DIREKT Workstream Lock¶
This file prevents overlapping writes in the single-lane build process.
Current lock¶
| Field | Value |
|---|---|
| Status | RELEASED — ISSUE #522 LIVELY TRUST MARKETPLACE UI REFRESH COMPLETE |
| Owner/agent | No active writer. The owner-authorized Issue #522 implementation, visual-evidence review, merge and canonical PWA deployment are closed and preserved. |
| Authorized scope | CLOSED. Android and customer/provider PWA Home, Saved, Enquiries and Account presentation work may resume only through a new explicit issue and lane claim. |
| Protected surface | Closed Issue #522 evidence; closed RC0–RC11 evidence; canonical OpenAPI authorization/privacy checks; Android auth/session/Firebase controls; customer/provider web BFF/private Cloud Run IAM; provider workspace; operations portal; payment boundaries; UIA Issue #354; Design DNA; and all Phase 11/12 gates. |
| Implementation receipts | PR #524 merged the visual refresh at 2825e8837c53bc3eb1263cabc14fd686709eae0c. PR #525 merged the reviewed-main deployment trigger at f206ef9ca42e35506e2b0f3c2740e4147d2b1383. PR #526 merged the canonical deployment receipt at e8923df1c921b5a2c7638bb6164f066ab9cb562e. |
| Stable baseline | main@e8923df1c921b5a2c7638bb6164f066ab9cb562e is the exact deployed closure source. Closed integration/readiness evidence remains regression-protected. |
| Current task | None. Owner testing may record follow-up observations, but any source correction requires a new bounded claim from current main. |
| Governing issue | Issue #522 is complete. Issue #112 remains closed not planned; Issue #354 and all closed RC/UIA evidence remain preserved. |
| Formal programme phase | Owner-directed post-VC presentation refinement is complete. The real Phase 11 pilot was not run and formal Phase 12 production release is not authorized. |
| Production-release authorization | BLOCKED. This UI closure does not create pilot entry, participant processing, production authentication, real communications, real money, trust authority or production release authorization. |
Issue #522 visual-refresh closure receipt — CLOSED AND PRESERVED¶
- The approved Lively Trust Marketplace direction was implemented across the native Android app and responsive customer/provider PWA without replacing canonical business, authentication, trust, privacy, provider or integration behavior.
- The exact reviewed implementation head
baa7abf85375a353f865b28b7412cb19fb5e30eepassed the material Android, PWA, W4, W7, W8, integration, performance, supply-chain and documentation matrix before PR #524 squash-merged at2825e8837c53bc3eb1263cabc14fd686709eae0c. - Exact-head Android evidence was captured by run
30340968088, artifact8681151691, covering customer Home, Saved, Enquiries and Account plus provider regressions. - Exact-head PWA evidence was captured by run
30340968094, artifact8681033369, covering compact customer Home, Saved, Enquiries and Account, tablet discovery, desktop customer/provider and operations regressions. - Screenshot review found and corrected compact PWA horizontal clipping, Android wordmark wrapping and narrow Android illustration/text overlap before merge.
- PR #525 made the existing fail-closed W8 deployment workflow run after relevant reviewed changes land on
main; PR #526 added an exact-source deployment receipt without changing IAM, API, participant or release authority. - Managed deployment run
30343083753deployed exact sourcee8923df1c921b5a2c7638bb6164f066ab9cb562eand passed the W2–W8 contract, IAM-private API boundary, responsive shell, manifest/service-worker/offline fallback, BFF discovery, synthetic session and browser privacy checks. - Canonical owner-test entries are
https://app.direkt.forum/andhttps://app.direkt.forum/?view=account; the accepted?view=discover|saved|enquiries|accountcontract remains preserved. - No concept-only rating, insurance, trust score, provider response, setting or generic
Verifiedclaim was added where canonical data did not support it. - The lane is released. Owner usability feedback may open a new bounded visual-correction issue; it cannot weaken the closed regression, trust, privacy, IAM, participant or production-release boundaries recorded here.
Historical Wave 0 contract marker: Stable baseline | main@632dd0bdbb2a3b8c24bd285918deff3e54bd3ba9
W8 historical closure receipt — CLOSED AND PRESERVED¶
The following strings are historical closure evidence required by the permanent W8 cutover verifier; they do not describe current lock ownership:
- Historical lock row:
Status | RELEASED. - W8 — controlled route/deployment cutover completed with a dedicated least-privilege runtime identity.
