gstack/review
Abhijeet Mahagaonkar f7bde4391d feat: add stakeholder lens layer V0.5 (opt-in via --lens)
Ships an opt-in stakeholder-lens layer on /review that runs after the
technical Review Army completes. Zero --lens = zero behavior change.

Core framing: a lens is a loss function, an evidence model, a
materiality threshold, and an escalation policy applied to a bounded
evidence set. Not stakeholder impersonation.

Two lenses in this release:
- insider-abuse (READY) — legitimate authority converted to unauthorized
  outcome without attribution, detection, or approval
- enterprise-readiness (DRAFT) — deployability under CISO / procurement /
  operations governance; ships as DRAFT pending its own Go/No-Go eval

Four additional lens specifications ship in DRAFT / DEFERRED status for
future evaluation: incentive-abuse, regulatory-defensibility,
investor-diligence, competitive-durability.

Design guarantees:
- Preserves Review Army unchanged (P1); no touching of review-army.ts,
  review/specialists/, or review/checklist.md
- Independent lens dispatch (Stage A, no tech findings) followed by
  deterministic reconciliation (Stage B) — clean incremental-value
  measurement
- CTO synthesis as a third stage (not another lens): identifies shared
  technical primitives across independently derived lens findings
  without collapsing distinct perspectives
- Evidence clustering (SHARED_EVIDENCE / MULTI_LENS / EVIDENCE_CLUSTER)
  replaces cross-lens 'confirmation'; production exact-match misses are
  not marked NOVEL
- Read-only tool boundary; lens subagents receive a bounded evidence
  bundle, never repository browse tools
- All stakeholder findings default to ASK / INVESTIGATE; autofix_policy
  ask_always on every lens (no stakeholder auto-fix)
- Append-only event log at ~/.gstack/projects/<slug>/lens-events.jsonl
  with stable finding IDs; sensitive-data controls (local-only,
  owner-only permissions, secret-scanned, GBrain opt-in only)
- Per-lens regression harness (9 fixture types per lens) and per-lens
  Go/No-Go criteria for lens graduation to READY

Insider-abuse ships as the Phase 1 validation lens. Enterprise-readiness
remains DRAFT until its own evaluation gate runs. No Phase 1 lens is
claimed as empirically validated in this PR — validation happens
post-merge per REVIEW_LENSES_V0.md Go/No-Go criteria.

Includes:
- review/lenses/{shared-behavior, registry, insider-abuse, enterprise-readiness,
  incentive-abuse, regulatory-defensibility, investor-diligence,
  competitive-durability}.md
- scripts/lenses/{bundle, events, parser, reconcile, registry, routing,
  synthesis, types, yaml-subset, index}.ts
- scripts/resolvers/lens-layer.ts + gen-skill-docs wiring in
  scripts/gen-skill-docs.ts and scripts/resolvers/index.ts
- bin/gstack-lens-{bundle, event, parse, reconcile, registry, route,
  stats, synthesis-validate}
- hosts/claude/agents/{gstack-cto-synthesizer, gstack-lens-output-validator,
  gstack-lens-reviewer}.md
- test/fixtures/lens-regression/{insider-abuse, enterprise-readiness}/cases.json
- test/lens-{registry, bundle, events, layer-resolver, regression-fixtures}.test.ts
- docs/designs/REVIEW_LENSES_V0.md + docs/{product-context, lens-policy}.yaml.example
- setup and bin/gstack-uninstall wired for lens artifacts
2026-07-31 03:17:44 -07:00
..
lenses feat: add stakeholder lens layer V0.5 (opt-in via --lens) 2026-07-31 03:17:44 -07:00
specialists
…
SKILL.md feat: add stakeholder lens layer V0.5 (opt-in via --lens) 2026-07-31 03:17:44 -07:00
SKILL.md.tmpl feat: add stakeholder lens layer V0.5 (opt-in via --lens) 2026-07-31 03:17:44 -07:00
TODOS-format.md v1.57.5.0 feat: cross-session decision memory + gbrain dream-stage call graph (#1910) 2026-06-08 06:20:58 -07:00
checklist.md
…
design-checklist.md
…
greptile-triage.md
…