SIGNAL-SHOPIFY LANE STATUS — 2026-08-12 R3
Extends: SIGNAL_SHOPIFY_LANE_STATUS_2026-08-11.md (F1–F8 completion) and the Drive board's 2026-08-12 base + R2 reports (round-2 state, ~01:00Z) ·
Canon: docs/product/SIGNAL_OVERVIEW_v5.md → docs/product/SIGNAL_SHOPIFY_MASTER_v4.md ·
Live build state: docs/roadmap/P1_BUILD_PLAN.md ·
Claim labels: TRUTH.md vocabulary; capability axis LIVE/PARTIAL/PROPOSED per surface.
Corrections (2026-09-30, lane plan Appendix A — this report is the 08-12 measurement and stays as written; the tree wins where they differ): §1 "every activation surface is flag-gated OFF" — OAuth has been ARMED since 2026-08-21 (PR #768: the deploy workflow's env list sets
SHOPIFY_OAUTH_ENABLED=true; the source literal stays False) while every other activation surface stays OFF. §4 item 2 — the three Shopify secrets are populated and mounted since 2026-08-25 (SHOPIFY_SECRETS_STATUS_2026-08-25.md); the "coordinate the swap" note is defect D1 of the 2026-09-30 lane plan (Shopify signs app webhooks with the app client secret; fix PR #1275). §4 item 3 — the env var isSHOPIFY_PIXEL_COLLECT_URL(SHOPIFY_PIXEL_EXTENDER_URLnever matched a source literal). §5 — the canonical-store erasure leg exists since 2026-08-20 (POST /api/v1/subjects/erase), unarmed in production behindCANONICAL_ERASER_URL. Zero genuine deliveries and zero installs remain true as of 2026-09-30.
1. Executive state
P1 is code-complete. Every P1 build item is implemented, tested, and merged; every activation surface is flag-gated OFF with the OFF default test-asserted at the source literal. Zero live merchant traffic has crossed any of it — the whole ingest half fails closed until the operator secrets land (register item 6), and no reconciliation attestation exists for any merchant until a runner feeds the harness real totals. Owner decisions 1, 2, and 11 are decided; the P1 exit (10 design partners, clean reconciliation) is owner-gated work, not build work.
State per the completion gate: implemented + merged throughout; gateway/extender deployed (rebuilds fired by path filters, deployed behavior unchanged while flags are off); nothing on this lane is live-verified with merchant traffic.
2. Landed since the 2026-08-11 report
| Item | State | Evidence |
|---|---|---|
C1 COGS validated import (cogs_import.py) |
implemented, merged | rails suite 334→364 |
C2 Reconciliation harness (reconciliation.py) — the L1 attestation instrument |
implemented, merged | tighten-only ceilings test-asserted |
C3 Value-feed wiring (ncm_feed_wiring.py) — E[NCM] only, raw revenue inexpressible |
implemented, merged; OFF ast-asserted | rails suite 364→396 |
C4 OAuth install flow B0–B6 complete (shopify_install.py + flag-off routes + tenant resolution + per-tenant sync credentials + single-flight refresh + uninstall/compliance jobs + README) |
implemented, merged; SHOPIFY_OAUTH_ENABLED=False ast-asserted ×2 |
+126 tests, gateway+connectors 205 |
| C5 Fulfillments mapping review — 6 gaps found & fixed (HIGH: consent gate leaked fulfillment ship-to; zero live exposure — secret was unset) + C5a sync resource + C5b/C5c sweeps | implemented, merged | FULFILLMENTS_MAPPING_REVIEW_2026-08-12.md |
B5 Web Pixel activation — activate_web_pixel (installed-rows-only, settings allowlist, idempotent) + default hook (defers loudly while unconfigured) + extender per-shop tenant map (INTENT_TENANT_MAP, fail-closed on misconfig, single-tenant byte-identical fallback) + suspended-hold guard |
implemented, merged | gateway+connectors 205→220; extender 12→20 |
| PR #664 — fulfillments backfill/webhook join parity fix | merged by another lane, reconciled | suite 224 combined |
3. Decisions
Decided (with attribution):
- 1 — App Store vs. direct, per tier (DECIDED 2026-08-12, owner-delegated): direct distribution P1–P3 — one platform-owned unlisted public app via the landed authorization-code grant; Level-1 protected-data request filed regardless. App Store at P4, where the ratified phase binding already schedules it (embedded token-exchange swap-in + Built-for-Shopify review activate then; direct + custom-app custody stay for enterprise/T3). Rulings: master §3.6a, design note §9.
