# Lily handover

## Shared refactor — 14 September 2026

The edition now selects shared SendGrid transport from Base while retaining its own durable send policy. Accepted responses may lack a remote receipt; uncertain outcomes remain distinct and are not automatically repeated. Owner SQL uses the shared generated-D1 mechanism after core; the edition wrapper owns its permanent ledger and path. Authoring1.1 includes changed-input diagnostics, retained baseline extraction, mapped comparison and portable adjacent release receipts verified against a clean clone. Source integrity does not establish product or deployment acceptance; the remaining obligations below are preserved.


## Authoritative edition conversion — 2026-09-14

Lily is now authored in this repository. Its latest completed Support605495b
source was materialized with pinned Base603ee025, preserving edition ancestry
from ae8426e at baseline b5d317e73db03916e64961a69193c911d308e050.
All 1,106 selected source files plus the historical composition lock matched
the pinned export byte for byte. The build refreshed the previously stale
tracked route tree from the existing route files; handwritten runtime source
and migration history were preserved.

`edition.json`, tracked source and `sources.lock.json` now govern this product.
Maintainers, owner forks and community publishers use the same local authoring
CLI and application commands. Support no longer generates or publishes Lily.
Historical family/Base receipts below do not verify edition-local edits. Future
receipts must bind the exact edition commit, source tree and source lock hash.

The genuine clean source-release clone at
`87c16871c26cf87e5832a9ccf11ba4859f91ada7` passed 65 source, 443 Worker,
nine operations and 55 packaged browser tests (1 empty, 49 disabled, 5 configured;
five intentional disabled-profile skips). Build, types, lint, boundaries,
migrations, artifact and reporter probes passed. Literal `pnpm verify` exited 1
only at final coverage: 128/131, missing QUEUE-001, INSIGHT-005 and DATA-003.
Later changes are shared acquisition tooling from Base00296f3 and provenance/
handover metadata; product runtime, migration and test bytes remain equivalent.
Final source integrity and portable local release are checked separately.

The initial worktree attempt failed a packed-search rollback Worker test and the
widget saved-status browser assertion. Their logs, ledger and widget trace are
preserved separately. Both tests passed in the independent clean full run without
runtime or fixture edits; the initial failures are not erased or assigned an
unproven cause. A separate native local preview sign-in, Home and Tickets browser
check also passed. None of these observations claims hosted or provider proof.

The bounded authoring conversion does not resume production readiness, capacity
experiments, provider calls or deployment. The prior checkpoint limitations
below remain explicit. Fresh verification is recorded in the conversion evidence.


## Parked local review checkpoint — 2026-09-14

The owner narrowed the task: “I don't need this production ready. Lets finish up
where we are at.” The revised checkpoint is complete and parked at the owner's
request. No further performance experiments, feature fixes, provider tests,
deployment, recovery or owner-fork updates are authorised by this checkpoint.
Resume only after a new owner request.
The retained product contract is not complete, and production readiness is not
claimed. The dated sections below preserve earlier scope and evidence; their
next-step language is historical, not an instruction to resume work.

The final verified implementation is Support author
`e52f17e90605ed971991da443b7c98581a5d819a`, tree
`bc6224d4a0f93467e442210ad360b745291e771b`. Its genuine composed edition clone
passed 65 source tests, 443 Worker tests, nine operations tests and 55 packaged
browser tests (empty installation 1, disabled channel 49, configured channel 5).
There were no failed or flaky tests; the disabled-channel profile had five
intentional configuration skips. Build, types, lint, boundaries, migration and
reporter checks passed. Literal full `pnpm verify` exited **1** solely at final
coverage: **128/131**, missing **QUEUE-001, INSIGHT-005 and DATA-003**. The
223-file immutable build was rehashed without mismatches. These are local
execution results, not a green full-contract or hosted-capacity verdict.

The frozen evidence directory is
`/Users/zemaj/.orchestrator/evidence/support/complete-lily-end-to-end-as-a-finished-product/zara-20260913/final-verification-e52f17e/`;
its manifest SHA-256 is
`7299fe9089616fa3d33d587e96961a214320b53ad6579fa1be7656f6bac7ee50`.
Earlier failed attempts remain preserved, including verification-context and
fixture failures, browser defects, native dependency deadlines, capacity failures
and the source-changing freshness observation. Later passing evidence does not
erase or relabel those attempts.

