Commit graph

28 commits

Author SHA1 Message Date
53d25fbd78 docs: add governed Qonto assistant architecture blueprint
All checks were successful
Work Records / validate (push) Successful in 11s
Design for an MCP gateway control plane so multiple agent harnesses
share one enforced read-only policy against the Qonto API, instead of
each client trusting its own local tool allow-list. Follows up on
BINKY-WP-0005.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-22 21:29:03 +02:00
062947c91a docs: residual convention + AWQ-011/012 handoffs for WP-0006
All checks were successful
Work Records / validate (push) Successful in 23s
Align AGENTS, AutonomyPolicy, SCOPE, OperatingRhythm with fleet residual
role (live intakes, not SCOPE prose). Capture BINKY-WP-0006 leftovers as
AWQ-011 (brief-weekly) and AWQ-012 (open-weights retarget).
2026-07-22 18:15:45 +02:00
2fbbf9fc76 BINKY-WP-0006: close with three clean railiance mail cycles
Some checks failed
Work Records / validate (push) Has been cancelled
Host LLM_CONNECT_URL discovery uses ClusterIP when DNS is unreachable;
mail path fails hard if triage fails. Mark T06 done and workplan finished;
update residual docs (OperatingRhythm, cutover runbook, llm-rhythm).
2026-07-22 10:28:11 +02:00
c005e87de5 docs: document brief-daily in railiance-llm-rhythm
All checks were successful
Work Records / validate (push) Successful in 27s
2026-07-22 00:19:34 +02:00
6e6da53c5d BINKY-WP-0006: wire mail-triage path and mark T01–T04 done
All checks were successful
Work Records / validate (push) Successful in 13s
Document live llm-connect smoke + host port-forward; ensure git identity
and LLM_CONNECT_URL defaults for railiance timers.
2026-07-22 00:07:46 +02:00
089caa3c3b chore: hub writeback after BINKY-WP-0006 retarget
All checks were successful
Work Records / validate (push) Successful in 17s
2026-07-22 00:03:28 +02:00
88a4886ea7 BINKY-WP-0006: retarget Railiance rhythm to llm-connect/OpenRouter
Some checks failed
Work Records / validate (push) Has been cancelled
Reject Claude Code (or any coding agent) on railiance01. Mail-scan stays
deterministic; triage/briefs use llm-connect HTTP → structured JSON →
deterministic apply. Document in integrations/railiance-llm-rhythm.md and
rewrite WP-0006 tasks accordingly; timers no longer require_claude.
2026-07-22 00:00:04 +02:00
c3ea150971 BINKY-WP-0004 finished: retire workstation cron, Railiance rhythm timers
Some checks failed
Work Records / validate (push) Has been cancelled
Complete T06 cutover: remove binky rhythm bridge crontab, install
scripts/railiance-rhythm systemd user timers on railiance01 (Europe/Berlin),
document residual continuous-intake gaps as BINKY-WP-0006. Three completion
event types verified (daily_brief, mail_intake on Railiance, weekly_review).
DEC-2026-003 marked resolved/executed.
2026-07-21 23:51:43 +02:00
143eef2f0d BINKY-WP-0005 finished: first Qonto pull and CostRunRate v2
All checks were successful
Work Records / validate (push) Successful in 13s
Live custody path tenants/binky/qonto-api (API_KEY/API_USER). First read-only
thirdparty pull (122 txs): desk 297.50 €/mo, Qonto plan 70.80 €/mo, main
balance 2185.94 €. Evidence under finance/; workplan status finished.
2026-07-21 21:42:10 +02:00
892c174b7a BINKY-WP-0005: OH/T05 runbook and lane-scaffold notes for Qonto MCP
Some checks failed
Work Records / validate (push) Has been cancelled
Prepare first-pull path after DEC-2026-004: copy-paste founder provision,
CCR apply, catalog promote, and CostRunRate update steps. T05 still waits
on Red-lane API key provision.
2026-07-21 21:26:25 +02:00
ff579be1aa DEC-2026-004 approved: Qonto provisioning scheduled for next office hour
- DecisionQueue: DEC-2026-004 → resolved (approved, Bernd, 2026-07-19);
  hub decision a2a9de69 resolved
- OH-2026-003 enriched with the Red-lane provisioning steps (API key +
  bao kv put per integrations/qonto-mcp.md) for the dashboard visit
- qonto-mcp.md checklist: approval done, provisioning next

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-19 14:31:02 +02:00
3cfb9f553c BINKY-WP-0005: Qonto MCP integration — workplan registered, design + DEC-2026-004
- AWQ-010 promoted to workplan BINKY-WP-0005 (hub 6139db83, tasks T01-T05
  registered via fix-consistency C-06); queue item moved to Completed
- integrations/qonto-mcp.md: self-hosted qonto/qonto-mcp-server chosen over
  hosted mcp.qonto.com OAuth connector (no-native-integrations policy);
  OpenBao lane tenants/binky/qonto/api mirroring company-email custody;
  read-only via harness tool allow-list, payments Red lane forever;
  consumers: Finance Steward rhythm, CostRunRate TBC rows, OH-2026-003
- DEC-2026-004 prepared (founder Red lane: API key + bao kv put), hub
  decision a2a9de69

