Skip to content

Source inventory

Approved estate source scopes and known exclusions for M1 (D-03). Pair with read-access-contract.md. Candidate machine-readable inventory: estate/candidates.yml.

Inventory version: source-inventory.v1 (Gate C approved; application discovery complete) Tracking: hector-sanchez-eu/conductor#3
Brief: M1 brief

Gate C approval is recorded on issue #3. The approved gh operator discovery is complete for the application boundary. An unattended service credential is not an M1 prerequisite; its need and scope are deferred to M3. Gate C approves the discovery envelope—not a pre-enumerated application list. Discovered identities remain candidates until reviewed.

Notion scopes

Scope Proposed Status
Workspace sdhector workspace (867ec393-2263-8154-bd17-000319357256) Approved
Parent page Conductor State (3a7ec393-2263-818b-bce3-daa9a46b9220) Approved
Databases Nine Gate D databases defined by state-model.v2 Created, validated, and approved
Existing sketch DBs Any pre-M1 Initiatives/Products DBs discovered under the approved parent Read-only migrate candidates
Exclusions Personal journals, unrelated team spaces Approved exclude

Privacy: default internal unless page sets privacy_class. Client/commercial pages require explicit class before indexing.

GitHub scopes

Scope Proposed Status
Orgs hector-sanchez-eu, Konstant-Ventures Approved
Users sdhector Approved
Repositories All visible repos in approved org/user scopes, minus exclusions Approved
Exclusions Archived forks remain discoverable metadata but are not active candidates; career and unrelated third-party repos excluded Approved
Contents read Repository metadata, README, and selected manifest/deployment metadata only Approved

GitHub Issues are optional evidence, not Initiative SoR.

Initial operator enumeration on 2026-07-26 used authenticated gh under the temporary exception in read-access-contract.md. It now enumerates 47 repositories in hector-sanchez-eu, 30 in Konstant-Ventures, and 26 in sdhector (103 total, including the incubator container). The authentication mode is recorded as gh-operator; future unattended service authentication remains a separate M3 decision.

Workspace and local-only prototypes

Scope Proposed Status
Workspace pointers D:\Workspace\05 - Software Pipeline\ REPO.md pointers Approved discovery aid; not SoR
Local prototypes D:\Workspace\05 - Software Pipeline\Prototypes\ Approved candidates only; need portable canonical ref or portability_gap
_repos checkouts D:\Workspace\_repos\lab, portfolio, tools Approved discovery aid pointing at GitHub remotes
Exclusions One-off Misc folders; Professional/career Approved exclude

A path on one computer is not Asset identity (asset-registry.md).

The read-only D:\ discovery on 2026-07-26 is recorded in estate/local-discovery.yml. It found 188 canonical Git worktrees, including 35 without origin (30 outside obvious archives/backups), and one confirmed active application root with manifests but no Git identity. The discovery scan itself performed no move, Git initialization, remote creation, or publication.

The reviewed consolidation was subsequently published as the private repository hector-sanchez-eu/software-estate-incubator. It contains 29 copied projects with fresh monorepo history and one import commit per project. Originals remain in place. Exact remote-name duplicates, linked worktrees, credentials, private keys, generated runtimes, dependencies, build output, logs, uploads, and local databases were excluded or quarantined.

Hector accepted GitHub plus the incubator as the complete M1 application source boundary. The generated source registry therefore contains 131 candidate project units: 102 ordinary GitHub repositories and 29 incubator projects. Notion and deployed-host sources may enrich these candidates but are not additional application-completeness prerequisites for Gate C.

Deployed hosts and services

Scope Proposed Status
Hostnames *.hectorsanchez.eu Approved metadata discovery through documented DNS/runtime configuration; no content crawl
VPS services konstant / documented runtime services Approved metadata-only discovery
Exclusions Unrelated third-party SaaS accounts Approved exclude

Deployed-only systems without GitHub still require Asset candidates with URL provenance.

Golden-path application discovery

Real estate is the preferred representative domain for proving that Conductor can discover and analyze an application in line with the vision. It is not a manually enumerated Gate C completeness boundary.

After Gate C, enumerate the approved sources and select at least one suitable application—or a related group—for reviewed golden-path evidence. Selection must be based on discovered provenance, not a count or names supplied from memory. The analysis must reconstruct purpose, users/needs, capabilities, repositories, deployments, lifecycle, freshness, privacy, and material relationships well enough to support reuse, extend, new, or insufficient-context.

If no suitable real-estate application is discovered, record that result and select another representative application or retain an explicit golden-path fixture gap. Do not treat the descriptive reference to three applications as inventory evidence.

Privacy classes allowed for indexing

Class May index metadata? May index body/README?
public Yes Yes
internal Yes Yes for approved roles
client-private Metadata only with Engagement Manager rules No by default
secret-adjacent No No

Behavior before enabling reads

Documented in read-access-contract.md: denied, unavailable, stale, partial, rate-limited, malformed.

Known exclusions (summary)

  • Career / Professional pipeline content
  • Misc one-offs
  • Secret values and Bitwarden contents
  • Generated corpus as estate SoR
  • Conductor write-orchestrator SQLite mapping DB as Asset SoR

Gate C approval checklist (inventory portion)

Hector approves Gate C when commenting Conductor-Gate-C: approve after confirming or correcting:

  1. Notion workspace/parent and any existing DB IDs.
  2. GitHub orgs/users/exclusions.
  3. Local/deploy supplemental scopes.
  4. Golden-path selection rule above; application identities are discovered after approval.
  5. Privacy class rules above.
  6. Secret names listed in the read-access contract (not values).