Context
This is an independently measurable child of #15524 under epic #15519 and the graduated authority in Discussion #15498 (OQ6/OQ7). The rate verdict is separately mergeable, while the source-mode transition and packaged witness remain sequenced behind #15543, #15544, and #15545.
This is not a micro-ticket: the result selects whether the flagship can honestly expose a zero-credential public-fleet mode or must keep public-fleet acquisition token-gated.
The Problem
The graduated plan requires a measured PASS/FAIL against GitHub's anonymous 60-request/hour REST budget before public-fleet wiring. The existing provider reader mixes REST, GraphQL, and trust-census operations. Without a live zero-token capability receipt, the product could expose a mode that cannot complete its own acquisition plan.
The Architectural Reality
ai/services/github-workflow/communityActivityShadowReader.mjs already owns GET-only acquisition and call/cost/gap receipts.
ai/services/github-workflow/probeCommunityActivityShadow.mjs binds its authenticated transport.
- The tracked 30-day acquisition receipt records 1,714 provider request/cost units: 1,683 GraphQL and 31 REST.
- A live token-cleared probe on 2026-07-18 observed anonymous REST limit 60, GraphQL limit 0 with HTTP 403, and HTTP 401 for the collaborators census. Public issue, issue-comment, and review-comment REST reads returned HTTP 200.
- The correct placement is a sibling measurement under
learn/agentos/measurements/; npm run --silent ai:structure-map -- --files --loc was run before authoring. No runtime owner or new .mjs file is introduced.
The Fix
Commit a versioned measurement that records the live zero-token capability receipt, the stable product verdict, and explicit reproduction triggers. The result must bind #15524 to:
- bundled sample as the zero-call offline default;
- token-present public fleet as an opt-in;
- no second reader and no reduced REST subset relabeled as the full public fleet.
Contract Ledger
| Authority / evidence |
Consumer |
Required effect |
| Live token-cleared provider receipt |
Versioned measurement |
Record capability facts, not a shared-machine remaining-counter policy |
| Existing reader request plan |
Capability audit |
Test the real plan; do not invent a second adapter |
| Discussion #15498 PASS/FAIL gate |
#15524 implementation |
Select the token-gated branch when anonymous capability is insufficient |
| Reproduction triggers |
Future maintainer |
Reopen only when provider capability or the canonical query plan changes |
Decision Record Impact
Aligned with ADR 0037 / PR #15546. This measurement consumes that topology decision; it does not amend the topology.
Decision Record
No new ADR is needed. The ticket applies ADR 0037 and the graduated criterion from Discussion #15498.
Acceptance Criteria
Out of Scope
- The bundled-sample to selected/live source-mode transition.
- The packaged-demo witness.
- Demo-host separation from #15545.
- A new REST-only public preview.
- Fleet Manager UI composition.
Avoided Traps
- No fake zero-credential toggle whose canonical reader cannot complete.
- No degraded REST subset presented as the full public fleet.
- No throughput threshold inferred from a shared machine's current remaining counter.
- No duplicated acquisition or fixture vocabulary.
Related
Freshness Receipt
Immediately before creation at 2026-07-18T23:12:10.214Z, the latest 20 open issues, the latest 30 A2A messages across read states, and an exact/local resource sweep were checked. No equivalent ticket was found.
Handoff
The measurement is already implemented on codex/15524-fm-demo-authority; after this ticket is created, the commit and PR will be rebound to this child authority.
Origin Session ID: ad71d4c3-3e37-4a17-8df7-8415509def84
Context
This is an independently measurable child of #15524 under epic #15519 and the graduated authority in Discussion #15498 (OQ6/OQ7). The rate verdict is separately mergeable, while the source-mode transition and packaged witness remain sequenced behind #15543, #15544, and #15545.
This is not a micro-ticket: the result selects whether the flagship can honestly expose a zero-credential public-fleet mode or must keep public-fleet acquisition token-gated.
The Problem
The graduated plan requires a measured PASS/FAIL against GitHub's anonymous 60-request/hour REST budget before public-fleet wiring. The existing provider reader mixes REST, GraphQL, and trust-census operations. Without a live zero-token capability receipt, the product could expose a mode that cannot complete its own acquisition plan.
The Architectural Reality
ai/services/github-workflow/communityActivityShadowReader.mjsalready owns GET-only acquisition and call/cost/gap receipts.ai/services/github-workflow/probeCommunityActivityShadow.mjsbinds its authenticated transport.learn/agentos/measurements/;npm run --silent ai:structure-map -- --files --locwas run before authoring. No runtime owner or new.mjsfile is introduced.The Fix
Commit a versioned measurement that records the live zero-token capability receipt, the stable product verdict, and explicit reproduction triggers. The result must bind #15524 to:
Contract Ledger
Decision Record Impact
Aligned with ADR 0037 / PR #15546. This measurement consumes that topology decision; it does not amend the topology.
Decision Record
No new ADR is needed. The ticket applies ADR 0037 and the graduated criterion from Discussion #15498.
Acceptance Criteria
Out of Scope
Avoided Traps
Related
Freshness Receipt
Immediately before creation at 2026-07-18T23:12:10.214Z, the latest 20 open issues, the latest 30 A2A messages across read states, and an exact/local resource sweep were checked. No equivalent ticket was found.
Handoff
The measurement is already implemented on
codex/15524-fm-demo-authority; after this ticket is created, the commit and PR will be rebound to this child authority.Origin Session ID:
ad71d4c3-3e37-4a17-8df7-8415509def84