- Canonical owner-review host:
https://app.direkt.forum; historical preview remainshttps://direkt.forum/preview/. - W8 implementation claim is RELEASED. No later implementation lane is currently claimed; RC5 closure is preserved below.
RC3 implementation contract — CLOSED AND PRESERVED¶
- Crashlytics is the Android crash/ANR telemetry path; Android Sentry remains inactive.
- Automatic Crashlytics collection is disabled by default. Only the explicit synthetic/debug canary path may opt in for bounded proof.
- RC3 did not add Firebase Analytics merely to obtain breadcrumbs or session context.
- No raw evidence, contact data, auth tokens, cookies, precise private coordinates, provider-reviewer notes or unrestricted free text may be attached to Crashlytics.
- No stable participant identifier is set as a Crashlytics user ID; synthetic canaries use non-identifying bounded metadata only.
- Release/build mapping remains source-controlled and compatible with existing preauthorization signing/version controls.
- Synthetic crash and ANR proof does not create a production-accessible crash trigger; the canary entry point remains debug/test-only and absent from the release manifest/runtime.
- Existing Firebase Auth/App Distribution behavior remains intact.
- The permanent integration verifier positively asserts Crashlytics/privacy/canary controls and remains mandatory.
- RC3 is
ACTIVE — SYNTHETIC-ONLY MANAGED CANARY; participant/production crash telemetry remains separately gated.
RC4 implementation contract — CLOSED AND PRESERVED¶
- FCM send authority is backend-owned. Android/browser clients never receive server credentials or decide delivery truth.
- Push delivery originates from a DIREKT-controlled transactional outbox event and records durable success/failure state.
- Device tokens are identity-bound server-side, may be registered/rotated/deleted only by the authenticated identity, are never logged, and are removed/disabled on provider invalid-token responses.
- FCM is fail-closed by default. Production and controlled-pilot participant push remain disabled during RC4; the managed canary is synthetic-only.
- Android must support foreground/background receipt and Android 13+ notification permission without making permission grant an authentication, trust, verification or service-access prerequisite.
- Push payloads contain only bounded routing/display identifiers; no raw evidence, auth tokens, contact data, exact private coordinates, reviewer notes or unrestricted free text.
- Retries are bounded and idempotency/deduplication identifiers are stable across retry attempts.
- The managed canary must prove exact reviewed source, a registered synthetic device token, backend outbox/provider send success, and Android receipt on the managed emulator/device.
- RC4 must not activate Firebase Test Lab, Maps, Analytics or unrelated Firebase products early.
- RC4 is
ACTIVE — SYNTHETIC-ONLY MANAGED CANARY; participant registration and participant/production push remain separately gated.
RC5 implementation contract — CLOSED AND PRESERVED¶
- Firebase Test Lab is a testing/evidence service only; it does not authorize production release, participant enrollment, production auth, real communications or real private evidence.
- The Test Lab workflow must build and test an exact reviewed source SHA that is already merged to
mainfor managed proof, while pull-request CI may validate source changes before merge. - Android instrumentation assertions must reflect the current post-VC product semantics and stable accessibility/test tags; stale copy must be repaired rather than changing the approved UI merely to satisfy an old test.
- The managed matrix must remain small, explicit and cost-bounded, and must use currently supported Firebase Test Lab model/version pairs discovered from the live catalog rather than guessed/stale device identifiers.
- Coverage must include the minimum supported Android boundary where feasible, the Android 13 notification-permission era, and a current platform baseline without multiplying redundant devices.
- Test APKs, app APKs, result summaries and retained artifacts must contain only synthetic/public-safe data and no production credentials, participant data, raw tokens, private evidence or exact private provider coordinates.
- GitHub Actions authenticates through existing Workload Identity Federation. Broad Test Lab authority is confined to the dedicated, empty Spark project
direkt-testlab-502701-20260726;roles/editoris isolated there,roles/ownerand service-account keys remain prohibited, and the main DIREKT project receives no broadening. - Test results must be machine-enforced: a matrix/infrastructure/test failure cannot be documented as passing, and flaky reruns must not erase the original failed evidence.
- Existing Android unit/lint/build, App Distribution, Crashlytics, FCM, signing, Play/Data Safety and cross-client regression gates remain intact.
- RC5 is
CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED MATRIX: exact sourcec3744430a7beb1cd47246d858df9ac1379a068acpassed run30183466799onMediumPhone.armAPI 26, 33 and 36 with zero flaky retries. Artifact8626329335(sha256:03a40951a23c937d8b0fd2990a7d2652afbd1172631c0b480af756aebd92a843) is schema-valid. Participant/production authorization remains false; historical failures and superseded v2 infrastructure remain evidence only.
UIA owner-review promotion contract — CLOSED AND PRESERVED¶
- UIA is an acceptance/promotion checkpoint, not a new visual-design phase. The approved VC1–VC8 Structured Trust + Neighbourhood Marketplace + Field Utility direction is preserved.
- Every promoted owner-review surface must be tied to an exact merged source on
main; no stale prototype or pre-VC deployment may be represented as the current product. - The canonical browser review remains synthetic/public-safe and must preserve the private API/BFF IAM boundary, privacy controls, offline/PWA contract and
https://direkt.forum/preview/historical preview separation. - Android distribution remains internal/preauthorization only through the approved Firebase App Distribution tester group; no Play production release or unrestricted tester enrollment is authorized.
- Operations remains protected/private. Synthetic supervisor/session/queue/evidence presentation may be used for visual review but must not be represented as connected real-operations UAT or grant consequential decision authority.
- No real participant data, production auth, private evidence activation, real communications, real money movement or Phase 11/12 release authority is introduced by UIA.
- Owner-facing evidence must come from production-built or equivalent clean runtime presentation with no Next.js development toolbar,
1 Issuebadge, debug/canary labels or other developer-only UI leakage. - Existing backend, Android, PWA, portal, supply-chain, privacy, authorization and integration regressions remain mandatory; RC5 must not weaken them.
- UIA Issue #354 closed after exact source
bb84968453b891dd511faddc093a8874fce8abc4passed browser/PWA run30314869549, Android internal-distribution run30314870954, IAM-private operations run30314872253and canonical-domain run30315044253. - UIA is
CLOSED — CURRENT-MAIN SYNTHETIC OWNER REVIEW PROVEN: browser access is canonical, Android is internal/preauthorization-only, operations is IAM-private/synthetic, real participant UAT has not run and production release remains unauthorized.
RC6 implementation contract — CLOSED AND PRESERVED¶
- WhatsApp send authority is backend-owned and application-managed; Android/browser clients never receive Meta/WhatsApp credentials or directly decide provider delivery state.
- Outbound WhatsApp delivery originates from the DIREKT transactional outbox and must preserve stable idempotency across retries.
- Consent and opt-out state are checked at send time; a queued event cannot bypass a later withdrawal or channel-specific opt-out.
- Only approved/template-governed payloads may be sent where Meta policy requires templates; unrestricted free-form participant messaging is not introduced by RC6.
- Payloads must not include identity documents, certificates, raw evidence, auth tokens, exact private coordinates, reviewer notes or other restricted/private evidence.
- Webhook authenticity must be verified before delivery/read/failure receipts affect durable DIREKT state; duplicate/out-of-order webhook events must be handled idempotently.
- Retries are bounded, observable and fail-closed; provider errors cannot silently become
deliveredor erase original failure evidence. - A kill switch/provider enablement gate must default real/participant delivery off. Synthetic managed proof may run only with bounded synthetic/non-personal data and approved provider state.
- Production/participant WhatsApp delivery remains disabled until business/phone/template/provider/legal/privacy approvals and later release authorization are explicitly evidenced.
- RC6 is
CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY: exact-current-main managed run30137700769on source8838b7a6d726a5aed44ce21a39506c1265a98d15passed the private outbox → Metahello_worldtest-template send → authentic signed webhook receipt path on retry. The initial failure remains preserved in Issue #404. Existing RC0–RC5, UIA, backend/database/OpenAPI, Android/PWA/portal, payment, privacy, authorization and production-release gates remain regression-protected; production/participant WhatsApp delivery remains disabled.
