MarketSignal / External-KG — Current State and Remaining Work
Measured through: 2026-08-22 17:47Z
Repository baseline reviewed: a0638a96bb6af480b599ab48f7db4d39c4e9ecea
Purpose: superseding operational status for the External-KG / MarketSignal program. Historical build and GATE-2 reports remain evidence records; this document is the current-state pointer.
Closure register (2026-09-02, Wave 2 WS-10): every row of §"Remaining work by ownership" below carries a disposition (CLOSED-BY / OWNER-HELD) in docs/reports/MARKETSIGNAL_CLOSURE_REGISTER_2026-09-02.md (rows MS-01…MS-07), pinned both ways by tests/test_marketsignal_closure_register.py; the list itself is unchanged and stays the origin of record.
Executive status
The MarketSignal / Cell 37 production lane is written, integrated, deployed, and live-verified. The old checkpoint that described Terraform as 8/9 and the SERP provider key as missing is superseded.
No unclaimed, agent-executable MarketSignal feature remains. The remaining work is tenant- or operator-specific activation, credentialing, and reviewed arming.
Current-state matrix
| Surface | Written | Integrated | Deployed | Live-verified | Current posture |
|---|---|---|---|---|---|
Cell 37 market-signal-ingest core |
Yes | Yes | Yes | Yes | Serving; IAM-locked; extraction primary path and governed ingest proven |
| BigQuery MarketSignal / entity / experiment objects | Yes | Yes | Yes | Yes | DDL applied; expected objects present |
| Terraform module | Yes | Yes | Yes | Yes | 9/9 resources reconciled from deployment/terraform/market_signal_platform |
| Scheduler jobs | Yes | Yes | Yes | Yes | SERP and Trends jobs exist; scheduled execution path and poll proof were exercised |
| Monitoring policies | Yes | Yes | Yes | Yes | Six alert policies: fallback, quarantine, consent drops, Cell 37 5xx, SERP budget, gateway 5xx |
| MarketSignal dashboard | Yes | Yes | Yes | Yes | Cell 37 and gateway telemetry panels available |
| Managed Prometheus sidecars | Yes | Yes | Yes | Yes | Cell 37 and gateway collectors are deployed and scraping /metrics |
| SERP provider lane | Yes | Yes | Yes | Yes | Real secret version mounted; /readyz 200; assisted poll proof landed 16 serp_provider rows |
| Canonical injection door | Yes | Yes | Yes | Not armed | Deliberately dark until operator allowlist + CANONICAL_INGESTION_URL wiring |
| Amazon SP-API rank lane | Yes | Yes | Code deployed | Per tenant | Requires each tenant's LWA secrets, reviewed watchlist, and first real pull proof |
| External entity spine | Yes | Yes | Runner available | Not enabled | OCP approved; EXTERNAL_ENTITY_SPINE remains off until an operator-scoped run |
| Shopify gateway / OAuth machinery | Yes | Yes | Protected deploy path exists | Tenant-dependent | Do not infer readiness from secret-version existence; verify value shape, live readiness, and first real merchant flow |
Evidence that supersedes the 8/9 checkpoint
- Commit
78959d64recorded the original §5 apply: eight resources created, two jobs born paused, five then-creatable policies plus the dashboard, andconsent_drop_spikeblocked until its Prometheus metric existed. - The gateway Managed Prometheus sidecar subsequently landed and wrote
connector_consent_drops_total. - Terraform was re-applied and reconciled 9/9, including
consent_drop_spike. - The real SerpApi key was later mounted as secret version v5. Operator-assist run
32578060694verified a new serving revision,/readyz200, and an end-to-end poll proof with 16 rows.
Remaining work by ownership
Operator / tenant work
- Canonical injection arming: add the reviewed Cell 37 caller to the canonical-ingestion allowlist, grant
roles/run.invoker, then setCANONICAL_INGESTION_URL. Keep synthetic and person-touching data on their governed paths. - Amazon SP-API tenants: add tenant-specific LWA credentials, confirm scopes/licensing, register the tenant in
sp_tenants, and verify the first real rank pull. - External entity spine: conduct the operator-scoped dry run, review candidate and licensing output, then decide whether to set
EXTERNAL_ENTITY_SPINE=truefor a bounded runner invocation. - Shopify merchant activation: verify non-placeholder app credentials and redirect configuration, deploy through protected review, complete one real merchant OAuth install, and verify webhook / compliance handling.
- Pilot configuration: provide the selected pilot tenant and any governed frontier values required by the Growth Control program. Never invent tenant economics, treasury floors, geo caps, or API credentials.
Engineering work
There is no open MarketSignal core build item. Any further engineering should be driven by measured production evidence, a named tenant requirement, or a new approved roadmap item rather than rebuilding the existing lane.
The highest-priority unclaimed engineering blocker found during this review is outside MarketSignal: the homepage deployment workflow cannot currently pass the new /intent frontend setup. Run 32587878059 passed approval, design canon, content QA, and marketing drift checks, then failed because setup-node was pointed at a nonexistent intent-site/package-lock.json. The source also contains a root favicon reference isolated as a Vite path-resolution failure in the # MIZ OKI 3.5 directory. A separate protected-path review branch repairs that build contract; production remains human-dispatch-only.
Concurrency ruling
The OPT-GOV program is owned by session 7pjhmg. At this audit point, Phase 2 and Phase 4 are complete on main, and that session retains the remaining Phase 3 → Phase 1 work. This review does not duplicate or fork that active implementation lane.
Canonical operating references
docs/runbooks/MARKET_SIGNAL_DEPLOY_RUNBOOK.mddeployment/terraform/market_signal_platform/README.mddocs/reports/GATE2_EXTKG_REGISTER_DETAIL_2026-08-19.mddocs/reports/STATE_RESUME_2026-08-22.mddocs/EXTERNAL_KG_ENRICHMENT.md