Add an append-only ledger of entitlement set rule changes with per-pool effect rows, a preview-and-commit rule change flow, and an automatic drain that settles deferred recomputations. Rules gain a tier reduction policy, resource keys declare over-limit behavior, and the materializer now lowers limits when a rule stops applying. Add entitlement set rule change ledger and preview flow Add an append-only ledger of entitlement set rule changes with a preview-and-commit operator flow. Rule writes now go through an enclosed `core.commit_rule_change` function that files an act row and one obligation per carrying pool, with a drain workflow settling deferred recomputations. The preview dry-runs the materializer with a rule overlay and renders per-pool buckets, reduction-policy disclosures, and provider over-limit consequences. Materializing transactions take a shared advisory rendezvous that rule changes hold exclusively, enforced by a possession assertion. Add History and Entitlement changes surfaces, a rule-less warning on five product-selection surfaces, and a `tier_reduction_policy` column that gates FedWiki parking.
Provisioning Module
The provisioning module orchestrates first-login auto-provisioning. When a user authenticates via OIDC for the first time, AutoProvision creates all governance and resource structures within a single database transaction:
- User — identity record linked to the OIDC subject
- Person — profile record (display name, email)
- Organization — personal org (
org_type = 'personal') - OrgMember — membership with the
ownersystem role - Workspace — default workspace within the org
- Role Assignment — org-scoped role assignment for the owner
- Resource Pool — default pool (
pool_type = 'default',is_auto_managed = true) - Pool Assignment — primary link between workspace and pool (
is_primary = true)
If any step fails, the entire transaction rolls back — no partial structures exist.