Archive v0.9: Candidate Inbox and promotion workflow - #24
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal
Turn the v0.8 Catalog Discovery queue into a controlled operator Inbox and explicit promotion workflow without weakening observe-first identity guarantees.
Operator Inbox
Adds
/catalog-inboxwith:The browser never receives
MODELAPSE_CONTROL_TOKEN.Controlled API
Adds control-token protected endpoints:
GET /v1/control/catalog/discoveriesGET /v1/control/catalog/providers/:providerId/modelsPOST /v1/control/catalog/discoveries/:candidateId/reconcilePOST /v1/control/catalog/discoveries/:candidateId/promotePromotion invariants
Promotion requires:
promotion_ready;provider_apimodel-list source;There is no discovered-to-Model shortcut.
Docs-derived discoveries cannot be promoted by this workflow.
Provenance
Promotion reuses the Candidate's existing immutable source record. The model registration primitive now validates and accepts an existing
sourceRecordId, so canonical Model provenance and the initial execution binding point back to the exact collection evidence that produced the Candidate.Audit
Migration
0011_catalog_candidate_promotion.sqladds append-onlycatalog_promotion_eventswith database validation for provider and canonical-source consistency. A Candidate can be promoted at most once.Promotion also appends the normal
match_existingreconciliation event and transitions the Candidate tomatched.Drift semantics
Initial promotion is registration, not drift. Later source-backed identity changes still flow exclusively through the v0.6 observer/drift path.
Coverage
Adds API control-boundary tests and PostgreSQL integration coverage for:
See
docs/catalog-inbox.md.