RC7 implementation contract — CLOSED AND PRESERVED¶
- RC7 activates only the APIs justified by the current product flow: Maps SDK for Android for map display and backend Geocoding for bounded search-area/address normalization. Places and Routes remain disabled because the existing manual area input and PostGIS distance/service-area logic already satisfy the reviewed flow.
- Android and backend authentication remain separate. The Android key is restricted to DIREKT package/signing-certificate pairs and Maps SDK for Android; backend Geocoding uses the assigned Cloud Run service identity with a downscoped address-only OAuth token and no backend API key, secret value, static egress IP or Cloud NAT dependency.
- Exact private provider bases never become public markers, polygons, distance origins, ranking inputs, logs, telemetry or provider payloads. Only consented public premises and privacy-approved service-area geometry may render.
- Mobile providers render public service areas without a base marker. Fixed-premises markers require a consented public premises point. Hybrid providers may show the consented public premises and the separate public service area.
- Manual area and list discovery remain fully functional and are never treated as lower trust. RC7 adds no background-location permission and cannot make device location a prerequisite for discovery, authentication, verification or service access.
- Android Maps and backend Geocoding default disabled. Explicit source-controlled switches, valid protected credentials and synthetic-only non-production data are required for managed proof; provider outage, map-load failure or denied location capability must fall back safely.
- Backend Geocoding accepts bounded search-area input, constrains results to Zambia, filters provider responses and never exposes or logs credentials, raw provider payloads, unnecessary coordinate precision or unrestricted free text.
- Quotas, budget alerts, per-request timeout, bounded result count and rotation instructions are required. Routes and Places costs cannot be incurred because those APIs are not enabled or accepted by either credential.
- Managed closure is proven on exact source
47285575862cbf08845eaeabe093afea1ea79bd1through run30234521983/1: restricted key/API metadata, backend synthetic Geocoding, final APK restriction, API 36 map readiness and cleanup all passed. Artifact8641270327(sha256:24da53c0bd6fa885fa4a6814f70af090096192e6c5b7a03c89fba51416877fde) preserves the sanitized receipt; earlier failures remain preserved. - RC7 is
CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY. It does not authorize participant Maps usage, private-location publication, production authentication, real communications, real money, Phase 11 exit or Phase 12 release.
RC8 implementation contract — CLOSED AND PRESERVED¶
- RC8 is limited to sandbox adapters, runtime proof and reconciliation for DIREKT-owned provider subscriptions, verification-processing fees and renewal/re-verification fees.
- Real money, participant payment data, production provider endpoints or credentials, customer-to-provider service payments, escrow, stored value, wallets and marketplace payouts remain disabled and outside scope.
- Source checkpoint PR #454 was replayed onto the RC8-claimed baseline and merged at
6098b71f89d62fa059de298be11a8d9d8539c25eafter the complete exact-head regression matrix passed without overwriting RC0–RC7 closure evidence. - Provider credentials remain server-side and Secret Manager-backed with least privilege. Android and browser clients never receive credentials or declare payment success.
- Success requires independent provider verification plus exact provider reference, transaction identifier where applicable, amount and currency agreement with the backend-owned DIREKT intent and ledger.
- Provider observations, payment events, ledger postings, mismatch cases and adjustments remain append-only and idempotent. A mismatch opens reconciliation; it is never silently repaired.
- Refund and accounting-adjustment execution requires two independent approvers, requester exclusion, balanced ledger effects and operations-only revision-checked resolution.
- Managed proof may bind only the existing reviewed MTN MoMo, Stripe and PayPal sandbox/test credentials. DPO remains source-integrated and externally sandbox-proven but runtime-unbound because no DIREKT private sandbox credential exists; Airtel remains provider-pending and Flutterwave remains deferred/excluded.
- Managed evidence must use bounded synthetic values, sanitized receipts, exact reviewed source, explicit cleanup and no raw provider payload or credential leakage. A failed provider attempt remains preserved and cannot be documented as passing.
- RC8 is
CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY: exact sourceccc4e9463d810ddf554182b1607c22d3a7c8c8d3passed run30241092949/1with artifact8643323319(sha256:bbb4600eb5a062552947e91c878dd09c6d1e4dc307ae4783c7fa1fb4cf6e4935). MTN independent success, Stripe unpaid Checkout retrieval, PayPal unapproved-order retrieval, immutable reconciliation, duplicate suppression, mismatch review, two-person adjustment planning and temporary-job cleanup all passed. The trigger is consumed; application runtime, production, participant and real-money authorization remain false.
