{
 "generated": "2026-10-09T13:44:03Z",
 "repo": "uncovertechtalent/machinebehavior.io",
 "closed_window_days": 30,
 "untriaged": 0,
 "issues": [
  {
   "n": 1,
   "title": "Docs tree at /inside/docs/",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: docs",
    "type: feature"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": null,
   "created": "2026-10-09T11:30:36Z",
   "updated": "2026-10-09T11:30:38Z",
   "closed": "2026-10-09T11:30:38Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/1",
   "body": "**What.** A Confluence-style documentation tree built from markdown: spaces, a page tree, breadcrumbs, child page lists, backlinks, labels and search.\n\n**Why.** The systems behind the sites were documented in scattered notes. One tree makes them readable in one place.\n\n**Done when.**\n- Engineering, Observability, Research, SRE Handbook and Standards and Compliance spaces are live\n- Pages from the knowledge vault carry a not-reviewed label\n\n**Shipped.** https://github.com/uncovertechtalent/machinebehavior.io/commit/0e4fe0a7b9782560e6fc19efa0b13e783fcab94a"
  },
  {
   "n": 2,
   "title": "Docs pages in the map of the work",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P2",
    "area: map",
    "type: feature"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": null,
   "created": "2026-10-09T11:30:41Z",
   "updated": "2026-10-09T11:30:43Z",
   "closed": "2026-10-09T11:30:43Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/2",
   "body": "**What.** The crawler adds every docs page to the map graph, with parent links and the page title as og:title.\n\n**Why.** One graph for everything published, so a reader or a model can walk from a claim to the reference page it rests on.\n\n**Done when.**\n- Docs pages are nodes in /map/graph.json\n- Sidebar navigation and hrefs inside code samples are not counted as links\n\n**Shipped.** https://github.com/uncovertechtalent/machinebehavior.io/commit/6d365b66c4ab2133730cbee6544110782b662b76"
  },
  {
   "n": 3,
   "title": "Inside and infrastructure in the menu on every page",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P2",
    "area: inside",
    "type: feature"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": null,
   "created": "2026-10-09T11:30:45Z",
   "updated": "2026-10-09T11:30:47Z",
   "closed": "2026-10-09T11:30:47Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/3",
   "body": "**What.** Add Inside and the infrastructure dashboards to the menu of every page: hand-written pages, the 404 page, the slips generator, the conformity page and the map header.\n\n**Why.** Inside and the dashboards were reachable only from a few pages.\n\n**Done when.**\n- Every page menu links /inside/ and /inside/#dashboards\n\n**Shipped.** https://github.com/uncovertechtalent/machinebehavior.io/commit/1f69a2e21e48b3c7f2a398f97ee532337ad5951f"
  },
  {
   "n": 4,
   "title": "No third-party requests on page load",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P0",
    "area: legal",
    "type: bug"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": "Phase 0: legal and leaks",
   "created": "2026-10-09T11:30:50Z",
   "updated": "2026-10-09T11:30:52Z",
   "closed": "2026-10-09T11:30:52Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/4",
   "body": "**What.** Serve the fonts and d3 from the site itself, and read the Inside deploy feed from a JSON file written by the deploy job. Add Open Graph tags to the reference pages.\n\n**Why.** Each request to a font or script server passes the visitor's IP address to that company. A German court found this unlawful for Google Fonts loaded without consent (LG München I, 3 O 17493/20).\n\n**Done when.**\n- Opening Inside, the map or a docs page sends no request to Google, a CDN or the GitHub API\n- The reference pages have og:image\n\n**Shipped.** https://github.com/uncovertechtalent/machinebehavior.io/commit/b4ba0eb433ced07dac37a0f47519cd73f627065e"
  },
  {
   "n": 5,
   "title": "Remove internal host details from the public dashboards",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P0",
    "area: security",
    "type: bug"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": "Phase 0: legal and leaks",
   "created": "2026-10-09T11:30:54Z",
   "updated": "2026-10-09T11:30:56Z",
   "closed": "2026-10-09T11:30:56Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/5",
   "body": "**What.** Remove a private network address from a panel description on the public deploys dashboard, and name the reverse proxy generically in the compose comments.\n\n**Why.** Public dashboards and a public repository should not describe the internal network.\n\n**Done when.**\n- The public dashboard endpoint no longer shows the address\n- The compose comments name no vendor\n\n**Shipped.** https://github.com/uncovertechtalent/agent-observability/commit/4f109a2 (dashboard) and https://github.com/uncovertechtalent/agent-observability/commit/f31897886b8ca0fcce05a8e0ee1b406f4ebe67a3 (compose comments)"
  },
  {
   "n": 6,
   "title": "SearXNG search engines dashboard on Inside",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P2",
    "area: observability",
    "area: search",
    "type: feature"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": null,
   "created": "2026-10-09T11:30:58Z",
