Skip to content

Add guarded analytics MCP authority and native delivery - #870

Open
shahryar-internal wants to merge 29 commits into
yc-software:mainfrom
shahryar-internal:codex/analytics-current-integration-public-safe-20260830
Open

Add guarded analytics MCP authority and native delivery#870
shahryar-internal wants to merge 29 commits into
yc-software:mainfrom
shahryar-internal:codex/analytics-current-integration-public-safe-20260830

Conversation

@shahryar-internal

@shahryar-internal shahryar-internal commented Aug 31, 2026

Copy link
Copy Markdown

Summary

  • add one-time founder-DM authority for a guarded analytics MCP tool
  • validate the discovered tool contract immediately before signed dispatch
  • render only closed, locally verified native Slack cards with durable idempotency
  • preserve forced transient Gemini precedence over individual model credentials
  • integrate the prerequisite durable delivery and runtime authority foundations

Safety

  • no provider credentials or organization-specific values are committed
  • public turns cannot supply trusted Slack identity or authority headers
  • analytics cards are signed, exact-target-bound, and verified again before rendering
  • unsupported or stale contracts fail closed

Verification

  • independent exact-tree review: code GO
  • focused affected suites: 416 checks passed before public-safe metadata rewrite
  • public-safe branch tree is byte-identical to the reviewed candidate
  • branch CI is running; live Chrome/Slack smoke remains a pre-merge activation check

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

ShahryarAbbasi and others added 29 commits August 28, 2026 00:18
Integrate the reviewed durable observer and web artifact work with signed schedule-fire authority. Fail closed on steering and orphan replay for durable scheduled runs so signed authority cannot be stripped during a terminal race.
Fail closed when orphan-signal provenance is unavailable, reject withdrawal of signed scheduled runs, and drain scheduled-run signals at the harness consumer boundary without invoking provider controls.
Only force an immediate signal drain for signed-run discard mode so unsigned run behavior remains unchanged.
Co-authored-by: Greg Jackson <gregj64@gmail.com>
@shahryar-internal
shahryar-internal marked this pull request as ready for review August 31, 2026 06:11
@shahryar-internal

Copy link
Copy Markdown
Author

Exact head 2df95bd4438c47dbce2e91aa70271e753fd2ecb1 passed the complete fork CI matrix: lint/Prettier/Knip/Oxlint, TypeScript, all five core shards, real Postgres tests, CLI, and all plugins. Evidence: https://github.com/shahryar-internal/qm/actions/runs/33362752022. Live activation remains separate and will use Chrome on macOS, not Firefox.

@shahryar-internal

Copy link
Copy Markdown
Author

@16francej This paired founder-analytics change is CODE-reviewed and the fork CI is fully green (run 33362752022). The Command Center counterpart is now deployed to dev in fail-closed mode; activation still waits on this upstream merge. When you have a moment, could you review/merge this PR? Maintainer edits are enabled.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants