docs: reconcile AgentBus and dashboard integration

This commit is contained in:
inman committed 2026-09-02 15:25:16 +08:00
1 parent cc09506a06
commit 9eeb071099
10 files changed
+115 -22

No files matched your search

+6 -4
View File
@@ -4,23 +4,25 @@
| Flow | Source | Destination | Notes |
|---|---|---|---|
| Business directive | Manual workbench or AgentBus | Route orchestrator | Source changes input/reply adaptation, not parser or confirmation policy |
| Business directive | Manual workbench or AgentBus | Route orchestrator | Manual input uses the signed-in account; AgentBus input uses the channel's bound employee account and its route allowlist. |
| AgentBus execution ownership | Enabled channel | Employee account → immutable task assignee → executable feed | One account owns at most one channel; unbound channels and unassigned historical tasks stay non-executable. |
| Manual account authorization | Signed-in account plus resolved business route | Intake and task-transition gates | Administrators hold all routes; team leads/users require explicit grants and unresolved routes fail closed |
| Parsing | Route orchestrator | AI Skill or deterministic Program parser | AI/Shadow/Auto/Program mode is frozen per task |
| Operation | Parser | Control-plane task and confirmation | Must validate against the same final contract |
| ERP execution | Confirmed task | Chrome extension and logged-in ERP page | Requires unique object, page identity, ownership, and write preflight |
| Completion evidence | ERP response/requery | Control-plane receipt and business reply | Evidence is action-specific; uncertain writes fail closed |
| Passenger workbook | Single `.xls/.xlsx` attachment | Deterministic encrypted canonical TSV | First row ignored, second row fixed header, exact leader-contact rules |
| Passenger workbook | Single `.xls/.xlsx` attachment | Deterministic encrypted canonical TSV | Exactly one complete ERP-semantic header is detected in rows 1–100 through finite aliases and arbitrary column order; exact leader-contact rules remain. |
| WeChat roster attachment | Strict transport envelope plus one structured `payload.attachments[]` entry | Existing `awaiting_attachment` task | Explicit conversation ID wins; otherwise strict `Conversation:` supplies the fallback. Placeholder text alone never creates a task. |
| Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. |
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Aggregate-first task/person/input/output/time/type/completion view with clickable business drill-through; no machine payloads, technical failure text, internal identifiers, or task mutation authority |
| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Display-only summaries plus explicit filters drive an aggregate-first task/person/input/output/time/type/completion view; list reads are bounded to one read-only connection and hydrate full details only for the current page. |
| Browser worker selection | Immutable task assignee | One fresh account-bound browser connection | The heartbeat must match the account's expected ERP identity; a second fresh worker or identity mismatch is non-executable, with failover only after staleness. |
| Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF |
| Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames |
## State Ownership
- PostgreSQL owns durable control-plane account, role, task-route grant, task, session, confirmation, channel, audit, archive, and outcome state.
- PostgreSQL owns durable control-plane account, role, expected ERP identity, task-route grant, AgentBus channel owner, immutable task assignee, browser worker, session, confirmation, audit, archive, and outcome state.
- Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted.
- Chrome extension local state is bounded execution/reconciliation support, not canonical business history.
- `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection.