deterministic owner evidence establishes semantic compatibility. A material change to eligibility meaning, threshold/cut score, ranking/order method, required-evidence meaning, suppression/routing, or another rule that changes who can enter, advance, or be excluded creates a new policy regime; ordinary `corrected_as_of` traversal of the prior regime must fail closed rather than cross it. Historical opportunities may be re-analyzed under the new policy only as a new simulation/counterfactual/analysis result with explicit new-policy provenance. Every released `workforce_validation` result binds the exact policy-regime identity in addition to the selected manifest authority; Talent records provenance but does not decide whether validity/fairness evidence supports the changed procedure. + +Policy-regime identity/equivalence evidence must itself be reproducible. The owner defines and versions a semantic projection schema that includes every material local rule and every released external dependency capable of changing entry, evaluability, advancement, exclusion, ranking/order, thresholding, suppression, routing, or human-review reachability, while explicitly excluding presentation-only metadata. Material external inputs are represented only by released owner identity plus immutable version/digest or equivalent content-addressed evidence; mutable branch/floating refs and live cross-service state are invalid. The owner canonicalizes that projection using an explicitly versioned deterministic representation and computes/verifies an identity using an explicit digest algorithm/domain/version. Caller-supplied regime IDs or digests are recomputed rather than trusted. Same-regime equivalence is established by deterministic equality or a separately versioned/auditable equivalence migration whose inputs and output are provenance-bound; operator prose alone is not authority. Every manifest and downstream result carries the projection schema/version and exact material dependency set needed for independent reproduction. Collision or digest mismatch is integrity evidence that fails closed and requires explicit resolution; it is not a domain-equivalence verdict. + +External-semantic authority must be resolved before runtime congruence. For every material external dependency in the policy projection, consume a released owner semantic-dependency receipt or an explicitly equivalent owner contract that separates exact artifact integrity from downstream-material semantic identity. The receipt must make its owner/context, contract/version, applicability/effective scope, integrity identity, semantic projection/identity, and deterministic equivalence rule reproducible without Talent reading foreign application state. If the owner says two released artifacts are semantically equivalent, that assertion is itself released/versioned evidence; if required semantic authority is absent, conflicting, stale, wrong-purpose, wrong-tenant, or ambiguous, Talent fails closed rather than inferring compatibility. + +Execution-congruence contracts then bind each material stage occurrence to what actually resolved at runtime. The trusted Talent boundary observes or verifies the final immutable owner receipts/artifacts and any material runtime parameters used by the canonical terminal attempt, compares them deterministically with the governing policy projection, and records `execution_congruent`, `execution_incongruent`, or a controlled unavailable/not-verifiable state. A requested alias, configured model group, cache key, or caller-supplied resolved digest is not sufficient. Missing expected dependencies, fallback artifacts, stale cache content, extra material dependencies, digest/receipt mismatch, or retry-to-retry dependency drift make the stage non-authorizing until resolved. Released manifests and downstream `workforce_validation` results bind the exact execution evidence so the procedure studied is the procedure that actually ran, not merely the one declared. + +First-stage opportunity-origin contracts must additionally prove where M1 came from and what coverage claim is justified. A first manifest that claims `population_complete` must bind a released/versioned authoritative source-universe receipt or equivalent immutable snapshot/projection identifying owner/context, tenant/purpose, source-universe definition, effective/system-time window, enumeration rule/version, coverage/completeness semantics, and any unavailable/failure portion. Intentionally non-exhaustive nomination, employee opt-in, targeted discovery, external import, or equivalent origins stay explicitly non-exhaustive. A human or algorithmic exposure/discovery/nomination/prescreen step that materially determines who can enter before M1 exists is itself a material stage or versioned source-universe transformation with policy/evidence/execution provenance; it cannot disappear merely because persistence begins after that step. The first manifest binds the exact origin/source receipt in its material evidence identity, and source-universe correction is append-only. A materially changed enumeration/discovery rule participates in the existing policy-regime contract rather than masquerading as data correction. `workforce_validation` must be able to distinguish the declared source universe or origin scope, the first observed Talent cohort, and every later stage denominator without cross-context SQL or copied protected attributes. + +Probability-sampling