DIREKT Workstream Lock

This file prevents overlapping writes in the single-lane build process.

Current lock

Field Value
Status RELEASED — ISSUE #522 LIVELY TRUST MARKETPLACE UI REFRESH COMPLETE
Owner/agent No active writer. The owner-authorized Issue #522 implementation, visual-evidence review, merge and canonical PWA deployment are closed and preserved.
Authorized scope CLOSED. Android and customer/provider PWA Home, Saved, Enquiries and Account presentation work may resume only through a new explicit issue and lane claim.
Protected surface Closed Issue #522 evidence; closed RC0–RC11 evidence; canonical OpenAPI authorization/privacy checks; Android auth/session/Firebase controls; customer/provider web BFF/private Cloud Run IAM; provider workspace; operations portal; payment boundaries; UIA Issue #354; Design DNA; and all Phase 11/12 gates.
Implementation receipts PR #524 merged the visual refresh at 2825e8837c53bc3eb1263cabc14fd686709eae0c. PR #525 merged the reviewed-main deployment trigger at f206ef9ca42e35506e2b0f3c2740e4147d2b1383. PR #526 merged the canonical deployment receipt at e8923df1c921b5a2c7638bb6164f066ab9cb562e.
Stable baseline main@e8923df1c921b5a2c7638bb6164f066ab9cb562e is the exact deployed closure source. Closed integration/readiness evidence remains regression-protected.
Current task None. Owner testing may record follow-up observations, but any source correction requires a new bounded claim from current main.
Governing issue Issue #522 is complete. Issue #112 remains closed not planned; Issue #354 and all closed RC/UIA evidence remain preserved.
Formal programme phase Owner-directed post-VC presentation refinement is complete. The real Phase 11 pilot was not run and formal Phase 12 production release is not authorized.
Production-release authorization BLOCKED. This UI closure does not create pilot entry, participant processing, production authentication, real communications, real money, trust authority or production release authorization.

Issue #522 visual-refresh closure receipt — CLOSED AND PRESERVED

  1. The approved Lively Trust Marketplace direction was implemented across the native Android app and responsive customer/provider PWA without replacing canonical business, authentication, trust, privacy, provider or integration behavior.
  2. The exact reviewed implementation head baa7abf85375a353f865b28b7412cb19fb5e30ee passed the material Android, PWA, W4, W7, W8, integration, performance, supply-chain and documentation matrix before PR #524 squash-merged at 2825e8837c53bc3eb1263cabc14fd686709eae0c.
  3. Exact-head Android evidence was captured by run 30340968088, artifact 8681151691, covering customer Home, Saved, Enquiries and Account plus provider regressions.
  4. Exact-head PWA evidence was captured by run 30340968094, artifact 8681033369, covering compact customer Home, Saved, Enquiries and Account, tablet discovery, desktop customer/provider and operations regressions.
  5. Screenshot review found and corrected compact PWA horizontal clipping, Android wordmark wrapping and narrow Android illustration/text overlap before merge.
  6. PR #525 made the existing fail-closed W8 deployment workflow run after relevant reviewed changes land on main; PR #526 added an exact-source deployment receipt without changing IAM, API, participant or release authority.
  7. Managed deployment run 30343083753 deployed exact source e8923df1c921b5a2c7638bb6164f066ab9cb562e and passed the W2–W8 contract, IAM-private API boundary, responsive shell, manifest/service-worker/offline fallback, BFF discovery, synthetic session and browser privacy checks.
  8. Canonical owner-test entries are https://app.direkt.forum/ and https://app.direkt.forum/?view=account; the accepted ?view=discover|saved|enquiries|account contract remains preserved.
  9. No concept-only rating, insurance, trust score, provider response, setting or generic Verified claim was added where canonical data did not support it.
  10. The lane is released. Owner usability feedback may open a new bounded visual-correction issue; it cannot weaken the closed regression, trust, privacy, IAM, participant or production-release boundaries recorded here.

Historical Wave 0 contract marker: Stable baseline | main@632dd0bdbb2a3b8c24bd285918deff3e54bd3ba9

W8 historical closure receipt — CLOSED AND PRESERVED

The following strings are historical closure evidence required by the permanent W8 cutover verifier; they do not describe current lock ownership:

  • Historical lock row: Status | RELEASED.
  • W8 — controlled route/deployment cutover completed with a dedicated least-privilege runtime identity.
  • Canonical owner-review host: https://app.direkt.forum; historical preview remains https://direkt.forum/preview/.
  • W8 implementation claim is RELEASED. No later implementation lane is currently claimed; RC5 closure is preserved below.

RC3 implementation contract — CLOSED AND PRESERVED

  1. Crashlytics is the Android crash/ANR telemetry path; Android Sentry remains inactive.
  2. Automatic Crashlytics collection is disabled by default. Only the explicit synthetic/debug canary path may opt in for bounded proof.
  3. RC3 did not add Firebase Analytics merely to obtain breadcrumbs or session context.
  4. No raw evidence, contact data, auth tokens, cookies, precise private coordinates, provider-reviewer notes or unrestricted free text may be attached to Crashlytics.
  5. No stable participant identifier is set as a Crashlytics user ID; synthetic canaries use non-identifying bounded metadata only.
  6. Release/build mapping remains source-controlled and compatible with existing preauthorization signing/version controls.
  7. Synthetic crash and ANR proof does not create a production-accessible crash trigger; the canary entry point remains debug/test-only and absent from the release manifest/runtime.
  8. Existing Firebase Auth/App Distribution behavior remains intact.
  9. The permanent integration verifier positively asserts Crashlytics/privacy/canary controls and remains mandatory.
  10. RC3 is ACTIVE — SYNTHETIC-ONLY MANAGED CANARY; participant/production crash telemetry remains separately gated.

RC4 implementation contract — CLOSED AND PRESERVED

  1. FCM send authority is backend-owned. Android/browser clients never receive server credentials or decide delivery truth.
  2. Push delivery originates from a DIREKT-controlled transactional outbox event and records durable success/failure state.
  3. Device tokens are identity-bound server-side, may be registered/rotated/deleted only by the authenticated identity, are never logged, and are removed/disabled on provider invalid-token responses.
  4. FCM is fail-closed by default. Production and controlled-pilot participant push remain disabled during RC4; the managed canary is synthetic-only.
  5. Android must support foreground/background receipt and Android 13+ notification permission without making permission grant an authentication, trust, verification or service-access prerequisite.
  6. Push payloads contain only bounded routing/display identifiers; no raw evidence, auth tokens, contact data, exact private coordinates, reviewer notes or unrestricted free text.
  7. Retries are bounded and idempotency/deduplication identifiers are stable across retry attempts.
  8. The managed canary must prove exact reviewed source, a registered synthetic device token, backend outbox/provider send success, and Android receipt on the managed emulator/device.
  9. RC4 must not activate Firebase Test Lab, Maps, Analytics or unrelated Firebase products early.
  10. RC4 is ACTIVE — SYNTHETIC-ONLY MANAGED CANARY; participant registration and participant/production push remain separately gated.

RC5 implementation contract — CLOSED AND PRESERVED

  1. Firebase Test Lab is a testing/evidence service only; it does not authorize production release, participant enrollment, production auth, real communications or real private evidence.
  2. The Test Lab workflow must build and test an exact reviewed source SHA that is already merged to main for managed proof, while pull-request CI may validate source changes before merge.
  3. Android instrumentation assertions must reflect the current post-VC product semantics and stable accessibility/test tags; stale copy must be repaired rather than changing the approved UI merely to satisfy an old test.
  4. The managed matrix must remain small, explicit and cost-bounded, and must use currently supported Firebase Test Lab model/version pairs discovered from the live catalog rather than guessed/stale device identifiers.
  5. Coverage must include the minimum supported Android boundary where feasible, the Android 13 notification-permission era, and a current platform baseline without multiplying redundant devices.
  6. Test APKs, app APKs, result summaries and retained artifacts must contain only synthetic/public-safe data and no production credentials, participant data, raw tokens, private evidence or exact private provider coordinates.
  7. GitHub Actions authenticates through existing Workload Identity Federation. Broad Test Lab authority is confined to the dedicated, empty Spark project direkt-testlab-502701-20260726; roles/editor is isolated there, roles/owner and service-account keys remain prohibited, and the main DIREKT project receives no broadening.
  8. Test results must be machine-enforced: a matrix/infrastructure/test failure cannot be documented as passing, and flaky reruns must not erase the original failed evidence.
  9. Existing Android unit/lint/build, App Distribution, Crashlytics, FCM, signing, Play/Data Safety and cross-client regression gates remain intact.
  10. RC5 is CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED MATRIX: exact source c3744430a7beb1cd47246d858df9ac1379a068ac passed run 30183466799 on MediumPhone.arm API 26, 33 and 36 with zero flaky retries. Artifact 8626329335 (sha256:03a40951a23c937d8b0fd2990a7d2652afbd1172631c0b480af756aebd92a843) is schema-valid. Participant/production authorization remains false; historical failures and superseded v2 infrastructure remain evidence only.

