Commit graph

65 commits

Author SHA1 Message Date
143eef2f0d BINKY-WP-0005 finished: first Qonto pull and CostRunRate v2
All checks were successful
Work Records / validate (push) Successful in 13s
Live custody path tenants/binky/qonto-api (API_KEY/API_USER). First read-only
thirdparty pull (122 txs): desk 297.50 €/mo, Qonto plan 70.80 €/mo, main
balance 2185.94 €. Evidence under finance/; workplan status finished.
2026-07-21 21:42:10 +02:00
custodian-sync
fc4c2149e3 chore(consistency): sync task status from DB [auto]
All checks were successful
Work Records / validate (push) Successful in 13s
Updated by fix-consistency on 2026-07-21:
  - update .custodian-brief.md for binky-control
2026-07-21 21:41:11 +02:00
892c174b7a BINKY-WP-0005: OH/T05 runbook and lane-scaffold notes for Qonto MCP
Some checks failed
Work Records / validate (push) Has been cancelled
Prepare first-pull path after DEC-2026-004: copy-paste founder provision,
CCR apply, catalog promote, and CostRunRate update steps. T05 still waits
on Red-lane API key provision.
2026-07-21 21:26:25 +02:00
5f5f74c017 CUST-WP-0061-T05: retarget queue closures to WORK-RECORDS.md (generated)
All checks were successful
Work Records / validate (push) Successful in 22s
Convention change, not new code: closing an item now means setting its
terminal status (status: closed/resolved/done + outcome where
applicable) directly on the item's own yaml block in place, instead of
deleting it and hand-writing a bullet in a separate "Completed"/
"Resolved decisions" log. WORK-RECORDS.md (CUST-WP-0061-T04, generated
by fix-consistency's C-33) already lists every closed/resolved/done
record with status/lane/source -- that supersedes the hand-maintained
logs as the going-forward view.

- AutopilotWorkQueue.md: closing note added; "## Completed" relabeled
  "(historical -- pre-canon, 2026-07-21)", frozen as-is, nothing
  migrated or deleted
- DecisionQueue.md: closing note added -- its "## Resolved decisions"
  entries were already structured as in-place yaml blocks with
  status: resolved (ahead of AWQ's convention already), so this only
  clarifies the log is superseded going forward, no structural change
- OfficeHourQueue.md: closing note added -- items already live under
  "## Queued items" with status: queued|prepared|done in place, no
  separate log ever existed here
- OperatingRhythm.md: queue-hygiene checklist updated to describe
  in-place status transitions instead of "moved to the log"; added
  item 5 noting WORK-RECORDS.md needs no hand-maintenance

Re-ran fix-consistency: WORK-RECORDS.md content unchanged (correctly
idempotent -- these were prose-only edits, no yaml block content
changed).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-21 01:54:40 +02:00
c523e0fe44 Add generated WORK-RECORDS.md (CUST-WP-0061-T04)
All checks were successful
Work Records / validate (push) Successful in 17s
First fix-consistency run with the new C-33 check: a cross-cutting,
file-derived index of every work record in this repo (5 workplans, 31
tasks, 3 intake items, 4 decisions, 5 engagements) -- the orientation
view the work-record architecture was designed to provide, generated
not hand-maintained.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-21 01:20:45 +02:00
5f43038353 C-32 registration: link real AWQ-002/003/006 to hub intake records
All checks were successful
Work Records / validate (push) Successful in 40s
Live verification of the new fix-consistency C-32 check
(state-hub CUST-WP-0061-T02): AWQ-002, AWQ-003, AWQ-006 were open,
never-registered intake items in AutopilotWorkQueue.md. C-32 created
real hub intake records for each and wrote state_hub_intake_id back —
the exact registration gap the work-record canon was built to close,
caught on real, non-synthetic data on its first run.

