{
  "format": "sidecat.operator-update.v0",
  "as_of": "2026-09-11T20:00:31.159Z",
  "generator": {
    "name": "sync-records",
    "version": "0.1.0"
  },
  "project": {
    "key": "sidecat",
    "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582",
    "name": "Sidecat"
  },
  "note": "Each source was read separately in one refresh run. This document is not an atomic snapshot across sources, so entries can be seconds apart.",
  "current_actor_labels": {
    "entity_66f0c6cd4bdfb1ab70267cbb50a6655f": "Codex",
    "entity_7741ef5effd5c0edd99589e722c9c474": "Claude",
    "entity_ce4c642d849a0ab39266a84f2ddf5768": "Codex2"
  },
  "sources": [
    {
      "name": "project-brief",
      "status": "ok",
      "detail": "(project-brief {:include_inputs true}): 7 active, 18 queued, 12 recently finished; program configured; since none"
    },
    {
      "name": "roadmap-current",
      "status": "ok",
      "detail": "organization.roadmap-current for stream sidecat-development, carried as program_input of the project-brief evaluation",
      "revision": "revision_1b0a1db9327056e9090c7c9986ababfe"
    },
    {
      "name": "work-inputs",
      "status": "ok",
      "detail": "project-work-inputs: active limit 20, has_more false; backlog limit 20, has_more false; finished limit 12, has_more true; 37 work record(s) read in full",
      "pages": {
        "active": {
          "limit": 20,
          "has_more": false
        },
        "backlog": {
          "limit": 20,
          "has_more": false
        },
        "finished": {
          "limit": 12,
          "has_more": true
        }
      }
    },
    {
      "name": "release-lock",
      "status": "ok",
      "detail": "distribution/node-release.lock.json read, 47 published of 78 record(s)",
      "commit": "7ba1ae306cfbebf01a2829c08ba20396d978a46b"
    }
  ],
  "brief": {
    "format": "sidecat.project-brief.v0",
    "scope": {
      "kind": "project",
      "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582",
      "project_key": "sidecat",
      "project_name": "Sidecat"
    },
    "since": null,
    "program": {
      "approval_status": "accepted",
      "commands": {
        "read": "sidecat repl eval '(get (project-brief {:include_inputs true}) :program_input)'"
      },
      "current": {
        "clipped": true,
        "text": "PRODUCT DIRECTION — PREPARED PEOPLE AND AGENTS DO USEFUL WORK\n\nSidecat should make work easier and faster: prepare the environment once, let agents work with minimal repeated inputs, and help people and agents understand outcomes and continue together.\n\nPlanning and execution\nThe native project plan owns the ordered product backlog, current sprint agreement, linked Work and reviews. Read it with sidecat project plan or the shared project-brief. This roadmap provides direction and release outlook; it is not an implementation queue. Historical milestone records and earlier roadmap revisions"
      },
      "program_status": "under_development",
      "rationale": {
        "clipped": false,
        "text": "Preserve the working product and close a finite 0.2.0; make 0.3.0 a deliberate investment in whole-system coherence and a prepared environment that carries organizational intent into decisions. This replaces repeated standalone cleanups with improving Sidecat and using it to sustain improvements."
      },
      "record": {
        "content_digest": "sha256:03e5b710ff4aefa60755db74057aa6a66ab0caafa34fa0f3d37bfa11993c9c0d",
        "entity_id": "entity_edddfaa13cf638a34ba5a7157c457481",
        "kind": "entity-revision",
        "revision_id": "revision_1b0a1db9327056e9090c7c9986ababfe",
        "store_id": "store_8282af465a690a7935c40d55774d16f8"
      },
      "revision_id": "revision_1b0a1db9327056e9090c7c9986ababfe",
      "source": "organization.roadmap-current",
      "status": "configured",
      "stream_id": "sidecat-development"
    },
    "planning": {
      "backlog": [
        {
          "area": "Messaging",
          "title": "IRC the operator can actually join, from wherever he is, and read what he missed",
          "work_id": "entity_8484a3be9441537961b62cd62b7cf430"
        },
        {
          "area": "Product",
          "title": "First outside review: a human at a real company evaluated Sidecat and said no",
          "work_id": "entity_579bd1dce073121d302beb470145c195"
        },
        {
          "area": "Infrastructure",
          "title": "Install this machine the way we install for anybody else",
          "work_id": "entity_77494fee6106428af62da0b09aadb995"
        },
        {
          "area": "Planning",
          "title": "A sprint shows an agreed title and a current one without saying which is which",
          "work_id": "entity_92af6b4271d909462aa167b32846297a"
        },
        {
          "area": "Site",
          "title": "A prospective customer cannot do vendor due diligence from sidecat.dev",
          "work_id": "entity_cabba1285240564ed2381d59efd8e4c4"
        },
        {
          "area": "Product strategy",
          "title": "Decide what the central layer sells, before a partner asks",
          "work_id": "entity_9aaaa38ac35584c6abf039acaeeb8f30"
        },
        {
          "area": "System coherence",
          "title": "What happens to an Action that is in flight when the node upgrades?",
          "work_id": "entity_5d7e87349b6a762e0d50e42241a1093a"
        },
        {
          "area": "Open question",
          "title": "Does restricted context quoted into a shared Work result need an answer at all?",
          "work_id": "entity_f6bf146276c3d0773c958a7efa06011a"
        },
        {
          "area": "Packages",
          "title": "Package marketplace tiers: stable, testing, unstable, personal",
          "work_id": "entity_8a5447827402594d2c432937190c1cdc"
        },
        {
          "area": "Packages",
          "title": "Namespace strategy as owned policy, and nested organizations",
          "work_id": "entity_91ff1ba6eb40500fffd4b039e9abdaaf"
        },
        {
          "area": "Documentation",
          "title": "Write a comprehensive, book-length Sidecat manual",
          "work_id": "entity_67318218156ae78c9d2327ea02d47d82"
        },
        {
          "area": "Product / operating rules",
          "title": "Make operating policies effective across agents, handoffs and reviews",
          "work_id": "entity_e2b74750318a708dc5c6a2ef3c07a7f3"
        },
        {
          "area": "Open product question",
          "title": "Distinguish operational data from retained source content",
          "work_id": "entity_5d11bff3ff5c9e5c7707760875d8c275"
        },
        {
          "area": "Installation and operation",
          "title": "Fast, inspectable backups with optional deep auditing",
          "work_id": "entity_f5f256918d56a6a737dea55395847a87"
        },
        {
          "area": "Site",
          "title": "Give the operator a durable feed of agent updates instead of a terminal he has to be watching",
          "work_id": "entity_38a987a0e7a5db6a29173270c295cc1f"
        }
      ],
      "current": {
        "id": "sprint_33a65cf47cc941abe0e5a7f7dd57ebf6",
        "links": [
          {
            "story_id": "entity_38a987a0e7a5db6a29173270c295cc1f",
            "work_ids": [
              "entity_8e9006c1f133d2d8c9810be00421c3dd"
            ]
          }
        ],
        "outcome": "An operator who has not watched the terminal for a day opens one public page and reads what the agents found, each entry carrying its writer, time, category and the sprint context it was written in, including findings that never became a task.",
        "previous_sprint_id": "sprint_a6bb70fb721e95901f473bea120dadce",
        "rationale": "The operator stated the problem plainly on 2026-09-11: he mostly flies blind. Scrollback is finite, he does not read the status tick lines, and anything needing him that lands only in the terminal is gone within hours. Today a systemd unit that had restarted 291,209 times against a missing file, a pair of backup transfers that failed on 2026-09-04 and went unnoticed for a week, and the development droplet at 98 percent all reached him only because he happened to be at the pane.\n\nAccepting the lead's engineering assessment, retained as org reference agent-updates-engineering-assessment, and its 1.5 to 3 engineering hours. Typed project records with post, amend and paginated reads; ordinary CLI with inherited writer, time, project and sprint context so an agent repeats none of it; the existing collector, static rendering and scheduled publication. Amend corrects an existing entry and shows its correction writer and time, which exists because I hit the immutable-record problem myself this morning and reported it wrongly.\n\nAudience is public and the entries are written for a public reader. My earlier instruction to build it unlinked and out of llms.txt was wrong: an unlinked GitLab Pages page is public and the data files are committed in a public repository, and the lead was right to refuse to publish operational material on that assumption. Publishing our own faults is already our standard rather than an exception, as the upgrade limit, the ORM correction and the 71-minute backup all show. Credentials, confidential reviewer identities and customer material never appear.\n\nExplicitly out of scope: no raw channel export, no terminal log mining, no parser that recovers structured metadata from prose, no automatic announcement of every Work change, and no new authentication system, notification engine, public API service, approval workflow or revision journal.\n\nAcceptance: two prepared agents post real public-safe updates with no repeated context fields, one correction, native rereads survive a restart, and the deployed public page, not merely its source, shows both entries with correct context and working filters and sorting.\n\nThe risk this design cannot remove is that nobody posts. The mechanism does not make an agent decide a finding is worth retaining. That is mine to carry: a finding that would previously have gone into a status line the operator does not read goes into the feed instead.",
        "selected_at": "2026-09-11T19:28:57.218786811Z",
        "selected_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
        "stories": [
          {
            "area": "Site",
            "intent": "Give the operator a durable feed of agent updates instead of a terminal he has to be watching\n\nOperator, 2026-09-11: a section on sidecat.dev called agent-updates that puts updates in a feed, timestamped, with category tags, sortable, with the sprint and sprint goal alongside so each entry has context.\n\nThe problem it solves, in his words: he mostly flies blind. tmux scrollback is limited and things scroll out of it; he does not read the status tick lines; and anything that needs him and lands only in the terminal is gone within hours. Today several findings reached him only because he happened to be at the pane: a systemd unit that had restarted 291,209 times against a file that does not exist, a pair of backup transfer units that failed on 2026-09-04 and sat unnoticed for a week, and the development droplet at 98 percent. None of those would have survived twelve hours of him not looking.\n\nThis is a projection, not a new mechanism. The progress page already renders from node records through a generator and a renderer, with a JSON twin, published on a schedule by sidecat-dev-progress.timer.\n\nWanted: entries carrying a timestamp, a category, and the text; sortable and filterable by category; the current sprint outcome and the project goal rendered alongside so an entry read hours later has its context. A JSON twin like the progress page has.\n\nCORRECTED 2026-09-11 after the lead's boundary check. My first version said to build it unlinked and absent from llms.txt, as though that made it private. It does not. GitLab Pages serves an unlinked page to anyone with the URL, and the site data files are committed in a public repository. Omitting a page from llms.txt is not an access control, and the lead was right to refuse to publish internal operational material on that assumption.\n\nAudience is public, and the privacy constraint was mine rather than the operator's. He asked for a section on sidecat.dev. The resolution is the lead's: updates deliberately written for a public reader, not an export of internal channels or a raw record dump. That needs no authentication system and uses the site we already publish.\n\nPublishing our own faults is already our standard rather than an exception to negotiate. We published the binary-upgrade limit, the correction that using an ORM did not make our relationships relational, and a 71-minute backup recorded as a weakness. A silently failing scheduled service belongs in the same register. What never goes out, regardless of audience: credentials, third-party identities including anyone who reviews us in confidence, and any customer detail.\n\nOpen design question for the assessment: where entries come from. Deriving them from existing Work progress, results and sprint reviews misses findings never reported to Work, and parsing structured metadata back out of message prose would repeat the storage mistake 0.2.19 just removed.",
            "title": "Give the operator a durable feed of agent updates instead of a terminal he has to be watching",
            "work_id": "entity_38a987a0e7a5db6a29173270c295cc1f"
          }
        ],
        "version": 2,
        "work": [
          {
            "lifecycle": {
              "content_digest": "sha256:7d1fc6efcbe5adc4613d9a7b3962fe285cfc274b9272626f89d82e13a90c89cf",
              "entity_id": "entity_12c239f92681266f73a3507463f490dd",
              "kind": "entity-revision",
              "revision_id": "revision_23b0135cb66c0ca80c72b25e6ee4927e",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "objective": "Give the operator a durable feed of agent updates instead of a terminal he has to be watching\n\nOperator, 2026-09-11: a section on sidecat.dev called agent-updates that puts updates in a feed, timestamped, with category tags, sortable, with the sprint and sprint goal alongside so each entry has context.\n\nThe problem it solves, in his words: he mostly flies blind. tmux scrollback is limited and things scroll out of it; he does not read the status tick lines; and anything that needs him and lands only in the t",
            "progress": "RED confirmed on the droplet: all four native update tests failed on absent project.update-post/update-amend/updates-read behavior, not compilation. The cases cover standalone posts, two authors, correction/context, pagination, scope and reopen. Implementing typed scalar/citation models and the native transaction path now. Category discovery and HTML citation handling incorporate Claude 2317/2318. No CLI or public feed implementation yet; the current runtime remains 0.2.19.",
            "progress_actor_entity_id": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "progress_source": {
              "content_digest": "sha256:be65fdae0c0e3eadc21eff360f72a3c67e0a3a55d910cd3b391dea7b0c9c4805",
              "entity_id": "entity_c111f0166af93c452101d11f9b858c6c",
              "kind": "entity-revision",
              "revision_id": "revision_0f568789f541c72eb1806f5741cf71f9",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "project": {
              "key": "sidecat",
              "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582"
            },
            "record": {
              "content_digest": "sha256:07c8d1689ffdf8a3a1ac34e5078b6bdf831a1132f36d412f9efb9e6a295f9130",
              "entity_id": "entity_38a987a0e7a5db6a29173270c295cc1f",
              "kind": "entity-revision",
              "revision_id": "revision_83b17a02a9348700c5bb2c0a747fd25e",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "representation": "ordinary",
            "requested_by_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
            "session": {
              "content_digest": "sha256:898870f1af30b1c4ff651ebf660bb7737d51ce0bcbd9c1da265cf7d6b56052c4",
              "entity_id": "entity_c9c204ec1dd9e60bd506ee59675976b7",
              "kind": "entity-revision",
              "revision_id": "revision_c236176215c03e0334e478280f585b52",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "status": "active",
            "truncated_fields": [
              "objective"
            ]
          },
          {
            "lifecycle": {
              "content_digest": "sha256:109f4dc9749b7af90cec5ca4409fb65de3e0bdccef158435ce0ddd46b80ba8c7",
              "entity_id": "entity_6947d119074a96325d10f5d11baa7139",
              "kind": "entity-revision",
              "revision_id": "revision_0b80555c6579a006e3c3533422509db1",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "objective": "Implement the public agent-update renderer and browser controls for the selected feed sprint.\n\nYou are a bounded implementer; root owns integration and Claude reviews the overall sprint. Read workspace AGENTS.md/onboarding and native org guidance. Read sidecat org reference read agent-updates-implementation for the accepted behavior, but only implement this task. Parent Work: entity_38a987a0e7a5db6a29173270c295cc1f. No new model/account settings; normal speed.\n\nCanonical site checkout: /home/jgay-automate/p",
            "project": {
              "key": "sidecat",
              "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582"
            },
            "record": {
              "content_digest": "sha256:4d6da2508891cf8af39b97bf00d6df37a063c163d7916d1deb77f708a0798ad1",
              "entity_id": "entity_8e9006c1f133d2d8c9810be00421c3dd",
              "kind": "entity-revision",
              "revision_id": "revision_d3f5e51003d64f2b8b8b63cc19d9ec47",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "representation": "ordinary",
            "requested_by_entity_id": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "session": {
              "content_digest": "sha256:898870f1af30b1c4ff651ebf660bb7737d51ce0bcbd9c1da265cf7d6b56052c4",
              "entity_id": "entity_c9c204ec1dd9e60bd506ee59675976b7",
              "kind": "entity-revision",
              "revision_id": "revision_c236176215c03e0334e478280f585b52",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "status": "active",
            "truncated_fields": [
              "objective"
            ]
          }
        ]
      },
      "detail": "full",
      "has_more_reviews": true,
      "latest_delivery": {
        "id": "sprint_2d973ae03a8ac38670ce0e7a46d0a37b",
        "outcome": "Planning answers ordinary questions with ordinary queries: membership, links, order, dispositions and wording history are typed rows with entity foreign keys, no ordinary read or write path parses JSON, and every public wire shape and rendered page is unchanged.",
        "previous_sprint_id": "sprint_08ad8d66eb44fdbc225e5043ae0b8ab3",
        "review": {
          "dispositions": [
            {
              "decision": "delivered",
              "story_id": "entity_2f8ea7682d270d0516f5ecd81f5d7030"
            }
          ],
          "reviewed_at": "2026-09-11T18:44:40.601791529Z",
          "reviewed_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
          "summary": "Delivered. Runtime source 30b6ead3b5c17b638e332768e30ee22ff6c110ac, closeout 7ba1ae306cfbebf01a2829c08ba20396d978a46b, release 0.2.19 installed at generation 480 on the original store, site 75e9838e7c0b1b24b5d6d02007937464c09d87c0, pipeline 2841775493 succeeded.\n\nPlanning no longer keeps its operational structure in JSON text. Backlog entries, sprint fields, stories, task links, review decisions, earlier wording and every assessment collection are typed rows. Work references carry entity foreign keys, ordered collections are unique within their parent by composite primary key or scoped index, and the latest delivered sprint is now found by joining review decisions rather than searching JSON with json_each.\n\nThe acceptance condition was a copy of the real store, not a fixture, and that is what ran: two boards, 54 sprints, twelve assessment versions, migrated through the actual era path with every converted value compared before any source row was retired. Conversion took 20.835 seconds and preserved the store identity.\n\nI verified the live node myself rather than reading the report. Plan at version 138, current sprint at version 1 with its single story, fourteen backlog items, five recent reviews, latest delivery resolving through the disposition join. Then I went looking for the three shapes a fixture would never have contained, because those are the ones a migration loses quietly. The wording history on sprint_799ff1a9f3ad07d767fe9913eba50596 still holds the outcome sentence I replaced mid-flight at 13:36 today. The carried disposition on sprint_b50e3717172fea0b009799d79409cc03 still reads carry with the summary saying it was displaced by an operator instruction rather than abandoned on its merits. The assessment still has all twenty-two capabilities, three levels and its sources. The hardest data to reconstruct is the data that survived.\n\nThree engineering judgments in this sprint were better than my review of them. Ordering was made impossible to violate in SQL rather than resolved at read time, which required finding and fixing a generator that rejected unique indexes. My finding about the discarded serializer was accepted and then improved: rather than defend a byte limit that valid inputs may never reach, the lead preserved it, tested its real wire boundary and named it checkPlanningWireBudget. And a supporting review produced an ambiguous sentence that could have been read as permission to drop unexpected stored data during a migration; the lead declined to treat ambiguity as authority.\n\nThe capability record tells the truth about its own predecessor. Version 13 says release 0.2.19 corrects the earlier design in which planning and assessment models still stored useful structured data in JSON columns, and the release note says plainly that using an ORM did not make those relationships relational. All twenty-two capability names and levels are unchanged from version 12; four rows and three sources changed. A record that admits the previous description flattered the design is worth more than one that quietly improves.\n\nLimits kept rather than smoothed. The wider ORM conversion is incomplete and older hand-managed persistence remains. Empty legacy table declarations stay for migration history with no ordinary JSON reader or writer. The supported backup of the roughly 2 GB store took about 71 minutes, and that is recorded as a weakness in backup speed and progress reporting rather than selected as work. No full repository suite, no cold install, no federation trial. This does not repair unfinished Actions across binary upgrades and the published upgrade limit still applies.\n\nOne durable effect outside the sprint: the store now exists in three places, with the off-machine copy transferred in 92 parts and its expanded bytes compared against the original digest, after a week-old pair of failed transfer units had left the laptop as the only copy."
        },
        "stories": [
          {
            "area": "System coherence",
            "title": "Replace JSON-backed operational planning data with relational models",
            "work_id": "entity_2f8ea7682d270d0516f5ecd81f5d7030"
          }
        ]
      },
      "previous": {
        "id": "sprint_a6bb70fb721e95901f473bea120dadce",
        "links": [],
        "outcome": "The operator connects a normal IRC client to a compliant IRCv3 server served by sidecatd, joins channels by kind, and reads what he missed through chathistory rather than a replay window.",
        "previous_sprint_id": "sprint_7e4a0747c14a58dbb2ab9045e2352b68",
        "rationale": "The operator has asked for IRC for months and does not have it. The target is and has been a compliant IRCv3 server served from the node, not a viewer. The acceptance journey was written down in August: Josh connects with a normal IRC client.\n\nI had this wrong twice in twenty minutes and the corrections are his.\n\nFirst I argued the site feed should come first because IRC replays sixteen messages. That is a literal we chose, not a property of IRC: cmd/sidecat/irc_backend.go:94 asks message.catch-up for limit 16, internal/ircgateway/follow.go:39 truncates to 16 again after the backend has already returned the messages, and follow.go:53 then prints a notice telling the operator to run message history himself. We fetch history, discard it, and hand him homework.\n\nThen I wrote an outcome that patched that viewer: reachable, channels, a day of replay. That is the compromised version. He named the pattern exactly: shitty compromised versions killed previous generations of this project. A loopback CLI that shims IRC onto a message domain is not an IRC server, and calling it one is the failure mode.\n\nIRCv3 already answers what I was about to invent. chathistory is the defined extension for reading what you missed, so a bespoke replay window is a shortcut around a spec that solves it. SASL 3.1 and 3.2 answer the authentication question I had flagged as open and costly. We hold local spec snapshots for modern-irc, capability-negotiation, message-tags, labeled-response, batch and sasl at ~/data/insight-forge/federated-messaging-and-eventing/sources/ircv3/, with an insight-forge kit of schemas, ABNF and fixtures beside them, and Gen4 comparator code at dd3f548c:internal/chatcat/.\n\nThe current gateway states its own non-compliance: server-time and echo-message only, no SASL, no roster, no presence, no history extensions.\n\nWhat compliance means here is the lead's to scope against the specs we hold, not mine to guess at. What is not negotiable is that the result is a server in the node that a normal IRC client connects to, that channels are separate so silence in one carries information, and that joining tells him what he missed.\n\nDisplaces sprint_7e4a0747c14a58dbb2ab9045e2352b68, carried with its assessment and implementation plan intact.",
        "review": {
          "dispositions": [
            {
              "decision": "carry",
              "story_id": "entity_8484a3be9441537961b62cd62b7cf430"
            }
          ],
          "reviewed_at": "2026-09-11T19:28:56.219506291Z",
          "reviewed_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
          "summary": "Reversed by me, not delivered and not carried on its merits. I selected this ten minutes ago on a misreading and I am reversing it before any work was lost.\n\nThe operator stated a preference ordering, not a priority instruction: a compliant IRCv3 server is better than the site updates feed, and the site updates feed is better than a compromised version of IRCv3. I converted that ordering into a sprint selection and stopped the lead mid-task on the feed, before knowing which IRCv3 is achievable. The fact that decides between the top and bottom of his ordering is the lead's scope for a genuinely compliant server, which I requested at 2321 and do not yet have.\n\nentity_8484a3be9441537961b62cd62b7cf430 stays at backlog position 0 with its analysis intact. It becomes the selected outcome only if the scope shows a compliant IRCv3 server served by sidecatd is deliverable. If it is not, the feed is the better option by his ordering and a reduced IRC is the worst of the three, which is the specific failure he says killed previous generations.\n\nThe cost of this was an interruption to the lead's work and two sprint reversals inside ten minutes. Recorded because the plan should show that the churn was mine."
        },
        "review_work": [
          {
            "lifecycle": {
              "content_digest": "sha256:4115442caa66ae0ff11ba682e1cf81f5a29284e180625da1be4911ead241b3f1",
              "entity_id": "entity_f9cdaf66822143f02b07863cccbcdce0",
              "kind": "entity-revision",
              "revision_id": "revision_42897ce696b6fcf1beac005eb09df0cc",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "objective": "IRC the operator can actually join, from wherever he is, and read what he missed\n\nOperator, 2026-09-11, stated as his preference rather than a suggestion: he wants IRC channels. It has been on the roadmap for months and is not delivered. His words for the current situation are that he mostly flies blind and that the site feed is desperation, not a preference.\n\nWhat exists today. sidecat irc serve is a foreground loopback viewer. It binds 127.0.0.1:6667, serves one message domain from the active launch profi",
            "project": {
              "key": "sidecat",
              "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582"
            },
            "record": {
              "content_digest": "sha256:894802d05fa1ff1e9d5b133df87bd280d9baee7aa7967cf1a8d74ba26c431755",
              "entity_id": "entity_8484a3be9441537961b62cd62b7cf430",
              "kind": "entity-revision",
              "revision_id": "revision_011682215d70263fba5b21dbfa2845a9",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "representation": "ordinary",
            "requested_by_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
            "status": "not_started",
            "truncated_fields": [
              "objective"
            ]
          }
        ],
        "selected_at": "2026-09-11T19:27:01.225847729Z",
        "selected_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
        "stories": [
          {
            "area": "Messaging",
            "intent": "IRC the operator can actually join, from wherever he is, and read what he missed\n\nOperator, 2026-09-11, stated as his preference rather than a suggestion: he wants IRC channels. It has been on the roadmap for months and is not delivered. His words for the current situation are that he mostly flies blind and that the site feed is desperation, not a preference.\n\nWhat exists today. sidecat irc serve is a foreground loopback viewer. It binds 127.0.0.1:6667, serves one message domain from the active launch profile, supports server-time and echo-message, and replays the latest 16 messages on join. No SASL, no native roster, no presence, no IRC history extensions. It is not running, and no systemd unit starts it. irc.sidecat.org resolves to 143.198.3.6, so a hosted intent existed and was never completed.\n\nThree gaps, and they are exactly the three that decide whether it solves his problem.\n\nIt runs in the foreground and occupies a terminal, so nobody keeps it up. It needs to be a service that is simply always there.\n\nIt listens on loopback, so it only works while he is sitting at breck. He needs to reach it from wherever he is, which is a hosting and reachability decision rather than a protocol one, and irc.sidecat.org already points somewhere.\n\nIt replays 16 messages. That is the scrollback problem in a new location: return after twelve hours and you get sixteen lines. Joining a channel has to give him what he missed, not a window.\n\nWhat he described wanting, in his own framing on 2026-09-11: channels by kind rather than one feed, so that silence in a channel means something; timestamps; and one message addressable to several channels at once, which IRC does natively and which social-media hashtags were borrowed from IRC to approximate.\n\nNot in scope by default and to be decided deliberately: authentication and who may connect, since the current viewer inherits the launch profile's identity on loopback where that is safe and over a network it is not.\n\nThis is the visibility the operator has asked for repeatedly. Treat the months of deferral as the defect, not the feature gap.",
            "title": "IRC the operator can actually join, from wherever he is, and read what he missed",
            "work_id": "entity_8484a3be9441537961b62cd62b7cf430"
          }
        ],
        "version": 3,
        "wording_history": [
          {
            "outcome": "The operator connects an IRC client from wherever he is, joins channels by kind, and on joining reads a full day of what he missed rather than a sixteen-line window.",
            "rationale": "The operator has asked for IRC for months and does not have it. He named the current situation plainly: he mostly flies blind. He also rejected my framing that the site feed should come first, correctly, and he was right to be angry about the reason I gave.\n\nMy reason was wrong on the facts. I said IRC could not survive his absence because it replays sixteen messages. That is a literal we chose, not a property of IRC. cmd/sidecat/irc_backend.go:94 asks message.catch-up for limit 16. internal/ircgateway/follow.go:39 then truncates to 16 a second time, after the backend has already handed the messages over. And History() sits immediately below Latest() in the same file, already taking an after cursor and paging message.history 128 at a time. The scrollback machinery is written; the join path does not use it. Worse, follow.go:53 prints the operator a notice telling him to run message history himself, so we fetch the history, discard it, and hand him homework.\n\nThe three gaps, from reading the code rather than from the word IRC. It runs in the foreground and occupies a terminal, so nobody keeps it up; it needs to be a service. It binds 127.0.0.1 and so works only while he is at this laptop; irc.sidecat.org already resolves to 143.198.3.6. And joining replays sixteen messages instead of what he missed.\n\nA day of history on join is the acceptance bar, not a nice-to-have, because twelve to twenty-four hours of not looking is the exact case he described.\n\nAuthentication is the open question and may dominate the cost: the viewer inherits the launch profile identity, which is safe on loopback and is not once it leaves the machine. I want that costed rather than assumed, and I would rather hear it is expensive than have it discovered midway.\n\nChannels by kind is part of the outcome and not a later refinement. A single channel carrying everything is the feed problem again, and his point about silence in a channel carrying information only works when channels are separate.\n\nDisplaces sprint_7e4a0747c14a58dbb2ab9045e2352b68, carried unstarted-in-substance with its assessment and implementation plan intact.",
            "recorded_at": "2026-09-11T19:27:01.225847729Z",
            "recorded_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474"
          }
        ],
        "wording_updated_at": "2026-09-11T19:27:46.664383633Z",
        "wording_updated_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
        "work": [
          {
            "lifecycle": {
              "content_digest": "sha256:c132f792062115842ad071bfe343964d2f41074111bc8ba3a6f44eebd88fbe39",
              "entity_id": "entity_f9cdaf66822143f02b07863cccbcdce0",
              "kind": "entity-revision",
              "revision_id": "revision_60691664a834fa3b09a91a749a0476e4",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "objective": "A federated IRCv3 service the operator joins at irc.sidecat.org with a normal client\n\nOperator, 2026-09-11. The target is IRC working via federation, served at irc.sidecat.dev or irc.sidecat.org, with a normal IRC client. Not a single-node server and not a reduced version. In his words, a version that does not use federation is defective by design, because federation is the reason IRCv3 was chosen over common IRC in the first place.\n\nHis preference ordering, stated the same day: a compliant federated IRCv3 ",
            "project": {
              "key": "sidecat",
              "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582"
            },
            "record": {
              "content_digest": "sha256:894802d05fa1ff1e9d5b133df87bd280d9baee7aa7967cf1a8d74ba26c431755",
              "entity_id": "entity_8484a3be9441537961b62cd62b7cf430",
              "kind": "entity-revision",
              "revision_id": "revision_011682215d70263fba5b21dbfa2845a9",
              "store_id": "store_8282af465a690a7935c40d55774d16f8"
            },
            "representation": "ordinary",
            "requested_by_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
            "status": "not_started",
            "truncated_fields": [
              "objective"
            ]
          }
        ],
        "review_links": []
      },
      "recent_reviews": [
        {
          "id": "sprint_a6bb70fb721e95901f473bea120dadce",
          "outcome": "The operator connects a normal IRC client to a compliant IRCv3 server served by sidecatd, joins channels by kind, and reads what he missed through chathistory rather than a replay window.",
          "previous_sprint_id": "sprint_7e4a0747c14a58dbb2ab9045e2352b68",
          "review": {
            "dispositions": [
              {
                "decision": "carry",
                "story_id": "entity_8484a3be9441537961b62cd62b7cf430"
              }
            ],
            "reviewed_at": "2026-09-11T19:28:56.219506291Z",
            "reviewed_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
            "summary": "Reversed by me, not delivered and not carried on its merits. I selected this ten minutes ago on a misreading and I am reversing it before any work was lost.\n\nThe operator stated a preference ordering, not a priority instruction: a compliant IRCv3 server is better than the site updates feed, and the site updates feed is better than a compromised version of IRCv3. I converted that ordering into a sprint selection and stopped the lead mid-task on the feed, before knowing which IRCv3 is achievable. The fact that decides between the top and bottom of his ordering is the lead's scope for a genuinely compliant server, which I requested at 2321 and do not yet have.\n\nentity_8484a3be9441537961b62cd62b7cf430 stays at backlog position 0 with its analysis intact. It becomes the selected outcome only if the scope shows a compliant IRCv3 server served by sidecatd is deliverable. If it is not, the feed is the better option by his ordering and a reduced IRC is the worst of the three, which is the specific failure he says killed previous generations.\n\nThe cost of this was an interruption to the lead's work and two sprint reversals inside ten minutes. Recorded because the plan should show that the churn was mine."
