Frontend Migration Ledger

Program: Command Center Transformation Status vocabulary: NOT STARTED | IN PROGRESS | VERIFIED | BLOCKED | HUMAN DECISION Rule: an item is VERIFIED only when its phase acceptance gate has evidence recorded in FRONTEND_VERIFICATION.md. Update this file at the end of every working session.

Last updated: 2026-08-30 (Zero-Mock sweep + Central URL step-8 completion, session 12 — see the dated section of that name below and FRONTEND_VERIFICATION.md §33; 2D row re-measured: step-7 ratchet at 42 cleaned modules, the "17" was a 2026-08-07 count; 14a7c7d6 gated the five scratch routes and closed the [kernel]/insights gap; 77ac7080 retired /service-health, deploy run 33338507973 → serving 00571-f65. Header corrected 2026-09-01 — it had read 2026-08-09 while rows and a whole section carried 2026-08-30 dates.)

Prior session (2026-08-09, session 9b follow-up — auth-flip lockout class closed in code, owner-directed re-check: the standing "do not flip REQUIRE_AUTH" warning was re-measured instead of repeated. Half was STALE (the cloudbuild auth-guard already blocks empty/placeholder credentials at build time); half was CONFIRMED by direct probe — live Firestore rules deny the auth collections (sessions/{token} → 403 PERMISSION_DENIED), so the legacy bridge is not a viable fallback and a flip REQUIRES real Supabase. Two defects closed: (1) the build guard had no runtime twin, so a placeholder set via services update enforced against a dead IdP — shared lib/auth/idp-config.ts now backs BOTH middleware and /login; (2) auth directory lookups swallowed the denial and reported a CORRECT password as "Invalid email or password" — an outage disguised as a credential error; they now raise and the routes answer 503 (this also stopped tenant-session's 401 branch from permanently deleting valid session cookies during an outage). Read-only GO/NO-GO preflight added. Gates: tsc 0 · 788/788 (117 files) · build 0. Evidence: VERIFICATION §36)

Prior session (session 10 — Wave 3, owner "all approved to go online": 1A FINISHED (mobile indicator parity + honest dataUpdatedAt freshness chip; global-freshness registry consciously deferred), 2D step-7 tail (ratchet 17→25; 8 drains + 6 new 0-importer HD-2 candidates; step-8 runway re-measured — socket.io retired, 2 protocol families remain), 3C slice 1 (axe gate 6→15 pages, homepage contrast lifts, palette focus-return fix, keyboard e2e; reaped-subagent tree independently verified before landing). Gates: tsc 0 · 685/685 · lint 0 err · build 0 · axe 15/15. Evidence: VERIFICATION §30)

Prior session (session 9 — TWO PARALLEL session-9 branches ran the remainder charter concurrently, then were hand-reconciled after the -X theirs auto-merge destroyed one side's records and left main tsc-red (AGENTS.md 3.2 class; full record VERIFICATION §29.5). Joint outcome: 9a (…frontend-mf4zyd, §28) = 3H archives ×11 incl. the events family (upstream REST measured ABSENT) · client/config drains · 1A shell EnvTenantIndicator + role-floor badges + contrast fix. 9b (…command-center-sprint-yb4edq, §29, 3-subagent wave) = client.ts hub-cluster drains · 3H archives incl. provenance/fetcher · 1D KG explorer browse slice (bounded nodes/edges) · 3D slice 2 (both direct-recharts routes −60%/−58%; cache policy measured document-only; the five-route static-import regression caught by the wave-close build and fixed with a ratchet-guarded lazy import). Reconciled union: ratchet 17 modules · 15 unique modules archived · events-family grants removed as unmeasured dead surface. Post-reconciliation gates: tsc 0 strict · full suite green (§29.5 commit) · lint 0 errors (JSON) · build 0 · e2e 18/18 no-retry (§29.4). Evidence: FRONTEND_VERIFICATION.md §28 + §29)

Prior session (session 8 — completion sprint, two subagent waves per docs/prompts/COMMAND_CENTER_COMPLETION_SPRINT_PROMPT_2026-08-07.md: Wave 1 = 3E OTel + client errors · 3F CSP report-only · 1D evidence/KG explorer first slices · 2D step-7 drains (ratchet 3→8) · 3G MSW + 3 e2e journeys; Wave 2 = 3A tokens+primitives · 3D code-splitting (measured −82%/−30%/−22% first-load on the three split routes) · 3H toSafeUrl family 444→0. Gates: tsc 0 strict · 532/532 tests (88 files) · lint 0 errors / 115 warnings (authoritative JSON) · build 0 · e2e per §27. Evidence: FRONTEND_VERIFICATION.md §26–§27)

Prior session (session 6 — 2026-08-06): 3H slice 1 build gates ENFORCED (ignoreBuildErrors/ignoreDuringBuilds removed) + 1D Command Center honesty pass (overview live-tiles first slice; every mock section labeled + [not-wired] HD-4 notes; 311/311 tests; VERIFICATION §20)

Prior session (session 5 — 2026-08-05): TWO audits closed: stage-1 14/14 + owner audit #2 13/13 reviewer findings & 5 unraised items fixed (CI-red lint forensics included); phases 0A–1D complete; 2A/2B/2C first slices VERIFIED, 2D measured; deployment reality: every auto-merge dispatches deploy-ui.yml via the Deploy Router — all runs green — so the stage-1 work is serving in production in its flag-off posture, live-verified: pages 200, BFF surfaces answering honest tenant_required/service_unconfigured/503 states


Standing constraints (apply to every item)

# Constraint Source
C1 Pushes to claude/* branches auto-merge to main within minutes; every code commit must be independently safe to land, risky cutovers behind flags Repo automation, verified in git history (chore: auto-merge cursor branch …)
C2 No commits/pushes of code without owner authorization; this session's harness designates branch claude/miz-oki-command-center-ui-pacu82 with commit+push instructions — treated as authorization for program artifacts; code slices remain gated per charter Charter §0.2 + session harness config
C3 Never edit canon-pinned # MIZ OKI 3.5/ files; never dispatch deploy workflows DESIGN_CANON.md, root CLAUDE.md
C4 No production mutations from tests; approval/action flows use fixtures until an authorized non-prod tenant exists Charter §0.2
C5 Truth discipline: claim labels on all performance numbers; mock never presented as live Charter §0.4, signal-story-bank rules

Finalization-prompt phase mapping (2026-08-06)

docs/prompts/MIZOKI_COMMAND_CENTER_FRONTEND_FINALIZATION_PROMPT_2026-08-05.md (landed on main 2026-08-06 via 2f5106d) uses F0–F7 phase names authored against a stale 2026-08-05 workspace (553 TS errors, zero tests, no BFF). Its §3 directs remeasurement over trust; this ledger IS the measured program state. Mapping: F0 measure ≈ 0A (done) · F1 toolchain/gates ≈ 0A.1 + 0C (done; build-gate enforcement landed 2026-08-06, see 3H) · F2 auth ≈ 1B (partial — see the b650de9 correction note) · F3 typed BFF ≈ 1C (done, under /api/bff/*; the prompt's /api/command-center/* shape is explicitly non-mandatory) · F4 live composition ≈ 1D + 2A–2E (in progress; strict "zero mock imports" blocked on HD-4 read-APIs per the prompt's own F3.6) · F5 shell/IA ≈ 1A + 3B · F6 design/a11y/perf ≈ 3A–3F · F7 release gates ≈ 3G–3H + the finalization report (F7.3 authors docs/reports/COMMAND_CENTER_FRONTEND_FINALIZATION_REPORT.md at program completion). The prompt's §7 per-package artifact list is satisfied by THIS directory's artifact set — do not fork a parallel tree under miz-oki-command-center-ui/docs/frontend/.

Phase 0A — Measure, stabilize inventory

Item Status Evidence
Read authority documents (18 listed in charter §0.1) VERIFIED FRONTEND_VERIFICATION.md §2
Git/worktree baseline captured VERIFIED FRONTEND_VERIFICATION.md §3.1
Route inventory (155 pages / 211 API routes classified) VERIFIED FRONTEND_ROUTE_INVENTORY.md
Backend/service inventory VERIFIED FRONTEND_SERVICE_CONTRACT_MAP.md
Mock/fallback inventory VERIFIED FRONTEND_ROUTE_INVENTORY.md §4
Auth and tenant inventory VERIFIED FRONTEND_ROUTE_INVENTORY.md §5 + VERIFICATION §3.4
State/data client inventory VERIFIED FRONTEND_ROUTE_INVENTORY.md §6
Design & accessibility inventory VERIFIED FRONTEND_ROUTE_INVENTORY.md §7
Tests/CI/build/deploy inventory VERIFIED FRONTEND_VERIFICATION.md §3.5–3.7
Baseline measurements (install, tsc, lint, build) VERIFIED FRONTEND_VERIFICATION.md §3.2–3.3
Six program artifacts created VERIFIED this directory

Phase 0A.1 — Fix pass ("fix all open issues", 2026-08-05 session 2)

Owner authorization: user message "Proceed fix all open issues first then move forward".

Item Status Evidence
npm ci repaired (lockfile regenerated w/ npm 12; swr + react-force-graph removed, 0 imports each) VERIFIED commit f37b40a; npm ci exit 0, 1,083 pkgs
TypeScript errors 570 → 0 (tsc --noEmit clean) VERIFIED FRONTEND_VERIFICATION.md §5
ESLint errors → 0 (557 pre-existing toSafeUrl warnings remain, fix-on-demand per UI CLAUDE.md) VERIFIED FRONTEND_VERIFICATION.md §5
next build green; standalone server boots; /+/login 200 VERIFIED FRONTEND_VERIFICATION.md §5
Truth-discipline removals: Math.random() srpvdal metrics → honest 503; kg edge/node/update mock-success catch paths removed; KPIGrid fabricated "Live" tiles deleted; BossAgentEnhanced embedded mock A2A client deleted VERIFIED §5 + route diffs
Broken-contract hooks rewritten against real APIs or explicit [not-wired] failures (lib/api/hooks, hooks/useMetrics, hooks/api/useMetrics, useCells, useConnectionHealth→removed, useSRPVDAL→removed, useJourney/useNeural repointed) VERIFIED §5
Runtime bugs fixed: BossAgentV2 undefined views + missing send handler; publishA2A missing auth field (5 routes); footer passed MouseEvent as message text; programming page crash on successMetrics; Next 15 async headers()/cookies() migrations VERIFIED §5
Security quick-wins: setup-tenant.yml committed password default removed (rotation = operator action); tenant admin route fails closed w/o TENANT_ADMIN_SECRET; Firebase web key parameterized as cloudbuild substitution VERIFIED §6
Dead code removed (each verified 0-importer + git-recoverable first) VERIFIED §5.3

Phase 0B — Architecture decisions

Item Status Notes
ADR-001 Product boundary ACCEPTED (2026-08-05) Decision + consequences in ADR register
ADR-002 Authentication & identity ACCEPTED (2026-08-05) HD-1 closed — owner signed off all stage-1 parts; Supabase Auth server-verified. Live flip = operator provisions credentials + REQUIRE_AUTH=true
ADR-003 Browser/backend boundary (BFF) ACCEPTED (2026-08-05) authedFetch gateway; NEXT_PUBLIC backend URLs frozen
ADR-004 State ownership ACCEPTED (2026-08-05) SWR already removed (0A.1); RQ=server, Zustand=UI
ADR-005 Contract strategy ACCEPTED (2026-08-05) OpenAPI-generated types first; hooks' live types are interim law
ADR-006 Visual system (Operator Dossier) ACCEPTED (2026-08-05) Implementation Phase 3A
ADR-007 Migration strategy (additive) ACCEPTED (2026-08-05) Session-2 fix pass is the template

Phase 0C — Quality infrastructure

Item Status Notes
Repair npm ci (lockfile sync) VERIFIED (0A.1) f37b40a — npm 12 regeneration; npm ci exit 0
Package scripts (typecheck/lint/test/verify) PARTIAL typecheck + test/test:watch scripts exist; a combined verify script and Playwright e2e remain
Test foundation — Vitest + RTL + jest-dom VERIFIED (2026-08-05) Vitest 4.1.10 + @testing-library/react 16.3.2 + jsdom 30; vitest.config.ts aliases mirror tsconfig paths; 6 suites / 25 tests passing (safe-navigation, agents/registry.validateContext, api hooks incl. 7-stage SRPVDAL mapping + [not-wired] no-network assertion, useCells registry/health derivation, srpvdal metrics route honest-503 contract, ui primitives a11y roles)
Test foundation — MSW / Playwright / axe NOT STARTED Deliberately deferred: unit+hook+route layer first; e2e/a11y tooling lands with Phase 1A shell surfaces worth driving
Unit tests wired into CI VERIFIED w/ correction (2026-08-05 audit) frontend-guard typecheck job runs npm test between tsc and lint. Audit findings: (1) the job crashed on Node 20 (jsdom 30/undici 8 needs ≥22.10) — fixed by a parallel session (0a51aca, Node 24); (2) the push trigger NEVER fires on auto-merged commits (GITHUB_TOKEN suppression, CI-001 class) — the gate had executed on zero merged commits. Fixed: workflow_dispatch added + registered in deploy_router.py ROUTED_CI_GATES, so the bots now dispatch the gate on every UI-touching merge exactly like the deploy workflows
UI CI workflow against real package VERIFIED (0A.1) frontend-guard typecheck job: npm ci + tsc + unit tests + lint on PRs and main pushes
Delta-first TS gate (no new diagnostics) SUPERSEDED → hard zero gate Error count reached 0, so the CI gate enforces zero outright (stronger than delta)

