Skip to content

docs: prepare Outly shadow audit deliverables - #16

Merged
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit
Jul 20, 2026
Merged

docs: prepare Outly shadow audit deliverables#16
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added draft schemas defining proposed Outly actions, decisions, and action outcomes.
    • Added validation for identifiers, decision statuses, timestamps, references, idempotency fields, and requested side effects.
  • Documentation

    • Added guidance clarifying that the schemas are non-canonical design artifacts and are not enabled at runtime.
    • Documented open questions, readiness findings, implementation gaps, and proposed requirements for future shadow-mode evaluation.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiReadyReadyPreview, CommentJul 20, 2026 7:29pm
veklom-id-59uwReadyReadyPreview, CommentJul 20, 2026 7:29pm

@coderabbitai

coderabbitaiBot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@reprewindai-dev, you've reached your PR review limit, so we couldn't start this review.

Next review available in:31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3d1c38b9-429c-48cc-94fb-ab13bfa7f577

📥 Commits

Reviewing files that changed from the base of the PR and between 41023dd and c4b14de.

📒 Files selected for processing (4)
  • src/app/api/outly/intercept/route.ts
  • src/app/api/outly/outcome/route.ts
  • src/lib/covenant/outly-gate.ts
  • src/lib/covenant/outly-types.ts
📝 Walkthrough

Walkthrough

Adds three non-canonical Outly shadow-mode JSON Schemas and documentation covering schema boundaries, readiness evidence, implementation gaps, and unresolved pilot questions.

Changes

Outly shadow-mode preparation

Layer / File(s)Summary
Draft shadow-mode contracts
contracts/drafts/outly/*.schema.json, contracts/drafts/outly/README.md
Adds strict draft schemas for proposed actions, decisions, and action outcomes, with identifiers, enums, timestamps, references, nested validation, and non-runtime disclaimers.
Readiness audit and boundary evidence
docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md
Documents the intended Outly/Veklom boundary, observed request path, runtime-authority conflicts, simulated behavior, validation results, readiness gaps, and a proposed implementation packet.
Shadow-mode discovery questions
docs/outly/OUTLY-OPEN-QUESTIONS.md
Lists unresolved questions for action selection, identity, retries, decisions, outcomes, evidence, audit, and pilot acceptance.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the docs-focused Outly shadow audit and deliverable preparation changes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1784560124-outly-shadow-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md`:
- Around line 45-55: Update the evidence questions in the “Evidence and audit”
section to explicitly address the required evidence-reference pair of
evidence_id and entry_hash, including whether Outly can provide and consume both
values and how cAPI verifies their binding to the associated action, decision,
and outcome.
- Around line 32-36: Update the open questions around DecisionV1 to explicitly
define consistency invariants between decision, modifications, and
human_review_required: specify when modifications must be empty or allowed, how
the HUMAN_REVIEW decision maps to human_review_required, and whether expired
decisions may be executed or must be rejected.
- Around line 26-28: Update the retry and replay questions around items 14–16 to
define stability and change semantics for action_id, execution_id, nonce, and
idempotency_key across retries. Explicitly specify the deduplication rule and
how already-seen correlation values are classified, covering both repeated
retries and duplicate outcomes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07e40fea-7544-4a4b-bad7-af3d20039686

📥 Commits

Reviewing files that changed from the base of the PR and between 5891406 and 41023dd.

📒 Files selected for processing (6)
  • contracts/drafts/outly/ActionOutcomeV1.schema.json
  • contracts/drafts/outly/DecisionV1.schema.json
  • contracts/drafts/outly/ProposedActionV1.schema.json
  • contracts/drafts/outly/README.md
  • docs/outly/OUTLY-OPEN-QUESTIONS.md
  • docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md

Comment on lines +26 to +28
14. How does Outly retry a proposal, and which idempotency key remains stable across retries?
15. What replay behavior should Outly expect for an already-seen nonce or idempotency key?
16. What should happen if Veklom is unavailable: fail open, fail closed, or continue in an explicitly marked audit-only mode?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Define retry identity across all correlation fields.

The draft schemas require action_id, execution_id, nonce, and idempotency_key, but these questions only cover action ID and idempotency-key stability. Specify which fields remain stable versus change per retry and the deduplication rule; otherwise retries may be misclassified as new executions or duplicate outcomes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 26 - 28, Update the retry
and replay questions around items 14–16 to define stability and change semantics
for action_id, execution_id, nonce, and idempotency_key across retries.
Explicitly specify the deduplication rule and how already-seen correlation
values are classified, covering both repeated retries and duplicate outcomes.

Comment on lines +32 to +36
17. What exactly should `MODIFY` mean to Outly: modify parameters, route to another capability, reduce scope, cap amount, change timing, or something else?
18. Can Outly consume a structured list of modifications, and which fields are safe to modify?
19. What does `HUMAN_REVIEW` mean operationally, and who is the reviewer?
20. Does `DENY` prevent Outly execution, or is the first pilot strictly observational?
21. For a lane-3 action, what CAPPO authorization artifact can Outly correlate to the decision?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Capture invariants between decision fields.

DecisionV1 requires decision, modifications, and human_review_required, but the questions do not define their consistency rules. Clarify whether modifications must be empty unless the decision is MODIFY, whether human_review_required must correspond to HUMAN_REVIEW, and how expired decisions affect execution.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 32 - 36, Update the open
questions around DecisionV1 to explicitly define consistency invariants between
decision, modifications, and human_review_required: specify when modifications
must be empty or allowed, how the HUMAN_REVIEW decision maps to
human_review_required, and whether expired decisions may be executed or must be
rejected.

Comment on lines +45 to +55
27. What evidence reference does Outly already create, if any, and can it be linked to the Veklom decision?

## Evidence and audit

28. Which decision, proposal, and outcome fields must be retained?
29. What audit retention, deletion, and data-residency requirements apply?
30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?
31. What should the system report when gnomledger is unavailable?
32. Which fields are confidential and must not be treated as merely base64-encoded?
33. Which parties may read decision and outcome evidence?
34. What evidence receipt or ledger hash format can Outly consume?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Make the evidence-reference contract explicit.

DecisionV1 and ActionOutcomeV1 require a non-null evidence reference to contain both evidence_id and entry_hash, while src/app/api/capi/v1/evidence/[id]/route.ts currently returns mocked evidence without entry_hash. Add an explicit question covering whether Outly can provide and consume this required pair, and how cAPI verifies its binding to the action, decision, and outcome.