UIA owner-review promotion contract — CLOSED AND PRESERVED

  1. UIA is an acceptance/promotion checkpoint, not a new visual-design phase. The approved VC1–VC8 Structured Trust + Neighbourhood Marketplace + Field Utility direction is preserved.
  2. Every promoted owner-review surface must be tied to an exact merged source on main; no stale prototype or pre-VC deployment may be represented as the current product.
  3. The canonical browser review remains synthetic/public-safe and must preserve the private API/BFF IAM boundary, privacy controls, offline/PWA contract and https://direkt.forum/preview/ historical preview separation.
  4. Android distribution remains internal/preauthorization only through the approved Firebase App Distribution tester group; no Play production release or unrestricted tester enrollment is authorized.
  5. Operations remains protected/private. Synthetic supervisor/session/queue/evidence presentation may be used for visual review but must not be represented as connected real-operations UAT or grant consequential decision authority.
  6. No real participant data, production auth, private evidence activation, real communications, real money movement or Phase 11/12 release authority is introduced by UIA.
  7. Owner-facing evidence must come from production-built or equivalent clean runtime presentation with no Next.js development toolbar, 1 Issue badge, debug/canary labels or other developer-only UI leakage.
  8. Existing backend, Android, PWA, portal, supply-chain, privacy, authorization and integration regressions remain mandatory; RC5 must not weaken them.
  9. UIA Issue #354 closed after exact source bb84968453b891dd511faddc093a8874fce8abc4 passed browser/PWA run 30314869549, Android internal-distribution run 30314870954, IAM-private operations run 30314872253 and canonical-domain run 30315044253.
  10. UIA is CLOSED — CURRENT-MAIN SYNTHETIC OWNER REVIEW PROVEN: browser access is canonical, Android is internal/preauthorization-only, operations is IAM-private/synthetic, real participant UAT has not run and production release remains unauthorized.

RC6 implementation contract — CLOSED AND PRESERVED

  1. WhatsApp send authority is backend-owned and application-managed; Android/browser clients never receive Meta/WhatsApp credentials or directly decide provider delivery state.
  2. Outbound WhatsApp delivery originates from the DIREKT transactional outbox and must preserve stable idempotency across retries.
  3. Consent and opt-out state are checked at send time; a queued event cannot bypass a later withdrawal or channel-specific opt-out.
  4. Only approved/template-governed payloads may be sent where Meta policy requires templates; unrestricted free-form participant messaging is not introduced by RC6.
  5. Payloads must not include identity documents, certificates, raw evidence, auth tokens, exact private coordinates, reviewer notes or other restricted/private evidence.
  6. Webhook authenticity must be verified before delivery/read/failure receipts affect durable DIREKT state; duplicate/out-of-order webhook events must be handled idempotently.
  7. Retries are bounded, observable and fail-closed; provider errors cannot silently become delivered or erase original failure evidence.
  8. A kill switch/provider enablement gate must default real/participant delivery off. Synthetic managed proof may run only with bounded synthetic/non-personal data and approved provider state.
  9. Production/participant WhatsApp delivery remains disabled until business/phone/template/provider/legal/privacy approvals and later release authorization are explicitly evidenced.
  10. RC6 is CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY: exact-current-main managed run 30137700769 on source 8838b7a6d726a5aed44ce21a39506c1265a98d15 passed the private outbox → Meta hello_world test-template send → authentic signed webhook receipt path on retry. The initial failure remains preserved in Issue #404. Existing RC0–RC5, UIA, backend/database/OpenAPI, Android/PWA/portal, payment, privacy, authorization and production-release gates remain regression-protected; production/participant WhatsApp delivery remains disabled.