Phase 1A — Shell & IA

Item Status
Verify/complete single nav source (config/navigation.ts) VERIFIED (2026-08-05) — delivered by the parallel maturity P0 (9df5935: hardcoded fork archived, NavigationShell sole consumer); locked by the nav test suite this session
Fix icon: any typing + route metadata (roles/flags/status) PARTIAL — roles shipped (2026-08-07, session 9, §28) — role metadata now DERIVED at render time from the middleware's ROLE_ROUTES via new pure pageRoleFloor() (longest-prefix, segment-bounded); nav badges via getRouteRoleBadge/formatRoleFloor with honest compaction (gapped floors render the exact list — operator/admin, never a fabricated +); a test forbids hand-written role-array literals in the SSOT so a parallel table can't drift. Earlier: icon/mobileIcon LucideIcon. Remaining: flags/status metadata (needs a real flag/status source first)
Nav↔route existence tests VERIFIED (2026-08-05) — config/navigation.test.ts (8 tests): all 101 internal paths resolve against the App Router tree (dynamic segments/route groups/catch-alls), unique ids, root-absolute paths, MOBILE_ROUTES id resolution, lookup helpers
Job-oriented primary IA (incl. Approvals section) VERIFIED (2026-08-07, session 9) — Command Center group LEADS the sidebar; children follow the governed decision pathway (Evidence → Decisions → Approvals → Actions → Policies → Audit → Learning → Six Domains/Domains/Cells), order test-pinned in config/navigation.test.ts; cc-events renamed Evidence (the page IS the evidence explorer — no route move, no Live claim); palette-search regression from duplicating child names in the group description caught by test and fixed. Earlier: approvals staked out 2026-08-05
Shared authenticated shell (breadcrumbs, tenant/env, freshness, palette) PARTIAL — tenant/env indicator shipped (2026-08-07, session 9, §28) — the shell's environment <select> was measured a DEAD affordance (store env had zero behavioral consumers; it implied env switching that switched nothing) and is replaced by read-only EnvTenantIndicator: server-derived facts threaded from the root layout (NODE_ENV; Cloud Run K_SERVICE/K_REVISION when deployed — never NEXT_PUBLIC) + a tenant chip that renders a legacy session with an explicit unverified marker (§20.4 language) or no tenant session; the region <select> stays (store.region has a real consumer, useKernelDashboard). Earlier: breadcrumbs pre-existed; command palette shipped (2026-08-05): components/CommandPalette.tsx (⌘K/Ctrl+K, dialog/listbox a11y, entries derived from the tested nav SSOT with cross-link dedupe, toSafeUrl navigation, 8 RTL tests) replacing the shell's dead /search?q= affordance. Remaining: freshness affordance (shell-level; per-tile freshness already live). Mobile parity CLOSED by measurement (2026-08-08, session 10): no separate mobile shell exists — "MobileNavigationShell.tsx" was a phantom in the SSOT header comment (never in the tree; MOBILE_ROUTES has zero runtime consumers, kept test-pinned for a future bottom-nav); the ONE responsive NavigationShell already renders the indicators + role badges on mobile by construction, and narrow viewports now yield the deploy-facts cluster + region select (hidden md:block) to the always-visible verified-session chips. Merge union (Run B, §29): SessionIndicator (verified-session chips over /api/auth/whoami — middleware-verified role/tenant + REQUIRE_AUTH posture, explicit no-session state) renders beside EnvTenantIndicator, env chip suppressed; Run B's zero-consumer claim for the REGION select was corrected by Run A's measurement (useKernelDashboard consumes store.region — select stays)
Route consolidation + redirects (ledgered) PARTIAL — parallel P0 archived 14 boss route trees + repointed inbound links (/boss-integrated→/boss etc.); remaining consolidation ledger-driven

Phase 1B — Auth, authorization, tenancy

HD-1 closed 2026-08-05 (owner sign-off). All enforcement ships behind REQUIRE_AUTH — production is byte-identical until the operator provisions Supabase credentials and flips the flag.

2026-08-06 correction + hand-resolution (measured): upstream merge b650de9 armed REQUIRE_AUTH=true in .env.production (owner-directed bridge: legacy tenant logins mirrored to mizoki_token/mizoki_role cookies so enforcement doesn't lock out /login) — but the -X theirs auto-merge grafted it onto middleware v3.1 broken: 3 tsc errors ON MAIN (undefined route tables), the graft unreachable dead code, and v3.1's api-error case destroyed. Hand-resolved same day (AGENTS.md 3.2, both sides preserved): bridge extracted to pure lib/auth/legacy-bridge.ts (active ONLY under enforce+no-IdP; deny-by-default kept — /dashboard, /boss, /command-center stay protected; NEVER stamps identity, so identity-gated BFF routes still 401; 6 contract tests), middleware v3.2.0 restores api-error. The bridge remains presence-based and spoofable BY DESIGN until the F2/1B closure (server-verified legacy sessions or Supabase-only enforcement) — page availability only, never verified identity. Live posture at probe time: enforcement NOT active (unauth /dashboard → 200). Evidence: FRONTEND_VERIFICATION.md §20.4.

Item Status
IdP configuration detection (lockout class) VERIFIED (2026-08-09, §36.2) — lib/auth/idp-config.ts is the single shape-validating predicate (https + placeholder scan + JWT-structured anon key + length floor, mirroring the cloudbuild auth-guard), used by BOTH middleware.ts enforcement and /login's form choice so they cannot disagree. Closes the runtime bypass the build guard could not see (a placeholder set via services update --set-env-vars previously made idpConfigured=true → enforce at a dead IdP → lockout with no escape hatch). +19 tests incl. an invariant test forbidding a regression to presence checks. Commit f42c4b63
Directory-outage honesty (auth reads) VERIFIED (2026-08-09, §36.3) — MEASURED: live Firestore rules deny the auth collections (sessions/{token} → 403 PERMISSION_DENIED, both committed web keys), so the legacy bridge is NOT a viable fallback and a flip REQUIRES real Supabase. getTenant/findTenantByDomain/getUser had caught every error and returned null, so a CORRECT password reported as "Invalid email or password" — an outage disguised as a credential error. They now raise TenantDirectoryUnavailableError → routes answer 503 honestly. Also stops real harm: tenant-session's 401 branch deletes the session cookie, so an outage previously signed valid users out permanently. Enumeration resistance unchanged. +9 tests. Commit 127ebddd
Fail-closed operator routes (explicit public allowlist) VERIFIED (2026-08-05) — lib/auth/route-guards.ts deny-by-default policy core; enforcing without a configured IdP denies (pages → login redirect w/ error=auth_unconfigured, APIs → 503 JSON); legacy trust-a-cookie branch deleted; boot-smoked in both flag states
Remove /dashboard,/boss from unconditional public list VERIFIED (2026-08-05) — no longer public; negative tests + live 307s under enforcement
BFF route guard classes (public-read → role-gated-mutation) VERIFIED in code (2026-08-07, session 9) — per-route mutation gates SHIPPED: lib/bff/require-role.ts; approve/deny = approver/admin, execute/rollback = operator/admin (explicit sets, /agents/config precedent); actor ALWAYS the verified session identity (body actor test-proven ignored); upstream 409/403/501 pass through untranslated. Live exercise awaits Wave O (governance redeploy + credentials)
Role model (viewer/analyst/operator/approver/admin) server-side VERIFIED (2026-08-05; role-absence baseline moved 2026-08-25) — roles read from app_metadata only (user_metadata is end-user writable — never an authz source); unknown/absent claims are UNPROVISIONED (null) and denied every non-public route (R-36 closure — they previously collapsed to viewer, which read every un-floored page); longest-prefix page floors (/settings→admin, /agents/config→operator+)
Human actor + service identity separation PARTIAL — middleware stamps verified x-authenticated-user/email/role after stripping inbound spoofs; service identity stays server-minted (lib/service-auth) — the BFF join is 1C
Tenant from session; cross-tenant negative tests VERIFIED (2026-08-07, session 9) — table-driven battery over EVERY tenant-scoped read (pending + evidence had dedicated suites; the remaining six — history, outcomes, audit-recent, decisions, decisions-summary, passports — now covered): 401 without a verified tenant with the adapter untouched, and the adapter receives EXACTLY the stamped tenant while query-string tenant-shopping is structurally ignored. Mutations additionally enforce BFF-side tenant-membership gates (upstreams measured tenant-blind on ids)
Session UX (expiry, return URL, logout, unauthorized/forbidden) VERIFIED (2026-08-05, 1B.2) — dual-path /login (Supabase primary when configured, legacy tenant sign-in otherwise/behind toggle); open redirect fixed (?from=/?redirect= now pass sanitizeReturnTo — raw value previously fed window.location.href unchecked; 6 attack-table tests); middleware↔login return-URL contract reconnected (from accepted); error=auth_unconfigured banner; shell account menu with real sign-out (Supabase + tenant sessions, hard-nav so middleware re-evaluates); /unauthorized page. Session-expiry UX rides Supabase cookie refresh in middleware

