Add evals for every shipped agent, a policy corpus, and CI
§9 says no agent ships without evals. Eight of the nine had none: the two
other suites in evals/ are harness fixtures rather than agents in the
registry, so the rule was being met by one agent in nine.
Evals — 40 new cases, five per agent, every one carrying mustNotLeak:
- the agent is loaded from its real spec in agents/*.md rather than
written out again in Go. A hand-copied agent tests the copy: it keeps
passing after somebody edits the spec, which is the moment it most
needed to fail.
- callNamed calls the tool a case names. toolThenAnswer always called
tools[0], so seven of positions-agent's eight tools were unreachable,
and a boundary nothing calls is a boundary nothing tests.
- seedWorkspace fills BOTH tenants. A leak test against an empty second
tenant cannot fail.
Verified by breaking workersByScore's org predicate: six cases across four
agents fail with LEAKED "RIVAL".
Knowledge — six policy documents, taking the corpus from 2 to 8 (34
chunks). Three restricted to admin and employer, five tenant-wide. They
cover what the tools cannot: a tool reports how many shifts went unworked,
a policy says what cover costs inside 24 hours.
corpus_test.go treats those documents as product rather than fixtures. The
first version was tautological — it read audience: from a file and checked
that file's audience was enforced, so opening a restricted document passed.
mustNotBeTenantWide now holds that judgement apart from the files, with the
reason recorded for each.
CI — the checks this repository already had, made unskippable. testutil
calls t.Skipf on an unreachable database, so a dead service container would
produce a green build over a suite that ran almost nothing. Simulated: go
test exits 0 with 74 tests skipped, including every tenant-isolation test.
The guard exits 1 and names them, while still allowing TestLive* to skip
without a model key.
This CI tests; it does not deploy. The README's claim that migrations are
run by CI against the target database remains aspirational.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0186JgqQUCDS8ZwGmyw3ymWu
This commit is contained in:
47
knowledge/conduct-and-venue-standards.md
Normal file
47
knowledge/conduct-and-venue-standards.md
Normal file
@@ -0,0 +1,47 @@
|
||||
---
|
||||
source: policy_docs
|
||||
audience: tenant
|
||||
title: Conduct and Venue Standards
|
||||
---
|
||||
|
||||
# Arriving for a shift
|
||||
|
||||
Arrive fifteen minutes before the scheduled start, changed and ready to be
|
||||
briefed. The scheduled start is when work begins, not when you walk in.
|
||||
|
||||
Sign in through the app on site. Signing in from elsewhere, or asking somebody
|
||||
to sign in for you, is treated as a falsified record rather than a shortcut.
|
||||
|
||||
# Uniform
|
||||
|
||||
Black trousers or skirt, plain black shoes with a closed toe, and the venue's
|
||||
own top unless told otherwise. Where a venue supplies a top it is returned
|
||||
laundered at the end of the assignment.
|
||||
|
||||
Jewellery is limited to a plain band and small studs in kitchen and bar roles.
|
||||
Long hair is tied back for any role handling food or working near equipment.
|
||||
|
||||
# Alcohol and drugs
|
||||
|
||||
No alcohol is consumed on shift, including at the end of an event while the bar
|
||||
is still open to guests. A worker who appears impaired is stood down for the
|
||||
shift and paid for the hours already worked; the conversation happens the next
|
||||
working day, not on the floor.
|
||||
|
||||
Staff may refuse service to a guest they judge to be intoxicated, and that
|
||||
judgement is supported by the venue. A worker overruled by a client on this
|
||||
point should record it and tell the venue manager.
|
||||
|
||||
# Phones
|
||||
|
||||
Phones stay out of sight in service areas. Checking a rota or responding to an
|
||||
operational message is fine on a break or with a supervisor's nod.
|
||||
|
||||
# Speaking about the venue and its guests
|
||||
|
||||
Nothing about a guest, a client or an event goes outside the shift. This
|
||||
includes naming a venue alongside a guest on social media, which is the form
|
||||
this usually takes and the one people do not think of as a disclosure.
|
||||
|
||||
Photographs at private events need the client's permission, which the venue
|
||||
manager holds or does not — ask rather than assume.
|
||||
50
knowledge/incidents-and-escalation.md
Normal file
50
knowledge/incidents-and-escalation.md
Normal file
@@ -0,0 +1,50 @@
|
||||
---
|
||||
source: policy_docs
|
||||
audience: tenant
|
||||
title: Incidents and Escalation
|
||||
---
|
||||
|
||||
# What to report
|
||||
|
||||
Report anything that injured somebody, could have injured somebody, or would
|
||||
embarrass the venue if it appeared in a review. The third category is the one
|
||||
people skip, and it is where most patterns start.
|
||||
|
||||
A near miss is reportable. A glass broken behind the bar with nobody hurt is a
|
||||
near miss if it happened because the floor was wet, and is not if it was simply
|
||||
dropped.
|
||||
|
||||
# How to report
|
||||
|
||||
Tell the supervisor on duty at the time. They record it before the end of the
|
||||
shift — a report written the next day loses the detail that made it useful, and
|
||||
the people who saw it have gone home.
|
||||
|
||||
An incident involving injury, the police, or a safeguarding concern also goes to
|
||||
the venue manager the same day, whatever the hour.
|
||||
|
||||
# Escalation
|
||||
|
||||
| Situation | Who decides | By when |
|
||||
|---|---|---|
|
||||
| Guest refused service, escalating | Supervisor on duty | Immediately |
|
||||
| Physical altercation | Venue manager, and police if ongoing | Immediately |
|
||||
| Injury needing more than first aid | Venue manager | Same day |
|
||||
| Safeguarding concern about a young person | Venue manager, then designated lead | Same day |
|
||||
| Allegation against a member of staff | Venue manager, do not investigate on the floor | Same day |
|
||||
|
||||
# Safeguarding
|
||||
|
||||
Anyone under 18 working an event is not left alone with guests and does not
|
||||
serve alcohol. Where an event is for under-18s, at least one supervisor holds a
|
||||
current safeguarding certificate.
|
||||
|
||||
A concern about a young person — staff or guest — is passed on the same day.
|
||||
Passing it on is the whole obligation; deciding whether it is serious enough is
|
||||
not the reporter's job and never has been.
|
||||
|
||||
# After an incident
|
||||
|
||||
The worker involved is offered a conversation the following working day. This is
|
||||
not an investigation and is not recorded against them. A worker who has had a
|
||||
bad night and hears nothing usually concludes the venue did not notice.
|
||||
45
knowledge/overtime-and-working-time.md
Normal file
45
knowledge/overtime-and-working-time.md
Normal file
@@ -0,0 +1,45 @@
|
||||
---
|
||||
source: policy_docs
|
||||
audience: tenant
|
||||
title: Overtime and Working Time
|
||||
---
|
||||
|
||||
# What counts as overtime
|
||||
|
||||
Overtime is time worked beyond the scheduled end of a shift. It begins at the
|
||||
scheduled end, not at the point the worker expected to leave, and it is recorded
|
||||
in fifteen-minute blocks rounded up.
|
||||
|
||||
Time spent waiting to be released at the end of an event is working time. A
|
||||
worker held back to clear a room is on overtime from the scheduled end, whether
|
||||
or not they were serving.
|
||||
|
||||
# Approval
|
||||
|
||||
Overtime beyond thirty minutes needs a supervisor's approval at the time it is
|
||||
worked. Approval after the fact is possible but is the exception, and a venue
|
||||
where most overtime is approved retrospectively is a venue with a rota problem
|
||||
rather than an approval problem.
|
||||
|
||||
A supervisor may approve up to two hours. Beyond that needs the venue manager.
|
||||
|
||||
# Weekly limits and rest
|
||||
|
||||
No worker is scheduled beyond 48 hours in a week averaged over 17 weeks. A
|
||||
worker may opt out in writing and may withdraw that opt-out with seven days'
|
||||
notice.