🧰 Tools
🪛 LanguageTool

[grammar] ~51-~51: Ensure spelling is correct
Context: ...ply? 30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~52-~52: Ensure spelling is correct
Context: ... 31. What should the system report when gnomledger is unavailable? 32. Which fields are co...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 45 - 55, Update the evidence
questions in the “Evidence and audit” section to explicitly address the required
evidence-reference pair of evidence_id and entry_hash, including whether Outly
can provide and consume both values and how cAPI verifies their binding to the
associated action, decision, and outcome.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
docs: prepare Outly shadow audit deliverables by reprewindai-dev · Pull Request #16 · reprewindai-dev/cAPI · GitHub
Skip to content

docs: prepare Outly shadow audit deliverables - #16

Merged
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit
Jul 20, 2026
Merged

docs: prepare Outly shadow audit deliverables#16
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added draft schemas defining proposed Outly actions, decisions, and action outcomes.
    • Added validation for identifiers, decision statuses, timestamps, references, idempotency fields, and requested side effects.
  • Documentation

    • Added guidance clarifying that the schemas are non-canonical design artifacts and are not enabled at runtime.
    • Documented open questions, readiness findings, implementation gaps, and proposed requirements for future shadow-mode evaluation.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiReadyReadyPreview, CommentJul 20, 2026 7:29pm
veklom-id-59uwReadyReadyPreview, CommentJul 20, 2026 7:29pm

@coderabbitai

coderabbitaiBot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@reprewindai-dev, you've reached your PR review limit, so we couldn't start this review.

Next review available in:31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3d1c38b9-429c-48cc-94fb-ab13bfa7f577

📥 Commits

Reviewing files that changed from the base of the PR and between 41023dd and c4b14de.

📒 Files selected for processing (4)
  • src/app/api/outly/intercept/route.ts
  • src/app/api/outly/outcome/route.ts
  • src/lib/covenant/outly-gate.ts
  • src/lib/covenant/outly-types.ts
📝 Walkthrough

Walkthrough

Adds three non-canonical Outly shadow-mode JSON Schemas and documentation covering schema boundaries, readiness evidence, implementation gaps, and unresolved pilot questions.

Changes

Outly shadow-mode preparation

Layer / File(s)Summary
Draft shadow-mode contracts
contracts/drafts/outly/*.schema.json, contracts/drafts/outly/README.md
Adds strict draft schemas for proposed actions, decisions, and action outcomes, with identifiers, enums, timestamps, references, nested validation, and non-runtime disclaimers.
Readiness audit and boundary evidence
docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md
Documents the intended Outly/Veklom boundary, observed request path, runtime-authority conflicts, simulated behavior, validation results, readiness gaps, and a proposed implementation packet.
Shadow-mode discovery questions
docs/outly/OUTLY-OPEN-QUESTIONS.md
Lists unresolved questions for action selection, identity, retries, decisions, outcomes, evidence, audit, and pilot acceptance.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the docs-focused Outly shadow audit and deliverable preparation changes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1784560124-outly-shadow-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md`:
- Around line 45-55: Update the evidence questions in the “Evidence and audit”
section to explicitly address the required evidence-reference pair of
evidence_id and entry_hash, including whether Outly can provide and consume both
values and how cAPI verifies their binding to the associated action, decision,
and outcome.
- Around line 32-36: Update the open questions around DecisionV1 to explicitly
define consistency invariants between decision, modifications, and
human_review_required: specify when modifications must be empty or allowed, how
the HUMAN_REVIEW decision maps to human_review_required, and whether expired
decisions may be executed or must be rejected.
- Around line 26-28: Update the retry and replay questions around items 14–16 to
define stability and change semantics for action_id, execution_id, nonce, and
idempotency_key across retries. Explicitly specify the deduplication rule and
how already-seen correlation values are classified, covering both repeated
retries and duplicate outcomes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07e40fea-7544-4a4b-bad7-af3d20039686

📥 Commits

Reviewing files that changed from the base of the PR and between 5891406 and 41023dd.

📒 Files selected for processing (6)
  • contracts/drafts/outly/ActionOutcomeV1.schema.json
  • contracts/drafts/outly/DecisionV1.schema.json
  • contracts/drafts/outly/ProposedActionV1.schema.json
  • contracts/drafts/outly/README.md
  • docs/outly/OUTLY-OPEN-QUESTIONS.md
  • docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md

Comment on lines +26 to +28
14. How does Outly retry a proposal, and which idempotency key remains stable across retries?
15. What replay behavior should Outly expect for an already-seen nonce or idempotency key?
16. What should happen if Veklom is unavailable: fail open, fail closed, or continue in an explicitly marked audit-only mode?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Define retry identity across all correlation fields.

The draft schemas require action_id, execution_id, nonce, and idempotency_key, but these questions only cover action ID and idempotency-key stability. Specify which fields remain stable versus change per retry and the deduplication rule; otherwise retries may be misclassified as new executions or duplicate outcomes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 26 - 28, Update the retry
and replay questions around items 14–16 to define stability and change semantics
for action_id, execution_id, nonce, and idempotency_key across retries.
Explicitly specify the deduplication rule and how already-seen correlation
values are classified, covering both repeated retries and duplicate outcomes.

Comment on lines +32 to +36
17. What exactly should `MODIFY` mean to Outly: modify parameters, route to another capability, reduce scope, cap amount, change timing, or something else?
18. Can Outly consume a structured list of modifications, and which fields are safe to modify?
19. What does `HUMAN_REVIEW` mean operationally, and who is the reviewer?
20. Does `DENY` prevent Outly execution, or is the first pilot strictly observational?
21. For a lane-3 action, what CAPPO authorization artifact can Outly correlate to the decision?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Capture invariants between decision fields.

DecisionV1 requires decision, modifications, and human_review_required, but the questions do not define their consistency rules. Clarify whether modifications must be empty unless the decision is MODIFY, whether human_review_required must correspond to HUMAN_REVIEW, and how expired decisions affect execution.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 32 - 36, Update the open
questions around DecisionV1 to explicitly define consistency invariants between
decision, modifications, and human_review_required: specify when modifications
must be empty or allowed, how the HUMAN_REVIEW decision maps to
human_review_required, and whether expired decisions may be executed or must be
rejected.

Comment on lines +45 to +55
27. What evidence reference does Outly already create, if any, and can it be linked to the Veklom decision?

## Evidence and audit

28. Which decision, proposal, and outcome fields must be retained?
29. What audit retention, deletion, and data-residency requirements apply?
30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?
31. What should the system report when gnomledger is unavailable?
32. Which fields are confidential and must not be treated as merely base64-encoded?
33. Which parties may read decision and outcome evidence?
34. What evidence receipt or ledger hash format can Outly consume?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Make the evidence-reference contract explicit.

DecisionV1 and ActionOutcomeV1 require a non-null evidence reference to contain both evidence_id and entry_hash, while src/app/api/capi/v1/evidence/[id]/route.ts currently returns mocked evidence without entry_hash. Add an explicit question covering whether Outly can provide and consume this required pair, and how cAPI verifies its binding to the action, decision, and outcome.