(A throwaway BINKY-IN-9001 test block used to trigger this run was
never git-tracked and has been removed from disk; its hub record was
closed declined as cleanup.)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-21 00:47:49 +02:00
1d936319df work-records gate: runner substrate fix (apt python3 on ubuntu-latest)
All checks were successful
Work Records / validate (push) Successful in 13s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 02:08:35 +02:00
e29c174f2f work-records CI gate — CUST-WP-0060-T06 pilot
Some checks failed
Work Records / validate (push) Failing after 3s
Wires the canon work-record validation workflow (repo-seed template).
Local proof: 45 records checked, 0 errors, 0 warnings — AWQ/DEC/OH ids
pass grandfathered, zero renames (the acceptance test for the
grandfathering design).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 02:07:37 +02:00
ff579be1aa DEC-2026-004 approved: Qonto provisioning scheduled for next office hour
- DecisionQueue: DEC-2026-004 → resolved (approved, Bernd, 2026-07-19);
  hub decision a2a9de69 resolved
- OH-2026-003 enriched with the Red-lane provisioning steps (API key +
  bao kv put per integrations/qonto-mcp.md) for the dashboard visit
- qonto-mcp.md checklist: approval done, provisioning next

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-19 14:31:02 +02:00
custodian-sync
a95dc29a73 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-19:
  - update .custodian-brief.md for binky-control
2026-07-19 14:30:58 +02:00
3cfb9f553c BINKY-WP-0005: Qonto MCP integration — workplan registered, design + DEC-2026-004
- AWQ-010 promoted to workplan BINKY-WP-0005 (hub 6139db83, tasks T01-T05
  registered via fix-consistency C-06); queue item moved to Completed
- integrations/qonto-mcp.md: self-hosted qonto/qonto-mcp-server chosen over
  hosted mcp.qonto.com OAuth connector (no-native-integrations policy);
  OpenBao lane tenants/binky/qonto/api mirroring company-email custody;
  read-only via harness tool allow-list, payments Red lane forever;
  consumers: Finance Steward rhythm, CostRunRate TBC rows, OH-2026-003
- DEC-2026-004 prepared (founder Red lane: API key + bao kv put), hub
  decision a2a9de69

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-19 14:26:55 +02:00
custodian-sync
ba4dfeea84 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-19:
  - update .custodian-brief.md for binky-control
2026-07-19 14:26:22 +02:00
06afc317f1 mail triage 2026-07-18 (founder) + AWQ-010 Qonto MCP integration
- E-mail triage log section added: jamesandersons spam resolved by
  founder; IHK Sommerfest invitation (August, founder calendar call);
  Qonto MCP mailing -> actionable
- AWQ-010: Qonto MCP integration prep (read scopes first, ops-warden/
  OpenBao credential lane, no native integrations; complements DUO =
  DATEV Unternehmen Online as main accounting, does not replace it)
- OH-2026-003 enriched: MCP integration is an argument FOR keeping
  Qonto; check API/plan prerequisites while in the dashboard

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 17:03:07 +02:00
custodian-sync
faca8019ba chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-18:
  - update .custodian-brief.md for binky-control
2026-07-18 16:40:35 +02:00
dd184613a9 kaizen metrics: harness catch-up runs 2026-07-18 (coach, review-prep)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 16:40:15 +02:00
80923a519b cutover executed: definitions live, deploy key attached, bridge paused
DEC-2026-003 deployment 2026-07-18: image with resolver + enabled
definitions imported to railiance01 k3s, sync 20/20 upserted, Temporal
schedules reconciled (3 Binky schedules live), cron bridge paused for
the Mon-Wed verification window.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 15:51:36 +02:00
6ab1391b18 BINKY-WP-0004-T06 in progress: DEC-2026-003 approved, definitions enabled
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 14:38:40 +02:00
b6c583f411 cutover runbook: deploy-key attach via warden lane, not founder UI clicks
Per ops-warden INTENT §7 / WARDEN-WP-0029 (founder directive 2026-07-18).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 14:27:23 +02:00
7425750e2b DEC-2026-003: hub decision id write-back
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 13:55:15 +02:00
ff6df2cc76 rhythm: weekly founder review prep note 2026-07-18 (week 1 milestone-free, RISK-005 watch)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 13:49:20 +02:00
custodian-sync
8e3b0303b6 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-18:
  - update .custodian-brief.md for binky-control
2026-07-18 13:49:00 +02:00
c1597691e4 BINKY-WP-0001 complete: bootstrap tasks verified and closed
- T01: generated files reviewed — INTENT is ratified canon v1.0; SCOPE
  caveat replaced with review stamp
- T02: local verification commands added to AGENTS.md (fix-consistency,
  agent-harness validate, bridge syntax check, queue YAML parse)
- T03: satisfied long ago — BINKY-WP-0002..0004 exist and are hub-synced