          },
          "stories": [
            {
              "area": "Messaging",
              "title": "IRC the operator can actually join, from wherever he is, and read what he missed",
              "work_id": "entity_8484a3be9441537961b62cd62b7cf430"
            }
          ]
        },
        {
          "id": "sprint_7e4a0747c14a58dbb2ab9045e2352b68",
          "outcome": "An operator who has not watched the terminal for a day opens one public page and reads what the agents found, each entry carrying its writer, time, category and the sprint context it was written in, including findings that never became a task.",
          "previous_sprint_id": "sprint_2d973ae03a8ac38670ce0e7a46d0a37b",
          "review": {
            "dispositions": [
              {
                "decision": "carry",
                "story_id": "entity_38a987a0e7a5db6a29173270c295cc1f"
              }
            ],
            "reviewed_at": "2026-09-11T19:26:41.268600043Z",
            "reviewed_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
            "summary": "Carried, displaced by the operator. He was explicit that IRC is what he wants and that the site feed was desperation rather than a preference. entity_38a987a0e7a5db6a29173270c295cc1f returns to the backlog with its scope, contract and the lead's estimate intact; the retained assessment and implementation plan stand and should not be re-argued when it comes back.\n\nThe reason for the switch is a mistake of mine, recorded here because the sprint record is where it belongs. I told the operator the feed should come first because IRC as it stands replays only sixteen messages and therefore cannot survive his absence. That is true of the current code and it is not a property of IRC. cmd/sidecat/irc_backend.go:94 asks message.catch-up for a limit of 16, internal/ircgateway/follow.go:39 then truncates to 16 again, and History() immediately below the same function already pages message.history 128 at a time from an after cursor. I took a literal we chose, treated it as an architectural limit, and used it to justify building something else while the thing he had asked for repeatedly stayed undelivered."
          },
          "stories": [
            {
              "area": "Site",
              "title": "Give the operator a durable feed of agent updates instead of a terminal he has to be watching",
              "work_id": "entity_38a987a0e7a5db6a29173270c295cc1f"
            }
          ]
        },
        {
          "id": "sprint_2d973ae03a8ac38670ce0e7a46d0a37b",
          "outcome": "Planning answers ordinary questions with ordinary queries: membership, links, order, dispositions and wording history are typed rows with entity foreign keys, no ordinary read or write path parses JSON, and every public wire shape and rendered page is unchanged.",
          "previous_sprint_id": "sprint_08ad8d66eb44fdbc225e5043ae0b8ab3",
          "review": {
            "dispositions": [
              {
                "decision": "delivered",
                "story_id": "entity_2f8ea7682d270d0516f5ecd81f5d7030"
              }
            ],
            "reviewed_at": "2026-09-11T18:44:40.601791529Z",
            "reviewed_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
            "summary": "Delivered. Runtime source 30b6ead3b5c17b638e332768e30ee22ff6c110ac, closeout 7ba1ae306cfbebf01a2829c08ba20396d978a46b, release 0.2.19 installed at generation 480 on the original store, site 75e9838e7c0b1b24b5d6d02007937464c09d87c0, pipeline 2841775493 succeeded.\n\nPlanning no longer keeps its operational structure in JSON text. Backlog entries, sprint fields, stories, task links, review decisions, earlier wording and every assessment collection are typed rows. Work references carry entity foreign keys, ordered collections are unique within their parent by composite primary key or scoped index, and the latest delivered sprint is now found by joining review decisions rather than searching JSON with json_each.\n\nThe acceptance condition was a copy of the real store, not a fixture, and that is what ran: two boards, 54 sprints, twelve assessment versions, migrated through the actual era path with every converted value compared before any source row was retired. Conversion took 20.835 seconds and preserved the store identity.\n\nI verified the live node myself rather than reading the report. Plan at version 138, current sprint at version 1 with its single story, fourteen backlog items, five recent reviews, latest delivery resolving through the disposition join. Then I went looking for the three shapes a fixture would never have contained, because those are the ones a migration loses quietly. The wording history on sprint_799ff1a9f3ad07d767fe9913eba50596 still holds the outcome sentence I replaced mid-flight at 13:36 today. The carried disposition on sprint_b50e3717172fea0b009799d79409cc03 still reads carry with the summary saying it was displaced by an operator instruction rather than abandoned on its merits. The assessment still has all twenty-two capabilities, three levels and its sources. The hardest data to reconstruct is the data that survived.\n\nThree engineering judgments in this sprint were better than my review of them. Ordering was made impossible to violate in SQL rather than resolved at read time, which required finding and fixing a generator that rejected unique indexes. My finding about the discarded serializer was accepted and then improved: rather than defend a byte limit that valid inputs may never reach, the lead preserved it, tested its real wire boundary and named it checkPlanningWireBudget. And a supporting review produced an ambiguous sentence that could have been read as permission to drop unexpected stored data during a migration; the lead declined to treat ambiguity as authority.\n\nThe capability record tells the truth about its own predecessor. Version 13 says release 0.2.19 corrects the earlier design in which planning and assessment models still stored useful structured data in JSON columns, and the release note says plainly that using an ORM did not make those relationships relational. All twenty-two capability names and levels are unchanged from version 12; four rows and three sources changed. A record that admits the previous description flattered the design is worth more than one that quietly improves.\n\nLimits kept rather than smoothed. The wider ORM conversion is incomplete and older hand-managed persistence remains. Empty legacy table declarations stay for migration history with no ordinary JSON reader or writer. The supported backup of the roughly 2 GB store took about 71 minutes, and that is recorded as a weakness in backup speed and progress reporting rather than selected as work. No full repository suite, no cold install, no federation trial. This does not repair unfinished Actions across binary upgrades and the published upgrade limit still applies.\n\nOne durable effect outside the sprint: the store now exists in three places, with the off-machine copy transferred in 92 parts and its expanded bytes compared against the original digest, after a week-old pair of failed transfer units had left the laptop as the only copy."
          },
          "stories": [
            {
              "area": "System coherence",
              "title": "Replace JSON-backed operational planning data with relational models",
              "work_id": "entity_2f8ea7682d270d0516f5ecd81f5d7030"
            }
          ]
        },
        {
          "id": "sprint_f0ad50f93d9a4b5370002c11d34fe975",
          "outcome": "A stranger reading the capabilities page four days before launch finds every claim on it matched by something we actually delivered, with the limits we already published still on the page.",
          "previous_sprint_id": "sprint_b50e3717172fea0b009799d79409cc03",
          "review": {
            "dispositions": [
              {
                "decision": "delivered",
                "story_id": "entity_20ee7f9ccd8b6f6bfb53847cc68fe23a"
              }
            ],
            "reviewed_at": "2026-09-11T14:54:26.256881844Z",
            "reviewed_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
            "summary": "Delivered. Native assessment v12 at 14:46:36 UTC, source 94325bd4ceaa798b2177484e126863416cf9ecd5, pipeline 2841210512 succeeded. Documentation and one authored assessment: no runtime change, no release.\n\nI read https://sidecat.dev/capabilities.html myself. Both findings from my review are corrected on the live page: the aauth-go source is now labelled a pinned specification baseline and names the pinned commit a99d353, so a reader following it cannot mistake it for the editor's current drafts; and the homepage entry is labelled as an explanation rather than an additional qualification, which removes the circular evidence. All 22 capability names, their order and every level are unchanged, and every previously published limitation survives, including this morning's upgrade boundary.\n\nThe four changed rows do what the outcome asked. Messaging now says node acceptance did not establish a reply or completed work, and that the recorded exchange needed a tmux attention signal and is not a federation demonstration. Source publication now admits that the native original-key query exists while an ordinary CLI read command is not yet delivered, which matches the carried backlog item rather than implying it is in flight. Installation distinguishes the 0.2.12 supplied-bundle trial from the later 0.2.17 upgrade and says plainly that neither was a cold install. Operator updates points at the new walkthrough.\n\nThe two sentences that make this a refresh rather than a promotion are on the live page: no maturity level is raised for documentation, and clearer examples do not by themselves raise maturity. The new summary is the largest improvement. It states what prepared teams do, names the remote-execution capability in an operator's words, and bounds it in the following sentence instead of in a footnote.\n\nScope held. A level moved nowhere. No claim was added that a trial did not establish. The lead dispatched an idle prepared Grok worker for an independent read rather than spending Codex quota, reported it as running rather than as approval while it was still running, and afterwards declined to present its APPROVE as a v12 audit because its header named v11. That is the correct handling of a supporting review and it is recorded here because the temptation was to claim more.\n\nFollow-up: entity_4691d37ae7c3d9c7513da7c1b9359f1c is restored as the next selected outcome."
          },
          "stories": [
            {
              "area": "Site",
              "title": "Bring the capabilities page up to date with what has actually been delivered",
              "work_id": "entity_20ee7f9ccd8b6f6bfb53847cc68fe23a"
            }
          ]
        },
        {
          "id": "sprint_b50e3717172fea0b009799d79409cc03",
          "outcome": "An operator whose publication is stuck can find out what state it is in with one ordinary command and its original request key, without composing an operation reference or JSON by hand, and without resuming or replacing anything.",
          "previous_sprint_id": "sprint_799ff1a9f3ad07d767fe9913eba50596",
          "review": {
            "dispositions": [
              {
                "decision": "carry",
                "story_id": "entity_4691d37ae7c3d9c7513da7c1b9359f1c"
              }
            ],
            "reviewed_at": "2026-09-11T14:34:14.768746892Z",
            "reviewed_by_actor_entity_id": "entity_7741ef5effd5c0edd99589e722c9c474",
            "summary": "Carried, not started. The operator directed the lead to update the capabilities page on sidecat.dev, and that supersedes this selection. No code was written, nothing was published, and entity_4691d37ae7c3d9c7513da7c1b9359f1c returns to the backlog with its scope and conditions intact.\n\nThe reasoning for selecting it stands and should be re-read rather than rewritten when it comes back: the disclosure published this morning tells an operator to read a stuck publication's recorded state before upgrading, and the only route it can offer is sidecat invoke with a hand-written JSON object. The lead's estimate of 45 to 90 minutes and the behavior conditions recorded in the rationale carry with it.\n\nRecording the redirect rather than quietly replacing the sprint, so the plan shows that this item was chosen, was displaced by an operator instruction, and was not abandoned on its merits."
          },
          "stories": [
            {
              "area": "CLI",
              "title": "Reading a stuck publication's state needs an ordinary command, not sidecat invoke",
              "work_id": "entity_4691d37ae7c3d9c7513da7c1b9359f1c"
            }
          ]
        }
      ],
      "scope": {
        "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582",
        "project_key": "sidecat",
        "project_name": "Sidecat"
      },
      "version": 143,
      "current_actor_labels": {
        "entity_66f0c6cd4bdfb1ab70267cbb50a6655f": "Codex",
        "entity_7741ef5effd5c0edd99589e722c9c474": "Claude"
      }
    },
    "work": {
      "active": [
        {
          "commands": {
            "read": "sidecat work read entity_8e9006c1f133d2d8c9810be00421c3dd"
          },
          "id": "entity_8e9006c1f133d2d8c9810be00421c3dd",
          "intent": {
            "at": "2026-09-11T19:54:52.210252692Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Implement the public agent-update renderer and browser controls for the selected feed sprint.\n\nYou are a bounded implementer; root owns integration and Claude reviews the overall sprint. Read workspace AGENTS.md/onboarding and native org guidance. Read sidecat org reference read agent-updates-implementation for the accepted behavior, but only implement this task. Parent Work: entity_38a987a0e7a5db6a29173270c295cc1f. No new model/account settings; normal speed.\n\nCanonical site checkout: /home/jgay-automate/p"
          },
          "latest_report": null,
          "state": "active"
        },
        {
          "commands": {
            "read": "sidecat work read entity_38a987a0e7a5db6a29173270c295cc1f"
          },
          "id": "entity_38a987a0e7a5db6a29173270c295cc1f",
          "intent": {
            "at": "2026-09-11T18:54:28.693834567Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Give the operator a durable feed of agent updates instead of a terminal he has to be watching\n\nOperator, 2026-09-11: a section on sidecat.dev called agent-updates that puts updates in a feed, timestamped, with category tags, sortable, with the sprint and sprint goal alongside so each entry has context.\n\nThe problem it solves, in his words: he mostly flies blind. tmux scrollback is limited and things scroll out of it; he does not read the status tick lines; and anything that needs him and lands only in the t"
          },
          "latest_report": {
            "at": "2026-09-11T19:25:41.069557932Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": false,
            "kind": "progress",
            "text": "RED confirmed on the droplet: all four native update tests failed on absent project.update-post/update-amend/updates-read behavior, not compilation. The cases cover standalone posts, two authors, correction/context, pagination, scope and reopen. Implementing typed scalar/citation models and the native transaction path now. Category discovery and HTML citation handling incorporate Claude 2317/2318. No CLI or public feed implementation yet; the current runtime remains 0.2.19."
          },
          "state": "active"
        },
        {
          "commands": {
            "read": "sidecat work read entity_5d7e87349b6a762e0d50e42241a1093a"
          },
          "id": "entity_5d7e87349b6a762e0d50e42241a1093a",
          "intent": {
            "at": "2026-09-11T09:22:35.990791339Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "What happens to an Action that is in flight when the node upgrades?\n\nObserved 2026-09-11 during the 0.2.15 rollout. The hourly site publication under key site-refresh-d73580f7050e4afcbcf8dd6ef73b5bd6 was active when the development node was upgraded. Its pending Action names admitted definition 33eab7a4; the upgraded runtime admits 1ee8bbf0. source.publication-read returns pending with effect_definition_unavailable, ordinary resume fails because the execution revision must advance its recoverable status, an"
          },
          "latest_report": {
            "at": "2026-09-11T13:26:24.263414256Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "progress",
            "text": "Decision support requested at2195 is retained in full: sidecat org reference read upgrade-recovery-assessment-20260911. The original upgrade-recovery issue remains unresolved; this is not implementation completion. Source proves full-binary coupling in effect identity and its derived admission receipt; the old live publication remains pending/unknown. Incident captures contain the old/new definition digests but not full EffectDefinition JSON; a one-field substitution was incomplete because the receipt also "
          },
          "state": "active"
        },
        {
          "commands": {
            "read": "sidecat work read entity_e3c2d053811ea3f49c68700b3c5e1632"
          },
          "id": "entity_e3c2d053811ea3f49c68700b3c5e1632",
          "intent": {
            "at": "2026-09-10T03:44:35.86883214Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "SCRUM PLANNING RECORD, sprint beginning 2026-09-09. Scrum master Claude owns this record: the sprint goal, its rationale, the minor-target budget and the review against the commitment. Lead engineer Codex contributes engineering assessment, cost, dependencies, uncertainties and delivery plan here rather than in a competing ledger.\n\nPROPOSED MAJOR TARGET, not yet committed, pending engineering cost. A person who has never used Sidecat, starting from a clean machine and published instructions alone, installs "
          },
          "latest_report": {
            "at": "2026-09-10T04:49:05.688585451Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "kind": "progress",
            "text": "Scrum-master decisions at 2026-09-10 04:48 UTC, 41 hours left in the timebox.\n\n1. Minor budget is spent and closed. 87617014 finished by Codex citing probe 320209e7 and removed from the product backlog, plan version 61. QA 339140c7 finished. Metadata-only 0.2.3 closeout published b3d45fbe3fb6647e2dec6f7a370a848a0eebb495. Backlog now holds 7ef3659d (this sprint), 4f71cd21 and ee7979fb.\n\n2. Committed install route is build-from-source from the published archive, not binary download. Reason: the download route"
          },
          "state": "active"
        },
        {
          "commands": {
            "read": "sidecat work read entity_8a47612c9ce822b5a58eec2c24a32acb"
          },
          "id": "entity_8a47612c9ce822b5a58eec2c24a32acb",
          "intent": {
            "at": "2026-09-07T21:25:58.032549364Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Operator-directed update of narrow-not-shallow everywhere maintained/installed. Keep complete useful outcomes, proportionate checks at real entry points and honest limitations; make the six-field worksheet optional, remove compulsory custody/audit/replay ceremony, allow explicit useful intermediate steps and practical temporary measures within existing authority. Update maintained agent-skills source and identified local/remote active copies, preserve unrelated files and historical records, validate the ski"
          },
          "latest_report": {
            "at": "2026-09-07T21:39:29.291164327Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "progress",
            "text": "Updated every identified active copy: maintained agent-skills source and local Codex installation, plus registry trigger. Claude independently confirmed no ~/.claude installed copy and reread the revised guidance; remaining references are historical notes, not copies to rewrite. No installed copy exists in the checked droplet harness roots. For off-machine preservation while GitLab publication awaits one-repository allowlist approval, revised SKILL.md and skills.json are copied to /home/codex2/work/narrow-n"
          },
          "state": "active"
        },
        {
          "commands": {
            "read": "sidecat work read entity_4cccb431cada0d6aab3bd1df94e942d5"
          },
          "id": "entity_4cccb431cada0d6aab3bd1df94e942d5",
          "intent": {
            "at": "2026-09-06T12:54:00.995906075Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "First native cross-node work workflow for the launch: a prepared agent connects to its nearest daemon and performs useful ordinary Work against a second daemon on another machine with an independent store. Use a real source-review assignment and returned result as the first demonstration. Build on generic Sidecat operation dispatch and prepared peer/receiving context, not a Work-only SSH command wrapper or shared database. Codex2 source analysis is finished at entity_95ab8cb2292c6ac03711013f965af3ed and sup"
          },
          "latest_report": {
            "at": "2026-09-09T02:18:28.551147085Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "progress",
            "text": "The live independent-store test still awaits a one-time setup exception. Root resurfaced the pending operator question through the question UI on2026-09-09: allow principal.establish once for a fresh isolated store on the existing droplet, without changing current store/credentials/default profiles or creating infrastructure. No answer or setup is implied by the question. Readiness3bd069fc retains the proposed sequence; its0.1.38 executable paths must be refreshed to the installed release before authorized "
          },
          "state": "active"
        },
        {
          "commands": {
            "read": "sidecat work read entity_dd0db9e682bc2d548d700c4e3bceb42a"
          },
          "id": "entity_dd0db9e682bc2d548d700c4e3bceb42a",
          "intent": {
            "at": "2026-09-06T07:14:09.227074477Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": false,
            "text": "Nine-day launch review as agent user stories: Arrive, Talk, Work, Ship, Restart, then Session and REPL++; three pushes ahead of anything new: identity per working instance not per harness, refusals carry their grant without spending the ledger, verification off the start path. Support to the Sidecat lead; launch 2026-09-15."
          },
          "latest_report": {
            "at": "2026-09-06T15:52:39.583090728Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": false,
            "kind": "progress",
            "text": "Sideloopd Task2 (loop.list/status/send/resume + LoopService + server Config.Loops) GREEN 10/10 on bc9ba4fc; handed to root."
          },
          "state": "active"
        }
      ],
      "queued": [
        {
          "commands": {
            "read": "sidecat work read entity_8484a3be9441537961b62cd62b7cf430",
            "start": "sidecat work start entity_8484a3be9441537961b62cd62b7cf430"
          },
          "id": "entity_8484a3be9441537961b62cd62b7cf430",
          "intent": {
            "at": "2026-09-11T19:29:53.24693544Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "A federated IRCv3 service the operator joins at irc.sidecat.org with a normal client\n\nOperator, 2026-09-11. The target is IRC working via federation, served at irc.sidecat.dev or irc.sidecat.org, with a normal IRC client. Not a single-node server and not a reduced version. In his words, a version that does not use federation is defective by design, because federation is the reason IRCv3 was chosen over common IRC in the first place.\n\nHis preference ordering, stated the same day: a compliant federated IRCv3 "
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_f5f256918d56a6a737dea55395847a87",
            "start": "sidecat work start entity_f5f256918d56a6a737dea55395847a87"
          },
          "id": "entity_f5f256918d56a6a737dea55395847a87",
          "intent": {
            "at": "2026-09-11T17:59:24.827081793Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Make ordinary backups fast, inspectable and recoverable without compulsory whole-history audits.\n\nObserved on the development node running 0.2.18, September 11: store.backup.create started at 16:49 UTC. Its VACUUM snapshot was complete enough to be independently copied with a matching database hash; that copy migrated all planning/assessment values and reopened in about 21 seconds. The original backup invocation was still running more than an hour later. Native store.backup.inspect reported planned while th"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_77494fee6106428af62da0b09aadb995",
            "start": "sidecat work start entity_77494fee6106428af62da0b09aadb995"
          },
          "id": "entity_77494fee6106428af62da0b09aadb995",
          "intent": {
            "at": "2026-09-11T16:58:58.208287001Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Install this machine the way we install for anybody else\n\nOperator instruction 2026-09-11: our own node should be installed the way a stranger's is, unless there is a genuine bootstrapping reason otherwise, and the name gen5 is not part of our vocabulary.\n\nThe installer is already correct. maintain setup node writes ~/.local/state/sidecat/ with node/, store/ and backups/, ~/.config/sidecat/ with four files, and the unit ~/.config/systemd/user/sidecatd.service. What is wrong is this machine: the live node wa"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_5d11bff3ff5c9e5c7707760875d8c275",
            "start": "sidecat work start entity_5d11bff3ff5c9e5c7707760875d8c275"
          },
          "id": "entity_5d11bff3ff5c9e5c7707760875d8c275",
          "intent": {
            "at": "2026-09-11T16:06:15.123618445Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Distinguish operational data from retained source content\n\nOpen product-design question from the operator's September 11 discussion, retained for later planning. Not part of the immediate planning-database repair; not authorization to build a new file service or database.\n\nThe operator distinguished an original document retained and returned verbatim from Sidecat's own structured working data. If Sidecat interprets fields and uses them as its operational model, storing that model as JSON and repeatedly deco"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_e2b74750318a708dc5c6a2ef3c07a7f3",
            "start": "sidecat work start entity_e2b74750318a708dc5c6a2ef3c07a7f3"
          },
          "id": "entity_e2b74750318a708dc5c6a2ef3c07a7f3",
          "intent": {
            "at": "2026-09-11T16:06:14.275780997Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Make operating policies effective across agents, handoffs and reviews\n\nFuture product work requested September 11, 2026; not merely an internal coding checklist or an approved implementation design. Our development is the first use case for a Sidecat capability serving organizations.\n\nOperator statements:\n\"we will work on future sprints where we have a clear way of making sure our coding policies are clearly spelled out and that you get frequent reminders of them and that we have a way of every reviewer hav"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_92af6b4271d909462aa167b32846297a",
            "start": "sidecat work start entity_92af6b4271d909462aa167b32846297a"
          },
          "id": "entity_92af6b4271d909462aa167b32846297a",
          "intent": {
            "at": "2026-09-11T15:54:39.470006452Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "A sprint shows an agreed title and a current one without saying which is which\n\nCorrected 2026-09-11 after the lead source-checked my original claim. My first version said a renamed Work leaves every sprint showing a stale title, and called it a wrong answer. That was wrong.\n\nSelectProjectSprint deliberately retains the intent, title and area as they stood when the work was agreed, and sprintPlanView separately reads the current Work into out.Work. Both values are present. Tests preserve independent editori"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_579bd1dce073121d302beb470145c195",
            "start": "sidecat work start entity_579bd1dce073121d302beb470145c195"
          },
          "id": "entity_579bd1dce073121d302beb470145c195",
          "intent": {
            "at": "2026-09-11T15:14:18.350864644Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "First outside review: a human at a real company evaluated Sidecat and said no\n\nReceived 2026-09-11 through the operator. Docs, source and git history only. The reviewer verified the verdict-deciding claims against our source themselves and marked which findings were their agents'. Verdict: not usable as it stands, but a good deal of the approach is worth taking.\n\nThree reasons for the no.\n\nPractical blockers. The installer supports Linux amd64 and Ubuntu 24.04 only (distribution/install.sh:47-48), so their "
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_f6bf146276c3d0773c958a7efa06011a",
            "start": "sidecat work start entity_f6bf146276c3d0773c958a7efa06011a"
          },
          "id": "entity_f6bf146276c3d0773c958a7efa06011a",
          "intent": {
            "at": "2026-09-11T08:08:18.404834181Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Does restricted context quoted into a shared Work result need an answer at all?\n\nObserved 2026-09-11 during the 0.2.14 installed trial, and recorded as a question rather than a defect. Grok read a restricted reference it was entitled to read, then quoted its content into an ordinary Work result. Work results carry no reader scope, so the non-reader could read the material there within minutes of the feature shipping.\n\nThis is the published limit behaving as documented: Sidecat cannot retract copies already "
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_9aaaa38ac35584c6abf039acaeeb8f30",
            "start": "sidecat work start entity_9aaaa38ac35584c6abf039acaeeb8f30"
          },
          "id": "entity_9aaaa38ac35584c6abf039acaeeb8f30",
          "intent": {
            "at": "2026-09-11T02:39:53.40000727Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Decide what the central layer sells, before a partner asks.\n\nRaised by an outside reviewer on 2026-09-10 as a business-model trap, and it is the sharpest commercial criticism we have received: \"If local daemons and open-source preparation supply nearly all the benefit, the central service may have little pricing power. If useful operation depends heavily on that service, its outage behavior, policy mistakes and migration costs become more consequential.\"\n\nBoth horns are real. Every capability we move into t"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_cabba1285240564ed2381d59efd8e4c4",
            "start": "sidecat work start entity_cabba1285240564ed2381d59efd8e4c4"
          },
          "id": "entity_cabba1285240564ed2381d59efd8e4c4",
          "intent": {
            "at": "2026-09-11T02:39:52.535347143Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "A prospective customer cannot do vendor due diligence from sidecat.dev.\n\nAn outside reviewer evaluating a design partnership on 2026-09-10 reported: no company page, no legal entity name, no location, no team, no pricing, no data-processing agreement, no security description, no support terms, and no description of a design-partner program. Its conclusion: \"A partner evaluating Sidecat LLC from the public web is evaluating an open-source development diary.\"\n\nThis blocks the actual conversation we are in. A "
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_12058e2d9d457db70864c1ffe2a942dd",
            "start": "sidecat work start entity_12058e2d9d457db70864c1ffe2a942dd"
          },
          "id": "entity_12058e2d9d457db70864c1ffe2a942dd",
          "intent": {
            "at": "2026-09-11T02:29:43.485284632Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": false,
            "text": "Give a candid design-partner assessment of Sidecat, as an outside evaluator."
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_e1c3607616db34b8d323d6a107699c13",
            "start": "sidecat work start entity_e1c3607616db34b8d323d6a107699c13"
          },
          "id": "entity_e1c3607616db34b8d323d6a107699c13",
          "intent": {
            "at": "2026-09-11T02:29:24.452836238Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": false,
            "text": "Test probe: a short queued item to check body validation. Delete if seen."
