P10-S-001record 1
{
"id": "P10-S-001",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"kind": "local-decision-record",
"claim": "A complete host-to-donor identity handoff contract, protocol-proven by an executable spike: host-signed Ed25519 token, 60-120s max lifetime, audience-bound per module, single-use jti consumed atomically, relative same-origin returnPath with absolute/protocol-relative/backslash/control-character rejection, typed adapter errors that never fall back to an anonymous donor home page, propagated logout with revocation checks for confidential records. Donor seams read from actual source for Twenty (community-side handoff avoiding the EE SSO guard), Documenso (signed sessionId cookie) and Frappe (LoginManager/sid). Context carries canonical user/workspace, module, correlation ID, canonical record IDs and capability hints; adapters keep explicit canonical-to-donor ID mapping because emails and display names are not durable foreign keys.",
"limitations": "The spike proves the token protocol only; it explicitly does not claim donor adapters or native session creation exist. Superseded for absorbed donors one day later by ABSORPTION-STRATEGY.md.",
"disposition": "load-bearing"
}
P10-S-002record 2
{
"id": "P10-S-002",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"kind": "local-decision-record",
"claim": "Reverses federation for owned-code donors: delete donor auth, substitute one host session, one database. Explicitly kills the Ed25519 launch tokens and six per-donor identity adapters. Plane remains host; infra remains service.",
"limitations": "Applies only where the code is owned; the killed protocol remains the correct answer for intact-service donors, which the document does not restate.",
"disposition": "load-bearing"
}
P10-S-003record 3
{
"id": "P10-S-003",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"kind": "local-decision-record",
"claim": "Federation-era runtime truth, dated: an embedded route is not an integrated product. Papermark, Documenso, Postiz, HRMS all had routes that existed while donor login blocked the experience. Names the real gap as identity, routing, provisioning, canonical record linkage and return navigation across donor boundaries, not more UI. Also records a navigation decision: ten labelled business pages plus global utility icons, with Settings given a full route outside the labelled hierarchy.",
"limitations": "One product's IA; the ten-page structure is a brokerage decision, not a general archetype (P08 owns archetypes).",
"disposition": "load-bearing"
}
P10-S-004record 4
{
"id": "P10-S-004",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"kind": "local-decision-record",
"claim": "Ready-made host-absorption acceptance shape: donor UI renders inside the host shell with no login prompt, no donor signup/login route reachable, state survives restart, host and donor tables in one database, clean build from documented commands.",
"limitations": "Teable-specific; success criteria are observable but were not executed.",
"disposition": "acceptance-shape"
}
P10-S-005record 5
{
"id": "P10-S-005",
"evidence_class": "observed",
"source": "clients/actionmodel/knowledge/00-MASTER-SYNTHESIS.md",
"observed": "2026-08-27",
"kind": "local-synthesis",
"claim": "Typical donor adaptation enumerated: remove donor branding, replace donor onboarding, inject host identity, relocate settings into the Actionist shell, reconcile navigation, map terminology, bind tenant-aware data, scope CSS/tokens, narrow routes, decide which migrations and background services remain donor-owned. Cosmetic adaptation and boundary adaptation must be distinguished; replacing a logo is trivial, replacing authentication/settings ownership/migration authority is not.",
"limitations": "Synthesis; the adaptation-cost distribution is explicitly unmeasured (A07 unknown).",
"disposition": "governing"
}
P10-S-006record 6
{
"id": "P10-S-006",
"evidence_class": "observed",
"source": "clients/actionmodel/knowledge/02-ASSUMPTION-LEDGER.md",
"observed": "2026-08-27",
"kind": "local-synthesis",
"claim": "A34 'the Actionist host can absorb donor identity/settings/navigation cleanly' is UNKNOWN with a host-contract pilot as its falsifier; A35 adapter-driven settings/onboarding/branding is a hypothesis; A15 the ISSO five-area shell is unproven; A06 most donors need some adaptation is observed/inferred.",
"limitations": "Ledger states; this lane's contribution is to split A34 into three tiers with different precedent strength.",
"disposition": "governing"
}
P10-S-007record 7
{
"id": "P10-S-007",
"evidence_class": "observed",
"source": "[local path redacted]",
"observed": "2026-08-27",
"kind": "local-framework",
"claim": "Factory loop from opportunity intake through research swarm, spec constitution, source-graph/template map, shell map, build waves, verification, launch and learning, with the ISSO five-area dashboard shell as default UX base.",
"limitations": "Contains no identity, tenant, settings or connector contract at all; the five-area shell is convention, not evidence (A15).",
"disposition": "gap-evidence"
}
P10-S-008record 8
{
"id": "P10-S-008",
"evidence_class": "observed",
"source": "clients/actionmodel/research/workstreams/p10-identity-settings-navigation/runs/2026-08-27-sprint-1-fable/top-companies.jsonl",
"observed": "2026-08-27",
"kind": "this-run-packet",
"claim": "33 commercial surfaces, 10 top10. Four named absorption patterns each observed in multiple independent surfaces (iframe+two-token exchange; nav manifest registration in deploy-time/runtime-component/stored-document variants; scoped settings tree with an explicit combination rule; two-gate entitlement-AND-permission visibility with cascading emptiness). Headline negative result: no observed surface renders a third party's settings inside host-owned chrome.",
"limitations": "Absence of evidence after a deliberate sweep, not proof of absence. Budibase licence read from a competitor blog not the LICENSE body; Permit.io pricing disputed across secondary sources; Salesforce Canvas current status and Wix deprecation timeline unresolved.",
"disposition": "this-run-evidence"
}
P10-S-009record 9
{
"id": "P10-S-009",
"evidence_class": "observed",
"source": "clients/actionmodel/research/workstreams/p10-identity-settings-navigation/runs/2026-08-27-sprint-1-fable/top-repos.jsonl",
"observed": "2026-08-27",
"kind": "this-run-packet",
"claim": "31 OSS projects at first pass (backfill pending). Supply-gap map: authorization heavily oversupplied (five Apache-2.0 engines, four deployment shapes); identity oversupplied and licence-stratified; tenancy partial (org models inside IdPs, nothing for host-composed tenant workspaces); shell/mounting well supplied but semantically empty; navigation registry near-greenfield; settings registry greenfield with no OSS settings-schema library at all. NocoBase's Apache badge is misleading — LICENSE.txt is a custom agreement barring public no-code/low-code/AI SaaS. Auth.js has joined Better Auth and recommends it for new projects; Lucia is deprecated.",
"limitations": "GitHub REST API blocked in that agent's sandbox, so no commit-recency evidence anywhere; all maintenance calls inferred. Four planned repos unfetched at first pass. Luigi's nav-node-tree unconfirmed and is the highest-value open question.",
"disposition": "this-run-evidence"
}