|
||||
|
||||
There must be eleven consecutive hours between the end of one shift and the
|
||||
start of the next. A shift ending at 2am cannot be followed by one starting
|
||||
before 1pm the same day. The rota should not offer it; if it does, the offer is
|
||||
declined without prejudice to the worker.
|
||||
|
||||
A break of twenty minutes applies to any shift over six hours, taken away from
|
||||
the service floor and not at the end of the shift.
|
||||
|
||||
# When overtime is climbing
|
||||
|
||||
Sustained overtime is a rota signal, not an individual one. Where overtime per
|
||||
scheduled shift has risen for several weeks running, the venue manager reviews
|
||||
headcount for that role before approving further overtime — the cheapest hour of
|
||||
overtime is still more expensive than the shift that should have been rostered.
|
||||
44
knowledge/right-to-work-and-certification.md
Normal file
44
knowledge/right-to-work-and-certification.md
Normal file
@@ -0,0 +1,44 @@
|
||||
---
|
||||
source: policy_docs
|
||||
audience: role:admin, role:employer
|
||||
title: Right to Work and Certification Checks
|
||||
---
|
||||
|
||||
# Before a first shift
|
||||
|
||||
No worker starts a first shift without a completed right-to-work check. This is
|
||||
not a paperwork step that can follow the shift: the obligation is on the
|
||||
business, the penalty falls on the business, and a shift worked before the check
|
||||
cannot be undone by completing it afterwards.
|
||||
|
||||
The check is a sight of the original document, or a share code verified against
|
||||
the online service, recorded with the date and the name of whoever checked it.
|
||||
A photograph sent by message is not a check.
|
||||
|
||||
# Documents that expire
|
||||
|
||||
Where a document carries an expiry date, the worker's record carries the same
|
||||
date and they stop being offered shifts seven days before it. Seven days rather
|
||||
than on the day, because a licence renewed on the morning of a shift is a licence
|
||||
that was not in place when the rota was published.
|
||||
|
||||
# Role-specific certification
|
||||
|
||||
| Role | Required before first shift | Renewal |
|
||||
|---|---|---|
|
||||
| Security officer | SIA licence, valid and in date | Three years |
|
||||
| Bar staff serving alcohol | Personal licence where required by venue | Venue-specific |
|
||||
| Kitchen and food handling | Level 2 Food Safety | Three years |
|
||||
| Supervisors | First aid at work | Three years |
|
||||
|
||||
A worker whose certification lapses is not removed from the pool. They stop
|
||||
being offered shifts for roles that require it and remain eligible for roles that
|
||||
do not, which is usually the difference between losing a good worker and losing
|
||||
three weeks of their availability.
|
||||
|
||||
# Recording a check
|
||||
|
||||
Checks are recorded against the worker profile, not against the shift. A check
|
||||
done for one venue is valid across the organisation — asking a worker to prove
|
||||
the same thing at each site is how a pool of willing people becomes a pool of
|
||||
people who work somewhere else.
|
||||
51
knowledge/screening-and-hiring-standards.md
Normal file
51
knowledge/screening-and-hiring-standards.md
Normal file
@@ -0,0 +1,51 @@
|
||||
---
|
||||
source: policy_docs
|
||||
audience: role:admin, role:employer
|
||||
title: Screening and Hiring Standards
|
||||
---
|
||||
|
||||
# What the match score means
|
||||
|
||||
The AI match score is a reading of an application against a role's stated
|
||||
requirements. It is a starting point for a decision, not the decision.
|
||||
|
||||
| Band | Reading | Expected action |
|
||||
|---|---|---|
|
||||
| 80 and above | Strong match on stated requirements | Shortlist |
|
||||
| 70 to 79 | Viable, usually with one gap | Shortlist if the gap is trainable |
|
||||
| 50 to 69 | Marginal | Read the application before deciding |
|
||||
| Below 50 | Weak against this role | Consider for other open roles |
|
||||
| No score | Not yet screened | Screen before deciding anything |
|
||||
|
||||
A candidate with no score has not been assessed. They are not a candidate who
|
||||
scored badly, and they must never be ranked as though they were — an unscored
|
||||
applicant sitting below a 40 in a sorted list is a reading error, not a
|
||||
judgement.
