- server-side employee position resolution (org snapshot) with hard
position gate for EXPERIENCE/CASE sources; formal sources unaffected;
unresolvable position fails closed to general-scope only
- merge published experiences (aihr_case_record, CASE_EXP) and moderated
best answers (COMMUNITY, no submitter identity) into the citation pool
as REFERENCE tier; auxiliary sources never alter formal answers and
fail without breaking the main chain; grading re-grades ROUTE into
GUIDANCE when only auxiliary evidence exists
- case recall endpoints enforce the same position gate
- moderator endpoint to promote a best answer into a CANDIDATE case
record (idempotent via source_ref unique key, never auto-published)
- migration aihr_20260822_case_source_ref_and_best_answer_index_mysql8.sql
- COMMUNITY citations carry community-question:{id} in detailRef for
direct navigation
- narrow amount-semantics clarification to adjudicative intents only
- persist pending clarification on conversation and resolve follow-up
replies as ANSWERED/GAVE_UP/NEW_TOPIC (max one round per field)
- add AihrEvidenceGradingService: FULL/PARTIAL/GUIDANCE/ROUTE arbitration,
policy-claim post-validation, reference answers labeled as non-formal
- unblock retrieval source gating; tag citations with evidence tier,
keep PUBLISHED/HUMAN_VERIFIED/effective-date authorization gates
- replace operator-facing no-evidence copy with actionable route exits
(human help, direct finance channel, web research)
- allow fragment-less down feedback for own NO_EVIDENCE queries so
ROUTE answers can escalate to human help (fragment_id nullable)
- migrations: aihr_20260804_pending_clarification_mysql8.sql,
aihr_20260804_feedback_fragment_nullable_mysql8.sql
Document the `/api/aihr/org/sync-changes` change feed shipped in 30ef6a8f:
`employee.id` is the stable subject key, the dry-run-then-apply order, and the
fail-closed rules that full `/sync` keeps for masked phone numbers and
duplicate memberships. Adds the endpoint row and a curl example alongside the
existing full-sync entry.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
App-Plus has no WebRTC or getUserMedia in the logic layer, so realtime
practice was H5-only and the native entry had to advertise a record-then-
transcribe downgrade.
Move the media/WebRTC engine into `realtime-browser-engine.js` and drive it
from `RealtimePracticeAppBridge.vue`, whose renderjs script runs inside the
system WebView where those APIs do exist. The logic layer keeps the
authenticated calls: SDP exchange and `search_knowledge` tool invocation stay
server-proxied, so the access token is never handed to the view layer. Both
sides talk over the renderjs bridge only in session payloads the server
already assembled.
Verified against a real App build (`app-renderjs.js` holds RTCPeerConnection
and getUserMedia; `app-service.js` holds the SDP endpoint, renderjs side has
zero hits). Microphone permission, live transcription, remote playback,
foreground/background switching and disconnect fallback still require Android
and iOS device verification.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>