Skip to content

Add an organization-level /audits/ evidence and findings view #35

Description

@szmyty

Outcome

Add a first-class organization-level /audits/ module that presents audit coverage, freshness, findings posture, recurring patterns, and approved issue-materialization state across the fleet while preserving repository-owned reports as canonical evidence.

This is the fleet counterpart to egohygiene/relay#74 and a bounded child of #27 and #30.

Primary question

Which repositories have current, partial, stale, blocked, or missing audits; what confirmed patterns deserve attention; and where is the canonical report or accepted GitHub work?

Data and ownership

Consume egohygiene/observatory#20 snapshots produced from the Aether profile contract and Reflector execution evidence. Do not parse report prose in the browser or treat proposed findings as accepted backlog.

Required experience

  • Latest audit coverage by repository/profile with represented revision and freshness.
  • Explicit complete, partial, blocked, failed, stale, unavailable, unsupported, and never-audited states.
  • Separate confirmed/probable defects and risks, contract drift, maintainability opportunities, feature opportunities, experimental ideas, intentional trade-offs, positive observations, and needs-clarification.
  • Recurring cross-repository patterns with evidence links and affected-scope disclosure.
  • Organization audit campaign/run history and comparison without inferring resolution from silence.
  • Candidate-backlog state that distinguishes proposals, rejected/deferred candidates, and real GitHub issues.
  • Drill-down to repository /audits/, canonical reports, findings, represented commits, profiles, and linked issues.
  • Public/private visibility filtering before aggregation.

Acceptance criteria

  • A canonical organization /audits/ surface is registered through egohygiene/hygiene#25.
  • The module consumes Observatory program(releases): track organization-wide semantic release convention rollout #20 and accepted Aether schema versions.
  • Coverage, completion state, freshness, findings classification, recurring patterns, and candidate materialization state are visible.
  • Speculative feature/experimental opportunities cannot be confused with defects or organization-health failures.
  • Suggested issues cannot be confused with actual GitHub issues.
  • Comparison never infers resolution from absence.
  • Every aggregate preserves repository, represented revision, profile version, provenance, and canonical drill-down.
  • Public output cannot leak private repositories, findings, counts, or evidence.
  • Clean, finding-heavy, partial, stale, never-audited, incompatible, redacted, and campaign fixtures pass.
  • Mobile, keyboard, screen-reader, reduced-motion, no-color-only, and large-fleet behavior is verified.

Dependencies / related

Non-goals

  • Running audits or editing reports from the public page.
  • Automatically creating issues.
  • Treating all observations as accepted work.
  • Replacing repository reports or /audits/ pages.
  • A universal audit score.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions