Skip to content

Catalog provisioning local result — 2026-09-23

Task: 4bba7d43-00b0-446b-b1bd-5995950c8909. Parent FLOW-08: ae03b6f5-8495-413e-931c-b6bff044dfdf. Base: server e4aed118c838e674e1869a674f39e39076397136; branch codex/agent-catalog-writes.

Implemented account-scoped role/skill/agent provisioning via three MCP tools, immutable full-replacement versions, pinned references, optimistic locking, atomic idempotency and attributable audit records. Migration 020 introduces explicit account editor grants without widening existing token permissions. Privileged administration grants/revokes editors; OAuth scope and current project owner/admin membership remain additional requirements.

Actual local complete PostgreSQL suite: 290 passed in 22.13 seconds, zero skips. The new actual HTTP MCP test exercises OAuth scopes, explicit editor grants, static-token denial, project binding, same-account sharing, cross-account denial, concurrent retries and updates, historical version stability, reference rollback, and revocation before replay. Runtime tools/list schemas and generated contract agree. Documentation contract covers 24 tools; runtime validation passes. An initial complete run found stale exact tool-name sets in the smoke clients; both clients were updated and the complete suite rerun successfully.

No production change is claimed by this local result. Catalog-backed workflow resolution, background pickup and the controlled release remain FLOW-08 children. Provisioning stores metadata and source references; it does not load skills, choose runtime accounts or start sessions. Existing list status-filter semantics remain compatible, including access to historical matching versions.