Files
ss-tools/specs/050-mcp-interface/data-model.md
busya e7bac04e98 feat(dashboard-testing): add reference URL baseline workflow and analyst UX
Discover dashboard filters, datasets and metrics from a parsed reference URL; capture and review baseline candidates with source provenance. Improve scenario DAG and run result views, add isolated browser coverage, and align contracts and ADRs.
2026-09-25 10:36:37 +03:00

3.0 KiB

@{ McpInterface.DataModel [C:4] [TYPE ADR]

@BRIEF MCP projection and durable operation identity; implemented=false for refresh additions. @INVARIANT MCP owns no second baseline, run, gate or analytics truth store. @RELATION DEPENDS_ON -> [BaselineEngine.ReferenceUrl] @INVARIANT MCP projects the same server-parsed URL source identity as REST; tool input cannot substitute an expected value or caller-decoded filter state.

ToolDefinition

{name, catalog_version, input_schema, output_schema, permission, principal_classes, read_only, idempotency_required, deprecated_since?}. Strict schemas are versioned; tools/list is permission-filtered. Invocation rechecks live ACL regardless of list history. Tool schemas define the audited additions.

ToolInvocation / AgentAction

{invocation_id, principal_id, delegator_id?, tool_name, catalog_version, canonical_arguments_digest, idempotency_key?, domain_operation_id, gate_id?, status, stable_error_code?, created_at, completed_at?}. Unique mutation identity is principal + tool + idempotency key; changed canonical intent conflicts. Retry returns the original domain receipt, never repeats a commit. Secrets, raw cookies and storage paths are excluded from arguments/audit. Bounded error detail includes correlation ID without secret payload.

BaselineSelectionPin

Exact 037 BaselineSelectionPin is server-resolved from approved published catalog entries. Caller selectors are not pins. Admission includes resolved set/version/catalog/release/commit/entry IDs and digests in request identity; persist unchanged in RunnerPlan/run/result and analytics. Authoring sessions store baseline constraints, not launch bindings.

Approval and publication receipt

036 ActionApprovalGate binds actor/delegator, object, canonical intent digest, candidate/review receipt, expected catalog revision, release and publication intent. User decision is immutable and CAS-protected. Consume reloads the exact approval. 037 PublicationReceipt owns materialized/publish_pending/committed/published/publish_failed; MCP reports those states verbatim. A pending push is not completed publication.

Evidence and context projections

044 result/evidence DTOs are authoritative; MCP reads typed bounded metadata and protected content refs. ScenarioRun and AgentRun ownership cannot be interchanged. 047 uses the stored full AnalyticsContextKey, not environment-only fallback. External clients may read authoring workspace state; frontend has no workspace/chat/prompt model or agent request action. Human ReviewDisposition is separate from immutable evaluation.

Migration

Legacy success envelopes without a durable receipt are non-authoritative and must be reported as unverified, not backfilled as published. Existing run pins missing required provenance remain legacy/ineligible for cross-run comparison until rerun. No fabricated hashes.

@} McpInterface.DataModel