mirror of
https://github.com/Sea-Haven-Industries/sh-mcp.git
synced 2026-10-05 21:12:05 +00:00
Research resolved the doc-answerable 0a unknowns before the live spike: - Finding 1: AllowedOAuthScopes does NOT cap a pre-token V2 Lambda's scopesToAdd -> redesign to a SUPPRESS-ONLY Lambda (keeps AllowedOAuthScopes as the real per-tier ceiling). - Finding 2: V2 needs Essentials plan (default; Lite ignores it) — negligible cost. - Finding 3: Cognito access tokens carry client_id/scopes, no aud -> client_id allow-list + scope-prefix as the audience proxy (resolves the §8c unknown). - Finding 4 (NEW CRITICAL G16, now THE top risk): Employee-Agent callouts may carry SERVICE identity, not the user's -> 0a fatal #1; fallbacks MuleSoft RFC 8693 / signed header / Bolt. - Finding 5: per-user actions UNTESTABLE via batch Testing Center -> scripted interactive parity sessions (G12 resolved). - Finding 6: all-staff agent not free (Flex Credits / $125-user add-on) -> G9 cost model. - Finding 7: model_config may allow BYOLLM as a per-agent planner -> reopen as verify (upside). Added §0.4 findings record; gap count 15->16; verify items reordered (G16 = fatal #1). |
||
|---|---|---|
| .. | ||
| agentforce-plan.md | ||
| design.md | ||