The isolated native installation remains on **dc36773**, version
`219bb597-2871-4681-a535-d7a780e6ac76`, schema through 0108. Its functional
freshness proof passed selected-view metrics and drillthroughs, overflow pack
byte/search checks and committed configuration/satisfaction effects. A first
final-Home drill sequence stopped with a canonical-snapshot-change no-verdict;
no exact three-row cause was established. The bounded known-case completion then
passed all 15 Home metrics and 15 independently bracketed drillthroughs, followed
by normal API erasure. Final census returned to 50,000 tickets, 250,000 messages,
26 operators (25 original agents plus the retained synthetic owner), zero active
test configurations, zero invalid projections and no foreign-key violations.
Original custody and R2 content were preserved; the temporary role was restored,
the owned view remains retired, and **native cron is empty**. Completion receipt
SHA-256: `11583e14761ff3888fb5197b85df081b9c535f59666f3a9646e26da9e5261421`
(`lily-known-case-completion-v2-dc36773.json` in private custody). This is current-dc
functional evidence; it does not grant missing local reporter registrations or
accept the complete QUEUE-001/INSIGHT-005 obligations.

The retained 25-user native capacity test failed at approximately **2.1 seconds
p95 against the unchanged 500 ms requirement**. No capacity reduction or
performance acceptance is claimed. The later 8/16-SELECT experiment plans were
never released and must not be executed as part of this parked checkpoint.
Native usage receipts are workload subtotals, not an end-to-end bill.

The latest e52 source is **not deployed**. Production review remains on the prior
`631a633` source and its dated provider receipts. The owner fork was last updated
and verified against dc36773, at fork commit
`f4a2322121ef830dae1d84666d82061a7e2c936f`, preserving four owner-intent files and
local data. Recovery remains at 0106; later recovery work was not performed.
An authentic owner Zendesk export is still absent, so synthetic importer tests do
not establish DATA-003. These are preserved product limitations, not outstanding
work in the owner's revised local-checkpoint scope. Preserve existing resources,
accounts, data, sessions and evidence; never replay prior provider intents.

## Historical completion-lane update — 2026-09-13

The scope at this historical checkpoint was the complete retained product in CONTRACT.md and
BASELINE.md. The historical pilot and first-release prioritisation below do not
limit this work. Author changes are in the Support family's `codex/lily-complete`
worktree; generated edition repositories remain outputs.

The current completion lane has implemented the wider ticket/customer/Help,
channel, operational, portability and owner-update surfaces. The clean composed
`c58fdea` run passed all 65 source tests, 389 Worker tests, nine operations tests,
and all browser phases (one empty-installation, 49 disabled-channel and five
configured-channel tests), with no failed or flaky executions. Its literal
verifier exits nonzero solely because the report registers 128 of 131 clauses:
native freshness and authentic owner-import evidence remain separate below.
Earlier minute-rollover test failures are preserved; Date-only fixture fixes
retain exact admission assertions and explicitly exercise normal window expiry.

The earlier `db41514` browser Widget transport failure and subsequent Help
hydration defect are preserved in the evidence. The UTC date fix in `2725b82`
now passes the complete browser sequence, delayed scripts, opposite timezones
and no-JavaScript language navigation. `3bb7a1b` removes certified unchanged
scheduled writes. `8c4389e` adds transactional selection-index maintenance,
canonical restore reconstruction and readiness checks; `1f75de3` selects exact
queue pages through those indexes. Actual local populated migration, global
ordering, metadata predicates, malformed-state rejection, archive rollback and
erasure isolation tests pass. These are local guarantees, not hosted latency
acceptance.

Native `db41514` upgrade acceptance succeeded on the isolated 50,000-ticket,
250,000-message installation: all facts and publication requirements matched,
enforcement was active, temporary fences were removed, and the queue's original
delivery state was restored. The subsequent actual 25-operator workload failed
the retained search latency requirement despite successful HTTP responses.
Local mixed-calendar performance passed at `2af9872`; that local result does not
substitute for the failed native workload. The indexed runtime with `5d26dc1` health observability passed native upgrade
and full selection readiness. Its single searches passed, but the first
25-operator broad-search wave returned correct results at p95 2,424 ms and
stopped automatically, so native performance remains unresolved;
capacity limits have not been lowered. Full final native recovery and owner
update acceptance remain pending. Preserved native usage is a workload subtotal,
not an end-to-end bill or measured per-operator cost.

Production remains on the earlier `631a633` runtime, with actual authenticated
mail, original attachments, signed delivery, customer-thread and public intake
receipts tied to their respective historical revisions. No current full release
or Stage 2 acceptance is claimed. Final production deployment and one new
reviewed test-owned mail intent are held behind the remaining runtime gates;
previous provider intents must never be replayed. Preserve James's owner account,
older pilots, native sessions, failed attempts and the isolated data resources.

The final census must combine the exact local execution ledger with separately
reviewed native freshness receipts for QUEUE-001 and INSIGHT-005. Literal local
reporting must not invent native credit. An authentic owner Zendesk archive is
still required for DATA-003; synthetic importer fixtures do not establish that
acceptance. This input remains independent of the engineering work above.


Read [first-release acceptance](ACCEPTANCE.md) for purpose, unmet release obligations, preserved requirements and the evidence decision rule.