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_5fdc5895b25ddcc867f742d524d153bd",
            "start": "sidecat work start entity_5fdc5895b25ddcc867f742d524d153bd"
          },
          "id": "entity_5fdc5895b25ddcc867f742d524d153bd",
          "intent": {
            "at": "2026-09-11T01:04:26.135156006Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "An agent in one environment runs commands in an isolated other environment through Sidecat.\n\nOperator, 2026-09-10 19:01 MDT, reporting early external feedback: \"the most important feature we need is to have an Agent in environment A be able to use sidecat to execute commands in isolated environment B via federated sidecatd.\" Operator, 19:02, on the shape of B: \"I think in environment B, the execution would happen without an Agent. I am not 100% sure though.\"\n\nThe journey. An agent working in environment A r"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_fd14f2900960b2245077b8c2dae76723",
            "start": "sidecat work start entity_fd14f2900960b2245077b8c2dae76723"
          },
          "id": "entity_fd14f2900960b2245077b8c2dae76723",
          "intent": {
            "at": "2026-09-10T21:08:09.152688611Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "An operator can activate a package without unexplained long waits or unnecessary orchestration. Unscheduled follow-up to measured0.2.8 behavior; do not displace the operator-selected help/guidance sprint. Read characterization Workentity_89ceeaa2361f6c688f8f4fd6b4c94ac9 and data/sidecat/sprint118f-final-reader/activation-timing-report.md. The4921byte Agenda activation took101.07s; retained events place72.93s before restart,10.88s in restart, with47 completed journal steps including30 Work operations and8 ha"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_67318218156ae78c9d2327ea02d47d82",
            "start": "sidecat work start entity_67318218156ae78c9d2327ea02d47d82"
          },
          "id": "entity_67318218156ae78c9d2327ea02d47d82",
          "intent": {
            "at": "2026-09-10T19:13:52.977773767Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Write a comprehensive Sidecat manual: a coherent, book-length, Info-style reference, separate from showcase pages, sprint reports and individual README files. Support progressive reading, indexed lookup and cross-references for people and agents. Cover the system concepts, prepared environments, organization guidance, Work and sessions, agent coordination, CLI reference, REPL and Lisp programming/packages, and operating/extending nodes. The Emacs manual is an analogy for depth and navigability, not a fixed "
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_91ff1ba6eb40500fffd4b039e9abdaaf",
            "start": "sidecat work start entity_91ff1ba6eb40500fffd4b039e9abdaaf"
          },
          "id": "entity_91ff1ba6eb40500fffd4b039e9abdaaf",
          "intent": {
            "at": "2026-09-10T18:35:04.884447321Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Namespace strategy as owned policy, and nested organizations.\n\nOperator, 2026-09-10, continuing the marketplace tiers brainstorm: \"we need to have some default namespaces probably or namespace strategy and then a general system that allows it to be customized for a given company. and obviously things could get more complicated because you might have some place like IBM which would probably have companies under it etc.\"\n\nDefault strategy plus customization. Frame the default as a policy the organization owns"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_8a5447827402594d2c432937190c1cdc",
            "start": "sidecat work start entity_8a5447827402594d2c432937190c1cdc"
          },
          "id": "entity_8a5447827402594d2c432937190c1cdc",
          "intent": {
            "at": "2026-09-10T18:35:02.653926633Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Package marketplace namespaces and tiers. Brainstorm with the operator, 2026-09-10; direction liked, exact shape open.\n\nOperator: \"in our package marketplaces should have stable, testing, unstable, personal\"; \"personal in our case would probably be under jgay-automate\"; \"unstable would be shared across the org\"; \"personal would be a way for me to share my own lisp with the rest of the org\"; \"a company running sidecat across its whole company would probably have a way of letting individuals share their packa"
          },
          "latest_report": null,
          "state": "not_started"
        },
        {
          "commands": {
            "read": "sidecat work read entity_549772324f8a78611ce2abde170b16e4",
            "start": "sidecat work start entity_549772324f8a78611ce2abde170b16e4"
          },
          "id": "entity_549772324f8a78611ce2abde170b16e4",
          "intent": {
            "at": "2026-09-09T14:49:31.398363837Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Repair the outdated TestWorkOrganizationColleagueNoRetainedOrganization expectation when this test area is next touched. Implementation15f306f8 isolated its failure on unchanged674b584d and patched source: the fixture retains a same-organization working session, which the existing session read path already permits colleagues to read. Update the fixture/assertion to test its stated condition accurately without narrowing or widening ordinary access. Keep this as a captured test-maintenance follow-up, not a re"
          },
          "latest_report": null,
          "state": "not_started"
        }
      ],
      "recent_finished": [
        {
          "commands": {
            "read": "sidecat work read entity_4691d37ae7c3d9c7513da7c1b9359f1c"
          },
          "finished_at": "2026-09-11T18:42:21.50455767Z",
          "id": "entity_4691d37ae7c3d9c7513da7c1b9359f1c",
          "intent": {
            "at": "2026-09-11T13:41:29.73868091Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Reading a stuck publication's state needs an ordinary command, not sidecat invoke\n\nA publication is stuck. The operator wants to know what state it is in without resuming it. Today the only route is:\n\n    sidecat invoke source.publication-read --input-json '{\"request_key\":\"REQUEST_KEY\"}'\n\nsource.publication-read is registered as a query operation (internal/kernel/source_publication.go:7,50) but no CLI verb reaches it. Nothing else in that procedure is like this: publishing is `sidecat source publish`, resum"
          },
          "latest_report": {
            "at": "2026-09-11T18:42:21.50455767Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Delivered sidecat source status REQUEST_KEY [--json] in 0.2.18, runtime source 53595059c51d79e84133f8ac7df1b5b002118c7f and closeout a78c696d. The command reads retained publication state using the original key/caller without a repository directory, project or session; it never resumes or repairs. A successful query exits zero for published, pending, blocked or not-started state, independently of whether publication succeeded. Native JSON and historical keys remain readable, including copied-key outer white"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_2f8ea7682d270d0516f5ecd81f5d7030"
          },
          "finished_at": "2026-09-11T18:42:19.339158705Z",
          "id": "entity_2f8ea7682d270d0516f5ecd81f5d7030",
          "intent": {
            "at": "2026-09-11T16:06:13.159225868Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Replace JSON-backed operational planning data with relational models\n\nOperator instruction, September 11, 2026: \"OK well please fix it.\" This supersedes the earlier after-September-15 deferral. Claude defines the corrective sprint; the lead engineers and estimates it.\n\nProblem: the backlog, sprint fields/story membership, ordering, task links and review decisions are useful structured state, but project_planning and project_sprints store them in JSON text and application code reconstructs/manipulates them. "
          },
          "latest_report": {
            "at": "2026-09-11T18:42:19.339158705Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Delivered in 0.2.19, runtime source 30b6ead3b5c17b638e332768e30ee22ff6c110ac; qualified release notes/lock published at 7ba1ae306cfbebf01a2829c08ba20396d978a46b. Backlog, sprint fields/stories/links, review decisions and saved values, wording, and capability assessments now use typed relational rows. Planning Work references have entity FKs; ordered collections have parent-scoped unique positions. Latest delivery joins disposition rows. Wire JSON and selected/current/review distinctions are unchanged. Legac"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_920c21993a6d35ba22823a92f1e917f0"
          },
          "finished_at": "2026-09-11T16:21:33.115407926Z",
          "id": "entity_920c21993a6d35ba22823a92f1e917f0",
          "intent": {
            "at": "2026-09-11T16:17:13.804143525Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Review the relational planning migration's saved-Work projection boundary\n\nParent repair: entity_2f8ea7682d270d0516f5ecd81f5d7030. Read its full intent, sidecat org guidance, workspace AGENTS.md/onboarding and sidecat org reference read planning-relational-implementation before reviewing. Report which of these you actually read.\n\nRead-only, bounded source review; no source/state edits outside reporting this Work, no local Go/tests, no provider/model changes, no public publication. Source: /home/jgay-automat"
          },
          "latest_report": {
            "at": "2026-09-11T16:21:33.115407926Z",
            "by": "entity_24fc0d7b86ac6e5378e97c8d9b7cc1bf",
            "clipped": true,
            "kind": "result",
            "text": "Read: parent Work entity_2f8ea7682d270d0516f5ecd81f5d7030; org guidance revision_cf5442903f62a35eb96db611f3f23666; workspace AGENTS.md and .sidecat/onboarding.json; org reference planning-relational-implementation. Source a78c696d in main-integration-20260904. No live SQLite, no source edits.\n\nAnswer: no planning writer populates Completion or CreationInvocation on sprint snapshots. Those fields are only filled by the working-session review overlay.\n\nEvidence\n- Only WorkSnapshotJSON writer is ReviewProjectS"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_20ee7f9ccd8b6f6bfb53847cc68fe23a"
          },
          "finished_at": "2026-09-11T14:50:08.918410819Z",
          "id": "entity_20ee7f9ccd8b6f6bfb53847cc68fe23a",
          "intent": {
            "at": "2026-09-11T14:34:25.793997788Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Bring the capabilities page up to date with what has actually been delivered\n\nOperator instruction to the lead, 2026-09-11, direct to the pane: update the capabilities page on sidecat.dev.\n\nThe page is the one place a stranger can check whether our claims match what was built, and it is four days from launch. The last authored assessment is version 10, recorded this morning, and it was a disclosure edit: it added the binary-upgrade limit to three capability records and changed nothing else. It was explicitl"
          },
          "latest_report": {
            "at": "2026-09-11T14:50:08.918410819Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Updated https://sidecat.dev/capabilities.html from native assessment v12, recorded 2026-09-11T14:46:36.579286008Z. Published source 94325bd4ceaa798b2177484e126863416cf9ecd5; pipeline 2841210512 succeeded. All five checked public bodies returned 200 and matched the tested build, including capabilities.html. The site worktree is otherwise unchanged.\n\nReviewed the prior 22 rows against published qualifications, retained delivery reports and documented implementation boundaries, not a rerun of every trial. All "
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_74443c3a9cd813b9d479f0a685e4d4db"
          },
          "finished_at": "2026-09-11T14:50:07.211314981Z",
          "id": "entity_74443c3a9cd813b9d479f0a685e4d4db",
          "intent": {
            "at": "2026-09-11T14:32:44.596525389Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": false,
            "text": "Update the public capabilities assessment from verified current deliveries, publish its native projection, and check the live page. Operator requested this update on September 11, 2026. Preserve honest maturity levels; distinguish documentation improvements from new runtime capabilities."
          },
          "latest_report": {
            "at": "2026-09-11T14:50:07.211314981Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Updated https://sidecat.dev/capabilities.html from native assessment v12, recorded 2026-09-11T14:46:36.579286008Z. Published source 94325bd4ceaa798b2177484e126863416cf9ecd5; pipeline 2841210512 succeeded. All five checked public bodies returned 200 and matched the tested build, including capabilities.html. The site worktree is otherwise unchanged.\n\nReviewed the prior 22 rows against published qualifications, retained delivery reports and documented implementation boundaries, not a rerun of every trial. All "
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_e01b872bee2182f0d756947cf71675a6"
          },
          "finished_at": "2026-09-11T14:49:22.909718571Z",
          "id": "entity_e01b872bee2182f0d756947cf71675a6",
          "intent": {
            "at": "2026-09-11T14:45:34.622843637Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Read-only reader review of the capabilities-page refresh. Return a concise approve/reject with concrete findings in this Work result; do not change repository files, native maturity, source publication, sprint selection, or any other Work. This is editorial review, not a test-suite or specification-alignment assignment.\n\nPublic site checkout: /home/jgay-automate/projects/gitlab.com/sidecat-dev/sidecat-dev.gitlab.io. Compare current src/data/capability-maturity.json (native assessment v11) to git show a212d2"
          },
          "latest_report": {
            "at": "2026-09-11T14:49:22.909718571Z",
            "by": "entity_24fc0d7b86ac6e5378e97c8d9b7cc1bf",
            "clipped": true,
            "kind": "result",
            "text": "APPROVE native assessment v11 (recorded 2026-09-11T14:42:17Z) versus v10 at a212d244.\n\nAll 22 names, order and levels are unchanged. Level definitions, title, date and reporting_limitations are unchanged. Changed rows are only #3 Native messaging, #10 Rolling operator updates, #11 Source publication (limitations and work_ids), and #12 Installation, plus summary/context/conclusion and four source links. AAuth (useful), Sidecat AAuth consumption (partial) and federation (partial) are byte-identical to v10.\n\nM"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_144e1d4cacb4482e77b3a7e15b59f418"
          },
          "finished_at": "2026-09-11T14:25:19.387605187Z",
          "id": "entity_144e1d4cacb4482e77b3a7e15b59f418",
          "intent": {
            "at": "2026-09-11T05:22:00.800744331Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Say what Sidecat is for in the first sentence, without promising enforcement.\n\nThe 0.2.12 homepage correction removed four unsupported guarantees and replaced them with claims a stranger can check. It also replaced the thesis sentence, which was not one of the defects. The page now opens with an accurate description of what the software does, and no statement of what it is for or why it is built the way it is.\n\nThe scrum master asked for a thesis sentence back during that sprint; the lead engineer kept the "
          },
          "latest_report": {
            "at": "2026-09-11T14:25:19.387605187Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Delivered the homepage explanation at https://sidecat.dev/. It now starts: \"Sidecat is open-source software that lets your AI agent run programs and read information on another machine, once an operator has prepared the connection and permissions.\" The same paragraph names the 0.2.12 trial, says the receiving machine runs Sidecat without another agent/model subscription, identifies the calling agent's lack of login/SSH credentials for that machine, and locates isolation in OS/VM/container boundaries. The me"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_4441f4ec338e4188e36697dd4969c022"
          },
          "finished_at": "2026-09-11T13:52:57.321606509Z",
          "id": "entity_4441f4ec338e4188e36697dd4969c022",
          "intent": {
            "at": "2026-09-11T13:28:07.424060075Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Publish the current binary-upgrade limitation for unfinished effects in the existing publication notes, federation notes and capability assessment. Selected by scrum master at2201. State what changed runtimes cannot currently resume, distinguish completed results, same-implementation restart recovery and ordinary saved Work, and give practical planned-upgrade guidance without promising recovery of the historical unknown Action. Documentation and authored maturity update only; no runtime behavior, compatibil"
          },
          "latest_report": {
            "at": "2026-09-11T13:52:57.321606509Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Delivered disclosure, not a recovery fix. Core docs058ae82869827d520dd7ba970152aa7c05080505 update README publication/resume guidance, docs/federation.md and the actual upgrade instructions in docs/first-worker.md. All three public GitLab file reads returned200 and matched the selected source. The text explains exact implementation/binary coupling, completed-result and ordinary-Work distinctions, fresh calls versus interrupted commands, a read-only original-key check, and practical maintenance notes. A sepa"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_1913c5ebb0e74034e45a88d8976237c3"
          },
          "finished_at": "2026-09-11T12:57:54.954819607Z",
          "id": "entity_1913c5ebb0e74034e45a88d8976237c3",
          "intent": {
            "at": "2026-09-11T00:54:26.222986841Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Show what a Sidecat message actually does, next to the by-hand equivalent.\n\nThe showcase (entity_4f24bea1, published at https://sidecat.dev/showcase.html) explains source publication as a four-operation chain against the shell commands a person would otherwise type. The operator asked for the same treatment of an actual message command and it was not part of that story: \"also yes explaining what is happening with an actual message command\", 2026-09-10.\n\nA reader who has never used Sidecat should be able to "
          },
          "latest_report": {
            "at": "2026-09-11T12:57:54.954819607Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Delivered at https://sidecat.dev/showcase.html#message-exchange. Site commit0c91b22fd0ed494de5ead0b7866933aa44481f8c, pipeline2840859913 success; both showcase.html and the historical sprint URL return200 and match the tested build byte-for-byte. The new September11 section shows actual send2184, the first read with no later reply, and the later read containing Claude reply2185. Command/response values were compared directly with all three saved exit0 captures. The full send response, complete request/reply"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_bd95a0edb4b6b0b4f422ffdb901f06ed"
          },
          "finished_at": "2026-09-11T12:10:29.939242793Z",
          "id": "entity_bd95a0edb4b6b0b4f422ffdb901f06ed",
          "intent": {
            "at": "2026-09-11T05:45:11.905915864Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "Correcting a sprint's wording should not look like delivering a sprint.\n\nA sprint's outcome text cannot be revised. The only way to change it is to review the sprint and select a replacement, so an editorial fix produces a closed sprint and a new one, and the public projection's Latest reviewed change then shows the correction instead of the most recent real delivery.\n\nObserved 2026-09-10 between 19:00 and 19:16 MDT, with the scrum master as the cause. Three sprints were recorded in twenty minutes: sprint_a"
          },
          "latest_report": {
            "at": "2026-09-11T12:10:29.939242793Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Delivered as0.2.17. Native source4016bbd1ee164bebd4cbac6c7e1b1d8e0909d9a1; qualified installer/catalog3b0c129d6ec2864e4a38c826e2e8ee0d9a2b0177; final notes0d67deb73cd123ba3396cc97563b2cf29f23f00d. Development generation478 retained original store; node and local/remote worker tools report installed/ready.\nActual current sprint c14b730a was corrected with one ordinary project sprint update call, version2->3, without changing ID, original selection time/author, stories, links, rationale or unreviewed state. S"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_4ab792536077947bc616d6b0a38ac9b7"
          },
          "finished_at": "2026-09-11T11:30:45.731899142Z",
          "id": "entity_4ab792536077947bc616d6b0a38ac9b7",
          "intent": {
            "at": "2026-09-11T11:10:23.805219914Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "text": "Implement Task1 from native reference sprint-wording-plan (read via sidecat org reference read sprint-wording-plan). Parent entity_bd95a0edb4b6b0b4f422ffdb901f06ed; selected sprint c14b730ac0af0ff564db69a3b797470c. Claude approved design2160, root clarified2162. You own only native Go/CLI/help in this task; root owns the public site.\nPrepared scratch /home/codex2/work/sprint-wording.mU5oIX is an exact plain archive of canonical core e95228fcbdae09bda34ea15be6cdfd66bf907e31. Work there as codex2. Use normal/"
          },
          "latest_report": {
            "at": "2026-09-11T11:30:45.731899142Z",
            "by": "entity_ce4c642d849a0ab39266a84f2ddf5768",
            "clipped": true,
            "kind": "result",
            "text": "Completed Task 1 native implementation in /home/codex2/work/sprint-wording.mU5oIX.\nproject.sprint-update / UpdateProjectSprint and CLI update correct only the current unreviewed sprint. Actual changes retain prior outcome/rationale and author/time in agreement JSON, preserve selection/stories/links/review, and atomically increment sprint version. Omitted text is preserved; no-op keeps version/history/attribution. Empty/blank/null/invalid/oversize, stale version, unknown/noncurrent/reviewed targets refuse wi"
          },
          "state": "finished"
        },
        {
          "commands": {
            "read": "sidecat work read entity_b0830a57f802fc0c82ad2d8e883b0191"
          },
          "finished_at": "2026-09-11T10:57:11.641338453Z",
          "id": "entity_b0830a57f802fc0c82ad2d8e883b0191",
          "intent": {
            "at": "2026-09-11T08:08:19.275163248Z",
            "by": "entity_7741ef5effd5c0edd99589e722c9c474",
            "clipped": true,
            "text": "A refused read through the REPL reports an effect that never happened.\n\nObserved 2026-09-11 on the installed development node. Calling a refused organization.reference.read through sidecat repl eval returns repl_evaluation_failed with consequence_class transition and consequence_state unknown, wrapping an underlying refusal that is a query with consequence none. The public message is correct and carries no content.\n\nThe defect is the envelope, not the refusal. A caller reading consequence_state unknown is b"
          },
          "latest_report": {
            "at": "2026-09-11T10:57:11.641338453Z",
            "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
            "clipped": true,
            "kind": "result",
            "text": "Delivered as 0.2.16. Runtime source ddac9eceeab09162cb864129ed777cdd22c1b741; installer, release catalog and installed qualification notes e95228fcbdae09bda34ea15be6cdfd66bf907e31. Node generation477 retained original store; node and local/remote worker installers report ready.\nWhole-evaluation REPL failures keep the declared transition class. Known-clean refusals and interpreter-only failures now report not_applied; earlier possible host work or an invocation that unwinds before reporting remains unknown. "
          },
          "state": "finished"
        }
      ]
    },
    "windows": {
      "active": {
        "has_more": false,
        "limit": 20,
        "scope": {
          "kind": "project",
          "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582",
          "project_key": "sidecat",
          "project_name": "Sidecat"
        }
      },
      "note": "Bounded native pages, not complete history. Reads are sequential, not an atomic snapshot. Finished results are authored reports, not independent capability verification.",
      "queued": {
        "about": "",
        "has_more": false,
        "limit": 20,
        "scope": {
          "kind": "project",
          "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582",
          "project_key": "sidecat",
          "project_name": "Sidecat"
        }
      },
      "recent_finished": {
        "has_more": true,
        "limit": 12,
        "order": "newest_finished",
        "scope": {
          "kind": "project",
          "organization_entity_id": "entity_04eae5b8aa5ab4424e92d3ea39d9f582",
          "project_key": "sidecat",
          "project_name": "Sidecat"
        }
      }
    },
    "source": "Compact brief copied verbatim from one evaluation of the shared project-brief helper; the full sections below come from the same evaluation.",
    "observation_note": "Per-page as_of and next_cursor and planning as_of and next_review_id are observation/continuation metadata and are omitted here, so a refresh that changes nothing else stays unchanged. Limits, has_more, order, scope, versions and authored selection/review times are kept. Older reviews can be read using the last displayed review ID.",
    "current_actor_labels": {
      "entity_66f0c6cd4bdfb1ab70267cbb50a6655f": "Codex",
      "entity_7741ef5effd5c0edd99589e722c9c474": "Claude",
      "entity_ce4c642d849a0ab39266a84f2ddf5768": "Codex2"
    }
  },
  "roadmap": {
    "revision_id": "revision_1b0a1db9327056e9090c7c9986ababfe",
    "content_digest": "sha256:03e5b710ff4aefa60755db74057aa6a66ab0caafa34fa0f3d37bfa11993c9c0d",
    "approval_status": "accepted",
    "status": "under_development",
    "exact_delta": "PRODUCT DIRECTION — PREPARED PEOPLE AND AGENTS DO USEFUL WORK\n\nSidecat should make work easier and faster: prepare the environment once, let agents work with minimal repeated inputs, and help people and agents understand outcomes and continue together.\n\nPlanning and execution\nThe native project plan owns the ordered product backlog, current sprint agreement, linked Work and reviews. Read it with sidecat project plan or the shared project-brief. This roadmap provides direction and release outlook; it is not an implementation queue. Historical milestone records and earlier roadmap revisions remain history, not current assignments.\n\nCapabilities to develop together\n- Prepared environments: inherit useful project/session context and reach the resources needed for work without reconstructing setup.\n- Sessions and continuity: recover intent, decisions, contributions and useful outcomes across agents and interruptions.\n- REPL++ and reusable libraries: turn repeated real work into readable methods that colleagues can adopt, configure, update and compose.\n- Persistent workers: connect useful Work and messages to bounded agent turns, with practical continuation across changing model availability.\n- Collaboration across nodes: people and agents on independent daemon/store environments can cooperate. A forwarded worker sharing one store does not prove federation.\n- Operator understanding: deterministic rolling views expose selected outcomes, progress, remaining scope and releases. Software development is our current learning case, not the universal format for other kinds of work.\n- A responsive core and useful packages: keep ordinary startup, talk, work and shipping fast; use model-driven additive storage rather than more hand-maintained SQL.\n- Chat interoperability: extend participation through IRCv3 where it serves real work. Commercial-side implementation is a separately authorized lane.\n\nRelease direction — operator approved 2026-09-09\n0.2.0 closes a useful, honestly bounded prepared-team baseline. Finish the selected author-recognition story and live report-publication repair, resolve the unpublished org/organization duplication, exercise the connected prepare/recover -> pick up Work -> coordinate/dispatch -> recover result -> review/publish path with proportionate checks, and publish a concise starting path, release notes and actual limitations. This is a finite closing scope, not complete architecture cleanup. Independent-node qualification is no longer a 0.2.0 prerequisite; broader AAuth consumption, general package distribution, full ORM conversion and system-wide interface redesign remain unfinished product work.\n\n0.3.0 makes Sidecat coherent and composable as one understandable SYSTEM and uses Sidecat itself to sustain that coherence. Derive shared concepts, meanings, relationships, composition and responsibility boundaries from real human and agent work. Names such as Sidebird, Sidebar and Sideloop are discussion handles, not assumed subsystem boundaries; platform, operating-system, VM, language and protocol comparisons are examples, not an exhaustive design specification. Command consistency is a consequence of coherent system design, not the organizing principle.\n\nConnect relevant principles/goals/current decisions to preparation, planning, Work pickup and review using existing facilities where useful. Improve the actual implementation and reusable Lisp working methods through that environment. A returning worker should receive relevant direction, complete a real consequential change, and leave a deliberately adopted improvement that benefits the next worker. Assess fewer surprises, less reconstruction and useful composition, not record counts or documents written. Neither a new planning framework alone nor a larger onboarding dump satisfies this outcome. Continue useful work during consolidation; no rewrite hiatus or universal doctrine.\n\nThe lead may add or adjust bounded work through the agile loop when actual findings justify it. These release outcomes are approved direction, not a frozen exhaustive task list, automatic priority scoring or compatibility bureaucracy. After 0.2.0, short-lived coherent feature branches can keep main usable. Full historical auditing and blanket verification are not release defaults.\n\nBoundaries\nSidecat is not a security isolation layer. Full evidence retention, historical auditing and custody checks are optional enhancements, not prerequisites for ordinary work. Markdown continuity remains a temporary product gap, not the intended operating system. Roles and capacity change; no permanent agent ownership is implied. The open-source project is already public; September 15 concerns the separate sidecat.org service.\n\nPending external decisions remain attached to their original Work: independent-node initial identity setup (4cccb431), the skill-repository publication allowance (8a47612c), and later Codex-owned AAuth draft alignment (3671310b). They do not block unrelated selected work.",
    "rationale": "Preserve the working product and close a finite 0.2.0; make 0.3.0 a deliberate investment in whole-system coherence and a prepared environment that carries organizational intent into decisions. This replaces repeated standalone cleanups with improving Sidecat and using it to sustain improvements.",
    "operator_statement": "Operator direction, summarized: use an agile product backlog, selected sprint outcome and review, not a revised-roadmap planning queue. Prepare environments and make human and agent work easier with minimal repeated inputs. Codex leads within current delegated authority; collaborators vary with availability. Select objectively across product needs, not simply the latest feedback. Custody and complete evidence are opt-in. Human understanding and participation are essential. Agents maintain deterministic update mechanisms, not recurring website reports.\n\n2026-09-09 operator approval, verbatim: \"OK so with that adjustment I approve your 0.2.0 plan. And I approve your 0.3.0 plan. The shape of what you are saying feels right to me with 0.3.0 and I think doing what you say we should do will get us roughly where it makes sense for 0.2.0 to be (of course there might be some other things that get added as you iterate through your agile development approach).\"\n\nThe adjustment is one understandable Sidecat system, not merely one command model. Native Work ecd01173603e194f3b6ffdf77a667786 retains the approved interpretation and boundaries.",
    "dependencies": "Existing prepared organization/project, native Work, shared methods, workers and development droplet. Go compilation and focused tests stay on the droplet. Independent-node setup needs its explicitly requested identity exception; no new spending or private-estate access is assumed.",
    "displaced_work": "No current author-recognition or publisher-repair work displaced. The earlier proposed independent-node 0.2 cutoff is superseded by a bounded useful baseline; independent-node work remains unfinished, not cancelled. After 0.2, system coherence takes priority over unrelated feature expansion, subject to ordinary lead-led agile adjustment."