Phase 1C — Typed observable BFF

Item Status
Server-only service registry (no NEXT_PUBLIC backend URLs) VERIFIED (2026-08-05, 1C.1) — lib/bff/registry.ts: 13 services, server-only env names, browser-import guard, origin normalization (OIDC audience discipline); defaults only for repo-documented URLs (boss, gaql-cell); governance ten + intent are env-only → honest service_unconfigured, never a guessed URL; a test greps the layer for process.env.NEXT_PUBLIC
Central gateway (authedFetch, timeouts, error envelope, traces) VERIFIED (2026-08-05, 1C.1) — lib/bff/gateway.ts: callService over OIDC authedFetch, AbortController timeout (504), unified envelope {error, service, status, traceId, detail≤500}, x-request-id propagation, 502/503/504 classes; 8 contract tests
Typed adapters ×13 (governance ten + Boss + Intent + cells + GAQL) VERIFIED (13/13) (2026-08-05, 1C.2) — every adapter typed from its deployed service's own source (routes read from services/service-*/main.py + src/cells/cell34/scoring_cell/main.py): approval-routing, decision-control-plane (propose / authorize-approved / decision), validation-orchestrator (passport — no checks param by design, subsets 422 server-side), policy-engine, action-runner (execute/rollback; Stage-4-no-adapter 501 documented), audit-replay (replay/chain/verify), canonical-ingestion (ingest + point-in-time, the only sanctioned evidence query), model-registry, data-manager-connector (validate_only rule noted), media-incrementality (evidence-class discipline noted), boss, gaql-cell, intent-scoring (advisory-only labeling in-code). Barrel at lib/bff/adapters/index.ts
Contract verification tests VERIFIED (2026-08-05) — 39 BFF tests: registry (env resolution, no-guess invariant, process.env.NEXT_PUBLIC grep gate), gateway (timeout/envelope/trace), reference route (tenant-required 401, cross-tenant negative), and a 21-case adapter path-contract table + a D16 health-path sweep (/health, never /healthz) across all 11 backend namespaces — a drifted path fails CI before it 404s in production
Reference BFF route VERIFIED — /api/bff/approvals/pending: tenant ONLY from middleware-stamped x-tenant-id (spoof-stripped in 1B), 401 tenant_required without a session tenant, standard error envelope
Missing backend read-APIs: proposals to service owners VERIFIED (2026-08-05) — docs/frontend/READ_API_PROPOSALS.md: 8 proposed endpoints across 6 services (measured absences from the 1D wiring), D6/D-class constraints baked into the spec, explicit non-proposals (no unscoped listings, no mutations, no filterable batteries); acceptance stays with service owners (HD-4)

Phase 1D — Governed Command Center live composition

Item Status
Overview (live tiles w/ source+freshness) PARTIAL — slices 1+2 (2026-08-06; slice 2 session 7: 4th tile over the HD-4 decisions/summary aggregate w/ bounded-window caveat — renders honest unavailable until the operator redeploy; VERIFICATION §22). Slice 1 was — three live tiles over the measured reads (/api/bff/approvals/pending, /api/bff/boss/cells/health, /api/bff/registry/status), per-tile tri-state + source + poll-interval freshness + trace id; NO decisions/throughput tile (would be fabrication until the HD-4 decisions/summary aggregate ships); all five mock sections labeled; 3-case test matrix. Evidence: VERIFICATION §20.2
Evidence explorer (4 time axes, redaction, point-in-time) PARTIAL — first slice VERIFIED (2026-08-07, §26) — the SANCTIONED point-in-time read wired end-to-end (/api/bff/evidence/point-in-time: tenant only from stamped header → 401; six-domain + tz-aware as_of validation → 400 converting the measured upstream 422; four time axes rendered as labeled columns; truncation honesty; D6 note in every state; exclusive tri-state XOR illustrative test-enforced). Redaction + deeper querying remain
KG explorer (progressive, accessible) PARTIAL — browse slice VERIFIED (final survivor: 9c §30; 9b §29 superseded at union) — on-demand bounded node/edge browsing over the measured /api/v1/kg/nodes+/api/v1/kg/edges GETs: 9c panel (KgLedgerBrowse + useKgReads hooks; limit 1–200, short-token filters, detected columns, permanent source pill "thin Boss ledger — not the Cell3 fleet graph", nothing-read-until-you-ask idle honesty) over the convergent union adapter contract (bare call = no query; explicit params clamp 200, filter-first; both response-type names exported). 9b's parallel implementation (identity-gated routes w/ default 25, truncation note, raw-JSON rows; +23 tests) is superseded — its honesty copy carried forward; its 121→124 kB budget note measured the superseded page, so the kg-live budget re-baselines at the next measured build. Remaining measured reads deferred by name: /api/v1/kg/events, /api/v1/kg/journey/{user_id}, /api/v1/kg/dropoffs. Earlier (§26): summary reads, nav label honesty, axe-scanned
Decision workbench (DecisionProof, exact eligibility states) PARTIAL — queue wired (1D.2 lookup + session 7 §22: live tenant queue over HD-4 /api/v1/decisions w/ eligibility pills + DEL/threshold + explicit truncation; mock queue stays labeled; serving requires the operator governance redeploy)
Approval center /command-center/approvals PARTIAL — live reads ×2 + role-gated mutations WIRED (9c, §30) — reads: pending 1D.1 + resolved history (HD-4, session 7 §22), three explicit states never blended. Mutations (9c): approve/reject enable ONLY for a verified approver/admin session (whoami progressive disclosure), POST role-gated BFF routes (require-role.ts; server re-verifies role + tenant-queue membership per call; body-supplied actor ignored — verified session only), refusals render untranslated (409/403/404/503) with traces; today's unauthenticated production keeps the buttons fail-closed disabled (e2e-pinned). LIVE exercise remains gated on the operator Wave-O asks (HD-3/HD-4 serving)
Action center (authorization lifecycle, honest 501/409/timeout) PARTIAL — live reads + role-gated mutations WIRED (9c, §30) — reads per session 7 §22 (actuator registry 501-truth + tenant outcome records). Mutations (9c, operator/admin): ActionAuthorization redeem form (verbatim DCP object; BFF refuses cross-tenant 403; runner refusals pass untranslated — 409 single-use / 501 no-adapter / 403 signature) + per-outcome rollback (tenant-membership gate; rolled_back_by = verified identity). [not-wired] now names only authorization ISSUANCE. Serving requires the operator governance redeploy
Learning center PARTIAL — composed (9c, §30) — predicted-vs-actual over action-runner outcomes (per-metric pairs, COMPUTED delta label; Stage-3 rows state "no actual — nothing executed, so nothing to measure" — no fabricated lift) + recent LEARN-phase activity over audit-replay recent (tenant-join + bounded-window caveat); honest-unavailable until the operator redeploy; [not-wired] names only calibration/drift (no read-API exists). Labeled illustrative table retained per the replacement contract
Policy center (read-only) PARTIAL — live read wired (session 7 §22): active policy inventory (version, DEL floor, per-domain gates verbatim, advisory-only chips) over HD-4 /api/v1/policies; labeled illustrative kept; serving requires the operator governance redeploy
Audit & replay PARTIAL — live tools + recent activity (1D.2 + session 7 §22: tenant recent-activity joins over HD-4 /api/v1/recent) — on-demand chain-integrity verify + replay-by-audit-id + decision-chain-by-id via /api/bff/audit/* (id-format 400 guard before any backend call); tri-state rendering via shared BffQueryState; example-trace table permanently labeled illustrative
Remove lib/command-center/data.ts mock arrays from prod routes SUPERSEDED → labeled-illustrative discipline (2026-08-06) — the program's own truth pattern (approvals/cells precedent) keeps the scenario walkthrough but labels it: every consumer section now carries illustrative scenario — mock data + a [not-wired] note citing its measured HD-4 gap, never co-rendered with live data (test-enforced per page); the arrays get REPLACED page-by-page as HD-4 read-APIs land, and data.ts's header now states this contract (the never-built /api/command-center/* swap note is gone)