## Support composition pilot — 2026-09-12

Lily's source implements the public-request → persisted ticket → authenticated operator review → explicitly selected SendGrid acceptance journey. The canonical edition source is `editions/lily/` in the Support family author repository; export it with its pinned base and selected shared components to obtain the runnable product. Setup, signature, waiting reason, public form activation, mailbox selection, delivery evidence, shared support admission policy, and non-idempotent provider attempt protection are integrated. See [README.md](README.md) and [the pilot guide](docs/SUPPORT-PILOT.md).

A dedicated deployed Worker at `https://lily-support-pilot-20260912.james-d16.workers.dev` accepted one native sign-in email and one reviewed reply to the explicitly authorised recipient. Ticket #1 remains Pending, with SendGrid acceptance reference `TbwapYoiROmjxwbM2ioJsQ` and dispatch `01M2A68DRWWHKWPRMB6D5BDHDD`. Its persisted public request and reply were read back in the hydrated native UI. The sign-in receipt is `YV3CteokRxiGjvmX5hDF5Q`. The test used a short-lived native session table fixture after the real mail request because it could not open the owner's inbox; every fixture was revoked. Inbox callback, incoming email, delivery events, and complete 1.0 acceptance are not claimed.

Live evidence is `/tmp/lily-live-pilot-evidence/result.json` and `06-durable-reload.png`. A pre-hydration public form click exposed a real SSR readiness issue; public and sign-in fields now remain disabled until their client handlers mount, with focused browser regression coverage. The final assembly must include that subsequent fix. No application mock or authentication bypass was introduced.

The implemented global Worker suite passed 128 tests across 39 suites, with one intentional capacity case pending; 32 source tests passed. Type checks, lint, boundaries, configuration, migrations, local runtime, build and artifact guards passed. The full contract report remains 17 satisfied / 114 uncovered of 131, with no failing/overridden clauses: literal full verification remains incomplete coverage, not a green 1.0 release gate. Final packaged browser run passed: disabled configuration 16 passed / 1 configured-only skip; configured configuration 2 passed (`/tmp/lily-browser-hydration-final.log`). Assembly receipts are recorded separately by the coordinating task.

## Historical repository state before the support pilot

`CONTRACT.md` remains the accepted 1.0 target, and `BASELINE.md` remains the cross-seed security, privacy, and operational target. The current source checkpoint is `289f4326a1f6776a7412d424e4f8717df260cc74`, which adds the reviewed stored service-cycle timing projection and compact ticket-detail inspector on top of the `aa9ca829dd51124496011bdb8344111436cc19ce` responsible-failure notification UI, FAL-traced navigation glyphs, and registered BASE-INPUT matrix.

This is an in-progress task-branch code checkpoint, never a release, `main`, deployment, hosted URL, provider delivery, account action, release tag, or full-contract acceptance.

The task branch is local at `289f432`; `main` remains at `11fa280`. The last confirmed remote checkpoint before preparing this update was `d6c24e9`; later push receipts live in task evidence. There is no rename or archive clearance.

`DATA-003` remains blocked on the authentic Zendesk export, which remains with the owner and has already been requested. Fixtures cannot establish that importer clause; Freshdesk replacement/import stays deferred.

## Historical full local checkpoint: exact `1fb5350`

The earlier completed clean-clone verification applies **only** to `1fb5350f4b99a485b6dc03e45a66855d739f2309`, before the later BASE-INPUT test pack, FAL icon integration, notification UI, and queue timing work.

A frozen install and implemented checks at that exact source passed:

- 32 source tests.
- 27 Worker suites: 108 passed, zero failed, and one intentional capacity case pending.
- Packaged browser profiles: disabled configuration 7 passed and 1 skipped; configured profile 1 passed.
- Type checks, lint, boundaries, migration checks, local runtime smoke, build, and emitted-artifact guards.

Literal `pnpm verify` exited 1 solely because its contract report recorded 12 satisfied and 119 uncovered clauses of 131. It had no failed or overridden clauses. This is an incomplete-coverage local checkpoint, not a green release gate. The raw logs, Worker JSON, reporter result, and root assessment are retained at `/Users/zemaj/.orchestrator/evidence/zendesk/ticket-desk-contract-and-1-0-built/stage-2-combined-verify/1fb5350-20260909/`.

The separate exact-`1fb5350` Start proof passed in both Vite and emitted-Worker profiles after a retained transient ProxyWorker network failure. It covers valid generated transport, malformed and present-empty native envelopes, public admission, native session lifecycle, SSR/client assets, and foreign-host controls. Its retained result is `/Users/zemaj/.orchestrator/evidence/zendesk/lily-on-tanstack-start/runtime-proof/attempts/candidate-1fb5350-native-envelope-r3-rerun-20260909/start-runtime-proof-results.json` (SHA-256 `1c537e0b1c89d91260132b19ad5a8b11fcda53b4dcf375a7c694749cb9befb24`). It is local runtime evidence, not deployment or provider evidence.