contracts refine that origin contract only when the first observed cohort is actually selected by a probability design. The exact authoritative source-universe receipt must be bound to a versioned sampling-design identity and sampled semantic occurrence set. Preserve the stage structure, with/without-replacement semantics, stratification/clustering/PPS or other declared design, known non-zero unit inclusion probabilities or stage-wise inputs sufficient to derive them, purpose-minimized design memberships, trusted actual selection execution, partial-frame/coverage failures, and selected-unit dispositions that distinguish participation/response, refusal/opt-out, unreachable/unavailable, post-selection ineligibility and processing failure from never-sampled units. Retry/replay remains idempotent at the semantic sampled occurrence; correction is append-only. Talent does not manufacture pseudo-probabilities for nomination/opt-in/ranking/quota cohorts, copy sensitive stratum truth, or compute analytic weights/variance. `workforce_validation` receives the released design evidence and chooses the estimand, weights, variance/SE/CI, FPC, calibration/nonresponse adjustment and scientific interpretation. + +Variance-sufficiency contracts refine #405 only when a probability-sampled origin is used to support a design-based uncertainty claim. The exact source-universe receipt, #405 sampling-design/sample/correction identity and actual selection execution must bind to the exact variance-evidence strategy and version. Where the selected downstream method needs joint inclusion probabilities, the owner evidence must carry `π_ij` or a deterministic released representation that reproduces it; where replication is used, method/version, replicate count, scale/Fay-equivalent factors, construction provenance and semantic sample binding are explicit; and certainty units, FPC/sampling-fraction or stage-specific information is retained when required. A first-order-only or other approximation is permitted only as an explicitly named/versioned approximate method with assumptions. Talent does not select the estimator or calculate uncertainty. `workforce_validation` records the estimator/method actually used and binds both the #405 sampling receipt and #406 variance-design evidence so missing or mismatched variance evidence is `not_verifiable`, not a scientific GREEN. + +RED acceptance must fail when the manifest is missing; when only aggregate counts/digests exist without exact entry membership; when exclusions/suppressions/errors disappear; when `not_evaluable`, stale/missing evidence, authorization/owner unavailability or policy inapplicability is collapsed into a negative outcome; when a retry creates a second occurrence; when separate opportunities for one worker are collapsed; when the counting unit is missing or changes without a versioned contract change; when the closed cardinalities do not reconcile; when one occurrence resolves to zero or multiple canonical active terminal entries; when a superseded entry or retry/failure attempt contributes to terminal totals; when unresolved stale/missing evidence or authorization/owner availability at closure does not produce `unavailable`; when unresolved error/failure at closure does not produce `failed`; when `unavailable`/`failed` are silently remapped to `not_evaluable`; when any canonical terminal class is omitted from the closure sum; when a correction mints a new occurrence without a genuinely new business opportunity; when an occurrence supersession chain is cyclic, dangling, or ambiguous; when a retryable unavailable/error state is counted as terminal before closure; when a closed unavailable/failed/not-evaluable outcome disappears; when a changed policy reuses an old denominator; when a finalized manifest/entry is rewritten instead of superseded; when M1 and its replacement M2 are blindly unioned; when an unqualified `latest` is accepted; when a historical as-recorded request returns a newer replacement or a corrected-as-of request returns a superseded predecessor; when manifest supersession is cyclic, dangling, or ambiguous; when a correction changes lineage without a genuinely new cohort/stage; when opportunity additions/removals lack controlled delta provenance; when a manifest digest cannot be independently recomputed from versioned canonical semantics or changes because of serializer/presentation accidents; when material eligibility/threshold/ranking/required-evidence/suppression-routing semantics change but the replacement remains in the old policy regime; when `corrected_as_of` crosses an incompatible policy regime; when policy-semantic identity is absent, ambiguous, or incompatible with the selected manifest; when a semantic no-op/editorial policy reseal is split into a new regime without evidence; when a caller-supplied policy-regime identity/digest cannot be independently recomputed; when serializer ordering/whitespace/presentation metadata changes the identity; when a material released dependency changes but the old regime identity survives because that dependency was omitted; when a mutable/floating external reference or live cross-service lookup participates in identity/equivalence; when canonicalization/projection/digest algorithm version is absent or ambiguous; when semantic equivalence depends on unaudited operator assertion; when an external artifact integrity digest is accepted as semantic equivalence