Tracks the Phase 1 scope from the architecture blueprint (policy kernel
+ REST, no MCP yet): ratify the five blueprint decisions, service
skeleton with default-deny policy, REST surface + CostRunRate cutover,
smoke tests and closure/handoff to Phase 2.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Design for an MCP gateway control plane so multiple agent harnesses
share one enforced read-only policy against the Qonto API, instead of
each client trusting its own local tool allow-list. Follows up on
BINKY-WP-0005.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Align AGENTS, AutonomyPolicy, SCOPE, OperatingRhythm with fleet residual
role (live intakes, not SCOPE prose). Capture BINKY-WP-0006 leftovers as
AWQ-011 (brief-weekly) and AWQ-012 (open-weights retarget).
Host LLM_CONNECT_URL discovery uses ClusterIP when DNS is unreachable;
mail path fails hard if triage fails. Mark T06 done and workplan finished;
update residual docs (OperatingRhythm, cutover runbook, llm-rhythm).
Reject Claude Code (or any coding agent) on railiance01. Mail-scan stays
deterministic; triage/briefs use llm-connect HTTP → structured JSON →
deterministic apply. Document in integrations/railiance-llm-rhythm.md and
rewrite WP-0006 tasks accordingly; timers no longer require_claude.
Queue hygiene checked: DecisionQueue (DEC-2026-003 still prepared, 3 days
old, no escalation needed yet), OfficeHourQueue (all items prepared,
OH-2026-003 refreshed with first-pull numbers), AutopilotWorkQueue (three
open items, none stale) — no status changes required this pass.
Live custody path tenants/binky/qonto-api (API_KEY/API_USER). First read-only
thirdparty pull (122 txs): desk 297.50 €/mo, Qonto plan 70.80 €/mo, main
balance 2185.94 €. Evidence under finance/; workplan status finished.
Prepare first-pull path after DEC-2026-004: copy-paste founder provision,
CCR apply, catalog promote, and CostRunRate update steps. T05 still waits
on Red-lane API key provision.
Convention change, not new code: closing an item now means setting its
terminal status (status: closed/resolved/done + outcome where
applicable) directly on the item's own yaml block in place, instead of
deleting it and hand-writing a bullet in a separate "Completed"/
"Resolved decisions" log. WORK-RECORDS.md (CUST-WP-0061-T04, generated
by fix-consistency's C-33) already lists every closed/resolved/done
record with status/lane/source -- that supersedes the hand-maintained
logs as the going-forward view.
- AutopilotWorkQueue.md: closing note added; "## Completed" relabeled
"(historical -- pre-canon, 2026-07-21)", frozen as-is, nothing
migrated or deleted
- DecisionQueue.md: closing note added -- its "## Resolved decisions"
entries were already structured as in-place yaml blocks with
status: resolved (ahead of AWQ's convention already), so this only
clarifies the log is superseded going forward, no structural change
- OfficeHourQueue.md: closing note added -- items already live under
"## Queued items" with status: queued|prepared|done in place, no
separate log ever existed here
- OperatingRhythm.md: queue-hygiene checklist updated to describe
in-place status transitions instead of "moved to the log"; added
item 5 noting WORK-RECORDS.md needs no hand-maintenance
Re-ran fix-consistency: WORK-RECORDS.md content unchanged (correctly
idempotent -- these were prose-only edits, no yaml block content
changed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
First fix-consistency run with the new C-33 check: a cross-cutting,
file-derived index of every work record in this repo (5 workplans, 31
tasks, 3 intake items, 4 decisions, 5 engagements) -- the orientation
view the work-record architecture was designed to provide, generated
not hand-maintained.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Live verification of the new fix-consistency C-32 check
(state-hub CUST-WP-0061-T02): AWQ-002, AWQ-003, AWQ-006 were open,
never-registered intake items in AutopilotWorkQueue.md. C-32 created
real hub intake records for each and wrote state_hub_intake_id back —
the exact registration gap the work-record canon was built to close,
caught on real, non-synthetic data on its first run.
(A throwaway BINKY-IN-9001 test block used to trigger this run was
never git-tracked and has been removed from disk; its hub record was
closed declined as cleanup.)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Wires the canon work-record validation workflow (repo-seed template).
Local proof: 45 records checked, 0 errors, 0 warnings — AWQ/DEC/OH ids
pass grandfathered, zero renames (the acceptance test for the
grandfathering design).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- DecisionQueue: DEC-2026-004 → resolved (approved, Bernd, 2026-07-19);
hub decision a2a9de69 resolved
- OH-2026-003 enriched with the Red-lane provisioning steps (API key +
bao kv put per integrations/qonto-mcp.md) for the dashboard visit
- qonto-mcp.md checklist: approval done, provisioning next
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- E-mail triage log section added: jamesandersons spam resolved by
founder; IHK Sommerfest invitation (August, founder calendar call);
Qonto MCP mailing -> actionable
- AWQ-010: Qonto MCP integration prep (read scopes first, ops-warden/
OpenBao credential lane, no native integrations; complements DUO =
DATEV Unternehmen Online as main accounting, does not replace it)
- OH-2026-003 enriched: MCP integration is an argument FOR keeping
Qonto; check API/plan prerequisites while in the dashboard
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Queue hygiene: DecisionQueue gained the missing prepared package for the
now-unblocked BINKY-WP-0004-T06 cutover; OfficeHourQueue and
AutopilotWorkQueue healthy (hub fix-consistency skipped — green lane,
no network).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Extend .kaizen/schedule.yml with harness fields for daily rhythm, weekly
mail intake, and weekly review-prep; add task files, onboarding handoff
doc, and cutover gate updates for BINKY-WP-0004-T06.