🧰 Tools
🪛 LanguageTool

[grammar] ~51-~51: Ensure spelling is correct
Context: ...ply? 30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~52-~52: Ensure spelling is correct
Context: ... 31. What should the system report when gnomledger is unavailable? 32. Which fields are co...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 45 - 55, Update the evidence
questions in the “Evidence and audit” section to explicitly address the required
evidence-reference pair of evidence_id and entry_hash, including whether Outly
can provide and consume both values and how cAPI verifies their binding to the
associated action, decision, and outcome.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' docs: prepare Outly shadow audit deliverables by reprewindai-dev · Pull Request #16 · reprewindai-dev/cAPI · GitHub
Skip to content

docs: prepare Outly shadow audit deliverables - #16

Merged
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit
Jul 20, 2026
Merged

docs: prepare Outly shadow audit deliverables#16
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added draft schemas defining proposed Outly actions, decisions, and action outcomes.
    • Added validation for identifiers, decision statuses, timestamps, references, idempotency fields, and requested side effects.
  • Documentation

    • Added guidance clarifying that the schemas are non-canonical design artifacts and are not enabled at runtime.
    • Documented open questions, readiness findings, implementation gaps, and proposed requirements for future shadow-mode evaluation.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiReadyReadyPreview, CommentJul 20, 2026 7:29pm
veklom-id-59uwReadyReadyPreview, CommentJul 20, 2026 7:29pm

@coderabbitai

coderabbitaiBot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@reprewindai-dev, you've reached your PR review limit, so we couldn't start this review.

Next review available in:31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3d1c38b9-429c-48cc-94fb-ab13bfa7f577

📥 Commits

Reviewing files that changed from the base of the PR and between 41023dd and c4b14de.

📒 Files selected for processing (4)
  • src/app/api/outly/intercept/route.ts
  • src/app/api/outly/outcome/route.ts
  • src/lib/covenant/outly-gate.ts
  • src/lib/covenant/outly-types.ts
📝 Walkthrough

Walkthrough

Adds three non-canonical Outly shadow-mode JSON Schemas and documentation covering schema boundaries, readiness evidence, implementation gaps, and unresolved pilot questions.

Changes

Outly shadow-mode preparation

Layer / File(s)Summary
Draft shadow-mode contracts
contracts/drafts/outly/*.schema.json, contracts/drafts/outly/README.md
Adds strict draft schemas for proposed actions, decisions, and action outcomes, with identifiers, enums, timestamps, references, nested validation, and non-runtime disclaimers.
Readiness audit and boundary evidence
docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md
Documents the intended Outly/Veklom boundary, observed request path, runtime-authority conflicts, simulated behavior, validation results, readiness gaps, and a proposed implementation packet.
Shadow-mode discovery questions
docs/outly/OUTLY-OPEN-QUESTIONS.md
Lists unresolved questions for action selection, identity, retries, decisions, outcomes, evidence, audit, and pilot acceptance.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the docs-focused Outly shadow audit and deliverable preparation changes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1784560124-outly-shadow-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md`:
- Around line 45-55: Update the evidence questions in the “Evidence and audit”
section to explicitly address the required evidence-reference pair of
evidence_id and entry_hash, including whether Outly can provide and consume both
values and how cAPI verifies their binding to the associated action, decision,
and outcome.
- Around line 32-36: Update the open questions around DecisionV1 to explicitly
define consistency invariants between decision, modifications, and
human_review_required: specify when modifications must be empty or allowed, how
the HUMAN_REVIEW decision maps to human_review_required, and whether expired
decisions may be executed or must be rejected.
- Around line 26-28: Update the retry and replay questions around items 14–16 to
define stability and change semantics for action_id, execution_id, nonce, and
idempotency_key across retries. Explicitly specify the deduplication rule and
how already-seen correlation values are classified, covering both repeated
retries and duplicate outcomes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07e40fea-7544-4a4b-bad7-af3d20039686

📥 Commits

Reviewing files that changed from the base of the PR and between 5891406 and 41023dd.

📒 Files selected for processing (6)
  • contracts/drafts/outly/ActionOutcomeV1.schema.json
  • contracts/drafts/outly/DecisionV1.schema.json
  • contracts/drafts/outly/ProposedActionV1.schema.json
  • contracts/drafts/outly/README.md
  • docs/outly/OUTLY-OPEN-QUESTIONS.md
  • docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md

Comment on lines +26 to +28
14. How does Outly retry a proposal, and which idempotency key remains stable across retries?
15. What replay behavior should Outly expect for an already-seen nonce or idempotency key?
16. What should happen if Veklom is unavailable: fail open, fail closed, or continue in an explicitly marked audit-only mode?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Define retry identity across all correlation fields.

The draft schemas require action_id, execution_id, nonce, and idempotency_key, but these questions only cover action ID and idempotency-key stability. Specify which fields remain stable versus change per retry and the deduplication rule; otherwise retries may be misclassified as new executions or duplicate outcomes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 26 - 28, Update the retry
and replay questions around items 14–16 to define stability and change semantics
for action_id, execution_id, nonce, and idempotency_key across retries.
Explicitly specify the deduplication rule and how already-seen correlation
values are classified, covering both repeated retries and duplicate outcomes.

Comment on lines +32 to +36
17. What exactly should `MODIFY` mean to Outly: modify parameters, route to another capability, reduce scope, cap amount, change timing, or something else?
18. Can Outly consume a structured list of modifications, and which fields are safe to modify?
19. What does `HUMAN_REVIEW` mean operationally, and who is the reviewer?
20. Does `DENY` prevent Outly execution, or is the first pilot strictly observational?
21. For a lane-3 action, what CAPPO authorization artifact can Outly correlate to the decision?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Capture invariants between decision fields.

DecisionV1 requires decision, modifications, and human_review_required, but the questions do not define their consistency rules. Clarify whether modifications must be empty unless the decision is MODIFY, whether human_review_required must correspond to HUMAN_REVIEW, and how expired decisions affect execution.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 32 - 36, Update the open
questions around DecisionV1 to explicitly define consistency invariants between
decision, modifications, and human_review_required: specify when modifications
must be empty or allowed, how the HUMAN_REVIEW decision maps to
human_review_required, and whether expired decisions may be executed or must be
rejected.

Comment on lines +45 to +55
27. What evidence reference does Outly already create, if any, and can it be linked to the Veklom decision?

## Evidence and audit

28. Which decision, proposal, and outcome fields must be retained?
29. What audit retention, deletion, and data-residency requirements apply?
30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?
31. What should the system report when gnomledger is unavailable?
32. Which fields are confidential and must not be treated as merely base64-encoded?
33. Which parties may read decision and outcome evidence?
34. What evidence receipt or ledger hash format can Outly consume?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Make the evidence-reference contract explicit.

DecisionV1 and ActionOutcomeV1 require a non-null evidence reference to contain both evidence_id and entry_hash, while src/app/api/capi/v1/evidence/[id]/route.ts currently returns mocked evidence without entry_hash. Add an explicit question covering whether Outly can provide and consume this required pair, and how cAPI verifies its binding to the action, decision, and outcome.