   "updated": "2026-10-09T11:31:01Z",
   "closed": "2026-10-09T11:31:01Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/6",
   "body": "**What.** A public cut of the SearXNG dashboard, framed on Inside under the search tab, with an app tile and a page in the Observability docs.\n\n**Why.** Every research agent searches through the self-hosted SearXNG instance. Whether each engine answers is part of the platform's health.\n\n**Done when.**\n- The search tab on Inside shows the public dashboard\n- The Observability space documents it\n\n**Shipped.** https://github.com/uncovertechtalent/machinebehavior.io/commit/961f80b245da3d4d8d5d30f0055894a78f439529"
  },
  {
   "n": 7,
   "title": "FinOps space in the docs",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P2",
    "area: docs",
    "type: docs"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": null,
   "created": "2026-10-09T11:31:04Z",
   "updated": "2026-10-09T11:31:06Z",
   "closed": "2026-10-09T11:31:06Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/7",
   "body": "**What.** A FinOps space: cost model, unit economics, showback, budgets and alerts, an anomaly case and a FOCUS export of the metered usage.\n\n**Why.** What the platform costs and how it is metered belongs next to the systems that cost it.\n\n**Done when.**\n- The space is live with seven pages\n- The FOCUS export is a CSV next to the docs\n\n**Shipped.** https://github.com/uncovertechtalent/machinebehavior.io/commit/b43861a4447f2559eac7bd8d4db65a86e2047f41 and the follow-up https://github.com/uncovertechtalent/machinebehavior.io/commit/0bb01046a176c64b9edce83522ee29b28f9b9f8c"
  },
  {
   "n": 8,
   "title": "Ticket board at /inside/board/",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: inside",
    "type: feature"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:08Z",
   "updated": "2026-10-09T11:42:53Z",
   "closed": "2026-10-09T11:42:53Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/8",
   "body": "**What.** A Jira-style board of work items with GitHub Issues as the system of record. The deploy job writes a snapshot of the issues; the page reads that snapshot, so a visitor's browser never calls GitHub.\n\n**Why.** The backlog from the platform review sat in a private note. A public board makes it visible and keeps it current.\n\n**Done when.**\n- /inside/board/ shows Backlog, Ready, In progress, Blocked and Done with counts\n- Filters by area, type and priority; a ticket drawer links to GitHub\n- The deploy job writes /inside/board/issues.json on every deploy\n- Inside and the docs top bar link the board"
  },
  {
   "n": 9,
   "title": "Report an issue link on every docs page",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: docs",
    "type: feature"
   ],
   "assignees": [
    "uncovertechtalent"
   ],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:10Z",
   "updated": "2026-10-09T11:42:59Z",
   "closed": "2026-10-09T11:42:59Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/9",
   "body": "**What.** A \"Report an issue\" link on every docs page that opens a new GitHub issue with the page title and URL filled in.\n\n**Why.** Readers find mistakes. Today they have no route to report one.\n\n**Done when.**\n- The link is on every docs page\n- It opens a prefilled issue on this repository\n- New reports show on the board once triaged"
  },
  {
   "n": 10,
   "title": "Impressum on all three sites",
   "state": "open",
   "reason": null,
   "labels": [
    "P0",
    "area: legal",
    "status: blocked",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 0: legal and leaks",
   "created": "2026-10-09T11:31:12Z",
   "updated": "2026-10-09T11:31:12Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/10",
   "body": "**What.** An Impressum page on machinebehavior.io, tychat.io and uncovertechtalent.com, linked from the footer of every page.\n\n**Why.** German law requires provider details on sites like these (§ 5 DDG), and a named person responsible for editorial content (§ 18 MStV). None of the three sites has one.\n\n**Blocked on.** A postal address where post can be served (a P.O. box does not count), and the decision on which name the sites carry.\n\n**Done when.**\n- /impressum/ is live on all three sites\n- Every footer links to it\n- The conformity gate passes"
  },
  {
   "n": 11,
   "title": "Privacy notice on all three sites",
   "state": "open",
   "reason": null,
   "labels": [
    "P0",
    "area: legal",
    "status: blocked",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 0: legal and leaks",
   "created": "2026-10-09T11:31:14Z",
   "updated": "2026-10-09T11:31:14Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/11",
   "body": "**What.** A privacy notice that describes what the sites do: GitHub Pages as host, the Grafana dashboards framed on Inside (loaded only when that section scrolls into view), outbound links to Substack, Reddit and GitHub, no cookies, no analytics, no third-party requests on page load.\n\n**Why.** GDPR Art. 13 requires it as soon as the host processes visitor IP addresses. None of the three sites has one.\n\n**Blocked on.** The same name and address as the Impressum.\n\n**Done when.**\n- The notice is live on all three sites and linked from every footer\n- Each processor is named with its purpose\n- The conformity gate passes"
  },
  {
   "n": 12,
   "title": "security.txt",
   "state": "open",
   "reason": null,
   "labels": [
    "P1",
    "area: security",
    "status: blocked",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 0: legal and leaks",
   "created": "2026-10-09T11:31:16Z",
   "updated": "2026-10-09T11:31:16Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/12",
   "body": "**What.** Serve /.well-known/security.txt with Contact and Expires (RFC 9116).\n\n**Why.** It gives a researcher one place to report a vulnerability. Today the path returns 404.\n\n**Blocked on.** A contact route. Private vulnerability reporting is off on the repository and there is no public security address yet. Turning on private vulnerability reporting would give a Contact URL.\n\n**Done when.**\n- The file is live with a working Contact and an Expires date less than a year out\n- The deploy artifact includes the dot folder (check after the first deploy)"
  },
  {
   "n": 13,
   "title": "Service catalog at /inside/services/",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: inside",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:18Z",
   "updated": "2026-10-09T12:05:49Z",
   "closed": "2026-10-09T12:05:47Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/13",
   "body": "**What.** A catalog of the services behind the platform, built from YAML in the repository: the three sites, the conformity gate, the deploy job, the map crawler, the deploy exporter, the observability stack, the local LLM and the agent sessions. One row per service: owner, tier, lifecycle, SLO, dashboard, runbooks, docs and repository.\n\n**Why.** The systems are documented page by page, but nothing lists them in one place with who answers for each.\n\n**Done when.**\n- /inside/services/ is built from a YAML source\n- Each service links its docs, dashboard and runbooks\n- Each service is a node in the map\n- An Inside app tile links the catalog"
  },
  {
   "n": 14,
   "title": "Owner and review date on every docs page",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: docs",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:19Z",
   "updated": "2026-10-09T12:15:30Z",
   "closed": "2026-10-09T12:15:30Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/14",
   "body": "**What.** Add owner, reviewed, review_by and type (tutorial, how-to, reference, explanation) to the docs front matter. Show them in the page byline and list overdue pages on a docs health page.\n\n**Why.** The docs carry dates, but no page says who keeps it true or when it was last checked.\n\n**Done when.**\n- Every page in the hand-written spaces has the four fields\n- Vault pages start as not reviewed\n- A docs health page lists missing and overdue reviews\n- A gate check for a missing owner or an overdue review is agreed with the gate owner, or recorded as not wanted"
  },
  {
   "n": 15,
   "title": "Status page at /inside/status/",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: observability",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:21Z",
   "updated": "2026-10-09T12:11:56Z",
   "closed": "2026-10-09T12:11:55Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/15",
   "body": "**What.** Current state per service from the conformity records and the deploy exporter, plus an incident history with the states Investigating, Identified, Monitoring and Resolved.\n\n**Why.** The dashboards show metrics, but a visitor cannot see at a glance whether a service is healthy or what went wrong last week.\n\n**Done when.**\n- /inside/status/ shows each service from the catalog\n- The history is seeded with real incidents: gate blocks, the Claude Code counter inflation, tag pages served as XML\n- Inside links the page"
  },
  {
   "n": 16,
   "title": "One top bar and one search",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: inside",
    "area: search",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:23Z",
   "updated": "2026-10-09T11:58:49Z",
   "closed": "2026-10-09T11:58:47Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/16",
   "body": "**What.** The same top bar on Inside, the docs, the map, the board and the status page, and one search box over one index (the map graph plus the docs).\n\n**Why.** There are three navigations today (site menu, Inside header, docs top bar) and two search boxes over two indexes. Docs search opens the first hit on Enter; there is no results page.\n\n**Done when.**\n- One shared top bar on every Inside page\n- One search index built at deploy time\n- Enter opens a results page"
  },
  {
   "n": 17,
   "title": "Access model page and public demo banner",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P2",
    "area: inside",
    "area: security",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:25Z",
   "updated": "2026-10-09T12:18:52Z",
   "closed": "2026-10-09T12:18:50Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/17",
   "body": "**What.** A banner on Inside and the docs home that says this is a public demo and that in production it sits behind SSO. An access model page: public, internal and restricted spaces, and who grants access.\n\n**Why.** A visitor should know the intranet is public on purpose and how access would work inside a company.\n\n**Done when.**\n- The banner is on Inside and the docs home\n- The access model page is in the Engineering space and the banner links it"
