Shadow Activation, Shopify Operator Credentials, SerpApi Revocation, Owner Decisions — Consolidated Status

Date: 2026-08-27 (evening; main HEAD 4e79bda at compile time) Session: wkky3z (branch claude/activation-approval-vendor-creds-wkky3z) Question answered: "Has this been started / processed / built? If not, build it; if it has, report where we are." Method: governed read-set + task-routed memory, then direct verification — repo content greps against origin/main, workflow-file inspection, GitHub Actions run conclusions via API, and the dated measured reports named per row. gcloud is absent in this sandbox, so Cloud Run revision facts are inherited from the same-day measured reports (cited inline), never asserted fresh here.


0. Verdict

All four threads are started, and every agent-buildable half is BUILT and on main. Nothing needs a restart. What remains is exactly the owner/operator tail: two typed GATE-2 approvals, one deploy dispatch + one runbook deploy, a short list of credentials/config values, one vendor-side key revocation, and the standing decision register (§4). Nothing in this report flips a flag, deploys a service, or invents a value — per the collected-is-not-armed rule.

Thread Buildable half Owner/operator tail
1. Shadow activation approval DONE — GATE-1 ×2 merged; GATE-2 plan written; its W3/W4/W5 zero-caller blocker closed (cc4126f1); net-yield dispatch executed Typed GATE-2 go ×2, flag flips (gcloud), growth-scheduler dispatch, rails runbook deploy, 2 additive DDLs + smokes
2. Shopify operator credentials DONE — fail-closed paths, runbooks, preflight table all landed App-cred validity proof, first real store webhook, pixel pair, Klaviyo keys, costs/roster values
3. SerpApi key revocation DONE — redaction serving, rotation closed at v13, credential-shape health leg Revoke bb45ed0ca6eb at serpapi.com (owner; vendor dashboard)
4. Owner decisions DONE — this §4 is the consolidated, verified register Decide/close the items listed

1. Shadow activation approval — where it stands

Landed (verified by content/ancestry on origin/main)

  1. Shopify Merchant Expansion v1.0 W1–W6, GATE 1 — code merge 51cbb7a6 + docs ab248164, clean fast-forwards. All five new flags default OFF at source literals with fail-if-flipped tests (docs/reports/SHOPIFY_EXPANSION_BUILD_2026-08-27.md §3).
  2. Autonomy Foundations v1.0, GATE 1 — main tip == branch tip 2aa5480cd on owner Approved:merge (~19:0xZ); Deploy Router 33106744488 dispatched 4 deploys, all SUCCESS (docs/reports/AUTONOMY_FOUNDATIONS_BUILD_2026-08-27.md).
  3. GATE-2 shadow-deployment plan — docs/reports/SHOPIFY_GATE2_SHADOW_DEPLOY_2026-08-27.md: sequence, per-flag commands, rollback one-liners, shadow-metric queries. Design document; nothing executed by it.
  4. The plan's Step-4 blocker is CLOSED. The plan found W3/W4/W5 (RETENTION_COHORTS, CREATIVE_FATIGUE, KLAVIYO_FEED) had zero production callers — flipping them would have been a silent no-op. cc4126f1 (2026-08-27 ~19:2xZ, gate2-w3w4w5-wiring session) landed the callers, verified by content on origin/main this session: - services/growth-scheduler/main.py:722 → POST /api/v1/f2/retention-cohorts - services/growth-scheduler/main.py:748 → POST /api/v1/creative/fatigue - services/measurement-rails/main.py:718 → POST /v1/rails/klaviyo-value-feed:send 61 new tests; tests/governance (859) + services/measurement-rails (450) recorded green fresh-venv by the landing session (ledger record 0bca89a — inherited here, not re-run).
  5. Net-yield dispatch (GATE-2 plan Step 2, part 1) is DONE — run 33106133149 (2026-08-27T18:58Z, workflow_dispatch) SUCCESS, measured via the Actions API this session. W1 code now serves flag-off (net-yield-00012-xwn per STATUS_REPORT_2026-08-27.md §2).

