Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .github/workflows/all-laws-rag-private-beta.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Wave 4D includes ESI exemption-governance and enforcement-authority controls.
name: All-Laws RAG Private Beta

on:
Expand All @@ -12,34 +13,39 @@ on:
- "growwithhr-rag/data/esi-wave4a-source-chunks.v1.json"
- "growwithhr-rag/data/esi-wave4b-source-chunks.v1.json"
- "growwithhr-rag/data/esi-wave4c-source-chunks.v1.json"
- "growwithhr-rag/data/esi-wave4d-source-chunks.v1.json"
- "server-all-laws-*.js"
- "server-epf-wave3a-*.js"
- "server-epf-wave3b-*.js"
- "server-epf-wave3c-*.js"
- "server-esi-wave4a-*.js"
- "server-esi-wave4b-*.js"
- "server-esi-wave4c-*.js"
- "server-esi-wave4d-*.js"
- "server-legal-explanation-router.js"
- "server-legal-explanation-router-wave3a.js"
- "server-legal-explanation-router-wave3b.js"
- "server-legal-explanation-router-wave3c.js"
- "server-legal-explanation-router-wave4a.js"
- "server-legal-explanation-router-wave4b.js"
- "server-legal-explanation-router-wave4c.js"
- "server-legal-explanation-router-wave4d.js"
- "server-legal-rag-catalogs.js"
- "js/assessment-v3/epf-wave3a-*.js"
- "js/assessment-v3/epf-wave3b-*.js"
- "js/assessment-v3/epf-wave3c-*.js"
- "js/assessment-v3/esi-wave4a-*.js"
- "js/assessment-v3/esi-wave4b-*.js"
- "js/assessment-v3/esi-wave4c-*.js"
- "js/assessment-v3/esi-wave4d-*.js"
- "tests/all-laws-*.mjs"
- "tests/epf-wave3a-*.mjs"
- "tests/epf-wave3b-*.mjs"
- "tests/epf-wave3c-*.mjs"
- "tests/esi-wave4a-*.mjs"
- "tests/esi-wave4b-*.mjs"
- "tests/esi-wave4c-*.mjs"
- "tests/esi-wave4d-*.mjs"
- "tests/legal-rag-catalog-loader-checks.mjs"
- "package.json"
- ".github/workflows/all-laws-rag-private-beta.yml"
Expand Down Expand Up @@ -89,5 +95,8 @@ jobs:
- name: Validate ESI Wave 4C overlay
run: node tests/esi-wave4c-private-beta-checks.mjs

- name: Validate ESI Wave 4D overlay
run: node tests/esi-wave4d-private-beta-checks.mjs

- name: Run complete legal RAG regression suite
run: npm run test:complete-legal-rag-platform
2 changes: 2 additions & 0 deletions .github/workflows/executive-assessment-tests.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Wave 4D includes the ESI exemption and enforcement-authority browser panel.
name: Executive Assessment Tests

on:
Expand Down Expand Up @@ -152,6 +153,7 @@ jobs:
tests/e2e/analyze-company-v3-esi-wave4a.spec.ts
tests/e2e/analyze-company-v3-esi-wave4b.spec.ts
tests/e2e/analyze-company-v3-esi-wave4c.spec.ts
tests/e2e/analyze-company-v3-esi-wave4d.spec.ts
tests/e2e/homepage-client-readiness.spec.ts
tests/e2e/presentation-polish.spec.ts
tests/e2e/m5-compliance-workspace.spec.ts
Expand Down
18 changes: 13 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ Deterministic rules decide. RAG retrieves governed material. The hosted model ex

## Legal RAG coverage

The Wave 4C stacked private-beta registry contains 57 runnable feature profiles:
The Wave 4D stacked private-beta registry contains 57 runnable feature profiles:

- seven POSH profiles use feature-specific deterministic rules and the governed POSH statutory catalogue;
- ten Maternity Benefit profiles use feature-specific deterministic rules and a governed Social Security Code, Central Rules, commencement and corrigendum catalogue;
Expand All @@ -38,7 +38,8 @@ The Wave 4C stacked private-beta registry contains 57 runnable feature profiles:
- five ESI Wave 4A profiles use feature-specific deterministic employer-control rules and a governed six-source catalogue;
- five ESI Wave 4B profiles use deterministic coverage and source-routing rules and a governed seven-source catalogue;
- three ESI Wave 4C profiles use deterministic special-route, benefit-process and medical-administration control rules and a governed seven-source catalogue;
- 15 profiles use conservative governance-fallback rules until their law-specific rules, official source packs and approvals are complete.
- two ESI Wave 4D profiles use deterministic exemption-governance and enforcement-authority source-routing rules and a governed eight-source catalogue;
- 13 profiles use conservative governance-fallback rules until their law-specific rules, official source packs and approvals are complete.

### Wave 1 — POSH

Expand Down Expand Up @@ -82,9 +83,15 @@ The three substantive Wave 4C profiles cover seasonal, hazardous and plantation

Wave 4C does not classify a seasonal factory, hazardous occupation or plantation route, decide a claim, validate a medical certificate, process diagnoses or treatment records, select a medical provider, determine a benefit scale or decide individual benefit entitlement. S.O. 2352(E) is retained only as a controlled medical-practitioner authority source. State and Union Territory implementation sources, the hazardous-occupation notification, plantation opt-in instruments, saved-regulation treatment and the other-beneficiaries user-charge instrument remain controlled gaps.

The Wave 1, Wave 2 and Wave 3A–4C profiles remain `needs-legal-review`. Their permitted private-beta outcomes are `specialist-review` and `more-information-needed`; they do not certify compliance, calculate payroll or contributions, decide individual insurance or entitlement, or represent qualified legal approval.
### Wave 4D — ESI exemption and enforcement-authority controls

The private-beta v3 page includes explicit in-memory review panels for all eight waves. They send only strict allow-listed organisational facts, categories, bands, routes, statuses, counts and evidence references after the user chooses to submit. They do not save inputs or results. Wave 4C excludes names, contact details, Aadhaar, insurance numbers, wages, payroll and contribution records, diagnoses, certificates, prescriptions, treatment records, family details, accident narratives, claims and evidence bodies.
The two substantive Wave 4D profiles cover exemption-governance and source controls, and enforcement-authority source routing.

Wave 4D records only organisation-level notification, comparison, version, authority-source, document-exclusion and specialist-escalation controls. It does not grant, validate, renew or withdraw an exemption; authenticate a notice, order, officer or signature; decide liability, default, recovery, limitation, penalty, prosecution or jurisdiction; or process enforcement documents. S.O. 2350(E), S.O. 2353(E), S.O. 2354(E) and S.O. 2356(E) are retained as controlled authority-source records only. Customer-specific exemption instruments, benefit-comparison evidence, service, limitation, delegation and case-jurisdiction facts remain qualified-review dependencies.

The Wave 1, Wave 2 and Wave 3A–4D profiles remain `needs-legal-review`. Their permitted private-beta outcomes are `specialist-review` and `more-information-needed`; they do not certify compliance, calculate payroll or contributions, decide individual insurance or entitlement, approve exemptions or determine enforcement outcomes.

The private-beta v3 page includes explicit in-memory review panels for all nine waves. They send only strict allow-listed organisational facts, categories, bands, routes, statuses, counts and evidence references after the user chooses to submit. They do not save inputs or results. Wave 4D excludes names, contact details, Aadhaar, insurance numbers, wages, payroll and contribution records, notices, orders, signatures, inspection findings, recovery amounts, dispute narratives and evidence bodies.

## What makes GrowWithHR different

Expand All @@ -102,7 +109,7 @@ The deployed product is the root-level HTML, CSS and JavaScript application. `se

## Data and persistence boundary

Assessment and workspace progress remain browser-local unless a user explicitly requests email delivery. The Wave 1, Wave 2 and Wave 3A–4C review panels are in-memory only. M6 durable-persistence contracts exist, but authentication, database connections, cloud evidence storage and cross-device resume remain disabled pending privacy, legal, security and release approval.
Assessment and workspace progress remain browser-local unless a user explicitly requests email delivery. The Wave 1, Wave 2 and Wave 3A–4D review panels are in-memory only. M6 durable-persistence contracts exist, but authentication, database connections, cloud evidence storage and cross-device resume remain disabled pending privacy, legal, security and release approval.

## Local validation

Expand All @@ -115,6 +122,7 @@ node tests/epf-wave3c-private-beta-checks.mjs
node tests/esi-wave4a-private-beta-checks.mjs
node tests/esi-wave4b-private-beta-checks.mjs
node tests/esi-wave4c-private-beta-checks.mjs
node tests/esi-wave4d-private-beta-checks.mjs
npm run test:release
npm run test:release:e2e
npm start
Expand Down
22 changes: 14 additions & 8 deletions docs/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ The default approved cross-origin client is `https://hrtechifyed.github.io`. Add

`/analyze-company-v3.html` is no-index and disabled from public routing by default. M1-M5 modules consume protected assessment answers through compatibility adapters and produce isolated traceability, Compliance Story and workspace output without changing stable report, PDF, email or delivery contracts.

The v3 route mounts nine legal-review surfaces:
The v3 route mounts ten legal-review surfaces:

- the existing POSH Internal Committee threshold explanation, which reads the three required facts from the protected assessment record;
- the POSH Wave 1 control-review panel, which collects six feature-specific fact sets in memory;
Expand All @@ -41,7 +41,8 @@ The v3 route mounts nine legal-review surfaces:
- the EPF Wave 3C panel, which exposes exemption-governance and international-worker or SSA control reviews using organisation-level statuses and evidence references;
- the ESI Wave 4A panel, which exposes five establishment, employee-insurance, contractor, payment and accident-reporting control reviews using organisation-level statuses, a declared route and evidence references;
- the ESI Wave 4B panel, which exposes five continuing or voluntary coverage, area commencement, wage-ceiling source, ceiling-continuation and contribution-rate source reviews using organisation-level statuses and evidence references;
- the ESI Wave 4C panel, which exposes special-route, benefit-process and medical-administration source reviews using organisation-level routes, statuses and evidence references.
- the ESI Wave 4C panel, which exposes special-route, benefit-process and medical-administration source reviews using organisation-level routes, statuses and evidence references;
- the ESI Wave 4D panel, which exposes exemption-governance and enforcement-authority source reviews using organisation-level source, exclusion and escalation controls plus evidence references.

All panels submit only after explicit user action. Their inputs and results are not written to browser storage and are not inserted into the stable report, PDF or email.

Expand Down Expand Up @@ -75,7 +76,7 @@ The deterministic decision owns applicability, control-review or entitlement-rou

## Runtime coverage

The Wave 4C stacked private-beta registry exposes 57 active profiles:
The Wave 4D stacked private-beta registry exposes 57 active profiles:

- seven POSH profiles use feature-specific deterministic rules and the governed POSH statutory catalogue;
- ten Maternity Benefit profiles use feature-specific deterministic rules and a governed Social Security Code, Central Rules, commencement and corrigendum catalogue;
Expand All @@ -85,11 +86,12 @@ The Wave 4C stacked private-beta registry exposes 57 active profiles:
- five ESI Wave 4A profiles use deterministic employer-control rules and a six-source governed catalogue;
- five ESI Wave 4B profiles use deterministic coverage and source-routing rules and a seven-source governed catalogue;
- three ESI Wave 4C profiles use deterministic special-route, benefit-process and medical-administration control rules and a seven-source governed catalogue;
- 15 profiles use conservative governance-readiness retrieval until their law-specific source packs, facts, rules and approvals are complete.
- two ESI Wave 4D profiles use deterministic exemption-governance and enforcement-authority source-routing rules and an eight-source governed catalogue;
- 13 profiles use conservative governance-readiness retrieval until their law-specific source packs, facts, rules and approvals are complete.

Wave 4C covers seasonal, hazardous and plantation route controls, organisation-level benefit-process support controls and medical-administration source routing. It accepts controlled organisation-level routes, process statuses, source statuses, escalation controls and evidence references.
Wave 4D covers ESI exemption-governance and enforcement-authority source routing. It accepts controlled organisation-level notification, comparison, version, authority-source, document-exclusion and specialist-escalation controls plus evidence references.

The Wave 1, Wave 2 and Wave 3A–4C catalogues remain `needs-legal-review`. Complete and reported-gap outcomes are `specialist-review`; missing facts produce `more-information-needed`. Wave 4C does not classify a special coverage route, decide a claim, validate a medical certificate, process medical records, select a provider or determine individual benefit entitlement.
The Wave 1, Wave 2 and Wave 3A–4D catalogues remain `needs-legal-review`. Complete and reported-gap outcomes are `specialist-review`; missing facts produce `more-information-needed`. Wave 4D does not approve an exemption, authenticate a customer document or officer, determine liability or recovery, calculate an amount, decide penalty or prosecution, or resolve jurisdiction.

## Source-governance boundary

Expand All @@ -99,7 +101,9 @@ Wave 4B adds S.O. 2351(E) as a controlled continuation source. That notification

Wave 4C adds S.O. 2352(E) as a controlled medical-practitioner authority source and the Other Beneficiaries Medical Facilities Scheme, 2026 as bounded scheme context. Neither source validates a customer certificate, determines treatment, selects a provider or decides individual access. The hazardous-occupation notification, plantation opt-in instruments, State and Union Territory implementation sources, medical-administration agreements, local facility procedures and the other-beneficiaries user-charge instrument remain unresolved.

The catalogues do not represent legacy instruments as automatically operative prospective authority. Area notifications, hazardous-route notifications, current portal specifications, due dates, forms, State medical administration, saved-law treatment, rate exceptions and effective-date treatment require qualified review.
Wave 4D adds S.O. 2350(E), S.O. 2353(E), S.O. 2354(E) and S.O. 2356(E) as controlled authority-source records. They do not prove case-specific delegation, service, jurisdiction, limitation, authenticity, liability or legal effect. Establishment-specific exemption notifications, benefit-comparison evidence, compliance history, customer notices and orders, signatures, findings and recovery records remain outside the controlled payload and require qualified review.

The catalogues do not represent legacy instruments as automatically operative prospective authority. Area notifications, hazardous-route notifications, current portal specifications, due dates, forms, State medical administration, saved-law treatment, rate exceptions, effective-date treatment and case-specific enforcement questions require qualified review.

## Privacy boundaries

Expand All @@ -119,6 +123,8 @@ ESI Wave 4B adapters additionally exclude addresses, wage-ceiling amounts and ra

ESI Wave 4C adapters exclude diagnoses, medical certificates, prescriptions, treatment records, family details, claim bodies and benefit payment records in addition to the existing ESI exclusions. Only organisation-level route, process, source, exclusion and escalation controls plus evidence references are accepted.

ESI Wave 4D adapters exclude exemption notifications, benefit-comparison bodies, compliance-history bodies, officer names, notices, orders, signatures, service records, inspection findings, recovery amounts, dispute narratives and all evidence bodies. Only organisation-level source, version, exclusion and escalation controls plus references are accepted.

## Operational endpoints

```text
Expand All @@ -127,6 +133,6 @@ GET /api/legal-rag/status
GET /api/m7/readiness
```

`server-entry.js` uses the Wave 4C router overlay, which preserves Waves 1–4B while activating three ESI benefit and medical-control profiles and reporting the 42/15 runtime mix.
`server-entry.js` uses the Wave 4D router overlay, which preserves Waves 1–4C while activating two ESI exemption and authority-control profiles and reporting the 44/13 runtime mix.

See `docs/architecture/compliance-engine-differentiation.md`, `docs/architecture/all-laws-runnable-private-beta-rag.md` and `docs/testing/all-laws-rag-validation.md`.
Loading
Loading