  },
  {
   "n": 18,
   "title": "On-call and escalation page, and Alertmanager",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P2",
    "area: observability",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:27Z",
   "updated": "2026-10-09T12:21:28Z",
   "closed": "2026-10-09T12:21:26Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/18",
   "body": "**What.** A page that states the real on-call model (one operator, agent sessions as responders, the gate as the control) and where alerts would route. Then wire Alertmanager, or say on the page that alerts do not page anyone.\n\n**Why.** 13 alert rules are defined in Prometheus and none of them reaches a person.\n\n**Done when.**\n- The page is live in the Observability space\n- Alertmanager routes at least one alert to a real channel, or the page says plainly that nothing pages"
  },
  {
   "n": 19,
   "title": "Numbered decision records and a changelog",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P2",
    "area: docs",
    "type: docs"
   ],
   "assignees": [],
   "milestone": "Phase 1: enterprise layer",
   "created": "2026-10-09T11:31:29Z",
   "updated": "2026-10-09T12:25:36Z",
   "closed": "2026-10-09T12:25:33Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/19",
   "body": "**What.** Number the decision log entries and give each a status (proposed, accepted, superseded). Add a changelog page generated from git, grouped by Added, Changed and Fixed.\n\n**Why.** The log has the shape of architecture decision records, but an entry cannot be cited by number or superseded cleanly. There is no changelog.\n\n**Done when.**\n- Every entry has a number and a status\n- A superseded entry links its successor\n- The changelog is generated at build time"
  },
  {
   "n": 20,
   "title": "Templates space",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: docs",
    "type: docs"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T11:31:31Z",
   "updated": "2026-10-09T11:31:31Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/20",
   "body": "**What.** A Templates space with a service page, a playbook, a postmortem, an architecture decision record and an onboarding checklist.\n\n**Why.** Templates keep pages consistent and make the next page faster to write.\n\n**Done when.**\n- The space is live with five templates\n- Each template links at least one real page made from it"
  },
  {
   "n": 21,
   "title": "Onboarding path for a new engineer or agent session",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: docs",
    "type: docs"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T11:31:33Z",
   "updated": "2026-10-09T11:31:33Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/21",
   "body": "**What.** One page with what to read, in what order, and a first task, for a new engineer or a new agent session.\n\n**Why.** The docs say where to start for single tasks, but not how to get from zero to a first change.\n\n**Done when.**\n- The page has a reading order and a first task\n- It states a measured target, such as time to first deploy"
  },
  {
   "n": 22,
   "title": "Postmortem index",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: observability",
    "type: docs"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T11:31:35Z",
   "updated": "2026-10-09T11:31:35Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/22",
   "body": "**What.** One index of the incident records with date, service, impact and status, plus the criteria for when a postmortem is written.\n\n**Why.** About 40 incident records sit in the SRE space with no index and no template.\n\n**Done when.**\n- The index lists every record\n- The criteria are on the page\n- The postmortem template comes from the Templates space"
  },
  {
   "n": 23,
   "title": "Withdrawn-page pattern",
   "state": "open",
   "reason": null,
   "labels": [
    "P3",
    "area: docs",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T11:31:37Z",
   "updated": "2026-10-09T11:31:37Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/23",
   "body": "**What.** A way to withdraw a page without breaking links: the page stays at its URL with a notice, the date, the reason and a link to what replaces it.\n\n**Why.** Pages go out of date or turn out wrong. Deleting them breaks links in the map and on other sites.\n\n**Done when.**\n- The pattern is documented in the Engineering space\n- One real page uses it\n- The map marks withdrawn pages"
  },
  {
   "n": 24,
   "title": "Accessibility pass to WCAG 2.2 AA",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: inside",
    "area: map",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T11:31:39Z",
   "updated": "2026-10-09T11:31:39Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/24",
   "body": "**What.** An accessibility pass over Inside, the docs and the map to WCAG 2.2 AA, including a keyboard path and a list view for the map, and an accessibility statement.\n\n**Why.** The map is a canvas with no keyboard path through the graph, and no page states the accessibility level.\n\n**Done when.**\n- Automated checks pass on a sample of pages from each area\n- The map has a list view reachable by keyboard\n- An accessibility statement names the level and the known gaps"