|
||||
|
||||
# Screening is not a decision
|
||||
|
||||
Screening moves an application from applied to screened. It does not reject
|
||||
anybody. A rejection is a decision a person takes, records a reason for, and can
|
||||
explain to the candidate if asked.
|
||||
|
||||
Rejecting on the score alone is not a reason. "Below the bar for this role"
|
||||
without a stated requirement it failed is the same as no reason at all.
|
||||
|
||||
# Time to decision
|
||||
|
||||
Every applicant gets a decision within ten working days of applying. Where a
|
||||
role is paused, the applicant is told it is paused rather than left in the
|
||||
pipeline — a candidate who hears nothing assumes a no and takes another job,
|
||||
which costs the same as a rejection while looking like nothing happened.
|
||||
|
||||
Candidates at interview stage get a decision within three working days of the
|
||||
interview.
|
||||
|
||||
# Interviews
|
||||
|
||||
An interview is required before hiring into a supervisory role. For general
|
||||
staff it is optional and should be used where the application leaves a specific
|
||||
question open, not as a default gate.
|
||||
|
||||
Interview notes are recorded against the application. A hire with no notes is a
|
||||
hire nobody can explain in six months.
|
||||
51
knowledge/shift-cover-and-cancellation.md
Normal file
51
knowledge/shift-cover-and-cancellation.md
Normal file
@@ -0,0 +1,51 @@
|
||||
---
|
||||
source: policy_docs
|
||||
audience: tenant
|
||||
title: Shift Cover and Cancellation
|
||||
---
|
||||
|
||||
# Filling an open shift
|
||||
|
||||
A shift is open from the moment it is published without a name against it. Open
|
||||
shifts are offered in this order, and the order is not a preference — skipping a
|
||||
step is what produces a rota nobody trusts:
|
||||
|
||||
1. Staff already rostered at that venue who are under their weekly hours.
|
||||
2. Staff at other venues in the same region with the required certification.
|
||||
3. The wider talent pool, filtered to those whose availability covers the window.
|
||||
|
||||
An offer stands for four hours during the working day, or until 9am the next
|
||||
morning if it is sent after 6pm. After that it lapses and moves to the next
|
||||
group. Do not hold an offer open longer in the hope of a better answer — the
|
||||
person who would have taken it has usually accepted something else by then.
|
||||
|
||||
# Late cover
|
||||
|
||||
A shift falling open inside 24 hours of its start is late cover. Late cover may
|
||||
be offered to all three groups at once rather than in order, because the cost of
|
||||
an unfilled shift now exceeds the cost of an imperfect match.
|
||||
|
||||
Late cover attracts a premium of one and a half times the base rate for the
|
||||
whole shift, not only the hours inside the 24-hour window.
|
||||
|
||||
# Cancelling a shift
|
||||
|
||||
Cancelling a worker's confirmed shift with less than 48 hours' notice obliges
|
||||
the venue to pay four hours at the base rate, whether or not the worker is
|
||||
re-deployed elsewhere. Inside 12 hours it is the full scheduled length.
|
||||
|
||||
This applies to cancellations the venue initiates. A shift cancelled because the
|
||||
event itself was called off by the client is still a venue cancellation — the
|
||||
client's decision does not transfer the cost to the worker.
|
||||
|
||||
# When a worker cancels
|
||||
|
||||
A worker withdrawing from a confirmed shift should do so as early as possible
|
||||
through the app. Withdrawals inside 12 hours are recorded against the worker's
|
||||
reliability, and three in a rolling quarter trigger a conversation with the
|
||||
venue manager before further shifts are offered.
|
||||
|
||||
A withdrawal for a reason covered by the sickness or emergency provisions in the
|
||||
staff handbook is not recorded against reliability. The manager records the
|
||||
reason at the time; a reason supplied a week later cannot be verified and will
|
||||
not be applied retrospectively.
|
||||
Reference in New Issue
Block a user