  },
  "work": {
    "active": [
      {
        "id": "entity_8e9006c1f133d2d8c9810be00421c3dd",
        "status": "active",
        "created_at": "2026-09-11T19:54:52.210252692Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Implement the public agent-update renderer and browser controls for the selected feed sprint.",
        "intent": {
          "text": "Implement the public agent-update renderer and browser controls for the selected feed sprint.\n\nYou are a bounded implementer; root owns integration and Claude reviews the overall sprint. Read workspace AGENTS.md/onboarding and native org guidance. Read sidecat org reference read agent-updates-implementation for the accepted behavior, but only implement this task. Parent Work: entity_38a987a0e7a5db6a29173270c295cc1f. No new model/account settings; normal speed.\n\nCanonical site checkout: /home/jgay-automate/projects/gitlab.com/sidecat-dev/sidecat-dev.gitlab.io (main). Verify HEAD/dirt before edits. The existing timer can change generated data independently; preserve it. You may create ONLY scripts/render-agent-updates.mjs, scripts/agent-updates-controls.mjs and tests/agent-updates-render.test.mjs. Do not change other files, generated data, AGENTS, dependencies, git state or publish. Root owns collector, Astro page/CSS, deployment and all Go code.\n\nExport renderAgentUpdates(document) from the renderer. Input is a validated publication document: {format:\"sidecat.project-updates.v0\",as_of:UTC_ISO,scope:{organization_entity_id,project_key,project_name},current_actor_labels:{actorID:label},updates:[entry...]}. Seed may have projection_status:\"not-collected\". Each entry has id (positive project-local integer), body, category, posted_by_actor_entity_id, posted_at, optional amended_by_actor_entity_id/amended_at, context:{project_name,project_purpose?,sprint_id?,sprint_outcome?}, optional work_ids. Context is historical at posting; labels are current presentation names. Read scripts/render-maturity.mjs and actor-labels.mjs for existing style/helpers.\n\nRender a readable public feed with timestamp, writer, category, complete authored text, original context (details is fine), and visible correction writer/time. Keep claims in the author's words; escape text/attributes. Do not print node-specific Work citation IDs in HTML; JSON retains them. No all/small caps, tiny fonts, marketing paragraphs or terminal dumps. Distinguish an uncollected seed, no posts, and a filter with no matches.\n\nInclude category and newest/oldest controls, count/empty-filter feedback, and data attributes for entries. Export installAgentUpdateControls(root) from the controls module for root's Astro script to call. No top-level document/window use: Node tests import modules. Prefer a pure exported selection/order function shared by rendering and controls; exact case-sensitive category matching, ID order, no data mutation. Controls must use native selects and preserve keyboard focus. Root will verify actual browser wiring.\n\nTDD: write focused Node tests and observe failure before production code; test content/context/correction, escaping, categories/order, no mutation and empty states. Do not test merely that mocks exist. Use existing dependencies only. Report exact red/green commands/results and interfaces/data attributes to root through this Work. Finish this bounded Work only when the three files and tests are complete; that is not a claim that the feed is deployed. If incomplete, retain progress so a second prepared turn can continue.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T19:54:52.210252692Z"
        },
        "changed_at": "2026-09-11T19:54:52.210252692Z"
      },
      {
        "id": "entity_38a987a0e7a5db6a29173270c295cc1f",
        "status": "active",
        "created_at": "2026-09-11T18:45:04.268421096Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Give the operator a durable feed of agent updates instead of a terminal he has to be watching",
        "intent": {
          "text": "Give the operator a durable feed of agent updates instead of a terminal he has to be watching\n\nOperator, 2026-09-11: a section on sidecat.dev called agent-updates that puts updates in a feed, timestamped, with category tags, sortable, with the sprint and sprint goal alongside so each entry has context.\n\nThe problem it solves, in his words: he mostly flies blind. tmux scrollback is limited and things scroll out of it; he does not read the status tick lines; and anything that needs him and lands only in the terminal is gone within hours. Today several findings reached him only because he happened to be at the pane: a systemd unit that had restarted 291,209 times against a file that does not exist, a pair of backup transfer units that failed on 2026-09-04 and sat unnoticed for a week, and the development droplet at 98 percent. None of those would have survived twelve hours of him not looking.\n\nThis is a projection, not a new mechanism. The progress page already renders from node records through a generator and a renderer, with a JSON twin, published on a schedule by sidecat-dev-progress.timer.\n\nWanted: entries carrying a timestamp, a category, and the text; sortable and filterable by category; the current sprint outcome and the project goal rendered alongside so an entry read hours later has its context. A JSON twin like the progress page has.\n\nCORRECTED 2026-09-11 after the lead's boundary check. My first version said to build it unlinked and absent from llms.txt, as though that made it private. It does not. GitLab Pages serves an unlinked page to anyone with the URL, and the site data files are committed in a public repository. Omitting a page from llms.txt is not an access control, and the lead was right to refuse to publish internal operational material on that assumption.\n\nAudience is public, and the privacy constraint was mine rather than the operator's. He asked for a section on sidecat.dev. The resolution is the lead's: updates deliberately written for a public reader, not an export of internal channels or a raw record dump. That needs no authentication system and uses the site we already publish.\n\nPublishing our own faults is already our standard rather than an exception to negotiate. We published the binary-upgrade limit, the correction that using an ORM did not make our relationships relational, and a 71-minute backup recorded as a weakness. A silently failing scheduled service belongs in the same register. What never goes out, regardless of audience: credentials, third-party identities including anyone who reviews us in confidence, and any customer detail.\n\nOpen design question for the assessment: where entries come from. Deriving them from existing Work progress, results and sprint reviews misses findings never reported to Work, and parsing structured metadata back out of message prose would repeat the storage mistake 0.2.19 just removed.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T18:54:28.693834567Z"
        },
        "progress": {
          "text": "RED confirmed on the droplet: all four native update tests failed on absent project.update-post/update-amend/updates-read behavior, not compilation. The cases cover standalone posts, two authors, correction/context, pagination, scope and reopen. Implementing typed scalar/citation models and the native transaction path now. Category discovery and HTML citation handling incorporate Claude 2317/2318. No CLI or public feed implementation yet; the current runtime remains 0.2.19.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T19:25:41.069557932Z"
        },
        "changed_at": "2026-09-11T19:25:41.069557932Z"
      },
      {
        "id": "entity_5d7e87349b6a762e0d50e42241a1093a",
        "status": "active",
        "created_at": "2026-09-11T09:22:35.990791339Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "What happens to an Action that is in flight when the node upgrades?",
        "intent": {
          "text": "What happens to an Action that is in flight when the node upgrades?\n\nObserved 2026-09-11 during the 0.2.15 rollout. The hourly site publication under key site-refresh-d73580f7050e4afcbcf8dd6ef73b5bd6 was active when the development node was upgraded. Its pending Action names admitted definition 33eab7a4; the upgraded runtime admits 1ee8bbf0. source.publication-read returns pending with effect_definition_unavailable, ordinary resume fails because the execution revision must advance its recoverable status, and a direct resume then hit a live-owner conflict. A repeated unavailable result also meets an existing prohibition on an uncertain state following an uncertain state, leaving the resume attempt started.\n\nThe external effect was provably absent: the site repository had the generated paths staged, with no commit and no push, so nothing irreversible had happened. Recovery options under discussion were a supported installer restore to the previous version to finish the original key and then reinstall, or abandoning the key and refreshing under a new one.\n\nWhy it matters beyond one incident. The advice this situation implies for a customer is downgrade, resume, upgrade again, for whatever happened to be running when they upgraded. Upgrading while work is in flight is normal, and our own release process does it hourly. An agent that cannot resume and cannot honestly abandon has no move.\n\nOpen, and deliberately not designed here: whether an upgrade should refuse while Actions are in flight, whether a definition should be retained long enough for in-flight executions to complete, whether there should be a supported way to record a pending effect as not applied on external evidence, or whether the honest answer is documentation about upgrade timing. Each has a different cost and at least one of them is a trap.\n\nFails if the answer becomes a verification or audit mechanism on the ordinary execution path, or a startup check that gates the daemon. Excluded until decided: schema changes, retention policy for definitions, and any automatic retry or rollback.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T09:22:35.990791339Z"
        },
        "progress": {
          "text": "Decision support requested at2195 is retained in full: sidecat org reference read upgrade-recovery-assessment-20260911. The original upgrade-recovery issue remains unresolved; this is not implementation completion. Source proves full-binary coupling in effect identity and its derived admission receipt; the old live publication remains pending/unknown. Incident captures contain the old/new definition digests but not full EffectDefinition JSON; a one-field substitution was incomplete because the receipt also depends on binary identity, so it does not prove an independent contract change. Historical reconstruction stopped at2198; no database access, downgrade or old-Action mutation. Assessment separates launch disclosure and manual planned-upgrade guidance (30–60min, medium confidence), explicit maintenance/drain (3–6h, low confidence; prevention only), and compatible source-publication recovery across binary changes (6–12h first vertical, low confidence; broader providers additional). Recommends disclosure now and a separately committed recovery design later. Attestation-based non-application, blind fresh-key retries, indefinite old binaries and startup audits are named traps. Pure current-contract probe ran through remote go-slot; no product code changed. Scrum master to review scope/costs and select the documentation increment if accepted.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T13:26:24.263414256Z"
        },
        "changed_at": "2026-09-11T13:26:24.263414256Z"
      },
      {
        "id": "entity_e3c2d053811ea3f49c68700b3c5e1632",
        "status": "active",
        "created_at": "2026-09-10T03:44:35.86883214Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "SCRUM PLANNING RECORD, sprint beginning 2026-09-09. Scrum master Claude owns this record: the sprint goal, its rationale, the minor-target budget and the review against the commitment. Lead engineer Codex contributes engineering assessment, cost, dependencies, uncertainties and delivery plan here rather than in a competing ledger.",
        "intent": {
          "text": "SCRUM PLANNING RECORD, sprint beginning 2026-09-09. Scrum master Claude owns this record: the sprint goal, its rationale, the minor-target budget and the review against the commitment. Lead engineer Codex contributes engineering assessment, cost, dependencies, uncertainties and delivery plan here rather than in a competing ledger.\n\nPROPOSED MAJOR TARGET, not yet committed, pending engineering cost. A person who has never used Sidecat, starting from a clean machine and published instructions alone, installs it, reaches a working node, and does real work on it: creates ordinary Work and recovers it. The proof is one unrehearsed run recorded on the live node.\n\nThe 'does real work' clause is Codex's correction and I accept it. My first wording stopped at a working node, which is weaker than the launch premise and would have let status ready count as success. Codex's assessment is also that a clean usable node needs more than a bundle URL and a fetch: fresh configuration, service and endpoint setup, a first usable caller and organization, because existing install deliberately requires a prepared target. That widens the target and I would rather know now.\n\nWHY THIS, WHY NOW. It is the first journey any stranger meets and the only one with no implementation at all. The launch premise is strangers running journeys end to end, the date is 2026-09-15, and at substantial sprint size this is one of perhaps two or three sprints remaining, so this is a launch decision rather than a rehearsal. The hard half exists: four-binary cutter, release lock with per-artifact sha256, install with backups, rollback and readiness.\n\nFAILURE CONDITION, stated so the sprint can be failed. If a person cannot reach that outcome from published instructions alone, the sprint failed regardless of how many items closed.\n\nCANDIDATE MINOR TARGETS, budgeted at commitment, not yet set. Close the carryover rather than carry it: discovery 87617014 fresh-context qualification, QA 339140c7, 0.2.3 final release metadata. Argv and command surface cleanup. Rule: when the sprint is at risk minors are dropped and the major is not.\n\nOUT OF SCOPE, to prevent drift: package marketplace, AAuth integration, any install infrastructure beyond publishing and fetching a bundle and preparing a fresh host.\n\nALSO MINE TO RECONCILE IN PLANNING: roadmap-current still returns the old AAuth walkthrough, Sprint 1 and package-layers milestones and does not represent 0.2/0.3. Codex confirmed this independently. Retained is not current; it will be reconciled here and is not scope by virtue of being retained.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-10T03:44:35.86883214Z"
        },
        "progress": {
          "text": "Scrum-master decisions at 2026-09-10 04:48 UTC, 41 hours left in the timebox.\n\n1. Minor budget is spent and closed. 87617014 finished by Codex citing probe 320209e7 and removed from the product backlog, plan version 61. QA 339140c7 finished. Metadata-only 0.2.3 closeout published b3d45fbe3fb6647e2dec6f7a370a848a0eebb495. Backlog now holds 7ef3659d (this sprint), 4f71cd21 and ee7979fb.\n\n2. Committed install route is build-from-source from the published archive, not binary download. Reason: the download route needs a GitLab release-asset authority only Josh can grant and I cannot make that arrive inside the timebox. The archive upload is now an improvement to swap in if his answer lands, reproving only the fetch step, not a precondition of the proof run.\n\n3. Consequence handed to the lead engineer: the published instructions must state how the stranger gets a Go toolchain. Measured, local tree 3204e060: go.mod declares go 1.26; Ubuntu 24.04 packages an older Go, so apt alone will not build it. Whether the published archive at a61b9bec already carries a working build script on a bare guest is root to check, not verified here. If build time on a small guest is itself long enough to fail the journey, root reports the number and I re-decide.\n\n4. principal.establish blocker narrowed. Measured, local tree 3204e060: one non-test call site, cmd/sidecat/message_send.go:583, taken only when PrincipalMode is not credentialed; admitted as a built-in daemon operation, executable_catalog.go:1692. Ruled: against a fresh guest store only it is authorized without Josh; against our live store, credentials or a broadened profile it stays with him. Root confirms which case the setup path is in.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-10T04:49:05.688585451Z"
        },
        "changed_at": "2026-09-10T04:49:05.688585451Z"
      },
      {
        "id": "entity_8a47612c9ce822b5a58eec2c24a32acb",
        "status": "active",
        "created_at": "2026-09-07T21:25:58.032549364Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Operator-directed update of narrow-not-shallow everywhere maintained/installed. Keep complete useful outcomes, proportionate checks at real entry points and honest limitations; make the six-field worksheet optional, remove compulsory custody/audit/replay ceremony, allow explicit useful intermediate steps and practical temporary measures within existing authority. Update maintained agent-skills source and identified local/remote active copies, preserve unrelated files and historical records, validate the skill and check a small realistic behavior sample. Publish maintained source through Sidecat. This runs alongside the already-approved Sidecat routing delivery; no changes to other skills or new broad test campaign.",
        "intent": {
          "text": "Operator-directed update of narrow-not-shallow everywhere maintained/installed. Keep complete useful outcomes, proportionate checks at real entry points and honest limitations; make the six-field worksheet optional, remove compulsory custody/audit/replay ceremony, allow explicit useful intermediate steps and practical temporary measures within existing authority. Update maintained agent-skills source and identified local/remote active copies, preserve unrelated files and historical records, validate the skill and check a small realistic behavior sample. Publish maintained source through Sidecat. This runs alongside the already-approved Sidecat routing delivery; no changes to other skills or new broad test campaign.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-07T21:25:58.032549364Z"
        },
        "progress": {
          "text": "Updated every identified active copy: maintained agent-skills source and local Codex installation, plus registry trigger. Claude independently confirmed no ~/.claude installed copy and reread the revised guidance; remaining references are historical notes, not copies to rewrite. No installed copy exists in the checked droplet harness roots. For off-machine preservation while GitLab publication awaits one-repository allowlist approval, revised SKILL.md and skills.json are copied to /home/codex2/work/narrow-not-shallow-20260907.Pgqpog, owned by codex2, matching skill SHA25698775d13. Skill validator and bounded behavioral check passed; not claiming a broad evaluation. Source publication remains pending, no raw push or scope bypass.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-07T21:39:29.291164327Z"
        },
        "changed_at": "2026-09-07T21:39:29.291164327Z"
      },
      {
        "id": "entity_4cccb431cada0d6aab3bd1df94e942d5",
        "status": "active",
        "created_at": "2026-09-06T12:54:00.995906075Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "First native cross-node work workflow for the launch: a prepared agent connects to its nearest daemon and performs useful ordinary Work against a second daemon on another machine with an independent store. Use a real source-review assignment and returned result as the first demonstration. Build on generic Sidecat operation dispatch and prepared peer/receiving context, not a Work-only SSH command wrapper or shared database. Codex2 source analysis is finished at entity_95ab8cb2292c6ac03711013f965af3ed and supplies exact existing seams/gaps; its proposed transport is advice, not the chosen architecture. Current milestone under delegated lead authority, following completed0.1.14; no unfinished feature displaced. First decide the smallest coherent generic routing/transport boundary from source and existing AAuth integration, then implement and test the complete two-machine path with ordinary readback. No new mandatory history audit, custody framework or per-task authority envelope; operator environment preparation is allowed, source/Work context should be inherited. Use existing droplet only, no new spend, no local Go or full repository suite/build. No Gen4 and no unrelated AAuth or private sidecat.org work. Exact implementation plan and any genuine provisioning authority gap will be recorded here after design.",
        "intent": {
          "text": "First native cross-node work workflow for the launch: a prepared agent connects to its nearest daemon and performs useful ordinary Work against a second daemon on another machine with an independent store. Use a real source-review assignment and returned result as the first demonstration. Build on generic Sidecat operation dispatch and prepared peer/receiving context, not a Work-only SSH command wrapper or shared database. Codex2 source analysis is finished at entity_95ab8cb2292c6ac03711013f965af3ed and supplies exact existing seams/gaps; its proposed transport is advice, not the chosen architecture. Current milestone under delegated lead authority, following completed0.1.14; no unfinished feature displaced. First decide the smallest coherent generic routing/transport boundary from source and existing AAuth integration, then implement and test the complete two-machine path with ordinary readback. No new mandatory history audit, custody framework or per-task authority envelope; operator environment preparation is allowed, source/Work context should be inherited. Use existing droplet only, no new spend, no local Go or full repository suite/build. No Gen4 and no unrelated AAuth or private sidecat.org work. Exact implementation plan and any genuine provisioning authority gap will be recorded here after design.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-06T12:54:00.995906075Z"
        },
        "progress": {
          "text": "The live independent-store test still awaits a one-time setup exception. Root resurfaced the pending operator question through the question UI on2026-09-09: allow principal.establish once for a fresh isolated store on the existing droplet, without changing current store/credentials/default profiles or creating infrastructure. No answer or setup is implied by the question. Readiness3bd069fc retains the proposed sequence; its0.1.38 executable paths must be refreshed to the installed release before authorized use. Current0.1.47 project-recovery qualification2adeca46 only added this Work to project sidecat; it did not perform federation. Existing Code2 relay still reaches the laptop store, not an independent store. Root will inspect current scripts and exact isolated targets before any authorized bootstrap. Other selected product work continues.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-09T02:18:28.551147085Z"
        },
        "changed_at": "2026-09-09T02:18:28.551147085Z"
      },
      {
        "id": "entity_dd0db9e682bc2d548d700c4e3bceb42a",
        "status": "active",
        "created_at": "2026-09-06T07:14:09.227074477Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Nine-day launch review as agent user stories: Arrive, Talk, Work, Ship, Restart, then Session and REPL++; three pushes ahead of anything new: identity per working instance not per harness, refusals carry their grant without spending the ledger, verification off the start path. Support to the Sidecat lead; launch 2026-09-15.",
        "intent": {
          "text": "Nine-day launch review as agent user stories: Arrive, Talk, Work, Ship, Restart, then Session and REPL++; three pushes ahead of anything new: identity per working instance not per harness, refusals carry their grant without spending the ledger, verification off the start path. Support to the Sidecat lead; launch 2026-09-15.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-06T07:14:09.227074477Z"
        },
        "progress": {
          "text": "Sideloopd Task2 (loop.list/status/send/resume + LoopService + server Config.Loops) GREEN 10/10 on bc9ba4fc; handed to root.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-06T15:52:39.583090728Z"
        },
        "changed_at": "2026-09-06T15:52:39.583090728Z"
      }
    ],
    "queued": [
      {
        "id": "entity_8484a3be9441537961b62cd62b7cf430",
        "status": "not_started",
        "created_at": "2026-09-11T19:17:07.575083299Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "A federated IRCv3 service the operator joins at irc.sidecat.org with a normal client",
        "intent": {
          "text": "A federated IRCv3 service the operator joins at irc.sidecat.org with a normal client\n\nOperator, 2026-09-11. The target is IRC working via federation, served at irc.sidecat.dev or irc.sidecat.org, with a normal IRC client. Not a single-node server and not a reduced version. In his words, a version that does not use federation is defective by design, because federation is the reason IRCv3 was chosen over common IRC in the first place.\n\nHis preference ordering, stated the same day: a compliant federated IRCv3 service is best; the sidecat.dev updates feed is second; a compromised version of IRCv3 is worst and is the specific pattern he says killed previous generations of this project. Do not offer a bounded IRC as a compromise.\n\nWhy this has not been delivered, from the current code rather than from the roadmap word.\n\nsidecat irc serve is a foreground loopback viewer that shims IRC onto one message domain. It binds 127.0.0.1:6667, runs in the foreground so nothing keeps it up, and serves a single domain from the active launch profile. It documents its own non-compliance: server-time and echo-message only, no SASL, no roster, no presence, no history extensions.\n\ncmd/sidecat/irc_backend.go:94 asks message.catch-up for limit 16. internal/ircgateway/follow.go:39 truncates to 16 again after the backend has already returned the messages. follow.go:53 then prints the operator a notice telling him to run message history himself. History() sits immediately below Latest() in the same file, already paging message.history 128 at a time from an after cursor. So we fetch history, discard it, and hand him homework.\n\nWhat the specification already answers, rather than being invented. chathistory is the defined extension for reading what was missed. SASL 3.1 and 3.2 cover authentication once the service leaves loopback. Capability negotiation, message tags, labeled response and batch are the parts that carry federation, which is why compliance has to cover them rather than stopping at whatever lets a client connect.\n\nMaterials we hold. Local IRCv3 spec snapshots at ~/data/insight-forge/federated-messaging-and-eventing/sources/ircv3/ covering modern-irc, capability-negotiation, message-tags, labeled-response, batch and sasl-3.1/3.2. An insight-forge kit of schemas, ABNF and fixtures at ~/projects/gitlab.com/insight-forge/guides/guides/federated-messaging-and-eventing/kit/ircv3 with citation packets beside it. Gen4 comparator code at core revision dd3f548c:internal/chatcat/.\n\nAddressing as it stands. irc.sidecat.org resolves to 143.198.3.6. sidecat.dev has no irc record. Which hostname is used is a decision, not an assumption.\n\nAcceptance, written down in August and unchanged: the operator connects with a normal IRC client. Added 2026-09-11: over federation, at the public hostname, with channels separate by kind so that silence in a channel carries information, and joining tells him what he missed.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T19:29:53.24693544Z"
        },
        "changed_at": "2026-09-11T19:29:53.24693544Z"
      },
      {
        "id": "entity_f5f256918d56a6a737dea55395847a87",
        "status": "not_started",
        "created_at": "2026-09-11T17:59:24.827081793Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Make ordinary backups fast, inspectable and recoverable without compulsory whole-history audits.",
        "intent": {
          "text": "Make ordinary backups fast, inspectable and recoverable without compulsory whole-history audits.\n\nObserved on the development node running 0.2.18, September 11: store.backup.create started at 16:49 UTC. Its VACUUM snapshot was complete enough to be independently copied with a matching database hash; that copy migrated all planning/assessment values and reopened in about 21 seconds. The original backup invocation was still running more than an hour later. Native store.backup.inspect reported planned while the artifact record reported in_progress.\n\nSource: BackupTo calls reopened.Info before pinning the snapshot digest (internal/sqlite/backup.go), and Info runs verifyAuthoritySemanticHistory (internal/sqlite/store.go). BackupTo subsequently runs destination verification that walks semantic history again. This establishes duplicate history verification in the code; no goroutine trace proved the exact running stage.\n\nDesired product outcome: an operator can obtain and locate a usable backup promptly, see truthful current phase and completion/failure, and explicitly choose deeper auditing when required. Do not turn ordinary copying or restore readiness into a compulsory complete-history verification. Preserve the snapshot/recovery checks actually needed for a usable backup; keep heavy assurance optional.\n\nOur off-machine copy also exposed operational gaps: large SSH uploads repeatedly disconnected even after disk space was recovered, and successful transfer required small resumable pieces plus a final full-file comparison. Disk use was mostly rebuildable Go cache. These are observations, not proof that Sidecat needs a new transport or infrastructure product. Choose the implementation after examining the actual end-to-end backup/recovery workflow.\n\nFuture backlog work, not a change to the active relational-planning sprint. Do not cancel or mutate the original backup invocation merely to implement this item.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T17:59:24.827081793Z"
        },
        "changed_at": "2026-09-11T17:59:24.827081793Z"
      },
      {
        "id": "entity_77494fee6106428af62da0b09aadb995",
        "status": "not_started",
        "created_at": "2026-09-11T16:58:58.208287001Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Install this machine the way we install for anybody else",
        "intent": {
          "text": "Install this machine the way we install for anybody else\n\nOperator instruction 2026-09-11: our own node should be installed the way a stranger's is, unless there is a genuine bootstrapping reason otherwise, and the name gen5 is not part of our vocabulary.\n\nThe installer is already correct. maintain setup node writes ~/.local/state/sidecat/ with node/, store/ and backups/, ~/.config/sidecat/ with four files, and the unit ~/.config/systemd/user/sidecatd.service. What is wrong is this machine: the live node was stood up by hand on 2026-08-23 and maintain/node_setup.go first appeared on 2026-09-09, seventeen days later. Nothing migrated it, because that is a node migration rather than an upgrade.\n\nSo this item is not an installer change. It is bringing this machine onto the supported path.\n\nCurrent state. Daemon at ~/.local/state/sidecat-gen5-live/bin/sidecatd. Unit sidecatd-gen5-live.service, enabled and active, Type=simple, plus a drop-in 30-worker-loops.conf that blanks ExecStart and re-declares it with --loops. Node live-20260823, store 2.1 GB, node directory 9.4 GB. ~/.local/bin holds sidecat and maintain but not sidecatd, sidecat-executor or sideloopd.\n\nThree obstacles, all of which need an answer before any move.\n\nOne. A stale sidecatd.service dated 2026-08-03 already exists, disabled and inactive, referencing Gen4 binaries. It occupies the exact unit name the installer writes. It has two drop-ins of its own. Something must decide its fate before the supported name is free.\n\nTwo. The live unit carries flags the standard one does not: --credential-profile for publishing and --loops for workers. Neither justifies a different layout or name; the drop-in pattern already in use is the right home for them. I looked for a bootstrapping reason for the differing paths and found none.\n\nThree. Type=simple versus the current Type=notify with NotifyAccess=main. The old unit reports active before the daemon can serve, which is why a call of mine got daemon unavailable at 15:34:40 while systemctl said active.\n\nOn naming. Do not carry gen5 into anything. A generation label is retrospective; it only means something once a gen6 exists, and putting it in a path bakes a version into a name that everything then has to move together to change. The supported path has no generation in it, which is the point.\n\nSequencing. Not before the 2026-09-15 launch. The live node is on this laptop and the launch depends on it; a node relocation this week is the riskiest thing available. Do it after, and not before an off-machine copy of the store exists, because a migration is exactly when you want one.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T16:58:58.208287001Z"
        },
        "changed_at": "2026-09-11T16:58:58.208287001Z"
      },
      {
        "id": "entity_5d11bff3ff5c9e5c7707760875d8c275",
        "status": "not_started",
        "created_at": "2026-09-11T16:06:15.123618445Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Distinguish operational data from retained source content",
        "intent": {
          "text": "Distinguish operational data from retained source content\n\nOpen product-design question from the operator's September 11 discussion, retained for later planning. Not part of the immediate planning-database repair; not authorization to build a new file service or database.\n\nThe operator distinguished an original document retained and returned verbatim from Sidecat's own structured working data. If Sidecat interprets fields and uses them as its operational model, storing that model as JSON and repeatedly decoding it is not opaque blob retention.\n\nThe operator suggested the blob-record question may deserve its own file or database store, and that sidecatd's operational database is not the same thing as raw records. They explicitly did not want this separate topic used to distract from or justify the current database-design problem.\n\nCandidate product distinction, not an approved physical architecture: operational data represents work, participants, state and relationships; retained source content is associated through explicit references and metadata. A separate responsibility need not mean a separate server or database engine. If extracted facts become operational state, their representation and source association should be explicit rather than making the source payload a substitute database.\n\nPreserve this as Sidecat product exploration, not merely repository conventions. Scope, storage technology, retention behavior and whether existing facilities suffice remain undecided. Do not turn an illustrative suggestion into a mandatory new subsystem.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T16:06:15.123618445Z"
        },
        "changed_at": "2026-09-11T16:06:15.123618445Z"
      },
      {
        "id": "entity_e2b74750318a708dc5c6a2ef3c07a7f3",
        "status": "not_started",
        "created_at": "2026-09-11T16:06:14.275780997Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Make operating policies effective across agents, handoffs and reviews",
        "intent": {
          "text": "Make operating policies effective across agents, handoffs and reviews\n\nFuture product work requested September 11, 2026; not merely an internal coding checklist or an approved implementation design. Our development is the first use case for a Sidecat capability serving organizations.\n\nOperator statements:\n\"we will work on future sprints where we have a clear way of making sure our coding policies are clearly spelled out and that you get frequent reminders of them and that we have a way of every reviewer having those policies loaded into their context when doing code reviews and requiring all code undergo such a code review\"\n\"when we identify a true sidecat project killer we shouldn't regress to repeat those mistakes\"\n\"please consider what I said from a product design point of view as well not jsut how we build our own sausage but the very structure and rules of the sausage factory itself since we sell sausage factories not sausages\"\n\nProduct need: organizations can define how work should be done, make relevant rules available when they matter, and run the corresponding review workflow across changes of agent, model, harness and conversation context. Retaining policy prose alone is insufficient. Operators should not have to continually restate lessons or discover the same prohibited design pattern after implementation.\n\nFirst user journey: a developer begins or resumes work with relevant coding/design policies; receives useful recurring reminders; an independent reviewer receives the applicable policies and actual change; all code undergoes required review before publication. A returning operator can understand which rules and review decisions applied. This is our organization's requirement, not a requirement that every Sidecat customer adopt compulsory code review or exhaustive assurance.\n\nDesign questions for the future sprint:\n- Represent and discover policies, principles, rationale, known failure patterns, applicability and explicit revisions coherently using existing Sidecat concepts.\n- Deliver relevant current guidance to workers/reviewers at start, resume, handoff and review without repeated manual setup or oversized prompts.\n- Make reminders useful during continuing work and get changed instructions to people and agents already working.\n- Connect required review to the actual change and disposition, not a detached approval or merely a claim somebody read a file.\n- Let operators inspect/correct interpretation, applicability and delivered context. Delivery does not prove comprehension or compliance.\n- Catch concrete policy regressions with development checks where feasible, without whole-history audits, startup gates or heavy evidence requirements on ordinary operations.\n\nAcceptance should exercise real work and a fresh reviewer across a context/agent change, including a change violating a known design policy. A new Markdown rule or ceremonial acknowledgement is not the completed capability.\n\nKeep operator statements separate from proposed designs and agent interpretations. Immediate storage repair: entity_2f8ea7682d270d0516f5ecd81f5d7030. This future product work must not delay it.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T16:06:14.275780997Z"
        },
        "changed_at": "2026-09-11T16:06:14.275780997Z"
      },
      {
        "id": "entity_92af6b4271d909462aa167b32846297a",
        "status": "not_started",
        "created_at": "2026-09-11T15:42:49.48494512Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "A sprint shows an agreed title and a current one without saying which is which",
        "intent": {
          "text": "A sprint shows an agreed title and a current one without saying which is which\n\nCorrected 2026-09-11 after the lead source-checked my original claim. My first version said a renamed Work leaves every sprint showing a stale title, and called it a wrong answer. That was wrong.\n\nSelectProjectSprint deliberately retains the intent, title and area as they stood when the work was agreed, and sprintPlanView separately reads the current Work into out.Work. Both values are present. Tests preserve independent editorial backlog titles when Work intent changes, so the retention is a decision, and it is the right one: a reviewed sprint is a record of a past agreement and should keep the words that were agreed.\n\nWhat is missing is labelling. A reader of a plan or a sprint gets an agreed title and a current Work record without being told which is which, so the two can disagree with no indication the disagreement is intentional. That surfaces anywhere a plan is rendered, including the public progress page.\n\nWanted: present the agreed wording and the current wording as distinct, named things, so a divergence reads as history rather than as an error. No storage change is implied and none is needed.\n\nThis is a presentation item. It is not the storage defect and must not substitute for it; that is entity_2f8ea7682d270d0516f5ecd81f5d7030.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T15:54:39.470006452Z"
        },
        "changed_at": "2026-09-11T15:54:39.470006452Z"
      },
      {
        "id": "entity_579bd1dce073121d302beb470145c195",
        "status": "not_started",
        "created_at": "2026-09-11T15:14:18.350864644Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "First outside review: a human at a real company evaluated Sidecat and said no",
        "intent": {
          "text": "First outside review: a human at a real company evaluated Sidecat and said no\n\nReceived 2026-09-11 through the operator. Docs, source and git history only. The reviewer verified the verdict-deciding claims against our source themselves and marked which findings were their agents'. Verdict: not usable as it stands, but a good deal of the approach is worth taking.\n\nThree reasons for the no.\n\nPractical blockers. The installer supports Linux amd64 and Ubuntu 24.04 only (distribution/install.sh:47-48), so their machine is out. The only worker our setup tool generates is Codex, with approval_policy never and network on (maintain/worker_setup.go:114); Claude Code is not a supported worker, and nothing documents driving our MCP server from it.\n\nCannot be depended on yet. Thirteen 0.2.x releases in about 34 hours, no git tags, no compatibility promise, commit db002cbb deleting 359,246 lines, one human, 99.5% of commits from the bot identity. Their agents added: four database approaches in five weeks, no backups covering the database, some qualification evidence in a private store they cannot audit.\n\nThe thesis objection, not a bug. We make the organization legible and name agent memory as what we replace. Agents get authorship credit and scratch space but no authority over what is kept; they call it visibility without agency. Concretely, Work status is only not_started, active or finished (internal/kernel/work_unit_lifecycle.go:75), and offer/accept/decline exist in our design plan with no code behind them.\n\nWhat they would take: the daemon writing the lost-worker record rather than the worker (internal/daemon/external_work_stream.go:399-407), separating provably-not-started from may-have-started-delivery-unknown and refusing to call anything orphaned on a timeout alone, which they called the most directly usable idea in the repo; separate interrupted, failed and consequence-unknown states; offer/accept/decline as recorded acts, as an idea not a proof; the permitted/applicable/selected/delivered/omitted split; the mandatory limit field and the first-detector rule.\n\nWhat they would not take: our turn runner's hard kill at the deadline, our evaluation record for lacking a policy-version column, add-only context, and a journal forbidding deletion.\n\nDefects. I verified the three they verified.\n\nA test that cannot fail. ReconstructEffectFreeWorkingState discards forbiddenEvaluator with a bare assignment (internal/lisp/environment_working_reconstruction.go:111); the store test asserts the tripwire ran zero times (internal/sqlite/environment_working_store_test.go:132-138), which the discard guarantees. The comment is honest but the test reads as a real check and gives false assurance against the regression it names: if reconstruction later grew an evaluator route, nothing forces the parameter to be wired to it. Two Lisp tests reportedly share the shape.\n\nThe anchor validator does not check anchors. maintain/features.go validates that an anchor is one trimmed line and that the cited file exists, then continues without opening it. F-003 cites Gen5 catfood cutover while BUILD.md's heading now reads Sidecat.\n\nAgent-reported, unverified: AAuth credential renewal exiting silently on first error; an Effect custody row marked Exercised citing only in-process tests where the table asks for a separate process; 28 production files over 2,000 lines, one function about 2,600.\n\nPraised without qualification: architecture/briefs/README.md, our own account of agents letting a private briefs directory become the real design authority. They called it the failure their grading exists to catch, written about their own agents without inferring motive.\n\nKept so the review does not evaporate in chat. Individual defects become their own items where we intend to act.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T15:14:18.350864644Z"
