diff --git a/docs/plans/integration-readiness-matrix.md b/docs/plans/integration-readiness-matrix.md index 1ab8eff88..01b574afc 100644 --- a/docs/plans/integration-readiness-matrix.md +++ b/docs/plans/integration-readiness-matrix.md @@ -47,7 +47,7 @@ The matrix below is the definition of "ready". A row is ready when every cell is | row | code exists | known state | |---|---|---| -| Telegram | yes | Re-walked live 2026-09-27 on `c941626b` with a real account (below). **C1 green**: the code typed exactly as the page shows it, spaces and a capitalised group included, binds on the first try (#1931 TASK-153, #1932 TASK-157); on `7ccc6ac2` the same form was refused. **More than one pod, green outbound**: a second pod switched on under "Pods that reach this channel" relayed its agent's line to the chat within the minute, and a line typed in the chat went only to the active pod, as the connector is built (one private chat binds one Commonly user, pods behind it as gates; TASK-154, ruled by Wren). **C3 green** (an agent line relayed) and **C5 inbound green** with sender identity ("Sam Xu (via Telegram)"). C10 green: both refusals are named, and since #1878 a dead chat is a named failure. Open: pod tags on relayed lines and quote-reply routing across pods (TASK-156) | +| Telegram | yes | Re-walked live 2026-09-27 on `c941626b` with a real account (below). **C1 green**: the code typed exactly as the page shows it, spaces and a capitalised group included, binds on the first try (#1931 TASK-153, #1932 TASK-157); on `7ccc6ac2` the same form was refused. **More than one pod, green outbound**: a second pod switched on under "Pods that reach this channel" relayed its agent's line to the chat within the minute, and a line typed in the chat went only to the active pod, as the connector is built (one private chat binds one Commonly user, pods behind it as gates; TASK-154, ruled by Wren). **C3 green** (an agent line relayed) and **C5 inbound green** with sender identity ("Sam Xu (via Telegram)"). C10 green: both refusals are named, and since #1878 a dead chat is a named failure. Shipped since the re-walk: relayed lines now carry their pod's name (#1935, TASK-156; seen live on `19d1d3e2` as "[Connector walk 0926] Scout: PONG-TAG"), and a quote-reply routes to the quoted line's pod or is refused by name (#1935; unit-witnessed, not walked live). The catalogue row names the multi-pod model (#1957, TASK-158) | | Slack | yes | Walked live 2026-09-26/27 on `7ccc6ac2` with a real workspace (below). **C1, C3 and C5 green**: connect through consent, callback and confirm; a hosted agent's reply relays to Slack; a Slack mention reaches the agent and its answer comes back. C5 inbound was green only after two Slack app settings were fixed during the walk. Red for customers until the app was publicly distributed, which is now done, and the distribution attestation is now true of the running backend: #1929 (TASK-151) removed every `SLACK_BOT_TOKEN`/`SLACK_APP_TOKEN` read and injection, live on `f5eb5563`. A second authorize on a connected row is refused with 409 `slack_already_authorized` (measured through the API); the refusal copy on the page (#1890, Row C) is still unwalked in the UI. Before #1875 (09-04 to 09-25), every new install was refused at Authorize | | Discord | partly | **red** in C0: not offered on the Connectors page (#1826, held for Sam's read of the renders). **red** in C1: not connectable (TASK-104). Two different fixes | | GroupMe | yes | **red**: TASK-101 | @@ -123,9 +123,11 @@ Walked by the Connectors session, 2026-09-27 02:43Z to 02:47Z, with `lily-shen` | inbound routing | as built: a plain line typed in the chat landed only in the active pod, as "Sam Xu (via Telegram)", authored by the connector's owner, and not in the second gated pod | | C3 | green: an agent's line in a gated pod relayed to the chat | | C5 inbound | green, with sender identity preserved | -| open | pod tags on relayed lines, and quote-reply routing to the quoted line's pod (TASK-156) | +| pod tags and quote-reply routing | shipped after the walk (#1935, TASK-156). Pod tags seen live on `19d1d3e2`; quote-reply routing is unit-witnessed and not yet walked live | -The test gate on "Scout (Default)" was switched back off after the walk. The Telegram binding stays on "Connector walk 0926", so Sam's Rewire Live Demo pod relays nothing until he binds it from his own account, which first needs this binding removed: one chat holds one active row. +The test gate on "Scout (Default)" was switched back off after the walk. On Sam's word (2026-09-27 ~10:30Z) the test binding on "Connector walk 0926" was then removed, so the chat is free: Sam's Rewire Live Demo pod relays nothing until he binds it from his own account. + +**Membership, hardened across every connector write path (2026-09-27).** A connector now writes only where its owner is a listed pod member, the same rule `createMessage` uses (`isListedPodMember`): relay, inbound, the gate PATCH, install, bind confirm and the gate reconciler (#1940, TASK-161). A pod's creator cannot leave it (#1945, TASK-166), so `createdBy` no longer stands in for membership; the Discord/Slack owner routes follow (#1946, TASK-168); `agent-admin` pods are not a gate target (#1954, TASK-171); the PG chat path reads Mongo membership rather than its own mirror (#1942, TASK-162); and a seat whose own declaration cannot confine a broker is refused at the broker call — every dispatch except the native runtime's in-process one, which is exempt because a hosted turn has no shell, web or file tool to confine (#1971, TASK-175, ruled by Wren). This bears on C9 (authority is bounded) for every channel row above. ## Cross-cutting reds