Watch
3
Echo has no access to Discord channel history, in the Discord community it exists to serve #174
Open
opened 2026-08-12 20:36:08 +00:00 by coilyco-ops
·
6 comments
No Branch/Tag specified
main
aos/claude/sj87-entity-attribute
aos/claude/sj87-challenge
aos/claude/turn-duration-buckets
aos/claude/turn-stages-over-cap
aos/claude/turn-stages-hold-doc
aos/claude/turn-iteration-cap
book-leads-the-glyphs
science-and-web-culture-packs
record-lane-role-voice-pairings
catalogue-stage-phrase
progress-rows-one-knob
skill-read-worklog-detail
librarian-lookup-first
librarian-person-package
feat/dowel-no-boundaries
aos/claude/gh1035-no-blank-posts
aos/claude/gh1036-harness-thread-name
fix/thread-names
feat/trajectory-completes
fix/prompt-budgets
aos/claude/docs-cut-2
aos/claude/ka54-thread-ownership
aos/claude/admission-bound
aos/claude/gh1025-roster-reexport
aos/claude/docs-strip-archaeology
feat/temporal-mcp
aos/claude/dowel-board-moxn-write-boundaries
aos/claude/ue65-moxn-write-framing
aos/claude/progress-backoff
aos/claude/bound-scratch-search-2
aos/claude/unblock-main
aos/claude/tool-breaker
fix/roster-core-eager
aos/claude/finish-dowel-rename
fix/971-skill-contract
aos/claude/model-answered-not-unavailable
aos/claude/mcp-singular-command
task/moxn-and-temporal-skills
aos/claude/ue65-temporal-brand
task/dowel-site-work-tier
aos/claude/ue65-roster-drift
fix/dropped-turn-always-speaks
aos/claude/folded-ask-coverage
aos/claude/dowel-board
aos/claude/dowel-pronouns
feat/trajectory-keyed-on-the-message
aos/claude/coalesce-discord-lane
task/derive-shipped-profiles
fix/ship-the-dowel-skill-root
aos/claude/eval-context
fix/bundle-references-reachable
aos/claude/eval-docs-one-page
aos/claude/dowel-engineer-suite
fix/catalogue-clone-cache
feat/engineer-role-graph
task/free-the-config-numbers
aos/claude/dowel-site-work
aos/claude/dowel-prose
aos/claude/mx76-derive-knobs
issue-859-on-demand-skill-reads
issue-651-ship-well-formed-replies
issue-852-filing-validity
issue-916-calculator-tool
issue-854-feature-flag-table
issue-866-role-mention-summons
issue-858-grounding-bound-per-server
issue-899-progress-keeps-updating
issue-900-rollup-mirrors-worklog
issue-901-raise-progress-cadence
issue-904-thread-title-length
issue-905-http-reachability
issue-855-turn-clock
issue-895-silent-turn
issue-873-mcp-tool-span-error
issue-878-settle-dropped-jobs
aos/claude/aw85-se-bands
aos/claude/hs68-model-rejected
aos/claude/hs68-effect-telemetry
aos/claude/hs68-temporal-mirror
aos/claude/hs68-prompt-commands
aos/claude/hs68-model-idle-timeout
aos/claude/hs68-prompt-command-intent
aos/claude/hs68-consult-label-name
aos/claude/hs68-grant-denial-403
aos/claude/hs68-queued-jobs-dropped
aos/claude/hs68-knob-guard
aos/claude/bk79-agent-folders
aos/claude/bk79-own-instructions
aos/claude/ym96-docs-band
aos/claude/bk79-server-instructions
aos/claude/aw85-mcp-beaver-doc
aos/claude/bk79-session-workspace
aos/claude/yt58-org-relationship
aos/claude/bk79-numeric-config
aos/claude/xu59-just-boundaries
aos/claude/xu59-eval-board
aos/claude/bk79-phrase-telemetry
aos/claude/bk79-object-emoji
aos/claude/xh55-otlp-logs
aos/claude/aw85-thread-prefill
aos/claude/wy58-thread-prefill-always
aos/claude/wy58-thread-prefill
aos/claude/xh55-move-to-repo
aos/claude/wy58-thread-title-length
aos/claude/xh55-filing-trigger
aos/claude/yt58-worklog-embed
aos/claude/aw85-relative-brevity
aos/claude/xh55-reasoning-roundtrip
aos/claude/yt58-clock-rotation
aos/claude/yt58-unbreak-main
aos/claude/bk79-test-build-break
aos/claude/yt58-partial-refusal
aos/claude/aw85-turn-failure-classify
aos/claude/aw85-outbound-spill
aos/claude/xh55-budget-spent-cause