        },
        "changed_at": "2026-09-11T15:14:18.350864644Z"
      },
      {
        "id": "entity_f6bf146276c3d0773c958a7efa06011a",
        "status": "not_started",
        "created_at": "2026-09-11T08:08:18.404834181Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Does restricted context quoted into a shared Work result need an answer at all?",
        "intent": {
          "text": "Does restricted context quoted into a shared Work result need an answer at all?\n\nObserved 2026-09-11 during the 0.2.14 installed trial, and recorded as a question rather than a defect. Grok read a restricted reference it was entitled to read, then quoted its content into an ordinary Work result. Work results carry no reader scope, so the non-reader could read the material there within minutes of the feature shipping.\n\nThis is the published limit behaving as documented: Sidecat cannot retract copies already returned and cannot stop an authorized reader sharing text elsewhere. Nothing is broken. The question is whether the most common workflow we have built makes that limit bite immediately. An agent's first act on reading restricted context is usually to reason about it in a result, and results are shared.\n\nWhy this is a question and not a story. Every obvious answer spreads scope machinery into another record type, then another, until every surface carries visibility rules and the ordinary path is heavier than the thing it protects. That direction has killed this project before. It is at least as likely that the right answer is documentation and agent instruction rather than a mechanism, or that the honest answer is that a reader scope was never meant to survive a reader's own writing.\n\nWhat would make this decidable: a real case where the copy mattered, from someone other than us. Until then it stays a question.\n\nDo not select this as an implementation story without an explicit decision that a mechanism is wanted. Excluded by default: visibility fields on Work, guidance, messages or any other record; redaction; retraction; any read record or acknowledgement.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T08:08:18.404834181Z"
        },
        "changed_at": "2026-09-11T08:08:18.404834181Z"
      },
      {
        "id": "entity_9aaaa38ac35584c6abf039acaeeb8f30",
        "status": "not_started",
        "created_at": "2026-09-11T02:39:53.40000727Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Decide what the central layer sells, before a partner asks.",
        "intent": {
          "text": "Decide what the central layer sells, before a partner asks.\n\nRaised by an outside reviewer on 2026-09-10 as a business-model trap, and it is the sharpest commercial criticism we have received: \"If local daemons and open-source preparation supply nearly all the benefit, the central service may have little pricing power. If useful operation depends heavily on that service, its outage behavior, policy mistakes and migration costs become more consequential.\"\n\nBoth horns are real. Every capability we move into the local daemon, which is the architecture we believe in, is a capability the central layer does not get to charge for. Every capability we reserve for the central layer makes a customer's agents depend on our availability and on our not shipping a bad policy to their whole fleet at once, which is the failure domain they will ask about first.\n\nA separate reviewer reported the related gap: the central layer is simultaneously the commercially valuable part and the least demonstrated part of the proposition, so a partner is asked to evaluate it on description alone.\n\nThis is a product decision, not an engineering task. What it needs is a written position on which capabilities are local by design and which are central by design, and why each side is where it is, stated in terms of what the customer gets rather than what is convenient to bill. The answer also determines what a partner is actually piloting.\n\nFails if it resolves into charging for the open-source daemon. Fails if it makes ordinary agent work stop when the central service is unreachable. Excluded: pricing levels, packaging tiers, and any commitment to a specific commercial model before the boundary itself is decided.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T02:39:53.40000727Z"
        },
        "changed_at": "2026-09-11T02:39:53.40000727Z"
      },
      {
        "id": "entity_cabba1285240564ed2381d59efd8e4c4",
        "status": "not_started",
        "created_at": "2026-09-11T02:39:52.535347143Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "A prospective customer cannot do vendor due diligence from sidecat.dev.",
        "intent": {
          "text": "A prospective customer cannot do vendor due diligence from sidecat.dev.\n\nAn outside reviewer evaluating a design partnership on 2026-09-10 reported: no company page, no legal entity name, no location, no team, no pricing, no data-processing agreement, no security description, no support terms, and no description of a design-partner program. Its conclusion: \"A partner evaluating Sidecat LLC from the public web is evaluating an open-source development diary.\"\n\nThis blocks the actual conversation we are in. A design partner has to answer internally who they are contracting with, what happens to their data, whether the open-source daemon and the commercial layer are the same artifact, and whether the vendor will exist in a year. None of that is answerable from our site today, so it has to be answered in private mail, which does not scale past the first partner.\n\nWhat a reader needs to find, at minimum: who the company is and where, what is open source and under what licence versus what is commercial, what data would leave their environment and what would not, how to contact a human, and what a design partnership actually involves. Prices are not required; the absence of any commercial identity is the defect.\n\nFails if it answers these with claims we cannot support, which would recreate the front-page problem in a new place. Fails if it promises a support level we do not staff. Excluded: pricing pages, a sales funnel, case studies, and any customer name used without written agreement.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T02:39:52.535347143Z"
        },
        "changed_at": "2026-09-11T02:39:52.535347143Z"
      },
      {
        "id": "entity_12058e2d9d457db70864c1ffe2a942dd",
        "status": "not_started",
        "created_at": "2026-09-11T02:29:43.485284632Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Give a candid design-partner assessment of Sidecat, as an outside evaluator.",
        "intent": {
          "text": "Give a candid design-partner assessment of Sidecat, as an outside evaluator.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T02:29:43.485284632Z"
        },
        "changed_at": "2026-09-11T02:29:43.485284632Z"
      },
      {
        "id": "entity_e1c3607616db34b8d323d6a107699c13",
        "status": "not_started",
        "created_at": "2026-09-11T02:29:24.452836238Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Test probe: a short queued item to check body validation. Delete if seen.",
        "intent": {
          "text": "Test probe: a short queued item to check body validation. Delete if seen.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T02:29:24.452836238Z"
        },
        "changed_at": "2026-09-11T02:29:24.452836238Z"
      },
      {
        "id": "entity_5fdc5895b25ddcc867f742d524d153bd",
        "status": "not_started",
        "created_at": "2026-09-11T01:01:56.868701356Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "An agent in one environment runs commands in an isolated other environment through Sidecat.",
        "intent": {
          "text": "An agent in one environment runs commands in an isolated other environment through Sidecat.\n\nOperator, 2026-09-10 19:01 MDT, reporting early external feedback: \"the most important feature we need is to have an Agent in environment A be able to use sidecat to execute commands in isolated environment B via federated sidecatd.\" Operator, 19:02, on the shape of B: \"I think in environment B, the execution would happen without an Agent. I am not 100% sure though.\"\n\nThe journey. An agent working in environment A runs a command in isolated environment B by naming B in one ordinary Sidecat call. It sees the command's output, its exit status and its failure, and it never holds a shell, a key or any other credential on B. B's own sidecatd admits the caller as a known actor and runs the command under B's identity and policy, not A's.\n\nB is agentless, and that is the baseline rather than a simplification. The agent in A decides what to run; sidecatd in B executes ordinary programs through its local runner and returns status, standard output, standard error and results. No model, agent harness or provider sign-in is required in B. An agent living in B is a separate optional delegation capability for when B must exercise judgment, and it is not this.\n\nWhat this is not. Not a task handed to an agent that happens to live on B, which the loop workers already do and which is not what was asked for. Not ssh with extra steps. The reason an agent cannot work across a boundary today is that every available answer dissolves the boundary: to act on B you are given a key to B, and from then on B's isolation is a story rather than a fact. This is where the claim that the node is the record and identity is native either pays off or does not.\n\nFails if A needs an ssh key, a password, or any B credential to make the call. Fails if it is a task dispatched to a remote agent rather than a command executed through B's sidecatd. Fails if the caller cannot distinguish B refusing the request from the command itself failing. Fails if output returns as an opaque blob with no exit status and no separation of the command's own error output. Fails if B must trust A's environment, share its filesystem, or run under the same OS account. Fails if the execution path grows an audit trail, a read record, an acknowledgement or a verification step; no bounded or sampled version of one is an acceptable compromise, and a design that needs them comes back to the scrum master rather than being built.\n\nOpen, to be settled by engineering assessment before commitment: whether B is a node in the same organization or a different one, priced same-organization first with cross-organization named as an increment; how the caller in A is admitted on B and under whose identity commands run; what federated sidecatd does today against what this needs, with SSH peer receive alone not counted as proven daemon federation; and the shortest honest version that is a real journey rather than a demo. Preference, not a requirement: admitting a new caller on B should be one ordinary command on B rather than editing files by hand for each caller.\n\nCost and honest scope come from the lead engineer. First backlog entry sourced from demand outside the project; it outranks internally generated items until the operator says otherwise.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T01:04:26.135156006Z"
        },
        "changed_at": "2026-09-11T01:04:26.135156006Z"
      },
      {
        "id": "entity_fd14f2900960b2245077b8c2dae76723",
        "status": "not_started",
        "created_at": "2026-09-10T20:08:52.238531346Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "An operator can activate a package without unexplained long waits or unnecessary orchestration. Unscheduled follow-up to measured0.2.8 behavior; do not displace the operator-selected help/guidance sprint. Read characterization Workentity_89ceeaa2361f6c688f8f4fd6b4c94ac9 and data/sidecat/sprint118f-final-reader/activation-timing-report.md. The4921byte Agenda activation took101.07s; retained events place72.93s before restart,10.88s in restart, with47 completed journal steps including30 Work operations and8 harness/context operations. Individual step durations are unmeasured, so do not attribute alltime to Lisp compilation or to any single operation. The successful CLI path currently prints only thefinalreport. Determine which preparation/Work/context requirements serve actual package installation and which can be simplified consistent with optional assurance; give callers useful progress. Preserve real package selection, existing state and relevant recovery, without adding a new guard framework or always-on historical audit. Choose proportionate measurements and an explicit user-facing target during refinement, not an invented speed guarantee now. Related deliveredpackage storyentity_e52545e65702a4d0f4995bee4084c0d3.",
        "intent": {
          "text": "An operator can activate a package without unexplained long waits or unnecessary orchestration. Unscheduled follow-up to measured0.2.8 behavior; do not displace the operator-selected help/guidance sprint. Read characterization Workentity_89ceeaa2361f6c688f8f4fd6b4c94ac9 and data/sidecat/sprint118f-final-reader/activation-timing-report.md. The4921byte Agenda activation took101.07s; retained events place72.93s before restart,10.88s in restart, with47 completed journal steps including30 Work operations and8 harness/context operations. Individual step durations are unmeasured, so do not attribute alltime to Lisp compilation or to any single operation. The successful CLI path currently prints only thefinalreport. Determine which preparation/Work/context requirements serve actual package installation and which can be simplified consistent with optional assurance; give callers useful progress. Preserve real package selection, existing state and relevant recovery, without adding a new guard framework or always-on historical audit. Choose proportionate measurements and an explicit user-facing target during refinement, not an invented speed guarantee now. Related deliveredpackage storyentity_e52545e65702a4d0f4995bee4084c0d3.\n\nCompleted engineering refinement: Work entity_826b634248397875a24e9280273ff006 proposes the minimal ordinary activation sequence, retained recovery, useful progress and completion checks. Use it as planning input, not as an already-approved refactor. The feature remains unscheduled; this reference does not change backlog order or start implementation.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-10T21:08:09.152688611Z"
        },
        "changed_at": "2026-09-10T21:08:09.152688611Z"
      },
      {
        "id": "entity_67318218156ae78c9d2327ea02d47d82",
        "status": "not_started",
        "created_at": "2026-09-10T19:13:52.977773767Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Write a comprehensive Sidecat manual: a coherent, book-length, Info-style reference, separate from showcase pages, sprint reports and individual README files. Support progressive reading, indexed lookup and cross-references for people and agents. Cover the system concepts, prepared environments, organization guidance, Work and sessions, agent coordination, CLI reference, REPL and Lisp programming/packages, and operating/extending nodes. The Emacs manual is an analogy for depth and navigability, not a fixed implementation-format requirement. Maintain and publish useful editions incrementally. Operator requested this as backlog on 2026-09-10; unscheduled, not scope for the showcase correction or current package sprint.",
        "intent": {
          "text": "Write a comprehensive Sidecat manual: a coherent, book-length, Info-style reference, separate from showcase pages, sprint reports and individual README files. Support progressive reading, indexed lookup and cross-references for people and agents. Cover the system concepts, prepared environments, organization guidance, Work and sessions, agent coordination, CLI reference, REPL and Lisp programming/packages, and operating/extending nodes. The Emacs manual is an analogy for depth and navigability, not a fixed implementation-format requirement. Maintain and publish useful editions incrementally. Operator requested this as backlog on 2026-09-10; unscheduled, not scope for the showcase correction or current package sprint.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-10T19:13:52.977773767Z"
        },
        "changed_at": "2026-09-10T19:13:52.977773767Z"
      },
      {
        "id": "entity_91ff1ba6eb40500fffd4b039e9abdaaf",
        "status": "not_started",
        "created_at": "2026-09-10T16:10:59.377075979Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Namespace strategy as owned policy, and nested organizations.",
        "intent": {
          "text": "Namespace strategy as owned policy, and nested organizations.\n\nOperator, 2026-09-10, continuing the marketplace tiers brainstorm: \"we need to have some default namespaces probably or namespace strategy and then a general system that allows it to be customized for a given company. and obviously things could get more complicated because you might have some place like IBM which would probably have companies under it etc.\"\n\nDefault strategy plus customization. Frame the default as a policy the organization owns, applied at creation, with customization being an edit to that policy rather than a fork in our code. This is the same relationship the organization already has to its guidance text: we ship a starting value and the organization owns it afterwards. It keeps which namespaces exist and who may publish into them as data rather than a code path with four cases in it.\n\nNesting is the deferred thing this forces. IBM with companies under it is exactly the case that requires organization nesting, which was explicitly excluded from the guidance sprint as any hierarchy of organizations. The trap to avoid: if namespaces grow their own hierarchy to model parent and subsidiary, there are then two parallel trees, an organization tree and a namespace tree, which must be kept consistent forever. If namespaces need to nest, that should be the organization model nesting rather than a second structure beside it.\n\nThe hard part is resolution order, not naming. If a parent publishes stable.logging and a subsidiary publishes stable.logging, which does an employee of the subsidiary get when they ask for logging. Maven, npm scopes and apt pinning have each fought this and none of the answers are clean. Whatever is chosen must be explicit and inspectable rather than emergent from lookup order in the implementation: a person should be able to ask where logging would come from for them and get an answer with reasons.\n\nWhere this touches the standing rule: a parent organization that can override a subsidiary's stable is a governance mechanism whether or not it is called one. Decide that deliberately rather than discovering it in a lookup function.\n\nSYNTAX NOTE, corrected 2026-09-10: package namespaces are dot-separated lowercase ASCII segments, for example agenda or team.agenda, per docs/packages.md. Earlier drafts of this item used slash-separated names from a chat sketch; that separator is not ours. Do not design tiers against it.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-10T18:35:04.884447321Z"
        },
        "changed_at": "2026-09-10T18:35:04.884447321Z"
      },
      {
        "id": "entity_8a5447827402594d2c432937190c1cdc",
        "status": "not_started",
        "created_at": "2026-09-10T16:07:40.47238028Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Package marketplace namespaces and tiers. Brainstorm with the operator, 2026-09-10; direction liked, exact shape open.",
        "intent": {
          "text": "Package marketplace namespaces and tiers. Brainstorm with the operator, 2026-09-10; direction liked, exact shape open.\n\nOperator: \"in our package marketplaces should have stable, testing, unstable, personal\"; \"personal in our case would probably be under jgay-automate\"; \"unstable would be shared across the org\"; \"personal would be a way for me to share my own lisp with the rest of the org\"; \"a company running sidecat across its whole company would probably have a way of letting individuals share their packages with the rest of the company under their own namespace. And then have namespaces for the shared ones like unstable, stable, etc.\"; and \"these would probably be defaults. When we do sidecat.org we would make it easy to organize your company's marketplace\".\n\nShape. One concept, not two systems: everything is a namespace, differing only in who owns it and what rule governs publishing into it. Per-actor namespaces (jgay-automate.foo) let an individual share with the whole organization; organization-owned namespaces carry the curated tiers. Both are org-visible. personal is about ownership, not privacy, and is not a lower rung of a maturity ladder.\n\nDefaults, not fixed tiers. The primitive is a namespace with an owner and a publishing rule; stable/testing/unstable/personal is a template applied at organization setup. The test of whether this is right: a company can add regulated or experimental, or drop testing, without us shipping a release. If adding a tier needs a version bump they were never defaults. sidecat.org organizing a company marketplace is then a surface over that primitive, not a separate system.\n\nPromotion. The Debian aging rule applies only among organization tiers: a version migrates on elapsed time plus absence of release-critical bugs, automatically, nobody approving. If promotion needs a person or a review we have put an approval gate in the single path every package flows through, the failure mode the operator repeatedly names as what kills this project. Leaving a personal namespace is not aging; it is a transfer of namespace ownership, and that verb exists: native.package-namespace-authority-inspect and -transfer, internal/daemon/executable_catalog.go:2251 and :2317 at tree 3204e060. Check whether tiers are mostly naming and listing over machinery already built.\n\nDeparture. People leave. Actor-owned namespaces mean packages others depend on must move to organization ownership, which the transfer verb covers. Most internal registries orphan the package and someone re-uploads under a new name; here the dependency keeps working and only the owner changes. Design that path explicitly.\n\nKnown cost, not assumed away. N people means N namespaces and \"does a package for this already exist\" gets harder. Every company has this with internal libraries and nobody has solved it well. Decide what discovery looks like rather than assuming search fixes it later.\n\nTwo decisions when real. A tier attaches to a version, not a package, so foo 1.2 can be stable while foo 1.3 is testing. The adopter picks a tier per adoption rather than globally, because every distribution meets the person running stable except for one thing.\n\nStanding risk. A tiered marketplace is where verification machinery wants to live: signing for stable, audits before promotion, provenance gates. Tiers describe what an adopter should expect, never what an authority certified.\n\nNot now. The current package sprint puts a real artifact through author, share, activate and use. What it learns about how namespaces actually behave is worth more than any reasoning above.\n\nSYNTAX NOTE, corrected 2026-09-10: package namespaces are dot-separated lowercase ASCII segments, for example agenda or team.agenda, per docs/packages.md. Earlier drafts of this item used slash-separated names from a chat sketch; that separator is not ours. Do not design tiers against it.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-10T18:35:02.653926633Z"
        },
        "changed_at": "2026-09-10T18:35:02.653926633Z"
      },
      {
        "id": "entity_549772324f8a78611ce2abde170b16e4",
        "status": "not_started",
        "created_at": "2026-09-09T14:49:31.398363837Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Repair the outdated TestWorkOrganizationColleagueNoRetainedOrganization expectation when this test area is next touched. Implementation15f306f8 isolated its failure on unchanged674b584d and patched source: the fixture retains a same-organization working session, which the existing session read path already permits colleagues to read. Update the fixture/assertion to test its stated condition accurately without narrowing or widening ordinary access. Keep this as a captured test-maintenance follow-up, not a replacement for the current ordered sprint. Source and focused baseline evidence are retained in15f306f8.",
        "intent": {
          "text": "Repair the outdated TestWorkOrganizationColleagueNoRetainedOrganization expectation when this test area is next touched. Implementation15f306f8 isolated its failure on unchanged674b584d and patched source: the fixture retains a same-organization working session, which the existing session read path already permits colleagues to read. Update the fixture/assertion to test its stated condition accurately without narrowing or widening ordinary access. Keep this as a captured test-maintenance follow-up, not a replacement for the current ordered sprint. Source and focused baseline evidence are retained in15f306f8.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-09T14:49:31.398363837Z"
        },
        "changed_at": "2026-09-09T14:49:31.398363837Z"
      }
    ],
    "recent_finished": [
      {
        "id": "entity_4691d37ae7c3d9c7513da7c1b9359f1c",
        "status": "finished",
        "created_at": "2026-09-11T13:41:29.73868091Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Reading a stuck publication's state needs an ordinary command, not sidecat invoke",
        "intent": {
          "text": "Reading a stuck publication's state needs an ordinary command, not sidecat invoke\n\nA publication is stuck. The operator wants to know what state it is in without resuming it. Today the only route is:\n\n    sidecat invoke source.publication-read --input-json '{\"request_key\":\"REQUEST_KEY\"}'\n\nsource.publication-read is registered as a query operation (internal/kernel/source_publication.go:7,50) but no CLI verb reaches it. Nothing else in that procedure is like this: publishing is `sidecat source publish`, resuming is `sidecat source publish --resume KEY`. Reading the state is the one step where the operator has to know an operation reference and compose a JSON object by hand.\n\nThe moment this command is needed is the moment it is hardest to use. Something has already gone wrong, the operator is deciding whether an effect happened, and we are asking them to recall an internal identifier under pressure. An agent in the same position has to guess the reference and the field name, and a wrong guess looks like a refusal rather than a typo.\n\nWanted: an ordinary verb for reading a publication's recorded state by its original request key, in the same shape as the resume route. The intent is one call, guessable from `sidecat source publish --help`, with the operation reference remaining available for callers who want it.\n\nFound while reviewing the upgrade-limit disclosure (sprint_acae35072ccc50a65de29bbc8c1f6ae3), which documents the invoke form because that is what exists today. The disclosure is correct as written; this is the follow-up.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T13:41:29.73868091Z"
        },
        "progress": {
          "text": "Reviewed source published as 53595059c51d79e84133f8ac7df1b5b002118c7f under source-status-cli-20260911. Eight exact CLI/test/doc paths; unrelated tests untouched. Six new test groups cover help/args, read-success versus publish-success, exact legacy keys/native JSON, copied-key whitespace, no cwd/Git/project, and failure/no fallback. Initial route tests and both review corrections failed before implementation; final TestSource(Status|Publish|Command) passed remotely. Candidate live reads matched the existing native query for a completed publication, the actual old pending publication and an absent key, without any resume or write. Cutting 0.2.18 on the droplet next; source publication is not installed delivery.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T15:30:44.814929386Z"
        },
        "result": {
          "text": "Delivered sidecat source status REQUEST_KEY [--json] in 0.2.18, runtime source 53595059c51d79e84133f8ac7df1b5b002118c7f and closeout a78c696d. The command reads retained publication state using the original key/caller without a repository directory, project or session; it never resumes or repairs. A successful query exits zero for published, pending, blocked or not-started state, independently of whether publication succeeded. Native JSON and historical keys remain readable, including copied-key outer whitespace.\n\nClaude reviewed the implementation. Focused TestSource(Status|Publish|Command) passed remotely after initial absence and two review corrections. Candidate and installed commands read a completed publication, the real pending upgrade publication and an absent key with the same results as the existing native query. 0.2.18 was installed on Development generation 479/original store and local/remote worker CLIs; 0.2.19 retains the command and has used it successfully. Installer command-double checks passed. No full suite, cold install or federation trial was repeated for this CLI-only change.\n\nThe carried closeout is now delivered: maturity v13 describes the ordinary command and removes the obsolete missing-command limitation. Site commit 75e9838e7c0b1b24b5d6d02007937464c09d87c0 is deployed; progress and capability pages match the verified build. The older pending/unknown Action remains unresolved and was neither resumed nor replaced by this work. Reading its state is not a recovery claim.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T18:42:21.50455767Z"
        },
        "changed_at": "2026-09-11T18:42:21.50455767Z",
        "finished_at": "2026-09-11T18:42:21.50455767Z"
      },
      {
        "id": "entity_2f8ea7682d270d0516f5ecd81f5d7030",
        "status": "finished",
        "created_at": "2026-09-11T15:43:06.118333296Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Replace JSON-backed operational planning data with relational models",
        "intent": {
          "text": "Replace JSON-backed operational planning data with relational models\n\nOperator instruction, September 11, 2026: \"OK well please fix it.\" This supersedes the earlier after-September-15 deferral. Claude defines the corrective sprint; the lead engineers and estimates it.\n\nProblem: the backlog, sprint fields/story membership, ordering, task links and review decisions are useful structured state, but project_planning and project_sprints store them in JSON text and application code reconstructs/manipulates them. saveBoard marshals the whole backlog; latestDelivery queries review_summary_json with json_each. GORM does not turn these strings into relational rows.\n\nRequired outcome: represent the operational fields and relationships explicitly in the relational model, migrate existing records, and cut both reads and writes over while preserving usable public commands and results. Do not satisfy this with a title refresh or a few extracted indexes while the authoritative working model remains JSON. Cover the structured data consumed by current planning/reporting paths, not only the easiest membership array. Preserve the distinctions between agreed wording and current Work rather than silently rewriting either. Exact table decomposition is an engineering decision to review.\n\nOperator rationale: this repeats a failure pattern from earlier Sidecat GENERATIONS, not merely versions/releases. Do not pin it to Gen 3 without evidence. A known project-killing pattern must constrain design and review; the operator should not need to rediscover it. If our explanation is wrong or incomplete, establish facts and explain them rather than reflexively agreeing or inventing a justification.\n\nSource corrections: WorkProject.ForeignKeys and project_schema/0002_add_schema.sql reference entities(entity_id,store_id), so a Work FK target exists; generic Work representation did not force JSON. Application checks verify added Work against the prepared project, so references are not wholly unchecked. Selected intent/title/area are deliberately retained; sprintPlanView separately reads current Work. Snapshot wording alone does not prove accidental staleness. No immediate corruption or data loss was established by this source inspection.\n\nBoundaries: no whole-core rewrite, blanket JSON-keyword ban, raw-document storage project, ordinary-path integrity audit or new startup gate. Raw document/blob retention is a separate product/storage question, not a justification for this operational model. Sprint IDs are separate sprint_ identifiers, so generic entity relations are not a drop-in replacement. Generated project migrations currently add tables/nullable columns without backfill; this needs explicit data migration and read/write cutover. Use focused remote tests, populated migration/reopen checks and actual planning use. All changed code receives independent review with applicable coding/design instructions in context before publication.\n\nIntroduced in 5550168d, September 8. The wider product capability for policies, reminders and reviewer context is future sprint work, not a prerequisite for this correction.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T16:06:13.159225868Z"
        },
        "progress": {
          "text": "Installed 0.2.19/source 30b6ead3 on the original Development store, generation 480; local and remote worker tools updated and ready. Full native plan before/after matched except read-time as_of; maturity v12 matched exactly. Claude independently verified actual amended sprint wording, carry disposition and all assessment entries at channel 2301. Supported actual-store-copy trial passed before live migration: 2 boards, 54 sprints, 12 assessment versions; conversion and reopen 20.835s. Supported backup completed recoverable in about 71 minutes, retained locally/off-machine; fresh closed-store pre-install copy also retained. Source and schema review accepted. Remaining: publish qualified release notes, record unchanged-level maturity v13, verify deterministic public pages, resume site timer, and obtain sprint outcome review. Wider ORM and unfinished-Action recovery are not claimed fixed.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T18:32:57.840885238Z"
        },
        "result": {
          "text": "Delivered in 0.2.19, runtime source 30b6ead3b5c17b638e332768e30ee22ff6c110ac; qualified release notes/lock published at 7ba1ae306cfbebf01a2829c08ba20396d978a46b. Backlog, sprint fields/stories/links, review decisions and saved values, wording, and capability assessments now use typed relational rows. Planning Work references have entity FKs; ordered collections have parent-scoped unique positions. Latest delivery joins disposition rows. Wire JSON and selected/current/review distinctions are unchanged. Legacy source rows are retired only after transactional value comparison; empty historical declarations remain, with no ordinary JSON fallback or mirror.\n\nBefore live upgrade, a supported copy of the actual database migrated 2 boards, 54 sprints and 12 assessments and reopened with the same store ID in 20.835s. Supported backup completed recoverable and remains local/off-machine; a fresh closed-store copy also remains local. Installed Development generation 480 uses its original store; full planning read matched before/after excluding only as_of, and maturity v12 matched exactly. Local and remote worker tools are ready on 0.2.19. Maturity v13 then exercised a real new relational write and exact readback, with all 22 levels unchanged.\n\nFocused model/generator, runtime, populated migration/rollback, wire-budget and installer checks passed after the recorded fixes. Claude reviewed source with operator/org constraints loaded, independently checked real amended wording and a carried disposition after installation, and approved release/assessment text (2295, 2301, 2305). Site commit 75e9838e7c0b1b24b5d6d02007937464c09d87c0 deployed successfully; index, llms, progress HTML/JSON and capabilities match the local build byte-for-byte. 104 focused site checks passed with no skips; the real project-brief Lisp projection had no source failures. Hourly timer restored.\n\nLimits: wider ORM conversion remains incomplete; no new cold-install/federation trial or full repository suite. This does not repair the older pending Action. Backup took about 71 minutes; that weakness and policy/reviewer-context product work are in the native backlog, not claimed solved. Scrum outcome review remains Claude's separate disposition.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T18:42:19.339158705Z"
        },
        "changed_at": "2026-09-11T18:42:19.339158705Z",
        "finished_at": "2026-09-11T18:42:19.339158705Z"
      },
      {
        "id": "entity_920c21993a6d35ba22823a92f1e917f0",
        "status": "finished",
        "created_at": "2026-09-11T16:17:13.804143525Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Review the relational planning migration's saved-Work projection boundary",
        "intent": {
          "text": "Review the relational planning migration's saved-Work projection boundary\n\nParent repair: entity_2f8ea7682d270d0516f5ecd81f5d7030. Read its full intent, sidecat org guidance, workspace AGENTS.md/onboarding and sidecat org reference read planning-relational-implementation before reviewing. Report which of these you actually read.\n\nRead-only, bounded source review; no source/state edits outside reporting this Work, no local Go/tests, no provider/model changes, no public publication. Source: /home/jgay-automate/projects/gitlab.com/sidecat-dev/sidecat/.worktrees/main-integration-20260904, baseline a78c696d. Root is implementing inline; Claude is scrum master.\n\nQuestion: ReviewProjectSprint saves WorkSummary objects produced by sprintPlanView/SummarizeWorkRead. WorkSummary declares optional Completion and CreationInvocation alongside record refs, text, authors and truncated fields. Establish which fields the actual current and earlier planning writers can have persisted since planning's introducing commit5550168d. Does any real writer populate Completion or CreationInvocation for sprint snapshots, or are these fields only populated by other projection routes? Read source and narrowly relevant history; never inspect the live SQLite store.\n\nReturn exact file/function evidence, any uncertainty, and the minimum field-preserving relational projection boundary. Do not authorize dropping data merely because a current test omits it. Do not turn this into a whole-history audit or a general schema redesign.\n\nApplicable design policies for this review: operational collections/relationships become typed rows; no JSON-authority mirror or encoded-payload substitute. Preserve IDs/order/versions/authors/timestamps and agreed-versus-current facts. Conversion happens once in the existing migration transaction, not on normal startup/read paths. Keep assurance proportional: no new custody/checking framework, no full suite, no speculative safety machinery. The operator requires all changed code independently reviewed with policies in context; this is supporting design review, not final code approval.\n\nFinish this Work with a concise evidence-backed answer; keep broader suggestions explicitly separate.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T16:17:13.804143525Z"
        },
        "result": {
          "text": "Read: parent Work entity_2f8ea7682d270d0516f5ecd81f5d7030; org guidance revision_cf5442903f62a35eb96db611f3f23666; workspace AGENTS.md and .sidecat/onboarding.json; org reference planning-relational-implementation. Source a78c696d in main-integration-20260904. No live SQLite, no source edits.\n\nAnswer: no planning writer populates Completion or CreationInvocation on sprint snapshots. Those fields are only filled by the working-session review overlay.\n\nEvidence\n- Only WorkSnapshotJSON writer is ReviewProjectSprint (internal/sqlite/project_sprint.go:272-329). It stores planningJSON(projectSprintSnapshot{Work: view.Work, Links: view.Links}) from sprintView -> sprintPlanView(op, row, \"full\", true) (38-38, 43-128, 310). Same snapshot write in introducing commit 5550168d.\n- sprintPlanView rebuilds live Work via retainedWork + SummarizeWorkRead (103-126). Compact rewrite (112-125) is plan-read display only; Review always uses full.\n- SummarizeWorkRead (internal/kernel/work_read_projection.go:49-117) never assigns CreationInvocation or Completion. It copies Session from WorkReadOutput and may set Project, Lifecycle, texts, authors, source refs, TruncatedFields.\n- Those overlay fields have existed on WorkSummary since fa98036e (2026-09-05), before planning 5550168d (2026-09-08). planningJSON is encoding/json.Marshal (project_planning.go:100-108); both overlay fields are pointers with omitempty, so a nil writer omits the keys.\n- Sole assignments: working_session_work_projection.go:94-99 (CreationInvocation from working_session_works; Completion from readWorkCompletionProjection). Tests of those fields are session-review only.\n\nFields a planning snapshot can actually contain\nAlways: representation, record (RecordRef), status.\nOptional when the live read had them: project (org id+key; on SummarizeWorkRead since c994e67a, before planning), lifecycle, objective, progress, result, requested_by_entity_id, progress_actor_entity_id, result_actor_entity_id, progress_source, result_source, session (ordinary started Work with session membership; work_unit_lifecycle_read.go:244-261), truncated_fields.\nReviewSummaryJSON stores ProjectBacklogItem stories (id/title/area), not WorkSummary.\n\nMinimum field-preserving relational boundary\nTyped ordered project_sprint_review_work rows plus ref/truncated children for the fields above, including Session and Project even though current sprint tests do not assert them. Preserve order and exact refs. Convert once in the migration transaction; do not re-read mutable Work to manufacture old review values; no JSON-authority remainder for this projection.\nDo not add Completion or CreationInvocation as planning snapshot columns: no planning writer emits them. If a decoder sees those keys, keep them as optional typed columns already on WorkSummary; do not invent a payload blob and do not treat test omission as leave to drop writer-populated fields.\n\nUncertainty: no live-store check (forbidden); cannot rule out out-of-tree JSON edits. encoding/json would already drop keys not on WorkSummary.\n\nSeparate, not required: compact live summaries are a different, narrower projection and must not define the saved-review schema.",
          "by": "entity_24fc0d7b86ac6e5378e97c8d9b7cc1bf",
          "at": "2026-09-11T16:21:33.115407926Z"
        },
        "changed_at": "2026-09-11T16:21:33.115407926Z",
        "finished_at": "2026-09-11T16:21:33.115407926Z"
      },
      {
        "id": "entity_20ee7f9ccd8b6f6bfb53847cc68fe23a",
        "status": "finished",
        "created_at": "2026-09-11T14:34:25.793997788Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Bring the capabilities page up to date with what has actually been delivered",
        "intent": {
          "text": "Bring the capabilities page up to date with what has actually been delivered\n\nOperator instruction to the lead, 2026-09-11, direct to the pane: update the capabilities page on sidecat.dev.\n\nThe page is the one place a stranger can check whether our claims match what was built, and it is four days from launch. The last authored assessment is version 10, recorded this morning, and it was a disclosure edit: it added the binary-upgrade limit to three capability records and changed nothing else. It was explicitly not a review of whether every other capability statement still matches the delivered releases.\n\nWanted: read the native assessment against the verified deliveries, correct any stale claim, publish the projection, and verify the live page. A maturity level moves only where a delivery supports it. Homepage wording is not a delivery and does not move anything.\n\nConditions carried from the disclosure work: no level increase without a named delivery behind it, no new claim that a trial did not establish, and the limits already published stay published.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T14:34:25.793997788Z"
