Enhance suitability assessment and documentation

- Implemented `check_suitability` method in `CoreReadOnlyRepository` for suitability determination based on customer and product risk levels.
- Added `build_suitability_log_row` function in `suitability.py` for mapping suitability check results to `risk_suitability_log`.
- Updated `AGENTS.md`, `ENVIRONMENT.md`, and `FLOW.md` to reflect changes in suitability assessment processes and documentation.
- Revised `FRAMEWORK.md` and `MEMORY.md` to clarify project structure and data flow related to suitability checks.
- Expanded `TODO.md` with tasks related to logging and auditing suitability assessments.
This commit is contained in:
2026-09-07 11:15:30 +08:00
parent 1ddd44a6cb
commit 3fb0ceb334
44 changed files with 7479 additions and 250 deletions
+10 -7
View File
@@ -9,7 +9,8 @@
## 本轮范围
- **目的:** 四 Agent 服务四类人群,统一数据层 + 合规底座,可对话闭环。
- **明确不做:** 自动交易、营销推荐、Agent 互调 LLM、自动冻户、Streamlit、P3 平台能力。
- **明确不做:** 自动交易、**营销式**推荐(千人千面话术/优劣对比/「强烈推荐」)、Agent 互调 LLM、自动冻户、Streamlit、P3 平台能力。
- **允许(客户 Agent):** 按客户 C1~C5 与产品 R 等级/期限/起购做 **适当性匹配说明**(C-07 P1、C-11 P2),须联动风控 R-02;**不是**投顾式推荐或买卖指导。
------
@@ -20,11 +21,11 @@
| F-01 | JWT + RBAC + 数据归属 | 越权 403 + audit;JWT 手册 §13 | 未做 | T-01 |
| F-02 | 全量审计留痕 | trace_id 可还原 | 未做 | T-02 |
| F-03 | 输入防护 | input_guard_log | 未做 | T-03 |
| F-04 | Core 只读层 | 不改 Core 账;Repository 只 SELECT | **部分** | T-04 |
| R0-DB | MySQL 共用 11 表 + Redis | 01-mysql-共用底座.sql | SQL 已定;灌库待验 | T-05 |
| R0-CORE | Core 模拟 + 同步 | reset.ps1 + sync 脚本 | **脚本已落地** | T-05 |
| F-04 | Core 只读层 | 不改 Core 账;Repository 只 SELECT | **大部分** | T-04 |
| R0-DB | MySQL 共用 11 表 + Redis | 01-mysql-共用底座.sql;`risk_suitability_log` P0 字段已定 | SQL 已定;灌库待验 | T-05 |
| R0-CORE | Core 模拟 + 同步 | reset.ps1 + sync;33 客户 / 14 产品 / KYC / C×R 矩阵 | **脚本已落地** | T-05 |
**F-04 部分完成说明:** `app/repository/core_ro.py` + `scripts/core/*` + `settings.mysql_core_database` 已有;尚未接入 api/service Tool 与归属校验。
**F-04 大部分完成说明:** `core_ro.py`(含 `check_suitability`)+ `scripts/core/*` + `settings.mysql_core_database` 已有;`suitability.py` 映射 log 行已定。尚未接入 api/service Tool 与归属校验。
## Wave 1 · 内部 Agent P0
@@ -38,13 +39,15 @@
| ID | 需求 | 验收对照 | 状态 | TODO |
| --- | --- | --- | --- | --- |
| R-01 | 大额预警 | risk_alert pending_review | 未做 | T-30 |
| R-02 | 适当性阻断请求 | 唯一阻断场景 | 未做 | T-31 |
| R-02 | 适当性阻断请求 | 唯一阻断场景;log 表 + 映射代码已定 | **契约已定** | T-31 |
| R-03 | AML 命中通知 | 不自动冻户 | 未做 | T-32 |
## Wave 3 · 客户 P0
| ID | 需求 | 验收对照 | 状态 | TODO |
| --- | --- | --- | --- | --- |
| C-01~C-05 | 持仓/产品/规则/阈值/净值 | 无买卖指导 | 未做 | T-40 |
| C-01~C-05 | 持仓/产品/规则/阈值/净值 | 无买卖指导;P0 不含匹配推荐 | 未做 | T-40 |
| C-07 | 风格测评 + 同类方向事实清单 | 须 R-02 适当性;无买卖指令 | 未做 | T-41 |
| C-11 | 按风险/期限/起购做匹配说明 | 非营销话术;不替代投顾 | 未做 | T-42 |
P1+ 见 `docs/需求拆解/业务场景优先级清单.md` §3。