🧰 Tools
🪛 LanguageTool

[grammar] ~51-~51: Ensure spelling is correct
Context: ...ply? 30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~52-~52: Ensure spelling is correct
Context: ... 31. What should the system report when gnomledger is unavailable? 32. Which fields are co...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 45 - 55, Update the evidence
questions in the “Evidence and audit” section to explicitly address the required
evidence-reference pair of evidence_id and entry_hash, including whether Outly
can provide and consume both values and how cAPI verifies their binding to the
associated action, decision, and outcome.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' docs: prepare Outly shadow audit deliverables by reprewindai-dev · Pull Request #16 · reprewindai-dev/cAPI · GitHub
Skip to content

docs: prepare Outly shadow audit deliverables - #16

Merged
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit
Jul 20, 2026
Merged

docs: prepare Outly shadow audit deliverables#16
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added draft schemas defining proposed Outly actions, decisions, and action outcomes.
    • Added validation for identifiers, decision statuses, timestamps, references, idempotency fields, and requested side effects.
  • Documentation

    • Added guidance clarifying that the schemas are non-canonical design artifacts and are not enabled at runtime.
    • Documented open questions, readiness findings, implementation gaps, and proposed requirements for future shadow-mode evaluation.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiReadyReadyPreview, CommentJul 20, 2026 7:29pm
veklom-id-59uwReadyReadyPreview, CommentJul 20, 2026 7:29pm

@coderabbitai

coderabbitaiBot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@reprewindai-dev, you've reached your PR review limit, so we couldn't start this review.

Next review available in:31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3d1c38b9-429c-48cc-94fb-ab13bfa7f577

📥 Commits

Reviewing files that changed from the base of the PR and between 41023dd and c4b14de.

📒 Files selected for processing (4)
  • src/app/api/outly/intercept/route.ts
  • src/app/api/outly/outcome/route.ts
  • src/lib/covenant/outly-gate.ts
  • src/lib/covenant/outly-types.ts
📝 Walkthrough

Walkthrough

Adds three non-canonical Outly shadow-mode JSON Schemas and documentation covering schema boundaries, readiness evidence, implementation gaps, and unresolved pilot questions.

Changes

Outly shadow-mode preparation

Layer / File(s)Summary
Draft shadow-mode contracts
contracts/drafts/outly/*.schema.json, contracts/drafts/outly/README.md
Adds strict draft schemas for proposed actions, decisions, and action outcomes, with identifiers, enums, timestamps, references, nested validation, and non-runtime disclaimers.
Readiness audit and boundary evidence
docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md
Documents the intended Outly/Veklom boundary, observed request path, runtime-authority conflicts, simulated behavior, validation results, readiness gaps, and a proposed implementation packet.
Shadow-mode discovery questions
docs/outly/OUTLY-OPEN-QUESTIONS.md
Lists unresolved questions for action selection, identity, retries, decisions, outcomes, evidence, audit, and pilot acceptance.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the docs-focused Outly shadow audit and deliverable preparation changes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1784560124-outly-shadow-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md`:
- Around line 45-55: Update the evidence questions in the “Evidence and audit”
section to explicitly address the required evidence-reference pair of
evidence_id and entry_hash, including whether Outly can provide and consume both
values and how cAPI verifies their binding to the associated action, decision,
and outcome.
- Around line 32-36: Update the open questions around DecisionV1 to explicitly
define consistency invariants between decision, modifications, and
human_review_required: specify when modifications must be empty or allowed, how
the HUMAN_REVIEW decision maps to human_review_required, and whether expired
decisions may be executed or must be rejected.
- Around line 26-28: Update the retry and replay questions around items 14–16 to
define stability and change semantics for action_id, execution_id, nonce, and
idempotency_key across retries. Explicitly specify the deduplication rule and
how already-seen correlation values are classified, covering both repeated
retries and duplicate outcomes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07e40fea-7544-4a4b-bad7-af3d20039686

📥 Commits

Reviewing files that changed from the base of the PR and between 5891406 and 41023dd.

📒 Files selected for processing (6)
  • contracts/drafts/outly/ActionOutcomeV1.schema.json
  • contracts/drafts/outly/DecisionV1.schema.json
  • contracts/drafts/outly/ProposedActionV1.schema.json
  • contracts/drafts/outly/README.md
  • docs/outly/OUTLY-OPEN-QUESTIONS.md
  • docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md

Comment on lines +26 to +28
14. How does Outly retry a proposal, and which idempotency key remains stable across retries?
15. What replay behavior should Outly expect for an already-seen nonce or idempotency key?
16. What should happen if Veklom is unavailable: fail open, fail closed, or continue in an explicitly marked audit-only mode?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Define retry identity across all correlation fields.

The draft schemas require action_id, execution_id, nonce, and idempotency_key, but these questions only cover action ID and idempotency-key stability. Specify which fields remain stable versus change per retry and the deduplication rule; otherwise retries may be misclassified as new executions or duplicate outcomes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 26 - 28, Update the retry
and replay questions around items 14–16 to define stability and change semantics
for action_id, execution_id, nonce, and idempotency_key across retries.
Explicitly specify the deduplication rule and how already-seen correlation
values are classified, covering both repeated retries and duplicate outcomes.

Comment on lines +32 to +36
17. What exactly should `MODIFY` mean to Outly: modify parameters, route to another capability, reduce scope, cap amount, change timing, or something else?
18. Can Outly consume a structured list of modifications, and which fields are safe to modify?
19. What does `HUMAN_REVIEW` mean operationally, and who is the reviewer?
20. Does `DENY` prevent Outly execution, or is the first pilot strictly observational?
21. For a lane-3 action, what CAPPO authorization artifact can Outly correlate to the decision?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Capture invariants between decision fields.

DecisionV1 requires decision, modifications, and human_review_required, but the questions do not define their consistency rules. Clarify whether modifications must be empty unless the decision is MODIFY, whether human_review_required must correspond to HUMAN_REVIEW, and how expired decisions affect execution.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 32 - 36, Update the open
questions around DecisionV1 to explicitly define consistency invariants between
decision, modifications, and human_review_required: specify when modifications
must be empty or allowed, how the HUMAN_REVIEW decision maps to
human_review_required, and whether expired decisions may be executed or must be
rejected.

Comment on lines +45 to +55
27. What evidence reference does Outly already create, if any, and can it be linked to the Veklom decision?

## Evidence and audit

28. Which decision, proposal, and outcome fields must be retained?
29. What audit retention, deletion, and data-residency requirements apply?
30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?
31. What should the system report when gnomledger is unavailable?
32. Which fields are confidential and must not be treated as merely base64-encoded?
33. Which parties may read decision and outcome evidence?
34. What evidence receipt or ledger hash format can Outly consume?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Make the evidence-reference contract explicit.

DecisionV1 and ActionOutcomeV1 require a non-null evidence reference to contain both evidence_id and entry_hash, while src/app/api/capi/v1/evidence/[id]/route.ts currently returns mocked evidence without entry_hash. Add an explicit question covering whether Outly can provide and consume this required pair, and how cAPI verifies its binding to the action, decision, and outcome.

