docs: add phased implementation plan and architecture decision records

Turns the design doc into an ordered, dependency-correct build plan (phases
0-9) with an exit criterion per phase, and records the twelve architectural
decisions it rests on as ADRs.

Decisions: single Rust binary with routed compose services; Streamable HTTP
only; per-agent bearer tokens with clientInfo as a display hint only; SQLite;
get_rules delivered via session gating; full-document rule delivery; project_id
from day one; enforcement tier scoped to Bridle-mediated actions; stable tool
list on upstream failure; OpenAI-compatible embeddings with model/dim guarding;
pattern RAG gated behind a spike; CLAUDE.md + AGENTS.md as v1 renderer targets.

Deviates from the design doc's original 1-8 ordering by moving the audit log
and multi-project schema into phase 1, building the admin API incrementally
rather than all at the Web Panel phase, downgrading vendor guardrail sourcing
to manual-first, and gating the pattern-example RAG behind a validation spike.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019RZerbsHGF9Ka3bKhCjJ9m
This commit is contained in:
2026-08-08 14:33:27 -05:00
parent 7fdde56560
commit 06917d43e2
13 changed files with 556 additions and 0 deletions

View File

@@ -0,0 +1,23 @@
# ADR-0007: `project_id` in the data model from day one
**Status:** Accepted (2026-08-08)
## Context
The design doc placed multi-project support in the final build phase. But `get_rules(project_id,
agent_type)` already carries a project identifier in its phase-1 signature, and retrofitting
multi-tenancy after five subsystems exist means migrating rules, audit, memory collections,
permissions, and the panel simultaneously.
## Decision
Every table and every tool signature carries **`project_id` from phase 1**. Memory collections are
namespaced per project (`<project>_sessions`). The Web Panel and CLI default to a single project so
the v1 user experience is unchanged.
## Consequences
- Near-zero upfront cost — the identifier was already in the API design.
- Phase 9 becomes exposing a project switcher rather than performing a cross-subsystem migration.
- Every query must be project-scoped from the start; a missing `WHERE project_id = ?` is a
correctness bug, so this belongs in the review checklist.