Ships an opt-in stakeholder-lens layer on /review that runs after the
technical Review Army completes. Zero --lens = zero behavior change.
Core framing: a lens is a loss function, an evidence model, a
materiality threshold, and an escalation policy applied to a bounded
evidence set. Not stakeholder impersonation.
Two lenses in this release:
- insider-abuse (READY) — legitimate authority converted to unauthorized
outcome without attribution, detection, or approval
- enterprise-readiness (DRAFT) — deployability under CISO / procurement /
operations governance; ships as DRAFT pending its own Go/No-Go eval
Four additional lens specifications ship in DRAFT / DEFERRED status for
future evaluation: incentive-abuse, regulatory-defensibility,
investor-diligence, competitive-durability.
Design guarantees:
- Preserves Review Army unchanged (P1); no touching of review-army.ts,
review/specialists/, or review/checklist.md
- Independent lens dispatch (Stage A, no tech findings) followed by
deterministic reconciliation (Stage B) — clean incremental-value
measurement
- CTO synthesis as a third stage (not another lens): identifies shared
technical primitives across independently derived lens findings
without collapsing distinct perspectives
- Evidence clustering (SHARED_EVIDENCE / MULTI_LENS / EVIDENCE_CLUSTER)
replaces cross-lens 'confirmation'; production exact-match misses are
not marked NOVEL
- Read-only tool boundary; lens subagents receive a bounded evidence
bundle, never repository browse tools
- All stakeholder findings default to ASK / INVESTIGATE; autofix_policy
ask_always on every lens (no stakeholder auto-fix)
- Append-only event log at ~/.gstack/projects/<slug>/lens-events.jsonl
with stable finding IDs; sensitive-data controls (local-only,
owner-only permissions, secret-scanned, GBrain opt-in only)
- Per-lens regression harness (9 fixture types per lens) and per-lens
Go/No-Go criteria for lens graduation to READY
Insider-abuse ships as the Phase 1 validation lens. Enterprise-readiness
remains DRAFT until its own evaluation gate runs. No Phase 1 lens is
claimed as empirically validated in this PR — validation happens
post-merge per REVIEW_LENSES_V0.md Go/No-Go criteria.
Includes:
- review/lenses/{shared-behavior, registry, insider-abuse, enterprise-readiness,
incentive-abuse, regulatory-defensibility, investor-diligence,
competitive-durability}.md
- scripts/lenses/{bundle, events, parser, reconcile, registry, routing,
synthesis, types, yaml-subset, index}.ts
- scripts/resolvers/lens-layer.ts + gen-skill-docs wiring in
scripts/gen-skill-docs.ts and scripts/resolvers/index.ts
- bin/gstack-lens-{bundle, event, parse, reconcile, registry, route,
stats, synthesis-validate}
- hosts/claude/agents/{gstack-cto-synthesizer, gstack-lens-output-validator,
gstack-lens-reviewer}.md
- test/fixtures/lens-regression/{insider-abuse, enterprise-readiness}/cases.json
- test/lens-{registry, bundle, events, layer-resolver, regression-fixtures}.test.ts
- docs/designs/REVIEW_LENSES_V0.md + docs/{product-context, lens-policy}.yaml.example
- setup and bin/gstack-uninstall wired for lens artifacts