The Epic crosses provider acquisition, tenant registration, durable admission, local/hosted transport, trust, Bird View, seen, claim, and count projection. A separately closeable capstone proof prevents each green unit PR from collectively missing the graduated end-to-end authority contract.
This is one fully closeable PR leaf under Epic #15145. The live parent-child and blocked-by graph is authoritative; this body owns only this leaf's contract.
The Problem
Unit tests can all pass while rename forks identity, stale epochs admit, lost responses skip history, remote auth crosses tenants, prose leaks into automatic paths, or two peers create two canonical Tasks. Those are the exact wrong-shape failures that review-time prose cannot reliably catch.
The Architectural Reality
This is a test/evidence PR using existing unit/integration locations and real service seams; it introduces no production authority. It must exercise both local direct and hosted authenticated paths against isolated tenant/source fixtures and assert negative GraphLog/Native Edge Graph/LifecycleFrontier effects.
The Agent OS structure map was run on 2026-07-14. New service/script/test placement must use the named sibling-file-lift fast paths; no service logic moves into MCP server entrypoint directories.
The Fix
Add a deterministic multi-tenant, multi-source integration harness covering provider fixtures through reconciliation, registration, admission, receipt/checkpoint, Bird View/trust drill-down, seen, canonical Task claim, count projection, revocation, restart/replay, and local/hosted parity. Publish a criterion-to-test matrix.
The community substrate is not a mirror of every GitHub repository notification. It separates:
source occurrences needed to reconstruct supported issue, pull-request/review, and Discussion conversation state; and
attention-eligible community items: externally authored, response-bearing occurrences that may need maintainer attention.
Stars/un-stars, forks, watches, and equivalent popularity telemetry are outside the community-event source families and cannot enter Bird View, counts, wake, or Task claim. Internal/rostered actions may update or resolve the state of an existing external item without minting new community attention. First-time versus trusted-repeat external status affects trust/projection, not basic eligibility. Bot eligibility must be an explicit ADR disposition and cannot be inferred from provider actor kind or trust tier.
Attention eligibility remains zero-authority: it does not assign work, enter LifecycleFrontier, or create a Task. Only the explicit canonical claim transition owns that promotion.
Acceptance Criteria
AC1 — At least two tenants and multiple sources prove strict isolation on registration, admission, query, seen, claim, and counts.
AC2 — Repository rename and grant rotation preserve sourceInstanceId; revoked/stale epochs reject writes.
AC3 — Crash before/after admission receipt and lost-response retry converge without loss or duplicate history.
AC4 — Local direct and hosted authenticated paths admit the same canonical batch and receipt semantics.
AC5 — Issue, PR/review, and Discussion fixtures prove coverage, explicit gaps, revisions, tombstones, and uncertain absence.
AC7 — Concurrent claims produce one sourceEventId-to-taskId binding and one canonical Task.
AC8 — Unclaimed events never enter LifecycleFrontier; community history never becomes Native Edge Graph/GraphLog authority.
AC9 — Degraded sources remain visible and never normalize to complete/zero.
AC10 — A public criterion-to-test matrix maps every OQ and STEP_BACK gate to executable evidence.
AC11 — An end-to-end noise-flood fixture combines star/fork/watch events, internal/rostered context, and one external response-bearing occurrence; only the external occurrence enters Bird View/count eligibility.
AC12 — An internal close/resolve occurrence can remove or resolve the existing external attention item without creating a second attention item or Task.
Out of Scope
New production features, threshold selection, conditional wake activation, GitLab implementation, Fleet UI, or HA topology.
Avoided Traps
Do not mock away tenant/auth/transaction seams, use one happy-path tenant, or treat unit-suite green as end-to-end proof.
community activity end to end tenant source claim replay
Discussion 15139 executable criteria matrix
Creation Freshness
Creation duplicate sweep: immediately before filing at 2026-07-14T05:32:12.123Z, checked the latest 20 open issues and last 30 all-state A2A messages. The independent broader audit at 2026-07-14T05:13:00Z covered open and closed issues, pull requests, A2A, ADRs, and code; no equivalent owner or foreign claim existed.
Context
The Epic crosses provider acquisition, tenant registration, durable admission, local/hosted transport, trust, Bird View, seen, claim, and count projection. A separately closeable capstone proof prevents each green unit PR from collectively missing the graduated end-to-end authority contract.
