Files
ThothII/docs/superpowers/plans/2026-08-20-psd-survey-remediation-checklist.md
T

121 lines
5.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# PSD Survey Remediation Checklist Implementation Plan
> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking.
**Goal:** Create one versioned, secret-free operational checklist for discussing and closing the ten PSD survey blockers one at a time.
**Architecture:** A single Markdown document under `docs/operations/` owns the current activity, resume marker, status summary, per-activity discussion record, and final re-survey gate. Protected evidence remains outside Git and is referenced only by path, digest, timestamp, or sanitized result.
**Tech Stack:** Markdown, Git, `rg`, repository documentation checks.
**Spec:** `docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md`
## Global Constraints
- Create only `docs/operations/psd-server-survey-remediation-checklist.md`.
- Use only `PENDING`, `IN_DISCUSSION`, `BLOCKED`, and `PASS` as activity states.
- Set Activity 1 to `IN_DISCUSSION`; set Activities 2–10 to `PENDING`.
- Keep `SURVEY_NO_GO` and prohibit Project A/B until their documented gates pass.
- Never include passwords, tokens, cookies, private keys, connection strings, raw claims, or realistic secret examples.
- Keep the legacy stack running and unchanged; this plan performs documentation work only.
---
### Task 1: Create and verify the resumable operational checklist
**Files:**
- Read: `docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md`
- Read: `docs/operations/psd-server-sol-orchestration-prompt.md`
- Create: `docs/operations/psd-server-survey-remediation-checklist.md`
**Interfaces:**
- Consumes: the approved activity order, safety rules, status vocabulary, and resume contract from the design.
- Produces: the single operational document used by later sessions to select and discuss exactly one activity.
- [ ] **Step 1: Confirm the documentation baseline**
Run:
```bash
git status --short --branch
test -f docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md
test -f docs/operations/psd-server-sol-orchestration-prompt.md
```
Expected: the two source documents exist and no unrelated uncommitted changes overlap the target.
- [ ] **Step 2: Create the checklist with the fixed initial state**
Create `docs/operations/psd-server-survey-remediation-checklist.md` with these top-level sections in order:
1. `Purpose and authority`
2. `Program gate`
3. `Current activity and resume point`
4. `How to use this checklist`
5. `Activity summary`
6. `Activity 1` through `Activity 10`
7. `Fresh survey and owner gate`
8. `Change log`
Set the initial fields to:
```text
Program result: SURVEY_NO_GO
Current activity: 1 — Rotate or revoke the exposed DWH credential safely
Resume from: Activity 1, identify the accountable credential owner and the credential type without revealing its value
```
Each activity section must contain exactly these fields:
```text
Status
Accountable owner
Objective
Why this is required
Ordered actions
Required redacted evidence
Discussion notes
Decision
Blockers
Next step
```
Use factual initial values such as `Unassigned`, `Not discussed`, and `No decision recorded`; do not use ambiguous filler markers.
- [ ] **Step 3: Verify structure, initial state, and safety gates**
Run:
```bash
test "$(rg -c '^## Activity [0-9]+:' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 10
test "$(rg -c 'Status: `IN_DISCUSSION`' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 1
test "$(rg -c 'Status: `PENDING`' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 9
rg -n --fixed-strings 'Program result: `SURVEY_NO_GO`' docs/operations/psd-server-survey-remediation-checklist.md
rg -n --fixed-strings 'Current activity: `1`' docs/operations/psd-server-survey-remediation-checklist.md
rg -n --fixed-strings 'Project A remains forbidden' docs/operations/psd-server-survey-remediation-checklist.md
rg -n --fixed-strings 'Project B remains forbidden' docs/operations/psd-server-survey-remediation-checklist.md
if rg -n '\b(TB[D]|TO[D]O)\b|<[^>]+>' docs/operations/psd-server-survey-remediation-checklist.md; then exit 1; fi
git diff --check
```
Expected: ten activities, one current discussion, nine pending activities, all gates present, no filler markers, and a clean Markdown diff.
- [ ] **Step 4: Perform a count-only secret-pattern check**
Run a scan that treats ripgrep exit `0` as failure, exit `1` as no match, and any other exit as a scanner error. Check for private-key headers, bearer-shaped values, and credential assignments with non-whitespace values of eight or more characters. Do not print matching content.
Expected: `secret-pattern-scan=PASS`.
- [ ] **Step 5: Review and commit only the checklist**
Run:
```bash
git diff -- docs/operations/psd-server-survey-remediation-checklist.md
git add docs/operations/psd-server-survey-remediation-checklist.md
git diff --cached --check
git commit -m "docs: add PSD survey remediation checklist"
```
Expected: one committed operational document; no server, configuration, evidence, or secret file changed.