Status: Reconciled against real implementation state (2026-09-08). Checked items have direct evidence (real code/build/test run) behind them; unchecked items are genuinely not done or not confirmed — see PROJECT_STATUS.md for detail and evidence per item.
Prioritized checklist to move from this foundation to a working platform. Owners: HR, Product, Engineering, Security, Legal/Privacy, DevOps, QA, Data/AI.
config/schemas/). — Owner: Engineeringsrc/HrAutomation.* solution). — Owner: Engineering — done; solution builds and its test suite passes.src/HrAutomation.Web (Vite + React, not Next.js); runs today in mock-API mode only, not yet wired to the real backend.src/agents/. — Owner: Data/AI — not done, and not the direction taken: AI skills are implemented as C# ISkill classes inside HrAutomation.Agents, in-process with the API. Revisit only if a real need for a separate agent runtime emerges — see DECISIONS_REQUIRED.md.infra/. — Owner: DevOps — not started..github/workflows/). — Owner: DevOps — workflow files exist (ci.yml, docs-validation.yml, security-scan.yml) but have not been verified to run green against the real solution./api/v1/dev/token, gated to Development environment) + SQL Server row-level security via SESSION_CONTEXT('TenantId'). Not production-ready: no real OIDC/OAuth 2.1 provider is wired up yet (frontend oidcAuthProvider.ts is an intentional stub that throws).dotnet user-secrets; no vault integration exists.src/lib/safeLogger.ts exists on the frontend, backend redaction not confirmed.recruitment.usp_CreateDuplicateReview), never an auto-merge, per the human-in-the-loop rule.DECISIONS_REQUIRED.md for the JD structured-fields gap).PROJECT_STRUCTURE.md · CLAUDE.md · docs/10-delivery/ · docs/00-product/scope-assumptions-open-questions.md