From a59a976ddaf5ce65feb17f1c52c5f8ae12bfea3e Mon Sep 17 00:00:00 2001 From: Jason Woltje Date: Sun, 4 Oct 2026 21:46:00 -0500 Subject: [PATCH] docs(prd): PRD draft 0.4 with PRDY round 3; lead decision 53 Tokens by hand from a runbook, Gitea bot users per role, slice 1 agents as Jason's OS user, DMs through the existing connector, digest at 08:00 Central, Gate E with the slice 1 WebUI step. Approval as 1.0 is still open. Co-Authored-By: Claude Opus 5.5 --- docs/SESSIONS.md | 1 + docs/plans/2026-09-26_lead-decisions.md | 17 ++++++++++ docs/prd/mosaic-stack.md | 41 ++++++++++++++++--------- 3 files changed, 45 insertions(+), 14 deletions(-) diff --git a/docs/SESSIONS.md b/docs/SESSIONS.md index 03eef13a..ad2d4837 100644 --- a/docs/SESSIONS.md +++ b/docs/SESSIONS.md @@ -479,3 +479,4 @@ are never rewritten or removed; corrections are new entries. 2026-10-04T20:47:45Z | Sage (T3 Claude Code, thread 1ef1e4f8) | row 5 CHAT-03 I1 commit | both round 2 approvals (26690, 26694); manifest 2b48e333 checked; all suites green on an export; candidate, packets and Filbert's review record committed; follow-ups in DEFERRED; row 5 to waiting-on-jason for Gate E 2026-10-04T23:31:47Z | Sage (T3 Claude Code, thread 1ef1e4f8) | Vikunja probes received | Researcher's P1-P7 record (ef0beec6) committed; scratch container confirmed gone; lead decision 51; Darkwing asked for addendum B (scope map, poll gaps) 2026-10-04T23:42:31Z | Sage (T3 Claude Code, thread 1ef1e4f8) | slice 1 addendum B | Darkwing's addendum B (14e747f5) committed as a record; lead decision 52 accepts B1-B3 (sync bot, no agent reopen, schema v3 at brief time) +2026-10-05T02:45:53Z | Sage (T3 Claude Code, thread 1ef1e4f8) | PRDY round 3, PRD 0.4 | lead decision 53 (1A 2A 3A 4A 5A 7B; question 6 unanswered, so the PRD stays a draft); PRD draft 0.4; row 5 note: Gate E rides the slice 1 WebUI step diff --git a/docs/plans/2026-09-26_lead-decisions.md b/docs/plans/2026-09-26_lead-decisions.md index d7405f2e..d862ae37 100644 --- a/docs/plans/2026-09-26_lead-decisions.md +++ b/docs/plans/2026-09-26_lead-decisions.md @@ -869,3 +869,20 @@ which stay with him. Each item names who decided it and what happened. - Section 7's unverified points join the brief's probe matrix as preconditions. The first is which labels `GET /labels` returns to a bot. Until that's settled, the business file lists label ids. +53. **PRDY round 3 answers (2026-10-04).** Jason, thread 1ef1e4f8, "1A + 2A 3A 4A 5A 7B". + - 1A: Jason creates the slice 1 tokens by hand from a runbook Sage + writes. Nothing in v1 mints them. + - 2A: Gitea gets new bot users per role: pm-bot, cto-bot, coder-bot + and reviewer-bot. + - 3A: slice 1 agents run as Jason's OS user. The PRD names the + broker as a rule they follow, not a wall. Containers come next. + - 4A: the existing Discord connector (#1509) sends the DM for a + blocking decision. + - 5A: the daily digest arrives at 08:00 Central. + - 7B: row 5's Gate E demonstration happens during the slice 1 WebUI + step. Row 5 stays waiting-on-jason until then. + - Question 6, approving the PRD as 1.0, got no answer. The PRD stays + a draft (0.4) until Jason approves it. Sage writes the slice 1 + brief against 0.4's requirement ids, and any id that changes + before approval gets fixed in the brief. diff --git a/docs/prd/mosaic-stack.md b/docs/prd/mosaic-stack.md index cfc4c117..2334d2d0 100644 --- a/docs/prd/mosaic-stack.md +++ b/docs/prd/mosaic-stack.md @@ -1,13 +1,13 @@ # PRD: Mosaic Stack -- Status: draft, version 0.3. Jason approves it, and once approved it is +- Status: draft, version 0.4. Jason approves it, and once approved it is never edited in place. Changes after approval are a new version. - Owner: Jason. Sage writes it from the PRDY interview. - Template: PRDY "software" (`v1/packages/prdy/src/templates.ts`), filled by hand until PRDY is ported. - Interview record: Sage's thread 1ef1e4f8. Round 1 is lead decision 45. - Round 2 is lead decision 48. Design inputs are lead decisions 43, 44, - 46, 47 and 49. + Round 2 is lead decision 48. Round 3 is lead decision 53. Design + inputs are lead decisions 43, 44, 46, 47 and 49 to 52. ## Introduction @@ -119,8 +119,13 @@ parent requirement is refused. ### Credentials - **REQ-CRED-1.** Every role instance has its own token for each service - (Gitea, Vikunja). In v1 Jason creates these tokens by hand. The broker - holds them, and they never enter an agent's environment or files. + (Gitea, Vikunja). The broker holds them, and they never enter an agent's + environment or files. In v1 Jason creates them by hand from a runbook + Sage writes (round 3, 1A): + - in Gitea, a new bot user per role: pm-bot, cto-bot, coder-bot and + reviewer-bot (round 3, 2A); + - in Vikunja, a `bot-` user per role, plus one read-only + `bot--sync` that does all polling (lead decision 52). - **REQ-CRED-2.** A session that finds only founder credentials stops. ### Decisions @@ -142,8 +147,9 @@ parent requirement is refused. started outside any agent run. Agents reach the decision store only through a broker. The broker stamps role and run from the launch record. - **REQ-DEC-4.** A gated decision that blocks work reaches Jason right - away: in the CLI inbox, plus a Discord DM. Everything else goes into one - daily digest. (Round 2, answers 2A and 3A.) + away: in the CLI inbox, plus a Discord DM sent through the existing + connector (#1509). Everything else goes into one daily digest at 08:00 + Central. (Round 2, answers 2A and 3A; round 3, 4A and 5A.) ### Messages @@ -159,8 +165,11 @@ parent requirement is refused. and the assigned role writes the task's state. Vikunja's token scopes cover whole route groups, so the broker's verbs enforce this, not the tokens. A person's edits come in as events. -- **REQ-TASK-2.** Polling for changes since the last check is the source - of truth, with an hourly full reconcile. Slice 1 uses no webhooks. +- **REQ-TASK-2.** Polling is the source of truth. Every 30 seconds the + sync bot reads each project's open-task board and the tasks updated + since the last check, so column moves and deletions of open tasks show + up within one poll. An hourly full reconcile catches the rest. Slice 1 + uses no webhooks. (Lead decisions 51 and 52.) - **REQ-TASK-3.** The installer offers two choices: point at an existing Vikunja, or deploy the bundled one. The bundled one is the unmodified upstream image. No Vikunja code enters the repository. @@ -250,14 +259,18 @@ piece: ## Risks and open questions -Round 3 sets these. Known so far: -- Agents running as the same OS user as Jason can write anything that - user can write. Until seats run as another user or in a container, the - broker is a rule they follow, not a wall. +- In slice 1, agents run as Jason's OS user (round 3, 3A). They can + write anything that user can write. Until seats run in a container, + which comes next, the broker is a rule they follow, not a wall. What + does hold in slice 1 is that agents never hold service tokens. +- Vikunja doesn't enforce `If-Match`. The broker compares before it + writes, and a person editing in the same moment can still be + overwritten in an owned field (lead decision 51). - The Vikunja owner password and Gitea token creation are gated. Jason holds them. ## Milestones Slice 1, in the order on the foundation direction page. The slice 1 brief -maps each step to requirement ids. +maps each step to requirement ids. CHAT-03's Gate E demonstration happens +during the slice 1 WebUI step, not separately (round 3, 7B).