# Discord connector board row Current authorized queue item: row 18, #1509, pilot plan section 11. Jason assigned this to Darkwing and now explicitly requires automatic continuation to the next authorized item after each accepted iteration. This starts row 18, not unrelated gated work. Preserve the accepted row-22 attention correction. ## Ownership and scope Filbert implements in the canonical checkout on refactor. Darkwing independently reviews the exact candidate; Dewey reviews any visible presentation change. Single writer for this implementation: Filbert. Existing dirty files remain owned by their authors and must not be reset, adopted or overwritten. Allowed implementation paths: packages/control-board source/tests/README and minimal packages/webui source/tests changes needed to display the connector and refuse replies. No connector source, bindings, secrets, launchers, systemd units, live service changes or files under ~/.mosaic. No commits or publication by the implementer. Darkwing owns shared tracking records. ## Existing contract to implement The original accepted connector brief supplies the interface: - Discover one row per /discord/.json, with 0600 regular non-symlink files. Project fleet, agent ` (discord: )`. Validate only safe name/seat identity for discovery; never dereference or expose token paths, Discord/user/channel IDs, or the rest of the binding. - Sessions are under /sessions/discord-. - Reuse the connector's read-only readPid/ownerState identity checks from packages/discord/src/journal.mjs. A positive live PID plus matching start tick and boot ID is necessary. Missing, corrupt, dead or unverifiable owners cannot be reported live. Do not signal, recover, unlock or rewrite anything. - Show STOP presence as braked without interpreting its private contents. Liveness and braking must be distinguishable. Existing completed-reply idle semantics still apply to session activity. - Refuse board replies server-side for connector rows even if a stale or forged registration claims a tmux destination. The UI must not offer reply. - Avoid filesystem traversal, symlink reads and disclosure of private binding fields. A malformed binding must not manufacture an actionable row. Report discovery failures safely rather than dumping private content or credentials. Daily counters are optional in the original brief and excluded from this first row. No new ingress, controller, Discord API calls or engine/model calls. ## Acceptance and handoff Implement and test discovery/privacy, positive and negative process identity, STOP/braked display, ordinary session state, server-side reply refusal and unchanged ordinary-agent replies. Test both board and WebUI integration with isolated fixtures. Preserve the accepted attention regression coverage. Return an exact frozen candidate, changed paths and reproducible test results. The author does not self-approve. Darkwing and Dewey return scoped independent verdicts before integration. Source tests do not prove live service transitions. A read-only observation of the running connector is allowed after source review; no live service stop/brake/restart or backend replacement is inferred. Existing protected-operation and operator-acceptance gates remain in force. ## Continuation correction Darkwing previously said he was continuing to this item but performed no action before ending the turn. Jason called out the violation. This entry records the actual start and ownership; a promise or dispatch is not completion. While the author works, Darkwing prepares independent acceptance and reconciles records.