RC9 implementation contract — CLOSED AND PRESERVED¶
- The canonical input is the exact backend-generated OpenAPI 3 document after the permanent authorization, privacy, deferred-domain and sensitive-field checks pass.
- OpenAPI Generator is pinned to stable version
7.22.0; generation must run locally/CI without an online generator service and with timestamps hidden. - Generated output is reproducible and committed or otherwise hash-pinned; CI regenerates from the same spec/config and fails on byte drift.
- Kotlin adoption is incremental. The first runtime slice is the existing Firebase-to-DIREKT auth/session exchange; current UI, encrypted session storage, consent, fail-closed configuration, timeouts and error semantics must remain intact.
- The Kotlin target is
jvm-retrofit2withkotlinx_serialization; generated code must not introduce Android API-level regressions, unreviewed cleartext, permissive certificate handling or direct provider/database credentials. - TypeScript generation supplies canonical contract models/operation types to the server-only BFF. It must not move authenticated browser calls to the client, reveal the private Cloud Run API origin or replace the reviewed infrastructure-token/session boundary.
- Generated transport defaults may not become authority for authorization, trust, payment, retry, idempotency or offline-success decisions. DIREKT-owned wrappers/interceptors preserve those policies.
- Additive API changes remain backward compatible; breaking changes require
/api/v2. Unknown/new response fields must not crash released clients, and enum evolution requires an explicit safe policy. - Cross-client evidence must include backend OpenAPI, generator drift, Android unit/lint/build/instrumentation and functional web type/security/build regressions before migration promotion.
- RC9 is
CLOSED — DETERMINISTIC GENERATED CLIENTS / BOUNDED RUNTIME ADOPTION: PR #497 exact head04ef57f31414ec5165e353abba74afb8dfdcc901passed the complete backend, Android, web/PWA, W7, security, runtime-audit, Phase 10–12 and RC5–RC9 matrix, then squash-merged at70de95c73128e921cd4d7c667de0e5a442a9e0c0. Generated imports remain limited to the reviewed Android auth wrapper and server-only BFF type adapter. No production, participant, privileged direct-access, provider-secret, payment-provider or real-money authorization changed.
RC10 implementation contract — CLOSED AND PRESERVED¶
- Turnstile is conditional abuse control, not a completeness checkbox. It may be introduced only for a specifically reviewed browser-accessible public flow whose risk is not adequately controlled by authentication, admission gates, quotas and rate limiting.
- RC10 inventories all public mutating or provider-cost-bearing routes, including challenge issuance/verification, public Help, discovery assistance, discovery-area normalization and public discovery reads.
- Database-backed rate limiting remains backend authoritative, fail-closed and keyed by an HMAC of the network subject. Raw IP addresses, challenge tokens and provider payloads must not be stored in durable rate-limit evidence.
- If Turnstile is justified, verification is server-side with hostname/action binding, expiry and replay resistance; the secret remains server-only; the browser token is short-lived, single-use and never logged; accessibility fallback and a kill switch are mandatory.
- Turnstile must not become authentication, identity, verification, trust, payment, publication or authorization authority. It must not be installed globally or required by Android/native flows.
- If no current flow justifies Turnstile, RC10 closes as
NOT CURRENTLY REQUIREDwith a written threat model and explicit re-evaluation triggers. Any uncovered first-party rate-limit gap must still be repaired. - No Cloudflare Turnstile widget, site key, secret, package or runtime binding is provisioned merely to close RC10.
- Real participants, production authentication, production communications, real money and production release remain separately blocked.
- Exact-head evidence must include backend formatting/lint/type/tests/build/OpenAPI, abuse-policy tests, RC5–RC10 permanent contracts, PWA/W7/W8, runtime audit, supply-chain and documentation gates as applicable.
