Files
LWLT-AIBOT/.project-docs/30-worklog/tasks/20260907-implement-leader-agentbus-copy-b7e31a94.md
T

8.5 KiB

Task: Implement leader task summaries via AgentBus

Identity

  • Task ID: 20260907-implement-leader-agentbus-copy-b7e31a94
  • Mode: Feature
  • Branch: codex/20260907-implement-leader-agentbus-copy-b7e31a94-implement-leader-agentbus-copy
  • Worktree: /Users/inmanx/Documents/lwltAPI-implement-leader-agentbus-copy-b7e31a94
  • Base commit: f4664997a8
  • Owner: codex
  • Status: Ready for Integration

Scope

  • Implement administrator-managed, default-off organization-wide subscriptions that copy deterministic summaries of other non-administrator employees' manual and AgentBus tasks to a bound team-lead AgentBus/WeChat route.
  • Add a separate encrypted durable notification outbox, idempotent projection from existing task.updated outbox events, lower-priority AgentBus proactive delivery, retry/release behavior, health projection, and explicit administration UI.
  • Cover stable completed, failed, cancelled, uncertain, and uncertain-then-resolved outcomes without copying transient progress, historical outcomes, raw instructions, attachments, passenger/customer details, technical payloads, or ERP execution authority.
  • Update the active AgentBus/control-plane contract and focused regressions. Do not modify business Skills, ERP schemas/mappings, Chrome extension source/releases, task queues, confirmation, execution, deployment, runtime database, channels, or live external messages.

Intent And Constraints

  • Base implementation on current origin/main commit f4664997a81722459f8d3e14acfbbf44cc6bbbe1 in this isolated worktree; preserve the occupied dirty main worktree.
  • Preserve AUTH-002 immutable assignee, per-account FIFO, assignee-only executable feeds/results, and the separation between organization-wide read projections and ERP mutation authority.
  • The user confirmed fixed-organization scope, both manual and agentbus sources, and implementation. Exclude administrator, system/unassigned, and recipient-owned tasks; do not invent team membership.
  • Do not reuse agentbus_deliveries or fabricate reply_to. Proactive frames use a separately verified recipient/conversation route and task.summary contract with stable frame IDs.
  • Destination and payload remain encrypted at rest; operational logs expose only bounded identifiers and fingerprints. Delivery failure must never change task state.
  • No historical backfill. A new or materially changed subscription starts at the change time, and target/channel/role invalidation cancels or blocks pending delivery without automatic rerouting.
  • Feature mode changes only implementation files, active component documentation, this task record, and any task-prefixed supporting record; canonical project memory remains an Integration Gate promotion candidate.

Outcome

  • Added migration 020_leader_task_summary_notifications with a default-off, organization-scoped team-lead subscription and a dedicated durable delivery outbox. Recipient address, conversation ID, and summary payload are encrypted at rest; only SHA-256 fingerprints are exposed to administration and diagnostics. Composite organization foreign keys, bounded projection/claim indexes, revisioned deduplication, and no data backfill keep the feature isolated from existing employee reply rows.
  • Added LeaderNotificationService as a read-only projection over existing task.updated outbox events. It includes future manual and AgentBus tasks assigned to other non-administrator employees, excludes recipient-owned/admin/system tasks, projects only stable outcome milestones, uses transaction advisory locks plus SKIP LOCKED, cancels obsolete subscription revisions, and retries delivery failures without changing task state.
  • Added deterministic privacy-safe summary generation for completed, failed, cancelled, uncertain, and uncertain-then-resolved outcomes. Messages contain only employee username, registered business label, public task ID, submission time, generic status/result wording, and allowlisted group/order identifiers; raw instructions, attachments, customer/traveller fields, URLs, and technical errors are not copied.
  • Integrated the separate summary queue into each team lead's existing AgentBus channel after the employee reply queue. Proactive task.summary frames use a stable delivery-derived ID plus explicit recipient/conversation routing and never fabricate reply_to; inbound task.summary events are reserved and ignored so an echo cannot create another task. Operational logs contain delivery/task/channel IDs and route fingerprints, not the frame or destination plaintext.
  • Added administrator-only list/update APIs and a /channels management panel. The panel requires explicit target verification and a second enable confirmation, explains default-off/future-only/at-least-once/non-retractable behavior, preserves encrypted routes when their fields are left blank, and shows eligibility plus pending/failed/sent health counts. There is deliberately no live test-send endpoint.
  • Updated the active AgentBus reply contract and control-plane README for proactive leader summaries and required schema 020. Existing task ownership, executable feeds, ERP confirmation/execution, business Skills, schemas/mappings, and Chrome extension sources/releases were not changed.
  • No runtime database was migrated, service deployed/restarted, AgentBus channel changed, or real AgentBus/WeChat message sent.

Verification

  • npm run check:repo: passed (10/10).
  • npm run check: passed.
  • npm run test:control-plane: passed (174/174), including summary privacy/status projection, migration/authorization/UI contracts, proactive no-reply_to framing, echo rejection, employee-first queue ordering, redacted logging, retry gateway behavior, and existing control-plane regressions.
  • npm run test:legacy: passed (270/270).
  • npm run build: passed.
  • node --check LianSyn-platform/app.js: passed.
  • git diff --check: passed.
  • Fresh disposable PostgreSQL 16 integration: applied all 19 repository migrations through 020; confirmed zero default subscription rows, administrator-created verified configuration without plaintext route exposure, no historical backfill, encrypted projection/claim, and a pending uncertainty reminder being cancelled when the task resolved so only one final completed summary was claimed. The temporary cluster was stopped and moved to Trash afterward.

Follow-ups

  • Integration/deployment remains separately authorized: merge this Feature branch, back up and apply migration 020, then restart the control plane. None of those live actions occurred here.
  • Before production enablement, choose the exact team-lead channel and controlled WeChat conversation, validate that the deployed AgentBus bridge accepts the proactive task.summary envelope and routes its explicit to/conversation_id without echoing it as inbound work, then manually mark that target verified and enable the subscription.
  • Observe one controlled manual task and one controlled AgentBus task end to end before widening use. Delivery is intentionally at-least-once, so downstream deduplication must honor the stable leader-summary-<delivery-id> frame ID and operators must understand that a message already accepted by AgentBus/WeChat cannot be retracted by deleting platform data.

Promotion Candidates

  • Target documents: canonical system architecture, authorization/data-isolation memory, current-state snapshot, and production operations guidance.
  • Proposed durable fact: team-lead WeChat summaries are a default-off organization-wide read projection, not task ownership or ERP authority. They use revisioned subscriptions and their own encrypted outbox; existing employee AgentBus replies remain the higher-priority queue and are never repurposed.
  • Proposed safety invariant: only future stable outcomes for other non-admin employees may be projected; route or role invalidation cancels unsent work without rerouting, stale uncertainty reminders are superseded before send, and delivery failures never mutate task state.
  • Proposed protocol fact: proactive frames use event task.summary, stable ID leader-summary-<delivery-id>, explicit to and conversation_id, and no reply_to; echoed task.summary frames are ignored inbound.
  • Evidence: migration 020, leader notification/projector sources, AgentBus integration, administration UI/API, focused tests, full regression results, and the disposable PostgreSQL integration recorded by this task.
  • Human confirmation required: exact production team-lead recipient/channel binding, controlled external AgentBus/WeChat canary result, and authorization to integrate, migrate, restart, and enable.