Governance Surfaces Integration Plan

Unit: governance-surfaces-integration Status: Planning phase Relates to: Phase 2 (Surface control plane), Phase 5 (MORK review) Sketches: governance-and-versioning-migration.md Architecture: Surface workflow, MORK review workbench

Purpose

Transform fixture-backed UI shells (Surface Contract Studio, MORK Review Workbench) into production governance surfaces connected to control-plane APIs, ledger persistence, and role-based permission enforcement.

Current State

Scope: Three Slices

S1. Surface Contract Studio Backend Integration (Phase 2)

Goal: Studio connects to Surface control plane and displays real contracts from ledger

Deliverables:

S2. MORK Review Bench Permission Model (Phase 5)

Goal: Enforce role-based visibility and decision constraints

Deliverables:

S3. Evidence Projection and Snapshot State (Phase 5)

Goal: Display real evidence projections and persist decisions

Deliverables:

Testing Strategy

Level Description Ownership
L1 Unit: permission checks, evidence filter functions both apps
L3 Contract: Surface revision API roundtrip, review decision schema conformance both apps, use existing contract fixtures
L4 Component integration: Playwright against seeded ledger (Testcontainers PostgreSQL) Phase 2 and Phase 5 gates
L5 System E2E: full workflow (author → approve → generate / snapshot → decide → record) via compose stack Phase 2 and Phase 5 gates

Acceptance Criteria

Risks and Mitigations

Risk Mitigation
Ledger migration not deployed Explicitly gate this work on database migration in Phase 2 validation
API contract changes during integration Use exact version of surface-workflow.openapi.json at slice start; review changes explicitly
Race conditions in concurrent decision recording Implement optimistic concurrency per ADR-A33
Permission model too complex to test Create a small fixture corpus of role×action×expected pairs; test as a matrix, not prose

Success Metrics

Timeline