Discussion #15139 graduated a provider-neutral, durable repo-external community-activity authority after five cross-family cycles. Epic #15145 is the coordination parent; this docs-only leaf is the authority transition and must merge before implementation.
This is one fully closeable PR leaf under Epic #15145. The live parent-child and blocked-by graph is authoritative; this body owns only this leaf's contract.
The Problem
Without a durable record, later implementers would reconstruct the design from the shorter Epic body and can silently collapse distinct identities, promote accelerators to authority, invent thresholds, or weaken tenant and Task boundaries. That is the exact failure mode this decomposition is preventing.
The Architectural Reality
The record belongs in learn/agentos/decisions/. It must preserve ADR 0015's single-Memory-Core SQLite/WAL posture, ADR 0019's AiConfig SSOT boundary, and ADR 0035's zero-authority Bird-View/LifecycleFrontier boundary. It must also add the mandatory ADR 0031 seam-table row and Architecture Overview pointers for the affected Memory Core, GitHub Workflow, Orchestrator, MCP, and content-trust rows.
The Agent OS structure map was run on 2026-07-14. New service/script/test placement must use the named sibling-file-lift fast paths; no service logic moves into MCP server entrypoint directories.
The Fix
Author ADR 0036 with the normalized identity model, source-registration lifecycle, exhaustive reconciliation authority, neutral admission transaction, local/hosted connector topology, tenant/source-relative trust, provider-neutral Bird View, per-viewer seen semantics, atomic source-event-to-Task transition, shadow-first measurement gate, explicit migration order, and empirical revalidation triggers.
K/O/V/X and accelerators E/F remain conditional with named falsifiers
No speculative implementation authority
ADR revalidation section
Review verifies every option disposition
Existing ADR composition
ADRs 0015, 0019, 0035
Keep all three in force; state exact seams and reopen triggers
No silent supersession
ADR relationship table
Cross-family architecture review
Decision Record impact
Creates ADR 0036; depends on ADR 0015, aligns with ADR 0019, and composes ADR 0035 without superseding them.
Decision Record
Required: ADR 0036 (this leaf). The human merge gate accepting the record is the implementation-authority transition.
Discussion Criteria Mapping
Upstream graduated criterion
This leaf's executable contract
OQ1
Source occurrence, attention eligibility, actor/trust classification, excluded telemetry, and explicit-claim authority become separate normative contracts.
OQ2-OQ4
Completeness, identity/replay, and durable-owner contracts become normative sections.
OQ5-OQ9
Seen/claim, Bird View, trust, deployment, registration, and local/hosted authority boundaries become normative sections.
OQ10 + STEP_BACK
Shadow measurement is first implementation; tenant-relative trust and atomic sourceEventId-to-taskId are hard gates.
24-option convergence
Every adopt/reject/defer disposition and residual-risk trigger is retained.
The community substrate is not a mirror of every GitHub repository notification. It separates:
source occurrences needed to reconstruct supported issue, pull-request/review, and Discussion conversation state; and
attention-eligible community items: externally authored, response-bearing occurrences that may need maintainer attention.
Stars/un-stars, forks, watches, and equivalent popularity telemetry are outside the community-event source families and cannot enter Bird View, counts, wake, or Task claim. Internal/rostered actions may update or resolve the state of an existing external item without minting new community attention. First-time versus trusted-repeat external status affects trust/projection, not basic eligibility. Bot eligibility must be an explicit ADR disposition and cannot be inferred from provider actor kind or trust tier.
Attention eligibility remains zero-authority: it does not assign work, enter LifecycleFrontier, or create a Task. Only the explicit canonical claim transition owns that promotion.
Acceptance Criteria
AC1 — ADR 0036 records all selected options and all rejected/deferred shapes without changing their disposition.
AC2 — The three Grace STEP_BACK partials are normative implementation gates, not advisory notes.
AC3 — ADR 0015/0019/0035 relationships and reopen triggers are explicit.
AC4 — The first-merge/first-implementation distinction is explicit: ADR first, shadow instrumentation first code.
AC5 — ADR 0031 seam table and Architecture Overview map pointers are updated in the same PR.
AC6 — The Discussion #15139 Signal Ledger, liveness revalidation, and source criteria are citeable from the record.
AC7 — Cross-family review verifies option-by-option fidelity before human merge.
AC9 — Stars/un-stars, forks, watches, and equivalent popularity telemetry are explicitly excluded, with no accelerator allowed to re-admit them.
AC10 — The actor matrix dispositions internal/rostered identities, first-time and trusted-repeat external humans, and bots without deriving eligibility from actor kind or trust tier alone.
Out of Scope
Any runtime code, schema migration, connector, tool, threshold, or wake behavior.
Avoided Traps
Do not convert GraphLog or Native Edge Graph into permanent history; do not use AiConfig or the KB SourceRegistry as operational registration; do not pre-authorize K/O/V/X; do not let the Epic body become the sub registry.