Stage-1 adversarial audit (session 5, owner-directed "fix up all")

Item Status
CI gate actually runs on bot merges (part 1, 688d6ca) VERIFIED — GITHUB_TOKEN suppression meant frontend-guard had run on ZERO merged commits; Deploy Router now dispatches it (ROUTED_CI_GATES) exactly like deploy workflows; dry-runs verified (UI change → deploy-ui + frontend-guard; docs-only → none)
BFF adversarial review — 9 findings VERIFIED (9/9 fixed) — static-bearer never on URL-addressed calls; identity gate (401) on all four governance lookup routes; approvals page exclusive branches (live+stale XOR unavailable+illustrative XOR error); gateway timeout spans body reads; non-JSON 2xx → attributable 502; nonce-carrying lookup submissions; dot-segment id rejection; {data, traceId} envelope everywhere + client unwrap; a11y (aria-describedby, persistent status region, th scope). Evidence: FRONTEND_VERIFICATION.md §10
Auth/session adversarial review — 5 findings VERIFIED (5/5 fixed) — getAll/setAll cookie adapter (chunked-session refresh no longer corrupts → the random-logout class under REQUIRE_AUTH is closed); refresh cookies carried on every response branch; legacy login auto-redirect gated to non-Supabase (loop fix); path-segment-bounded public/role route matching; refreshed cookie header forwarded to server components. Clean: return-to sanitizer, header strip/stamp, role model, decide() ordering, CORS, sign-out. Evidence: §10
Self-flagged items VERIFIED — account-menu Escape/outside-click dismissal; PUBLIC_ROUTES boundary matching (converged with auth finding #4)

