From 959d8e623e5efefe273aceb94df5641d5d64dac7 Mon Sep 17 00:00:00 2001 From: Lily Shen <115414357+lilyshen0722@users.noreply.github.com> Date: Tue, 1 Sep 2026 15:30:32 -0700 Subject: [PATCH] docs(adr-025): the private-chat binding supersedes D7; D7 narrows to team-group bridging MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sam's 2026-08-31 01:44Z ruling folds #1295 into this document and delegates "whose text is canonical" to cl-strategist and pod-architect. This records my half: the two texts overlap on exactly one decision, and #1295's user-scoped binding replaces D7 for the private-chat case, landing as D8 under the D8+ numbering so no slot is contested. D7 is not withdrawn — it narrows to team-group bridging, which is the case #1295 keeps the pod-scoped connector dormant for. Finding 6 stays as written; only the decision it feeds changes. In place under D7 rather than appended, so it does not queue behind the EOF-append PRs. Co-Authored-By: Claude Opus 5 --- docs/adr/ADR-025-connector-substrate.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/docs/adr/ADR-025-connector-substrate.md b/docs/adr/ADR-025-connector-substrate.md index ade899efd..02eb959a7 100644 --- a/docs/adr/ADR-025-connector-substrate.md +++ b/docs/adr/ADR-025-connector-substrate.md @@ -300,6 +300,27 @@ shipping a seventh plaintext credential is a decision too, and it should be take **D7 — Connectors scope like Installables.** One connector record projected to N pods, per ADR-001's one-install-fans-out, so an enterprise install is one administrative act rather than twenty. +> **Superseded for the private-chat case — the reconciliation position (pod-architect, 2026-09-01).** +> Sam's 2026-08-31 01:44Z ruling folds #1295 into this document and delegates "whose text is +> canonical" to cl-strategist and me. This is my half of that call, filed as an artifact rather than +> a comment so it carries its own answer. +> +> The two texts overlap on exactly one decision. #1295's **"The private chat binds to the USER, not +> to a pod"** — `Integration.scope: 'user'`, `linkedUserId` the owner, no `podId` — **replaces D7** +> for that case, and lands as the first folded decision (D8 under the D8+ numbering, so no slot is +> contested). D7's own evidence is what argues for it: Finding 6 measures `podId` as required and +> singular, and reads that as an N-pod projection problem, because a projection is what ADR-001 +> supplies. But an enterprise install and a person's private chat want opposite things from the same +> field. A projection to N pods keeps the pod as the binding unit and multiplies it; the user-scoped +> record removes the binding unit instead, which is the shape a private chat actually has — one +> human, every pod they are in, one credential. Finding 6 stays as written; only the decision it +> feeds changes. +> +> D7 is **not** withdrawn: team-group bridging still wants one record across many pods, and #1295 +> keeps the pod-scoped connector for exactly that, dormant until per-sender attribution exists. So +> the two are a case split, not a contest — D7 for the shared channel, the folded D8 for the private +> one. Read D7 as scoped to team-group bridging from here. + --- ## What this ADR does not decide