RC7 implementation contract — CLOSED AND PRESERVED

  1. RC7 activates only the APIs justified by the current product flow: Maps SDK for Android for map display and backend Geocoding for bounded search-area/address normalization. Places and Routes remain disabled because the existing manual area input and PostGIS distance/service-area logic already satisfy the reviewed flow.
  2. Android and backend authentication remain separate. The Android key is restricted to DIREKT package/signing-certificate pairs and Maps SDK for Android; backend Geocoding uses the assigned Cloud Run service identity with a downscoped address-only OAuth token and no backend API key, secret value, static egress IP or Cloud NAT dependency.
  3. Exact private provider bases never become public markers, polygons, distance origins, ranking inputs, logs, telemetry or provider payloads. Only consented public premises and privacy-approved service-area geometry may render.
  4. Mobile providers render public service areas without a base marker. Fixed-premises markers require a consented public premises point. Hybrid providers may show the consented public premises and the separate public service area.
  5. Manual area and list discovery remain fully functional and are never treated as lower trust. RC7 adds no background-location permission and cannot make device location a prerequisite for discovery, authentication, verification or service access.
  6. Android Maps and backend Geocoding default disabled. Explicit source-controlled switches, valid protected credentials and synthetic-only non-production data are required for managed proof; provider outage, map-load failure or denied location capability must fall back safely.
  7. Backend Geocoding accepts bounded search-area input, constrains results to Zambia, filters provider responses and never exposes or logs credentials, raw provider payloads, unnecessary coordinate precision or unrestricted free text.
  8. Quotas, budget alerts, per-request timeout, bounded result count and rotation instructions are required. Routes and Places costs cannot be incurred because those APIs are not enabled or accepted by either credential.
  9. Managed closure is proven on exact source 47285575862cbf08845eaeabe093afea1ea79bd1 through run 30234521983/1: restricted key/API metadata, backend synthetic Geocoding, final APK restriction, API 36 map readiness and cleanup all passed. Artifact 8641270327 (sha256:24da53c0bd6fa885fa4a6814f70af090096192e6c5b7a03c89fba51416877fde) preserves the sanitized receipt; earlier failures remain preserved.
  10. RC7 is CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY. It does not authorize participant Maps usage, private-location publication, production authentication, real communications, real money, Phase 11 exit or Phase 12 release.

RC8 implementation contract — CLOSED AND PRESERVED

  1. RC8 is limited to sandbox adapters, runtime proof and reconciliation for DIREKT-owned provider subscriptions, verification-processing fees and renewal/re-verification fees.
  2. Real money, participant payment data, production provider endpoints or credentials, customer-to-provider service payments, escrow, stored value, wallets and marketplace payouts remain disabled and outside scope.
  3. Source checkpoint PR #454 was replayed onto the RC8-claimed baseline and merged at 6098b71f89d62fa059de298be11a8d9d8539c25e after the complete exact-head regression matrix passed without overwriting RC0–RC7 closure evidence.
  4. Provider credentials remain server-side and Secret Manager-backed with least privilege. Android and browser clients never receive credentials or declare payment success.
  5. Success requires independent provider verification plus exact provider reference, transaction identifier where applicable, amount and currency agreement with the backend-owned DIREKT intent and ledger.
  6. Provider observations, payment events, ledger postings, mismatch cases and adjustments remain append-only and idempotent. A mismatch opens reconciliation; it is never silently repaired.
  7. Refund and accounting-adjustment execution requires two independent approvers, requester exclusion, balanced ledger effects and operations-only revision-checked resolution.
  8. Managed proof may bind only the existing reviewed MTN MoMo, Stripe and PayPal sandbox/test credentials. DPO remains source-integrated and externally sandbox-proven but runtime-unbound because no DIREKT private sandbox credential exists; Airtel remains provider-pending and Flutterwave remains deferred/excluded.
  9. Managed evidence must use bounded synthetic values, sanitized receipts, exact reviewed source, explicit cleanup and no raw provider payload or credential leakage. A failed provider attempt remains preserved and cannot be documented as passing.
  10. RC8 is CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY: exact source ccc4e9463d810ddf554182b1607c22d3a7c8c8d3 passed run 30241092949/1 with artifact 8643323319 (sha256:bbb4600eb5a062552947e91c878dd09c6d1e4dc307ae4783c7fa1fb4cf6e4935). MTN independent success, Stripe unpaid Checkout retrieval, PayPal unapproved-order retrieval, immutable reconciliation, duplicate suppression, mismatch review, two-person adjustment planning and temporary-job cleanup all passed. The trigger is consumed; application runtime, production, participant and real-money authorization remain false.