  },
  {
   "n": 25,
   "title": "Retention statement for the metrics and log stores",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: legal",
    "area: observability",
    "type: docs"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T11:31:41Z",
   "updated": "2026-10-09T11:31:41Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/25",
   "body": "**What.** State how long the Loki and Prometheus stores keep data, what they hold, and what is stripped before storage.\n\n**Why.** The dashboards are public. Readers and the privacy notice need the retention facts.\n\n**Done when.**\n- A retention section in the Observability space, checked against the live configuration\n- The privacy notice links it"
  },
  {
   "n": 26,
   "title": "Security headers",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: security",
    "status: blocked",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 3: hosting",
   "created": "2026-10-09T11:31:43Z",
   "updated": "2026-10-09T11:31:43Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/26",
   "body": "**What.** HSTS, a Content Security Policy and frame-ancestors for the sites.\n\n**Why.** GitHub Pages cannot send custom headers. A CSP in a meta tag covers part of it; full headers need a proxy in front or a different host.\n\n**Blocked on.** The hosting decision: stay on GitHub Pages with a meta CSP, or put a proxy in front, which adds a processor to the privacy notice.\n\n**Done when.**\n- The hosting decision is recorded in the decision log\n- The chosen headers are live and checked with a header scan"
  },
  {
   "n": 27,
   "title": "Gate check for docs owner and review dates (open decision)",
   "state": "open",
   "reason": null,
   "labels": [
    "P3",
    "area: docs",
    "area: gate",
    "status: blocked",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T12:15:28Z",
   "updated": "2026-10-09T12:15:28Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/27",
   "body": "**What.** Decide whether the conformity gate should block a deploy when a docs page has no owner or is past its review date.\n\n**Why.** Since #14 every hand-written docs page carries owner, reviewed, review_by and type, and https://machinebehavior.io/inside/docs/health/ lists what is missing or late. The gate does not check these fields.\n\n**Blocked on.** A decision by Stefan Coetzee with the gate owner (the legislation-track session). Until then the health page is the check; first reviews fall due in January 2027.\n\n**Done when.** The check is added by the gate owner, or this issue records that it is not wanted."
  },
  {
   "n": 28,
   "title": "Left sidebar for Inside pages",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P3",
    "area: inside",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T12:31:06Z",
   "updated": "2026-10-09T13:36:06Z",
   "closed": "2026-10-09T13:36:06Z",
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/28",
   "body": "**What.** A left sidebar on Inside pages, built from the same source as the top bar (`scripts/inside_chrome.py`): docs spaces, services by system, status, board. On a phone it becomes a drawer.\n\n**Why.** Raised by Stefan Coetzee on 2026-10-09. The top bar carries eight sections plus search; a sidebar gives each section room for its own tree and keeps the bar short. The docs already have a space-tree sidebar, which is the pattern to generalise.\n\n**Scope.** Inside pages only. The research pages keep the site menu, so no page shows two navigations.\n\n**Done when.**\n- One sidebar source, synced like the bar, with a drift check\n- Works at 375 px without sideways scroll; keyboard focus visible\n- The docs space tree is one section of it"
  },
  {
   "n": 29,
   "title": "Cost counters: drop them or alert on their resets (incident follow-up)",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: observability",
    "status: ready",
    "type: chore"
   ],
   "assignees": [],
   "milestone": null,
   "created": "2026-10-09T12:56:24Z",
   "updated": "2026-10-09T12:56:24Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/29",
   "body": "Follow-up from the incident [Claude Code spend overstated about 1,960 times by counter resets](https://machinebehavior.io/inside/status/#2026-10-09-phantom-spend-counters) (2026-10-09).\n\nThe fix moved every spend and token query to the per-request events in Loki ([agent-observability c163b42](https://github.com/uncovertechtalent/agent-observability/commit/c163b429a63c69cff49dcde533da45f4a2c2f206)). The cost and token counters still arrive in Prometheus and still reset (230,328 resets in the week of the incident). No panel or rule reads them, so nothing tells a broken meter from a spending spike.\n\nTwo options:\n\n1. Drop the Claude Code counter series in Alloy before they reach Prometheus.\n2. Keep them and add a rule on `resets()` of the cost counter, so a broken meter raises its own alert (lesson 2 in the write-up).\n\nDone when one option is in agent-observability and [The phantom two million](https://machinebehavior.io/inside/docs/fin/anomaly-the-phantom-two-million/) says which.\n\nRunbook: [Counter resets from parallel sessions](https://machinebehavior.io/inside/docs/obs/runbook-counter-resets-parallel-sessions/)."
