docs: integrate automatic leader summary routing

This commit is contained in:
inman
2026-09-07 16:20:02 +08:00
parent 0b3aa5c42d
commit 6bdaa2a6e6
9 changed files with 76 additions and 16 deletions

View File

@@ -5,7 +5,7 @@
- 已登记业务能从手工输入或 AgentBus 输入稳定路由到统一 operation 契约。
- 写能力只在唯一对象、页面身份、ownership、写前投影、明确服务端响应和 action-specific 完成凭据成立时执行。
- ERP 执行以不可变任务归属账号为队列边界:同账号保持 FIFO 与单活跃执行,不同账号互不阻塞;管理员查看权限不能进入他人任务的事件、领取或插件回执链路。
- 启用组长任务摘要时,系统只将未来稳定结果通过独立加密队列发送到已核验的组长 AgentBus 目标;通知失败不改变任务状态,摘要不扩大任务或 ERP 权限,也不暴露原始指令、客户资料或技术载荷。
- 有效组长身份绑定可用 AgentBus 渠道后,系统自动从当前账号的 AgentBus 路由开始发送未来稳定结果;通知使用独立加密队列,失败不改变任务状态,摘要不扩大任务或 ERP 权限,也不暴露原始指令、客户资料或技术载荷。
- 归档/恢复与永久强制删除保持为两个明确操作;强制删除不受任务状态门禁限制、完整移除任务平台记录,并明确不代表回滚既有 ERP 写入。
- 当前发布物、源码和机器可读发布清单逐文件、逐哈希一致。
- 项目记忆能在并行任务下保持任务隔离,并只通过串行 Integration Gate 更新 canonical 状态。