## Later bounded work not covered by that full checkpoint

- `a6f72fb` adds the registered `BASE-INPUT-001` Worker matrix. The independently reviewed focused run passed one suite and one `[baseline:BASE-INPUT-001]` execution. Its focused reporter marked that clause satisfied while correctly reporting the other 130 clauses unexecuted. That focused 1/130 report is not a substitute for the later exact-`289f432` global report below. Evidence: `/Users/zemaj/.orchestrator/evidence/zendesk/ticket-desk-contract-and-1-0-built/stage-2-access/base-input-001-conformance-1fb5350/successor-2-registered-runtime/`.
- `aa9ca82` integrates the 11 reviewed responsible-failure notification UI/fixture/runner paths. Focused proof passed: one Worker suite with 5 passed, zero failed or pending; packaged disabled browser profile with 8 passed and 1 intentional skip; configured browser profile with 2 passed. The configured journey writes durable failure provenance into local D1, refreshes the recipient-scoped native route twice, and retains an unsaved active ticket draft without navigation. This is focused local Worker/browser evidence only: it does not rerun the global reporter or establish the full `NOTIFY-004` clause beyond the delivery-failure path. Evidence and integration receipt: `/Users/zemaj/.orchestrator/evidence/zendesk/ticket-desk-contract-and-1-0-built/stage-2-ui-integration/responsible-failure-notification-ui-1fb5350/successor-7-alert-panel-cardinality/`.
- `289f432` integrates nine reviewed QUEUE-005 projection/detail paths. Ticket detail now reads each durable service cycle newest first through one ordered D1 history read, preserving stored calendar, response-evidence, pause, recalculation, resolution-measurement, final-outcome, no-target, and legacy facts without GET writes or live-config lookup. The compact existing inspector labels valid stored response/resolution measures by cycle and marks restored first-response evidence as voided. Its focused real-D1 Worker result passed one suite with four tests and no failures, pending tests, or unhandled errors; the two browser presence assertions are registered but not executed by that focused run. This is bounded local proof, not complete QUEUE-005 or global contract credit. Evidence: `/Users/zemaj/.orchestrator/evidence/zendesk/ticket-desk-contract-and-1-0-built/stage-2-service-targets/queue-005-measured-cycle-times-aa9ca829/source-runtime-freeze.md`.

The exact-`289f432` clean-clone verification completed with a frozen install and all implemented checks green: 28 Worker suites with 109 passed, zero failed, and one capacity case pending; 7 source suites with 32 passed; disabled browser profile with 8 passed and 1 configured-only skip; configured browser profile with 2 passed; plus type, lint, boundary, migration, runtime, build, and emitted-artifact checks. Tracked source was clean.

Literal `pnpm verify` still exited 1 solely for incomplete contract coverage: 13 satisfied, 118 uncovered, zero failed, zero overridden, out of 131 clauses. This is a stronger local checkpoint, not a green release gate or full-contract acceptance. Evidence: `/Users/zemaj/.orchestrator/evidence/zendesk/ticket-desk-contract-and-1-0-built/stage-2-combined-verify/289f432-20260910/`.

The separate Vite/emitted Start proof remains the historical exact-`1fb5350` local runtime result recorded above; it was not rerun as part of the exact-`289f432` clean-clone verification.

## Owner preview

The owner-approved local preview remains available only at `http://127.0.0.1:8791`:

- launcher/process group: `16449`; workerd: `16464`;
- it retains the original pre-Start server bundle and persistence, while serving the reviewed FAL-traced client; it is **not** a runtime of the current Start source checkpoint;
- candidate browser evidence covers native sign-in plus real queue and ticket-detail reads, populated desktop/intermediate/mobile captures, no console or request failures, and no overflow.

The candidate artifact, swap record, rollback command, and screenshots are retained at `/Users/zemaj/.orchestrator/evidence/zendesk/ticket-desk-contract-and-1-0-built/stage-2-owner-preview/local-sample-20260910-owner-nav-fal-traced-candidate/`. Preserve the preview process and its local data unless the owner explicitly requests a new preview change.

## Boundaries and next verification

Generated artifacts are local proof inputs only. Keep source review, focused Worker/browser evidence, full clean-clone verification, external Start proof, provider proof, and deployment proof distinct. Do not add automatic demo data, provider fallbacks, result-JSON shortcuts, or request-time empty-installation seeding.

Before any release or deployment claim, preserve the exact-`289f432` result as a local checkpoint only. Any later integrated source requires a new clean-clone `pnpm verify`, Worker-JSON and global-reporter inspection, and an honest report of remaining uncovered clauses. `pnpm setup` and `pnpm deploy` are remote-capable and remain unused.
