Bilko HR Autopilot G1-01 — Unified Document Gateway (MC #106851)

Bilko HR Autopilot G1-01 — Unified Document Gateway

MC: #106851
Status: Implemented and independently reviewed; pending postflight, authenticated Azure target-drift adjudication, commit, and PR. Not deployed.
Related: Gate 1 implementation plan (BookStack page 3338), G1-02 upload-security boundary (#106852), and separately owned purchase_invoices convergence (#106632).

Purpose

G1-01 establishes one canonical, tenant-scoped document identity for every currently supported authenticated stored upload. It extends the existing inbox_items lineage rather than creating another document model.

Supported stored-upload surfaces:

Each accepted upload creates exactly one canonical inbox_items row containing organization, exact-byte SHA-256, web_upload source, receipt timestamp, storage identity, uploader, and the G1-02 RELEASED scan provenance.

Security and persistence boundaries

Database guarantees

V154 and V155 enforce:

V155 intentionally fails closed if historical lineage is orphaned, cross-organization, or has multiple direct parents. Production preflight and explicit adjudication are mandatory; the migration does not silently delete or reassign lineage.

Verification

The reviewed uncommitted patch has SHA-256:

f51e9eeffef4a0e2d3321848f1c2f36b6c1181398d13bb4c93613e81d1f38352

Authoritative isolated Docker/JDK 21 validation executed 11 migration, service, and HTTP suites:

The Bilko OCR domain owner, independent Proveo reviewer, and Securion security reviewer each returned PASS for that exact patch, with zero P0/P1 findings.

Explicit non-claims and remaining gates

This work does not:

A deployed configuration is documented as using bilko_admin, which has BYPASSRLS. Schema/RLS policy tests therefore do not establish production runtime-role conformance. Production RLS readiness remains NO-GO until that role boundary is independently evidenced and adjudicated.

Before PR creation, Azure DevOps main must be refreshed through authenticated access and any target drift must be adjudicated. Integration remains Azure-PR-only with no direct main push or policy bypass.


Revision #2
Created 2026-08-06 21:35:05 UTC by John
Updated 2026-08-10 07:38:08 UTC by John