Title: Generated Files Version: 1.1 Owner: [TENANT_CONFIGURATION_REQUIRED] Status: Draft Last reviewed: 2026-09-08 Next review: [TENANT_CONFIGURATION_REQUIRED] Reviewers: Product, Architecture, Security, Legal, HR
This is the index of every file in the documentation/configuration package generated for the AI-enabled HR Recruitment and Onboarding Automation platform, plus the real application code that was built afterward. This is a documentation navigation aid, not the source of implementation truth — for what is actually implemented versus planned, see PROJECT_STATUS.md (authoritative, maintained) and PROJECT_STRUCTURE.md (real repository tree). Several documents indexed below describe target-state designs that were superseded once real code was written — each such document now carries its own “Implementation reality notice” near the top; trust that notice over the document’s original body where they disagree.
docs/adr/ (all 5)prompts/system/config/schemas/ + config/defaults/ + config/environments/ + config/tenants/sample-tenant.yaml.claude/rules/ + .claude/commands/| File | Purpose |
|---|---|
| README.md | Product overview, navigation, governance statement |
| CLAUDE.md | Stable, concise project-wide instructions |
| PROJECT_STRUCTURE.md | Real repository tree, folder responsibilities, dependency direction |
| PROJECT_STATUS.md | Authoritative implemented/scaffolded/planned/deferred status |
| DECISIONS_REQUIRED.md | Open decisions needing HR/Legal/Security/DBA/Architecture sign-off |
| CHANGELOG.md | Keep-a-Changelog-style record of notable changes, including doc/context updates |
| GENERATED_FILES.md | This file |
| .gitignore | Excludes secrets, build artifacts, sensitive reports |
| .editorconfig | Cross-language formatting conventions |
| .env.example | Safe placeholder environment variable template |
| Path | Purpose | Status |
|---|---|---|
src/HrAutomation.Domain/ |
Entities, enums | Implemented (subset backing Candidate/TAN flows) |
src/HrAutomation.Application/ |
ISkill/IWorkflowOrchestrator/IApprovalGateService/IGuardrailPipeline contracts, DTOs |
Implemented |
src/HrAutomation.Infrastructure/ |
HrAutomationDbContext (EF Core, database-first), audit/approval-gate implementations |
Implemented (subset of tables wired up) |
src/HrAutomation.Infrastructure/Database/ |
Hand-written SQL Server DDL/seed/tests for HrAutomationDb (scripts/, seed/, tests/, publish/, migrations/, docs/ [empty placeholder]) |
Implemented (schema + seed); docs/ subfolder not yet written |
src/HrAutomation.Agents/ |
ISkill implementations: CV ingestion, TAN create/approve (real) + Stubs/ (everything else) |
Partially implemented |
src/HrAutomation.Rag/ |
Retrieval-only content access for AI grounding | Not present (empty scaffold) |
src/HrAutomation.Mcp/ |
External-system tool servers | Not present (empty scaffold) |
src/HrAutomation.Api/ |
ASP.NET Core REST API, auth, DI composition | Implemented (subset of openapi/ endpoints) |
src/HrAutomation.Web/ |
React/TypeScript frontend — see src/HrAutomation.Web/README.md | Implemented UI shell; mock-API mode only, not wired to the real API |
tests/HrAutomation.Tests/ |
xUnit integration tests against a real HrAutomationDb instance |
Implemented (22 tests, CV upload + TAN create/approve flows) |
| File | Purpose |
|---|---|
| product-requirements-document.md | Functional/non-functional requirements, goals, metrics |
| personas-and-roles.md | User personas and RBAC role responsibilities |
| scope-assumptions-open-questions.md | Living register of scope, assumptions, pending decisions |
| File | Purpose |
|---|---|
| solution-architecture.md | Bounded contexts, context diagram, sync/async decisions |
| component-architecture.md | Internal module breakdown per service |
| deployment-architecture.md | Runtime topology, environments, RTO/RPO |
| integration-architecture.md | Event-driven integration patterns, reliability |
| non-functional-requirements.md | Availability, latency, scalability, security, cost targets |
| resilience-and-disaster-recovery.md | Resilience patterns, DR strategy |
| technology-selection-matrix.md | Default tech per capability, alternatives, selection criteria |
| ADR-001 | Relational DB as system of record |
| ADR-002 | Deterministic workflow engine + supervisor/specialist agents |
| ADR-003 | Vector store boundary (retrieval only, never system of record) |
| ADR-004 | Isolated MCP server per external system |
| ADR-005 | OpenTelemetry-based observability standard |
| File | Purpose |
|---|---|
| end-to-end-recruitment-onboarding-workflow.md | Full candidate journey, stage table, diagrams |
| workflow-state-machine.md | Formal state machines for TAN/application/offer/verification/employee |
| human-approval-matrix.md | Every sensitive action, required approver, evidence |
| sla-escalation-rules.md | SLA targets and escalation triggers |
| notification-catalog.md | Every notification, trigger, recipient, PII rules |
| exception-handling-playbook.md | Exception catalog and handling principles |
| File | Purpose |
|---|---|
| data-architecture.md | Data domain separation, data flow |
| er-diagram.md | Entity-relationship Mermaid diagram |
| data-dictionary.md | Field-level entity dictionary |
| data-classification-and-retention.md | Classification tiers, retention, legal hold, deletion |
| data-quality-rules.md | Validation/quality rules per entity |
| audit-log-specification.md | Audit event coverage and record structure |
| database-migration-strategy.md | Migration principles, rollback strategy |
| master-data-management.md | Reference-data ownership and sync |
| sample-relational-schema.sql | Baseline DDL for all core entities |
| File | Purpose |
|---|---|
| api-standards.md | Mandatory REST conventions |
| rest-api-catalog.md | Human-readable endpoint index |
| error-handling-and-problem-details.md | RFC 7807 format, PII-safe error rules |
| versioning-and-deprecation-policy.md | Breaking-change and deprecation process |
| webhook-security.md | Inbound webhook signature/replay/idempotency rules |
| hr-onboarding-api.openapi.yaml | Full REST contract |
| hr-onboarding-events.asyncapi.yaml | Full event contract |
| File | Purpose |
|---|---|
| security-architecture.md | Zero-trust posture, encryption, access layers, tenant isolation |
| threat-model.md | STRIDE + AI/RAG/MCP abuse cases |
| ai-guardrails-policy.md | Non-negotiable AI behavior boundaries |
| prompt-injection-defense.md | Direct/indirect injection defenses |
| identity-access-control.md | RBAC/ABAC model and access matrix |
| privacy-and-pii-handling.md | PII minimization, redaction, data subject rights |
| fairness-and-bias-governance.md | Excluded characteristics, fairness testing process |
| secure-file-upload-policy.md | Malware scanning, quarantine workflow |
| secrets-and-key-management.md | Vault usage, rotation cadence |
| incident-response-runbook.md | Severity classification, response process |
| security-test-plan.md | SAST/SCA/DAST/pen-test tiers |
| compliance-review-checklist.md | Pre-go-live legal/compliance checklist |
| File | Purpose |
|---|---|
| agent-architecture.md | Supervisor/specialist orchestration diagram |
| agent-skill-catalog.md | Every skill: inputs, outputs, tools, thresholds |
| agent-state-and-orchestration.md | Ephemeral agent state vs. system-of-record split |
| rag-architecture.md | RAG pipeline within ADR-003 boundary |
| rag-ingestion-and-chunking.md | Chunking strategy, metadata requirements |
| retrieval-and-grounding-policy.md | Hybrid search, reranking, citation enforcement |
| model-routing-and-cost-controls.md | Model tiering, resilience/cost controls |
| prompt-management.md | Prompt versioning/approval/rollback lifecycle |
| ai-evaluation-strategy.md | Evaluation dimensions and release criteria |
| red-team-plan.md | Adversarial testing cadence and scoring |
