Release summaries
companyos-connect-canonicalization-v1
Add a strict historical-v1 database read boundary so a human can approve forward-only migration 007 before it normalizes text storage to the unchanged public integer-v1 contract, while preserving approval-event provenance across historical JSON-only and complete denormalized storage shapes.
integrator
Integrators retain the literal canonicalizationVersion 1 contract while exact historical PostgreSQL text "1" is read compatibly for approval and then normalized by a tracked migration; approval event provenance remains canonical in integrity_metadata before and after denormalization.
maintainer
Migration owners get a dry-run-first CLI with advisory locking, predecessor enforcement, transactional rollback, ledger replay, and explicit confirmation. The first-reviewer provisioning apply is intentionally outside the otherwise-circular Connect signature gate, but requires the authenticated migration-owner role, seven exact confirmations, rollback evidence, and idempotent replay. Migration 006a preserves historical ledger IDs while adding reviewer-runtime nonce, issuer, and RLS support; explicit public authorization and reviewer proof metadata replace embedded trust.
real-organizations-auth-recovery
Ship server-authoritative organization and workspace contracts with API/web recovery runtime, and separate authentication readiness from the legacy ND pilot-admission tuple without weakening legacy route admission.
integrator
Adopt organization.list, organization.set-active, and workspace.list as additive operations. Use organization.set-active authorityToken for stale-request rejection while retaining authorityVersion as a compatibility field. Continue treating existing tenantId fields as compatibility assertions only. The API and browser adapters now bind these operations with ambient credentials, explicit no-store transport, and canonical authority revalidation.
maintainer
Authentication readiness validates auth, database, origin, cookie, and secret prerequisites. Keep the pilot tuple configured for the legacy ND route until persisted organization authority replaces that admission guard. The public composition requires credentialed exact-trusted-origin authority refresh with a private no-store policy, plus one lazy app-owned authority runtime reused until host shutdown. Corrective v1 semantics preserve every distinct provider Set-Cookie, bypass caches for post-write canonical revalidation, recover through membership listing before selection, and atomically audit only actual active-organization transitions. The API, Node response adapter, browser transport, and web switching runtime implement these semantics; live production migration, bootstrap, deployment, and cutover remain separately gated.
real-organizations-bootstrap-recovery
Make the three-organization bootstrap resumable with durable phase receipts and truthful cross-connection interruption semantics.
integrator
Bootstrap receipts now expose the stable manifest revision, eight phases, and recovered phases as an additive CompanyOS contract.
maintainer
Operators can rerun the same manifest after interruption and must require all eight durable receipts plus three final bindings and grants before cutover.
real-organizations-canonical-seeding
Seed the canonical LSSM, CompanyOS, and NDconsulting organization families from one contract-owned manifest with deterministic replay and redacted evidence.
integrator
Adopt the additive organization-seed subpath for exact identities, families, digest versions, expected counts, and redacted receipt DTOs. The existing organization-bootstrap:v1 revision and receipt semantics remain unchanged.
maintainer
Run migrate, canonical bootstrap, one manifest-wide seed, and complete verification. Do not supply live tenant/workspace selectors or treat receipt presence alone as replay proof.
integrator
Public profile drafts may represent intentionally inactive event metadata with destination mode unavailable; active unavailable events fail validation. Approved hybrid destinations remain HTTPS/Calendly-only.