Phase 2 — Capability surface

Item Status
2A Six-domain workspace + authority boundaries VERIFIED (first slice) (2026-08-05) — /domains renders the transcribed governance constants (lib/domains/authority.ts from source-of-truth v3.5.5 DOMAIN_STATUS + FORBIDDEN_AUTONOMY + measured passport batteries media 6 / finance 5 / counsel 12 / estate 13 / risk 14 / cre 5): maturity claim labels verbatim, media the SOLE non-advisory domain, counsel/estate/risk permanently advisory, forbidden scopes as refuse-at-grant chips, open proof obligations, DEL 80 platform-wide; 11 invariant tests lock the transcription (incl. a surface dead-link gate) + 6 page tests; nav entry cc-six-domains (auto-validated by the nav↔route gate). Deeper 2A slices (per-domain live composition) ride the 1D pattern as read-APIs land
2B Intent/ORACLE advisory integration + blocked-activation states VERIFIED (first slice) (2026-08-05, parallel wave) — 5 identity-gated BFF routes over the measured Cell 34 surface (taxonomy/cohort/transitions/explain/health; endpoints verified against scoring_cell/main.py; param guards mirror upstream semantics; tenant never request-supplied); /intent gains an additive governed live section: tri-state, "advisory evidence only" on every live payload, measured built, pre-benchmark claim label surfaced, permanent "Activation blocked — no registered holdout" banner; test-asserted rules: no activate button/toggle exists, no "audio" anywhere on the page. Score-by-identity deliberately NOT wired — the 1C adapter omits the service's required topic param (known follow-up, below). +43 tests
2C 36-cell fleet truth + failure-class semantics VERIFIED (first slice) (2026-08-05, parallel wave) — lib/fleet/registry.ts static transcription of the deployed Boss fleet table (36 = 32 production + 4 oracle_intent; stage vocabulary transcribed verbatim incl. META; 13 invariant tests); 2 BFF routes over the measured deduped endpoints (/api/v1/cells/list, /api/v1/cells/health/all) with URL-free payload projection + leak-check tests; raw-registry endpoints deliberately not wired (OPERATING_SYSTEM.md 6.1); failure classes from 6.3 only (403 = IAM-locked posture, not an outage; unmapped signals render raw); cells page: static + tri-state live sections with loud count-drift flags, mock grid preserved under illustrative label. +30 tests
2D One Boss experience (single shell/client/session store) IN PROGRESS — steps 1-6 + 8-10 LANDED; step-7 ratchet at 42 modules (2026-08-30; the "17" that stood here was a 2026-08-07 count and the ratchet is an append-only list of CLEANED modules, never a backlog). 2026-08-30: the three client-reachable modules §4.1's "CLOSED for backend URLs" note did not cover — lib/config.ts, lib/api.ts, lib/ekisClient.ts — were drained (behaviour-preserving: none of their NEXT_PUBLIC names is in the Dockerfile ARG list, which is where NEXT_PUBLIC values bake, so each was undefined in every shipped bundle and its same-origin default already governed) and ratcheted 40-42. Honest remainder = the deferred step-8 transport family + lib/flags.ts (own slice) + lib/neural-event-service.ts (the one genuinely open step-7 module: its fallback is a HARDCODED run.app URL, so it needs a proxy route, not a drain). See ONE_BOSS_CONSOLIDATION.md §4.2 and FRONTEND_VERIFICATION.md §34.6. Prior state: steps 1-6 + 8-10 LANDED (reconciled union, §29.5) (2026-08-07 session 9b §29 + 9a §28, hand-reconciled per §29.5: the client.ts hub cluster drained — CELL_URLS repointed same-origin (/api/boss-proxy + new SSE-only /api/cell22-proxy), CODING_MOA_STREAM deleted (0 consumers), JWT via the shared supabase client (LAZY import, ratchet-enforced after a measured +68-69 kB five-route regression was caught by the wave-close build and fixed same-session); config.ts now URL/env-free (cell origins resolve server-side in boss-proxy cellOrigin()); events/hooks/journey/neural/strategies/moe/moa/useKGComposition ratcheted with evidence tests; boss-proxy allowlist extended per measured caller incl. method-scoped PUT/DELETE + two unbuffered streams. MEASURED corrections: cellFetch ignored its cellId (all traffic was boss-origin — the map's cell13/14/15 attributions were routing metadata only); moe/moa are LIVE via the orchestration chain to mounted /chat, not 0-importer. Step-7 remainder measured at 47 client-importable files reading NEXT_PUBLIC URL envs: flags.ts (presence-gating semantics — own slice), 2 server-only closures (api-config, connector-gateway — importers are route handlers only), 44 out-of-zone = a2a/WS/SSE transport family (step-8-class), cloud-run-client, agents/, 9 component-inline fetches, 8 page-inline. Prior state: 2026-08-07 update; steps 8-10 + metrics/nervousSystem drains landed 2026-08-06/07 via owner-directed merge 8534ef9a, live-verified — memory inbox record; this session's step-7 wave 79f5efb: lib/api/boss.ts (21 allowlisted shapes on /api/boss-proxy), agent-ide.ts non-chat (28 calls, server-side CELL_REGISTRY fan-out), relu-client.ts (/api/relu-proxy, SSE pass-through), useKnowledgeGraph (stale-map correction: already same-origin), BossQuickstartView. MEASURED no-ops: BossAgentFooter HTTP already same-origin (residual = its step-8 A2A WebSocket read); useDataStream pure WS. Corrected remainder: lib/api/client.ts has 14 importers (map said 1) and drains together with the moe/moa/coding-moa/events stream consumers; config.ts NOT 0-importer; WS/A2A transport family (a2a, use-event-source, streamChat SSE internals) is the remaining step-8-class scope. Historical detail: steps 1-4 done + step 5 COMPLETE (5/5 surfaces) (2026-08-05) — all five live chat surfaces repointed onto the governed route behind per-surface BOSS_CHAT_GOVERNED_SURFACES flags (chat, footer, media-agent, boss-srpvdal, useBossAgentChat); each default flag-off = byte-identical, per-surface rollback = env change; governed branches parse the { data, traceId } envelope and render errors honestly (no silent WS fallback on the footer). Step 6 done — agent-IDE CHAT drained onto same-origin: new /api/ide/boss-chat verbatim authed pass-through (non-stream) + reuse of the existing /api/boss/chat/stream for SSE; sendChatMessage/streamChatResponse no longer make browser-direct cross-origin calls to the boss URL (both now relative paths; the boss URL resolves server-side in the route). The IDE's 28 non-chat calls (workspace/GitHub/Drive/snapshots/sessions/MCP/terminal) still use the cross-origin URL — deferred to later step-6 slices per the map. Step 7 mechanism established + first module — lib/no-public-backend-url.ratchet.test.ts is the append-only NEXT_PUBLIC ratchet (1C pattern extended bundle-wide); lib/api/srpvdal.ts is the first cleaned module (7 browser-direct cell calls → same-origin /api/srpvdal/[...path] authed proxy). ~30 other client modules remain, one ratchet entry per push. Remaining 2D: finish step 7's module sweep + steps 8-10 (WS consolidation, 404-feature fixes, owner-gated HD-2 archival). Branch synced with main (v2 auth bridge + strict flags) before this slice. Earlier: steps 1-4 — — step 5.1: /chat repointed onto the governed route behind the server-config flag BOSS_CHAT_GOVERNED_SURFACES (comma list, NEXT_PUBLIC-free, prop-threaded from the server page; unset = legacy path byte-identical — today's production; rollback = env change). Governed branch in useChat: shared step-3 sessionId as conversationId, enum-validated orchestration parity on the route, {data, traceId} envelope with traceId onto message metadata, honest envelope-error rendering incl. the 401 gate state. Remaining repoints (footer, media-agent, boss-srpvdal, useBossAgentChat) follow one per push. Step 4 was — step 4 (server session truth, read slice): measured GET /api/v1/conversations/{id} (Section 12 — the read side of the SAME FirestoreConversationManager the chat handler persists through, so the governed path's write truth was already server-side); new identity-gated /api/bff/boss/conversations/[id] lets surfaces rehydrate from the SERVER instead of localStorage — the legacy route's in-instance Map plays no part in the governed path. Upstream DELETE measured, deliberately unwired (mutations follow the role-gated pattern); per-USER conversation LIST has no canonical endpoint (legacy_state_manager only) — registered as an HD-4 read-API candidate. Step 3 was — step 3: ONE session identity — shared getBossSessionId()/resetBossSessionId() over the pre-existing boss-chat:session-id key (monotonic mint, SSR/storage-failure-safe), adopted by all five live chat callers: footer (was minting a NEW id per MESSAGE — defect S5, server memory defeated by design — 3 sites), useBossAgentChat (per-mount mint), SRPVDAL + media-agent (sent none), useBOSS unified onto the helper (clear-chat resets through it). 7 tests incl. the map's cross-component-share RTL case; user-visible check: footer conversation survives navigation. Step 1 was — governed POST /api/bff/boss/chat stands beside the legacy proxy (zero callers changed): typed chat() from the measured ChatRequest/chat_v1 contract, identity gate (chat is an invocation surface), bounded message validation, upstream clientId from VERIFIED identity only (test proves body-supplied clientId is ignored — the correction of the legacy client-supplied-identity trust); chatStream deferred with recorded reason (SSE cannot ride callService's JSON/timer contract — needs a gateway streaming primitive). Step 2 (authedFetch on the legacy proxies) landed in audit #2. Measurement (map) was — docs/frontend/ONE_BOSS_CONSOLIDATION.md: measured inventory (1 global shell + 18 mounted Boss surfaces + 6 orphaned chat components; 6 HTTP client modules; 9 disjoint session stores; 7 WS/A2A transports across 3 protocol families; 52 files referencing NEXT_PUBLIC_BOSS_AGENT_URL), ranked risks R1–R6, PROPOSED target architecture + 10-step additive migration sequence. Security findings for the next increment: primary chat proxy (app/api/boss/chat*) forwards with raw unauthenticated fetch (anonymous door while flag-off; fleet-wide chat outage the day Boss is IAM-locked); 3 mounted components call nonexistent routes (guaranteed 404s); footer mints a new sessionId per message
2E Channels/connectors parity patterns (Data Manager API rule) VERIFIED (first slice) (2026-08-05) — /channels parity workspace over lib/channels/connector-registry.ts: transcription of the governed-connector mandate (9 providers with rollout waves 1-3 + wave-4 category, 12 production gates, status vocabulary VERBATIM with the mandate's live-verified definition) joined to MEASURED status — the canonical gateway service-marketing-connectors EXISTS with all nine providers registered (Shopify first-class: HMAC webhook + Admin GraphQL backfill; eight fail-closed direct-pull adapters; everything forwards through service-canonical-ingestion), so all nine carry implemented and NOTHING stronger (serving revisions unverifiable from a checkout — the invariant test forces a conscious, evidence-carrying edit to ever upgrade); Data Manager rule measured (validate_only: bool = True default, consent 422 gate, hashed identifiers); GAQL surface honestly described as the Cell-29 sensing/read workspace, not connector ingress. 13 registry invariants (incl. gateway-source parity against main.py) + 7 page tests; nav: channels group rooted at /channels with a Connectors entry

