Governance Model
starnum.com.tw's platform decision framework: human-led, AI-assisted.
Version 1.0 · Effective date:
Governance Philosophy
starnum.com.tw operates under a human-led, AI-assisted model. The human operator (mychenan) retains final decision authority over all matters. AI systems provide suggestions, cross-validation, and automation, but may not autonomously implement policy changes.
Core principle: Quality and ethics take priority over speed. No roadmap pressure may override content quality standards.
Three-Tier Decision Process
Tier 1: Routine Operations (Autonomous)
The following are handled automatically by the state machine (run-master.js) without human approval:
- Article production (within existing guidelines)
- Daily quality audits
- Certificate rotation
- Knowledge base maintenance
- Performance monitoring
Tier 2: Standard Decisions (Human Approval Required)
The following require human operator review before implementation:
- New content categories or topics
- Quality threshold adjustments (current: below 70 triggers weekly fix, below 60 triggers same-day fix)
- New script deployments
- Dependency updates (major versions)
- Knowledge base source additions
Process:
- 1AI proposes change (via proposed-rules.json or direct suggestion)
- 2multi-provider governance audit vote (FIX / SKIP / DEFER)
- 3Human operator reviews vote summary
- 4Implemented after human approval
- 548-hour monitoring period post-implementation
Tier 3: Major Decisions (Extended Review)
The following require extended deliberation:
- Architecture changes affecting multiple systems
- New external service integrations
- Privacy policy changes
- Ethics policy modifications
- Pricing or business model changes
- Any change matching L3_MAJOR_PATTERNS in run-master.js
Process:
- 1Proposal logged in NOTEPAD.md
- 2multi-provider governance audit: full 52-preset evaluation
- 3Human operator review, 7-day consideration period
- 4Implemented with complete rollback plan
- 57-day monitoring period post-implementation
Conflict Priority Order
When guidelines conflict, the following hierarchy applies:
-
1EthicsDo not produce content that may cause psychological harm, discrimination, or facilitate crime
-
2Content QualityAccuracy and depth take priority over volume or speed
-
3Astrology Logic127 hard rules enforced (no impossible events produced)
-
4SEOOptimization for organic search discoverability
-
5TechnicalTechnical performance and operational efficiency
Example: If an SEO optimization requires arguing against astrology logic, astrology logic takes precedence.
Issue Severity & Response Schedule
Issues are classified by severity and handled according to the following schedule:
| Severity | Definition | Response Time |
|---|---|---|
| Critical | Data loss, security breach, site outage | Immediate (within 1 hour) |
| High | Any article quality score below 60, ethics violation | Same day |
| Medium | Quality score 60–70, broken links, missing translations | Within 1 week |
| Low | Style improvements, minor SEO, nice-to-have features | Next roadmap cycle |
The fix queue is recorded in data/fix-queue.json and reviewed weekly.
AI System Governance
Approved AI Systems
| System | Role | Authorization Level |
|---|---|---|
| Claude Sonnet 4.5 | Primary production | Read + Write (human review) |
| OpenAI model documentation | Quality audit | Read-only (voting) |
| Google Gemini model documentation | Quality audit | Read-only (voting) |
| legacy xAI benchmark | Quality audit | Read-only (voting) |
What AI Systems May Do Autonomously
- Generate article drafts
- Run quality audits
- Update state files (data/state-machine/)
- Run maintenance scripts
- Generate reports
What AI Systems May NOT Do
- Write directly to the Supabase production database
- Push to the GitHub main branch
- Modify ethics.html, acceptable-use.html, or this GOVERNANCE document without human review
- Make pricing decisions
- Approve their own output for publication (always requires human review)
AI Audit Quorum
A joint audit finding requires a majority vote from all four (3/4 or 4/4) of Claude, OpenAI model documentation, Gemini, and legacy xAI benchmark to be classified as FIX. SKIP or DEFER requires a minority. A single AI conclusion without cross-validation is treated as a suggestion, not a mandate.
Transparency Commitments
The following documents are always publicly accessible:
| Document | Update Frequency |
|---|---|
| Methodology page | Quarterly or on major changes |
| model-card.html | On capability changes |
| system-card.html | Quarterly |
| Quality benchmarks | Monthly |
| ethics.html | On policy changes |
| Roadmap | Quarterly |
| CHANGELOG.md | Every release |
| Research blog | On research completion |
Rule Lifecycle
Rules in the system follow a defined lifecycle (managed by scripts/rule-lifecycle.js):
↘ REJECTED
- Proposed: Generated from failure analysis or AI suggestions
- Pending Review: Submitted to joint audit
- Approved: Approved by human or 4/4 audit
- Auto-Applied: Technical rules applied to skill packs
- Deprecated: Rules not triggered within 90 days are removed
Rules never triggered within 90 days are deprecation candidates, preventing the rule base from expanding indefinitely.
Contact & Contributions
- Feature requests: Instagram @mychenan
- Security issues: Instagram DM @mychenan (see security-policy.html)
- Ethics concerns: Instagram @mychenan
- General matters: Contact form on the About page
This platform does not accept external code contributions. All implementation is handled internally. Research collaboration inquiries are welcome.
External standards and primary sources
These primary sources inform this page. They are benchmarks, not third-party endorsements of this site.
Current Machine Audit Snapshot
This block uses only traceable local audit data. No unsupported metrics or model claims are added.
- data/state-machine/i18n-parity.json: 8,036 parent URLs, 7,976 articles.
- data/kb-machine-audit.json: 3,238 source files, 0 missing coverage, 0 orphan chunks.
- data/discovery-surface-audit.json: 0 errors, 0 warnings.
- data/sla-report.json: critical / 5 critical, 0 warnings.