- RC10 is
CLOSED — NOT CURRENTLY REQUIRED / TURNSTILE NOT ACTIVE: PR #502 exact headcdab6622e0cc06e35cddca2bb5bc8ea70c027b38passed the complete backend, container, generated-client, PWA/W7/W8, runtime-audit, recovery, staging, Phase 11 synthetic, RC5–RC10 and documentation matrix, then squash-merged at620a99ba5465ad38ce012df0a8fa15e458de6505. The three public POST helper gaps are protected by the existing fail-closed database rate limiter; no Turnstile credential, widget, package or runtime binding exists. RC11 remains unclaimed.
RC11 implementation contract — CLOSED AND PRESERVED¶
- RC11 is reconciliation and closure only; it may not activate a new provider, SDK, participant channel, production environment or real-money path.
- RC11A requires the combined Android, backend, database, OpenAPI, generated-client, customer/provider PWA, operations portal and integration-runtime regression matrix on one exact head.
- RC11B maintains one managed evidence index that records exact source, run, artifact and boundary where available without inventing identifiers.
- RC11C reconciles the live ledger and current integration register while preserving
PENDING_PROVIDER,BLOCKED,DISABLED,IMPLEMENTED_GATED,SANDBOX_PROVENandEXTERNALLY_PROVISIONEDdistinctions. - Synthetic, sandbox and managed-canary evidence may never be relabelled as PRIMARY-PILOT or production evidence.
- Client applications retain no provider, database, payment or telemetry-admin credentials; backend authorization remains authoritative.
- Payment cannot create trust, verification, publication or ranking authority; AI cannot become consequential authority.
- Real participants, production authentication, participant communications/telemetry/Maps, production AI, real money and Phase 12 release remain blocked.
- RC11D requires a dedicated exact-head closure receipt, permanent verifier, Issue #261 completion and released lane.
- RC11 is
CLOSED — FINAL INTEGRATION RECONCILIATION / LANE RELEASED: PR #505 exact head66626d315a8d132dbf8f34749a2679e42c609d7cpassed the complete combined matrix and squash-merged at87f567fccfa92244c7951432436c7163c71d5fc7. The clean handoff names Phase 11C–11J execution preparation as next, while real pilot activity remains prohibited until the Phase 11 entry checklist is genuinely satisfied.
Phase 11C–11J execution-readiness contract — CLOSED AND PRESERVED¶
- This lane creates execution instruments only; it does not authorize participant recruitment, admission, data processing, external communication, provider activation, payment or production traffic.
PILOT_ENTRY_APPROVEDremains false and fail-closed. No workflow, deployment or documentation change may set it true in this lane.PRIMARY_PILOT_EVIDENCE_REGISTER.mdremains explicitly empty until approved, consenting participants generate evidence in the authorized pilot environment.- The protocol must cover 11C provider onboarding/evidence, 11D discovery/location/trust, 11E enquiries/handoff/reviews, 11F operations/field capacity, 11G devices/connectivity, 11H pricing/economics, 11I canonical corrections and 11J exit decision.
- The real-entry blocker register preserves DPC, transfer, qualified legal/privacy/consumer, notice/consent, Firebase real-canary, private-storage and deletion/withdrawal gates as open until actual evidence closes them.
- Wave ceilings remain at most 8 providers and 20 customers; actual approved counts may be lower and must be recorded before invitations.
- Immediate stop rules protect consent, authorization, private evidence, exact private coordinates, participant safety, credentials, data integrity, unsupported trust claims and real-money boundaries.
- Every 11I correction uses canonical production code, forward-only migrations, backend authorization, OpenAPI/client boundaries and full regression; pilot-only shortcuts are prohibited.
- The 11J instrument must require exactly one evidence-backed STOP, REPEAT, NARROW or PROCEED decision and must keep Phase 12 authorization false unless separately approved.
- The readiness package is
CLOSED — EXECUTION READY / REAL ENTRY BLOCKED / NO PRIMARY-PILOT EVIDENCE: PR #508 exact headae4fcb0350be4023f82e2be8df88c18cca583695passed the complete preserved matrix and squash-merged at2bf58c2c5df40aa76742730ec4a49644c2506a89. Issue #112 remains open; Wave 0 real-entry evidence reconciliation requires a new explicit claim.
Phase 11 Wave 0 finishing-line contract — CLOSED AND PRESERVED¶
- This lane may close repository-clearable preparation and verification only; it may not claim that regulator, counsel, provider, owner or participant evidence exists when it has not been supplied.