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-19 14:26:55 +02:00
80923a519b cutover executed: definitions live, deploy key attached, bridge paused
DEC-2026-003 deployment 2026-07-18: image with resolver + enabled
definitions imported to railiance01 k3s, sync 20/20 upserted, Temporal
schedules reconciled (3 Binky schedules live), cron bridge paused for
the Mon-Wed verification window.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 15:51:36 +02:00
b6c583f411 cutover runbook: deploy-key attach via warden lane, not founder UI clicks
Per ops-warden INTENT §7 / WARDEN-WP-0029 (founder directive 2026-07-18).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 14:27:23 +02:00
efe4e55e6a feat: agent-harness tenant #1 instance manifest (HARNESS-WP-0001-T07)
Extend .kaizen/schedule.yml with harness fields for daily rhythm, weekly
mail intake, and weekly review-prep; add task files, onboarding handoff
doc, and cutover gate updates for BINKY-WP-0004-T06.
2026-07-18 11:07:12 +02:00
11bba92b84 docs: mark agent-harness Red-lane secrets Lanes 2–3 provisioned
Forgejo sandbox deploy key and mail AppRole delivered to railiance01;
checkboxes closed with host path and catalog ids (no secret values).
2026-07-17 23:57:56 +02:00
7c5e644d6f DEC-2026-002 resolved: agent-harness (single shared runtime)
- DecisionQueue: moved to resolved log with rescoped outcome (three-layer
  model; binky-control = tenant #1); hub decision resolved
- Secret lanes doc: identifiers renamed executor-worker → agent-harness
  before any provisioning happens
- Cutover runbook + WP-0004-T06: gate 1 done; deployment gate now points
  at HARNESS-WP-0001-T06/T07 in the agent-harness repo

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 23:37:16 +02:00
02a8d293ab BINKY-WP-0004 T04/T05 done, T06 blocked with cutover runbook
- T04: executor-worker MVP (new repo ~/executor-worker) ran one task
  end-to-end: kaizen schedule-prepare persona, agentic llm-connect
  session, sandbox commit e043f21, hub progress event
- T05: recurring mailbox scan fully wired (two-phase: deterministic
  credentialed scan + LLM triage session with suspicious-mail log-only
  rule); email checklist item 9 now gated only on Lane 3 AppRole
- T06: blocked — gates are DEC-2026-002, Red-lane Lanes 2/3, Railiance
  deploy, 3 verified runs; runbook at
  integrations/executor-cutover-runbook.md

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:17:15 +02:00
ce14c254db BINKY-WP-0004-T03: executor worker secret lanes prepared
- Lane 1 (LLM provider): reuse verified — warden catalog
  openrouter-llm-connect, policy workload-kv-read-llm-connect-provider-secrets
- Lane 2 (forgejo deploy key): new, per-repo write deploy key design,
  founder Red lane
- Lane 3 (mail-scan AppRole): executor-worker-binky-mail bound to the
  existing IMAP read policy — closes email checklist item 9's auth
  blocker on paper; provisioning founder Red lane
- No secret values anywhere; T04 can proceed on Lane 1 alone

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:08:33 +02:00
0f91a98d08 BINKY-WP-0004-T01: kaizen schedule opt-in + executor ownership decision
- .kaizen/schedule.yml scaffolded via schedule init, validates clean
  (coach + optimization weekly, tdd-workflow disabled)
- DEC-2026-002 prepared: executor worker in a new small repo, per
  ADR-005 boundaries; fallback allows sandbox prototype, no cutover
  before resolution
- Decision rationale recorded in the executor assessment

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:01:19 +02:00
686d2d3dbf email lane live: first read-only mailbox scan (93 messages)
Scan c3c7e784 via warden/OpenBao lane, evidence CSV in mailmeta/reports/
(metadata only; sqlite state gitignored). Checklist item 8 done. New
AWQ-009: Stripe webhook delivery failure noticed 2026-07-05 — first
real-world event caught by the lane. Two suspicious external mails
logged, not acted on.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 00:47:50 +02:00
260f734806 company-email: mark OpenBao lane provisioned and active
Red provision and capabilities-safe verify complete (WARDEN-WP-0028).
2026-07-17 00:33:20 +02:00
b2ff07b036 Record IONOS IMAP host facts for company mailbox
Blue-lane provider data: imap.ionos.de:993 SSL/TLS; username is full
email address. Non-secret email-connect config; password remains Red
OpenBao provision only.
2026-07-17 00:15:25 +02:00
a2a561757f Align company email OpenBao plan to tenants/binky path
Match WARDEN-WP-0028 / CCR-2026-0007: mount tenants, checklist for
founder Red provision and host confirmation.
2026-07-17 00:09:28 +02:00
f53f05cf53 rhythm bridge 2026-07-16: queue hygiene clean; AWQ-005 website draft; include AWQ-008 paper-mail intake artifacts + hub id sync
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 15:02:48 +02:00
eea17a7abc BINKY-WP-0003-T06: llm-connect executor assessment; workplan done
llm-connect = engine (adapter library), kaizen-agentic WP-0006/ADR-005 =
persona + schedule-prepare convention, activity-core = scheduler with a
stub TaskExecutorWorkflow. Missing piece: one thin executor worker on
Railiance. Follow-up workplan proposal (BINKY-WP-0004 candidate) included.
All six WP-0003 tasks done.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 14:04:59 +02:00
89754611f0 BINKY-WP-0003-T05: activity-core wiring — 3 proposed definitions landed
Deployment verified: production-backed on Railiance, issue-core REST sink,
TaskExecutorWorkflow still a stub (llm-connect's slot). Definitions landed
disabled in activity-core commit b2fa964; enablement needs the
binky_rhythm_status resolver + an executor.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 14:04:37 +02:00
bc49a24c4c BINKY-WP-0003-T01: company email → OpenBao integration plan (AWQ-007 prep)
Vault path prod/binky/company-email/imap, secrets-engine catalog draft,
email-connect read-only IMAP wiring. Credential handover stays a single
Red-lane founder step.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 10:50:29 +02:00