Sea Haven MCP platform — trust-tiered MCP servers + Cognito/Google auth broker, replacing seahaven-slack-bot and exec-aide (design phase)
Find a file
Adam Moussa 74e834a7c4 Remediate sh-plan-review findings (B1-B5, F1-F7, NITs, Qs)
Address the Fable plan-review gate (REQUEST CHANGES):
- B1: move ALL teardown to Phase 4 + shared-consumer audit; notion-sync dual-feeds;
  rollback never targets a deleted/starved resource.
- B2: propagate the §0.1 resolutions through D5/D11/§1d/§2.x/§3/G6/G9/§6 (model,
  guardrail, dropped ~30% claim, Phase-0 'verify' not 'decide').
- B3: pin D12 to one facade per trust tier (per-server Cognito audience at the edge);
  reconcile the §1h list_tools test (deferred with MCP adapter).
- B4: specify per-agent External Credential + Cognito app client minting only its tier's
  scopes; add the token-layer trifecta test.
- B5: split Phase 0 (0a auth spike gates 0b); add custom-Bolt fallback; relabel G1 as
  mitigation-chosen/unverified.
- F1-F7: Testing-Center identity (G12); design.md amendments reframed (F2); sh-agentforce
  new-repo checklist + cd-sfdx JWT-key auth (F3); platform-build phase (F4); Salesforce
  data-processor gap (G13/F5); memory+README obligations (F6); per-user visibility
  degradation (G14/F7).
- NITs: S3->Data Cloud ingestion pinned; facade+notion-sync ALARM monitoring; DevName
  naming boundary. Qs Q1-Q3 registered as G15 + verify items.
- §0.3 remediation log + gap count 11->15.
2026-06-11 12:44:00 -04:00
docs Remediate sh-plan-review findings (B1-B5, F1-F7, NITs, Qs) 2026-06-11 12:44:00 -04:00
.gitignore Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00
README.md Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00

sh-mcp

Sea Haven MCP platform. A TypeScript monorepo of trust-tiered MCP servers that expose Sea Haven's proprietary integrations as tools, plus the Cognito/Google auth broker and the rebuilt scheduled jobs. This service replaces seahaven-slack-bot and exec-aide, which are deprecated completely; the conversational surface becomes a configurable Slack task agent.

Status: DESIGN / PLANNING. Not built. No stack deployed. The full design, auth architecture, scope matrix, and build plan live in docs/design.md. Read it before writing any code.

Shape (planned)

  • MCP servers (trust-tiered, remote HTTP, per-server IAM):
    • sh-mcp-ops — read-mostly, agent-facing (WO/PO/site lookups, KB search, Google Maps, Gmail/Calendar, tasks, reminders).
    • sh-mcp-finance — sensitive, read-only, audited (QBO vendor search, payment lookups).
    • sh-mcp-physical — DEFERRED, admin/out-of-band only (Lenel/Yealink/3CX control).
  • Auth — Google Workspace is the single IdP; an Amazon Cognito user pool federated to Google issues scoped, audience-bound JWTs; group → scope mapping via a pre-token Lambda. See design §2.
  • Jobs — rebuilt proactive Lambdas (email classify/digest, KB syncs).
  • Language — TypeScript everywhere (servers, packages, CDK, jobs).

Open decisions

  • Task-agent surface: Agentforce (recommended) vs marketplace Claude app vs custom Bolt assistant (design §12). Drives the model + guardrail story.
  • Endpoint exposure specifics (Slack egress ranges / WAF) — design §9 / §11.

Layout (target)

packages/   shared + one package per integration
servers/    sh-mcp-ops, sh-mcp-finance  (CDK stacks)
auth/       cognito, pre-token-lambda, group-sync-lambda
jobs/       rebuilt scheduled Lambdas
docs/       design.md  (the canonical plan)

See docs/design.md for the authoritative spec.