The targeted edits in the previous commit left the document
self-contradictory in places. This reconciles it.
- The stale-export rule contradicted the append-only invariant on
PayrollExport. Staleness is now derived from
PayPeriod.unlockedAt rather than written as a flag, and the
period gains unlockedAt/unlockedBy to support it.
- Invariant count was still seven after an eighth was added.
- Lot references were a mix of the old Lot 0-4 numbering and the
current WP-xx packages; all now use WP-xx.
- Articles/conversations were said to be deferred to "lot 5" while
HR analytics were wrongly listed as deferred too.
- Section 1 now carries all five audit findings, including the
non-terminal pay-period lock and the closed enumerations.
Adds the matching tests: the unlock/re-export cycle, cross-view
consistency, mutation refusal while locked, and CSP enforcement.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
The dropdown audit enumerates values the earlier spec had guessed.
Replaces the guesses with the observed lists and adds what they imply.
- Roles: five, not the six invented ones (owner, admin, director,
manager, employee).
- Contract types: nine observed values, including the two dirigeant
types that were missing; professionnalisation was never observed and
is dropped.
- Planning has five views, not three: month and presence/absence were
missing. All five read one model.
- Pay periods can be unlocked, and deleted while locked. Locking is
therefore not terminal: re-locking recomputes snapshots, so exports
from a since-unlocked period must be flagged stale or a file sent to
Silae silently stops matching the data.
- Absence types carry a social-security flag; incomplete-profile
filtering needs separate RUP and DPAE required-field sets.
- Document templates resolve variables per location.
Adds a telemetry invariant: the audit intercepted 2102 third-party
tracking requests and no business calls. An HR app must not leak
employee-context navigation to ad networks, so trackers are banned and
a restrictive CSP ships in WP-00 to make that testable.
Notes that the root dropdowns/ directory duplicates the copy under
Audit Combo/ byte for byte.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
Rewrites PLAN.md as a normative spec an orchestrator can build from
end to end, rather than a proposal.
Scope locked per owner decision: multi-location, Silae as the
downstream payroll system, no time clock. Timeclock entities are
dropped; actual hours are now manager-entered on the shift, with
planned hours authoritative when absent.
Adds the full Prisma schema, the permission catalogue, 17 compliance
rule codes, the leave ledger contract, the Silae CSV format
(UTF-8, semicolon, HS-/AB-/EV- prefixes), the route inventory, and
12 work packages with testable acceptance criteria.
Collective-agreement values and Silae rubric codes are declared stop
signals: the spec forbids inventing them and requires human input
before production.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
Rewrites the plan against the audit bundle rather than public docs.
Three findings changed the design:
- The audited account runs IDCC 1517 (commerces de detail non
alimentaires), not HCR. The rules engine seeds from that agreement.
- Authorization is capability-based with separate scopes, and roles are
customer-configurable, so Role/Permission/Scope are split from day one.
- Leave counters are a ledger of operations, not a stored balance.
Scope, stack and deployment are stated as assumptions pending
confirmation. Payroll stays export-only; DSN, eIDAS signature and DPAE
transmission are delegated.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
Screenshots, contact sheets, inventory and page-by-page audit notes
for the Combo HR platform, used as the reference for the PlanFlow
reimplementation. Personal data in the captures is blurred.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>