without an owner-defined semantic contract; when Talent reconstructs foreign owner semantics locally; when a semantic receipt is missing/conflicting/stale/wrong-purpose/wrong-tenant but composition proceeds; when runtime resolves a different model/tool/FJA/KSAO/assessment/evidence contract than the regime expects and the stage still authorizes; when a mutable alias is stored without the final immutable resolved identity; when fallback, stale cache, extra material dependency, or retry dependency drift remains hidden; when caller-supplied resolved metadata substitutes for trusted observation; when execution evidence is missing/ambiguous/unverifiable but a downstream manifest/result is released as congruent; when a caller supplies an arbitrary subset as M1 and labels it population-complete without authoritative source-universe evidence; when a pre-M1 discovery/prescreen removes workers/options without a material-stage or source-transformation record; when nomination-only/opt-in/targeted/imported origins are analyzed as complete populations; when source-universe identity is only mutable query/free text/floating state; when material origin receipts are omitted from first-manifest provenance; when source-universe evidence is stale/wrong-purpose/wrong-tenant/wrong-time; when a material enumeration/discovery rule changes without a new compatible policy-regime identity; when partial source enumeration failures silently shrink coverage; when later source-universe correction rewrites historical M1 or released analysis; when Talent reconstructs completeness through foreign application SQL/source copying; when protected attributes are copied merely to reconcile the source universe; when `workforce_validation` receives M1 but cannot determine whether it arose from exhaustive enumeration, nomination, opt-in, targeted discovery, import, or another selective origin; when a `probability_sample` lacks an authoritative source-universe receipt; when a required inclusion probability is missing, zero, negative, greater than one, ambiguous or associated with the wrong selection stage; when an unequal-probability design is flattened so it can only be analyzed as an unweighted/simple-random sample; when stratified, clustered, PPS or multistage design structure is lost; when sampled refusal/unreachable/ineligible/failure cases become indistinguishable from never-sampled units; when frame/coverage failure is hidden; when retry/replay mints another sampled unit or probability; when released sampling evidence is mutated in place; when pseudo-probabilities/weights are fabricated for a non-probability origin; when Talent reconstructs strata/weights by foreign SQL/source copying/protected-demographic replication; when sensitive stratum values are copied although an opaque released owner/design receipt suffices; when downstream `workforce_validation` cannot identify the exact source-universe receipt, sampling design/version, sampled occurrence set, inclusion-probability provenance, relevant design structure and selected-unit disposition evidence; when an unequal-probability without-replacement uncertainty method needs joint inclusion information but only first-order probabilities are retained; when SRS/with-replacement variance is silently substituted for the intended complex design; when an approximation is unlabeled/unversioned or presented as exact; when replicate weights lack method/count/scaling/construction/sample binding; when variance evidence and point-estimation evidence refer to different sample/design/correction versions; when required certainty/FPC/stage information is dropped; when variance evidence is mutated rather than superseded; when downstream cannot identify both the #405 sampling receipt and #406 variance-design evidence/method/version; when downstream `workforce_validation` receives only an opaque regime ID without the released projection/dependency/semantic-receipt/execution/origin/sampling/variance provenance required to reproduce it; when a digest mismatch/collision is accepted as semantic equivalence; when a historical result is rewritten under a later policy rather than producing a new analysis/evidence version; when a released scientific result omits exact source-universe/origin scope, applicable sampling/variance design evidence, selected manifest lineage/version/digest/digest-contract/view/as-of or governing policy-regime identity/projection/dependency/actual-execution provenance; when relevant multiple-membership/cross-classified/repeated-opportunity/time structure is flattened; when `workforce_validation` needs cross-service SQL/copied protected demographics to recover the denominator or sampling design; or when a fairness/adverse-impact claim is made from synthetic-only or non-right-cleared denominator evidence. + +Imported/historical/external fully automated final outcomes may be retained only as non-authorizing provenance for reconstruction and applicable rights handling. A canonical legal/compliance-policy authority must be resolved before implementation; Talent must consume it by released/versioned contract rather than make its own legal applicability determination. The review must not treat Draft-path model-review skip-success as approval. If protected product scope has materially contracted by then, reopen C versus D explicitly and update PRD/positioning rather than silently deleting or broadening the owner boundary. \ No newline at end of file