🧰 Tools
🪛 LanguageTool

[grammar] ~51-~51: Ensure spelling is correct
Context: ...ply? 30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~52-~52: Ensure spelling is correct
Context: ... 31. What should the system report when gnomledger is unavailable? 32. Which fields are co...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 45 - 55, Update the evidence
questions in the “Evidence and audit” section to explicitly address the required
evidence-reference pair of evidence_id and entry_hash, including whether Outly
can provide and consume both values and how cAPI verifies their binding to the
associated action, decision, and outcome.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' docs: prepare Outly shadow audit deliverables by reprewindai-dev · Pull Request #16 · reprewindai-dev/cAPI · GitHub
Skip to content

docs: prepare Outly shadow audit deliverables - #16

Merged
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit
Jul 20, 2026
Merged

docs: prepare Outly shadow audit deliverables#16
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added draft schemas defining proposed Outly actions, decisions, and action outcomes.
    • Added validation for identifiers, decision statuses, timestamps, references, idempotency fields, and requested side effects.
  • Documentation

    • Added guidance clarifying that the schemas are non-canonical design artifacts and are not enabled at runtime.
    • Documented open questions, readiness findings, implementation gaps, and proposed requirements for future shadow-mode evaluation.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiReadyReadyPreview, CommentJul 20, 2026 7:29pm
veklom-id-59uwReadyReadyPreview, CommentJul 20, 2026 7:29pm

@coderabbitai

coderabbitaiBot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@reprewindai-dev, you've reached your PR review limit, so we couldn't start this review.

Next review available in:31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3d1c38b9-429c-48cc-94fb-ab13bfa7f577

📥 Commits

Reviewing files that changed from the base of the PR and between 41023dd and c4b14de.

📒 Files selected for processing (4)
  • src/app/api/outly/intercept/route.ts
  • src/app/api/outly/outcome/route.ts
  • src/lib/covenant/outly-gate.ts
  • src/lib/covenant/outly-types.ts
📝 Walkthrough

Walkthrough

Adds three non-canonical Outly shadow-mode JSON Schemas and documentation covering schema boundaries, readiness evidence, implementation gaps, and unresolved pilot questions.

Changes

Outly shadow-mode preparation

Layer / File(s)Summary
Draft shadow-mode contracts
contracts/drafts/outly/*.schema.json, contracts/drafts/outly/README.md
Adds strict draft schemas for proposed actions, decisions, and action outcomes, with identifiers, enums, timestamps, references, nested validation, and non-runtime disclaimers.
Readiness audit and boundary evidence
docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md
Documents the intended Outly/Veklom boundary, observed request path, runtime-authority conflicts, simulated behavior, validation results, readiness gaps, and a proposed implementation packet.
Shadow-mode discovery questions
docs/outly/OUTLY-OPEN-QUESTIONS.md
Lists unresolved questions for action selection, identity, retries, decisions, outcomes, evidence, audit, and pilot acceptance.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the docs-focused Outly shadow audit and deliverable preparation changes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1784560124-outly-shadow-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md`:
- Around line 45-55: Update the evidence questions in the “Evidence and audit”
section to explicitly address the required evidence-reference pair of
evidence_id and entry_hash, including whether Outly can provide and consume both
values and how cAPI verifies their binding to the associated action, decision,
and outcome.
- Around line 32-36: Update the open questions around DecisionV1 to explicitly
define consistency invariants between decision, modifications, and
human_review_required: specify when modifications must be empty or allowed, how
the HUMAN_REVIEW decision maps to human_review_required, and whether expired
decisions may be executed or must be rejected.
- Around line 26-28: Update the retry and replay questions around items 14–16 to
define stability and change semantics for action_id, execution_id, nonce, and
idempotency_key across retries. Explicitly specify the deduplication rule and
how already-seen correlation values are classified, covering both repeated
retries and duplicate outcomes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07e40fea-7544-4a4b-bad7-af3d20039686

📥 Commits

Reviewing files that changed from the base of the PR and between 5891406 and 41023dd.

📒 Files selected for processing (6)
  • contracts/drafts/outly/ActionOutcomeV1.schema.json
  • contracts/drafts/outly/DecisionV1.schema.json
  • contracts/drafts/outly/ProposedActionV1.schema.json
  • contracts/drafts/outly/README.md
  • docs/outly/OUTLY-OPEN-QUESTIONS.md
  • docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md

Comment on lines +26 to +28
14. How does Outly retry a proposal, and which idempotency key remains stable across retries?
15. What replay behavior should Outly expect for an already-seen nonce or idempotency key?
16. What should happen if Veklom is unavailable: fail open, fail closed, or continue in an explicitly marked audit-only mode?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Define retry identity across all correlation fields.

The draft schemas require action_id, execution_id, nonce, and idempotency_key, but these questions only cover action ID and idempotency-key stability. Specify which fields remain stable versus change per retry and the deduplication rule; otherwise retries may be misclassified as new executions or duplicate outcomes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 26 - 28, Update the retry
and replay questions around items 14–16 to define stability and change semantics
for action_id, execution_id, nonce, and idempotency_key across retries.
Explicitly specify the deduplication rule and how already-seen correlation
values are classified, covering both repeated retries and duplicate outcomes.

Comment on lines +32 to +36
17. What exactly should `MODIFY` mean to Outly: modify parameters, route to another capability, reduce scope, cap amount, change timing, or something else?
18. Can Outly consume a structured list of modifications, and which fields are safe to modify?
19. What does `HUMAN_REVIEW` mean operationally, and who is the reviewer?
20. Does `DENY` prevent Outly execution, or is the first pilot strictly observational?
21. For a lane-3 action, what CAPPO authorization artifact can Outly correlate to the decision?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Capture invariants between decision fields.

DecisionV1 requires decision, modifications, and human_review_required, but the questions do not define their consistency rules. Clarify whether modifications must be empty unless the decision is MODIFY, whether human_review_required must correspond to HUMAN_REVIEW, and how expired decisions affect execution.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 32 - 36, Update the open
questions around DecisionV1 to explicitly define consistency invariants between
decision, modifications, and human_review_required: specify when modifications
must be empty or allowed, how the HUMAN_REVIEW decision maps to
human_review_required, and whether expired decisions may be executed or must be
rejected.

Comment on lines +45 to +55
27. What evidence reference does Outly already create, if any, and can it be linked to the Veklom decision?

## Evidence and audit

28. Which decision, proposal, and outcome fields must be retained?
29. What audit retention, deletion, and data-residency requirements apply?
30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?
31. What should the system report when gnomledger is unavailable?
32. Which fields are confidential and must not be treated as merely base64-encoded?
33. Which parties may read decision and outcome evidence?
34. What evidence receipt or ledger hash format can Outly consume?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Make the evidence-reference contract explicit.

DecisionV1 and ActionOutcomeV1 require a non-null evidence reference to contain both evidence_id and entry_hash, while src/app/api/capi/v1/evidence/[id]/route.ts currently returns mocked evidence without entry_hash. Add an explicit question covering whether Outly can provide and consume this required pair, and how cAPI verifies its binding to the action, decision, and outcome.

🧰 Tools
🪛 LanguageTool

[grammar] ~51-~51: Ensure spelling is correct
Context: ...ply? 30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~52-~52: Ensure spelling is correct
Context: ... 31. What should the system report when gnomledger is unavailable? 32. Which fields are co...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 45 - 55, Update the evidence
questions in the “Evidence and audit” section to explicitly address the required
evidence-reference pair of evidence_id and entry_hash, including whether Outly
can provide and consume both values and how cAPI verifies their binding to the
associated action, decision, and outcome.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' docs: prepare Outly shadow audit deliverables by reprewindai-dev · Pull Request #16 · reprewindai-dev/cAPI · GitHub
Skip to content

docs: prepare Outly shadow audit deliverables - #16

Merged
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit
Jul 20, 2026
Merged

docs: prepare Outly shadow audit deliverables#16
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added draft schemas defining proposed Outly actions, decisions, and action outcomes.
    • Added validation for identifiers, decision statuses, timestamps, references, idempotency fields, and requested side effects.
  • Documentation

    • Added guidance clarifying that the schemas are non-canonical design artifacts and are not enabled at runtime.
    • Documented open questions, readiness findings, implementation gaps, and proposed requirements for future shadow-mode evaluation.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiReadyReadyPreview, CommentJul 20, 2026 7:29pm
veklom-id-59uwReadyReadyPreview, CommentJul 20, 2026 7:29pm

@coderabbitai

coderabbitaiBot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@reprewindai-dev, you've reached your PR review limit, so we couldn't start this review.