  },
  {
   "n": 30,
   "title": "Founder tour at /inside/tour/",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: inside",
    "type: feature"
   ],
   "assignees": [],
   "milestone": null,
   "created": "2026-10-09T13:05:53Z",
   "updated": "2026-10-09T13:09:08Z",
   "closed": "2026-10-09T13:09:08Z",
   "comments": 1,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/30",
   "body": "One page that walks a startup founder through the platform in about five minutes, so one link can go out with a message.\n\nSix stops, each with a screenshot of the live page, what to notice, one line on what the same part does for a 10 to 200 person team, and the link: the front page, one service, owned and dated docs with a decision record, one incident from the status page to the fix and its ticket (#29), a deploy that a failed check blocked (2026-10-08), and, optionally, cost and the map.\n\nDone when the page is live with self-hosted screenshots and its own preview image, linked from the Inside banner and the home page, with an Engineering docs line and ADR-0020, and the map re-crawled."
  },
  {
   "n": 31,
   "title": "One navigation source: site/nav.yml, one top bar, breadcrumbs on every page",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: site",
    "status: in progress",
    "type: feature"
   ],
   "assignees": [],
   "milestone": null,
   "created": "2026-10-09T13:17:10Z",
   "updated": "2026-10-09T13:32:49Z",
   "closed": "2026-10-09T13:32:49Z",
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/31",
   "body": "Sections and pages defined once in `site/nav.yml`. The build generates the top bar (same on every page), breadcrumbs on every page (visible, plus JSON-LD BreadcrumbList), and checks sitemap.xml and llms.txt against the tree; pages outside the tree are reported as orphans. Sections: Home, Research, Inside, Docs, Map. Hand-written pages keep their content; the build replaces chrome between markers. No URL changes.\n\nRequested by Stefan Coetzee on 2026-10-09: \"breadcrumbs all populated\"."
  },
  {
   "n": 32,
   "title": "Section sidebars for Research and Inside",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P1",
    "area: site",
    "status: in progress",
    "type: feature"
   ],
   "assignees": [],
   "milestone": null,
   "created": "2026-10-09T13:17:12Z",
   "updated": "2026-10-09T13:36:05Z",
   "closed": "2026-10-09T13:36:04Z",
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/32",
   "body": "Research and Inside get a sidebar like the docs tree: current page marked, collapsible on phones, generated from `site/nav.yml`. Supersedes #28 (Inside only)."
  },
  {
   "n": 33,
   "title": "Topic hubs at /topics/<topic>/",
   "state": "closed",
   "reason": "completed",
   "labels": [
    "P2",
    "area: site",
    "status: in progress",
    "type: feature"
   ],
   "assignees": [],
   "milestone": null,
   "created": "2026-10-09T13:17:14Z",
   "updated": "2026-10-09T13:42:19Z",
   "closed": "2026-10-09T13:42:19Z",
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/33",
   "body": "A Topics block in the sidebars and one hub page per topic at `/topics/<topic>/`, listing everything tagged with it across research pages, docs, posts and tickets. Labels come from docs front matter and map tags; hand-written pages get a small tag map in `site/`. Topic hubs are map nodes."
  },
  {
   "n": 34,
   "title": "One design system: tokens and component CSS, reading and app layouts",
   "state": "open",
   "reason": null,
   "labels": [
    "P1",
    "area: site",
    "status: in progress",
    "type: feature"
   ],
   "assignees": [],
   "milestone": null,
   "created": "2026-10-09T13:17:15Z",
   "updated": "2026-10-09T13:17:15Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/34",
   "body": "One token file (colours, type scale, spacing) and component CSS: top bar, sidebar, breadcrumbs, page header (section label, title, owner, updated date, status), cards, tables, panels, pills, footer. Reading layout keeps the serif body; app layout keeps the portal look. Light and dark follow the system setting, nothing stored on the device. One footer everywhere: conformity line, page source and history, report an issue, a reserved slot for Impressum and privacy (#10, #11). Skip link, landmarks, visible focus, WCAG 2.2 AA contrast (part of #24)."