RC9 implementation contract — CLOSED AND PRESERVED

  1. The canonical input is the exact backend-generated OpenAPI 3 document after the permanent authorization, privacy, deferred-domain and sensitive-field checks pass.
  2. OpenAPI Generator is pinned to stable version 7.22.0; generation must run locally/CI without an online generator service and with timestamps hidden.
  3. Generated output is reproducible and committed or otherwise hash-pinned; CI regenerates from the same spec/config and fails on byte drift.
  4. Kotlin adoption is incremental. The first runtime slice is the existing Firebase-to-DIREKT auth/session exchange; current UI, encrypted session storage, consent, fail-closed configuration, timeouts and error semantics must remain intact.
  5. The Kotlin target is jvm-retrofit2 with kotlinx_serialization; generated code must not introduce Android API-level regressions, unreviewed cleartext, permissive certificate handling or direct provider/database credentials.
  6. TypeScript generation supplies canonical contract models/operation types to the server-only BFF. It must not move authenticated browser calls to the client, reveal the private Cloud Run API origin or replace the reviewed infrastructure-token/session boundary.
  7. Generated transport defaults may not become authority for authorization, trust, payment, retry, idempotency or offline-success decisions. DIREKT-owned wrappers/interceptors preserve those policies.
  8. Additive API changes remain backward compatible; breaking changes require /api/v2. Unknown/new response fields must not crash released clients, and enum evolution requires an explicit safe policy.
  9. Cross-client evidence must include backend OpenAPI, generator drift, Android unit/lint/build/instrumentation and functional web type/security/build regressions before migration promotion.
  10. RC9 is CLOSED — DETERMINISTIC GENERATED CLIENTS / BOUNDED RUNTIME ADOPTION: PR #497 exact head 04ef57f31414ec5165e353abba74afb8dfdcc901 passed the complete backend, Android, web/PWA, W7, security, runtime-audit, Phase 10–12 and RC5–RC9 matrix, then squash-merged at 70de95c73128e921cd4d7c667de0e5a442a9e0c0. Generated imports remain limited to the reviewed Android auth wrapper and server-only BFF type adapter. No production, participant, privileged direct-access, provider-secret, payment-provider or real-money authorization changed.

RC10 implementation contract — CLOSED AND PRESERVED

  1. Turnstile is conditional abuse control, not a completeness checkbox. It may be introduced only for a specifically reviewed browser-accessible public flow whose risk is not adequately controlled by authentication, admission gates, quotas and rate limiting.
  2. RC10 inventories all public mutating or provider-cost-bearing routes, including challenge issuance/verification, public Help, discovery assistance, discovery-area normalization and public discovery reads.
  3. Database-backed rate limiting remains backend authoritative, fail-closed and keyed by an HMAC of the network subject. Raw IP addresses, challenge tokens and provider payloads must not be stored in durable rate-limit evidence.
  4. If Turnstile is justified, verification is server-side with hostname/action binding, expiry and replay resistance; the secret remains server-only; the browser token is short-lived, single-use and never logged; accessibility fallback and a kill switch are mandatory.
  5. Turnstile must not become authentication, identity, verification, trust, payment, publication or authorization authority. It must not be installed globally or required by Android/native flows.
  6. If no current flow justifies Turnstile, RC10 closes as NOT CURRENTLY REQUIRED with a written threat model and explicit re-evaluation triggers. Any uncovered first-party rate-limit gap must still be repaired.
  7. No Cloudflare Turnstile widget, site key, secret, package or runtime binding is provisioned merely to close RC10.
  8. Real participants, production authentication, production communications, real money and production release remain separately blocked.
  9. Exact-head evidence must include backend formatting/lint/type/tests/build/OpenAPI, abuse-policy tests, RC5–RC10 permanent contracts, PWA/W7/W8, runtime audit, supply-chain and documentation gates as applicable.
  10. RC10 is CLOSED — NOT CURRENTLY REQUIRED / TURNSTILE NOT ACTIVE: PR #502 exact head cdab6622e0cc06e35cddca2bb5bc8ea70c027b38 passed the complete backend, container, generated-client, PWA/W7/W8, runtime-audit, recovery, staging, Phase 11 synthetic, RC5–RC10 and documentation matrix, then squash-merged at 620a99ba5465ad38ce012df0a8fa15e458de6505. The three public POST helper gaps are protected by the existing fail-closed database rate limiter; no Turnstile credential, widget, package or runtime binding exists. RC11 remains unclaimed.