View File

@@ -14,35 +14,41 @@ Team leads could inspect manual employee work through the read-only operations d
## Decision
- Model each recipient as one administrator-managed subscription for an active `team_lead` and that leader's enabled AgentBus channel. The scope is the fixed organization, the feature defaults off, and manual and AgentBus task sources are independently selectable.
- Treat leader-summary delivery as an automatic consequence of an active `team_lead` identity with that leader's enabled, account-bound AgentBus channel. The scope is the fixed organization and both manual and AgentBus task sources are always included; there is no separate administrator subscription switch or source selector.
- Project only results created after the current subscription revision starts. Include stable completed, failed, cancelled, and uncertain outcomes for tasks assigned to other non-administrator employees; never backfill history or copy transient progress.
- Keep the summary projection read-only. It does not alter `assigned_user_id`, route grants, confirmation, queue position, executable SSE, browser claim, plugin result handling, reconciliation, or ERP authority, and delivery failure never changes task state.
- Use a dedicated revisioned durable outbox rather than `agentbus_deliveries`. Encrypt recipient address, conversation ID, and payload at rest; expose only bounded fingerprints and counts to administration and diagnostics.
- Require an explicitly verified recipient/conversation route before enablement. A subscription, target, role, ownership, or channel change cancels obsolete unsent rows without automatically rerouting them.
- Derive the proactive route from AgentBus state. Prefer the latest accepted inbound `from` and `conversation_id` whose task is assigned to the current channel owner; otherwise use the channel's `external_user_ref` and the normal `agentbus:<sender>` conversation fallback. If neither exists, remain waiting until the leader's first valid inbound message. Channel rebind clears the previous external-user reference, and a route, role, ownership, account-validity, or channel change creates a new revision and cancels obsolete unsent rows instead of sending them to a stale target.
- Keep messages deterministic and business-safe: employee username, registered business label, public task ID, submission time, generic outcome wording, and allowlisted group/order identifiers only. Do not copy original instructions, attachments, customer or traveller details, URLs, technical payloads, or technical errors.
- Send employee replies before the smaller leader-summary batch. Proactive frames use event `task.summary`, stable ID `leader-summary-<delivery-id>`, explicit `to` and `conversation_id`, and no `reply_to`; inbound `task.summary` is reserved so an echo cannot create work.
- Treat WebSocket delivery as at-least-once. Downstream routing should deduplicate the stable frame ID, and deleting platform data cannot retract a message already accepted by AgentBus or WeChat.
## Rationale
A separate projection preserves the existing employee reply and ERP execution invariants while giving leaders timely, privacy-bounded awareness. Default-off administration, target verification, encryption, revisioned deduplication, and future-only projection limit accidental disclosure and make route changes fail closed.
A separate projection preserves the existing employee reply and ERP execution invariants while giving leaders timely, privacy-bounded awareness. Role-driven activation matches the meaning of the `team_lead` identity; current-owner route correlation, encryption, revisioned deduplication, future-only projection, and fail-closed invalidation limit accidental disclosure without requiring administrators to duplicate AgentBus routing state.
## Consequences
- Migration `020_leader_task_summary_notifications` is required before the updated control plane starts.
- The `/channels` administrator page configures and observes subscriptions; it is not an arbitrary message composer and deliberately exposes no live test-send endpoint.
- Repository verification proves projection, privacy, retry, priority, echo rejection, and database behavior, but production enablement still requires an authorized migration/restart plus a controlled AgentBus/WeChat canary for the exact target.
- The `/channels` administrator page observes automatic status only; it is not an arbitrary message composer and exposes neither a subscription mutation endpoint nor a live test-send endpoint.
- The migration's `enabled DEFAULT false` remains an internal fail-closed storage default. Only the runtime role/channel/route reconciler activates a row, so migration 020 does not need to change.
- Repository verification proves projection, privacy, retry, priority, echo rejection, and database behavior, but production assurance still requires an authorized rollout plus a controlled AgentBus/WeChat canary of automatic route resolution.
- A later real team-membership model may narrow scope, but role labels alone must not be used to invent reporting relationships.
## Supersedes
- None. This extends the read-only leadership model without superseding AUTH-001 or AUTH-002.
## Revision
- 2026-09-07: Replaced the initial administrator-configured/default-off workflow with role-driven automatic activation at explicit user direction. The fixed organization scope, privacy allowlist, future-only projection, independent encrypted outbox, and no-ERP-authority boundaries remain unchanged.
## Related
- `.project-docs/10-decisions/AUTH-001-fixed-scope-account-authorization.md`
- `.project-docs/10-decisions/AUTH-002-account-scoped-execution-and-force-delete.md`
- `.project-docs/30-worklog/tasks/20260907-implement-leader-agentbus-copy-b7e31a94.md`
- `.project-docs/30-worklog/tasks/20260907-auto-leader-summary-routing-5e8c1a73.md`
- `control-plane/migrations/020_leader_task_summary_notifications.sql`
- `control-plane/src/leader-notification-service.ts`
- `control-plane/src/agentbus.ts`

View File

@@ -12,7 +12,7 @@
| NETWORK-001 | In the trusted internal deployment, AgentBus roster attachment URLs may resolve to internal/private addresses; HTTPS, credential rejection, DNS pinning, redirect validation, bounds, and digest checks remain. | Active | 2026-08-31 | AgentBus attachment ingress | [Reply contract](../../agent设计规范/agentbus-reply-contract.md) |
| AUTH-001 | The fixed deployment scope uses administrator-managed `admin`, `team_lead`, and `user` accounts, owner-isolated normal tasks, display-only leadership metrics with explicit filtering, explicit non-admin route grants, and assignee-bound AgentBus/browser/ERP execution. | Active except clauses superseded by AUTH-002 | 2026-09-01 | Authentication, authorization, audit, AgentBus workers, and operations oversight | [ADR](AUTH-001-fixed-scope-account-authorization.md) |
| AUTH-002 | ERP execution is serialized per immutable assigned account, administrator visibility is never execution routing, and explicit force delete physically removes authorized tasks regardless of lifecycle state. | Active | 2026-09-03 | ERP claim queues, executable events/results, and task removal | [ADR](AUTH-002-account-scoped-execution-and-force-delete.md) |
| AUTH-003 | Administrator-configured team-lead task summaries are a default-off, organization-wide read projection with a verified proactive AgentBus target and a separate encrypted outbox; they never grant task or ERP authority. | Active | 2026-09-07 | Team-lead notifications, AgentBus outbound routing, and summary privacy | [ADR](AUTH-003-leader-task-summary-notifications.md) |
| AUTH-003 | Active team-lead identities automatically receive an organization-wide read projection through their current-owner AgentBus route and a separate encrypted outbox; it never grants task or ERP authority. | Active | 2026-09-07 | Team-lead notifications, AgentBus outbound routing, and summary privacy | [ADR](AUTH-003-leader-task-summary-notifications.md) |
## Superseded And Reverted Decisions