Next review available in:31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3d1c38b9-429c-48cc-94fb-ab13bfa7f577

📥 Commits

Reviewing files that changed from the base of the PR and between 41023dd and c4b14de.

📒 Files selected for processing (4)
  • src/app/api/outly/intercept/route.ts
  • src/app/api/outly/outcome/route.ts
  • src/lib/covenant/outly-gate.ts
  • src/lib/covenant/outly-types.ts
📝 Walkthrough

Walkthrough

Adds three non-canonical Outly shadow-mode JSON Schemas and documentation covering schema boundaries, readiness evidence, implementation gaps, and unresolved pilot questions.

Changes

Outly shadow-mode preparation

Layer / File(s)Summary
Draft shadow-mode contracts
contracts/drafts/outly/*.schema.json, contracts/drafts/outly/README.md
Adds strict draft schemas for proposed actions, decisions, and action outcomes, with identifiers, enums, timestamps, references, nested validation, and non-runtime disclaimers.
Readiness audit and boundary evidence
docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md
Documents the intended Outly/Veklom boundary, observed request path, runtime-authority conflicts, simulated behavior, validation results, readiness gaps, and a proposed implementation packet.
Shadow-mode discovery questions
docs/outly/OUTLY-OPEN-QUESTIONS.md
Lists unresolved questions for action selection, identity, retries, decisions, outcomes, evidence, audit, and pilot acceptance.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the docs-focused Outly shadow audit and deliverable preparation changes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1784560124-outly-shadow-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md`:
- Around line 45-55: Update the evidence questions in the “Evidence and audit”
section to explicitly address the required evidence-reference pair of
evidence_id and entry_hash, including whether Outly can provide and consume both
values and how cAPI verifies their binding to the associated action, decision,
and outcome.
- Around line 32-36: Update the open questions around DecisionV1 to explicitly
define consistency invariants between decision, modifications, and
human_review_required: specify when modifications must be empty or allowed, how
the HUMAN_REVIEW decision maps to human_review_required, and whether expired
decisions may be executed or must be rejected.
- Around line 26-28: Update the retry and replay questions around items 14–16 to
define stability and change semantics for action_id, execution_id, nonce, and
idempotency_key across retries. Explicitly specify the deduplication rule and
how already-seen correlation values are classified, covering both repeated
retries and duplicate outcomes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07e40fea-7544-4a4b-bad7-af3d20039686

📥 Commits

Reviewing files that changed from the base of the PR and between 5891406 and 41023dd.

📒 Files selected for processing (6)
  • contracts/drafts/outly/ActionOutcomeV1.schema.json
  • contracts/drafts/outly/DecisionV1.schema.json
  • contracts/drafts/outly/ProposedActionV1.schema.json
  • contracts/drafts/outly/README.md
  • docs/outly/OUTLY-OPEN-QUESTIONS.md
  • docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md

Comment on lines +26 to +28
14. How does Outly retry a proposal, and which idempotency key remains stable across retries?
15. What replay behavior should Outly expect for an already-seen nonce or idempotency key?
16. What should happen if Veklom is unavailable: fail open, fail closed, or continue in an explicitly marked audit-only mode?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Define retry identity across all correlation fields.

The draft schemas require action_id, execution_id, nonce, and idempotency_key, but these questions only cover action ID and idempotency-key stability. Specify which fields remain stable versus change per retry and the deduplication rule; otherwise retries may be misclassified as new executions or duplicate outcomes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 26 - 28, Update the retry
and replay questions around items 14–16 to define stability and change semantics
for action_id, execution_id, nonce, and idempotency_key across retries.
Explicitly specify the deduplication rule and how already-seen correlation
values are classified, covering both repeated retries and duplicate outcomes.

Comment on lines +32 to +36
17. What exactly should `MODIFY` mean to Outly: modify parameters, route to another capability, reduce scope, cap amount, change timing, or something else?
18. Can Outly consume a structured list of modifications, and which fields are safe to modify?
19. What does `HUMAN_REVIEW` mean operationally, and who is the reviewer?
20. Does `DENY` prevent Outly execution, or is the first pilot strictly observational?
21. For a lane-3 action, what CAPPO authorization artifact can Outly correlate to the decision?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Capture invariants between decision fields.

DecisionV1 requires decision, modifications, and human_review_required, but the questions do not define their consistency rules. Clarify whether modifications must be empty unless the decision is MODIFY, whether human_review_required must correspond to HUMAN_REVIEW, and how expired decisions affect execution.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 32 - 36, Update the open
questions around DecisionV1 to explicitly define consistency invariants between
decision, modifications, and human_review_required: specify when modifications
must be empty or allowed, how the HUMAN_REVIEW decision maps to
human_review_required, and whether expired decisions may be executed or must be
rejected.

Comment on lines +45 to +55
27. What evidence reference does Outly already create, if any, and can it be linked to the Veklom decision?

## Evidence and audit

28. Which decision, proposal, and outcome fields must be retained?
29. What audit retention, deletion, and data-residency requirements apply?
30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?
31. What should the system report when gnomledger is unavailable?
32. Which fields are confidential and must not be treated as merely base64-encoded?
33. Which parties may read decision and outcome evidence?
34. What evidence receipt or ledger hash format can Outly consume?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Make the evidence-reference contract explicit.

DecisionV1 and ActionOutcomeV1 require a non-null evidence reference to contain both evidence_id and entry_hash, while src/app/api/capi/v1/evidence/[id]/route.ts currently returns mocked evidence without entry_hash. Add an explicit question covering whether Outly can provide and consume this required pair, and how cAPI verifies its binding to the action, decision, and outcome.

🧰 Tools
🪛 LanguageTool

[grammar] ~51-~51: Ensure spelling is correct
Context: ...ply? 30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~52-~52: Ensure spelling is correct
Context: ... 31. What should the system report when gnomledger is unavailable? 32. Which fields are co...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 45 - 55, Update the evidence
questions in the “Evidence and audit” section to explicitly address the required
evidence-reference pair of evidence_id and entry_hash, including whether Outly
can provide and consume both values and how cAPI verifies their binding to the
associated action, decision, and outcome.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' docs: prepare Outly shadow audit deliverables by reprewindai-dev · Pull Request #16 · reprewindai-dev/cAPI · GitHub
Skip to content

docs: prepare Outly shadow audit deliverables - #16

Merged
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit
Jul 20, 2026
Merged

docs: prepare Outly shadow audit deliverables#16
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added draft schemas defining proposed Outly actions, decisions, and action outcomes.
    • Added validation for identifiers, decision statuses, timestamps, references, idempotency fields, and requested side effects.
  • Documentation

    • Added guidance clarifying that the schemas are non-canonical design artifacts and are not enabled at runtime.
    • Documented open questions, readiness findings, implementation gaps, and proposed requirements for future shadow-mode evaluation.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiReadyReadyPreview, CommentJul 20, 2026 7:29pm
veklom-id-59uwReadyReadyPreview, CommentJul 20, 2026 7:29pm

@coderabbitai

coderabbitaiBot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@reprewindai-dev, you've reached your PR review limit, so we couldn't start this review.