  },
  {
   "n": 35,
   "title": "SRE principles in practice: one page per principle, linked to the services that apply it",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: docs",
    "status: in progress",
    "type: docs"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T13:40:08Z",
   "updated": "2026-10-09T13:40:09Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/35",
   "body": "What: a \"Principles in practice\" section in the SRE Handbook space of the docs. One page per principle, from Stefan Coetzee's SRE framework (the manifesto and the ten pillars) with the principles of Google's SRE book Part II as the reference. Each page says how this platform applies the principle, links the live evidence (services, status page incidents, the gate, runbooks, dashboards, FinOps), states whether it is in place, partial or a gap, and what a company of 10 to 200 people would do with it.\n\nWhy: the SRE Handbook is imported from the knowledge vault and does not link to the running platform. A reader sees the principles and the platform separately.\n\nAlso:\n- `principles:` in each service YAML, shown on the service page; principle pages list the services that name them, so the map records the links both ways.\n- The vault import removes only the pages it wrote (those with `origin:`), so hand-written pages in the SRE Handbook space survive a re-import.\n- Gaps found become issues on the board.\n\nDone when: the pages are live and pass the gate, the service pages show their principles, the map is re-crawled, and the Engineering docs and a decision record describe the change."
  },
  {
   "n": 36,
   "title": "Alert routing: Alertmanager, a Watchdog and receivers chosen by the operator",
   "state": "open",
   "reason": null,
   "labels": [
    "P1",
    "area: observability",
    "status: blocked",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T13:41:30Z",
   "updated": "2026-10-09T13:41:30Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/36",
   "body": "What: wire the routing proposed on the on-call page (https://machinebehavior.io/inside/docs/obs/on-call/). An Alertmanager service in the compose file of agent-observability, an `alerting` block in `prometheus.yml`, an always-firing `Watchdog` rule with an outside heartbeat check, the inhibition rules, and promtool tests for the routes.\n\nWhy: Prometheus evaluates 17 alert rules (5 page, 11 ticket, 1 info), and none of them reaches a person. All four incidents on the status page were found by someone who was working at the time. A dead Prometheus and a quiet night look the same today. SRE principle: https://machinebehavior.io/inside/docs/sre/principle-standby/\n\nBlocked on: the operator's choice of receivers (a push service for page alerts in waking hours; a webhook that opens an issue on this board for tickets). Sending a page to a phone needs the operator's go.\n\nDone when: a test alert with severity page reaches the chosen receiver, a ticket alert opens or updates an issue here, and stopping the Watchdog raises the outside heartbeat alarm."
  },
  {
   "n": 37,
   "title": "SLOs for the tier-1 services and the agent sessions",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: observability",
    "status: ready",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T13:41:32Z",
   "updated": "2026-10-09T13:41:32Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/37",
   "body": "What: service level objectives for the five tier-1 services (machinebehavior.io, tychat.io, uncovertechtalent.com, the conformity gate, the deploy job) and for the agent sessions, in the service YAML, with recording rules, burn-rate alerts and promtool tests.\n\nWhy: one of the 12 services in the catalog has SLOs (Local LLM). The tier-1 services, which readers meet directly, have none, so nobody can say how reliable they are or whether a week was good. SRE principle: https://machinebehavior.io/inside/docs/sre/principle-service-level-objectives/\n\nCandidate SLIs, to be checked against the data before any target is set:\n- Sites: share of one-minute probes from a black-box prober that get a 200 with the expected title. Needs a prober that runs outside GitHub (server side; nothing new loads in the reader's browser).\n- Deploy job: share of pushes to main that are live within 10 minutes, from the runs the deploy exporter already records.\n- Conformity gate: share of failed runs that a later review finds to be a false positive.\n- Agent sessions: tool-call success rate, and spend per session inside the budget on the FinOps pages.\n\nDone when: each of these services shows its SLOs on its service page, the targets are set from at least two weeks of data, and each SLO has a burn-rate alert with tests."