View File

@@ -16,7 +16,7 @@
| Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. |
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Display-only summaries plus explicit filters drive an aggregate-first task/person/input/output/time/type/completion view; list reads are bounded to one read-only connection and hydrate full details only for the current page. |
| Team-lead task summary | Future stable manual/AgentBus task outcome for another non-admin employee | Separate encrypted durable outbox → leader-owned AgentBus channel → verified WeChat conversation | Administrator-configured and default-off; employee replies are sent first, summary frames use stable IDs and explicit routing with no `reply_to`, and delivery failure never changes task state. |
| Team-lead task summary | Future stable manual/AgentBus task outcome for another non-admin employee | Role/channel reconciler → current-owner encrypted route → separate durable outbox → leader-owned AgentBus channel → WeChat | Automatic for active team leads with a usable route; employee replies are sent first, summary frames use stable IDs and explicit routing with no `reply_to`, and delivery failure never changes task state. |
| Browser worker selection | Immutable task assignee | One fresh account-bound browser connection | The heartbeat must match the account's expected ERP identity; a second fresh worker or identity mismatch is non-executable, with failover only after staleness. |
| Account-scoped ERP queue | Confirmed task assignee | Assigned account's browser worker | Organization-plus-account advisory locking preserves FIFO and at most one active execution for that account; another account's active, queued, stale, or uncertain work is outside this queue. |
| Executable event and result routing | Immutable task assignee | Matching authenticated platform page and plugin | SSE history/live events, claims, plugin results, and browser cleanup commands never use administrator-wide visibility and fail closed when the authenticated account is not the assignee. |

View File

@@ -2,7 +2,7 @@
## Current Architecture
Authenticated manual or account-bound AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns account, channel owner, immutable task assignee, account-scoped execution queue, browser worker, session, task-type authorization, confirmation, audit, reversible archive, explicit force-delete behavior, and default-off team-lead task-summary subscriptions. The Chrome extension verifies the expected ERP account, resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
Authenticated manual or account-bound AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns account, channel owner, immutable task assignee, account-scoped execution queue, browser worker, session, task-type authorization, confirmation, audit, reversible archive, explicit force-delete behavior, and role-driven automatic team-lead task-summary projection. The Chrome extension verifies the expected ERP account, resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
## Main Components
@@ -24,7 +24,7 @@ Authenticated manual or account-bound AgentBus input is routed through task-scop
- The product is one fixed internal organization scope with three roles. Administrators manage accounts, channels, and all 18 manual routes; team leads and users are owner-scoped for normal tasks and require explicit per-route grants. Team leads additionally receive a dedicated read-only, manual-task-only platform-operations dashboard. Administrator-wide visibility does not permit executing another account's assigned ERP work.
- Account passwords are accepted when non-empty without an application-level length rule. First-login forced password changes are disabled; voluntary changes and administrator resets still revoke the relevant sessions, while the historical `must_change_password` column remains compatibility-only storage.
- The leadership dashboard is an aggregate-first projection across task, person, original input, final output, time, task type, and completion state. Summary cards are display-only; filtering is explicit and defaults to all results. List reads use one bounded read-only database transaction, SQL prefiltering, selective historical-message hydration, and full detail projection only for the current 20-row page. Its drill-through stays business-facing; technical payloads, internal identifiers, machine-shaped historical input, and technical failure text remain in separate authorized audit/engineering surfaces.
- Team-lead task summaries are a separate administrator-configured read projection, not an extension of dashboard, task, or ERP authority. Each default-off subscription uses the leader's own enabled AgentBus channel and a verified encrypted target, covers only future stable outcomes for other non-admin employees from explicitly selected manual/AgentBus sources, and never copies raw instructions, attachments, customer/traveller data, URLs, or technical errors.
- Team-lead task summaries are a separate role-driven read projection, not an extension of dashboard, task, or ERP authority. An active leader with an enabled owned AgentBus channel is automatically subscribed to future stable manual and AgentBus outcomes for other non-admin employees. Routing comes from the current owner's latest valid inbound route or channel external-user reference, remains encrypted, fails closed when unavailable or stale, and never copies raw instructions, attachments, customer/traveller data, URLs, or technical errors.
- Authorization is enforced in server and service paths, not by navigation visibility. A denied or unresolved non-admin business route stops before parsing, plugin dispatch, and ERP execution; creator authorization is rechecked at confirmation and browser claim.
- Each enabled AgentBus channel owns one active non-admin employee account. Inbound work uses that account and route allowlist, persists the same account as immutable task assignee, and is returned only to that account's executable feed. A team-lead channel may additionally carry its leader's lower-priority proactive summary outbox; those rows use explicit destination/conversation routing and never become executable task traffic.
- Each employee account has one expected ERP identity and at most one fresh browser execution worker. Mismatched ERP identity, concurrent fresh workers, unbound channels, or unassigned tasks fail closed. Browser claims, active-execution checks, and confirmed FIFO are serialized per immutable task assignee, so one account cannot block or occupy another account's queue.