RC11 implementation contract — CLOSED AND PRESERVED

  1. RC11 is reconciliation and closure only; it may not activate a new provider, SDK, participant channel, production environment or real-money path.
  2. RC11A requires the combined Android, backend, database, OpenAPI, generated-client, customer/provider PWA, operations portal and integration-runtime regression matrix on one exact head.
  3. RC11B maintains one managed evidence index that records exact source, run, artifact and boundary where available without inventing identifiers.
  4. RC11C reconciles the live ledger and current integration register while preserving PENDING_PROVIDER, BLOCKED, DISABLED, IMPLEMENTED_GATED, SANDBOX_PROVEN and EXTERNALLY_PROVISIONED distinctions.
  5. Synthetic, sandbox and managed-canary evidence may never be relabelled as PRIMARY-PILOT or production evidence.
  6. Client applications retain no provider, database, payment or telemetry-admin credentials; backend authorization remains authoritative.
  7. Payment cannot create trust, verification, publication or ranking authority; AI cannot become consequential authority.
  8. Real participants, production authentication, participant communications/telemetry/Maps, production AI, real money and Phase 12 release remain blocked.
  9. RC11D requires a dedicated exact-head closure receipt, permanent verifier, Issue #261 completion and released lane.
  10. RC11 is CLOSED — FINAL INTEGRATION RECONCILIATION / LANE RELEASED: PR #505 exact head 66626d315a8d132dbf8f34749a2679e42c609d7c passed the complete combined matrix and squash-merged at 87f567fccfa92244c7951432436c7163c71d5fc7. The clean handoff names Phase 11C–11J execution preparation as next, while real pilot activity remains prohibited until the Phase 11 entry checklist is genuinely satisfied.

Phase 11C–11J execution-readiness contract — CLOSED AND PRESERVED

  1. This lane creates execution instruments only; it does not authorize participant recruitment, admission, data processing, external communication, provider activation, payment or production traffic.
  2. PILOT_ENTRY_APPROVED remains false and fail-closed. No workflow, deployment or documentation change may set it true in this lane.
  3. PRIMARY_PILOT_EVIDENCE_REGISTER.md remains explicitly empty until approved, consenting participants generate evidence in the authorized pilot environment.
  4. The protocol must cover 11C provider onboarding/evidence, 11D discovery/location/trust, 11E enquiries/handoff/reviews, 11F operations/field capacity, 11G devices/connectivity, 11H pricing/economics, 11I canonical corrections and 11J exit decision.
  5. The real-entry blocker register preserves DPC, transfer, qualified legal/privacy/consumer, notice/consent, Firebase real-canary, private-storage and deletion/withdrawal gates as open until actual evidence closes them.
  6. Wave ceilings remain at most 8 providers and 20 customers; actual approved counts may be lower and must be recorded before invitations.
  7. Immediate stop rules protect consent, authorization, private evidence, exact private coordinates, participant safety, credentials, data integrity, unsupported trust claims and real-money boundaries.
  8. Every 11I correction uses canonical production code, forward-only migrations, backend authorization, OpenAPI/client boundaries and full regression; pilot-only shortcuts are prohibited.
  9. The 11J instrument must require exactly one evidence-backed STOP, REPEAT, NARROW or PROCEED decision and must keep Phase 12 authorization false unless separately approved.
  10. The readiness package is CLOSED — EXECUTION READY / REAL ENTRY BLOCKED / NO PRIMARY-PILOT EVIDENCE: PR #508 exact head ae4fcb0350be4023f82e2be8df88c18cca583695 passed the complete preserved matrix and squash-merged at 2bf58c2c5df40aa76742730ec4a49644c2506a89. Issue #112 remains open; Wave 0 real-entry evidence reconciliation requires a new explicit claim.