Phase 3 — Experience & quality bar

Item Status
3A Tokens + primitives + workbench PARTIAL — slices 1+2 VERIFIED (2026-08-07; slice 2 §31, slice 1 §27) — Slice 2: banner-cluster primitive components/ui/banner.tsx (Banner + BannerTitle/BannerBody/BannerTrace; measured tone×tier class matrix byte-pinned by test — error/warn/success × xl/lg/md + neutral loading tier on the 3A tokens; role/testid passthrough; tone explicit on internals so the set stays server-component-safe) + components/ui/stat-tile.tsx riding Tile (value/delta lines verbatim; scaffold StatTile removed at verified 0 importers); 26 banner sites swapped render-identical across approvals/events/kg-live/cells/actions + bff-states/kg-ledger-browse/redeem-authorization; page tests pass UNMODIFIED (668/668). Deliberately left: the /20-border note family, DEMO watermark, button chips, cells' two bespoke panels (§31.2). Slice 1 (§27): Operator Dossier tokens on :root + Tailwind theme (every value the MEASURED de-facto palette, zero restyle; --od- prefix collision-forced by the marketing homepage's styled-jsx variables); 5 primitives w/ 18 tests (StatusBadge, Tile, DataTable, SectionLabel + single-source ILLUSTRATIVE_LABEL, TraceFooter); 12 command-center pages refactored. Remaining: shadcn variable set + darkMode:'class' (fleet-restyle risk — own slice), workbench
3B Command palette, deep links, saved views PROPOSAL DELIVERED (2026-08-07) — docs/frontend/SAVED_VIEWS_PROPOSAL.md (deep-link param conventions per surface + v0 SavedView schema + storage-tier decision + owner questions). Palette shipped in 1A; build gated on the owner answering §5
3C WCAG 2.2 AA program PARTIAL — slice 1 VERIFIED (2026-08-07 session 10, §30) — axe serious+critical gate 6 → 15 pages (all primary mounted top-level surfaces; every serious finding fixed incl. measured homepage styled-jsx contrast lifts ≥6.2:1; /cells excluded by measurement — the [kernel] fix 404s it); CommandPalette dialog focus-return contract fixed (was silently dropping to <body>); e2e/keyboard.spec.ts (login tab order, palette focus/Escape-return, sidebar traversal); a11y scan budget 90s + reduced-motion emulation (runtime budget — the violation gate is unchanged, never loosened). Remaining: the witnessed screen-reader pass (owner/operator), deeper interior pages
3D Perf budgets, code-splitting, virtualization, cache policy SLICE 2 VERIFIED — cache policy CLOSED (document-only, measured) (2026-08-07 session 9b, §29) — /operations/email-intelligence 262→106 kB (−60%) and /operations/unified-revenue 253→106 kB (−58%) First Load JS via the /analytics thin-wrapper precedent (bodies byte-copied; fallbacks mirror each page's own idiom); wave-close build re-confirmed EXACT vs the concurrent-tree build. Cache policy measured decisively (PERF_BASELINE §10): the next.config catch-all no-cache, no-store, must-revalidate overrides every route-level Cache-Control on the wire (verified by local serve), /_next/static immutable — so route-level no-store would change zero wire bytes; recommendation recorded (bake no-store into a future central BFF emitter; do not relax the catch-all without revisiting the two dead-letter public, max-age routes + SSE no-transform). Slice-1 (§27): /analytics −82%, /kg/ecosystem −30%, /kg/live −22%; virtualization measured-SKIPPED. §9.4 re-ranked candidates next: /boss/realtime 263 kB, /visualize/[kernelId] 252 kB, /operations/cell32-optimizer 232 kB
3E OTel instrumentation of BFF + client error reporting VERIFIED (first slice) (2026-08-07, §26) — CLIENT span per callService (tracer bff-gateway; service/path/status/traceId/outcome attributes; ERROR only ≥500; API-only, SDK-less no-op test-proven); traceparent propagated beside x-request-id; client error reporter (batch/rate-limit/PII-free/no-loop) → /api/client-errors sink (size/rate ladder, structured logs). +32 tests. Log-sink alerting = operator option
3F CSP + security hardening + focused reviews PARTIAL — report-only slice LIVE-VERIFIED (2026-08-08, §31.1: the exact header set measured serving on production — CSP-Report-Only + Reporting-Endpoints + nosniff + Referrer-Policy + XFO DENY + Permissions-Policy; /api/csp-report answering 204 live). Shipped 2026-08-07 (§26) with per-directive tightening notes; both telemetry sinks in PUBLIC_ROUTES. Operator follow-up unchanged: report-only → enforce after ≥2 weeks quiet reports + nonce pipeline (the header-contract test deliberately fails on an enforced CSP until consciously edited)
3G Full test matrix (unit/component/route/contract/e2e/visual) PARTIAL — e2e+a11y foundation VERIFIED + MSW landed (2026-08-07 update, §26–§27) — MSW 2.15 at the network edge (empty defaults + bypass; 4 suites migrated, URL contracts now proven at the edge); e2e +3 journeys (palette, 404 honesty, approvals tri-state via measured-envelope fixtures); axe list now SIX pages (serious+critical=fail, ratchet unchanged). Session-7 foundation retained: Playwright vs the production standalone artifact, real shell a11y fixes, verify script. Remaining: CI e2e wiring (SSH operator follow-up), visual regression, mutation e2e (HD-3)
3H Remove ignoreBuildErrors/ignoreDuringBuilds; strict TS; SWR/dead-code removal strict TS COMPLETE + toSafeUrl family CLOSED (2026-08-07, §27) — the "362 warnings" were a truncated-pretty-stream artifact; authoritative JSON measured 444, of which ~431 were STRUCTURAL false positives (the esquery > child selector matched the callee/LHS node itself — probe-verified). Fixed the 13+1 genuinely-dynamic sites (zero behavior change), then refined the selectors to field-level (> .arguments / > .right, router-scoped) with a both-directions probe: family 444 → 0, total warnings 558 → 115, protection intact. Dead-code verdicts recorded (report-only): lib/api/{change-detection,media-autopilot,production-client,coding-moa,rewoo,supabase-client}.ts + lib/time.ts measured 0-importer (archive slices pending); @miz-oki/boss-agent + AgentVoiceBridge confirmed already archived w/ clean barrels. Earlier: strict TS slices 1–3 (sessions 6-7, §20.1/§21.2/§24.4). Session 9 (both branches, §28 + §29): archive moves EXECUTED — 15 unique modules — 9a: the 7 verdicted + the events family (ActivityFeed, hooks/api/useEvents, lib/api/events.ts, lib/useSSE — 0-importer AND upstream REST measured ABSENT); 9b: the same 7 re-measured independently + lib/provenance/{client,index,types}.ts + lib/supabase/fetcher.ts; moe/moa re-measured LIVE in both and kept; tsc 0 after each move; 9b's never-live cell22-proxy archived in the §29.5 reconciliation. Remaining: 114 other-rule warnings (authoritative JSON: react/no-unescaped-entities 59, react-hooks/exhaustive-deps 39 — behavior-risk class needing per-site review, import/no-anonymous-default-export 9, @next/no-img-element 5, jsx-a11y/alt-text 1, no-page-custom-font 1)

Phase 2D step 10 — Orphaned Boss chat components + duplicate clients archived (session 7)

2026-08-06 — Archive-only slice (ONE_BOSS_CONSOLIDATION §4 step 10; §1.1.3 / §1.2 / §1.5 / §6.2). Eight verified-orphan modules moved into archive-ui/ via git mv (history preserved as R-renames; the tree is already tsconfig.json-excluded, so the move drops them from tsc/build with no config change — the established non-breaking pattern). Non-breaking confirmed: npx tsc --noEmit clean (0 errors) after all eight moves — no dangling import references any archived file. Step-10 definition-of-done (0-importer greps + build green + ledger entries) met.