Not yet serving (measured this session via Actions API + workflow files)

The approval the owner actually types/does, in order

  1. Review SHOPIFY_GATE2_SHADOW_DEPLOY_2026-08-27.md + this report; give the typed GATE-2 go for the Shopify lane.
  2. Operator executes Step 1 — INVENTORY_SPEND_GATE=true on service-action-runner (the only fully-wired, serving flag). Soak 48–72h. One flag, one service, one soak window — never two in the same window.
  3. Step 2 part 2 — RETURNS_ADJUSTED_NCM=true on net-yield (dispatch already done). Soak ≥ one order+return cycle.
  4. Dispatch deploy-growth-scheduler.yml (dark) and run the measurement-rails operator runbook deploy; then W3 → W4 → W5 flag flips, one soak window each (per-flag commands + rollbacks in the plan §2–§3; replace-semantics caveat applies to every --set-env-vars).
  5. Separately: type APPROVED: DEPLOY for Autonomy Foundations GATE 2; operator applies the two additive DDLs and runs the CLI fixture smokes.

W6's reconciliation meter is not a flag — it is one watched manual run of ops/reconciliation/run_reconciliation.py, blocked on merchant credentials (§2, register item 6).


2. Shopify operator credentials — measured state, credential by credential

Correction carried into the two 08-27 reports in this same commit: the STATUS_REPORT §4 / GATE-2 plan §5 lines saying app creds are "absent / no client_id anywhere" describe the code/terraform fail-closed defaults, not the live project. docs/reports/SHOPIFY_SECRETS_STATUS_2026-08-25.md measured Secret Manager directly two days earlier: all three governed secrets are populated with real-format material and mounted on the serving gateway revision. Both readings are reconciled below; the register item that survives is validity, not existence.

Credential Measured state Evidence What remains (whose)
shopify-app-client-id / shopify-app-client-secret Populated + mounted, SHOPIFY_OAUTH_ENABLED=true 08-25 shape probe (32-hex / shpss_+32-hex; 1 & 5 versions); mounts in the reviewed workflow (deploy-service-marketing-connectors.yml:201-202, re-checked on main this session); gateway redeployed green 08-27 19:09Z (run 33106781210) Validity vs Shopify unproven — format ≠ authentication. Proof = one OAuth token exchange / merchant install visit (owner, SHOPIFY_CONNECT_RUNBOOK.md). A stale payload fails at Shopify's far end, merchant-visible.
shopify-webhook-secret (SHOPIFY_WEBHOOK_SECRET) Populated (2 versions) + mounted; HMAC verification real on the one governed receiver Same 08-25 report §1/§3; fail-open HMAC fixed 19cc1343d (08-18) First REAL store webhook delivery (register 6c) — app miz-oki-commerce-link-5 released, 13 topics → Pub/Sub, delivery proven only via CLI trigger; zero genuine merchant deliveries ever.
Pixel pair: SHOPIFY_PIXEL_COLLECT_URL + SHOPIFY_PIXEL_INGEST_SECRET Unset — no lines in the reviewed workflow env list (checked this session); activation defers loudly ("status": "deferred", "reason": "pixel_collect_url_unset", service-marketing-connectors/main.py:954-981) grep + workflow read Operator: build/host the pixel-extension artifact, set both values via the reviewed workflow (replace semantics — hand-set values are wiped on the next deploy). Note the correct var name is …_COLLECT_URL, not the task-brief's …_EXTENDER_URL.
Klaviyo #1 — KLAVIYO_PRIVATE_API_KEY (W5 value feed) Unset; klaviyo_feed.health() → not_configured; now in the rails RUNBOOK secret-name table (preflight drift healed by 2aa5480c) AF build report; operator_preflight.py 0 DRIFT per cc4126f1 record Operator secret + rails runbook deploy; dark regardless of the KLAVIYO_FEED flag until set.
Klaviyo #2 — intent-klaviyo-api-key (6c extender) Secret exists, no real version; CI already mounts :latest register item 6c (unchanged this window) Operator: add a real version + bounce the revision.
Klaviyo #3 — per-tenant key + webhook secret (KLV-1 pull half, W7 webhook half) Tenant-owned; collected via the Connectors catalog / authenticated onboarding UI only (.claude/rules/tenant-onboarding.md) KLV-1 record; W7 build report Tenant supplies via UI; owner: license review (ontology/sources/klaviyo.yaml = PENDING_BOSS) + live signature verification before the W7 flag ever flips.
net_yield_costs real values 5 NULL cost rows; every dependent order economics_complete=false by design register item 21 Operator/tenant (onboarding UI carries net-yield costs per the tenant-onboarding rule).
INVENTORY_SPEND_GATE_CONFIG_PATH roster/velocity Ships empty by design; not_configured rows, never invented demotion W2 build report Operator, informed by the W2 soak's observed provider/action roster.
Reconciliation runner (register item 6) Code-complete, inert GATE-2 plan §2 Step 3 Merchant credentials + RECONCILIATION_EVENTS_TABLE, then one watched manual run.