Phase 11 Wave 0 finishing-line contract — CLOSED AND PRESERVED

  1. This lane may close repository-clearable preparation and verification only; it may not claim that regulator, counsel, provider, owner or participant evidence exists when it has not been supplied.
  2. PILOT_ENTRY_APPROVED remains false. No workflow, deployment, source document or local command may set it true in this lane.
  3. PRIMARY-PILOT evidence and findings remain at zero; synthetic, secondary, sandbox or managed-canary evidence remains separately labelled.
  4. Official-source Zambia privacy, controller/processor, overseas-storage/transfer and consumer-protection research may be refreshed, but cannot close P11-G01 through P11-G06 without the required accountable authority.
  5. The lane must produce a structured evidence-intake manifest, hash/reference rules, accountable-owner attestations and a deterministic gate evaluator that fails closed on missing, expired, mismatched or unreviewed evidence.
  6. Repository-clearable technical preflight must verify exact source, migrations, private storage boundaries, Firebase fail-closed configuration, communication/Maps/telemetry/AI/payment exclusions, support/incident templates and zero unresolved repository critical/high defects.
  7. Real participant Firebase, invitation, consent, withdrawal, deletion and private-storage canaries remain blocked until legal/privacy/owner gates are actually closed; synthetic negative-path proof may not be relabelled as a real canary.
  8. The terminal Wave 0 decision must be one of ENTRY_APPROVED, ENTRY_BLOCKED_EXTERNAL, ENTRY_BLOCKED_TECHNICAL or STOP, with exact unresolved gate IDs and no ambiguous partial activation.
  9. If external evidence is absent, the finishing line for this lane is a verified ENTRY_BLOCKED_EXTERNAL receipt and a minimal owner/manual action packet—not false Phase 11 closure.
  10. Wave 0 repository finishing-line work is CLOSED — ENTRY_BLOCKED_EXTERNAL / TECHNICAL PREFLIGHT PASSED: PR #512 exact head 1befa902def70d2c997aaba260e0d8e2a5d4b12d passed the complete matrix and squash-merged at f561658d140aaf214fa6eaca99c80bcc98ee284f. P11-G14 is closed for that source only; P11-G01–P11-G13 remain open, Issue #112 remains open and any later evidence lane requires a new explicit claim.

Runtime integration closure contract

  1. Close one bounded integration checkpoint at a time; do not batch unrelated SDK/provider activation.
  2. An external account, API key, DSN, secret or dashboard project is not ACTIVE evidence by itself.
  3. Each closure requires applicable source integration, least-privilege secret/runtime binding, privacy/security controls, fallback or kill switch, managed canary/device evidence, exact-head regressions and status documentation.
  4. Android/browser clients call DIREKT-controlled API/BFF boundaries; they do not receive privileged provider, database, payment, AI, registry or telemetry-auth credentials.
  5. Real participants, real external communications, real payment movement, production auth and production release remain separately gated.
  6. Payment state cannot create or improve verification, publication or ranking authority.
  7. AI output cannot independently verify providers, change trust/ranking/publication, authorize payments/escrow, decide disputes, override consent/authorization or act as legal/regulatory authority.
  8. Exact private provider coordinates, raw evidence, contact data, credentials and tokens must not leak into telemetry, public maps, browser caches or provider payloads.
  9. Sentry auth tokens remain CI/release tooling only and must never bind to API, portal, Android or browser runtime.
  10. The workstream releases or transitions the lane only after status/ledger reconciliation, exact-head regression matrix, managed evidence and handoff are promoted.

