Governance Library
Governance Library
Indexes controlled source assets — strategy, SOPs, decisions, process documents, and version history — without copying document bodies. Each record holds a source link, version, owner, classification, and disposition. Real inventory connects only after authenticated RLS and audit-logging gates pass.
Link / Index — Not Copy
The Governance Library does not duplicate document bodies. Controlled source assets live in their canonical locations — GitHub repositories and organization shared storage. This library stores metadata records that point to those sources: asset name, source link, version or commit SHA, classification, owner, review date, and disposition. Copying a document into the Portal creates an uncontrolled duplicate; linking preserves a single version history and a single source of truth.
Asset Record — Field Reference
| Field | Description | Value |
|---|---|---|
| Source Asset | Name or identifier of the controlled source document or repository object. | — |
| Source Link | Canonical URL or path to the asset in GitHub or organization shared storage. | — |
| Version / Commit | Version tag, commit SHA, or document version at time of indexing. | — |
| Classification / Sensitivity | Access tier: General, Restricted, or Confidential. | — |
| Owner | Role or individual responsible for the asset. | — |
| Review Date | Next scheduled review or last-reviewed date. | — |
| Disposition | Current disposition code: Link/Retain, Migrate, Archive, or Retire. | — |
No asset records are indexed in this prototype. Real inventory connects after authenticated RLS/audit validation passes and a controlled migration packet is approved.
Permissible Disposition Values
Asset remains in its canonical source (GitHub or shared storage). The Portal indexes metadata and a source link only — no document body is copied.
Governed metadata or workflow data will be migrated into a Portal record. The original source file is retained. Migration requires auth/RLS/audit gate approval.
Retained for provenance and version history. Excluded from active search, templates, and operating views. No operational use without founder approval.
Operational use disabled after founder approval and confirmed replacement. Asset record is preserved; it is never deleted from this register.
Source Posture & Access Model
GitHub
Canonical source for code, versioned migrations, and configuration. Portal records link commits and releases; source code stays in GitHub.
Organization shared storage
Canonical source for strategy, process, SOP, and decision documents. Portal indexes metadata and source links; document bodies are not copied.
Version history
Every indexed asset record should carry a version tag or commit SHA. Prior versions are preserved as version history, not overwritten.
RLS / future server authorization
Current navigation is static and for UI convenience only. Real access control for restricted and confidential assets requires RLS and future authenticated server authorization. Navigation alone is not a security boundary.
RLS & Authentication Status
Blocked by Supabase email rate limit. Password-recovery, unapproved-user, test-organization, audit-trigger, and cross-organization tests are required before any real or sensitive inventory is connected.
Nine public tables show RLS enabled; all tables empty; security advisor returned no findings as of 2026-08-06.
This static prototype is UI convenience only. Restricted and confidential assets require explicit grants enforced by RLS and future authenticated server authorization — not sidebar visibility alone.
Controlling Sources
intofocus_portal_build_control_and_migration_register_v0_1.md— defines build sequence, migration gates, and the link/index-not-copy rule.intofocus_portal_asset_disposition_register_v1_2026-08-05.md— asset-by-asset disposition inventory and migration controls.intofocus_portal_information_architecture_and_tenancy_v0_1.md— Portal organization, tenancy controls, role model, and navigation rules.intofocus_portal_now_next_later_v0_1.md— current Portal program status and decision log.
Source document bodies are not reproduced here. The filenames above are references only; they are stored in canonical shared storage and GitHub.