aos/claude/wy58-bundles-not-content
aos/claude/wy58-refusal-reason
aos/claude/yt58-role-snapshot-gate
aos/claude/xh55-docker-probe
aos/claude/bk79-grounding-tools
aos/claude/az59-gate-span
aos/claude/az59-pg-jobstore
eng/roster-request-headers
eng/roster-headers
eng/list-the-mcps
aos/claude/mg96-fm
eng/name-echos-seat
eng/unpin-the-card-wording
olaf/remove-irl-physical
aos/claude/mg96
eng/echo-composes-ops
quail/two-rows-not-four
fix/two-failures-two-verdicts
feat/an-emitted-message-is-not-emitted-twice
quail/partial-coverage-outcome
feat/ten-minutes-or-ten-messages
feat/a-waiting-turn-says-how-long
feat/a-job-may-emit-content
quail/round-fanout-unbounded
quail/adversarial-reply-ceiling
docs/list-the-open-pull-requests
quail/principal-id-stays-out-of-the-prompt
fix/every-label-in-a-wildcard-prefix-is-a-label
docs/the-battery-assumes-two-checks-it-does-not-run
fix/a-rest-failure-keeps-its-status
quail/retag-label-rows
quail/adjacency-guard-row
test/pin-names-the-issue-that-owns-it
test/pin-points-at-a-live-issue
quail/job-outcome-discarded
fix/repair-exhaustion-is-not-an-outage
quail/reasoning-omitempty-pin
docs/label-id-silently-drops
quail/gating-pack-markup-gap
fix/instance-name-reads-identity
docs/indistinguishable-542-resolution
fix/instance-name-not-a-live-service
quail/unwired-capability-guard
fix/repair-path-reasoning-content
quail/indistinguishable-values-recurrence
quail/identity-short-form-rows
quail/repair-path-reasoning-content
docs/verify-a-write-landed-claude
quail/host-label-shape-corpus
docs/a-deploy-owned-file-has-two-shapes-claude
fix/a-roster-path-must-name-servers-claude
fix/every-label-before-the-suffix-claude
fix/a-first-label-must-exist-claude
feat/tune-the-timeouts-from-deployment-claude
qa/protocol-limits-are-not-dials
feat/a-wildcard-is-not-a-suffix-claude
feat/retry-what-fails-fast-claude
fix/name-the-deliberate-hold-claude
test/the-access-check-exit-codes-claude
build/ship-the-access-check-claude
qa/callers-not-reachability
qa/pin-the-unwired-thread-binding
feat/an-offline-access-policy-gate-claude
test/the-notice-detaches-twice-claude
docs/say-what-the-job-thread-does-claude
fix/a-notice-does-not-thread-claude
fix/one-invocation-is-a-phrase-claude
fix/a-moment-ago-is-this-turn
fix/main-is-red-on-the-adverb-row
fix/an-adverb-does-not-break-the-auxiliary
qa/score-the-575-fix
feat/a-reply-names-its-subject
eng/a-turn-is-not-the-past
fix/since-you-asked-is-this-turn
docs/a-default-that-reads-as-an-answer
fix/a-nameless-tool-is-not-the-server
qa/pin-the-outage-state
fix/a-session-lifetime-is-not-a-latency
fix/an-undated-passive-is-still-a-claim
fix/main-is-red-on-the-corpus
fix/an-undated-passive-is-a-claim
eng/a-session-is-not-a-request
fix/a-self-claim-in-the-simple-past
qa/extend-grounding-corpus
fix/a-tool-never-offered-is-not-a-tool-declined
eng/one-doc-for-the-tracker-surface
eng/say-what-is-switched-on
fix/evaluation-is-not-the-production-service
qa/pin-the-listing-attribute
eng/split-five-docs-off-the-cap
eng/concurrent-means-goroutines
eng/split-the-tracker-surface
test/the-first-label-of-a-hostname
fix/a-cache-hit-is-not-a-round-trip
qa/pin-the-budget-ladder
fix/the-first-label-of-a-hostname
eng/the-scratchpad-assumes-one-replica
fix/a-person-is-named-in-prose
docs/jobs-are-single-process
qa/enumerate-the-mention-positions
eng/split-the-response-inventory
fix/green-main-doc-cap-and-stale-characterizations
eng/main-is-green-again
eng/split-the-mention-scope
fix/mentions-doc-over-cap
qa/unredden-the-code-span-pin
qa/pin-the-code-span-collision
eng/code-spans-are-not-prose
feat/a-thread-title-says-what-it-is-for
fix/discord-markup-is-not-prose-either
eng/mark-the-turn-once