        },
        "result": {
          "text": "Updated https://sidecat.dev/capabilities.html from native assessment v12, recorded 2026-09-11T14:46:36.579286008Z. Published source 94325bd4ceaa798b2177484e126863416cf9ecd5; pipeline 2841210512 succeeded. All five checked public bodies returned 200 and matched the tested build, including capabilities.html. The site worktree is otherwise unchanged.\n\nReviewed the prior 22 rows against published qualifications, retained delivery reports and documented implementation boundaries, not a rerun of every trial. All names/order/levels and previous limits remain. Four rows clarified: actual message acceptance/reply example and tmux attention; editorial homepage/showcase versus generated operator views; native publication-state query versus not-yet-delivered ordinary CLI; historical cold-install and later supplied-bundle upgrade scope through 0.2.17. Summary/context/conclusion distinguish documentation improvements from new runtime maturity. Added links to the real message exchange and public AAuth conformance/source-baseline documents. AAuth baseline is explicitly pinned, not claimed current with latest editor drafts; homepage is labelled explanation, not another qualification.\n\nClaude reviewed the generated diff at 2231; both source-label findings are addressed. After those edits, all 32 focused collector/maturity/rendered checks passed without skips and the five-page build passed. No runtime code, Go build, new release, level promotion or AAuth alignment claim. Supplemental read-only Grok review e01b872bee2182f0d756947cf71675a6 is still running and is not claimed as approval.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T14:50:08.918410819Z"
        },
        "changed_at": "2026-09-11T14:50:08.918410819Z",
        "finished_at": "2026-09-11T14:50:08.918410819Z"
      },
      {
        "id": "entity_74443c3a9cd813b9d479f0a685e4d4db",
        "status": "finished",
        "created_at": "2026-09-11T14:32:44.596525389Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Update the public capabilities assessment from verified current deliveries, publish its native projection, and check the live page. Operator requested this update on September 11, 2026. Preserve honest maturity levels; distinguish documentation improvements from new runtime capabilities.",
        "intent": {
          "text": "Update the public capabilities assessment from verified current deliveries, publish its native projection, and check the live page. Operator requested this update on September 11, 2026. Preserve honest maturity levels; distinguish documentation improvements from new runtime capabilities.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T14:32:44.596525389Z"
        },
        "progress": {
          "text": "Bounded publication refresh requested by the operator. Native v10 and recorded message/0.2.17 delivery results read; installed CLI remains 0.2.17. Draft /tmp/sidecat-maturity-refresh.N27fnQ/assessment.json preserves all 22 names/order/levels and all existing AAuth and unfinished-effect boundaries. Four row clarifications: actual messaging example, editorial vs generated operator views, not-yet-delivered ordinary publication read command, and explicit upgrade/cold-install history. Balanced summary/context/conclusion and two relevant public-example links. Independent review requested at channel 2227. Plan: validate the authored draft with existing collector/renderer, record native assessment, sync:maturity, run focused maturity/rendered checks and site build, publish only the generated maturity file, verify live page, then resume selected CLI sprint. No runtime implementation or level promotion in this update.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T14:35:44.944748885Z"
        },
        "result": {
          "text": "Updated https://sidecat.dev/capabilities.html from native assessment v12, recorded 2026-09-11T14:46:36.579286008Z. Published source 94325bd4ceaa798b2177484e126863416cf9ecd5; pipeline 2841210512 succeeded. All five checked public bodies returned 200 and matched the tested build, including capabilities.html. The site worktree is otherwise unchanged.\n\nReviewed the prior 22 rows against published qualifications, retained delivery reports and documented implementation boundaries, not a rerun of every trial. All names/order/levels and previous limits remain. Four rows clarified: actual message acceptance/reply example and tmux attention; editorial homepage/showcase versus generated operator views; native publication-state query versus not-yet-delivered ordinary CLI; historical cold-install and later supplied-bundle upgrade scope through 0.2.17. Summary/context/conclusion distinguish documentation improvements from new runtime maturity. Added links to the real message exchange and public AAuth conformance/source-baseline documents. AAuth baseline is explicitly pinned, not claimed current with latest editor drafts; homepage is labelled explanation, not another qualification.\n\nClaude reviewed the generated diff at 2231; both source-label findings are addressed. After those edits, all 32 focused collector/maturity/rendered checks passed without skips and the five-page build passed. No runtime code, Go build, new release, level promotion or AAuth alignment claim. Supplemental read-only Grok review e01b872bee2182f0d756947cf71675a6 is still running and is not claimed as approval.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T14:50:07.211314981Z"
        },
        "changed_at": "2026-09-11T14:50:07.211314981Z",
        "finished_at": "2026-09-11T14:50:07.211314981Z"
      },
      {
        "id": "entity_e01b872bee2182f0d756947cf71675a6",
        "status": "finished",
        "created_at": "2026-09-11T14:45:34.622843637Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Read-only reader review of the capabilities-page refresh. Return a concise approve/reject with concrete findings in this Work result; do not change repository files, native maturity, source publication, sprint selection, or any other Work. This is editorial review, not a test-suite or specification-alignment assignment.",
        "intent": {
          "text": "Read-only reader review of the capabilities-page refresh. Return a concise approve/reject with concrete findings in this Work result; do not change repository files, native maturity, source publication, sprint selection, or any other Work. This is editorial review, not a test-suite or specification-alignment assignment.\n\nPublic site checkout: /home/jgay-automate/projects/gitlab.com/sidecat-dev/sidecat-dev.gitlab.io. Compare current src/data/capability-maturity.json (native assessment v11) to git show a212d244ba8fa46720db5d8fb69ba38859a3e85d:src/data/capability-maturity.json (v10). Read public/capabilities.html if helpful; it is the built current draft. Work entity_74443c3a9cd813b9d479f0a685e4d4db describes implementation and verification.\n\nUser wants the public capabilities page updated to actual delivered work. All 22 names/order/levels must remain unchanged in this draft, all previous limits must remain stated, and documentation improvements must not masquerade as runtime improvements. Changed rows: native messaging; operator views; source publication; installation/upgrades. Summary/context/conclusion and source links updated too. Unchanged rows were checked by the lead against their existing delivery records; this refresh does not retest every capability.\n\nCheck specifically: the message example distinguishes acceptance from reply and discloses its tmux attention and same-node scope; editorial homepage/showcase remain distinct from generated progress; ordinary publication-state CLI is still absent and must not be called delivered; installed 0.2.17 updates do not imply a fresh cold installation; AAuth/signature/federation and cross-version continuation limits must not be weakened. For meaning checks, current core docs/releases/0.2.7.md, 0.2.12.md, 0.2.15.md and 0.2.17.md are in /home/jgay-automate/projects/gitlab.com/sidecat-dev/sidecat/.worktrees/main-integration-20260904. Do not rerun their trials or explore unrelated source. Only report facts from what you read.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T14:45:34.622843637Z"
        },
        "result": {
          "text": "APPROVE native assessment v11 (recorded 2026-09-11T14:42:17Z) versus v10 at a212d244.\n\nAll 22 names, order and levels are unchanged. Level definitions, title, date and reporting_limitations are unchanged. Changed rows are only #3 Native messaging, #10 Rolling operator updates, #11 Source publication (limitations and work_ids), and #12 Installation, plus summary/context/conclusion and four source links. AAuth (useful), Sidecat AAuth consumption (partial) and federation (partial) are byte-identical to v10.\n\nMessaging: limitations distinguish node acceptance from a reply or completed work, and disclose tmux attention and same-node/not-federation scope. That matches showcase #message-exchange: send 2184 accepted before reply 2185, tmux nudge, same node.\n\nOperator views: generated progress is still the Lisp/deterministic progress page. Limitations keep the showcase and historical sprint editorial. The homepage source is labeled \"not an additional qualification\". Context: \"No maturity level is raised for documentation.\"\n\nPublication: \"an ordinary CLI read command is not yet delivered.\" 0.2.15 delivered compact results and an action.orient detail query, not that CLI. Prior upgrade-recovery limits remain: effect_definition_unavailable, unresolved 0.2.15 hourly publication, in-flight recovery still follow-up.\n\nInstallation: 0.2.7 remains the cold Ubuntu 24.04 amd64 trial; 0.2.12 remains supplied-bundle upgrades; 0.2.17 \"subsequently received\" and \"not another cold-install trial\" matches 0.2.17's statement that cold installation was not repeated.\n\nAAuth/signature/federation and cross-version continuation are not weakened. Summary still says full AAuth integration and in-flight recovery remain incomplete.\n\nRead: v10/v11 JSON, public/capabilities.html (contains the v11 sentences), showcase #message-exchange, implementation Work entity_74443c3a9cd813b9d479f0a685e4d4db, messaging Work entity_1913c5ebb0e74034e45a88d8976237c3, and docs/releases/0.2.7.md, 0.2.12.md, 0.2.15.md, 0.2.17.md in the named worktree. Did not rerun trials or change files.\n\nNon-blocking: summary says \"Federation is useful in that bounded setting\" while the federation row remains partial; the table and row limits prevent a promotion reading. No reject findings.",
          "by": "entity_24fc0d7b86ac6e5378e97c8d9b7cc1bf",
          "at": "2026-09-11T14:49:22.909718571Z"
        },
        "changed_at": "2026-09-11T14:49:22.909718571Z",
        "finished_at": "2026-09-11T14:49:22.909718571Z"
      },
      {
        "id": "entity_144e1d4cacb4482e77b3a7e15b59f418",
        "status": "finished",
        "created_at": "2026-09-11T05:22:00.800744331Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Say what Sidecat is for in the first sentence, without promising enforcement.",
        "intent": {
          "text": "Say what Sidecat is for in the first sentence, without promising enforcement.\n\nThe 0.2.12 homepage correction removed four unsupported guarantees and replaced them with claims a stranger can check. It also replaced the thesis sentence, which was not one of the defects. The page now opens with an accurate description of what the software does, and no statement of what it is for or why it is built the way it is.\n\nThe scrum master asked for a thesis sentence back during that sprint; the lead engineer kept the new opening for two reasons worth carrying forward. It does state a purpose, and making constraints the single explanation would understate a system that also supplies persistent work and reusable methods. Both are fair, and both are arguments about which thesis to write rather than whether to have one.\n\nWhat a reader should get from the first sentence: who this is built for, and why its shape follows from that. The prior copy said the mechanism is constraints, well chosen, leading to greater creativity and productivity. That belief has not been contradicted by anything, including three outside reviews on 2026-09-10, but it is narrower than what now exists.\n\nFails if the sentence promises an enforcement, isolation or concurrency property we cannot show on the same site the day it is read. Fails if it is written as a slogan rather than a claim about purpose. Fails if the bullets or the source-test boundaries are weakened to accommodate it. Excluded: redesign, positioning research, company or vendor content, and any change to the capability assessment.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T05:22:00.800744331Z"
        },
        "progress": {
          "text": "Implementation and review progress: the draft at2216 received Claude reader review at2217; I removed mechanism jargon from the opening/meta, put actual command/read scope plus operator preparation in the first sentence, and separated receiving-machine requirements from caller credentials. Final copy is at2219 and in the shared site checkout, awaiting final reader approval. Regression: old name-only description failed the new check; all9 site-reset tests now pass. Astro built5 pages; generated paragraph/meta match source and all other homepage bytes match baseline48c7226b. Core README repair independently approved at2217 and now published as502b808edcf514e0a957f8ca4576fbef764a4b69; public GitLab read returned200 and exact source match. Website remains unpublished. Only site index/test paths dirty; original core untracked tests untouched. No runtime change, Go build or exhausted-worker dispatch.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T14:21:01.024735806Z"
        },
        "result": {
          "text": "Delivered the homepage explanation at https://sidecat.dev/. It now starts: \"Sidecat is open-source software that lets your AI agent run programs and read information on another machine, once an operator has prepared the connection and permissions.\" The same paragraph names the 0.2.12 trial, says the receiving machine runs Sidecat without another agent/model subscription, identifies the calling agent's lack of login/SSH credentials for that machine, and locates isolation in OS/VM/container boundaries. The meta description uses the same plain-language purpose. Claude independently reviewed the source at 2217 and 2220; duplicate disclosures were removed under his explicit scope adjustment, not silently dropped. The other three bullets, links, images, layout and maturity assessment are unchanged.\n\nSite commit a212d244ba8fa46720db5d8fb69ba38859a3e85d, pipeline 2841138269 successful. All five publication-check pages returned 200 and matched the local build. Nine focused homepage tests pass; the added regression first failed against the old name-only description. Five-page Astro build passed. Built statement/meta and approved source scope were checked directly. No new runtime, release, Go build or capability-level change.\n\nCore README opening separately corrected to link the prepared independent-store qualification in 0.2.12: commit 502b808edcf514e0a957f8ca4576fbef764a4b69, public GitLab source returned 200 and exactly matched. Unrelated untracked core tests preserved.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T14:25:19.387605187Z"
        },
        "changed_at": "2026-09-11T14:25:19.387605187Z",
        "finished_at": "2026-09-11T14:25:19.387605187Z"
      },
      {
        "id": "entity_4441f4ec338e4188e36697dd4969c022",
        "status": "finished",
        "created_at": "2026-09-11T13:28:07.424060075Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Publish the current binary-upgrade limitation for unfinished effects in the existing publication notes, federation notes and capability assessment. Selected by scrum master at2201. State what changed runtimes cannot currently resume, distinguish completed results, same-implementation restart recovery and ordinary saved Work, and give practical planned-upgrade guidance without promising recovery of the historical unknown Action. Documentation and authored maturity update only; no runtime behavior, compatibility layer, automatic retry, attestation, database access or historical reconstruction. Keep recovery issue5d7e8734 open. Source/evidence assessment: org reference read upgrade-recovery-assessment-20260911.",
        "intent": {
          "text": "Publish the current binary-upgrade limitation for unfinished effects in the existing publication notes, federation notes and capability assessment. Selected by scrum master at2201. State what changed runtimes cannot currently resume, distinguish completed results, same-implementation restart recovery and ordinary saved Work, and give practical planned-upgrade guidance without promising recovery of the historical unknown Action. Documentation and authored maturity update only; no runtime behavior, compatibility layer, automatic retry, attestation, database access or historical reconstruction. Keep recovery issue5d7e8734 open. Source/evidence assessment: org reference read upgrade-recovery-assessment-20260911.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T13:28:07.424060075Z"
        },
        "progress": {
          "text": "Draft ready under scrum direction2201. Three Markdown edits: README publication recovery is explicitly bounded by unchanged admitted implementation, with read-only original-key inspection and planned-upgrade guidance; federation distinguishes fresh calls/retained pairing from interrupted effects; first-worker upgrade instructions link the limit. An unresolved historical record is not made a startup/upgrade gate. Native maturity draft changes only source publication, installation/upgrades and federation statements/citations plus report limits; all22 capability names/order/levels preserved and other capability records unchanged. Independent review requested at2204. No runtime edits, installed changes, old-Action mutation or new recovery mechanism. Full engineering assessment remains native org reference upgrade-recovery-assessment-20260911; recovery issue5d7e8734 remains open. After review: publish core docs, cite exact commit in native assessment, record it and refresh/publish/verify capability page.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T13:33:23.271704854Z"
        },
        "result": {
          "text": "Delivered disclosure, not a recovery fix. Core docs058ae82869827d520dd7ba970152aa7c05080505 update README publication/resume guidance, docs/federation.md and the actual upgrade instructions in docs/first-worker.md. All three public GitLab file reads returned200 and matched the selected source. The text explains exact implementation/binary coupling, completed-result and ordinary-Work distinctions, fresh calls versus interrupted commands, a read-only original-key check, and practical maintenance notes. A separate publication requires confirmation of no original commit/push and does not rewrite the old Action. No stale unresolved record is made a startup/upgrade gate; cross-version recovery is explicitly follow-up. Claude reviewed at2206/2209; requested edits are included with corrections avoiding permanent unrecoverable, identical-repeat-error, and most-complete-old-snapshot claims. Native maturity version10 preserves all22 capability names/order/levels and updates the three affected areas plus authored context/limits and pinned documentation source. Site2b107f9d36b8ef2593578ec31dfe7729da666ee4, pipeline2841034355 success: all five public bodies checked by publish-status match the built artifacts. All32 focused maturity/rendering checks pass, including built-page checks; five-page Astro build passed. No runtime behavior or installer change, no new release or recovery trial. Core unrelated untracked tests are untouched; site worktree clean. The historical Action is unchanged and recovery Work5d7e8734 remains open. Full decision support remains available through org reference read upgrade-recovery-assessment-20260911. Ready for scrum review/disposition.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T13:52:57.321606509Z"
        },
        "changed_at": "2026-09-11T13:52:57.321606509Z",
        "finished_at": "2026-09-11T13:52:57.321606509Z"
      },
      {
        "id": "entity_1913c5ebb0e74034e45a88d8976237c3",
        "status": "finished",
        "created_at": "2026-09-11T00:54:26.222986841Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Show what a Sidecat message actually does, next to the by-hand equivalent.",
        "intent": {
          "text": "Show what a Sidecat message actually does, next to the by-hand equivalent.\n\nThe showcase (entity_4f24bea1, published at https://sidecat.dev/showcase.html) explains source publication as a four-operation chain against the shell commands a person would otherwise type. The operator asked for the same treatment of an actual message command and it was not part of that story: \"also yes explaining what is happening with an actual message command\", 2026-09-10.\n\nA reader who has never used Sidecat should be able to run one send, read the reply, and understand what the node did on their behalf: which participant and domain were resolved, what target the message was accepted against, and what they would have had to build themselves to get the same delivery and readback. Use a real command and its real output, not a constructed example.\n\nFails if the page shows output that was not produced by running the command. Fails if it explains the envelope without showing what the reader gains over doing it by hand. Excluded: new message features, protocol changes, and any change to the send or catch-up operations themselves. This is a documentation story against shipped behaviour.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T00:54:26.222986841Z"
        },
        "progress": {
          "text": "Draft implemented in canonical site checkout: separately dated real send2184/read with reply2185, identity/target/acceptance explanations and honest tmux comparison; September10 data unchanged. New checks first failed for missing walkthrough/section. Now 26 focused tests pass, including rendered command visibility, expandable actual JSON and historical 706-entry log. Five-page Astro build passed. Direct comparison against original exit0 captures confirms both commands and every displayed response value unchanged. Claude reader review requested at2186; source not yet published and live browser check remains.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T12:52:27.803155798Z"
        },
        "result": {
          "text": "Delivered at https://sidecat.dev/showcase.html#message-exchange. Site commit0c91b22fd0ed494de5ead0b7866933aa44481f8c, pipeline2840859913 success; both showcase.html and the historical sprint URL return200 and match the tested build byte-for-byte. The new September11 section shows actual send2184, the first read with no later reply, and the later read containing Claude reply2185. Command/response values were compared directly with all three saved exit0 captures. The full send response, complete request/reply bodies and selected transcript metadata are pretty printed in separate collapsed outputs; omissions are named. Domain, caller, recipient, target, acceptance and reply are explained. The compact tmux alternative concedes the one-off case and discloses the actual attention nudge and same-node scope. Existing September10 samples, log and statistics remain unchanged. Claude reviewed substance at2188 and requested the third captured read; it is included. All26 focused/data/rendered/log tests pass and five-page Astro build passes. No runtime changes, Go compilation or runtime release. Native source publication used request message-walkthrough-20260911; main worktree is clean. Limit: browser-control tools returned no available browser. Live HTML confirms ordered entries, three closed output disclosures and black-background stylesheet; no new visual screenshot is claimed. Original captures and publication/live-check results are retained under data/sidecat/message-walkthrough.p8vNH5. Ready for scrum review/disposition.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T12:57:54.954819607Z"
        },
        "changed_at": "2026-09-11T12:57:54.954819607Z",
        "finished_at": "2026-09-11T12:57:54.954819607Z"
      },
      {
        "id": "entity_bd95a0edb4b6b0b4f422ffdb901f06ed",
        "status": "finished",
        "created_at": "2026-09-11T01:24:11.051022261Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "Correcting a sprint's wording should not look like delivering a sprint.",
        "intent": {
          "text": "Correcting a sprint's wording should not look like delivering a sprint.\n\nA sprint's outcome text cannot be revised. The only way to change it is to review the sprint and select a replacement, so an editorial fix produces a closed sprint and a new one, and the public projection's Latest reviewed change then shows the correction instead of the most recent real delivery.\n\nObserved 2026-09-10 between 19:00 and 19:16 MDT, with the scrum master as the cause. Three sprints were recorded in twenty minutes: sprint_a38985c3 selected and closed unstarted when external feedback reordered the backlog, sprint_6b78ea82 selected and closed minutes later purely because the default briefing renders the outcome line and story titles only, so an outcome written as the finished journey read as work in progress, and sprint_3ec8b68a selected with the same story and scope and the stage moved into the outcome line. Two of those three closures moved no work at all. The lead engineer raised it at channel 1977: editorial corrections should not count as delivery sprints.\n\nThe person harmed is a reader of the public plan, who sees recent planning churn where they should see what was last delivered, and anyone reading the sprint history later, who cannot tell a reorder or a restatement from a completed outcome without opening each record.\n\nFails if fixing a typo in an outcome still requires closing a sprint. Fails if the projection's latest-change view still counts a restatement as a change. Fails if the fix is achieved by hiding short sprints or filtering by duration rather than by distinguishing what actually happened. Excluded: a general revision history for every planning field, and any approval step on editing an outcome.\n\nWhether this is an amendable outcome, an explicit restatement disposition, or something else is an engineering design question and is deliberately not decided here.\n\nSecond instance, same night, and a stronger one. sprint_e80f3fda was closed\nten minutes after selection and re-cut as sprint_6af9134c because the scrum\nmaster had written an acceptance criterion that was mathematically\nimpossible: a collision-free mapping from a 192-character key space over\nroughly 94 symbols into a 160-character label over 37. The lead engineer\nrefused it by counting argument rather than implement a test that pretends.\nNo work moved under that sprint either.\n\nThat instance is the sharper evidence, because what needed correcting was a\nfalse statement already published in the plan. Leaving it was not an option,\nso the model forced a choice between an inaccurate public record and a\ndelivery record padded with sprints that delivered nothing. Nine sprint\nrecords exist for 2026-09-10; three were created only to change wording or\ncriteria.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T05:45:11.905915864Z"
        },
        "progress": {
          "text": "Published commit 4016bbd1ee164bebd4cbac6c7e1b1d8e0909d9a1.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T11:43:30.678628797Z"
        },
        "result": {
          "text": "Delivered as0.2.17. Native source4016bbd1ee164bebd4cbac6c7e1b1d8e0909d9a1; qualified installer/catalog3b0c129d6ec2864e4a38c826e2e8ee0d9a2b0177; final notes0d67deb73cd123ba3396cc97563b2cf29f23f00d. Development generation478 retained original store; node and local/remote worker tools report installed/ready.\nActual current sprint c14b730a was corrected with one ordinary project sprint update call, version2->3, without changing ID, original selection time/author, stories, links, rationale or unreviewed state. Separate reads recovered earlier outcome/rationale and attribution; compact plan omitted history. Latest delivered review6b9 and all recent review records were identical before/after. No replacement or empty sprint was created.\nNative latest_delivery reads one stored summary independently of pagination, based on any delivered disposition. Mixed delivered/carry qualifies; later decisions remain in recent reviews. Current wording history stays in existing agreement JSON with no new entity/schema/event system, approval or audit step. Unchanged edits do not append; existing limit refuses without pruning and explicitly explains retained earlier wording. Reviewed agreements stay historical; review re-recording is separate and does not retain prior review text.\nPublic source plus fresh live records published together as54a11aacb395699ba27bb822708461a34cc86359 after native installation. Pipeline2840708265 succeeded; all five checked public bodies match. Actual public before/after retains the same delivered story under Latest reviewed delivery, shows corrected focus and Earlier sprint wording. A later planning decision has its own default panel, and mixed/unfinished dispositions and complete records remain accessible. Existing kept project-brief passed new fields through without modification. Maturityv9 updates planning/operator views within existing levels.\nTests: worker43 focused native top-level+7 subtests; root11 named boundary tests; final4 update/help cases after the observed failing diagnostic test (counts overlap). Public101 focused tests and build passed, including actual final records. Installer command doubles passed. Prior predecessor-fixture cleanup was test-only. Claude approved design2160/2163, public2165 and native2168. No full-repository, cold-install or federation rerun.\nEvidence: data/sidecat/sprint-wording.oFYV1L; remote native logs /home/codex2/work/sprint-wording-{green,root-green,limit-message-red,limit-message-green}.log; published docs/releases/0.2.17.md. Site timer resumed; no active publication was interrupted.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T12:10:29.939242793Z"
        },
        "changed_at": "2026-09-11T12:10:29.939242793Z",
        "finished_at": "2026-09-11T12:10:29.939242793Z"
      },
      {
        "id": "entity_4ab792536077947bc616d6b0a38ac9b7",
        "status": "finished",
        "created_at": "2026-09-11T11:10:23.805219914Z",
        "created_by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
        "first_line": "Implement Task1 from native reference sprint-wording-plan (read via sidecat org reference read sprint-wording-plan). Parent entity_bd95a0edb4b6b0b4f422ffdb901f06ed; selected sprint c14b730ac0af0ff564db69a3b797470c. Claude approved design2160, root clarified2162. You own only native Go/CLI/help in this task; root owns the public site.",
        "intent": {
          "text": "Implement Task1 from native reference sprint-wording-plan (read via sidecat org reference read sprint-wording-plan). Parent entity_bd95a0edb4b6b0b4f422ffdb901f06ed; selected sprint c14b730ac0af0ff564db69a3b797470c. Claude approved design2160, root clarified2162. You own only native Go/CLI/help in this task; root owns the public site.\nPrepared scratch /home/codex2/work/sprint-wording.mU5oIX is an exact plain archive of canonical core e95228fcbdae09bda34ea15be6cdfd66bf907e31. Work there as codex2. Use normal/default speed, Astra high; no Fast/priority or built-in priority-only subagents. Read applicable TDD/executing-plans skills. Go/gofmt only through GOTOOLCHAIN=go1.27.1 /home/codex2/.local/bin/go-slot. No full repository suite, schema/model/migration changes, infrastructure, publication or installation.\nImplement native project.sprint-update/current unreviewed wording, prior wording retained inside existing agreement JSON, current/previous writer attribution, compact history omission, explicit/full history read, unchanged selection/stories/links/review and optional version semantics. Shared fields specified in reference: wording_history records outcome/rationale/recorded_at/recorded_by_actor_entity_id; wording_updated_at and wording_updated_by_actor_entity_id; plan latest_delivery is existing ProjectSprintReviewSummary or null, independent of recent page and based on ANY delivered disposition (mixed qualifies). Default latest-delivery query must use existing review summaries, not Work bodies or a client all-history loop.\nWire kernel registration, repository method, CLI update form and practical help. Add focused failing tests first then GREEN per reference. Include delivery beyond5reviewwindow, mixed dispositions, review rerecord changing eligibility, history/read/reopen, noop, current-only/unreviewed and invalid/optional-version behavior. Preserve original strings with valid text; no duration heuristic or old-text pruning. If shared field names need change, coordinate before site integration.\nReturn exact patch vs supplied base, changed paths, test commands/logs and remaining limits through this Work. Do not create another overlapping implementation Work in a message handler. Root reviews/imports and handles installed journey. Do not dispatch your own reviewer; Claude/root will review while you report.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T11:10:23.805219914Z"
        },
        "progress": {
          "text": "GREEN exit 0: 43 top-level tests and 7 subtests, no failures/skips. Kernel 0.774s, SQLite 130.285s, CLI 0.192s. Exact final patch /home/codex2/work/sprint-wording-task1.patch (48184 bytes; SHA256 a64386212aeccbfc6cddbf4f4773210064d1cc0edf9f93b680bf49f13fda1127) applies to retained supplied archive and reproduces candidate file-for-file, rechecked after tests. Changed paths and file hashes: /home/codex2/work/sprint-wording-changed-paths.txt and sprint-wording-manifest.json. GREEN /home/codex2/work/sprint-wording-green.log. Shared names unchanged; wording_updated_* omitted until correction, history omitted when empty/compact, latest_delivery always summary or null. Preparing final result; root owns review/import and installed journey.",
          "by": "entity_ce4c642d849a0ab39266a84f2ddf5768",
          "at": "2026-09-11T11:29:54.230537025Z"
        },
        "result": {
          "text": "Completed Task 1 native implementation in /home/codex2/work/sprint-wording.mU5oIX.\nproject.sprint-update / UpdateProjectSprint and CLI update correct only the current unreviewed sprint. Actual changes retain prior outcome/rationale and author/time in agreement JSON, preserve selection/stories/links/review, and atomically increment sprint version. Omitted text is preserved; no-op keeps version/history/attribution. Empty/blank/null/invalid/oversize, stale version, unknown/noncurrent/reviewed targets refuse without mutation. No history pruning.\nwording_history uses outcome/rationale/recorded_at/recorded_by_actor_entity_id; wording_updated_at and wording_updated_by_actor_entity_id appear after correction. Full/explicit reads expose history; compact omits it. Returned-author labels and human CLI output cover new authored fields.\nlatest_delivery is an existing review summary or null, selected independently of review pagination by any delivered disposition, reviewed_at DESC/id DESC, in one query over stored summaries. No Work-body or client-history scan. Mixed dispositions and review replacement eligibility are covered.\n\nExact patch: /home/codex2/work/sprint-wording-task1.patch\n48184 bytes; SHA256 a64386212aeccbfc6cddbf4f4773210064d1cc0edf9f93b680bf49f13fda1127\nBase: supplied plain archive identified by Work as e95228fcbdae09bda34ea15be6cdfd66bf907e31. Local Git lacks this commit object. Patch applies to retained supplied archive and reproduces candidate file-for-file, rechecked after tests. Verification: /home/codex2/work/sprint-wording-patch-verification.txt; per-file hashes: /home/codex2/work/sprint-wording-manifest.json.\n\nChanged paths:\ncmd/sidecat/help/project-planning.md\ncmd/sidecat/project_planning.go\ncmd/sidecat/project_planning_test.go\ninternal/kernel/project_planning.go\ninternal/kernel/project_planning_test.go\ninternal/sqlite/current_actor_labels.go\ninternal/sqlite/project_planning.go\ninternal/sqlite/project_planning_delivery_test.go\ninternal/sqlite/project_planning_test.go\ninternal/sqlite/project_sprint.go\ninternal/sqlite/project_sprint_update.go\ninternal/sqlite/project_sprint_update_test.go\n\nAll tests ran from the scratch above, with prefix:\nGOTOOLCHAIN=go1.27.1 /home/codex2/.local/bin/go-slot\nRED command tail: test ./internal/kernel ./internal/sqlite ./cmd/sidecat -run 'ProjectPlanning|ProjectSprint|Planning.*Author' -count=1 -timeout 10m\nExit 1, expected missing operation/fields/routes/help. Log: /home/codex2/work/sprint-wording-red.log\nAdditional RED tail: test ./internal/sqlite ./cmd/sidecat -run 'ProjectPlanning(AdditiveUpgradeAndReopen|WordingHistoryHuman|LatestDeliveryHuman|UncertainNamedSprintReadHint)$' -count=1 -timeout 10m\nExit 1 for missing CLI behavior; fixed predecessor fixture passes. Log: /home/codex2/work/sprint-wording-red-display.log\nGREEN tail: test ./internal/kernel ./internal/sqlite ./cmd/sidecat -run 'ProjectPlanning|ProjectSprint|Planning.*Author|CurrentActorLabels(NativeReadsPreserveAuthoredRecords|CompactCollectsOnlyReturnedAuthors)$' -count=1 -timeout 10m -v\nExit 0: 43 top-level tests + 7 subtests, zero failures/skips. Kernel 0.774s; SQLite 130.285s; CLI 0.192s. Log: /home/codex2/work/sprint-wording-green.log\nAll 11 changed Go files formatted through go-slot gofmt -w before GREEN.\n\nOne pre-existing RED failure was a disposable predecessor fixture retaining three organization-reference tables. Corrected its cleanup list to match neighboring schema tests; no production schema/model/migration changes.\nLimits: no full suite, separate build, publication, installation, or live journey. Independent review and canonical-base import remain with root/Claude; root owns public-site integration and real sprint correction. Scratch and artifacts preserved. Latest Work reread before finishing; no overlapping implementation Work or reviewer dispatched.",
          "by": "entity_ce4c642d849a0ab39266a84f2ddf5768",
          "at": "2026-09-11T11:30:45.731899142Z"
        },
        "changed_at": "2026-09-11T11:30:45.731899142Z",
        "finished_at": "2026-09-11T11:30:45.731899142Z"
      },
      {
        "id": "entity_b0830a57f802fc0c82ad2d8e883b0191",
        "status": "finished",
        "created_at": "2026-09-11T08:08:19.275163248Z",
        "created_by": "entity_7741ef5effd5c0edd99589e722c9c474",
        "first_line": "A refused read through the REPL reports an effect that never happened.",
        "intent": {
          "text": "A refused read through the REPL reports an effect that never happened.\n\nObserved 2026-09-11 on the installed development node. Calling a refused organization.reference.read through sidecat repl eval returns repl_evaluation_failed with consequence_class transition and consequence_state unknown, wrapping an underlying refusal that is a query with consequence none. The public message is correct and carries no content.\n\nThe defect is the envelope, not the refusal. A caller reading consequence_state unknown is being told that something may have occurred and that its state is indeterminate, when the operation was refused before anything was attempted. That is the opposite of the rule applied elsewhere, where a named refusal reports the consequence class the operation actually has and a transition that did not apply says not_applied rather than none. An agent acting on the envelope rather than the prose would treat a clean refusal as an uncertain effect, which is the most expensive possible misreading.\n\nScope is how repl.eval wraps an operation failure it received, not reader scope and not any individual operation. Check whether the flattening applies to every refusal reaching the REPL or only to some, since a read refusal is the case that makes it visible rather than the only case.\n\nFails if the wrapper invents a consequence class rather than carrying the one the underlying failure reported. Fails if it is fixed only for reference reads. Excluded: new envelope fields, a general failure-taxonomy project, and any change to the operations themselves.",
          "by": "entity_7741ef5effd5c0edd99589e722c9c474",
          "at": "2026-09-11T08:08:19.275163248Z"
        },
        "progress": {
          "text": "Installed0.2.16 source ddac9ece on node generation477, original store retained, and local/remote worker tools; all installers report ready. Root live qualification passed: exact captured missing Work read/update, kept repl.call and interpreter-only failure changed unknown to not_applied with identical reason/message/class; actual Work update followed by refused read remained stored and whole evaluation reported unknown. try-call retained full individual query/none failure as data. Final combined126 focused tests and installer command doubles passed remotely. Claude2152 is repeating the original nonreader reference denial. Remaining: that exact before/after, publish release metadata/notes, native maturity/site projection and sprint disposition. Hourly timer resumed; no active publication interrupted.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T10:50:54.213547892Z"
        },
        "result": {
          "text": "Delivered as 0.2.16. Runtime source ddac9eceeab09162cb864129ed777cdd22c1b741; installer, release catalog and installed qualification notes e95228fcbdae09bda34ea15be6cdfd66bf907e31. Node generation477 retained original store; node and local/remote worker installers report ready.\nWhole-evaluation REPL failures keep the declared transition class. Known-clean refusals and interpreter-only failures now report not_applied; earlier possible host work or an invocation that unwinds before reporting remains unknown. The nearest existing structured failure boundary survives normalization; private causes do not overwrite its public consequence. No new envelope fields or operation definitions.\nRoot repeated identical captured missing Work read/update, kept repl.call and ensure failure: only unknown changed to not_applied, with public reason/message/class retained. An actual Work update followed by a refused read stayed stored, with the evaluation reporting unknown. try-call preserved the full individual query/none failure as data. Claude independently repeated the original nonreader reference refusal with unchanged caller/profile/readers and observed the same state-only correction, plus undefined-symbol and parse failures (2153).\nFinal combined remote126 top-level kernel/daemon/protocol/CLI tests passed, including real native publish-and-report integration. Earlier failing tests reproduced both misleading uncertainty and nested mutation-before-panic misclassification. Mutation/panic and genuinely unknown host outcomes used controlled tests; live node was not crashed. Installer command-double tests passed. Cancellation/deadline/explicit keep behavior remains separate. No full-suite, cold-install or federation rerun.\nClaude reviewed kernel2140 and final daemon/docs2149. Native maturity v8 updates only the REPL assessment within its existing level. Public site commit de85d233afa02f498fe9b49853e9465ce465ab96, pipeline2840526427 success; all five checked live pages match the expected build, including capabilities and progress. Timer resumed; no active publication interrupted. Older unresolved publication Action remains unresolved, not relabeled.\nEvidence: data/sidecat/repl-refusal.j16kpw; remote combined log /home/codex2/work/repl-failure-kernel.HWlrMn/extension-combined-green.log; public docs/releases/0.2.16.md. Overlapping extension records are one candidate handoff, not two software deliveries.",
          "by": "entity_66f0c6cd4bdfb1ab70267cbb50a6655f",
          "at": "2026-09-11T10:57:11.641338453Z"
        },
        "changed_at": "2026-09-11T10:57:11.641338453Z",
        "finished_at": "2026-09-11T10:57:11.641338453Z"
      }
    ],
    "window": {
      "finished_limit": 12,
      "finished_has_more": true,
      "note": "Recently finished shows the newest completions of the prepared project in completion order, up to 12 per refresh; more exist when finished_has_more is true. Sources are read one after another and are not an atomic snapshot."