Collected is not armed: none of the above starts a pilot, flips a writeback, registers a holdout, or widens autonomy — activation still runs the governed approval/holdout/DCP paths.


3. SerpApi vendor-side key revocation — where it stands

State per register item 32 (recorded 2026-08-25; no newer record exists — git log --grep=serp since 08-25 returns only the unrelated L-06E alert-policy commits, checked this session):

The one remaining action is the owner's, at the vendor: revoke bb45ed0ca6eb in the serpapi.com dashboard. disable in Secret Manager only stops MIZ OKI reading it — the vendor-side credential is still technically live for anyone holding the disclosed value until the exposed entries expire and/or the key is revoked. This cannot be executed or verified from the repo; once done, record it on the ledger so item 32 can close.


4. Owner decisions — the consolidated register (verified today)

A. Approvals to type (blocking the two GATE-2s)

  1. Shopify Merchant Expansion GATE-2 shadow-activation go (plan §1 above).
  2. Autonomy Foundations APPROVED: DEPLOY (+ operator DDLs + smokes).

B. Shopify register decisions — Step-0 item 6, re-verified 2026-08-27 (SHOPIFY_CLOSEOUT_VERIFY_2026-08-27.md Item 6): all 7 genuinely OPEN

  1. Decision 3 — Profit Truth Audit wedge go/no-go.
  2. Decision 9 — citation sign-off: unblocked (5/5 PASS, CITATION_CHECK_2026-08-11.md) but never formally closed by the owner.
  3. Decision 12 — L5 blueprint phase-name confirmation (blueprint never landed on the board).
  4. Decision 13 — 30-day plan wholesale vs. triaged.
  5. Decision 14 — EU data-residency mechanism (with counsel). No EU merchant onboards before this.
  6. Decision 15 — holdout-share covenant floor by tier (value undeclared).
  7. Decision 17 — Stage 1–4 benchmarks: contractual SLA vs. internal target (until decided, benchmarks stay out of merchant-facing contract language).

C. Autonomy Foundations §6 list (new 2026-08-27)

  1. PORTFOLIO_RISK_POLICY cap values per (tenant, currency, channel-group).
  2. W5 first certification candidates + the owner-approved certification program document (L5-CERT-1 flip condition; real evaluations also wait on real forward labels — register 17/6c/23).
  3. Klaviyo license review + per-tenant webhook secrets + live signature verification (pre-flag-flip; also §2 above).
  4. TTD seat (TTD-1 unchanged).
  5. Capital/Risk/Estate go/no-go (CELL-CRE-1).
  6. Distillation go once W6 baselines exist against live models (DIST-4 = a recorded run).
  7. W1/W2 residual deltas (per-cycle BQ reconciliation job, correlation-aware concentration warning, log-based alert policies — GATE-2 protected-path terraform).
  8. "GC r2.1" does not exist as a Growth Control revision — if a different board document was intended, name it and it lands byte-identical.