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 13:48:40 +02:00
0978a0796e rhythm: 2026-07-18 daily brief + DEC-2026-003 cutover go package
Queue hygiene: DecisionQueue gained the missing prepared package for the
now-unblocked BINKY-WP-0004-T06 cutover; OfficeHourQueue and
AutopilotWorkQueue healthy (hub fix-consistency skipped — green lane,
no network).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 13:48:24 +02:00
efe4e55e6a feat: agent-harness tenant #1 instance manifest (HARNESS-WP-0001-T07)
Extend .kaizen/schedule.yml with harness fields for daily rhythm, weekly
mail intake, and weekly review-prep; add task files, onboarding handoff
doc, and cutover gate updates for BINKY-WP-0004-T06.
2026-07-18 11:07:12 +02:00
agent-harness
04410c6269 harness onboard: review-prep 2026-07-18 11:06:51 +02:00
agent-harness
2785d511e2 harness onboard: mail-intake 2026-07-18 11:06:50 +02:00
agent-harness
defc938fd3 harness onboard: daily-rhythm 2026-07-18 11:06:48 +02:00
11bba92b84 docs: mark agent-harness Red-lane secrets Lanes 2–3 provisioned
Forgejo sandbox deploy key and mail AppRole delivered to railiance01;
checkboxes closed with host path and catalog ids (no secret values).
2026-07-17 23:57:56 +02:00
7c5e644d6f DEC-2026-002 resolved: agent-harness (single shared runtime)
- DecisionQueue: moved to resolved log with rescoped outcome (three-layer
  model; binky-control = tenant #1); hub decision resolved
- Secret lanes doc: identifiers renamed executor-worker → agent-harness
  before any provisioning happens
- Cutover runbook + WP-0004-T06: gate 1 done; deployment gate now points
  at HARNESS-WP-0001-T06/T07 in the agent-harness repo

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 23:37:16 +02:00
3c0404fdba DEC-2026-001: hub decision id written back (retroactive mirror)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 19:26:23 +02:00
d917883f83 DEC-2026-002: register in State Hub decisions view
Hub decision 63620255 (open, pending) linked to the WP-0004 workplan;
id written back here. DecisionQueue.md items were previously file-only
and invisible to /decisions/ and the pending_decisions resolver.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:21:41 +02:00
02a8d293ab BINKY-WP-0004 T04/T05 done, T06 blocked with cutover runbook
- T04: executor-worker MVP (new repo ~/executor-worker) ran one task
  end-to-end: kaizen schedule-prepare persona, agentic llm-connect
  session, sandbox commit e043f21, hub progress event
- T05: recurring mailbox scan fully wired (two-phase: deterministic
  credentialed scan + LLM triage session with suspicious-mail log-only
  rule); email checklist item 9 now gated only on Lane 3 AppRole
- T06: blocked — gates are DEC-2026-002, Red-lane Lanes 2/3, Railiance
  deploy, 3 verified runs; runbook at
  integrations/executor-cutover-runbook.md

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:17:15 +02:00
ce14c254db BINKY-WP-0004-T03: executor worker secret lanes prepared
- Lane 1 (LLM provider): reuse verified — warden catalog
  openrouter-llm-connect, policy workload-kv-read-llm-connect-provider-secrets
- Lane 2 (forgejo deploy key): new, per-repo write deploy key design,
  founder Red lane
- Lane 3 (mail-scan AppRole): executor-worker-binky-mail bound to the
  existing IMAP read policy — closes email checklist item 9's auth
  blocker on paper; provisioning founder Red lane
- No secret values anywhere; T04 can proceed on Lane 1 alone

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:08:33 +02:00
0f91a98d08 BINKY-WP-0004-T01: kaizen schedule opt-in + executor ownership decision
- .kaizen/schedule.yml scaffolded via schedule init, validates clean
  (coach + optimization weekly, tdd-workflow disabled)
- DEC-2026-002 prepared: executor worker in a new small repo, per
  ADR-005 boundaries; fallback allows sandbox prototype, no cutover
  before resolution
- Decision rationale recorded in the executor assessment