| model-risk-register.md | Per-skill risk tier and mitigations |
| prompts/system/*.md (7 files) | Production system prompts per skill |
| prompts/skills/README.md | Prompt-fragment convention index |
| prompts/evaluation/evaluation-prompts.md | LLM-as-judge evaluation templates |
| prompts/red-team/prompt-injection-test-cases.md | Adversarial test-case catalog |
| File | Purpose |
|---|---|
| mcp-architecture.md | MCP server topology per external domain |
| mcp-security-and-authorization.md | AuthN/AuthZ, tool tiers, human-confirmation flow |
| mcp-tool-governance.md | Manifest versioning, onboarding/offboarding |
| integration-adapter-catalog.md | Adapter-to-MCP-server mapping |
| mcp/servers/README.md | MCP server registry |
| mcp/tool-schemas/hr-tools.schema.json | Tool manifest JSON Schema |
| mcp/prompts/README.md | Tool-use prompt fragment convention |
| File | Purpose |
|---|---|
| observability-strategy.md | OTel instrumentation plan, AI-specific telemetry |
| logging-and-redaction-standard.md | Mandatory redaction pipeline |
| metrics-slos-and-alerts.md | SLOs and alert thresholds |
| dashboard-specification.md | Required dashboards and audiences |
| on-call-runbook.md | Operational incident triage |
| cost-management.md | Cost allocation and budget controls |
| File | Purpose |
|---|---|
| test-strategy.md | Full test pyramid definition |
| acceptance-criteria.md | Requirement → acceptance criteria mapping |
| test-case-catalog.md | Representative test cases per tier |
| ai-evaluation-scorecard.md | Per-release AI scorecard template |
| platform-upgrade-gap-analysis.md | .NET/Node/React platform upgrade: current-vs-target version inventory, blocking dependencies, phased upgrade plan |
| navigation-feature-gap-analysis.md | Route-by-route trace of every frontend navigation item through the full stack; root causes behind the /interviews (and 6 sibling modules) “Something went wrong” bug |
| production-readiness-report.md | What was actually broken/fixed/remaining for the navigation-reliability pass; endpoints added, tests added, remaining blockers |
| ui-ux-modernization-audit.md | Grounded audit of the current HrAutomation.Web UI: design-token gaps, visual inconsistencies, UX pain points, priority screens |
| ui-modernization-report.md | What was actually redesigned/refactored in the UI modernization pass: tokens, shell, shared patterns, screens, responsiveness, accessibility |
| File | Purpose |
|---|---|
| backlog-epics-and-user-stories.md | Epic breakdown, sample stories, delivery risks |
| definition-of-ready.md | Pre-sprint checklist |
| definition-of-done.md | Completion checklist |
| release-plan.md | Phased release sequencing |
| environment-strategy.md | Environment purpose and promotion flow |
| ci-cd-quality-gates.md | Mandatory pipeline gates |
| File | Purpose |
|---|---|
| document-template.md | Reusable document-control-block template |
| File | Purpose |
|---|---|
| platform-config.schema.json | Schema: tech selection, resilience, feature flags |
| tenant-config.schema.json | Schema: tenant metadata, roles, departments |
| workflow-config.schema.json | Schema: stages, SLAs, checklists, matching weights |
| approval-matrix.schema.json | Schema: fixed gated-action enum, approver mapping |
| rag-config.schema.json | Schema: chunking, retrieval, evaluation thresholds |
| model-routing.schema.json | Schema: per-skill model routes and budgets |
| retention-policy.schema.json | Schema: retention categories, erasure process |
| notification-template.schema.json | Schema: notification channel/template config |
| platform.default.yaml | Default platform config |
| workflow.default.yaml | Default workflow config |
| rag.default.yaml | Default RAG config |
| model-routing.default.yaml | Default model routing config |
| security.default.yaml | Default security config |
| observability.default.yaml | Default observability config |
