← Results index

Close private-pilot account sync readiness

2026-07-29T07:33:19Z Website/UI done Documented fail-closed private-pilot readiness matrix and operator runbook in research/findings/private-pilot-readiness-t292
t292

Source report: research/findings/private-pilot-readiness-t292.md

Objective

Close private-pilot account sync readiness.

Notes: Documented fail-closed private-pilot readiness matrix and operator runbook in research/findings/private-pilot-readiness-t292.md. Existing isolation, backup/restore, auth/evaluator, browser-error, and FEATURE_COMPLETION evidence pass bounded preflight; t293 observability/rollback and t294 measured host selection remain hard launch blockers. Focused suite: 9 passed; live PostgreSQL test cannot run because this image exposes pg_config but lacks initdb/postgres OS user.

Approach

Reuses existing report research/findings/private-pilot-readiness-t292.md — tables/metrics preserved verbatim via source_report pointer. Body below summarizes grounded evidence from that report and adjacent artifacts.

Files / code / data changed

Results

Key table from source report (preserved):

BoundaryExisting evidencePrivate-pilot disposition
Browser fallback and merget289 covers disabled configuration, sign-in, read-only preview, explicit local-wins confirmation, errors, sign-out, JSON export/restore, and Chromium integration.Pass. Require each participant to export JSON before first sync; never infer remote deletion.
Account isolationt290 exercises anonymous denial, two-user RLS CRUD and deduplication against ephemeral PostgreSQL.Pass for preflight. Repeat the two-user probe against the provisioned project before invitations.
Portable recoveryt290 restores a data-only dump into a fresh database and documents ordering and validation.Pass for preflight. A real encrypted off-site export and restore rehearsal is a launch gate, not an assumption.
AuthenticationBrowser tokens remain in memory; the evaluator verifies signature, issuer, audience, and subject against Supabase JWKS.Pass for invited accounts. Self-sign-up is out of scope. Account creation and recovery are operator-assisted through Supabase; verify one recovery before invitations.
Evaluator safetyt291 proves authentication, 16 KiB bodies, per-subject rate limiting, two-worker capacity, a 45-second server timeout, exact-origin CORS, bounded event logs, and 60-second browser failure UX.Pass for host benchmarking only. In-memory limits reset on restart and are appropriate only for the small invited cohort. t294 must measure cold/warm behavior and cost before launch.
Discoverability and errorsThe catalog links the Custom Meta builder; configured account sync and remote evaluation reuse the existing workflow and preserve local configuration on failure.Pass. Run the browser smoke checks against the deployed origins before invitations.
Logs, spend, rollbackt293 defines credential-free signals, redaction/retention, measurable stop thresholds, RPO/RTO, deletion, spend, and timed rollback acceptance.Specification passes; t295 must record live evidence against every gate before invitations.

Conclusions and metrics are in research/findings/private-pilot-readiness-t292.md; see detail page for preserved tables/metrics.

Conclusions

[reconstructed — uncertain] Outcome inferred from status done and task note.

Problems / follow-ups

Links

Source artifact: research/results/t292.md