D. Standing register items (unchanged this window; sources in current-priorities.md)

  1. Item 20 — briefing approval.
  2. Item 21 — net_yield_costs NULLs (also §2).
  3. Item 22 — measurement secret VALUES + BQ DDL confirms.
  4. Item 23 — FIRST real registered holdout (writebacks stay hard-false until it exists; no intent activation is legal without it).
  5. Item 31 — boss-rewoo-orchestrator min-instances (optional comfort).
  6. Item 32 — SerpApi vendor revocation (§3).
  7. Items 9/12 operator sequences (GraphRAG seed-first raise; cell3 watched manual run then human-PR scheduler), item 14 (78/107 default-SA services), item 6c per-source afferent steps (GA4 / TTD / Klaviyo / mizoki-events), 10 design partners (P1 exit).
  8. L-06E — the F4 cap-approach metric + alert policy landed 08-26 (88451b0, PR #850); the register row stays OPEN pending the operator apply/attach leg (ddf292a NEEDS_ACTION: six of seven alert policies dispatch to nobody; attach MIZ OKI Ops (email) and test-fire).

E. One live deploy regression needing a decision

  1. gemini-kg-pipeline: PR #854 (dedicated SA + JourneyEvent canonical-forward activation) merged 08-26, but its deploy run 32971557546 FAILED and no retry has run since (measured this session via the Actions API — last success is still 32432405545, 2026-08-21). The change is on main, not live. Decide: fix-and-redispatch (respecting AGENTS 7.7 drain safety) or accept implemented, not deployed for now. SUPERSEDED LATER THE SAME DAY (dated note by the 22:xxZ closeout sweep): resolved as fix-and-redispatch — root cause was the SA-precondition race; deployment/terraform/gemini_kg_pipeline_sa/ was applied ~16:17Z and redeploys succeeded (runs 33111045522 → rev 00076, 33112711137 → rev 00077-5hq serving 100% under the dedicated SA; unauth /health 403, authed probe green). Authority: STATUS_REPORT_2026-08-27.md as trued in e1cecf6; this row is history.

5. Evidence and non-independence

Measured directly this session: origin/main content greps for the cc4126f1 routes; deploy-growth-scheduler.yml / deploy-net-yield.yml / deploy-gemini-kg-pipeline.yml run lists and conclusions via the GitHub Actions API (run ids above); gateway workflow secret mounts + SHOPIFY_OAUTH_ ENABLED=true on current main; pixel env absence from that workflow; registry rows for growth-scheduler / measurement-rails; git log sweep for post-08-25 SerpApi records; shopify_install.py token-refresh fail-closed path; TokenRefreshError call-site inventory.

Inherited from dated records (not re-measured — gcloud absent here): Cloud Run revision names/timestamps (GATE-2 plan §1, same-day gcloud); Secret Manager payload shapes (08-25 secrets report); suite-green claims for cc4126f1 (ledger record 0bca89a) and both GATE-1 batteries (their build reports); SerpApi Secret Manager/logging state (item 32, 08-25). Where a claim above is inherited, its source is named on the row.

Corrections applied in this commit (rule 01 — fix the claim where it lives): STATUS_REPORT_2026-08-27.md §4 items 1–2 and SHOPIFY_GATE2_SHADOW_DEPLOY_2026-08-27.md §5 items 1–2 now carry a dated correction pointing at the 08-25 secrets measurement; the GATE-2 plan also gains a dated update noting its Step-4 blocker closed (cc4126f1) and its Step-2 dispatch executed (run 33106133149).

← All docsView source on GitHub →