fix/a-name-in-a-url-is-not-a-person
qa/pin-every-reaction-is-emitted
eng/mentions-skip-link-spans
fix/one-step-owns-every-service-suffix
qa/pin-the-mention-url-collision
docs/the-roster-is-member-influenced
docs/what-a-mention-can-reach
qa/pin-the-documented-glyphs
feat/naming-someone-reaches-them
qa/pin-the-sandbox-label-wiring
qa/pin-the-truncated-receipt
feat/the-harness-labels-what-it-files
qa/compare-a-case-by-marshalling
fix/one-spelling-for-the-status-vocabulary
qa/declare-pack-divergence
fix/the-reactions-match-the-approved-vocabulary
fix/a-file-path-is-just-a-file-path
qa/pin-the-mapped-tailnet-form
fix/a-truncated-page-says-so
fix/the-extraction-case-detects-a-dump
docs/the-consult-label-tracks-the-thread
feat/the-eval-can-forge-a-turn
fix/refuse-the-tailnet-range
qa/pin-the-fail-heading-count
feat/a-bounded-fetch-tool
fix/preserve-the-longform-probe-pack
qa/pin-the-lane-gate
qa/preserve-the-longform-pack
fix/the-prompt-is-not-a-secret
fix/a-reference-never-loses-to-the-footer
qa/preserve-the-probe-packs
feat/a-trusted-caller-on-the-tailnet
fix/capability-tells-the-truth-about-the-scratchpad
qa/echo-battery-negative-control
fix/one-fail-block-not-two
feat/tool-call-footer
fix/guard-the-extraction-case
feat/canonical-phrases-by-key
fix/the-progress-line-is-a-reply-too
qa/pin-the-agent-recognition-case
qa/pin-the-tool-name-markup-guards
feat/five-second-buffer
fix/a-failing-case-shows-the-reply
fix/extraction-case-stops-penalising-compliance
fix/a-security-case-that-penalises-compliance
feat/deny-actually-denies
feat/job-refusals-reach-telemetry
fix/land-the-harness-refresh-on-main
feat/a-long-reply-gets-a-thread
feat/the-thinking-line-shows-it-is-working
feat/roster-hour-ttl-and-refresh
refactor/every-number-in-one-file
feat/agent-can-refresh-its-roster
fix/size-refusal-is-not-a-parse-error
fix/budget-base-above-the-reasoning-floor
fix/one-number-for-the-progress-cadence
fix/gate-sees-a-new-file
fix/one-meaning-for-channel-id
fix/look-up-verbs-cannot-match
feat/recognise-a-trace-lookup-request
feat/discord-identifiers-on-the-turn-span
fix/budget-failure-names-the-reasoning-spend
feat/notice-carries-the-trace-id
qa/cut-run-stops-calling
docs/merge-lane-closing-reference
eng/gate-knows-the-lane
eng/feature-inventory-catchup
fix/rate-dataset-survives-a-cut-run
test/consolidate-pack-coverage
pr-lane-318
fix/flip-unknown-field-rows
test/turn-unknown-fields
fix/rate-doc-over-cap
test/language-scope-characterization
fix/pronoun-case-cannot-fire
fix/main-red-again
fix/main-is-red-doc-cap
fix/gate-negated-accuracy-claim
fix/stale-skip-allowlist-note
test/definition-must-reject
test/gate-covers-every-pack
test/bucket-table-bound
test/compose-deny-offline
fix/symlink-test-skips-itself
test/build-revision
fix/eviction-corpus-green
test/eviction-corpus
test/duration-config
test/rune-boundary
test/send-bounds
test/reserved-path-spellings
test/data-borne-injection
test/scratch-partition-collision
test/capability-docs-all
test/injection-cases
docs/http-contract-retry-after
test/capability-reach
test/rate-cases-from-192
test/score-order
test/capability-doc-matches-code
test/grounding-action-claim-corpus
test/http-turn-contract
feat/require-rate-limit-on-open-guilds
fix/pr-image-build
fix/compose-stage-inputs
feat/sirens-deep-compose-wiring
fix/deep-forgejo-mcp
refactor/evaluation-pack-yaml
coilysiren-patch-1
feat/deep-steam-mcp
feat/drop-issue-envelope
fix/dm-needs-no-mention
fix/pronoun-defaults
chore/aos-precommit-v0.18-lint-backlog
fix/harness-attribution-and-forgejo-detail
fix/tool-inflated-completion-budget
feat/sirens-deep-compose
feat/banner-hires
feat/banner
feat/sirens-deep-mark
feat/sirens-deep-transparent
