Shadow Activation, Shopify Operator Credentials, SerpApi Revocation, Owner Decisions — Consolidated Status
Date: 2026-08-27 (evening; main HEAD 4e79bda at compile time)
Session: wkky3z (branch claude/activation-approval-vendor-creds-wkky3z)
Question answered: "Has this been started / processed / built? If not, build it; if it has, report where we are."
Method: governed read-set + task-routed memory, then direct verification — repo
content greps against origin/main, workflow-file inspection, GitHub Actions run
conclusions via API, and the dated measured reports named per row. gcloud is
absent in this sandbox, so Cloud Run revision facts are inherited from the
same-day measured reports (cited inline), never asserted fresh here.
0. Verdict
All four threads are started, and every agent-buildable half is BUILT and on
main. Nothing needs a restart. What remains is exactly the owner/operator
tail: two typed GATE-2 approvals, one deploy dispatch + one runbook deploy, a
short list of credentials/config values, one vendor-side key revocation, and
the standing decision register (§4). Nothing in this report flips a flag,
deploys a service, or invents a value — per the collected-is-not-armed rule.
| Thread | Buildable half | Owner/operator tail |
|---|---|---|
| 1. Shadow activation approval | DONE — GATE-1 ×2 merged; GATE-2 plan written; its W3/W4/W5 zero-caller blocker closed (cc4126f1); net-yield dispatch executed |
Typed GATE-2 go ×2, flag flips (gcloud), growth-scheduler dispatch, rails runbook deploy, 2 additive DDLs + smokes |
| 2. Shopify operator credentials | DONE — fail-closed paths, runbooks, preflight table all landed | App-cred validity proof, first real store webhook, pixel pair, Klaviyo keys, costs/roster values |
| 3. SerpApi key revocation | DONE — redaction serving, rotation closed at v13, credential-shape health leg | Revoke bb45ed0ca6eb at serpapi.com (owner; vendor dashboard) |
| 4. Owner decisions | DONE — this §4 is the consolidated, verified register | Decide/close the items listed |
1. Shadow activation approval — where it stands
Landed (verified by content/ancestry on origin/main)
- Shopify Merchant Expansion v1.0 W1–W6, GATE 1 — code merge
51cbb7a6+ docsab248164, clean fast-forwards. All five new flags default OFF at source literals with fail-if-flipped tests (docs/reports/SHOPIFY_EXPANSION_BUILD_2026-08-27.md§3). - Autonomy Foundations v1.0, GATE 1 — main tip == branch tip
2aa5480cdon ownerApproved:merge(~19:0xZ); Deploy Router33106744488dispatched 4 deploys, all SUCCESS (docs/reports/AUTONOMY_FOUNDATIONS_BUILD_2026-08-27.md). - GATE-2 shadow-deployment plan —
docs/reports/SHOPIFY_GATE2_SHADOW_DEPLOY_2026-08-27.md: sequence, per-flag commands, rollback one-liners, shadow-metric queries. Design document; nothing executed by it. - The plan's Step-4 blocker is CLOSED. The plan found W3/W4/W5
(
RETENTION_COHORTS,CREATIVE_FATIGUE,KLAVIYO_FEED) had zero production callers — flipping them would have been a silent no-op.cc4126f1(2026-08-27 ~19:2xZ, gate2-w3w4w5-wiring session) landed the callers, verified by content onorigin/mainthis session: -services/growth-scheduler/main.py:722→POST /api/v1/f2/retention-cohorts-services/growth-scheduler/main.py:748→POST /api/v1/creative/fatigue-services/measurement-rails/main.py:718→POST /v1/rails/klaviyo-value-feed:send61 new tests;tests/governance(859) +services/measurement-rails(450) recorded green fresh-venv by the landing session (ledger record0bca89a— inherited here, not re-run). - Net-yield dispatch (GATE-2 plan Step 2, part 1) is DONE — run
33106133149(2026-08-27T18:58Z,workflow_dispatch) SUCCESS, measured via the Actions API this session. W1 code now serves flag-off (net-yield-00012-xwnperSTATUS_REPORT_2026-08-27.md§2).
