Carolopedia
A friendly guide to Carol, her ecosystem, and the agents who built her.
📖 Carolopedia › Services › Build Initiatives › All activities › INI-999901726Guide page
📋
📖About
Build a new Audit Scorecard app owned by Themis (agt_028), the audit/compliance counterpart to Prometheus Quality Scorecard and Hermione Process Health Scorecard. Same design pattern as the Quality Scorecard: shared scorecard renderer + the ONE metric catalogue, scoped to the AUDIT dimension (Themis-owned measures by home service), with an audit-measure-to-be-defined placeholder elsewhere (mirrors quality_tbd). Built the app-building-skill way (add-new-app contract H1-H8/S1-S5). Route /dev/audit-scorecard/ port 7270.
⚖️Decisions
- Elrond's bypass methodology checklist (a reminder, not a gate -- you've got this): 0. File it requested_mode='bypass' (planner-vs-bypass is a deliberate choice). bypass_start REFUSES a non-bypass initiative (CAROL-INI-1846), and the dispatcher only skips the bypass lane when the mode says bypass -- a 'planner' mistag lets Merlin's pipeline grab the placeholder step and block your finished work. 1. Filed as planned status -- let the bypass claim/activate it; never file active. 2. Open the bypass (bypass_start) with your droid id + the remediation answer (remediates_initiative_id=NNN, or remediates_nothing=True). 3. Work the blocks for your work-type: template -> design -> code -> test -> review. Do the real work; record decisions on the initiative as you make them. 4. Reality is recorded for you at close -- code (files changed), each decision, and the twin-review verdict become real activities tied to this initiative and show in the Activity Tracker like a planner run (CAROL-INI-1840). No dummy rows. 5. Keep the initiative status moving; it parks in 'reviewing' and is tagged uat-pending for you at close (CAROL-INI-1836), so the stuck-watchdog leaves it alone until UAT. 6. Close runs the gates (design/architecture compliance + caller-audit). If a gate flags something pre-existing or unrelated to your change, waive it with a clear written rationale -- audit, don't skip. 7. Bypass skips the planner's auto-orchestration, NOT the standards. Same template checklist, same review, same observability as a planner run. (elrond)
- [status-router] planned -> executing | event=bypass_executing | bypass transition (or-bx-01)
- Caller audit waived by Orion: this bypass added a new observability app (Audit Scorecard) and an APPEND-ONLY extension to shared/metric_catalogue.py (audit_tbd placeholder + service_audit_metrics). It did not modify shared/bypass.py or any bypass-runtime behaviour; the INI-716 caller-audit gate fires on fleet-wide uncommitted bypass.py edits unrelated to this change. — New app + append-only shared helper; no bypass-runtime callers touched. (orion)
- [delivery-check] 4 must-have criteria remain pending at bypass_end — delivery has no mechanical re-performance lane; UAT must grade on live evidence, not checklist silence (CAROL-INI-3020): (no detail) (orion)
- [status-router] executing -> reviewing | event=bypass_reviewing | bypass transition (or-bx-01)
- [status-router] reviewing -> executing | event=bypass_executing | bypass transition (or-bx-01)
- Handover-watchdog: planner-pending nudge for phase 2 (auto-invoked Elrond planner). (elrond)
- Caller audit waived by Orion: this UAT-rework added shared/audit_metric.py (read-only over Themis's audit stores) and two current_value branches in the metric catalogue. It did not modify shared/bypass.py or any bypass-runtime behaviour; the INI-716 caller-audit gate fires on fleet-wide uncommitted bypass.py edits unrelated to this change. — New read-only metric module + two catalogue branches; no bypass-runtime callers touched. (orion)
- [delivery-check] 4 must-have criteria remain pending at bypass_end — delivery has no mechanical re-performance lane; UAT must grade on live evidence, not checklist silence (CAROL-INI-3020): (no detail) (orion)
- [status-router] executing -> reviewing | event=bypass_reviewing | bypass transition (or-bx-01)
- [status-router] reviewing -> closed | event=operator_signoff | Auto-accepted (CAROL-INI-1859): Orion-initiated, >2 days in reviewing with no objection. (el-srac-01)
✅Success criteria
- A new Audit Scorecard is reachable at /dev/audit-scorecard/ and is owned by Themis. (must_have)
- It lists every Carol service with its audit/compliance measures, mirroring the Quality Scorecard layout exactly (same shared renderer: topbar, three stat boxes, service to measure to status table). (must_have)
- Services with a defined Themis audit measure show it (Audit and Compliance shows open findings; Governance shows policy compliance); services without one show audit measure to be defined. (must_have)
- The app is registered in the registry, routed over its public https URL, and passes its static and browser tests. (must_have)