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:01:19 +02:00
custodian-sync
5e22a45cbf chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-17:
  - update .custodian-brief.md for binky-control
2026-07-17 12:20:35 +02:00
bcabe2d17b BINKY-WP-0004 draft: workstation-independent executor
Six tasks from the llm-connect executor assessment: kaizen WP-0006
alignment + schedule opt-in, binky_rhythm_status resolver, OpenBao lanes
(incl. non-interactive AppRole for recurring mail scans), executor worker
MVP on Railiance, recurring mailbox scan, cutover retiring the cron
bridge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 12:20:11 +02:00
9cf9788599 rhythm bridge 2026-07-17: queues clean, daily brief; AWQ-003 evidence from mailbox scan (Sedo account, IONOS registrar)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 10:57:11 +02:00
4fb7cc7726 AWQ-009 done: Stripe webhook failure = stale Blobr preprod endpoint
DNS for api.preprod.blobr.dev (and blobr.dev) no longer resolves; Stripe
has sent monthly failure digests since April. Deletion is a founder
dashboard action, prepared as OH-2026-005 incl. webhook-endpoint
inventory while in the dashboard.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 10:54:52 +02:00
686d2d3dbf email lane live: first read-only mailbox scan (93 messages)
Scan c3c7e784 via warden/OpenBao lane, evidence CSV in mailmeta/reports/
(metadata only; sqlite state gitignored). Checklist item 8 done. New
AWQ-009: Stripe webhook delivery failure noticed 2026-07-05 — first
real-world event caught by the lane. Two suspicious external mails
logged, not acted on.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 00:47:50 +02:00
260f734806 company-email: mark OpenBao lane provisioned and active
Red provision and capabilities-safe verify complete (WARDEN-WP-0028).
2026-07-17 00:33:20 +02:00
b2ff07b036 Record IONOS IMAP host facts for company mailbox
Blue-lane provider data: imap.ionos.de:993 SSL/TLS; username is full
email address. Non-secret email-connect config; password remains Red
OpenBao provision only.
2026-07-17 00:15:25 +02:00
a2a561757f Align company email OpenBao plan to tenants/binky path
Match WARDEN-WP-0028 / CCR-2026-0007: mount tenants, checklist for
founder Red provision and host confirmation.
2026-07-17 00:09:28 +02:00
f53f05cf53 rhythm bridge 2026-07-16: queue hygiene clean; AWQ-005 website draft; include AWQ-008 paper-mail intake artifacts + hub id sync
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 15:02:48 +02:00
86aa02c90a rhythm bridge: installed by founder; fix script exec bit, add health check note
Crontab line active (weekdays 08:23). chmod +x had been lost when the
original install command was denied — without it every cron run would
have failed silently.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 14:34:25 +02:00
0144ca8131 finance: record railiance01 VM upgrade in cost base
4 vCPU / 16 GB at 25,19 EUR/mo, 24-month commitment (~604,56 EUR total,
to ~2028-07). Documented run-rate floor now ~100 EUR/mo. Added note that
this table feeds adaptive-pricing's allocated_fixed_cost (cost floor) —
adaptive-pricing consumes cost data, it does not capture it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 14:19:30 +02:00
custodian-sync
a048542394 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-16:
  - update .custodian-brief.md for binky-control
2026-07-16 14:05:25 +02:00
eea17a7abc BINKY-WP-0003-T06: llm-connect executor assessment; workplan done
llm-connect = engine (adapter library), kaizen-agentic WP-0006/ADR-005 =
persona + schedule-prepare convention, activity-core = scheduler with a
stub TaskExecutorWorkflow. Missing piece: one thin executor worker on
Railiance. Follow-up workplan proposal (BINKY-WP-0004 candidate) included.
All six WP-0003 tasks done.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 14:04:59 +02:00
89754611f0 BINKY-WP-0003-T05: activity-core wiring — 3 proposed definitions landed
Deployment verified: production-backed on Railiance, issue-core REST sink,
TaskExecutorWorkflow still a stub (llm-connect's slot). Definitions landed
disabled in activity-core commit b2fa964; enablement needs the
binky_rhythm_status resolver + an executor.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 14:04:37 +02:00
306a8cd232 BINKY-WP-0003-T03: cost & run-rate table v1 (AWQ-004)
Evidence from 2binky archive: FSW DATEV pass-through 483,69 EUR/yr, HUB31
desk contract renewed to 2027-04, private-card company costs (bubble.io,
AI subs), open 450 EUR Binect receivable. Audit corrected: desk landlord
is HUB31; Binect is income side.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 10:59:04 +02:00
d2f68f0f53 BINKY-WP-0003-T02: OK audit template v1 (AWQ-001)
Company-agnostic flagship-offer template generalized from the Binky
dogfood run. audit-core assessed as home candidate — it owns audit event
logging, not company audits, so the template stays in binky-control.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 10:56:17 +02:00