Dependency-safe implementation sequence

  • RC0 — integration ledger, dependency/source audit, permanent-gate ownership sanity check and payment evidence reconciliation. Closed — PR #263.
  • AI0 — provider-neutral AI foundation. Closed — PR #265; runtime activation remains per-use-case and data-classification gated.
  • RC1 — Resend transactional-outbox runtime. Closed; synthetic managed execution proven; real-participant/production email remains disabled.
  • RC2 — Sentry for approved NestJS/Next.js surfaces. Closed — PR #275 source + managed synthetic API/private-portal canary + closure PR #280; participant/production telemetry remains disabled.
  • RC3 — Firebase Crashlytics Android. Closed — exact source 9098f7eb333baf096163f1564b3d8e5e5da3fcf0; managed bridge run 29885635547 successful; closure PR #338 merged at 0d7d29313990c37b25bd985588866a85bbe10f83.
  • RC4 — FCM push delivery: server send path, token lifecycle, Android notification handling/permissions, retries and managed canary. CLOSED — exact source f05ff19105cb8dc7c4621c044c110b6029f63300; managed run 29916381754 successful; participant/production push disabled.
  • RC5 — Firebase Test Lab device-matrix automation. CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED MATRIX — dedicated Spark project direkt-testlab-502701-20260726; exact source c3744430a7beb1cd47246d858df9ac1379a068ac; managed run 30183466799; API 26/33/36; zero flaky retries; participant/production authorization false.
  • UIA — post-VC owner-review promotion. CLOSED — CURRENT-MAIN SYNTHETIC OWNER REVIEW PROVEN — source bb84968453b891dd511faddc093a8874fce8abc4; browser 30314869549; Android 30314870954; operations 30314872253; canonical 30315044253; participant/production authorization false.
  • RC6 — WhatsApp Cloud API application adapter. CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY — exact source 8838b7a6d726a5aed44ce21a39506c1265a98d15; managed run 30137700769 succeeded on retry through outbox → Meta test template → authentic signed webhook receipt; initial failure preserved in Issue #404; production/participant sends remain disabled.
  • RC7 — Google Maps runtime activation with separate restricted Android/backend credentials, privacy-safe publication semantics, quotas, manual/list fallback and kill switch. CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY — exact source 47285575862cbf08845eaeabe093afea1ea79bd1; run 30234521983/1; artifact 8641270327 (sha256:24da53c0bd6fa885fa4a6814f70af090096192e6c5b7a03c89fba51416877fde); production/participant authorization false.
  • RC8 — sandbox-only payment-provider adapter closure/reconciliation. CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY — exact source ccc4e9463d810ddf554182b1607c22d3a7c8c8d3; run 30241092949/1; artifact 8643323319 (sha256:bbb4600eb5a062552947e91c878dd09c6d1e4dc307ae4783c7fa1fb4cf6e4935); MTN/Stripe/PayPal proved privately; DPO runtime-unbound, Airtel provider-pending, Flutterwave deferred; application runtime and real money disabled.
  • RC9 — OpenAPI-generated Kotlin and TypeScript client adoption/decision. CLOSED — deterministic generation, Android Firebase-session exchange adoption and server-only BFF type adoption merged through PR #497 at 70de95c73128e921cd4d7c667de0e5a442a9e0c0; exact-head matrix passed on 04ef57f31414ec5165e353abba74afb8dfdcc901; no production/participant or privileged direct-access change.
  • RC10 — Turnstile threat-model decision. CLOSED — NOT CURRENTLY REQUIRED / TURNSTILE NOT ACTIVE — PR #502 exact head cdab6622e0cc06e35cddca2bb5bc8ea70c027b38, merge 620a99ba5465ad38ce012df0a8fa15e458de6505; first-party rate-limit gaps closed; production authorization false.
  • RC11 — combined integration regression, managed evidence index, live ledger/status reconciliation and lane release. CLOSED — FINAL INTEGRATION RECONCILIATION / LANE RELEASED — PR #505 head 66626d315a8d132dbf8f34749a2679e42c609d7c, merge 87f567fccfa92244c7951432436c7163c71d5fc7.

Persistent stop conditions

Stop rather than merge or activate a later checkpoint if it would:

  • regress Android/backend/database/OpenAPI/web/portal required gates;
  • weaken Cloud Run IAM or expose privileged Supabase/database/Storage access;
  • expose private evidence, raw contact data or exact private provider coordinates;
  • fabricate or bypass participant, legal/privacy, payment, AI-provider or production-release gates;
  • accept client-selected provider scope or authorization;
  • allow commercial/payment state to influence verification or public trust claims;
  • allow AI output to become authoritative verification/trust/payment/dispute/publication authority;
  • store production credentials, model/provider secrets or telemetry admin tokens in application runtime or browser-readable surfaces;
  • replace backend-authoritative behavior with static fixtures while claiming runtime completion;
  • mark an integration or AI use case ACTIVE without exact configured-provider/runtime evidence.

Conflict rule

The repository write lane is RELEASED. Issue #522, RC0–RC11, UIA, Phase 11C–11J readiness and Wave 0 finishing-line evidence remain immutable/regression-protected. Any future visual or functional write lane must be claimed from current main and preserve the exact deployed Lively Trust Marketplace closure. Real participants, participant data, real money and production authorization remain blocked until the explicit Phase 11 entry checklist is satisfied.