Next review available in:31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3d1c38b9-429c-48cc-94fb-ab13bfa7f577

📥 Commits

Reviewing files that changed from the base of the PR and between 41023dd and c4b14de.

📒 Files selected for processing (4)
  • src/app/api/outly/intercept/route.ts
  • src/app/api/outly/outcome/route.ts
  • src/lib/covenant/outly-gate.ts
  • src/lib/covenant/outly-types.ts
📝 Walkthrough

Walkthrough

Adds three non-canonical Outly shadow-mode JSON Schemas and documentation covering schema boundaries, readiness evidence, implementation gaps, and unresolved pilot questions.

Changes

Outly shadow-mode preparation

Layer / File(s)Summary
Draft shadow-mode contracts
contracts/drafts/outly/*.schema.json, contracts/drafts/outly/README.md
Adds strict draft schemas for proposed actions, decisions, and action outcomes, with identifiers, enums, timestamps, references, nested validation, and non-runtime disclaimers.
Readiness audit and boundary evidence
docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md
Documents the intended Outly/Veklom boundary, observed request path, runtime-authority conflicts, simulated behavior, validation results, readiness gaps, and a proposed implementation packet.
Shadow-mode discovery questions
docs/outly/OUTLY-OPEN-QUESTIONS.md
Lists unresolved questions for action selection, identity, retries, decisions, outcomes, evidence, audit, and pilot acceptance.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the docs-focused Outly shadow audit and deliverable preparation changes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1784560124-outly-shadow-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md`:
- Around line 45-55: Update the evidence questions in the “Evidence and audit”
section to explicitly address the required evidence-reference pair of
evidence_id and entry_hash, including whether Outly can provide and consume both
values and how cAPI verifies their binding to the associated action, decision,
and outcome.
- Around line 32-36: Update the open questions around DecisionV1 to explicitly
define consistency invariants between decision, modifications, and
human_review_required: specify when modifications must be empty or allowed, how
the HUMAN_REVIEW decision maps to human_review_required, and whether expired
decisions may be executed or must be rejected.
- Around line 26-28: Update the retry and replay questions around items 14–16 to
define stability and change semantics for action_id, execution_id, nonce, and
idempotency_key across retries. Explicitly specify the deduplication rule and
how already-seen correlation values are classified, covering both repeated
retries and duplicate outcomes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07e40fea-7544-4a4b-bad7-af3d20039686

📥 Commits

Reviewing files that changed from the base of the PR and between 5891406 and 41023dd.

📒 Files selected for processing (6)
  • contracts/drafts/outly/ActionOutcomeV1.schema.json
  • contracts/drafts/outly/DecisionV1.schema.json
  • contracts/drafts/outly/ProposedActionV1.schema.json
  • contracts/drafts/outly/README.md
  • docs/outly/OUTLY-OPEN-QUESTIONS.md
  • docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md

Comment on lines +26 to +28
14. How does Outly retry a proposal, and which idempotency key remains stable across retries?
15. What replay behavior should Outly expect for an already-seen nonce or idempotency key?
16. What should happen if Veklom is unavailable: fail open, fail closed, or continue in an explicitly marked audit-only mode?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Define retry identity across all correlation fields.

The draft schemas require action_id, execution_id, nonce, and idempotency_key, but these questions only cover action ID and idempotency-key stability. Specify which fields remain stable versus change per retry and the deduplication rule; otherwise retries may be misclassified as new executions or duplicate outcomes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 26 - 28, Update the retry
and replay questions around items 14–16 to define stability and change semantics
for action_id, execution_id, nonce, and idempotency_key across retries.
Explicitly specify the deduplication rule and how already-seen correlation
values are classified, covering both repeated retries and duplicate outcomes.

Comment on lines +32 to +36
17. What exactly should `MODIFY` mean to Outly: modify parameters, route to another capability, reduce scope, cap amount, change timing, or something else?
18. Can Outly consume a structured list of modifications, and which fields are safe to modify?
19. What does `HUMAN_REVIEW` mean operationally, and who is the reviewer?
20. Does `DENY` prevent Outly execution, or is the first pilot strictly observational?
21. For a lane-3 action, what CAPPO authorization artifact can Outly correlate to the decision?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Capture invariants between decision fields.

DecisionV1 requires decision, modifications, and human_review_required, but the questions do not define their consistency rules. Clarify whether modifications must be empty unless the decision is MODIFY, whether human_review_required must correspond to HUMAN_REVIEW, and how expired decisions affect execution.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 32 - 36, Update the open
questions around DecisionV1 to explicitly define consistency invariants between
decision, modifications, and human_review_required: specify when modifications
must be empty or allowed, how the HUMAN_REVIEW decision maps to
human_review_required, and whether expired decisions may be executed or must be
rejected.

Comment on lines +45 to +55
27. What evidence reference does Outly already create, if any, and can it be linked to the Veklom decision?

## Evidence and audit

28. Which decision, proposal, and outcome fields must be retained?
29. What audit retention, deletion, and data-residency requirements apply?
30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?
31. What should the system report when gnomledger is unavailable?
32. Which fields are confidential and must not be treated as merely base64-encoded?
33. Which parties may read decision and outcome evidence?
34. What evidence receipt or ledger hash format can Outly consume?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Make the evidence-reference contract explicit.

DecisionV1 and ActionOutcomeV1 require a non-null evidence reference to contain both evidence_id and entry_hash, while src/app/api/capi/v1/evidence/[id]/route.ts currently returns mocked evidence without entry_hash. Add an explicit question covering whether Outly can provide and consume this required pair, and how cAPI verifies its binding to the action, decision, and outcome.

🧰 Tools
🪛 LanguageTool

[grammar] ~51-~51: Ensure spelling is correct
Context: ...ply? 30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~52-~52: Ensure spelling is correct
Context: ... 31. What should the system report when gnomledger is unavailable? 32. Which fields are co...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 45 - 55, Update the evidence
questions in the “Evidence and audit” section to explicitly address the required
evidence-reference pair of evidence_id and entry_hash, including whether Outly
can provide and consume both values and how cAPI verifies their binding to the
associated action, decision, and outcome.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); docs: prepare Outly shadow audit deliverables by reprewindai-dev · Pull Request #16 · reprewindai-dev/cAPI · GitHub
Skip to content

docs: prepare Outly shadow audit deliverables - #16

Merged
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit
Jul 20, 2026
Merged

docs: prepare Outly shadow audit deliverables#16
reprewindai-dev merged 2 commits into
mainfrom
devin/1784560124-outly-shadow-audit

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Added draft schemas defining proposed Outly actions, decisions, and action outcomes.
    • Added validation for identifiers, decision statuses, timestamps, references, idempotency fields, and requested side effects.
  • Documentation

    • Added guidance clarifying that the schemas are non-canonical design artifacts and are not enabled at runtime.
    • Documented open questions, readiness findings, implementation gaps, and proposed requirements for future shadow-mode evaluation.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiReadyReadyPreview, CommentJul 20, 2026 7:29pm
veklom-id-59uwReadyReadyPreview, CommentJul 20, 2026 7:29pm

@coderabbitai

coderabbitaiBot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@reprewindai-dev, you've reached your PR review limit, so we couldn't start this review.

Next review available in:31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3d1c38b9-429c-48cc-94fb-ab13bfa7f577

📥 Commits

Reviewing files that changed from the base of the PR and between 41023dd and c4b14de.

📒 Files selected for processing (4)
  • src/app/api/outly/intercept/route.ts
  • src/app/api/outly/outcome/route.ts
  • src/lib/covenant/outly-gate.ts
  • src/lib/covenant/outly-types.ts
📝 Walkthrough

Walkthrough

Adds three non-canonical Outly shadow-mode JSON Schemas and documentation covering schema boundaries, readiness evidence, implementation gaps, and unresolved pilot questions.

Changes

Outly shadow-mode preparation

Layer / File(s)Summary
Draft shadow-mode contracts
contracts/drafts/outly/*.schema.json, contracts/drafts/outly/README.md
Adds strict draft schemas for proposed actions, decisions, and action outcomes, with identifiers, enums, timestamps, references, nested validation, and non-runtime disclaimers.
Readiness audit and boundary evidence
docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md
Documents the intended Outly/Veklom boundary, observed request path, runtime-authority conflicts, simulated behavior, validation results, readiness gaps, and a proposed implementation packet.
Shadow-mode discovery questions
docs/outly/OUTLY-OPEN-QUESTIONS.md
Lists unresolved questions for action selection, identity, retries, decisions, outcomes, evidence, audit, and pilot acceptance.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title matches the docs-focused Outly shadow audit and deliverable preparation changes.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1784560124-outly-shadow-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md`:
- Around line 45-55: Update the evidence questions in the “Evidence and audit”
section to explicitly address the required evidence-reference pair of
evidence_id and entry_hash, including whether Outly can provide and consume both
values and how cAPI verifies their binding to the associated action, decision,
and outcome.
- Around line 32-36: Update the open questions around DecisionV1 to explicitly
define consistency invariants between decision, modifications, and
human_review_required: specify when modifications must be empty or allowed, how
the HUMAN_REVIEW decision maps to human_review_required, and whether expired
decisions may be executed or must be rejected.
- Around line 26-28: Update the retry and replay questions around items 14–16 to
define stability and change semantics for action_id, execution_id, nonce, and
idempotency_key across retries. Explicitly specify the deduplication rule and
how already-seen correlation values are classified, covering both repeated
retries and duplicate outcomes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07e40fea-7544-4a4b-bad7-af3d20039686

📥 Commits

Reviewing files that changed from the base of the PR and between 5891406 and 41023dd.

📒 Files selected for processing (6)
  • contracts/drafts/outly/ActionOutcomeV1.schema.json
  • contracts/drafts/outly/DecisionV1.schema.json
  • contracts/drafts/outly/ProposedActionV1.schema.json
  • contracts/drafts/outly/README.md
  • docs/outly/OUTLY-OPEN-QUESTIONS.md
  • docs/outly/OUTLY-SHADOW-MODE-READINESS-AUDIT.md

Comment on lines +26 to +28
14. How does Outly retry a proposal, and which idempotency key remains stable across retries?
15. What replay behavior should Outly expect for an already-seen nonce or idempotency key?
16. What should happen if Veklom is unavailable: fail open, fail closed, or continue in an explicitly marked audit-only mode?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Define retry identity across all correlation fields.

The draft schemas require action_id, execution_id, nonce, and idempotency_key, but these questions only cover action ID and idempotency-key stability. Specify which fields remain stable versus change per retry and the deduplication rule; otherwise retries may be misclassified as new executions or duplicate outcomes.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 26 - 28, Update the retry
and replay questions around items 14–16 to define stability and change semantics
for action_id, execution_id, nonce, and idempotency_key across retries.
Explicitly specify the deduplication rule and how already-seen correlation
values are classified, covering both repeated retries and duplicate outcomes.

Comment on lines +32 to +36
17. What exactly should `MODIFY` mean to Outly: modify parameters, route to another capability, reduce scope, cap amount, change timing, or something else?
18. Can Outly consume a structured list of modifications, and which fields are safe to modify?
19. What does `HUMAN_REVIEW` mean operationally, and who is the reviewer?
20. Does `DENY` prevent Outly execution, or is the first pilot strictly observational?
21. For a lane-3 action, what CAPPO authorization artifact can Outly correlate to the decision?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Capture invariants between decision fields.

DecisionV1 requires decision, modifications, and human_review_required, but the questions do not define their consistency rules. Clarify whether modifications must be empty unless the decision is MODIFY, whether human_review_required must correspond to HUMAN_REVIEW, and how expired decisions affect execution.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 32 - 36, Update the open
questions around DecisionV1 to explicitly define consistency invariants between
decision, modifications, and human_review_required: specify when modifications
must be empty or allowed, how the HUMAN_REVIEW decision maps to
human_review_required, and whether expired decisions may be executed or must be
rejected.

Comment on lines +45 to +55
27. What evidence reference does Outly already create, if any, and can it be linked to the Veklom decision?

## Evidence and audit

28. Which decision, proposal, and outcome fields must be retained?
29. What audit retention, deletion, and data-residency requirements apply?
30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?
31. What should the system report when gnomledger is unavailable?
32. Which fields are confidential and must not be treated as merely base64-encoded?
33. Which parties may read decision and outcome evidence?
34. What evidence receipt or ledger hash format can Outly consume?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Make the evidence-reference contract explicit.

DecisionV1 and ActionOutcomeV1 require a non-null evidence reference to contain both evidence_id and entry_hash, while src/app/api/capi/v1/evidence/[id]/route.ts currently returns mocked evidence without entry_hash. Add an explicit question covering whether Outly can provide and consume this required pair, and how cAPI verifies its binding to the action, decision, and outcome.

🧰 Tools
🪛 LanguageTool

[grammar] ~51-~51: Ensure spelling is correct
Context: ...ply? 30. Should evidence be anchored to gnomledger synchronously, asynchronously, or both?...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~52-~52: Ensure spelling is correct
Context: ... 31. What should the system report when gnomledger is unavailable? 32. Which fields are co...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/outly/OUTLY-OPEN-QUESTIONS.md` around lines 45 - 55, Update the evidence
questions in the “Evidence and audit” section to explicitly address the required
evidence-reference pair of evidence_id and entry_hash, including whether Outly
can provide and consume both values and how cAPI verifies their binding to the
associated action, decision, and outcome.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator