External task tools — cutover plan and evidence
Implemented under documented waivers; not merged or deployed. Feature code is complete; the latest authorized integration of origin/main (e9f6e9b7) into 8e6addd8 is pending CI. This implements the approved scheduler-removal design and replaces the modular intake implementation plan without erasing its historical evidence. No external schedule is configured.
Qualified successor, approved 2026-09-10: the managed Outlook design and implementation plan add real delegated read/send through new managed storage and authorization, not the retired scheduler grants, account-kind controls, /delegation or list_manageable_mailboxes. Historical no-replacement/personal-only statements below describe the cutover, not this new capability. User-reported PR #415 head 2a20299b11 includes the previous cutover with green Actions; pending-CI statements below are historical checkpoints. Managed mailboxes remain uncommitted/unverified and in progress. Retain the lane plan/dual-review waiver; the explicitly authorized Devin/Fable route supersedes the earlier Astra-only preference. No merge or deployment is authorized.
Authorized scope
External Claude, ChatGPT, or another MCP host schedules; North exposes generic tools and an explicit immediate send_newsletter/north__send_newsletter. Existing jobs stop only at the separately authorized deploy. The lane's existing plan/dual-review waiver remains authorized, as recorded in .claude/handoff/automation-tools-lane.md; visible Astra workers are by explicit user request. No merge or deploy is authorized by that waiver.
| Lane | Required result |
|---|---|
| Runtime | Delete scheduler worker/package, dispatch/execution lifecycle, old firm-newsletter sender and scheduled-newsletter package, profiles, and dead runtime/build/deploy consumers. Keep unrelated notification loops. |
| Web and chat | Remove automation board/navigation, scheduling/newsletter-management APIs and tools, execution/resume paths, orphan mailbox-grant lifecycle/display/tool/API controls, and the entire delegation settings page/navigation/account-kind API with its exclusive helpers. Keep normal membership/admin/auth management, Outlook connections elsewhere, ordinary chat, retained history, and owner/organization read checks. |
| Native, MCP, provider | Expose the design's generic catalogue. Save by task_key without a scheduler; retain authorized historical reads. Deliver explicit Markdown newsletters through personal Outlook to at most 20 recipients, with correlation-only keys and no automatic uncertain-send retry. |
| Authorization and data | Keep stored user data and historical provenance. Preserve personal Microsoft file authorization while organization OneDrive ingestion is off; no new connect flow or writes outside North Drafts. Keep disconnected-feeder knowledge gates. |
| Operations | Retire old scheduler and sender before switching code/traffic; refuse active-process cutover and pre-decommission rollback. No live operations in this implementation lane. |
Integration evidence supplied on 2026-09-10
Earlier integration results are recorded in /tmp/app-cutover-proof-20260910; the counts below are supplied evidence, not broad suites rerun by the cleanup writer. Known failures and environment limitations remain explicit.
| Surface | Reported evidence | Limit |
|---|---|---|
| Runtime / notifications | Runtime removal across 43 files; 66 notifications tests. | Not a root integration result or proof of live process retirement. |
| Web | 145 retained tests + 35 API tests + 2 real isolated-PostgreSQL history owner/organization tests. | No UI listener; visual verification unavailable. No dev server started for this lane. |
| Root / Next | Root lint and typecheck: 61 tasks passed each. Next build: 58 pages generated. | Local gates, not CI or deployment evidence. |
| Chat / DB | Chat: 289 passed. DB: 335 passed plus 7 separately reported checks. | Isolated test evidence; no broad DB suite rerun for grant cleanup. |
| Agent runtime | 4,980 passed; 2 known baseline matter-retrieval failures. | Not a full-suite-green claim. |
| MCP | 782 passed; 5 known baseline organization-isolation failures. | Not full DB or external-host end-to-end green. |
| Provider | 107 tests. | No live provider delivery or token-refresh proof. |
| Drive | 48 passed. | No live OneDrive write verification. |
| Cheap eval | Environment-blocked: dummy Voyage credentials and absent eval organization. | No full cheap-eval-green claim. |
R2 exception: two real storage fixtures ran in the initial broad run with inherited credentials; their cleanup passed. The final broad rerun was sanitized (the agent log records local storage fallback and skipped storage fixtures). Preserve this exception rather than claiming that the entire lane performed no live-provider writes.
Grant and classification deletion rationale: the only remaining consumers were lifecycle/settings display and the discovery tool; neither grants nor account classification had a non-scheduler operational consumer. Removed those modules, exports, registration/concurrency entries, the entire delegation page/nav/router/query, exclusive account-kind control/transport, and obsolete grant/classification tests. No shim or replacement page. Shared canManageWorkspace/parseRoles and their tests remain: workspace settings, member management, MCP and knowledge pages still consume them. Normal membership/admin/auth and Outlook connection flows remain unchanged. Historical member classification columns/rows, grant rows/schema/migrations, analytics historical types, and thread ownership/sharing remain unchanged.
Earlier grant-only cleanup checks (before final classification removal): root lint and typecheck passed (61 tasks each and script tsconfigs); sanitized Next build passed with 58/58 pages. The first sanitized build lacked AUTH_TRUSTED_ORIGINS; supplying its explicit localhost value fixed that setup failure. An initial typecheck raced temporary smoke-file removal; the stable rerun passed. These results are historical evidence, not verification of the final route deletion.
Earlier grant-only focused checks: 36 web route/auth tests, 7 auth-session tests, 48 native catalogue/concurrency/mail tests, 75 telemetry tests with the Bun runner, and 3 documentation converter tests passed. The initial telemetry Vitest invocation could not load bun:test. A temporary server-render smoke of the then-retained classification page passed and was removed; that page and its classification-route tests are now obsolete and deleted. No browser visual verification was performed.
Final classification removal: 117 focused web tests passed across the actual Hono absence checks, API/session auth, shared role authority, workspace settings, member actions, Outlook OAuth and settings-shell rendering. The account-kind POST API now returns 404 with and without authentication, alongside the retired grants. Rendering retains Members/General/Connections navigation and excludes Delegation. Native catalogue/concurrency/mail checks passed 48 tests: no list_manageable_mailboxes, and generic send_newsletter remains. All final checks use env -i and bun --no-env-file; Next/runtime checks receive only explicit dummy credentials and unreachable DB/Redis addresses, without a dotenv wrapper or live R2 credentials.
After final route removal, sanitized root lint passed (61 tasks, warnings only), root typecheck passed (61 tasks plus both script tsconfigs), and sanitized Next build passed with 57/57 pages. The generated app-paths manifest confirms that /delegation is absent while Connections, Members and Workspace pages remain. Documentation status-preservation tests passed 3/3. Middleware-deprecation and pdfjs-dist externalization build warnings remain; focused Outlook tests also emit non-fatal analytics-mock warnings. UI verification is server rendering plus the actual build manifest, not a browser session or live provider exercise.
Code-complete checkpoint — b83538ba
Product cutover b83538ba atop f238fb72 covers 310 files (+2,440/−54,769). Final orchestrator-supplied proof: root lint/typecheck passed 61 tasks each plus script typechecks; Next generated 57/57 pages; orphan grant and classification UI/API removal passed 117 focused web and 48 native tests. Stored history, database ownership, and owner/organization authorization are preserved. This is local code-complete evidence, not final CI, merge readiness, or deployment.
Coverage checks passed 11 tests, alongside deterministic tool/protocol/ownership smokes. The orchestrator waives the live cheap-eval requirement for this decommission: no new retrieval/model quality behavior is claimed, and live quality remains unverified. The environment-blocked eval and known 2 agent + 5 MCP baseline failures above remain disclosed; full suites are not green. Plan and dual reviews remain user-waived under the original lane decision.
Latest main integration local proof — e9f6e9b7 into 8e6addd8
Current merge source is e9f6e9b7766945042028410a3dbb58885dc580dc, PR #416. Its commit and primary PR body require proactive-screenshot retirement while preserving explicit image sharing, chat, meetings, and MCP security gates. Keep upstream retired-agent rejection before database/model work and retained catalogue coverage; retain scheduler retirement and remove obsolete declaration-catalogue/intake-execution tests rather than restoring their imports. Auto-merged runtime.ts, chat-runtime run.ts, and MCP protocol changes need no manual product fix. The four conflict files are marker-free; the index remains unmerged until the orchestrator stages the resolutions. No merge completion was performed.
| Current command / working directory | Observed result |
|---|---|
Root: bun --no-env-file run lint | PASS: 61/61 tasks, zero cached; script ESLint completed with 0 errors / 36 warnings. Package warnings remain. |
Root: bun --no-env-file run typecheck | PASS: 61/61 tasks, zero cached, plus both script tsconfigs. |
apps/web: bun --no-env-file x --no-install next build | PASS: compiled, TypeScript passed, 57/57 pages generated. Middleware deprecation and two pdfjs-dist externalization warnings remain. |
packages/agent-runtime: vitest run --maxWorkers=2 src/runtime.test.ts src/tools/index.test.ts src/tools/concurrency.test.ts src/tools/list-recent-mail.test.ts src/tools/read-email-attachment.test.ts src/tools/mail-send.test.ts src/tools/send-newsletter.test.ts | PASS: 63 passed, 2 opt-in live tests skipped; 7 files. |
packages/chat-runtime: vitest run --maxWorkers=2 src/run.test.ts src/run-desktop.test.ts src/run-attachments.test.ts src/run-resume.test.ts | PASS: 159 passed; 4 files. Existing partial-graph mock warnings and dummy Redis connection refusals occurred; desktop exercised the in-process lock fallback, not real Redis locking. |
apps/mcp-server: vitest run --maxWorkers=2 test/mcp-protocol.test.ts -t 'lists immediate personal writes without an organization feeder or scheduler'; separately -t 'uses only the active mail-search token|initialize → tools/list returns exactly the admitted C3 catalogue' | PASS: 1 and 6 selected tests respectively; 145 and 140 excluded per invocation. Seven distinct protocol fixtures cover immediate writes without scheduler/feeder, active mail search, and exact Clio-gated admission. Not a full protocol-suite or real-Redis result. |
apps/mcp-server: vitest run --maxWorkers=2 test/tools-discovery.test.ts | PASS: 10 catalogue tests. |
apps/worker-notifications: vitest run --maxWorkers=2 src/newsletter/changelog.test.ts; root: bun --no-env-file test docs/superpowers/convert-docs-to-html.test.ts | PASS: 3 changelog parser tests and 3 status-preservation tests. |
All Vitest commands use bun --no-env-file x --no-install, bypassing dotenv package scripts. Checks run under env -i PATH=/home/kwiss/.bun/bin:/usr/local/bin:/usr/bin:/bin HOME=/tmp CI=true, with APP_DATABASE_URL and DATABASE_URL set to postgres://dummy:dummy@127.0.0.1:1/dummy and REDIS_URL to redis://127.0.0.1:1 when needed. Next additionally uses NODE_ENV=production __NEXT_PROCESSED_ENV=true NEXT_TELEMETRY_DISABLED=1, explicit dummy auth/model/Clio settings, localhost auth/MCP URLs, and an unreachable connectors-api URL. No R2/provider call, live or shared DB/Redis suite, dependency installation, dev server, staging, commit, push, abort, or deployment was performed in this integration check.
Throwaway merge smoke PASS: every complete changelog entry from both parents survives (106 each, 107 unique combined); all four conflict files are marker-free; successor metadata remains implemented with historical 8e6addd8 green and current e9f6e9b7 pending CI. The real Next manifest excludes Delegation/Automations and retains Connections/Members/Workspace. Both preexisting Outlook recovery HTML files retain their original SHA-256 checksums. status.ts sync regenerated STATUS.md/index.html; the generator dry run reported zero page rewrites. The smoke script is removed after verification. These are current local results, not new CI or proof that previously documented broad-suite/environment failures are fixed.
Historical first main integration proof — 2026-09-10
kwiss-authorized origin/main (db803be4) into feature fc5ebb01 completed at 6e7aae6a, without rebase or force push; this was not a PR merge or deployment. The four conflicts are resolved. Changelog parsing preserves all 106 entries from both parents, including cutover, classification, and Outlook recovery. Every incoming environment-example value remains except the retired scheduler port; classifier credential guidance remains. Both indexes were regenerated from canonical metadata, not selected from either parent.
Historical merged-tree gates at 6e7aae6a: bun --no-env-file run lint passed 61/61 tasks (warnings only); bun --no-env-file run typecheck passed 61/61 tasks plus both script tsconfigs (52 task results reused from the post-merge attempt). The first typecheck lacked the incoming worker-mail connector-auth workspace link; bun --no-env-file install --frozen-lockfile --ignore-scripts restored it without a lockfile change. Direct bun --no-env-file x --no-install next build from apps/web passed, generating 57/57 pages; Delegation remains absent and Connections/Members/Workspace remain. Middleware-deprecation and two pdfjs-dist externalization warnings remain.
Focused Vitest proof, each via bun --no-env-file x --no-install vitest run --maxWorkers=2: web 123/123 across lib/api/app.test.ts lib/api-auth.test.ts lib/auth-session.test.ts lib/settings/router.test.ts lib/settings/roles.test.ts lib/connections/outlook-oauth.test.ts app/(settings)/members/actions.test.ts app/api/connectors/outlook/callback/route.test.ts components/app-shell/settings-shell.test.ts; agent-runtime 57/57 across src/tools/{index,concurrency,list-recent-mail,read-email-attachment,mail-send,send-newsletter}.test.ts; connectors-api 54/54 across src/lib/personal-drive.test.ts src/routes/personal-drive.test.ts; worker-notifications changelog parser 3/3 via src/newsletter/changelog.test.ts. The initial web invocation omitted dummy Clio settings; the corrected run passed. Outlook analytics-mock warnings remain non-fatal.
Historical bun --no-env-file test docs/superpowers/convert-docs-to-html.test.ts scripts/preprod-install-env.test.ts: docs status preservation 3/3; deployment environment 5 passed, 1 failed. The DCC scrub test at scripts/preprod-install-env.test.ts:108 receives three definitions instead of one: deploy/preprod/install.sh:46 omits DCC keys such as CONTEXT_DIGEST_MODEL from its scrub list while appending them later. Both parents contain that omission. This pre-existing, out-of-scope failure remains unfixed; implementation closure does not waive or pass that test. A dummy-example --render-env smoke passed: classifier routing survives; retired scheduler port/tuning are stripped.
Historical gate processes used env -i; tests/build bypassed package dotenv wrappers with explicit dummy credentials, unreachable DB/Redis, blank R2/sync DSNs, and Next's __NEXT_PROCESSED_ENV=true. Installer safety exception: Bun 1.4 emitted a .env.local load notice despite --no-env-file; no secret values were printed. That verification writer performed no live-provider request, shared DB/Redis operation, dev-server launch, staging, commit, push, merge completion, abort, or deployment. The subsequent authorized integration is recorded above; the earlier R2 exception remains disclosed. The user reports the two PostgreSQL history tests are wired in CI; no local DB fixture was created or rerun.
Implementation closure and remaining release boundary
- Historical code CI on
6e7aae6apassed all nine GitHub Actions checks: build, lint-migrations, provenance-guard, quality, quality-code, quality-deploy, test, whisperx, worker-image-safety. The user confirms all nine also passed on metadata head8e6addd8, including retained-history CI. Main then advanced during CI; the lateste9f6e9b7integration is pending CI, not covered by those earlier green heads. - Devin Review separately remains FAILURE, description “completed analysis in 4s”;
gh pr checksstill exits 1. No new review or inline findings since the earlier 16:01 checkpoint. All eight available threads are adjudicated/resolved: two actual drive issues fixed infc5ebb01(7 pre-fix failing reproductions, then 54 passing tests), six superseded/rejected/waived with evidence in PR comments 5624056218 and 5624144267. - The explicit 2026-09-09 user plan/dual-review waiver remains. The orchestrator treats the nonrequired external review status as nonblocking under that waiver; reviews have not converged. Baseline 2 agent/5 MCP failures and the DCC duplicate-env failure remain documented; live cheap eval is waived, not passed, and live quality remains unverified.
- PR #415 targets main with #412's ancestor work included; #412 is closed unmerged, branch retained. Cutover changelog coverage remains bound to product commit
b83538ba; the latest integration also preserves the upstream screenshot-retirement entry. - This pair remains
implemented: feature code-complete under the existing waivers and exceptions, not final CI or release approval. These evidence updates belong to the current integration; no later status-only commit or extra status step is required. kwiss still owns PR merge and deploy decisions. Retirement/rollback procedures below remain unperformed live; no external schedule is configured.
Authorized deployment procedure, not performed
Follow deploy/preprod retirement instructions through the authorized deployment path. Stop/mask the old scheduler and stop the old firm-newsletter sender before code/traffic cutover; refuse if either remains running. The normal fleet restart brings back notifications from the new release, preserving pending-confirmation nudges and the weekly product digest. Installer-only retirement leaves notifications stopped until that deploy.
Refuse a rollback target containing apps/worker-automations or apps/worker-notifications/src/loops/firm-newsletter.ts; roll forward. Existing jobs cease at this authorized retirement point. Do not replay old jobs or uncertain sends. This document records a required procedure, not an executed stop/mask or live validation.
Documentation closure
The predecessor pair remains superseded; this successor pair remains implemented. Regenerate both indexes from canonical metadata with bun --no-env-file docs/superpowers/status.ts sync in this integration. Release copy remains bound to b83538ba and describes behavior when deployed, not an existing deployment. The current integration is pending CI; do not add a subsequent metadata-only commit.
This cleanup writer made no commits, pushes, PR operations, merges, deployments, dev-server launches, database writes, or live-provider writes. The earlier broad-run R2 exception is disclosed above, not erased by the sanitized rerun.