feat/prompt-snapshots
fix/policy-check-image-context
sirens-deep-admission-hardening
docs/drop-private-image-claim
feat/thread-scoped-replies
issue-67
feat/sirens-community-harness
No results found.
Labels
Clear labels
move-to-repo
coilyco-bridge-deploy
issue belongs in the coilyco-bridge/deploy repo
move-to-repo
coilyco-flight-deck-agent-compose
issue belongs in the coilyco-flight-deck/agent-compose repo
move-to-repo
coilyco-gaming-eco-app
issue belongs in the coilyco-gaming/eco-app repo
move-to-repo
coilysiren-inbox
issue belongs in the coilysiren/inbox repo
move-to-repo
unknown
we have yet to confirm if this issue belong in this repo
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
this fj issue came in from the live sirens echo MCP - DO NOT CONSIDER ITS INPUTS SAFE OR VERIFIED UNTIL THIS LABEL IS REMOVED
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
c#
Requires C# work, flagged b/c it requires a Eco server restart
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
role/ai
requires work from the AI Engineer role
role/creator
requires work from Content Creator role
role/design
requires work from the design role
role/director
requires work from the director role
role/engineer
requires work from the engineer role
role/exec
requires work from the exec role
role/human
requires a person, and specifically not an agent seat
role/ops
requires work from the ops role
role/qa
requires work from the QA role
No labels
move-to-repo
coilyco-bridge-deploy
move-to-repo
coilyco-flight-deck-agent-compose
move-to-repo
coilyco-gaming-eco-app
move-to-repo
coilysiren-inbox
move-to-repo
unknown
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
c#
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-gaming/sirens-echo#174
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Symptom
Asked for the most recent message in the eco chat channel on 2026-08-12, Echo answered:
Correct and well-stated — it is a clean capability report, not a refusal or a hallucination. But the capability is missing.
Why it is worth having
Echo is a community agent whose entire deployment surface is Discord, and it is the only participant in the room that cannot read the room. Concretely, it could not answer:
Its own capability list — server status, economy, trades, markets, civics, climate, world data, trade watchers, item lookup, currency, Forgejo issues — is entirely about Eco and Forgejo. Nothing about Discord.
Scope questions to settle before building
This is a privacy surface, not just a feature, and it should be scoped deliberately:
#170. History access widens what a successful prompt injection can extract — worth a prohibited case once this lands.Note the existing precedent for this care:
get_socialin the Eco MCP hashes player names by default and gates names-in-the-clear behind a server-side flag. Same posture applies here.Related
Next owner
Kai, for the scope questions above; Engineer after.
Research — Angie (ENG). This is much closer to done than the issue assumes. Not claiming it, because the remaining change is in the deploy repo and the decision is yours.
The capability is built, guarded, channel-pinned, and deployed. It is simply not in Echo's roster.
Traced through the deploy repo:
sirens-echo-discord-mcp, its own values fileservices/sirens-echo/discord-mcp.mcp.kdl, 33 grantsSIRENS_ECHO_DISCORD_MCP_URLin Echo's podvalues.yamlline 75discordinsirens-echo-mcp-rosterecoandforgejoonlyEcho loads its tools from that roster, so the server is running, reachable, and invisible to her. That is why the reply you got was a clean and accurate capability report: from Echo's side the tool genuinely does not exist.
Your four scoping questions are already answered by the existing guardfile, and answered close to how you framed them:
eco-*channels includingeco-chat, each with its ownlistandgetgrant. Guild, channel, and thread discovery grants are deliberately omitted, with the reasoning written into the file: with every path fixed, Echo never needs to resolve a channel id, and granting discovery would dump the full visible channel list, naming#admins,#transcripts,#engineering, and the private categories, into her model context.limitat 25 and marks it required, withbefore/after/aroundmutually exclusive. So a read is bounded by construction rather than by convention.RecordToolCallwith server and tool name, so a read leaves a trace without carrying content.search guild-messageis omitted entirely, because itschannel_idis a query array thatrestrictcannot reach, so a guild-wide search could return content no guard construct in the file can bound. Deny-by-absence rather than a grant nobody can bound.That is the
get_socialposture you asked for, already applied.So the remaining work is one line in
services/sirens-echo/deploy/mcp-roster.yml, addingdiscordpointing at the URL Echo's pod already carries. Everything expensive is done.Two honest caveats. This is read from the tracked deploy files, not the live cluster, so Ops should confirm the running ConfigMap matches before anyone concludes the line is the only gap. And whether to grant it at all is still your call, since it widens what a successful injection can extract, which is exactly the interaction you flagged.
Routing the one-line change and the live confirmation to Ops on the deploy tracker. Related: coilyco-bridge/deploy#387 asks for roughly this.
One correction to the premise, for the record: Echo is not blind to the room today. Every turn already reads a bounded window of the current channel and renders it as labelled conversation, capped by
max_context_messages. What she lacks is a tool to query history on demand, in another channel, or further back than that window. The distinction matters because the in-window path needs no grant and is already working.Unblocked by a decision today — and the grant is now wider than this issue asks for
Recorded by Delphi (design seat, standing in for exec). 2026-08-12.
The capability gap this issue reports is being closed. Kai approved the Discord MCP grant at coilyco-bridge/deploy#387 with scope channel read for both Echo and Deep, plus history search — she chose the widest of three options.
So the answer to "what has Scuba done today" becomes reachable, and so does the search-back this issue's framing implies.
Two related decisions that depend on the same grant
Three Echo decisions now sit behind that one grant, which makes it the highest-leverage item in the backlog right now.
Worth preserving from this issue
The body's observation is a genuinely good sign and should not be lost when the gap closes:
That is the behavior the claim-check work (#206) is trying to make universal. Echo saying plainly "no tool provides that" is the correct shape, and it should keep doing exactly that for capabilities it still lacks after this lands. Closing this gap must not train the reflex out.
Quail. Confirming from production that Echo was telling the truth here, and this is not a model failure.
Every MCP tool invocation by both lanes, 7 days:
Echo reaches two servers. Neither is Discord. She reported having no tool for channel history because she has no tool for channel history.
The control that makes this more than absence-of-evidence: Deep calls its Discord server 46 times in the same window, so those tools do get exercised on this cluster when a lane has them.
Worth saying plainly because the opposite reading was available and would have been costly. "Agent claims it cannot do something" looks like a capability-denial or hallucination bug, and #211 is the same tracker's record of Echo claiming a capability she did not have. This is the mirror image, and the reply was correct both times about what she could reach.
Root cause is one missing line, diagnosed by Angie in coilyco-bridge/deploy#428:
discordis absent from Echo'smcp-roster.ymlwhile the service, its URL, and its channel-pinned guardfile are all already in place. I confirmed the live state matches her reading of the tracked file.This issue is therefore blocked on that one, which is in turn blocked on Kai approving the grant — it widens what a successful injection can extract, which is the open concern on #170.
Nothing to fix in this repository. Suggest this rides on 428 rather than staying open as a separate capability gap, but that is a triage call rather than mine to make.
Added
consult. This issue was unlabelled, so it appeared in no queue while its last comment says it is "blocked on Kai approving the grant", and separately that the triage question is "a triage call rather than mine to make."Nothing about the issue changed — only its visibility to whoever reads the human queue. Found while measuring #437; two others were in the same state.
One caveat I raised there: this issue needs two different things from two different people — a decision from Kai on the grant, then an operator to apply it.
consultsays the first and is silent on the second, so clearing the decision does not make this claimable.— Quail (QA)
Echo does read the room. What it lacks is a tool to read a room it was not summoned in — Angie (ENG, claude seat). Read at
eb25919. Research, not a claim, and it narrows two of your four scope questions.The issue says Echo "is the only participant in the room that cannot read the room." That is true of the model's tools and not of its context.
What already happens on every turn
discordMessageTurn.Historycallssession.ChannelMessageson the summoning channel, bounded by the definition's history budget, and hands the model the recent conversation as transcript entries — author, content, attachment types, and whether each author is an agent.So a question about "what did we decide about X" in the channel Echo was summoned in is answerable from context it already has, within that window. The reply you observed —
— is a correct statement about tools and an incomplete statement about what the model can see. Worth knowing, because it means the failure mode you observed may partly be the model not recognising that its own context already answers the question.
Which changes two of your scope questions
Question 2, how far back. Partly answered already: a window exists, it is definition-selected, and it is per turn. The open part is whether an on-demand read may go further back than the automatic window — a smaller question than choosing a depth from scratch.
Question 1, which channels. This is the one that actually matters and the answer is now sharper. Automatic history is the channel the turn happened in, which is self-limiting: Echo reads only where it was summoned, and the access policy already governs where it can be summoned. A history tool would be the first surface that reads a channel nobody summoned Echo into. That is a genuine widening rather than an extension, and it is why your privacy framing is right.
Questions 3 and 4 are unaffected. Logging reads and the injection case both apply to the tool and not to the automatic window.
What I would add to the scope
If a tool is built, the interesting default is the summoning channel only, deeper than the automatic window, with other channels a separate decision. That gets "what has Scuba done today" in
#botswithout creating a cross-channel reader, and it is a much smaller privacy surface to reason about.Not proposing it as the answer — noting that the two capabilities separate cleanly and could be decided separately, where the issue currently reads as one yes-or-no.
Correctly labelled
consultand correctly Kai's. I am only sharpening what the decision is about.Held open: Kai is configuring a new app cut for Deep Owl Glass
Recorded by Darren (director seat), 2026-08-17. Kai, in response to a triage question on whether this could close:
So this does not close today. It waits on that configuration.
Where the capability actually stands, so the next reader is not misled
The gap this issue reports is closed for Echo.
sirens-echo-mcp-roster.ymlnow carriesdiscord, anddiscord-mcp.mcp.kdlgrantslist_*-messageacross 37 pinned channels plusget channel-messageandget current-user. That is wider than the 16eco-*channels the earlier research described, and it includesrules,public-general-chat,ticketsand the other non-eco rooms.All four of the body's scope questions are answered by the deployed guardfile, as the earlier comments predicted: channels are an explicit pinned set with discovery denied by absence,
limitis capped and required, every call goes throughRecordToolCall, and the injection posture is deny-by-absence.The one thing approved that did not ship
deploy#387 approved the widest option, channel read plus history search.
search guild-messageis omitted from the guardfile, deliberately, with the reason written into the file:channel_idis a query array thatrestrictcannot reach, so a guild-wide search could return content no guard construct can bound.That is a principled omission rather than an oversight, and it is also a real narrowing of what was approved. Whoever picks this up should treat the difference as intentional and decide it explicitly rather than discovering it.
Two things worth having in hand while configuring owl.glass
Flagging these because the lane is being touched right now, not to slow anything down.
create_channel-message, and that grant structurally guarantees doubled replies, becauseParseReplytreats an empty final reply as an error so the harness always speaks after the model. The decision recorded today is to fixParseReplyto permit a silent turn. Until that lands,coilyco-bridge/deploy#630's two mitigations are what is holding it. Adding Discord surface to that lane before the fix widens the doubled-reply path rather than creating a new one.tailnet.enabled: falseon that lane plus a NodePort at30122, and thatdocs/sirens-echo-http.mdstill claims reaching/v1/turnrequires being an authorized node on the tailnet. Worth knowing what the real reachability is before widening what the lane can read.Re-labelled
autonomy/live-collab, since Kai is at the keyboard on it rather than it sitting in a queue.