Program.cs built the BIG-nummer reveal's audit resource ref as
"brief/" + ctx.Zorgverlener().Bsn. AuditAuthz persists that to the
AuthzAudit.Resource column in SQLite and /admin/audit renders it, so a BSN
reached durable storage and a UI on the one trail four documents describe as
data-minimised and PII-free — on the endpoint whose own comment promises the
audit carries no PII.
The ref is now "brief". Nothing is lost: BriefStore keys one brief per owner,
so the id named what the row's acting principal already implies.
The existing guard, The_audit_schema_carries_no_pii, asserts on column names,
so a BSN inside a column called Resource could never fail it. Added
No_audit_row_carries_a_subjects_bsn, which drives a denied reveal as a
non-default subject and scans every string field of every row for that BSN
and for DemoOwner — asserting on the two BSNs actually in play rather than a
\d{9} shape, since a hex correlation id can hold nine digits by chance.
Verified it goes red when only the Program.cs line is reverted.
AuditEntry.Actor on document audit rows holds a raw BSN too; that is a
different store and stays with RB-04.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Refactoring backlog — automated setup
What's in this package
refactor-backlog-setup/
setup.sh ← run this once, from the root of the target repo
agents/ ← source prompts (edit these if you need to tweak
scope/wording before running setup.sh)
_persistence-protocol.md
00-baseline.prompt.md
01-readability.prompt.md
02-testability.prompt.md
03-ddd-hexagonal.prompt.md
04-cqrs-light.prompt.md
05-bdd.prompt.md
06-adr-conformance.prompt.md
07-bio2-compliance.prompt.md
08-consolidation.prompt.md
09-implementation.prompt.md (template — one TICKET-ID per Phase 3 dispatch)
Usage
- Copy this
refactor-backlog-setup/folder into the root of the target repo (or reference it via a relative path). - Edit anything in
agents/if scope/exclusions need repo-specific detail (e.g. exact module paths, ADR folder location) — the prompts currently use the defaults agreed in the design conversation. - Run:
This creates
bash refactor-backlog-setup/setup.sh./refactor-backlog/with:_status.mdinitialized, all agentsnot_started00-baseline.mdthrough07-bio2-compliance.mdinitialized with headers99-backlog.mdempty, ready for Consolidationimplementation/folder for Phase 3 notesfinal-prompts/— every agent prompt with the persistence protocol already merged in. These are the exact prompts to dispatch — no manual copy-paste needed.
Dispatch order
- Dispatch
final-prompts/00-baseline.prompt.md(Opus). Wait for_status.md→ baseline: complete. - Dispatch the 7 Phase 1 prompts in parallel (Opus):
01through07. Each checks its own dependency in_status.mdbefore starting. - Once all 7 show
complete, dispatchfinal-prompts/08-consolidation.prompt.md(Opus). It writes99-backlog.mdand halts for human approval — check the file for anyADR-fixor BIO2-flagged tickets before proceeding. - For each approved ticket, copy
final-prompts/09-implementation.prompt.md, fill inTICKET-ID:, dispatch (Sonnet). Run tickets in parallel within a CD batch, sequential across batches, per theDepends oncolumn in99-backlog.md.
Re-running / resuming
Safe to re-run setup.sh only on a fresh workspace — it does not check for an
existing ./refactor-backlog/ and will overwrite _status.md and the phase
output files. If a run is already in progress, don't re-run setup.sh; just
re-dispatch the relevant final-prompts/*.prompt.md — each agent reads
_status.md and its own output file first and resumes from where it left off.