PILOT_ENTRY_APPROVEDremains false. No workflow, deployment, source document or local command may set it true in this lane.- PRIMARY-PILOT evidence and findings remain at zero; synthetic, secondary, sandbox or managed-canary evidence remains separately labelled.
- Official-source Zambia privacy, controller/processor, overseas-storage/transfer and consumer-protection research may be refreshed, but cannot close P11-G01 through P11-G06 without the required accountable authority.
- The lane must produce a structured evidence-intake manifest, hash/reference rules, accountable-owner attestations and a deterministic gate evaluator that fails closed on missing, expired, mismatched or unreviewed evidence.
- Repository-clearable technical preflight must verify exact source, migrations, private storage boundaries, Firebase fail-closed configuration, communication/Maps/telemetry/AI/payment exclusions, support/incident templates and zero unresolved repository critical/high defects.
- Real participant Firebase, invitation, consent, withdrawal, deletion and private-storage canaries remain blocked until legal/privacy/owner gates are actually closed; synthetic negative-path proof may not be relabelled as a real canary.
- The terminal Wave 0 decision must be one of
ENTRY_APPROVED,ENTRY_BLOCKED_EXTERNAL,ENTRY_BLOCKED_TECHNICALorSTOP, with exact unresolved gate IDs and no ambiguous partial activation. - If external evidence is absent, the finishing line for this lane is a verified
ENTRY_BLOCKED_EXTERNALreceipt and a minimal owner/manual action packet—not false Phase 11 closure. - Wave 0 repository finishing-line work is
CLOSED — ENTRY_BLOCKED_EXTERNAL / TECHNICAL PREFLIGHT PASSED: PR #512 exact head1befa902def70d2c997aaba260e0d8e2a5d4b12dpassed the complete matrix and squash-merged atf561658d140aaf214fa6eaca99c80bcc98ee284f. P11-G14 is closed for that source only; P11-G01–P11-G13 remain open, Issue #112 remains open and any later evidence lane requires a new explicit claim.
Runtime integration closure contract¶
- Close one bounded integration checkpoint at a time; do not batch unrelated SDK/provider activation.
- An external account, API key, DSN, secret or dashboard project is not
ACTIVEevidence by itself. - Each closure requires applicable source integration, least-privilege secret/runtime binding, privacy/security controls, fallback or kill switch, managed canary/device evidence, exact-head regressions and status documentation.
- Android/browser clients call DIREKT-controlled API/BFF boundaries; they do not receive privileged provider, database, payment, AI, registry or telemetry-auth credentials.
- Real participants, real external communications, real payment movement, production auth and production release remain separately gated.
- Payment state cannot create or improve verification, publication or ranking authority.
- AI output cannot independently verify providers, change trust/ranking/publication, authorize payments/escrow, decide disputes, override consent/authorization or act as legal/regulatory authority.
- Exact private provider coordinates, raw evidence, contact data, credentials and tokens must not leak into telemetry, public maps, browser caches or provider payloads.
- Sentry auth tokens remain CI/release tooling only and must never bind to API, portal, Android or browser runtime.
- The workstream releases or transitions the lane only after status/ledger reconciliation, exact-head regression matrix, managed evidence and handoff are promoted.
Dependency-safe implementation sequence¶
- RC0 — integration ledger, dependency/source audit, permanent-gate ownership sanity check and payment evidence reconciliation. Closed — PR #263.
- AI0 — provider-neutral AI foundation. Closed — PR #265; runtime activation remains per-use-case and data-classification gated.
- RC1 — Resend transactional-outbox runtime. Closed; synthetic managed execution proven; real-participant/production email remains disabled.
- RC2 — Sentry for approved NestJS/Next.js surfaces. Closed — PR #275 source + managed synthetic API/private-portal canary + closure PR #280; participant/production telemetry remains disabled.