Creation duplicate sweep: immediately before filing at 2026-07-14T05:29:53.918Z, checked the latest 20 open issues and last 30 all-state A2A messages. The independent broader audit at 2026-07-14T05:13:00Z covered open and closed issues, pull requests, A2A, ADRs, and code; no equivalent owner or foreign claim existed.
Context
Discussion #15139 graduated a provider-neutral, durable repo-external community-activity authority after five cross-family cycles. Epic #15145 is the coordination parent; this docs-only leaf is the authority transition and must merge before implementation.
This is one fully closeable PR leaf under Epic #15145. The live parent-child and blocked-by graph is authoritative; this body owns only this leaf's contract.
The Problem
Without a durable record, later implementers would reconstruct the design from the shorter Epic body and can silently collapse distinct identities, promote accelerators to authority, invent thresholds, or weaken tenant and Task boundaries. That is the exact failure mode this decomposition is preventing.
The Architectural Reality
The record belongs in
learn/agentos/decisions/. It must preserve ADR 0015's single-Memory-Core SQLite/WAL posture, ADR 0019's AiConfig SSOT boundary, and ADR 0035's zero-authority Bird-View/LifecycleFrontier boundary. It must also add the mandatory ADR 0031 seam-table row and Architecture Overview pointers for the affected Memory Core, GitHub Workflow, Orchestrator, MCP, and content-trust rows.The Agent OS structure map was run on 2026-07-14. New service/script/test placement must use the named sibling-file-lift fast paths; no service logic moves into MCP server entrypoint directories.
The Fix
Author ADR 0036 with the normalized identity model, source-registration lifecycle, exhaustive reconciliation authority, neutral admission transaction, local/hosted connector topology, tenant/source-relative trust, provider-neutral Bird View, per-viewer seen semantics, atomic source-event-to-Task transition, shadow-first measurement gate, explicit migration order, and empirical revalidation triggers.
Contract Ledger Matrix
Decision Record impact
Creates ADR 0036; depends on ADR 0015, aligns with ADR 0019, and composes ADR 0035 without superseding them.
Decision Record
Required: ADR 0036 (this leaf). The human merge gate accepting the record is the implementation-authority transition.
Discussion Criteria Mapping
Source authority: Discussion #15139 body at the version-bound graduation anchor plus Grace's STEP_BACK and GRADUATION_APPROVED.
Operator Scope Clarification — 2026-07-14
The community substrate is not a mirror of every GitHub repository notification. It separates:
Stars/un-stars, forks, watches, and equivalent popularity telemetry are outside the community-event source families and cannot enter Bird View, counts, wake, or Task claim. Internal/rostered actions may update or resolve the state of an existing external item without minting new community attention. First-time versus trusted-repeat external status affects trust/projection, not basic eligibility. Bot eligibility must be an explicit ADR disposition and cannot be inferred from provider actor kind or trust tier.
Attention eligibility remains zero-authority: it does not assign work, enter LifecycleFrontier, or create a Task. Only the explicit canonical claim transition owns that promotion.
Acceptance Criteria
AC1 — ADR 0036 records all selected options and all rejected/deferred shapes without changing their disposition.
AC2 — The three Grace STEP_BACK partials are normative implementation gates, not advisory notes.
AC3 — ADR 0015/0019/0035 relationships and reopen triggers are explicit.
AC4 — The first-merge/first-implementation distinction is explicit: ADR first, shadow instrumentation first code.
AC5 — ADR 0031 seam table and Architecture Overview map pointers are updated in the same PR.
AC6 — The Discussion #15139 Signal Ledger, liveness revalidation, and source criteria are citeable from the record.
AC7 — Cross-family review verifies option-by-option fidelity before human merge.
AC8 — ADR 0036 normatively distinguishes source occurrence, attention eligibility, and explicit Task claim authority.
AC9 — Stars/un-stars, forks, watches, and equivalent popularity telemetry are explicitly excluded, with no accelerator allowed to re-admit them.
AC10 — The actor matrix dispositions internal/rostered identities, first-time and trusted-repeat external humans, and bots without deriving eligibility from actor kind or trust tier alone.
Out of Scope
Any runtime code, schema migration, connector, tool, threshold, or wake behavior.
Avoided Traps
Do not convert GraphLog or Native Edge Graph into permanent history; do not use AiConfig or the KB SourceRegistry as operational registration; do not pre-authorize K/O/V/X; do not let the Epic body become the sub registry.
Related
Origin Session ID: 837ad74b-c2d2-413d-9aab-b7165a93a82a
Handoff Retrieval Hints
ADR 0036 community activity authority H I J tenant source registrationDiscussion 15139 sourceEventId taskId shadow measurementCreation Freshness
Creation duplicate sweep: immediately before filing at 2026-07-14T05:29:53.918Z, checked the latest 20 open issues and last 30 all-state A2A messages. The independent broader audit at 2026-07-14T05:13:00Z covered open and closed issues, pull requests, A2A, ADRs, and code; no equivalent owner or foreign claim existed.