KB-5A69
Action-Ready Blocker — Auto-Birth/Governance Gaps (2026-06-10)
5 min read Revision 1
tool-kiem-thugovernanceaction-ready-blockerauto-birthroot-cause2026-06-10
Action-Ready Blocker Packet — Auto-Birth/Governance Gaps
Date: 2026-06-10. These blockers close the auto-system gaps found in auto-birth-governance-system-audit-…. Each is action-ready (exact next action + who). None is resolved by this macro (all require owner/governance-owner/Codex or a build that is prohibited here). None blocks Phase 5 (offline) or the controlled-pilot subject directly unless stated.
| ID | Object(s) | Missing governance fact | Root cause | Evidence | Why it matters | Exact next action | Who | Blocks |
|---|---|---|---|---|---|---|---|---|
| GOV-AB-1 | repo tool-kiem-thu-ci, ip_dot_inspector, seccomp, Dockerfiles |
No native sensor detects external (GitHub/OS-file) objects | DISCOVERY_GAP | birth_registry=0 for all; no GitHub/FS scanner |
External venue/tool stays invisible to governance | Decide whether to register a dot_tools/asset row manually OR accept "external, KB-governed only" with this record as the authority |
owner + governance-owner | Production governance completeness only |
| GOV-AB-2 | new species (offline-inspector-tool, ci-evidence-repo, sandbox-attestation-profile, governed-export-packet, etc.) | Not present in entity_species/species_collection_map |
TAXONOMY_GAP | first-hand probe: no matching species | Objects cannot be natively classified | Owner+governance-owner insert provisional species into entity_species + map (or extend context_pack_manifest species for packets) |
owner + governance-owner | Native classification of these species |
| GOV-AB-3 | new lifecycle statuses + authority classes | No native column governs provisional-non-authority/design-authority/evidence-only or richer lifecycle |
LABEL_SCHEMA_GAP | birth_registry.status = born/certified only |
Vocabulary can't be expressed natively | Extend governance label schema (or keep KB-level) under owner decision | owner + governance-owner | Native vocabulary expression |
| GOV-AB-4 | all tool-kiem-thu KB docs | Auto-birth into knowledge_documents lands certified=false, owner=null, canonical_address=null |
OWNER_GAP + LIFECYCLE_GAP + RELATIONSHIP_GAP | rows 8002–8009 @02:45–02:49 2026-06-10 | Docs are counted but not governed/traceable; can't bind row→doc | Add owner + certification + address backfill for knowledge_documents births (the inspect_*/certified flow) |
governance-owner / automation runtime | Governance (not counting) of KB docs |
| GOV-AB-5 | named-query catalog (NQ-*-V1) | No governed named-query registry surface | REGISTRY_GAP | provisional-non-authority | Catalog can't be cited as authority | Provide governed home + seal (= B7-EXP-1) | owner + Codex | Catalog-as-authority; B7 promotion |
| GOV-AB-6 | object-level ownership for ALL objects | governance_object_ownership is EMPTY (designed, not populated); One-Roof agencies draft |
AUTOMATION_RUNTIME_GAP + REGISTRY_GAP | 0 rows; agencies draft |
Object-level governance/orphan detection not yet live | Activate One-Roof governance-orphan/anarchic-object detectors + populate ownership | owner + governance program | Native object-level governance org-wide |
| GOV-AB-7 | this registry → production | KB record exists but no birth_registry/ownership row inserted |
PERMISSION_GAP (by design; read-only role) + REGISTRY_GAP | agent role read-only; prohibition on mutation | Production registry remains unaware | Owner authorizes a backfill that inserts the registry's objects into birth_registry/governance_object_ownership |
owner (authorize) + operator (run) | Production-registry awareness (BIRTH_GOVERNANCE_AUTHORITY_BLOCKER) |
Notes
- Article 14: every "did/did-not detect" claim above is backed by a first-hand probe or a cited native fact; no auto-system success is claimed without a row.
- Prohibited here and therefore deferred: any insertion into
birth_registry,entity_species,species_collection_map,governance_object_ownership,system_issues, or Directus. - These are governance-completeness blockers; the next safe build increment (Phase 4 Call Contract design) is not blocked by them.
Verdict
AUTO_GOVERNANCE_ROOT_CAUSE_BLOCKERS_RAISED — 7 root-caused, action-ready blockers; owners named; none silently deferred.