View File

@@ -4,6 +4,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Source commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` from feature task `20260907-auto-leader-summary-routing-5e8c1a73` for automatic role-driven team-lead summaries, current-owner AgentBus route learning/fallback, read-only status UI, stale-route cancellation, and removal of the manual mutation endpoint; integration task `20260907-integrate-auto-leader-summary-9a4d2c61` revised AUTH-003 and canonical notification behavior.
- Source commit `1a3ab63` from feature task `20260907-implement-leader-agentbus-copy-b7e31a94` for default-off team-lead task summaries over future manual and AgentBus outcomes, a separate encrypted/revisioned outbox, verified proactive AgentBus routing, administrator configuration/health UI, and migration 020; integration task `20260907-integrate-leader-summaries-84c1d7ea` accepted AUTH-003 and canonical notification boundaries.
- Correction commit `fe1cc2cddc29e4dead81e53c16d31bb71493602d` from integration task `20260903-backup-revert-extension-update-c71a4e92` preserved the complete former `0.5.167`/migration-019 stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed the central private-OSS/ECS automatic-update service architecture without rewriting history, and retained the exact Chrome extension `0.5.167` source/package on the active main line with migration 018.
- Merge commit `3224758` and integration task `20260903-finalize-extension-update-a6c4e192` remain historical records of the full-stack extension-update design. Only the plugin `0.5.167` release, adaptive entry readiness, and dormant plugin-side idle/reload safeguards remain active; the server orchestration is preserved on the backup branch only.
@@ -34,7 +35,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Current Focus
Operate the repository's current `0.5.167` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator or team-lead visibility never enters another account's executable event/result path. Team-lead task summaries remain default-off until an administrator verifies the exact proactive route; migration 020, manual extension reload, guarded product-search retry, and service rollout remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
Operate the repository's current `0.5.167` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator or team-lead visibility never enters another account's executable event/result path. Active team leads with usable owned AgentBus routes automatically receive future privacy-bounded summaries; migration 020, manual extension reload, guarded product-search retry, service rollout, and any live AgentBus/WeChat canary remain separately authorized runtime work. Server-side automatic extension updating is not part of the active main line.
## Recently Completed
@@ -60,11 +61,12 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back.
- 2026-09-03: Backed up the complete adaptive-readiness and central extension-update stack at remote branch `codex/backup-extension-update-20260903-b2e33e2`, then removed the central OSS/ECS update service and migration 019 from `main` with normal history-preserving commits. After correcting an initially over-broad rollback, the active repository retains the exact extension `0.5.167` source/package and uses migration 018; the removed server architecture was never deployed by these tasks.
- 2026-09-07: Integrated AUTH-003 and migration 020 for administrator-managed team-lead task summaries. Future stable manual/AgentBus outcomes for other non-admin employees project into a separate encrypted outbox and use the leader's verified AgentBus/WeChat target without changing task ownership, employee reply priority, or ERP execution authority.
- 2026-09-07: Revised AUTH-003 so active team-lead identity plus an enabled owned AgentBus channel automatically activates both-source summaries. Routing uses only the current owner's latest valid inbound route or the channel external-user reference; channel rebind clears stale identity data, the settings API/UI is read-only, and all prior privacy, future-only, revision, priority, and no-ERP-authority boundaries remain.
## In Progress
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
- Required migrations through `020_leader_task_summary_notifications`, employee ERP identities/channel bindings, extension `0.5.167`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/notification runtime changes have not been applied to or restarted on the standard service in this integration task. No production team-lead target is configured or enabled.
- Required migrations through `020_leader_task_summary_notifications`, employee ERP identities/channel bindings, extension `0.5.167`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/automatic-notification runtime changes have not been applied to or restarted on the standard service in this integration task. No live automatic team-lead delivery canary was performed.
## Next Recommended Steps
@@ -73,7 +75,7 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
3. In the same authorized staging window, verify that an administrator receives no employee executable events/results, then force-delete disposable waiting and active employee tasks and confirm database absence plus cleanup only in the owning employee plugin.
4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
6. With explicit external-send authorization, configure one controlled team-lead route, verify proactive `task.summary` handling and stable-frame deduplication through AgentBus/WeChat, then observe one manual and one AgentBus task before wider enablement.
6. With explicit external-send authorization, use one controlled team-lead channel to verify automatic current-owner route resolution, proactive `task.summary` handling, and stable-frame deduplication through AgentBus/WeChat, then observe one manual and one AgentBus task before wider assurance.
## Open Questions / Blockers
@@ -83,7 +85,7 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering mismatched ERP login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator executable-feed isolation, and both manual and automatic channel work.
- Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
- A live internal AgentBus attachment verification remains separately unperformed.
- Proactive team-lead `task.summary` delivery has repository, mock-WebSocket, and disposable-PostgreSQL evidence but no deployed AgentBus/WeChat canary; exact production target verification and enablement remain pending authorization.
- Proactive team-lead `task.summary` delivery has repository, mock-WebSocket, and disposable-PostgreSQL evidence but no deployed AgentBus/WeChat canary; automatic current-owner route resolution remains unverified in the live bridge.
## Risky Areas
@@ -93,7 +95,7 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
- AgentBus channel ownership, immutable task assignment, expected ERP identity, browser-worker freshness/failover, and administrator non-execution are security- and write-safety-sensitive boundaries.
- Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
- Team-lead summary target verification, encrypted projection/delivery rows, at-least-once stable-frame deduplication, privacy allowlisting, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
- Team-lead automatic route derivation, stale-owner invalidation, encrypted projection/delivery rows, at-least-once stable-frame deduplication, privacy allowlisting, and non-retractable external delivery are authorization- and disclosure-sensitive boundaries.
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
## Last Updated

View File

@@ -12,3 +12,4 @@ This is integrated history. Feature tasks write only their task-scoped records;
| 2026-09-03 | Adaptive ERP readiness and extension host updates | Integrated immediate-first scatter-plan readiness plus private OSS/ECS host updating as extension `0.5.167`; the server-update architecture was later reverted before deployment while the plugin release was retained. | [Original integration task](tasks/20260903-finalize-extension-update-a6c4e192.md) |
| 2026-09-03 | Extension-update iteration backup and scoped rollback | Preserved exact commit `b2e33e2` on remote branch `codex/backup-extension-update-20260903-b2e33e2`, removed migration 019 and server-side automatic updating, and retained extension `0.5.167` plus migration 018 through non-force commits. | [Rollback task](tasks/20260903-backup-revert-extension-update-c71a4e92.md) |
| 2026-09-07 | Team-lead AgentBus task summaries | Integrated default-off future-only summaries for other non-admin employees' manual/AgentBus outcomes through a separate encrypted outbox and verified proactive target, without changing task or ERP authority. | [Integration task](tasks/20260907-integrate-leader-summaries-84c1d7ea.md) |
| 2026-09-07 | Automatic leader-summary routing correction | Replaced the duplicate administrator subscription form with role-driven activation and current-owner AgentBus route resolution while retaining future-only privacy and delivery boundaries. | [Integration task](tasks/20260907-integrate-auto-leader-summary-9a4d2c61.md) |

View File

@@ -0,0 +1,51 @@
# Task: Integrate automatic leader summary routing
## Identity
- Task ID: 20260907-integrate-auto-leader-summary-9a4d2c61
- Mode: Integration
- Branch: codex/20260907-integrate-auto-leader-summary-9a4d2c61-integrate-auto-leader-summary
- Worktree: /Users/inmanx/Documents/lwltAPI-integrate-auto-leader-summary-9a4d2c61
- Base commit: 0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00
- Owner: codex
- Status: Ready for Integration
## Scope
- Integrate source commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` from feature task `20260907-auto-leader-summary-routing-5e8c1a73` onto the current `origin/main` ancestry.
- Promote the user-approved role-driven automatic leader-summary behavior into AUTH-003, architecture, domain rules, success criteria, current state, and integrated history.
- Re-run repository, type, control-plane, legacy, build, and documentation gates before a normal non-force push to `origin/main`.
## Intent And Constraints
- The user explicitly replaced the earlier administrator-configured/default-off workflow with automatic activation for active team leads using their AgentBus channel routing.
- Preserve all privacy, future-only, durable-outbox, employee-first, role/channel fail-closed, and no-ERP-authority-expansion guarantees from AUTH-003.
- Do not apply migrations, restart services, deploy, mutate production data, or send a real AgentBus/WeChat message.
- Preserve the dirty local `main` worktree and its unrelated untracked task record; integrate only from this isolated worktree.
## Outcome
- Promoted feature commit `0b3aa5c42d5810761dd3d6bc6deee1dc4af5fd00` as the canonical implementation of role-driven automatic leader-summary routing.
- Updated AUTH-003, its decision index entry, success criteria, system overview, data flow, business rules, current state, and integrated task history to remove the obsolete administrator-configured/default-off product model.
- Recorded that active team leads are reconciled automatically against an enabled, bound, owned AgentBus channel; the current observed route is preferred and the bound external recipient is the fallback.
- Preserved fail-closed invalidation, encrypted route snapshots, durable outbox delivery, future-only semantics, employee-first scheduling, and both manual and AgentBus task sources.
- No migration, production-data mutation, deployment, service restart, or real AgentBus/WeChat send was performed. Migration 020 remains the current schema requirement.
## Verification
- `node --run check:repo` — passed (10/10).
- `node --run check` — passed.
- `node --run test:control-plane` — passed (176/176).
- `node --run test:legacy` — passed (270/270).
- `node --run build` — passed.
- `node --check LianSyn-platform/app.js` — passed.
- Disposable PostgreSQL 16.14 verification from the source feature task applied migrations 001–020 and confirmed idempotent reconciliation, learned-route delivery, both task sources, and role-revocation cancellation.
- `check_project_docs.py` and `check_doc_drift.py --task-id 20260907-integrate-auto-leader-summary-9a4d2c61` — passed after canonical promotion.
## Follow-ups
- A real WeChat canary requires separate deployment/runtime authorization and should use a non-sensitive test summary.
## Promotion Candidates
- None; the accepted behavior was promoted directly into canonical project memory by this Integration task.

View File

@@ -9,7 +9,7 @@
- Administrators always hold all 18 manual business routes. Team leads and ordinary users start with no task grants, require explicit administrator allowlists, and may use normal task APIs only for their own manual tasks.
- A known ungranted route or a non-unique/unresolved route for a non-administrator fails before parsing, plugin dispatch, or ERP execution. Authorization is rechecked for supplemental input, attachments, confirmation, automatic confirmation, and browser claim.
- Team leads may read all manual account work only through the platform-operations dashboard. The dashboard is aggregate-first across task, person, original input, final output, time, task type, and completion state, with business-facing drill-through. Its five summary cards are display-only; the explicit task-result filter defaults to all results. Internal attention or waiting-for-input states remain unchanged in task storage but are presented and filtered as “进行中”; the leadership view exposes no separate “待跟进” category. It is not an audit log and never renders technical payloads, internal identifiers, machine-shaped historical input, or technical failure text; this visibility does not grant cross-user task mutation, artifacts, SSE, global settings, audit administration, or AgentBus access.
- Separately, an administrator may configure one default-off organization-wide task-summary subscription on a team lead's own AgentBus channel. It may include future manual and/or AgentBus tasks assigned to other non-admin employees, but only stable completed, failed, cancelled, uncertain, and uncertain-then-resolved outcomes. The verified target and summary payload are encrypted, history is not backfilled, employee replies retain priority, and the message never includes raw instructions, attachments, customer/traveller data, URLs, or technical errors. This notification grants no task mutation, executable event, confirmation, browser, reconciliation, or ERP authority.
- Separately, every active team lead with an enabled owned AgentBus channel and a usable current-owner route automatically receives an organization-wide task-summary projection for future manual and AgentBus tasks assigned to other non-admin employees. Only stable completed, failed, cancelled, uncertain, and uncertain-then-resolved outcomes qualify. The route and summary payload are encrypted, history is not backfilled, role/channel/routing invalidation cancels unsent rows, employee replies retain priority, and the message never includes raw instructions, attachments, customer/traveller data, URLs, or technical errors. This notification grants no task mutation, executable event, confirmation, browser, reconciliation, or ERP authority.
- Creator and input-turn attribution are durable, business inputs remain encrypted at rest, and denial audit excludes plaintext. Archive/restore is the reversible routine removal path. Explicit force delete is a separate irreversible operation that may physically remove an authorized task in any lifecycle state, retains only a minimal non-content deletion audit marker, and cannot undo ERP effects already written or retract a task summary already accepted by AgentBus/WeChat.
- Each non-admin employee may carry one case-insensitively unique expected ERP account and one AgentBus channel. New manual and AgentBus tasks persist an immutable assignee; only that account may confirm, claim, reconcile, resume, or submit ERP execution results. Administrators manage and inspect but do not execute another assignee's work.
- A browser is execution-ready only when it is the account's sole fresh worker and the active ERP session matches the expected account. Concurrent fresh workers, identity mismatch, unbound channels, and historical unassigned AgentBus tasks fail closed; stale failover waits 90 seconds. Claim locking, active-execution detection, confirmed FIFO, and queue position are scoped to immutable `assigned_user_id`: the same account stays serialized while different accounts execute independently.