diff --git a/status/OPEN-ISSUES.md b/status/OPEN-ISSUES.md index adb0f11..7d052bc 100644 --- a/status/OPEN-ISSUES.md +++ b/status/OPEN-ISSUES.md @@ -1,6 +1,6 @@ # Open issues — WRPS Plant Assistant -**Work we own, know about, and intend to do.** One entry per issue, newest first. +**Work we own, and decisions we expect to revisit.** One entry per issue, newest first. Nothing here is assigned yet; owners are set at handover. ## What belongs here, and what does not @@ -14,6 +14,7 @@ a repository ends up saying two different things about the same fact. | A shortcut we **consciously accepted** | [`BUILD-AI-CONTAINERS.md`](../spec/BUILD-AI-CONTAINERS.md) §14 | ✗ | | Something already running, and its state | [`current-state.html`](current-state.html) | ✗ | | **A defect or gap we own and have not fixed** | **here** | ✓ | +| **A design decision we expect to revisit** | **here**, marked *not a defect* | ✓ | Three rules: @@ -30,6 +31,48 @@ Three rules: ## Open +### OI-02 · The no-setpoint rule may need to become optional + +**Raised** 2026-09-01 · **Owner** unassigned · **Affects** the product, not the build · +**Not a defect** — the rule works as designed. Logged because it is a design decision that +is expected to be revisited. + +The second of the three lines this system does not cross is **no recommended setpoints or +operating parameters**. An Advisory answer gives evidence, ranges, outcomes and documented +limits, then defers explicitly to a competent person. It never returns a number as the answer. + +There is a foreseeable case for allowing it — a recommendation is the thing an operator +actually wants, and withholding it has a cost. This entry exists so that conversation starts +from what is built rather than from scratch. + +**Where the rule lives.** It is not a prompt instruction, so relaxing it is a code change in +several places at once: + +| Enforcement point | What it does | +|---|---| +| `api/contracts.py` → `AdvisoryAnswer` | `recommendation_given: Literal[False]` — the contract cannot express a recommendation. A `deferral` string is required, and a scope banner is attached to every Advisory answer | +| `api/classifier.py` | Advisory beats Historical; partly-advisory is advisory. Anything that could be read as advice is routed to the class that refuses to advise | +| `eval/testset.jsonl` | 14 Advisory cases assert the refusal | +| `api/tests/` | 15 tests across contracts and classifier rules | + +**What would have to be decided before it changes** — none of this is a coding question: + +- **Who is accountable for a number the assistant produces**, once it stops deferring. Today the + deferral is what keeps that answer unambiguous. +- **What evidence is sufficient.** The rule exists because "best" depends on equipment condition + and concurrent operations this system cannot see — the historian shows what happened, not what + the plant can safely do now. +- **How a recommendation is distinguished on screen** from evidence, so it cannot be misread as a + documented limit. +- **Whether it applies to all parameters or a named subset**, and who approves that list. +- **§2 of the build spec is still awaiting an OT/safety review.** This rule is the largest single + thing that review will have an opinion on. Do not relax it beforehand. + +**Blocked by** the OT/safety review of `spec/BUILD-AI-CONTAINERS.md` §2, which is outstanding. +**Blocking** nothing. + +--- + ### OI-01 · OpenPLC Editor is not installed **Raised** 2026-09-01 · **Owner** unassigned · **Affects** the demo plant, not the assistant