- 2 — merchant-owned vs. managed ad accounts (DECIDED 2026-08-12, owner-delegated): merchant-owned only, merchant-granted Connectors-page credentials into per-tenant Secret Manager custody. Managed accounts not adopted; would be a new decision gated L3+.
- 11 — clipped-ReLU DEL as canon (DECIDED 2026-08-11, owner-merged PR #656):
docs/architecture/DEL_AUTHORIZATION_FUNCTION.mdis law.
Open for the owner (master §3.6 register): 3 Profit Truth Audit wedge go/no-go ·
9 citation sign-off (report CITATION_CHECK_2026-08-11.md is 5/5 PASS — closable on
your word) · 12 blueprint phase-name confirmation (blueprint text still not on the
board) · 13 30-day plan wholesale vs. triaged · 14 EU data-residency mechanism
(gates all EU onboarding; options memo in FLEET_INTEGRITY.md (c)) · 15
holdout-share covenant floor by tier · 17 Stage 1–4 benchmarks: contractual SLA vs.
internal target (until decided they stay internal targets) · plus the Constitution
Article VI 36→37 cell patch (governance-surface edit, review PR path).
4. Operator remainder (nothing in code substitutes for these)
- Shopify app creation — direct/unlisted distribution per decision 1;
client_id/client_secretinto Secret Manager; redirect-URI allowlist; Level-1 protected-customer-data request; mandatory compliance webhooks declared in app config (design §8 OP row). - Register item 6 secrets —
SHOPIFY_WEBHOOK_SECRET(semantics become "app client secret" once registry rows go live — coordinate the swap), provider credentials. The entire ingest half answers 401/fail-closed until these exist. - Pixel extension artifact — the Web Pixel JS + settings schema (reads
ingest_url/shop_domain) ships with the Shopify app project; the extender's/pixel/eventsreceiving endpoint is designed together with that artifact. Until then B5 activation defers loudly by design (SHOPIFY_PIXEL_EXTENDER_URLunset). - Reconciliation runner credentials — Admin API + BigQuery access so the harness can produce real per-merchant attestations; the 14-clean-day L1 gate stays shut until real attestations exist.
5. Blocked / not built, and why
- Canonical-store erasure leg (design §6 step 3): measured 2026-08-12 —
service-canonical-ingestionexposes no subject/erasure path at all, so there is nothing to wire to. The compliance-job leg stays honestlypending_in_buildand keeps jobs OPEN and alerting (fail-closed needs somewhere to close onto; a pretend-eraser would be worse). Needs its own design + build on the canonical-ingestion lane. - P1 exit — 10 design partners (owner recruiting; onboarding now unblocked on decisions 1+2), each needing Stage-1 ≥80% identity coverage before counting.
6. Memory center / documentation state (this pass)
- Ledger (
CLAUDE.md+.claude/memory/): structurally valid on main (check --strictPASS). Five bot theirs-merge splices occurred across today's concurrent landings; all repaired byte-faithful from authoring commits, nothing lost (every displaced record is durably archived and re-indexed). - Google Drive memory-clone parity: not claimable from this session —
sync-drivetargets the owner-machine Drive desktop mount (MIZOKI_DRIVE_CLONE), which cloud sandboxes do not have. Runpython3 scripts/claude_memory.py sync-drive --apply && python3 scripts/claude_memory.py check-driveon a machine with the mount to restore parity over today's six new archives. This report itself is delivered to the Drive board via the connector (documents, not the checksum-managed memory files).