Commit graph

5 commits

Author SHA1 Message Date
74e834a7c4 Remediate sh-plan-review findings (B1-B5, F1-F7, NITs, Qs)
Address the Fable plan-review gate (REQUEST CHANGES):
- B1: move ALL teardown to Phase 4 + shared-consumer audit; notion-sync dual-feeds;
  rollback never targets a deleted/starved resource.
- B2: propagate the §0.1 resolutions through D5/D11/§1d/§2.x/§3/G6/G9/§6 (model,
  guardrail, dropped ~30% claim, Phase-0 'verify' not 'decide').
- B3: pin D12 to one facade per trust tier (per-server Cognito audience at the edge);
  reconcile the §1h list_tools test (deferred with MCP adapter).
- B4: specify per-agent External Credential + Cognito app client minting only its tier's
  scopes; add the token-layer trifecta test.
- B5: split Phase 0 (0a auth spike gates 0b); add custom-Bolt fallback; relabel G1 as
  mitigation-chosen/unverified.
- F1-F7: Testing-Center identity (G12); design.md amendments reframed (F2); sh-agentforce
  new-repo checklist + cd-sfdx JWT-key auth (F3); platform-build phase (F4); Salesforce
  data-processor gap (G13/F5); memory+README obligations (F6); per-user visibility
  degradation (G14/F7).
- NITs: S3->Data Cloud ingestion pinned; facade+notion-sync ALARM monitoring; DevName
  naming boundary. Qs Q1-Q3 registered as G15 + verify items.
- §0.3 remediation log + gap count 11->15.
2026-06-11 12:44:00 -04:00
f4a11c558f Add D12: OpenAPI-first, MCP-ready transport-agnostic core
Tool handlers + shared auth/scope/PII/audit guard built independent of wire
protocol; OpenAPI adapter shipped now (Agentforce External Service actions, Apex
only for shaping); MCP adapter deferred to a named trigger (real IDE/Claude Code
workflow, or native remote-MCP per-user GA). Update decision log, §0.1 transport
architecture block, §1h test split (OpenAPI contract now, MCP conformance deferred),
and §4 deliverables (annotate design.md §4; transport-agnostic core story).
2026-06-11 12:24:09 -04:00
eaf2aae480 Resolve open decisions: per-user auth pattern + reasoning model
Fold Adam's decisions and deep-research (wf_1bf9e142) outcomes into the plan:
- D4: ES/Apex actions + Per-User OAuth Browser Flow External Credential -> Cognito;
  native remote-MCP connector off the per-user hop (Beta, per-user binding unconfirmed).
- D5: AWS-Hosted Claude as the planner; BYOLLM ruled out (custom-action-only, routes
  through SF Models API/Trust Layer). Guardrail moves to the MCP/action layer (revises D11).
- D1 accepted; D3 accepted; G8 corpus authoring deferred (fund when needed).
- Resolve gaps G1/G2/G6; add §0.1 resolutions and a Phase-0 verify-in-org gate.
2026-06-11 11:58:11 -04:00
Claude
e7e96458b3
Add Agentforce migration & architecture plan
Decision document mapping the sh-mcp design.md substrate onto Agentforce:
3-agent roster (Ops/Finance/Lauren Exec) on trust-tiered MCP servers,
per-user OAuth via Cognito, Data Library/retriever design replacing the
Bedrock KB, model/DX/Testing-Center plans, cutover phasing, and an
11-item capability-gap register.

https://claude.ai/code/session_01BvKGBQ4ek6JRZVkFicZuw6
2026-06-11 00:11:52 +00:00
3e2d99a1eb Initial commit: sh-mcp design and plan
Design doc for the Sea Haven MCP platform that replaces seahaven-slack-bot
and exec-aide: trust-tiered MCP servers, Google-SSO via a Cognito broker,
TypeScript monorepo. Cross-review (cross_reviewer/GPT-4.1) folded in.

Status: planning only, nothing built.
2026-06-09 19:25:24 -04:00