Verifiable Evidence Layer
This block is not a narrative claim. Each core assertion has a claim id, source JSON, hash, and a repeatable verification command. Public pages disclose governance evidence without exposing source code, secrets, private data, or exploitable attack details.
| Claim ID | Verifiable value | Status | Owner | Source and verification |
|---|---|---|---|---|
| claim.public-url-manifest.indexable-count Public URL and canonical inventory |
38,965 indexable URLs | verified | sitewide | node scripts/generate-public-evidence-manifest.js --dry |
| claim.trust-pages.audit-pass-rate Trust page machine audit |
180/180 pass | verified | sitewide | node scripts/verify-trust-pages.js --check |
| claim.discovery-surface.zero-errors AI discovery surface audit |
{"errors":0,"warnings":0} | verified | sitewide | node scripts/verify-discovery-surface.js |
| claim.structured-data.jsonld-errors JSON-LD / structured data audit |
{"structured_data_invalid_files":0,"breadcrumb_count":28274,"faq_count":27506,"dataset_count":30,"article_count":27406} | verified | sitewide | node scripts/site-machine-audit.js |
| claim.status.sla-state Status page SLA source |
critical / 5 critical, 0 warnings | verified | sitewide | node scripts/generate-status-page.js |
| claim.provider-alignment.openai-anthropic-gemini OpenAI / Anthropic / Google Gemini benchmark alignment |
benchmark alignment only unless code/config evidence exists | verified | sitewide | node scripts/verify-public-evidence.js --check |
| claim.transparency-report.sha256 Transparency report SHA-256 anchor |
{"report":"transparency/report-2026-Q3.json","sha256":"47b09e2ca4e8b8fe9dffdfaccef3b11212de9ee3a8a14badca8044e2481203c5"} | verified | sitewide | node scripts/update-transparency-current-data.js |
| claim.release-integrity.gpg-signing GPG signing status |
GPG signing configured locally; GitHub verification pending | github_verification_pending | sitewide | gpg --list-secret-keys --keyid-format=long && git log -1 --show-signature |
System Card V2.0: Technical Transparency Layer
This layer publishes the technical governance evidence that can be safely disclosed: architecture, data sources, AI-use boundaries, quality gates, release integrity, and provider alignment. Source code, secrets, exploitable attack details, and private data remain out of scope.
Public architecture
Cloudflare Pages/Workers, R2/D1/KV/Pagefind, and local generation scripts form the public-site and governance publication chain. Public pages disclose behavior, state, and traceable sources, not secrets or internal permissions.
AI-use disclosure
AI-assisted workflows are used for knowledge-base retrieval, cross-checking, and error detection. Governance documents are benchmarked against OpenAI, Anthropic, and Google Gemini public frameworks. Production model usage is disclosed only when code/config evidence exists.
Quality and safety gates
Governance page audit 180/180 passing, JSON-LD errors 0, discovery-surface errors 0. Status pages report critical / 5 critical, 0 warnings as-is.
Data traceability
Knowledge base 32,724 chunks, TM 789,031 entries, AI answer-ready 7,976/7,976. Public metrics trace to data/state-machine/*, data/*audit*.json, and transparency reports.
| Governance area | OpenAI | Anthropic | Google Gemini | Starnum implementation evidence |
|---|---|---|---|---|
| Model/system-card disclosure | OpenAI models + safety docs | Claude model docs + system/model cards | Gemini model docs + safety settings | system-card, model-card, methodology, benchmark, transparency-log |
| Safety evaluation and use boundaries | Safety best practices / deployment checklist | Responsible Scaling / safety policy | Gemini safety controls / policy | AI safety, acceptable-use, ethics, risk-boundary copy, crawler policy audit |
| Data governance | Data controls / privacy controls | privacy and data handling docs | Gemini API data governance references | privacy, ai-data-governance, KB/TM source tracking, SHA-256 hashes |
| Monitoring and release | production checklist / eval discipline | system-card transparency discipline | model/version documentation discipline | deploy.js, status.html, SLA report, trust-pages-machine-audit, sitemap/hreflang audits |
- Sources: data/state-machine/model-card.json, public-bench.json, trust-pages.json, security-headers.json.
- Sources: data/trust-pages-machine-audit.json, data/discovery-surface-audit.json, data/ai-answer-readiness-audit.json.
- Sources: data/kb-machine-audit.json, data/tm/quality-audit-report.json, data/sla-report.json.
- Official benchmark docs checked: 2026-07-30; links are listed in the OpenAI / Anthropic / Google Gemini alignment table.
The V2.0 goal is not more claims; it separates implemented controls from planned controls. Production usage, benchmark alignment, status exceptions, GPG signing, and SLA breaches are disclosed from source data.
Release Integrity And GPG
GPG signing configured locally. signingkey=0934DFA0EDA6363A. GitHub verification pending until the public key upload and Verified badge are confirmed.
OpenAI / Anthropic / Google Gemini Alignment
The governance surface is benchmarked against the three public frameworks: model docs, system/model cards, safety evaluation, data governance, and use policies. This is benchmark alignment, not a claim that every provider is active in production inference. Official docs checked: 2026-07-30
| Provider | Governance focus | Starnum disclosure | Official source |
|---|---|---|---|
| OpenAI | Model documentation, latest model notes, safety best practices, and data controls. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://platform.openai.com/docs/models |
| Anthropic | Claude model documentation, system/model cards, Responsible Scaling, and safety policy. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://docs.anthropic.com/en/docs/about-claude/models |
| Google Gemini | Gemini API model documentation, safety settings, data governance, and platform policy. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://ai.google.dev/gemini-api/docs/models |