Re-measurement (critical — the §1 map is dated 2026-08-05). Importers were re-counted across the ACTIVE tree only (app/ components/ hooks/ lib/ store/, excluding archive-ui/), covering static imports, barrel re-exports, and dynamic import(). A module was archived ONLY at 0 live importers:

Archived → archive-ui/<same relative path> Live importers 0-importer evidence
components/PersistentBossChat.tsx 0 only self-export; other hits are docs (README / CLAUDE.md / A2A_INTEGRATION_COMPLETE.md) + an archive-ui/ comment
components/EnhancedBossChat.tsx 0 stale-map correction — §1.1.3 recorded "imported only by EnhancedBossChatCompact"; re-measure shows Compact NO LONGER imports it (Compact imports: react, lucide, @/lib/a2a/client, @/hooks/useMediaCapabilities, @/lib/voice*). Now an independent orphan
components/EnhancedBossChatCompact.tsx 0 only self-export
components/boss-system-components/BOSSChatAdvanced.tsx 0 only self-export; the lone hooks/api/useCells.ts:14 hit is a comment, not an import
components/BossAgent.tsx (the COMPONENT) 0 every …/BossAgent' import specifier resolves to @/agents/orchestration/BossAgent — a DIFFERENT, still-live type/orchestrator module (imported by app/test-orchestration, components/CausalOverlay, app/api/agents/orchestrate/route.ts), left untouched. The component itself has no importer
lib/api/boss-api.ts (§1.2 C2) 0 no api/boss-api importer; distinct from live lib/api/boss.ts (C1, 31 KB, widely imported) and from the doc-only never-existed boss-api-client.ts (hooks/api/index.ts:140-166 DISABLED notes); no lib/api/index.ts barrel exists. Matches map "Zero importers"
lib/production-a2a-client.ts (§1.5 T3) 0 socket.io client; only doc references. Matches map "zero importers" (also the step-8 T3 archival target)
lib/websocket.ts (§1.5 T6, MizOkiWebSocket) 0 no lib/websocket / ./websocket importer in the active tree. Matches map "zero importers" (also the step-8 T6 archival target)

Mirror dirs created: archive-ui/components/boss-system-components/, archive-ui/lib/api/.

SKIPPED (kept live — import-closure NOT orphaned): - components/agent-ux/AgentVoiceBridge.tsx — re-exported by the live barrel components/agent-ux/index.ts (:152, :156-157), which is imported by the mounted page app/agent-ux/page.tsx:25 (from '@/components/agent-ux'). §1.1.3 listed it "grep: only self-match", but that measurement missed the barrel re-export; archiving it now would leave a dangling re-export in an out-of-scope barrel and break tsc. Deferred until the barrel export can be pruned in the same slice.

Deliberately not touched this slice (follow-ups): - packages/@miz-oki/boss-agent/ (§1.2 C5, zero-importer per map) — left in place (workspace-package resolution risk); flagged for a dedicated later slice. - The mock hooks/useBossAgent + CreativeStudioPanel repoint named in step 10 — belongs to the CreativeStudioPanel (live-surface) workstream, out of this slice's scope.

HD-2 PROPOSED permanent removals / route-redirects (owner-gated, traffic evidence required) are recorded in docs/frontend/HD2_ARCHIVE_PROPOSALS.md. Nothing is deleted or redirected in 2D itself; HD-2 stays OPEN.


Zero-Mock sweep + Central URL step-8 completion (session 12, 2026-08-09 → 2026-08-12)

Owner directives executed: "All mock data must be removed" (Zero-Mock, Law #1) and the Central URL / NEXT_PUBLIC → same-origin drain driven to completion. Full per-slice evidence: FRONTEND_VERIFICATION.md §33. All states implemented + merged (auto-merge to main); nothing below is claimed live-verified.

Landed commits: a54ddc2d, c7d57d3d, 9c8d0c21, ae14e9ec, 36a1d73b, 097d0cdb, 6c04b785, 52f5d26e (Zero-Mock); 6e6bd1be, 17cdaef0 (step 8); 48dabb63 (SSE). Final gates: tsc 0 · lint 0 errors · full vitest 874/874 · build 0.


Open HUMAN DECISION register

# Decision Context Status
HD-1 IdP consolidation (Supabase vs Firebase Auth vs keep-hybrid) Evidence in ROUTE_INVENTORY §5; two independent measurements converged on Supabase CLOSED (2026-08-05) — owner signed off all stage-1 parts; ADR-002 ACCEPTED; live flip = operator credentials + REQUIRE_AUTH
HD-2 Route removals (any deletion beyond redirect/archive) Charter forbids removal without migration evidence + approval; 2D step-10 archival receipt + proposed permanent removals/redirects in docs/frontend/HD2_ARCHIVE_PROPOSALS.md (+7 newly-measured 0-importer modules appended 2026-08-07 — archive moves executed session 9 (both branches) per §28 + §29; §1d six-family slice executed 2026-08-08). P1 EXECUTED 2026-08-12 — the 20 enumerated modules + archive-ui/packages/@miz-oki/boss-agent deleted; the permission block recorded on 2026-08-08 no longer applied. The doc's "shrink the ratchet in the same commit" instruction was re-measured and found STALE: with the entire archive-ui/ tree moved aside, no-public-backend-url.ratchet.test.ts + ws-transport.freeze.test.ts both pass (39/39) — zero ratchet entries were resolving through an archive-ui mirror, so no guard was shrunk and none needed to be. The §1d six families are NOT in P1 and remain (retention window from 2026-08-08). §3 redirects still lack their traffic-evidence precondition OPEN (P1 closed; §1d retention + §3 traffic evidence remain)
HD-3 Staging/non-prod tenant for approval/action e2e tests Required before any mutation testing. Operator action — cannot be closed in code: it needs a provisioned non-prod tenant, which is a credentials/environment task per AGENTS.md 7.6. Blocked on the same provisioning as the Supabase flip (docs/frontend/SUPABASE_PROVISIONING.md) OPEN (operator)
HD-4 New backend read endpoints on governance services (adds backend scope) CLOSED (2026-08-08) — endpoints implemented 2026-08-06 (§22); operator ran deploy_all.sh GREEN and the read-APIs are live-verified (mizoki-platform impersonation; mizoki-ui-sa invoker on the six services + ALLOWED_CALLER_SA — operator memory record, §31.3). Remaining condition for on-screen tenant data is the auth flip (sessions carry identity/tenant); BFF routes answer honest 401s until then — correct posture CLOSED
HD-5 apps/web retirement (root CLAUDE.md operator follow-up already flags it) Confirm no CI depends on it before archive. CLOSED 2026-08-12 — tree deleted. Preconditions re-measured first: frontend-guard.yml triggers only on miz-oki-command-center-ui/** (the apps/web Zero-Mock lane was dropped in 0e94f510); no workflow runs a root-level npm ci (ekis-ci and frontend-guard both set working-directory); nothing in deployment/, Dockerfile, or any cloudbuild references it. Retired as a DELETE rather than the archive/apps-web move attempted on 2026-08-08 (owner-directed 2026-08-12); git history is the recovery path. Wiring cleaned in the same change: apps/* dropped from root workspaces, the !/apps/ + !/apps/web/ un-ignore lines dropped from .gcloudignore, and the apps/web / node_modules/web entries pruned from package-lock.json surgically (34 lines) — a full npm install --package-lock-only rewrote 14,008 lines of pre-existing lockfile staleness and was deliberately reverted rather than bundled here CLOSED
← All docsView source on GitHub →