Not yet serving (measured this session via Actions API + workflow files)
- growth-scheduler has NOT redeployed since the wiring landed. Last deploy
run is #10,
32749122278, 2026-08-24T16:08Z — three days beforecc4126f1. The workflow isworkflow_dispatch-only by design (its own header; net-yield ADR-NY-001 precedent), so no merge ever deploys it. Until a human dispatchesdeploy-growth-scheduler.yml(a DARK deploy — the workflow sets none of the lane flags), the W3/W4 routes exist only in source. Registry note: the service's F4 lane is live-armed (pilot, 2026-08-24) — a redeploy from this workflow re-derives that env; the ARMED posture is workflow-carried, not hand-set, so a dispatch does not disarm F4. - measurement-rails is
status: source-only—production/service-registry.yaml:473-476:deploy: operator RUNBOOK only (no CI workflow). The W5 route serves nowhere until an operator runbook deploy. (TheKLAVIYO_FEEDflag check also rides insideboss-agent-adk's image via the vendored bridge, but the caller route is rails-local.) - Autonomy Foundations GATE 2 is open — needs
APPROVED: DEPLOY, the two additive DDLs (unified.autonomy_certifications,unified.model_benchmarks), and the fixture smokes (build report §8).
The approval the owner actually types/does, in order
- Review
SHOPIFY_GATE2_SHADOW_DEPLOY_2026-08-27.md+ this report; give the typed GATE-2 go for the Shopify lane. - Operator executes Step 1 —
INVENTORY_SPEND_GATE=trueonservice-action-runner(the only fully-wired, serving flag). Soak 48–72h. One flag, one service, one soak window — never two in the same window. - Step 2 part 2 —
RETURNS_ADJUSTED_NCM=trueonnet-yield(dispatch already done). Soak ≥ one order+return cycle. - Dispatch
deploy-growth-scheduler.yml(dark) and run the measurement-rails operator runbook deploy; then W3 → W4 → W5 flag flips, one soak window each (per-flag commands + rollbacks in the plan §2–§3; replace-semantics caveat applies to every--set-env-vars). - Separately: type
APPROVED: DEPLOYfor Autonomy Foundations GATE 2; operator applies the two additive DDLs and runs the CLI fixture smokes.
W6's reconciliation meter is not a flag — it is one watched manual run of
ops/reconciliation/run_reconciliation.py, blocked on merchant credentials
(§2, register item 6).
2. Shopify operator credentials — measured state, credential by credential
Correction carried into the two 08-27 reports in this same commit: the
STATUS_REPORT §4 / GATE-2 plan §5 lines saying app creds are "absent /
no client_id anywhere" describe the code/terraform fail-closed defaults,
not the live project. docs/reports/SHOPIFY_SECRETS_STATUS_2026-08-25.md
measured Secret Manager directly two days earlier: all three governed secrets
are populated with real-format material and mounted on the serving
gateway revision. Both readings are reconciled below; the register item that
survives is validity, not existence.
| Credential | Measured state | Evidence | What remains (whose) |
|---|---|---|---|
shopify-app-client-id / shopify-app-client-secret |
Populated + mounted, SHOPIFY_OAUTH_ENABLED=true |
08-25 shape probe (32-hex / shpss_+32-hex; 1 & 5 versions); mounts in the reviewed workflow (deploy-service-marketing-connectors.yml:201-202, re-checked on main this session); gateway redeployed green 08-27 19:09Z (run 33106781210) |
Validity vs Shopify unproven — format ≠ authentication. Proof = one OAuth token exchange / merchant install visit (owner, SHOPIFY_CONNECT_RUNBOOK.md). A stale payload fails at Shopify's far end, merchant-visible. |
shopify-webhook-secret (SHOPIFY_WEBHOOK_SECRET) |
Populated (2 versions) + mounted; HMAC verification real on the one governed receiver | Same 08-25 report §1/§3; fail-open HMAC fixed 19cc1343d (08-18) |
First REAL store webhook delivery (register 6c) — app miz-oki-commerce-link-5 released, 13 topics → Pub/Sub, delivery proven only via CLI trigger; zero genuine merchant deliveries ever. |
Pixel pair: SHOPIFY_PIXEL_COLLECT_URL + SHOPIFY_PIXEL_INGEST_SECRET |
Unset — no lines in the reviewed workflow env list (checked this session); activation defers loudly ("status": "deferred", "reason": "pixel_collect_url_unset", service-marketing-connectors/main.py:954-981) |
grep + workflow read | Operator: build/host the pixel-extension artifact, set both values via the reviewed workflow (replace semantics — hand-set values are wiped on the next deploy). Note the correct var name is …_COLLECT_URL, not the task-brief's …_EXTENDER_URL. |