| dev.yaml / test.yaml / staging.yaml / prod.yaml | Environment-specific overrides |
| sample-tenant.yaml | Worked example tenant configuration (fake/demo) |
| File | Purpose |
|---|---|
| settings.json | Claude Code permission/env defaults |
| rules/architecture.md, security.md, api.md, data.md, ai-agents.md, testing.md, documentation.md | Always-loaded conventions per domain |
| commands/*.md (6 files) | Slash commands for common structured tasks |
| skills/README.md | Claude Code skills index (none yet) |
| File | Purpose |
|---|---|
| evals/datasets/README.md, evals/cases/README.md, evals/rubrics/README.md, evals/reports/README.md | Placeholders describing planned evaluation asset structure |
| scripts/README.md | Placeholder for future operational scripts |
| Requirement (from PRD) | Primary documents |
|---|---|
| FR-01–03 CV Bank ingestion | end-to-end-recruitment-onboarding-workflow.md, data-architecture.md, sample-relational-schema.sql, secure-file-upload-policy.md, cv-parsing-system-prompt.md |
| FR-04–05 TAN lifecycle | workflow-state-machine.md, human-approval-matrix.md, rest-api-catalog.md (/tans*) |
| FR-06 AI matching | agent-skill-catalog.md, candidate-matching-system-prompt.md, fairness-and-bias-governance.md |
| FR-07 Shortlist approval | human-approval-matrix.md, rest-api-catalog.md (shortlist-approval) |
| FR-08–12 Interview lifecycle | workflow-state-machine.md, interview-coordination-system-prompt.md, mcp-architecture.md (mcp-calendar) |
| FR-13–14 Offer lifecycle | offer-management-system-prompt.md, ai-guardrails-policy.md, rest-api-catalog.md (/offers*) |
| FR-15–17 Green Form & verification | document-verification-system-prompt.md, sample-relational-schema.sql (green_form, verification_result) |
| FR-18–19 Discrepancy management | exception-handling-playbook.md, human-approval-matrix.md |
| FR-20–21 Employee conversion & integrations | employee-conversion-system-prompt.md, integration-adapter-catalog.md, mcp-architecture.md |
| FR-22 Audit trail | audit-log-specification.md, ADR-001 |
| Non-negotiable 1 (human-in-the-loop) | human-approval-matrix.md, ai-guardrails-policy.md, ADR-002 |
| Non-negotiable 2 (security/privacy) | security-architecture.md, threat-model.md, privacy-and-pii-handling.md |
| Non-negotiable 3 (fairness) | fairness-and-bias-governance.md |
| Non-negotiable 4 (configuration-first) | all config/schemas/* + config/defaults/* |
| Non-negotiable 5 (architecture) | solution-architecture.md, ADR-001–005 |
| Review type | Files |
|---|---|
| Legal review | privacy-and-pii-handling.md, data-classification-and-retention.md, fairness-and-bias-governance.md, compliance-review-checklist.md, scope-assumptions-open-questions.md, retention-policy.schema.json |
| HR policy review | human-approval-matrix.md, sla-escalation-rules.md, workflow.default.yaml (document checklist, discrepancy taxonomy), tenant-config.schema.json (job grades/compensation refs) |
| Security review | security-architecture.md, threat-model.md, secrets-and-key-management.md, secure-file-upload-policy.md, mcp-security-and-authorization.md, security-test-plan.md |
| Architecture/DBA review | sample-relational-schema.sql (now superseded by the real src/HrAutomation.Infrastructure/Database/scripts/ — see its own implementation-reality notice), data-architecture.md, database-migration-strategy.md, technology-selection-matrix.md, all ADRs including ADR-006 |
| AI Governance review | ai-guardrails-policy.md, model-risk-register.md, prompt-management.md, ai-evaluation-strategy.md, all prompts/system/*.md |
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-09-07 | Documentation package generation | Initial creation |
| 1.1 | 2026-09-08 | Documentation reconciliation pass | Added real src//tests/ code index, PROJECT_STATUS.md/DECISIONS_REQUIRED.md/CHANGELOG.md pointers; noted which indexed documents now carry an implementation-reality notice |