docs(plans): C4 exit record — stranger run reached; a grant binds only a seat with no ambient credentials (TASK-053) - #1749
Merged
Conversation
lilyshen0722
force-pushed
the
wren/c4-run-record-2026-09-18
branch
from
September 18, 2026 12:34
8e8352d to
0ddc8c1
Compare
This was referenced Sep 18, 2026
…inds only a seat with no ambient credentials (TASK-053) The 2026-09-18 stranger run on commonly.me reached C4: admin-minted grant 11:32:51Z, first approved write (issue #1745) 12:10:11Z, close approved 12:16:28Z, five-row trail read as the stranger at 12:20Z. The row now carries the timeline, the ~28 minutes the seat cost, the thirteen stumbles filed from the recording (TASK-039..058, #1743) and the evidence paths. #1714's exit criterion said the stranger grants and approves; the run showed the stranger can do neither. The criterion now says what happened: the admin installs once, grants and approves; the stranger mentions the seat and reads the trail. tools-catalogue-room-grants.md: the "no daemon or adapter change" claim in §4 and §8 did not survive the run (#1721 projection reaches daemon-supervised seats only, launchd token-file seats never see it; #1743; #1740; codex). New §4 statement: a grant binds a seat, not an agent, and only a seat with no other path to the provider — the host-gh answer left a 0-call trail — so the public sandbox default is the seat half of the confirmation floor, not an option (TASK-052, #1746, #1744). Eight stranger-view captures at 1200 under docs/design/evidence/. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…res renamed for what they show Vera (69588): the three captures named for trail states were the same Tools viewport with the trail below the fold. T4 is re-shot as the stranger with the trail card in view (5 calls, 0 refused, five rows). T1 and T2 cannot be re-shot — those states are gone — so they are renamed for the granted row they do show (1m, 33m) and the row cites the ledger reads for the empty → one-call progression. #1746 is now merged (48a5ea9); the row says so. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…w timestamp, and the T4 capture is dated by its own row Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
lilyshen0722
force-pushed
the
wren/c4-run-record-2026-09-18
branch
from
September 19, 2026 10:57
2547500 to
912ec46
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The C4 stranger run of 2026-09-18 reached its exit. This PR is the record, read on
mainat0011545c.docs/plans/production-readiness-and-selling-2026-09-11.md— the C4 row's exit record goes from NOT REACHED (09-16) to REACHED (09-18) with the UTC timeline: admin mint 11:32:51Z, seat confined 12:00:04Z, list 12:03:58Z → ok, create 12:07:02Z → parked → approved 12:10:10Z → issue C4 run 2026-09-18 12:06Z #1745 12:10:11Z, close 12:11:39Z → parked → approved 12:16:28Z → closed 12:16:29Z, trail read as the stranger 12:20Z (five rows, 0 refused). 38m11s from Tools open to the first approved write, ~28 of them the seat (host-ghanswer with no trail row, then the fix(cli): a public-sandboxed claude seat survives an HTTP MCP server in its environment #1743 spawn crash). The thirteen stumbles filed from the recording are listed by task with their PRs.grantedByfrom the Connection owner and 403s anyone else, and approval carries the granter's authority. The criterion now reads: the admin installs once, grants and approves each write; the stranger in the room mentions the seat and reads the trail.docs/plans/tools-catalogue-room-grants.md— §4 item 2 and the §8 table said "no daemon or adapter change is needed" for a seat to reach the broker. That did not survive the run: feat(daemon): project active room grants into MCP env #1721 projects grants intoenvironment.mcpviaGET /api/agent-binding/assigned, which onlydaemon-supervisor.jsreads, so a launchdcommonly agent runseat off a token file never receives it (TASK-039); the claude adapter needed fix(cli): a public-sandboxed claude seat survives an HTTP MCP server in its environment #1743; pi has no HTTP MCP transport (cli: the pi adapter keeps only stdio MCP servers, so a pi seat holding a room grant never sees the broker tools #1740, TASK-054); codex cannot consume a URL transport. New §4 statement (TASK-053): a grant binds a seat, not an agent, and only a seat with no other path to the provider — the trail is evidence about the grant, never about the seat — so the public sandbox default is the seat half of the confirmation floor (piece 2b), not an option (TASK-052; fix(registry): changing an installed agent requires its installer or an instance admin (TASK-055) #1746 installer-or-admin PATCH; fix(cli): the daemon refuses a declared environment that would run a foreign command or ship the seat token off-instance #1744 declared-server guard). §8 gains the matching row.docs/design/evidence/c4-run-2026-09-18-*.png— eight stranger-view captures at 1200 (T0 not granted, T1 granted + empty trail, T2 reply + one-call trail, T3 create card + approved, T4 close card + five-row trail). No UI changed here, so no 390 pair.Why
TASK-053 (C4-7). Sam 69556: post the stranger-side T0→T3 record and the stumbles.
Checks
git merge-tree --write-tree origin/main 8e8352d0exits 0 atorigin/main = 0011545c; three-dot diff is these ten files only.🤖 Generated with Claude Code