  },
  {
   "n": 38,
   "title": "Error budget policy: what happens when a service spends its budget",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: observability",
    "status: ready",
    "type: docs"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T13:41:33Z",
   "updated": "2026-10-09T13:41:34Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/38",
   "body": "What: a written error budget policy in the Observability docs, linked from every service that has an SLO. It says who decides, what stops (feature work, risky changes) and what restarts it when a service has spent its budget over the window, and how a disagreement is escalated.\n\nWhy: the Local LLM has two SLOs and burn-rate alerts, but nothing says what happens when the budget is gone, so the alerts measure the risk and do not steer it. SRE principle: https://machinebehavior.io/inside/docs/sre/principle-embracing-risk/ . Reference: the example policy in the Google SRE Workbook, https://sre.google/workbook/error-budget-policy/\n\nDone when: the policy page is live, the Local LLM service page links it, and the policy names the budget window and the action at 100% spent."
  },
  {
   "n": 39,
   "title": "Toil: the bot commit on main forces a rebase before every push",
   "state": "open",
   "reason": null,
   "labels": [
    "P3",
    "area: gate",
    "type: chore"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T13:41:50Z",
   "updated": "2026-10-09T13:41:50Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/39",
   "body": "What: stop the gate from committing its record to main after every run, or make that commit not move the branch other writers push to.\n\nWhy: after each run, `conformity-bot` commits `conformity/latest.json` and `conformity/index.html` to main with `[skip ci]`. Every writer, person or agent session, has to run `git pull --rebase` before each push, and a push without it is rejected. The runbook \"Push rejected after a deploy\" (https://machinebehavior.io/inside/docs/eng/runbook-push-rejected/) documents the workaround; the step itself is repeated by hand on every push. SRE principle: https://machinebehavior.io/inside/docs/sre/principle-eliminate-toil/\n\nOptions, for the gate owner and Stefan Coetzee to decide:\n- Write the record to a separate branch that only the bot pushes, and build /conformity/ from it in the deploy job.\n- Keep the record in the Pages artifact and the run artifacts, with the history file on the separate branch.\n\nDone when: a push made after a gate run needs no rebase, and the record history stays in git."
  },
  {
   "n": 40,
   "title": "CI check: generated pages match their sources",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: docs",
    "area: gate",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T13:41:52Z",
   "updated": "2026-10-09T13:41:52Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/40",
   "body": "What: a CI step that rebuilds the generated pages from their sources on a clean checkout (`scripts/build_docs.py`, `scripts/build_inside.py`) and fails when the result differs from what is committed.\n\nWhy: the docs, the service pages and the status page are built on the author's machine and committed as HTML. CI does not rebuild them, so a source edited without a build, or generated HTML edited by hand, deploys without anyone noticing. Release engineering asks for builds that give the same output from the same input, wherever they run. SRE principle: https://machinebehavior.io/inside/docs/sre/principle-release-engineering/ . Reference: https://sre.google/sre-book/release-engineering/\n\nTo solve first: the builds read today's date (docs health, review state) and git dates, and the changelog needs the GitHub API. The check has to pin the date to the commit date and leave the changelog out.\n\nWhether it blocks the deploy or runs as a separate job is the gate owner's call.\n\nDone when: a push that changes a source file without the matching build fails the check, and a clean push passes it."
  },
  {
   "n": 41,
   "title": "Incident records: when and how each incident was detected",
   "state": "open",
   "reason": null,
   "labels": [
    "P2",
    "area: observability",
    "status: ready",
    "type: feature"
   ],
   "assignees": [],
   "milestone": "Phase 2: depth",
   "created": "2026-10-09T13:41:54Z",
   "updated": "2026-10-09T13:41:54Z",
   "closed": null,
   "comments": 0,
   "url": "https://github.com/uncovertechtalent/machinebehavior.io/issues/41",
   "body": "What: two fields in `incidents/*.yml`: `detected` (time) and `detected_by` (one of: gate, alert, person working, reader report). The status page shows them, and the build reports time to detect and time to resolve per incident.\n\nWhy: three of the four incident records say \"Time of the first report not recorded\". Without the time of detection there is no time to detect, and without the route there is no evidence for or against the monitoring. Today all four were found by someone working at the time. SRE principles: https://machinebehavior.io/inside/docs/sre/principle-incidents-end-in-records/ and https://machinebehavior.io/inside/docs/sre/principle-monitor-symptoms/\n\nDone when: the schema in the status page docs has both fields, the four existing records carry them (with \"not recorded\" where that is the truth), and the status page shows them."
  }
 ]
}