KB-3B19

Auto-Detection Coverage Matrix — Tool-Kiem-Thu Objects (2026-06-10)

5 min read Revision 1
tool-kiem-thugovernanceauto-detectioncoverage-matrixbirth-registry2026-06-10

Auto-Detection Coverage Matrix — Tool-Kiem-Thu Objects

Date: 2026-06-10. Per-object answer to: should the native auto-birth/governance system detect it, did it, where, with what label/lifecycle/owner/authority/timestamp, verdict. Evidence: see auto-birth-governance-system-audit-tool-kiem-thu-objects-2026-06-10.md (first-hand query_pg probes). DETECTED column values: NO (no path), PARTIAL (BORN-UNCERTIFIED), N/A.

Object (TKT-OBJ) Should detect Detected Where Label/species Lifecycle/status Owner Authority lvl Timestamp evidence Verdict / root cause
001 ip_dot_inspector Yes NO birth_registry=0 ORPHAN · DISCOVERY_GAP+TAXONOMY_GAP
002 build_guard.py No (build-time) NO ORPHAN (acceptable; build accessory)
003 inspector/main.py No NO ORPHAN (acceptable)
004 b7_validate.py No NO local /tmp ORPHAN · local-last evidence
005 test_acceptance.py No NO ORPHAN (acceptable)
006/007 seccomp profiles Yes NO ORPHAN · TAXONOMY_GAP
008 docker-run L1 boundary No NO ORPHAN (config)
009 Dockerfiles Yes NO ORPHAN · TAXONOMY_GAP
010 image digest No (ephemeral) NO N/A ephemeral
011 repo tool-kiem-thu-ci Yes NO birth_registry=0 ORPHAN · DISCOVERY_GAP (no GitHub sensor)
012/013 CI workflows No NO ORPHAN (in-repo accessory)
014 runner venue No (ephemeral) NO N/A ephemeral
015 CI run artifacts No (auto-expire) NO N/A 30d retention
016 packet PKT-B7-REF-… Conditional NO (file) would be context_pack_manifest if stored manifest ORPHAN as file · REGISTRY_GAP; native precedent exists
017 fix7 fixtures No NO ORPHAN (test accessory)
018 6 NQ-*-V1 catalog Conditional NO would be dot_iu_command_catalog if stored command provisional ORPHAN · REGISTRY_GAP (no governed named-query home, B7-EXP-1)
019–024 B7 schema/contracts (KB docs) Yes (as KB docs) PARTIAL knowledge_documents if synced ai_support born null provisional/design rows 8002–8009 @2026-06-10 02:45–02:49 (binding UNVERIFIED) BORN-UNCERTIFIED · OWNER/LIFECYCLE/RELATIONSHIP_GAP
025–035 evidence/report/checkpoint KB docs Yes PARTIAL knowledge_documents if synced ai_support born null evidence-only same BORN-UNCERTIFIED · same gaps
036 new species Yes NO not in entity_species ORPHAN · TAXONOMY_GAP
037 new statuses Yes NO ORPHAN · LABEL_SCHEMA_GAP
038 new authority classes Yes NO ORPHAN · LABEL_SCHEMA_GAP
039 new blocker classes No (KB concept) NO ORPHAN (KB-governed)
040 Phase 3.5 roadmap No (KB concept) NO KB-governed by this macro
041 this macro's 15 deliverables Yes (as KB docs) PARTIAL knowledge_documents if synced ai_support born null KB-governance future BORN-UNCERTIFIED — same gap they document (self-referential)

Coverage rollup

  • Objects that SHOULD be auto-governed and are FULLY governed: 0.
  • Objects auto-detected PARTIAL (BORN-UNCERTIFIED, KB docs only): the markdown/JSON deliverables, if and only if ingested into the Directus knowledge_documents collection; binding to specific docs is UNVERIFIED (address NULL).
  • Objects with NO native detection path: all external/runtime/file objects (tool, repo, seccomp, Dockerfiles, packet file, named-query catalog, fixtures, new taxonomy).
  • Net native auto-governance coverage for this project: effectively 0% governed; ≤ a degraded "born-uncertified" count for KB docs only.
  • All gaps carried into the root-cause blocker packet action-ready-blocker-auto-birth-governance-gaps-2026-06-10.md.
Back to Knowledge Hub knowledge/dev/laws/tool-kiem-thu/governance/auto-detection-coverage-matrix-tool-kiem-thu-objects-2026-06-10.md