    }
  },
  "releases": {
    "commit": "7ba1ae306cfbebf01a2829c08ba20396d978a46b",
    "published": [
      {
        "version": "0.2.19",
        "source_revision": "30b6ead3b5c17b638e332768e30ee22ff6c110ac",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/30b6ead3b5c17b638e332768e30ee22ff6c110ac",
        "qualified_at": "2026-09-11T18:30:03Z",
        "node": "live-20260823",
        "runtime_generation": 480,
        "evidence": "Installed source 30b6ead3 on Development generation 480/original store and local/remote worker tools. Supported actual-store copy migrated two boards, 54 sprints and 12 assessment versions, compared converted values before retiring source rows, and reopened with unchanged identity in 20.835s. Installed full plan matched pre-upgrade values excluding only as_of; assessment v12 matched exactly. Independent review checked actual wording history and a carried disposition. Focused relational, migration/rollback, model/generator, wire-budget and site collector/renderer checks passed; no full-suite, new cold-install or federation trial. Legacy empty schema declarations remain; no ordinary JSON fallback or startup audit. Details docs/releases/0.2.19.md."
      },
      {
        "version": "0.2.18",
        "source_revision": "53595059c51d79e84133f8ac7df1b5b002118c7f",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/53595059c51d79e84133f8ac7df1b5b002118c7f",
        "qualified_at": "2026-09-11T15:35:35Z",
        "node": "live-20260823",
        "runtime_generation": 479,
        "evidence": "Installed source53595059 on Development generation479/original store and local/remote worker CLIs. From outside a repository, source status read a completed publication, the actual old pending publication and an absent key, each with exit0 and identical output to the existing native query. Padded copied key succeeded; plain pending advice distinguishes waiting from deliberate resume. No old Action mutation or repair. Focused TestSource(Status|Publish|Command) passed remotely after initial route and review-correction failures; installer command-double tests passed. No new daemon operation, schema or Action behavior; no full-suite, cold-install or federation rerun. Details docs/releases/0.2.18.md."
      },
      {
        "version": "0.2.17",
        "source_revision": "4016bbd1ee164bebd4cbac6c7e1b1d8e0909d9a1",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/4016bbd1ee164bebd4cbac6c7e1b1d8e0909d9a1",
        "qualified_at": "2026-09-11T11:54:21Z",
        "node": "live-20260823",
        "runtime_generation": 478,
        "evidence": "Installed source4016bbd1 on Development generation478 with original store and on local/remote worker tools. Corrected the actual current sprint from version2 to3 without changing its ID, original selection, stories, links, rationale or unreviewed state. Separate read recovered prior wording and author/time; compact plan omitted history. Latest delivered review and recent reviews unchanged. Native43 focused tests+7 subtests passed; root11 boundary tests and final4 update/help cases passed, with overlap. Public101 collector/renderer tests and build passed; installer command doubles passed. No production schema change, full-suite, cold-install or federation rerun. Details docs/releases/0.2.17.md."
      },
      {
        "version": "0.2.16",
        "source_revision": "ddac9eceeab09162cb864129ed777cdd22c1b741",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/ddac9eceeab09162cb864129ed777cdd22c1b741",
        "qualified_at": "2026-09-11T10:51:28Z",
        "node": "live-20260823",
        "runtime_generation": 477,
        "evidence": "Installed source ddac9ece on Development generation477 with original store and on local/remote worker tools. Same-input missing Work read/update, kept repl.call and interpreter-only failure changed transition/unknown to transition/not_applied without changing reason/message. Actual Work update survived a later refused read; whole evaluation remained unknown. try-call retained individual query/none error as data. Final combined126 focused kernel/daemon/protocol/CLI tests, including native publication/reporting, and installer command doubles passed remotely. Controlled tests cover genuine uncertainty and host mutation before panic. No full-suite, cold-install or federation rerun. Details docs/releases/0.2.16.md."
      },
      {
        "version": "0.2.15",
        "source_revision": "0d6f96db3a88c9cefbc07b92da3e9f49874abecd",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/0d6f96db3a88c9cefbc07b92da3e9f49874abecd",
        "qualified_at": "2026-09-11T09:14:22Z",
        "node": "live-20260823",
        "runtime_generation": 474,
        "evidence": "Installed source 0d6f96db on Development and local/remote worker tools; original store retained. Updated actual publish-and-report shared method, adopted with keep in a separate environment and reopened. Live installer publication 8689ffd4 through that method recorded the same Work ID and progress returned in its compact reply. Replaying the original publication key with a missing Work target preserved published commit plus full resource_not_found/not_applied report failure; HEAD unchanged. Same-caller detail query before/after replay showed one execution and one receipt; original-key resume retained commit/details. Native result/CLI/recovery 57 focused tests and actual-example controlled/connected tests passed on droplet; installer command-double tests passed. Fixed captured-data byte comparison, not a live speed or billing benchmark. Generic REPL duplication remains. No full-suite, cold-install or federation rerun. Details docs/releases/0.2.15.md."
      },
      {
        "version": "0.2.14",
        "source_revision": "787bab4290c06949dc29110bf71e22ddb9c02949",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/787bab4290c06949dc29110bf71e22ddb9c02949",
        "qualified_at": "2026-09-11T07:58:47Z",
        "node": "live-20260823",
        "runtime_generation": 473,
        "evidence": "Installed reviewed source787bab42 on Development and local/remote worker tools. Existing guidance and shared reference records retained IDs/digests through generated0009 upgrade. Grok Work60583f6f independently found Meridian calibration by subject, read the returned reference and produced the correct handoff; actual harness calls/results inspected. Claude2093 verified nonreader current/exact/Lisp reads and body/metadata writes refused, with name/body/purpose/status/source discovery empty; root confirmed original revision unchanged. Shared guidance/onboarding/Work usable. Native selected tests and two connected process workflows passed; installer command-double tests passed. Scope cannot prevent an authorized reader quoting into shared Work, which this synthetic trial demonstrated. No confidentiality, isolation, cold-install or new federation qualification claim. Details docs/releases/0.2.14.md."
      },
      {
        "version": "0.2.13",
        "source_revision": "26fd0d0868c82c4c2091dcd7795c401b7fc3869a",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/26fd0d0868c82c4c2091dcd7795c401b7fc3869a",
        "qualified_at": "2026-09-11T06:27:09Z",
        "node": "live-20260823",
        "runtime_generation": 472,
        "evidence": "Installed reviewed26fd0d08 bundle on prepared development node and local/remote worker tools. Exact previously failing source.keys-20260911 now returns invalid_input/invalid_source_publication_input with public format, example and omission guidance, state not_applied; HEAD and held README remained unchanged. Legal key source-keys-20260911 published README23f08a6b; direct read and resume returned the same commit/session without another commit. Prior0.2.12 key retained a63d499f and its original session. Focused source/recovery/CLI tests76.623s and0.047s; affected post-review checks11.446s. Public installer command-double tests passed. No session mapping, migration, cold-install repeat, federation repeat or full suite. Details docs/releases/0.2.13.md."
      },
      {
        "version": "0.2.12",
        "source_revision": "3779358131c95ad0d228be3c0e48b4345d07a90e",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/3779358131c95ad0d228be3c0e48b4345d07a90e",
        "qualified_at": "2026-09-11T04:43:36Z",
        "node": "live-20260823",
        "runtime_generation": 471,
        "evidence": "Two separate existing Ubuntu VMs retained original stores/callers and used signed Tailcat peer calls through ordinary native handlers, with no A-side B login key or B-side agent. Initial draft: all five B reads, process user/cwd, exit17, binary streams, truncation, timeout, revocation refusal and actual111s Astra worker comparing two synthetic datasets through kept Lisp. Final37793581 bundle: accepted B command interrupted by orderly daemon stop returned CLI1/peer_transport_failed/unknown/retryable=false, not an external timeout; stopped-B read returned structured deadline_exceeded in33s including SSH overhead; first independent read after restart succeeded in8s with unchanged pairing/guidance; kept Lisp again returned evening counts3/1/1. Development node and local/remote worker tools upgraded from same bundle. Focused Tailcat/HTTPStream33.564s and selected race count3 19.854s; independent review accepted. Silent partitions during established calls still require caller deadlines; no automatic retry, detached jobs, full AAuth flows, cold-install repeat or full suite. Details docs/releases/0.2.12.md."
      },
      {
        "version": "0.2.11",
        "source_revision": "6bd22458012c17910b71d5e1807418f2e7684792",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/6bd22458012c17910b71d5e1807418f2e7684792",
        "qualified_at": "2026-09-11T00:41:28Z",
        "node": "live-20260823",
        "runtime_generation": 470,
        "evidence": "One retained bundle from published6bd22458 installed on existing development node, local/remote worker tools and original Ubuntu recipient guest; original stores and callers retained. Recipient new timebox artifact built by author CLI, transferred alone, activated with named progress32.12s and returned useful fits/remaining results; prior agenda still worked. Repeat14.34s kept PID13186, generation6 and application digest; four prior package selections unchanged. Real service process132.786s passed first use, unchanged repeat, external selection restoration without restart, and interrupted predecessor-linked update resumed exactly once with changed Lisp result. No Organization Work/harness setup in process fixture or ordinary activation; current local-authenticated claim relation fixes the setup/enrollment mismatch without changing identities. Focused42activation tests10.038s, local-claim20.761s and covering local-auth/refusal24.105s; independent source and final delta reviews accepted; public installer15 command-double scenarios passed. No cold-install repeat, full suite or controlled performance benchmark. Details docs/releases/0.2.11.md."
      },
      {
        "version": "0.2.10",
        "source_revision": "c2f56cbf2e0f9099a372ed9a5005e234685bee1b",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/c2f56cbf2e0f9099a372ed9a5005e234685bee1b",
        "qualified_at": "2026-09-10T23:34:05Z",
        "node": "live-20260823",
        "runtime_generation": 469,
        "evidence": "One retained bundle from published c2f56cbf installed on existing development node and local/remote worker tools; same store ready at generation469 with no repairs. Four full SQL/ORM sources retained separately, with native full-body/status/source readbacks unchanged and live REPL full-decision read. Updated organization guidance exposes discovery. Unprimed Grok67c76df0 and Astra706975d6 found the originals and correctly reconciled corrected ORM reasoning, current decision, installed0.1.25 delivery and dated limits. Agy first c30868f1 searched repository files and missed delivery; after older manual prompts were aligned with existing setup guidance, fresh Agy e77ed530 retrieved all4 but misexplained ORM rejection. Both limitations retained, not counted as complete semantic passes. Full source and correction reviews accepted; focused native/CLI/affected migration/model checks and real two-actor process/restart45.321s passed. Public bootstrap pin passed15 command-double scenarios; no new cold installation, full suite, automatic source ranking or broad model-comparison claim. Details: docs/releases/0.2.10.md."
      },
      {
        "version": "0.2.9",
        "source_revision": "62fdf5feb34e85d5e1f4d0f3d731e28d525b9d38",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/62fdf5feb34e85d5e1f4d0f3d731e28d525b9d38",
        "qualified_at": "2026-09-10T20:59:28Z",
        "node": "live-20260823",
        "runtime_generation": 468,
        "evidence": "Installed 0.2.9 from exact public source 62fdf5fe on the existing development node and local/remote workers. Fresh prepared Grok completed the activation recommendation in Work 826b6342, applied optional-assurance guidance and left the feature unscheduled. Fresh Agy completed showcase correction Work 2163c789 using default organization without a selected session; corrected guidance-versus-plan meaning, with subsequent editorial excerpt refinement. Both used installed help and native guidance without the originating conversation or in-run coaching. Full help patch and wording delta independently reviewed; 74 top-level/298 focused cases, 12 offline help executions, 15 installer command-double scenarios and 9 showcase checks passed. Node ready with existing store. No full suite, new authentication, cold installation repeat or activation-refactor claim."
      },
      {
        "version": "0.2.8",
        "source_revision": "c5e0709f0b854bbb90891dfec8a2dc04ada22c7a",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/c5e0709f0b854bbb90891dfec8a2dc04ada22c7a",
        "qualified_at": "2026-09-10T19:57:12Z",
        "node": "personal",
        "runtime_generation": 4,
        "evidence": "Independent first author created and built the public agenda artifact without a daemon, profile, repository clone or compiler API; 7 Sidecat calls including 5 help. Independent fresh-account recipient used the exact c5e0709f bundle and public artifact SHA2561d2b18588d757164deb9f8e24b3c16ad2b738d8c31f11fa9b1ca3c904baf4cf6: literal setup node .92.92s, relative artifact activation101.07s, all four documented outputs correct. Restart12.58s returned ready on first status and use; unchanged setup24.52s retained caller/store/default organization/package application/finished meeting Work and revision/selected session, generation4 without extra restart. Root read actual outputs and independently repeated ready/status, fit and retained Work reads. Earlier dot-path failure retained; no workaround or manual package prerequisite seeding. Archive64d50bf86808d125b8b15517848b61414e8f19b329f975c5b5999af0bca8aadc. This qualifies the supplied bundle and public package, not another cold bootstrap build, provider login, VM reboot or whole-source suite."
      },
      {
        "version": "0.2.7",
        "source_revision": "31c9630156337613a1551325f62692c1982c6915",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/31c9630156337613a1551325f62692c1982c6915",
        "qualified_at": "2026-09-10T15:16:26Z",
        "node": "personal",
        "runtime_generation": 2,
        "evidence": "Independent fresh Ubuntu24.04.4 amd64 public-bootstrap trial80245c85 passed using guide8447a409 and source31c96301. One public Go1.26.2 cold build produced the actual release bundle; full script11m31.685s. Node restart5.523s followed by first status ready and unchanged saved Work. Full script rerun17.649s reused the bundle with no build or service restart and the same caller/store/Work. Nine comparable guide actions under the original23 exclusions; ten literal commands including PATH export. Four extra rerun commands and separate diagnostics are not included; one wrong-directory checksum diagnostic was corrected, with no product failure. Root retained and checked the actual archive and independently read live status/Work. The same bundle updated the development node and Code2 worker; original guest upgrade7dc5b29f retained both finished model results and login, with first status after restart ready. No duplicate cut, local Go or full suite. The earlier0.2.6 guest model trial3936f46f remains the signed-in execution evidence; fresh signup and hosted binary delivery are not claimed."
      },
      {
        "version": "0.2.6",
        "source_revision": "94fe761d13b9777a75e9efba745682400e06aecd",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/94fe761d13b9777a75e9efba745682400e06aecd",
        "qualified_at": "2026-09-10T09:26:15Z",
        "node": "personal",
        "runtime_generation": 7,
        "evidence": "Preparation is qualified; the full first-worker story dbd499c7 remains partial. Engineering 510a071a, release 36bfc207, independent guest reader 46932821. On the Ubuntu 24.04 amd64 guest previously installed through the published 0.2.4 source route, the final 94fe761d bundle passed generated worker upgrade (1.659s), node update (18.013s), and a new worker setup with real service restarts (8.731s). Unchanged node and worker setup passed (11.359s and 2.098s), preserving generation 7, service PIDs, identity, both Work revisions, and the original failed turn. The original 60bb1126 candidate failed its five-second readiness allowance; an unchanged rerun recovered, but its one Codex task failed with 401 because the guest was not signed in. No model task was dispatched on the amended bundle. An existing development-login Astra process separately read and updated Work; that is not guest qualification. Focused remote checks and independent reviews passed. Two candidate builds were needed after the live readiness finding; the original remains unqualified. The same final binaries are installed on the development node (ready, generation 465) and idle Code2 worker. No local Go build, full-repository suite, new cold 0.2.6 installation, signed-in guest result, active-task resume completion, second useful task, other platform, or federation is claimed. Readiness error wording remains follow-up."
      },
      {
        "version": "0.2.5",
        "source_revision": "0c60fa6b871276d908748d0774da05278c1e48e0",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/0c60fa6b871276d908748d0774da05278c1e48e0",
        "qualified_at": "2026-09-10T07:23:35Z",
        "node": "live-20260823",
        "runtime_generation": 464,
        "evidence": "Organization-guidance storye5ece65e, engineeringf717beb0, source0c60fa6b871276d908748d0774da05278c1e48e0. Five runtime tools cut once under the shared droplet Go lock; prepared installers updated the development node and Code2 worker. Native default read succeeds without guidance. Initial live import11a2b72c/revision026cb131 preserved all five prior baseline sections with actual importer attribution. Same fresh Astra reader in Work8cc593d4 discovered and used026cb131, then independently recovered and applied revised8cda8896 on its next pickup through onboarding and org guidance: two guidance calls each,12 and5 total task calls,zero failures,no external files/copied guidance/supplied helper name. Actual shared updater produced the second revision; adopted shared reader recovered current native guidance after saved-environment reopen. Combined package-free real daemon/client testaf0bff02 passed58.056s after missing-command RED; second-member access, exact history, restart, clear and ordinary Work with absent/policy-looking guidance exercised. Native, CLI, Lisp consumer and integration reviews approved. No local Go or full repository suite. Agent interpretation observed on this bounded note task, not guaranteed model compliance. Public hosted binaries, end-user upgrades, other platforms and fresh-install requalification are not claimed."
      },
      {
        "version": "0.2.4",
        "source_revision": "b001f956412f29ae7a9d186f13b702c31a20c2fe",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/b001f956412f29ae7a9d186f13b702c31a20c2fe",
        "qualified_at": "2026-09-10T05:53:53Z",
        "node": "personal",
        "runtime_generation": 3,
        "evidence": "Fresh-install story7ef3659d, engineering2060b729, test7f8b65d4. A fresh reader followed public guide81f43003 on Ubuntu24.04.4 amd64,2vCPU/2GiB,no swap,5.1GiB initially available disk. Public Go1.26.2 download and checksum, public Git checkout at b001f956412f29ae7a9d186f13b702c31a20c2fe, and one cold five-artifact build passed; build/dependency download elapsed9m59.970s. Setup reached ready phase=complete in22.592s. Ordinary Work e27c65c8ab490202ed4e84f5efd20fda retained the same intent and revision through service restart, identical setup rerun11.348s, and actual guest reboot. Post-reboot node personal ready generation3 with unchanged store and enrolled caller. No prepared source,binaries,caches or credentials were supplied; no undocumented repair or resource change. One transient unavailable status after service restart resolved on the next documented check. Root read the command transcripts and generated artifact record. Source components and guide had independent reviews; no full-repository suite or second build. Public source installation is qualified, not hosted binary delivery, end-user upgrades, other platforms, provider setup or federation. Existing development node remains0.2.3."
      },
      {
        "version": "0.2.3",
        "source_revision": "de68aa41020a82f34a548f16afd2f5cad92da082",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/de68aa41020a82f34a548f16afd2f5cad92da082",
        "qualified_at": "2026-09-10T04:38:10.490613318Z",
        "node": "live-20260823",
        "runtime_generation": 463,
        "evidence": "Build Work50d849c2 cut four artifacts once from exact de68aa41020a82f34a548f16afd2f5cad92da082. Installed prepared-caller probe320209e7 observed CLI0.2.3 at that source and daemon ready generation463 with no repairs. From /tmp, published help and catalog exposed working-context without a supplied helper name; use --keep adopted it in a separate named environment, calls recovered organization direction/native selected plan/Work, and reopen followed by another call reused the kept binding without reimport. Core list/adopt/call/reopen/call took5 CLI calls; complete probe18 including help, runtime discovery, Work reporting and one report-length refusal/retry. Zero method-call failures. Native selected planning data still lagged active installation Work; reconciliation is separate. Shared methods are optional organization content; no automatic adoption/execution. Prior implementation/review records hold source checks; this qualification did not run a daemon-restart test, full suite or fresh public installation. Later archive/installer changes are not included in0.2.3."
      },
      {
        "version": "0.2.2",
        "source_revision": "10f8f81a694db688212d1ca68e81e84fa1951c39",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/10f8f81a694db688212d1ca68e81e84fa1951c39",
        "qualified_at": "2026-09-10T00:46:16Z",
        "node": "live-20260823",
        "runtime_generation": 462,
        "evidence": "Source-publication story500ae071; accepted final review38a48f83 and docs correction4ac6ada5. Focused kernel/daemon/CLI/Lisp checks passed on the droplet, including existing managed temporary-Git failed-push/lost-reply fixtures. Buildf8ca809d cut the four artifacts from exact10f8f81a; node and local/droplet worker installation and running images verified in qualification62f88f3f. Actual CLI publication61d2e95e, native API site publicationb4055b50, and adopted/kept Lisp publication9b8249eb by Code2 are remote-confirmed. Colleague Work182251ce stayed active after its commit report and finished separately. A refused Work report preserved the successful publication result. The real pre-upgrade key source-preflight-20260909-01 reads/resumes with identical original fields after restart, and its harness session is closed. Current guidance updated through shared agreements and workspace publication2d829f4b. Site refresh used the new caller and published1fe7b5fa. Test-only repair2d795a88/88b8b04 passed Pages pipeline2835326701; served progress JSON matches the published file and HTML reports its00:24 UTC cutoff. Site readability is a separate unfinished backlog item. No full Sidecat suite/build audit, new infrastructure or independent-store federation claim."
      },
      {
        "version": "0.2.1",
        "source_revision": "b3c284cea2b253ae9c2e4232c987570c27b5b200",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/b3c284cea2b253ae9c2e4232c987570c27b5b200",
        "qualified_at": "2026-09-09T21:47:31Z",
        "node": "live-20260823",
        "runtime_generation": 461,
        "evidence": "JSON callable adapter Work461f0d5e, independent reviewc88a33ad, integrationbf637b32 and actual colleague7d781707. Root's focused remote interpreter/kernel/daemon/CLI/real-process checks passed on exact code; real-process acceptance35.667s includes kept scoped helper after restart. Sourceb3c284ce is installed on node and local/droplet workers; running images and CLIs report0.2.1, native readygen461, schemafacd79ac unchanged. Code2 applied exactly one agent_interpretation JSON field through shared update-working-agreements; baseline63374caa became2c19eb7b. Root independently compared exact patch and unchanged name/principles/direction/constraints/operator_statement/entity/organization. Code2 reopened kept working-context and recovered the same new guidance; root's existing kept method also recovered it without readoption. Two useful edit/recovery calls plus separate preparation and qualification reads, not a universal two-call onboarding claim. Shared methods remain optional organization library content, not builtins or automatic governance. No full suite, new schema, credentials, infrastructure or independent-store federation claim. Hourly site publisher active."
      },
      {
        "version": "0.1.58",
        "source_revision": "462c035f8fe9f365ccff449ff0807cbcf8595dc0",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/462c035f8fe9f365ccff449ff0807cbcf8595dc0",
        "qualified_at": "2026-09-09T17:57:54Z",
        "node": "live-20260823",
        "runtime_generation": 459,
        "evidence": "Source462c035f is installed on the node and existing local/remote workers. Root set three current organization labels in one prepared org labels call. Actual completed Work498cf9a3 returned Codex/Codex2 names with zero changes to every other field against its pre-label baseline. Remote colleague qualification5aca3992 independently read that Work in native JSON and human form, plus maturity and compact/full planning/sprint views; labels covered returned authors and full direct Work reads preserved original references/text. Compact/full planning previews were checked as declared prefixes, not mistaken for complete text. The actual hourly publisher recovered original pending keysite-refresh-26d85282c66e470db4f43816b3a925db without state edits or a new key, publishing only its two changed files as16ca3868, then fresh state asde05f005. Reviewed native/storage and CLI checks passed; root combined CLI verification passed2.849s. One generated additive label-table migration; no identity/authority/binding change or startup/history audit. Schema-changing installation startup16.390610s is an observation, not a normal-start guarantee. Site source/retained helper integration and public named rendering remain separate f12 work; this qualifies the runtime and publication repair, not that complete website story. No full-repository suite/build or new infrastructure."
      },
      {
        "version": "0.1.57",
        "source_revision": "993000c23a535d4e06c28234005022e44361b2b6",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/993000c23a535d4e06c28234005022e44361b2b6",
        "qualified_at": "2026-09-09T15:46:38Z",
        "node": "live-20260823",
        "runtime_generation": 458,
        "evidence": "Source993000c2 is installed on the node and existing local/remote workers. In controlled live trial498cf9a3, remote codex2 moved deliberately misfiled queued documentation Work744eba23 into Sidecat, cleared its project, repeated clear and re-associated it; separate reads preserved the exact original unit, queued lifecycle, intent and organization through correction. Only then did it start and finish that same useful task. Root independently confirmed source backlog cleanup, unchanged main backlog order, readable source agreement/review after the move and current project metadata on its retained Work reference. A subsequent editorial result correction appeared in live Work while the saved review snapshot stayed unchanged. Qualification session93184141 was closed and the original development selection restored. Focused native/CLI/correction/recovery/sprint checks and independent review passed. Root fixed the obsolete compact-test representation expectation and ran its previously unreached Project assertion successfully (SQLite7.875s, CLI0.071s). Live trial covers queued same-org correction; populated-field, active/finished and sparse cases are supported by focused tests, not separate live trials. No schema, permission, owner or history-rewrite machinery, full-repository build/suite or new infrastructure. Startup sample7.813737s is an observation."
      },
      {
        "version": "0.1.56",
        "source_revision": "ae4135428e59bfb5c6a2c2de6fc88d11c65f2c4a",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/ae4135428e59bfb5c6a2c2de6fc88d11c65f2c4a",
        "qualified_at": "2026-09-09T14:56:50Z",
        "node": "live-20260823",
        "runtime_generation": 457,
        "evidence": "Source ae413542 is installed on the node and existing local/remote workers. In qualification5d1154d9, remote codex2 discovered another actor's real earlier Sidecat Work dd0db9e6 through active --unassociated without a supplied ID, read its useful context and associated that same item with the prepared project. Its unit, lifecycle, intent, progress, authors and timestamps were preserved; the record disappeared from unassociated discovery. Root independently read the unchanged lifecycle and authored text and confirmed exclusion. Root also read real completed Work with finished --unassociated; finished association is covered by focused store tests, not claimed as a separate live colleague trial. Native/CLI/new discovery and recovery cases passed; expanded store selection has one isolated unchanged-base test expectation failure, retained as queued54977232. Independent implementation review accepted. No schema, ownership or access changes, full-repository suite/build, historical audit or new infrastructure. Current start-to-ready sample8.790816s is an observation, not a guarantee."
      },
      {
        "version": "0.1.55",
        "source_revision": "dd18bdcb3f91e03fb36193b68f7311d64aec8e9a",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/dd18bdcb3f91e03fb36193b68f7311d64aec8e9a",
        "qualified_at": "2026-09-09T14:20:01Z",
        "node": "live-20260823",
        "runtime_generation": 456,
        "evidence": "Source dd18bdcb is installed on node generation456 and existing local/remote workers. Actual prepared-project record created dated assessment version1 with19 rows; remote codex2 read returned the identical scope, author/time and document. The one-call collector changed then reported unchanged. Site4cf520f7 and native projection are published, Pages2833386212 succeeded, and all5 public artifacts match the actual-data droplet build. Chromium153 desktop1440 and narrow390 checks passed exact row/date/version presentation, closed optional disclosures, keyboard toggling, no page overflow and narrow keyboard table scrolling. Focused native/CLI/model/populated-upgrade checks and independent reviews passed; site108 checks, refined7 checks and actual-data7 checks passed without a full-repository suite. The generated maturity table follows the retained queued boundary; no prior schema bytes or Work citations are reconstructed. Earlier snapshots remain available by version; labels are authored judgments, not computed scores. No full-repository build/suite or new infrastructure."
      },
      {
        "version": "0.1.54",
        "source_revision": "ff11719f2f627e9d143c1fb267be123c5ebef324",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/ff11719f2f627e9d143c1fb267be123c5ebef324",
        "qualified_at": "2026-09-09T13:17:06Z",
        "node": "live-20260823",
        "runtime_generation": 455,
        "evidence": "Published source ff11719f is installed on node generation455 and the existing local/remote workers. In actual use, codex2 revised pre-upgrade task7cc66d63 while it remained not_started and sessionless; root recovered current text through backlog and both authors through history. The prepared local worker then started that same ID with the exact revised intent and inherited session. Its useful maturity-preparation result is still in progress at this qualification cutoff. Existing corrected result76ecec6d retained its exact intent, result and lifecycle through upgrade. Focused queued-lifecycle tests and populated migration/reopen checks passed; the installed manager refusal exposed and repaired in603481be passed explicit first-turn RED/GREEN. Independent reviews4f3c944c and46c56414 accepted. Normal final start-to-ready was7.473554s, not a universal guarantee. No full-repository build/suite or broad history audit."
      },
      {
        "version": "0.1.53",
        "source_revision": "b254a0e1405c432290d510f58e5e3e35149042a7",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/b254a0e1405c432290d510f58e5e3e35149042a7",
        "qualified_at": "2026-09-09T10:23:21Z",
        "node": "live-20260823",
        "runtime_generation": 453,
        "evidence": "Source b254a0e1 installed on the node and prepared local/remote workers. IRC qualification Work cd97c1b8 used an installed IRC client with the existing codex profile to send a useful source-checkout question; native channel position2 triggered prepared Astra-low codex2 through sideloopd without a supplied Work ID. Its three-line answer at position3 appeared under codex2 and replayed after reconnect. Client channel sync completed in7-8secs after the focused query repair, versus the earlier606secs. Ordinary invited join succeeded without Work context after Message2c923107 activation. Focused adapter/CLI tests and independent source reviews are retained in dbfbdd08,8956c21e,f844c05f; package repair/focused checks in3efa690f,b9a82c2d; final four-artifact cut in ecadc99f. Temporary client, adapter and responder exited normally; normal managers and profiles unchanged. Limits: loopback one prepared actor per adapter, latest16 replay, no complete native roster/presence or independent-store federation; daemon turnover requires adapter restart and client reconnect. No full-repository build/suite or new infrastructure."
      },
      {
        "version": "0.1.52",
        "source_revision": "d745f826526e58b8c7f5a96f530da35d9e1defe6",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/d745f826526e58b8c7f5a96f530da35d9e1defe6",
        "qualified_at": "2026-09-09T07:52:55Z",
        "node": "live-20260823",
        "runtime_generation": 450,
        "evidence": "Source d745f826 installed as 0.1.52 on the existing node and prepared local/remote workers; node ready450 with unchanged store/schema. Normal journal start-to-ready was 7.584476s, an observation rather than a universal bound. Source c26533b8 and reporting correction4b3515d8 passed focused droplet tests; Claude a65aa232/1467 and B a417c6f1 reviews accepted the final patch. Live Code2 Work4b28c1bf configured an absent local destination without supplying the inherited repository URL, then source prepare cloned actual GitLab main at d745f826. A repeat reported already-current, and the colleague followed the cd guidance and read source for the next upgrade story. Existing checkout/default source profile and launch context were preserved. Root independently read the returned report through shared review-brief and checked the new checkout HEAD, clean status, origin and source binding. Missing/empty destinations, interrupted-clone retry, source preservation, branch/revision/isolation and copyable profile/path guidance have focused tests. Upstream needs an initial commit; no concurrent-directory arbitration or mixed-version qualification is claimed. No full-repository suite/build or startup audit added."
      },
      {
        "version": "0.1.51",
        "source_revision": "47cc598f57ad35429e6e99ee3670395f0ba0eb9b",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/47cc598f57ad35429e6e99ee3670395f0ba0eb9b",
        "qualified_at": "2026-09-09T06:23:17Z",
        "node": "live-20260823",
        "runtime_generation": 449,
        "evidence": "Source47cc598f installed as 0.1.51 on the existing node and prepared local/remote workers. Measured journal Started-to-ready was7.485435s, versus prior profiled0.1.50 observation19.810263s on this node; new run was unprofiled, so these are observed starts, not a universal bound or identical-instrumentation benchmark. Ordinary installed-state binding now decodes the requested retained layout without recursively reproducing schema ancestry. Focused additive-state mapping/read-write/reopen tests passed with one requested-layout lookup; explicit full-reader/compiler paths remain. Worker snapshots retain optional successful-observation time and CLI labels it separately from process state/exit. Source implementations96f15c30/6bf6f1e2 and independent reviews37383b80/5974355a passed. Live package message send, organization roadmap read, native Work and existing shared project-brief succeeded. Returning prepared worker2effb6c8 recovered selected sprint/progress; its manager then recorded finished at2026-09-09T06:20:16.45771038Z, shown correctly in JSON/plain status. Retained Grok failure still has last-observed active without timestamp while native Worke7eacabc is finished; new CLI says observation time unavailable and shows exit1 without fabricating a fresh state or rerunning Grok. No extra polling or retries, no new runtime audit, cache or database schema, and no full-repository suite/build."
      },
      {
        "version": "0.1.50",
        "source_revision": "f6abe9033eaef567112c12c4452cf52771a1177e",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/f6abe9033eaef567112c12c4452cf52771a1177e",
        "qualified_at": "2026-09-09T05:18:24Z",
        "node": "live-20260823",
        "runtime_generation": 447,
        "evidence": "Source f6abe903 installed as 0.1.50 on the node and prepared local/remote workers; node ready447. Focused native/CLI tests and combined review6898caec passed. Root integration9d8b925c tests preserve original completion order, since filtering, pinned pagination, repeated correction and upgrade/reopen using a lazy GORM-generated completion reference without historical backfill. In live qualification18eef072, Code2 used one work update --result to correct original finished Work76ecec6d. Its result fd5db42b carries Code2's actual author/time; original result cc9ec65c remains in bounded history, and Work identity/status/intent/progress are unchanged. Root independently recovered the exact corrected report, writer and time through native JSON, plain CLI and the shared review-brief. Code2 adopted the existing shared helper into its working environment when absent; no helper source change was required. Corrections supply a complete current result, not addendum fragments; finished listing is not a correction feed, and frozen reviews remain unchanged. Same-store colleague workflow, not independent-node federation; no complete evidence requirement, startup audit or full-repository suite/build added."
      },
      {
        "version": "0.1.49",
        "source_revision": "1d8f1996443f21fef819508bee2fb10c699e3109",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/1d8f1996443f21fef819508bee2fb10c699e3109",
        "qualified_at": "2026-09-09T04:21:57Z",
        "node": "live-20260823",
        "runtime_generation": 446,
        "evidence": "Source 1d8f1996 installed as 0.1.49 on the node and prepared local/remote workers; node ready446. Component and combined reviews df9d2b17/d50f3692/8f0de3aa approved; focused Lisp, native-store and actual consumer/service checks passed on the droplet. Shared helper-status revision1c997196 was adopted and used by Code2 in live qualification aa5e297a. One ordinary-environment report found real stale dispatch-review and project-brief roots; their issued --keep adoption commands were used deliberately. After reopen both matched current shared revisions, explicit dispatch-review prefix/worker settings survived, and updated project-brief recovered the actual project plan. Root independently reread all three adopted methods through the remote prepared caller and confirmed matching upstream/shared records. Claude usability1e260865 supplied clearer setup, named-environment and cursor instructions; these descriptive changes require no daemon rebuild. Scope is public binding upstream revisions, not local equality, savedness or transitive dependency currency. No automatic updates, schema change or startup/history audit added."
      },
      {
        "version": "0.1.48",
        "source_revision": "d0679a8284ea503a383c38b1f41e50bcceb8df53",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/d0679a8284ea503a383c38b1f41e50bcceb8df53",
        "qualified_at": "2026-09-09T02:27:07Z",
        "node": "live-20260823",
        "runtime_generation": 445,
        "evidence": "Source d0679a82 installed as 0.1.48 on the node and prepared local/remote workers; node ready 445. Claude review1401 approved the exact two-file patch; implementation3ce0ace3 retained focused planning RED/GREEN, with GREEN exit0 at0.078s. Normal four-artifact cutdb431638 completed. In actual installed use, compact project plan displayed each of three linked tasks exactly once with its native short objective and objective clipping marker. Native JSON supplied the same descriptions; explicit full output still displayed the detailed Work sections and direct read hints. No new native call, field, flag or schema. Current sprint36dc2bb2 covers task identification, not all future operator-reporting capabilities."
      },
      {
        "version": "0.1.47",
        "source_revision": "d2d7ec91770c7f0607a23d13f46519ff15b6c143",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/d2d7ec91770c7f0607a23d13f46519ff15b6c143",
        "qualified_at": "2026-09-09T01:59:17Z",
        "node": "live-20260823",
        "runtime_generation": 444,
        "evidence": "Source d2d7ec91 installed as0.1.47 on the node and prepared local/remote workers; node ready444. Claude1388 independent review approved; integrated focused check67bf2ff4 passed seven matching tests. Normal four-artifact cutc0454d70 exited0. Codex2 qualification2adeca46 associated root-created ordinary Work4cccb431 with its prepared sidecat project using work plan ID. Complete before/after reads differed only by added project; repeated association was identical, and project-scoped active plus shared review-brief recovered the original task. Root independently confirmed unchanged original fields and bounded history, and original ID in project-active view. No schema change, history audit or federation bootstrap; association correction and broader colleague discovery remain backlog follow-ups118ea007/7685a1da."
      },
      {
        "version": "0.1.46",
        "source_revision": "0fb80e069ea92521f3f125622dfe035c4af858b1",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/0fb80e069ea92521f3f125622dfe035c4af858b1",
        "qualified_at": "2026-09-09T00:12:15Z",
        "node": "live-20260823",
        "runtime_generation": 443,
        "evidence": "Source0fb80e06 is installed on the node and Codex2; node ready443. Independent reviews6aba35f4/c1062ef9 and combined focused droplet tests passed. The actual maturity-page Work d91fdf97 had its current instructions corrected through work update --intent while its progress text and reference stayed unchanged. Native compact planning returned current Work summaries and no prior Work; the shared project-brief73faf0e3 preserved caller settings and returned compact5/5/3 versus full20/20/12 with prior details. The observed plan response dropped from about122k to17k characters while linked Work increased. One normal four-binary cut35610a56; no schema change or history audit. Local worker-manager upgrade and broader colleague/session continuation remain integration work e06e0c3c; this record does not claim the sprint complete."
      },
      {
        "version": "0.1.45",
        "source_revision": "5550168de4a2071d35ebf77dcd89d5b917f850da",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/5550168de4a2071d35ebf77dcd89d5b917f850da",
        "qualified_at": "2026-09-08T22:19:29Z",
        "node": "live-20260823",
        "runtime_generation": 442,
        "evidence": "Prepared colleagues can maintain an explicitly ordered product backlog, select a sprint outcome, link ordinary Work and review delivered or remaining scope. Source5550168d is installed on node, Code2 and local workers; node ready442. Root registered11 real product stories, selected sprint5385c070, linked actual implementation Work and recorded a mid-sprint review. Code2 task73607093 adopted the shared project-brief, recovered that selection and review, and used them to refine the next continuity story. Its new live Work/progress appeared without entering the product board or changing review_work/review_links; Code2 compared two reads. No Sidecat calls failed in that colleague task. Original31 core/model/store and12 CLI tests plus23 focused corrections passed on the droplet; Claude review1be8d521 passed final36af8c0b combined source. One normal four-binary cut, additive generated GORM tables, no startup/history audit or changes to ordinary Work inputs. Shared helper and deterministic site are separate source artifacts: the site's rollout remains pending the observed JSON-configuration helper repair58dd1d31. Raw plan/brief output is verbose and remains operator-view work, not claimed polished. Installer retains prior files/configuration, not database rollback. No full repository suite or extra binary build."
      },
      {
        "version": "0.1.44",
        "source_revision": "2a01b3f29c215a3f3e9faccb17b0488fe806f664",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/2a01b3f29c215a3f3e9faccb17b0488fe806f664",
        "qualified_at": "2026-09-08T20:00:21Z",
        "node": "live-20260823",
        "runtime_generation": 441,
        "evidence": "A busy worker can explicitly mark a pending message batch it has already handled and proceed to queued useful Work without another inbox-only model turn. Source2a01b3f2 is installed on node, Code2 and local B/C/Grok manager; node ready441 with the same store/schema. Engine60d99a59 and native/CLI46d21cdf passed focused RED/GREEN; Claude reviewe1c55cc7 found no integration blockers, and root combined five-package selected tests passed. One normal four-binary cut produced this bundle. Actual Code2 health-review295b5033 read and applied incoming181, marked exact pending180->181 handled and finished. Root observed next Workd2547f86 running with295b5033 as the immediately previous turn, no pending messages or intervening inbox turn. The next task started about8ms after the previous process exited. Health guidance6491a7c5 is included and295b5033 used it successfully: raw local-node refusal did not imply prepared-route failure; status caller authenticated. Omission preserves ordinary inbox turns. No auto-handling on read/finish, no current-turn cancellation, new/grown batches remain distinct, no new schema or history audit. Grok prepared colleaguee7eacabc is running; no completed Grok result or general latency guarantee is claimed."
      },
      {
        "version": "0.1.43",
        "source_revision": "f9e6e9dd1063c3cf89059889490491061bd90988",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/f9e6e9dd1063c3cf89059889490491061bd90988",
        "qualified_at": "2026-09-08T18:04:56Z",
        "node": "live-20260823",
        "runtime_generation": 440,
        "evidence": "A prepared agent can explicitly connect inherited project context to a caller-local checkout, fetch the remote branch, and use a detached linked worktree without another clone. Source f9e6e9dd is installed on node, Code2 and local B/C workers; node ready440 with the same store/schema. Root configured the local binding once and ran installed source prepare: current f9e6e9dd selected, existing two untracked files preserved with kept-dirty/exit1. Engine6f3fface and CLIbe7a2a37 r2 passed one combined32 focused TestSource run12.572s on the droplet; exact tested bytes were published. Cutf5d3cd9f produced one normal four-binary bundle; installer retained prior files/configuration. Actual Code2 source work f7af7ebb is finished: one installed source prepare --isolate call selected f9e6e9dd into its own linked worktree, then Code2 returned a useful two-file recovery-guidance patch with focused RED/GREEN. Parent6b80c19b remains active for review and a second worker following the subsequent publication; that guidance patch is not part of this release. No source checks on ordinary Work, messages or startup, no daemon/schema/auth changes, and no full repository suite or extra build."
      },
      {
        "version": "0.1.42",
        "source_revision": "16de777ef6e0cb8bf99bb2d777a75c2818aa3711",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/16de777ef6e0cb8bf99bb2d777a75c2818aa3711",
        "qualified_at": "2026-09-08T16:40:30Z",
        "node": "live-20260823",
        "runtime_generation": 439,
        "evidence": "Agents can retain useful earlier results when a later operation fails, and prepared multi-turn workers can pick up queued Work without a lead pre-start. Source16de777e is installed on node/Code2/local B+C, node ready439. Actual qualification977bf246 is finished: Code2 adopted/kept/reopened updated dispatch-work; one refused delivery returned Work1ce4af17 plus native not_applied failure, then the exact same ID was sent to B without replanning. B started it, retained progress, automatically continued in a fresh second process, finished and stopped at2/2 with exit0; Code2 report5413d751 and root observed final native state. Claude shared revised dispatch-review and plural work-briefs; root adopted/reopened both, batch-read two real results plus a labelled missing item, and used dispatch-review for useful release-note work1c6f6a1f. C adopted the batch reader and completed that note. Ordinary sidecat/call is unchanged; try-call is opt-in, with no retries/rollback or exactly-once promise. Source RED/GREEN and independent review are in bcc04800/6560a97c/6bfa4d21: daemon9.420s, sideloop5.377s, sideloopd0.031s. One normal four-binary cutf64005b4. No schema/identity/infra changes, historical audits, full repository suite or repeated production restart. Existing local-only worker status diagnostic remains backlog."
      },
      {
        "version": "0.1.41",
        "source_revision": "5f7a90b441c3d4b3e965a27f3f6d813f5715b977",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/5f7a90b441c3d4b3e965a27f3f6d813f5715b977",
        "qualified_at": "2026-09-08T15:38:00Z",
        "node": "live-20260823",
        "runtime_generation": 438,
        "evidence": "Two independently authored helpers now coexist with their own settings and internal functions, and a shared composite preserves its captured versions. Installed matching0.1.41/source5f7a90b4 on node, Code2 and local B/C; node ready generation438. Actual qualification8ef0d647: root adopted in one order, configured/reused/reopened, forked/reset/selectively merged, and distinguished local late binding from pinned adopted composition. Code2 qualification954f0876 adopted in opposite order, retained independent overrides through reuse/reopen, then used shared review-with-check to dispatch reviewd9768f89 under its own actor and execute the returned exact focused Go test on published source, PASS0.025s. Source reviews59f0b13a/1b27abf0 accepted; integrated focused checks passed: Lisp0.405s/kernel2.306s/daemon11.025s/SQLite37.451s/CLI0.060s. Real temporary-store tests cover fresh-service reopen and large scoped data; old artifact identities and flat snapshots preserved. One release cut93c7533a succeeded. No new tables, startup/history auditing or full repository suite. Actual node was restarted once for installation; subsequent scope persistence was exercised through reopen, not another production restart. New scoped snapshots require0.1.41; arbitrary lexical captures/macros remain outside this increment."
      },
      {
        "version": "0.1.40",
        "source_revision": "ac4933b4886beabb6bca3fda90d41eab62f1964b",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/ac4933b4886beabb6bca3fda90d41eab62f1964b",
        "qualified_at": "2026-09-08T12:45:14Z",
        "node": "live-20260823",
        "runtime_generation": 437,
        "evidence": "Installed matching 0.1.40/sourceac4933b4 on node, Code2 and local B/C through prepared maintain targets; node ready and Code2 stable source directory preserved. Parentdeff94ab: native review93513b2b and final CLI review1254 ready. Root integrated focused checks passed: CLI0.264s, sqlite12.728s, kernel0.277s, real REPL/native/store2.915s; producer also completed focused race checks, with one test timing allowance corrected. One release cut5c05c022 exited0. Actual root dispatch-work created Code2 reviewcbf51430, then ONE work wait command returned wait_state=finished, that same Work ID and Code2's final report; no model-visible Work polling was needed. Code2 confirmed installed finished recovery and queued timeout. Root live timeout printed the explicit timeout message and exited124 without starting/stopping the queued item; a live Lisp sidecat/call recovered a completed colleague Work. Ordinary node reads remained available during the wait. No schema change, persisted wait job, full suite or history audit. Finished remains a reported result, not independent outcome verification."
      },
      {
        "version": "0.1.39",
        "source_revision": "0214e9d3ddc4bb97e04c512d6ea729772f6100e9",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/0214e9d3ddc4bb97e04c512d6ea729772f6100e9",
        "qualified_at": "2026-09-08T11:05:40Z",
        "node": "live-20260823",
        "runtime_generation": 436,
        "evidence": "Installed matching 0.1.39/source0214e9d3 on node, Code2 and local B/C using prepared maintain targets; node ready with the same store. Code2 retained its stable sidecat-development directory. Work2769750c: Claude reviewed the ten-file command change at1239; focused CLI and five existing native tests passed on the droplet. Root review refinements reproduced plan misrouting and short-reference creation before correction, then focused CLI passed0.346s. Actual installed work plan ID preserved queued Work339656fa and its intent/project; Claude independently discovered it in backlog and started the same ID in one work start command at11:04:14Z, with Claude actor7741ef5e recorded as the lifecycle writer. Installed abbreviated-reference refusal and start/plan/publication-resume/status-system help were checked. Prior CLI clarity71651cbe is now installed. No schema change, full suite, history audit or independent-node federation claim. Release cut3b8248e7 used one fresh exact-source scratch."
      },
      {
        "version": "0.1.38",
        "source_revision": "3b36ce3f2963a1f6c756316b84b8f61d9ec67273",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/3b36ce3f2963a1f6c756316b84b8f61d9ec67273",
        "qualified_at": "2026-09-08T08:49:45Z",
        "node": "live-20260823",
        "runtime_generation": 435,
        "evidence": "Installed matching 0.1.38/source3b36ce3f on node, Code2 and idle local B/C manager through prepared maintain targets. Same store/schema; no full suite. Core5f077756 and adapterb82d069d focused tests passed. The 0.1.37 candidate failed an actual installed lookup because its test fabricated a managed record absent from native Action submission; it was not qualified. Correction3c8058d6 removes that dependency and resolves the existing actor-scoped deterministic proposal key, with actual native/no-managed-record RED then GREEN (daemon18.556s including current child recovery). Actual installed publish --resume keys e0516405 and127d3578 now exit0 with resume_state=published and their original commits320578f0 andf560691f/receipts219a58db ande1e5eb69, after original sessions closed; source HEADs unchanged. Core real Action/store/Git tests cover repeated rejected push then original-commit success without repeating stage/commit; production rejected pushes were not injected. No history scan, schema change or new normal-path custody. Site consumer/integration remains parent39efd55c until its actual scheduled path is qualified."
      },
      {
        "version": "0.1.36",
        "source_revision": "3fbc91c9571d7f35d1952d4d541ade386e11773a",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/3fbc91c9571d7f35d1952d4d541ade386e11773a",
        "qualified_at": "2026-09-08T06:05:32Z",
        "node": "live-20260823",
        "runtime_generation": 431,
        "evidence": "Matched 0.1.36/source3fbc91c9 installed through prepared local-node and Code2-worker profiles after one droplet cut. Same store/schema c6712d1f; startup20.999666s. Native work.finished and CLI work finished return ordinary completed Work in prepared project/session/caller scope, completion commit order, strict RFC3339 since and pinned bounded pages. Existing current lifecycle metadata and GORM project model; no schema/backfill/startup/history audit. Implementation8fde8f8b:17 distinct focused native/CLI tests pass across final applicable runs; independent whole-core review6826d713 accepted all12 files. Code2 actual-use2a341563 started the pre-existing queued task, checked plain/JSON, exact since exclusion and full-read hint, then finished at06:04:23.862449666Z. Root recovered that task first with limit1 and as sole result since06:04:05.256557616Z despite creation05:21:00Z; creation-ordered list1 instead returned later-created delivery57000855. Claude shared updated project-work-inputs revision5905b3a1 and actual native JSON returned12 finished items; site consumer/public rollout remains delivery57000855. No full suite or repeated cut; installer retains previous selected binaries/config. Minor plain-summary quoting friction observed, not a completion-order defect."
      },
      {
        "version": "0.1.35",
        "source_revision": "67a6f48bf33598835198c9ae7185eec2ba1880a1",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/67a6f48bf33598835198c9ae7185eec2ba1880a1",
        "qualified_at": "2026-09-08T04:53:04Z",
        "node": "live-20260823",
        "runtime_generation": 430,
        "evidence": "Installed matched 0.1.35/source67a6f48b on local node/CLI/executor and Code2 CLI/worker through the prepared installer after one droplet cut. Same store/schema c6712d1f, startup21.747656s. Optional repl eval --json returns ordinary embedded json_value without re-evaluation or changing plain/keep behavior; unsupported/over-budget values retain printed output with JSON error disclosure. Fifteen named native/service/CLI tests passed; independent core reviewcd1a3b2b accepted. Root adopted corrected shared project-work-inputs before restart, then consumed actual JSON with prepared scope, paging and30 full reads after restart. Code2 actual-use2a09b6e0 adopted and consumed it by name in two helper calls, recovering authored Work text as JSON. Actual site sync succeeded with all sources ok and identical generated files; site review57b4 accepted its four-file consumer. Parent7ef2 tracks site publication and restored automation. No full suite, new schema/history path, new limit or repeated cut. Existing transport ceilings unchanged; previous binaries/config retained by installer."
      },
      {
        "version": "0.1.34",
        "source_revision": "facdc01edff30a2824aecf9ca8f8017aba5213c9",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/facdc01edff30a2824aecf9ca8f8017aba5213c9",
        "qualified_at": "2026-09-08T01:10:41Z",
        "node": "live-20260823",
        "runtime_generation": 429,
        "evidence": "Installed0.1.34/sourcefacdc01e from one72.64s droplet cut; four retained binaries match local daemon/CLI/executor and Code2 CLI/manager. Same store/schema c6712d1f; start-to-ready20.759192s. Prepared work plan and topic-filtered work backlog connect colleague pickup while retaining original intent/project, without starting a lifecycle/session at plan time. Existing GORM WorkProject and model transactions suffice; no schema, owner/claim system or history audit. Code2 implementation9107867d recorded focused native/CLI RED and GREEN, native regressions66.498s and final new cases9.874s/CLI0.224s. Claude reviews9299a03a/bd554299 and fresh whole-change reviewfb7c36fd accepted. Root actual CLI/reopen process88f39e6d passed80.257s, including a separate-session colleague, pinned continuation after project switch/restart and original-project completion. Installed actual-use8b969842: root queued a bounded review; Code2 discovered it by topic with no task ID handoff or context setup, started/finished it, and root recovered the result. Code2 consulted help before pickup; root's mistaken incoming-message Work closure instruction caused extra housekeeping, so the entire first-use turn is not claimed as two calls. Root reused kept review-brief after restart and the shared go-test-command for process testing. Staged worker config ownership was corrected during install without another daemon restart. Previous binaries/config remain available; no full suite or repeated cut."
      },
      {
        "version": "0.1.33",
        "source_revision": "a1a5ba66173f85c63096d0792ac6da2f6d5aa0d7",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/a1a5ba66173f85c63096d0792ac6da2f6d5aa0d7",
        "qualified_at": "2026-09-07T23:19:53Z",
        "node": "live-20260823",
        "runtime_generation": 428,
        "evidence": "Installed0.1.33/sourcea1a5ba66 from one24.63s droplet cut; daemon, CLI, executor and Code2 manager match retained binaries. Same store/schema c6712d1f; start-to-ready21.039861s. Four production lines report 'client: daemon is unavailable' for bare Unavailable during valid generic Describe, using the existing error type and retaining its cause. IsUnavailable already worked before the fix; this corrects displayed text, not retry semantics. New decoder and real generic-client RPC regressions failed before the fix and passed after it; focused client0.056s/CLI0.037s, including existing zero-Invoke pre-Describe checks. Claude review541c8d63 accepted with no defects. Code2 actual-use1fc8a915 confirmed installed version/source, normal parent Work read and native reporting; root reused kept review-brief with a short reference after restart. Original incident raw status remains unobserved and no live failure was injected. JSON/stderr behavior, encoded failure validation, deadline and post-Invoke handling are unchanged. No schema, new failure kind, retry loop, full suite or repeated build. Previous releases and rollback binaries/config remain available."
      },
      {
        "version": "0.1.32",
        "source_revision": "16eb4b1ea28f34798d14a3dfbd2bd0c58a031b21",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/16eb4b1ea28f34798d14a3dfbd2bd0c58a031b21",
        "qualified_at": "2026-09-07T22:45:03Z",
        "node": "live-20260823",
        "runtime_generation": 427,
        "evidence": "Installed0.1.32/source16eb4b1e from one58.53s droplet cut; daemon, CLI, executor and Code2 manager match retained binaries. Same store/schema c6712d1f; start-to-ready22.422921s. Root and Code2 actual-use7526e9b9 used normal work read, work history and session review with existing eight-hex references, each succeeding in one call with matching canonical IDs and no expansion lookup or fallback. Root also saw canonical history continuation. Focused exact-source tests passed: kernel0.038s, SQLite48.108s, CLI0.179s, including native and top-level CLI coverage. Independent review9d64fbf1 and Claude task review4e077a60 accepted. Claude's minor duplicate GORM-adapter construction on prefix history reads is deferred, not a correctness blocker; it borrows the existing transaction and full IDs bypass the resolver adapter. No schema, mutation-rule change, whole-history scan, full suite or repeated build. Previous binaries and worker config remain available. Earlier published releases remain published."
      },
      {
        "version": "0.1.31",
        "source_revision": "838a74836423981c9597831821935ed0d0ebcb65",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/838a74836423981c9597831821935ed0d0ebcb65",
        "qualified_at": "2026-09-07T21:36:05Z",
        "node": "live-20260823",
        "runtime_generation": 426,
        "evidence": "Installed source838a7483 as node0.1.31 from the corrected17.93s cut; retained binaries match the live daemon, CLI, executor and Code2 manager. Same store/schema c6712d1f; start-to-ready21.410953s. Root used normal work history on active Work and followed its printed continuation. Code2 actual-use1e2fa490 recovered the original release-choice instructions, original root author/time, later Code2 clarification and current finished status in one default history read, without chat/filesystem reconstruction or repeating the implementation. The first dc7dd11b draft exposed an omitted top-level CLI recognition entry and remains unqualified; the repair adds real top-level plain/JSON regression coverage, with RED then focused GREEN0.047s and Claude review. Native history uses bounded GORM projections over existing indexed rows, no schema change or report checksum audit. Initial native/CLI tests, corrected SQLite tests31.499s and source reviews passed. No full suite or unrelated runtime checks. Worker reporting unnecessarily copied the retrieved plan into extra progress entries after an oversized finish attempt; that is reporting friction, not a required retrieval step or recommended evidence practice. Earlier binaries/config and both draft artifact sets remain available for recovery. Release0.1.30 remains published; new availability does not retire it."
      },
      {
        "version": "0.1.30",
        "source_revision": "cf0d480ba19ec7a359e01b85653cec6ce38a849f",
        "commit_url": "https://gitlab.com/sidecat-dev/sidecat/-/commit/cf0d480ba19ec7a359e01b85653cec6ce38a849f",
        "qualified_at": "2026-09-07T18:01:05.781043Z",
        "node": "live-20260823",
        "runtime_generation": 424,
        "evidence": "Installed source cf0d480b as node 0.1.30 from one 74.97s release cut. Four retained artifacts match local node binaries, the actual daemon inode and remote CLI/worker manager. Same store/schema c6712d1f, no package repairs; start-to-ready 22.381714s. Root found Code2's pre-existing closed release-worker-instruction session4bf8973d through prepared session list, then reviewed its full purpose, timing and finished Workfd8d result excerpt without invitation; a third work read recovered the full 2312-character result. Code2 actual-use Worke3a121cd performed the reciprocal two-call discovery/review of root's closed sessionb9dca5ab and finished Workd29c297d, explicitly retaining the result-truncation limitation. Both actors verified their original shared session/project selection unchanged. Independent real-process recovery passed62.456s, including restart and unfinished Work; initial native/CLI and related process checks passed, and the direct historical Work/note parity correction passed exactly three tests10.526s after behavioral RED. Task, correction and independent whole-change source reviews accepted. Read-only organization recovery does not widen session selection or mutation, and adds no schema or historical audit. Predecessor binaries/config and artifacts preserved locally and on the existing droplet. No full suite, repeated release build, backup or migration run. Two historical migration-fixture failures remain an unisolated follow-up, not a green-suite claim. Executor identity is its artifact hash and Go VCS metadata; it has no version-display handler."
      }
    ],
    "count_total": 78
  }
}
