Background
CoreLink is managed as one product across multiple implementation boundaries. This work is owned by .github under EPIC-01.
Problem
CoreLink does not yet have verified, consistently maintained evidence that every active repository has an authoritative ownership map and protected-review enforcement. A central policy in the organization .github repository is useful, but GitHub CODEOWNERS files are repository-scoped and are not inherited automatically by other repositories.
Goal
Establish team-based ownership and protected review rules across all active repositories, with .github holding the authoritative policy/template and each repository carrying or receiving the enforcement artifacts it actually requires.
Parent
- Primary Product Epic: EPIC-01
- Backlog ID:
GH-02
Scope
- Define the authoritative organization ownership policy and reusable CODEOWNERS template/generation approach in
.github.
- Materialize repository-scoped
CODEOWNERS in each active repository that requires code-owner review; do not assume organization-level inheritance.
- Configure or verify protected review enforcement through repository rulesets/branch protection as appropriate.
- Define a minimal documented exception path for repositories that intentionally use different ownership/review rules.
- Reconcile affected organization policy, product claims, security, release, documentation and repository maturity.
- Retain acceptance evidence for the Governance Baseline gate.
Out of Scope
- Runtime feature implementation in this Issue.
- Duplicating the product roadmap in repository README files.
- Presenting scaffolds or planned capability as a supported release.
- Treating a CODEOWNERS file in the organization
.github repository as inherited enforcement for other repositories.
Acceptance Criteria
Current Audit Evidence
- Organization-wide code search on 2026-08-25 found no
CODEOWNERS file in the accessible CoreLink repositories.
- The connected GitHub integration cannot read
platform/main branch-protection details (403 Resource not accessible by integration), so protected-review enforcement cannot be certified from this audit and must remain an explicit acceptance check.
Technical Notes
Use organization-wide policy/templates where useful, but keep enforcement semantics repository-local where GitHub requires it. Repository-specific exceptions must be minimal and documented. Product maturity claims must distinguish Scaffold, Experimental, Alpha, Beta, Stable and Deprecated.
Dependencies
- Decision prerequisite: team and repository ownership approval must establish authoritative owners before CODEOWNERS/protection can be treated as accepted governance.
- Execution prerequisite: identify all active repositories in scope and the protection mechanism used by each (ruleset or branch protection).
- Blocks: protected review enforcement, repository ownership acceptance, and EPIC-01 governance completion.
- Cross-repository: implementation will require repository-specific changes/configuration; link concrete PRs or evidence instead of duplicating product planning.
- Current dependency state: See the CoreLink Product organization Project.
Planning Metadata
- Type: Technical Task
- Priority snapshot: P0
- Product milestone snapshot: Governance Baseline
- Domains snapshot: governance, security
- Area snapshot: operations
- Complexity: M
- Created in status: Triage
- Current status and DRI: See the CoreLink Product organization Project.
- Intended repository labels:
type:technical-task
Definition of Done
Background
CoreLink is managed as one product across multiple implementation boundaries. This work is owned by
.githubunder EPIC-01.Problem
CoreLink does not yet have verified, consistently maintained evidence that every active repository has an authoritative ownership map and protected-review enforcement. A central policy in the organization
.githubrepository is useful, but GitHubCODEOWNERSfiles are repository-scoped and are not inherited automatically by other repositories.Goal
Establish team-based ownership and protected review rules across all active repositories, with
.githubholding the authoritative policy/template and each repository carrying or receiving the enforcement artifacts it actually requires.Parent
GH-02Scope
.github.CODEOWNERSin each active repository that requires code-owner review; do not assume organization-level inheritance.Out of Scope
.githubrepository as inherited enforcement for other repositories.Acceptance Criteria
Current Audit Evidence
CODEOWNERSfile in the accessible CoreLink repositories.platform/mainbranch-protection details (403 Resource not accessible by integration), so protected-review enforcement cannot be certified from this audit and must remain an explicit acceptance check.Technical Notes
Use organization-wide policy/templates where useful, but keep enforcement semantics repository-local where GitHub requires it. Repository-specific exceptions must be minimal and documented. Product maturity claims must distinguish Scaffold, Experimental, Alpha, Beta, Stable and Deprecated.
Dependencies
Planning Metadata
type:technical-taskDefinition of Done