- RC3 — Firebase Crashlytics Android. Closed — exact source
9098f7eb333baf096163f1564b3d8e5e5da3fcf0; managed bridge run29885635547successful; closure PR #338 merged at0d7d29313990c37b25bd985588866a85bbe10f83. - RC4 — FCM push delivery: server send path, token lifecycle, Android notification handling/permissions, retries and managed canary. CLOSED — exact source
f05ff19105cb8dc7c4621c044c110b6029f63300; managed run29916381754successful; participant/production push disabled. - RC5 — Firebase Test Lab device-matrix automation. CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED MATRIX — dedicated Spark project
direkt-testlab-502701-20260726; exact sourcec3744430a7beb1cd47246d858df9ac1379a068ac; managed run30183466799; API 26/33/36; zero flaky retries; participant/production authorization false. - UIA — post-VC owner-review promotion. CLOSED — CURRENT-MAIN SYNTHETIC OWNER REVIEW PROVEN — source
bb84968453b891dd511faddc093a8874fce8abc4; browser30314869549; Android30314870954; operations30314872253; canonical30315044253; participant/production authorization false. - RC6 — WhatsApp Cloud API application adapter. CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY — exact source
8838b7a6d726a5aed44ce21a39506c1265a98d15; managed run30137700769succeeded on retry through outbox → Meta test template → authentic signed webhook receipt; initial failure preserved in Issue #404; production/participant sends remain disabled. - RC7 — Google Maps runtime activation with separate restricted Android/backend credentials, privacy-safe publication semantics, quotas, manual/list fallback and kill switch. CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY — exact source
47285575862cbf08845eaeabe093afea1ea79bd1; run30234521983/1; artifact8641270327(sha256:24da53c0bd6fa885fa4a6814f70af090096192e6c5b7a03c89fba51416877fde); production/participant authorization false. - RC8 — sandbox-only payment-provider adapter closure/reconciliation. CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY — exact source
ccc4e9463d810ddf554182b1607c22d3a7c8c8d3; run30241092949/1; artifact8643323319(sha256:bbb4600eb5a062552947e91c878dd09c6d1e4dc307ae4783c7fa1fb4cf6e4935); MTN/Stripe/PayPal proved privately; DPO runtime-unbound, Airtel provider-pending, Flutterwave deferred; application runtime and real money disabled. - RC9 — OpenAPI-generated Kotlin and TypeScript client adoption/decision. CLOSED — deterministic generation, Android Firebase-session exchange adoption and server-only BFF type adoption merged through PR #497 at
70de95c73128e921cd4d7c667de0e5a442a9e0c0; exact-head matrix passed on04ef57f31414ec5165e353abba74afb8dfdcc901; no production/participant or privileged direct-access change. - RC10 — Turnstile threat-model decision. CLOSED — NOT CURRENTLY REQUIRED / TURNSTILE NOT ACTIVE — PR #502 exact head
cdab6622e0cc06e35cddca2bb5bc8ea70c027b38, merge620a99ba5465ad38ce012df0a8fa15e458de6505; first-party rate-limit gaps closed; production authorization false. - RC11 — combined integration regression, managed evidence index, live ledger/status reconciliation and lane release. CLOSED — FINAL INTEGRATION RECONCILIATION / LANE RELEASED — PR #505 head
66626d315a8d132dbf8f34749a2679e42c609d7c, merge87f567fccfa92244c7951432436c7163c71d5fc7.
Persistent stop conditions¶
Stop rather than merge or activate a later checkpoint if it would:
- regress Android/backend/database/OpenAPI/web/portal required gates;
- weaken Cloud Run IAM or expose privileged Supabase/database/Storage access;
- expose private evidence, raw contact data or exact private provider coordinates;
- fabricate or bypass participant, legal/privacy, payment, AI-provider or production-release gates;
- accept client-selected provider scope or authorization;
- allow commercial/payment state to influence verification or public trust claims;
- allow AI output to become authoritative verification/trust/payment/dispute/publication authority;
- store production credentials, model/provider secrets or telemetry admin tokens in application runtime or browser-readable surfaces;
- replace backend-authoritative behavior with static fixtures while claiming runtime completion;
- mark an integration or AI use case
ACTIVEwithout exact configured-provider/runtime evidence.
Conflict rule¶
The repository write lane is RELEASED. Issue #522, RC0–RC11, UIA, Phase 11C–11J readiness and Wave 0 finishing-line evidence remain immutable/regression-protected. Any future visual or functional write lane must be claimed from current main and preserve the exact deployed Lively Trust Marketplace closure. Real participants, participant data, real money and production authorization remain blocked until the explicit Phase 11 entry checklist is satisfied.