Klaviyo #1 — KLAVIYO_PRIVATE_API_KEY (W5 value feed) |
Unset; klaviyo_feed.health() → not_configured; now in the rails RUNBOOK secret-name table (preflight drift healed by 2aa5480c) |
AF build report; operator_preflight.py 0 DRIFT per cc4126f1 record |
Operator secret + rails runbook deploy; dark regardless of the KLAVIYO_FEED flag until set. |
Klaviyo #2 — intent-klaviyo-api-key (6c extender) |
Secret exists, no real version; CI already mounts :latest |
register item 6c (unchanged this window) | Operator: add a real version + bounce the revision. |
| Klaviyo #3 — per-tenant key + webhook secret (KLV-1 pull half, W7 webhook half) | Tenant-owned; collected via the Connectors catalog / authenticated onboarding UI only (.claude/rules/tenant-onboarding.md) |
KLV-1 record; W7 build report | Tenant supplies via UI; owner: license review (ontology/sources/klaviyo.yaml = PENDING_BOSS) + live signature verification before the W7 flag ever flips. |
net_yield_costs real values |
5 NULL cost rows; every dependent order economics_complete=false by design |
register item 21 | Operator/tenant (onboarding UI carries net-yield costs per the tenant-onboarding rule). |
INVENTORY_SPEND_GATE_CONFIG_PATH roster/velocity |
Ships empty by design; not_configured rows, never invented demotion |
W2 build report | Operator, informed by the W2 soak's observed provider/action roster. |
| Reconciliation runner (register item 6) | Code-complete, inert | GATE-2 plan §2 Step 3 | Merchant credentials + RECONCILIATION_EVENTS_TABLE, then one watched manual run. |
Collected is not armed: none of the above starts a pilot, flips a writeback, registers a holdout, or widens autonomy — activation still runs the governed approval/holdout/DCP paths.
3. SerpApi vendor-side key revocation — where it stands
State per register item 32 (recorded 2026-08-25; no newer record exists —
git log --grep=serp since 08-25 returns only the unrelated L-06E alert-policy
commits, checked this session):
- Leak FIXED and serving: redaction (not suppression) via
serp.py QuerySecretRedactingFilter; blindserp_adapter=configuredleg replaced with aserp_credentialleg (key shape + last provider verdict). Commits21cc6f9f+f619a9a9; first redacting revision00041-vkn(deploy run32771817572). - Exposure extent (corrected measurement): 14 log entries / 4 revisions
(
00035/36/38/40) / 2026-08-21T06:17Z–08-24T06:41Z; one distinct credentialbb45ed0ca6eb, which also sat in secret versions v2+v3; v2/v3/v6 all nowdisabledin Secret Manager._Defaultbucket only (30-day retention) — the exposed entries age out 2026-09-23. Purge deliberately not done (owner decision: the only purge nukes stderr fleet-wide); log-read access not restricted (33secretAccessorvs 6 log-readers — the blast radius inverts). - Rotation CLOSED at v13: 64-hex, fingerprint
36fec456fcdd, distinct from the disclosed value, serving on00044-64v; rotation toolingscripts/maintenance/rotate_serp_key.sh. - Caveat that still stands:
serp_credential: unverified= shape-valid, never exercised — production redaction is unit-proven, not proven on real SERP traffic, as of the 08-25 record.
The one remaining action is the owner's, at the vendor: revoke
bb45ed0ca6eb in the serpapi.com dashboard. disable in Secret Manager only
stops MIZ OKI reading it — the vendor-side credential is still technically
live for anyone holding the disclosed value until the exposed entries expire
and/or the key is revoked. This cannot be executed or verified from the
repo; once done, record it on the ledger so item 32 can close.
4. Owner decisions — the consolidated register (verified today)
A. Approvals to type (blocking the two GATE-2s)
- Shopify Merchant Expansion GATE-2 shadow-activation go (plan §1 above).
- Autonomy Foundations
APPROVED: DEPLOY(+ operator DDLs + smokes).
B. Shopify register decisions — Step-0 item 6, re-verified 2026-08-27 (SHOPIFY_CLOSEOUT_VERIFY_2026-08-27.md Item 6): all 7 genuinely OPEN
- Decision 3 — Profit Truth Audit wedge go/no-go.
- Decision 9 — citation sign-off: unblocked (5/5 PASS,
CITATION_CHECK_2026-08-11.md) but never formally closed by the owner. - Decision 12 — L5 blueprint phase-name confirmation (blueprint never landed on the board).
- Decision 13 — 30-day plan wholesale vs. triaged.
- Decision 14 — EU data-residency mechanism (with counsel). No EU merchant onboards before this.
- Decision 15 — holdout-share covenant floor by tier (value undeclared).
- Decision 17 — Stage 1–4 benchmarks: contractual SLA vs. internal target (until decided, benchmarks stay out of merchant-facing contract language).
C. Autonomy Foundations §6 list (new 2026-08-27)
PORTFOLIO_RISK_POLICYcap values per (tenant, currency, channel-group).- W5 first certification candidates + the owner-approved certification program document (L5-CERT-1 flip condition; real evaluations also wait on real forward labels — register 17/6c/23).
- Klaviyo license review + per-tenant webhook secrets + live signature verification (pre-flag-flip; also §2 above).
- TTD seat (TTD-1 unchanged).
- Capital/Risk/Estate go/no-go (CELL-CRE-1).
- Distillation go once W6 baselines exist against live models (DIST-4 = a recorded run).
- W1/W2 residual deltas (per-cycle BQ reconciliation job, correlation-aware concentration warning, log-based alert policies — GATE-2 protected-path terraform).
- "GC r2.1" does not exist as a Growth Control revision — if a different board document was intended, name it and it lands byte-identical.
D. Standing register items (unchanged this window; sources in current-priorities.md)
- Item 20 — briefing approval.
- Item 21 —
net_yield_costsNULLs (also §2). - Item 22 — measurement secret VALUES + BQ DDL confirms.
- Item 23 — FIRST real registered holdout (writebacks stay hard-false until it exists; no intent activation is legal without it).
- Item 31 —
boss-rewoo-orchestratormin-instances (optional comfort). - Item 32 — SerpApi vendor revocation (§3).
- Items 9/12 operator sequences (GraphRAG seed-first raise; cell3 watched manual run then human-PR scheduler), item 14 (78/107 default-SA services), item 6c per-source afferent steps (GA4 / TTD / Klaviyo / mizoki-events), 10 design partners (P1 exit).
- L-06E — the F4 cap-approach metric + alert policy landed 08-26
(
88451b0, PR #850); the register row stays OPEN pending the operator apply/attach leg (ddf292aNEEDS_ACTION: six of seven alert policies dispatch to nobody; attachMIZ OKI Ops (email)and test-fire).
E. One live deploy regression needing a decision
gemini-kg-pipeline: PR #854 (dedicated SA + JourneyEvent canonical-forward activation) merged 08-26, but its deploy run32971557546FAILED and no retry has run since (measured this session via the Actions API — last success is still32432405545, 2026-08-21). The change is onmain, not live. Decide: fix-and-redispatch (respecting AGENTS 7.7 drain safety) or acceptimplemented, not deployedfor now. SUPERSEDED LATER THE SAME DAY (dated note by the 22:xxZ closeout sweep): resolved as fix-and-redispatch — root cause was the SA-precondition race;deployment/terraform/gemini_kg_pipeline_sa/was applied ~16:17Z and redeploys succeeded (runs33111045522→ rev00076,33112711137→ rev00077-5hqserving 100% under the dedicated SA; unauth/health403, authed probe green). Authority:STATUS_REPORT_2026-08-27.mdas trued ine1cecf6; this row is history.
5. Evidence and non-independence
Measured directly this session: origin/main content greps for the
cc4126f1 routes; deploy-growth-scheduler.yml / deploy-net-yield.yml /
deploy-gemini-kg-pipeline.yml run lists and conclusions via the GitHub
Actions API (run ids above); gateway workflow secret mounts + SHOPIFY_OAUTH_
ENABLED=true on current main; pixel env absence from that workflow; registry
rows for growth-scheduler / measurement-rails; git log sweep for
post-08-25 SerpApi records; shopify_install.py token-refresh fail-closed
path; TokenRefreshError call-site inventory.
Inherited from dated records (not re-measured — gcloud absent here): Cloud
Run revision names/timestamps (GATE-2 plan §1, same-day gcloud); Secret Manager
payload shapes (08-25 secrets report); suite-green claims for cc4126f1
(ledger record 0bca89a) and both GATE-1 batteries (their build reports);
SerpApi Secret Manager/logging state (item 32, 08-25). Where a claim above is
inherited, its source is named on the row.
Corrections applied in this commit (rule 01 — fix the claim where it lives):
STATUS_REPORT_2026-08-27.md §4 items 1–2 and
SHOPIFY_GATE2_SHADOW_DEPLOY_2026-08-27.md §5 items 1–2 now carry a dated
correction pointing at the 08-25 secrets measurement; the GATE-2 plan also
gains a dated update noting its Step-4 blocker closed (cc4126f1) and its
Step-2 dispatch executed (run 33106133149).