This is one fully closeable PR leaf under Epic #15145. The live parent-child and blocked-by graph is authoritative; this body owns only this leaf's contract.
The Problem
Unit tests can all pass while rename forks identity, stale epochs admit, lost responses skip history, remote auth crosses tenants, prose leaks into automatic paths, or two peers create two canonical Tasks. Those are the exact wrong-shape failures that review-time prose cannot reliably catch.
The Architectural Reality
This is a test/evidence PR using existing unit/integration locations and real service seams; it introduces no production authority. It must exercise both local direct and hosted authenticated paths against isolated tenant/source fixtures and assert negative GraphLog/Native Edge Graph/LifecycleFrontier effects.
The Agent OS structure map was run on 2026-07-14. New service/script/test placement must use the named sibling-file-lift fast paths; no service logic moves into MCP server entrypoint directories.
The Fix
Add a deterministic multi-tenant, multi-source integration harness covering provider fixtures through reconciliation, registration, admission, receipt/checkpoint, Bird View/trust drill-down, seen, canonical Task claim, count projection, revocation, restart/replay, and local/hosted parity. Publish a criterion-to-test matrix.
Contract Ledger Matrix
Decision Record impact
Depends on ADR 0036 and every required core implementation/evidence leaf; validates composition with ADRs 0015, 0019, and 0035.
Decision Record
Required: ADR 0036. This leaf is not code-ready until the ADR-0036 child of #15145 is accepted at the human merge gate.
Discussion Criteria Mapping
Source authority: Discussion #15139 body at the version-bound graduation anchor plus Grace's STEP_BACK and GRADUATION_APPROVED.
Operator Scope Clarification — 2026-07-14
The community substrate is not a mirror of every GitHub repository notification. It separates:
Stars/un-stars, forks, watches, and equivalent popularity telemetry are outside the community-event source families and cannot enter Bird View, counts, wake, or Task claim. Internal/rostered actions may update or resolve the state of an existing external item without minting new community attention. First-time versus trusted-repeat external status affects trust/projection, not basic eligibility. Bot eligibility must be an explicit ADR disposition and cannot be inferred from provider actor kind or trust tier.
Attention eligibility remains zero-authority: it does not assign work, enter LifecycleFrontier, or create a Task. Only the explicit canonical claim transition owns that promotion.
Acceptance Criteria
AC1 — At least two tenants and multiple sources prove strict isolation on registration, admission, query, seen, claim, and counts.
AC2 — Repository rename and grant rotation preserve sourceInstanceId; revoked/stale epochs reject writes.
AC3 — Crash before/after admission receipt and lost-response retry converge without loss or duplicate history.
AC4 — Local direct and hosted authenticated paths admit the same canonical batch and receipt semantics.
AC5 — Issue, PR/review, and Discussion fixtures prove coverage, explicit gaps, revisions, tombstones, and uncertain absence.
AC6 — Automatic rows/counts/wakes contain no external prose; explicit drill-down applies source-relative trust.
AC7 — Concurrent claims produce one sourceEventId-to-taskId binding and one canonical Task.
AC8 — Unclaimed events never enter LifecycleFrontier; community history never becomes Native Edge Graph/GraphLog authority.
AC9 — Degraded sources remain visible and never normalize to complete/zero.
AC10 — A public criterion-to-test matrix maps every OQ and STEP_BACK gate to executable evidence.
AC11 — An end-to-end noise-flood fixture combines star/fork/watch events, internal/rostered context, and one external response-bearing occurrence; only the external occurrence enters Bird View/count eligibility.
AC12 — An internal close/resolve occurrence can remove or resolve the existing external attention item without creating a second attention item or Task.
Out of Scope
New production features, threshold selection, conditional wake activation, GitLab implementation, Fleet UI, or HA topology.
Avoided Traps
Do not mock away tenant/auth/transaction seams, use one happy-path tenant, or treat unit-suite green as end-to-end proof.
Related
Origin Session ID: 837ad74b-c2d2-413d-9aab-b7165a93a82a
Handoff Retrieval Hints
community activity end to end tenant source claim replayDiscussion 15139 executable criteria matrixCreation Freshness
Creation duplicate sweep: immediately before filing at 2026-07-14T05:32:12.123Z, checked the latest 20 open issues and last 30 all-state A2A messages. The independent broader audit at 2026-07-14T05:13:00Z covered open and closed issues, pull requests, A2A, ADRs, and code; no equivalent owner or foreign claim existed.