Platform boundaries · Customer delivery
From a customer-owned domain to a pinned application release
M1 groundwork connects an external customer repository, local distribution candidates and an inspectable deployment journey; the deployment MCP inspects and plans over the same control-plane contract. Hosted pilot evidence is historical; publication and current-runtime acceptance remain explicit milestones.
Platform boundaries · Customer delivery
From a customer-owned domain to a pinned application release
M1 groundwork connects an external customer repository, local distribution candidates and an inspectable deployment journey; the deployment MCP inspects and plans over the same control-plane contract. Hosted pilot evidence is historical; publication and current-runtime acceptance remain explicit milestones.
What this view establishes
The architectural commitments
- A customer owns its domain and application; release pins identify the platform artifacts it consumes.
- Project and deployment MCPs are implemented. Customer-data MCP admits delegated reads and bounded writes with local installed HTTPS/source-denied proof. Human MCP access ended. Tenant-admin MCP remains planned.
- The hosted pilot is evidence for its pinned runtime, not a current production service.
Layered platform stack
Customer owns the product
Platform supplies the boundary
Swift, Python and web
Local distribution candidates support customer-owned applications.
Pinned local release
Manifest, compatibility and installed validation bind the candidate.
Current runtime acceptance
Rebuild the customer artifact with the latest access-gate migrations.
Customer data MCP (scoped writes)
Delegation-only: five read tools plus submit_mutation for write capability. Scoped endpoints, member ownership and agent attribution. Local installed HTTPS/source-denied write and revoke proof.
Evidence and operations
Field Notebook pilot
Python create, Swift update and signed-in browser update over HTTPS.
Deployment console
Inspect permitted environments and server-admitted actions.
Deployment MCP (bounded changes)
Seven tools cover inspect, plan and confirmed create/trim through existing control-plane APIs. Local and real staging session evidence passed; freshness, scoped authority and sibling retention are proven. Recovery remains unavailable.
Customer tenant admin MCP
Future separate delegated-admin surface for tenant membership and roles; not customer data or deployment administration.
Connections and evidence
Open the 8-relationship source key
Numbers set an explanatory reading order. They do not measure runtime timing.
Connections and evidence
Open the 8-relationship source key
- 01implemented
Customer repository→Project MCP
author locally
- 02implemented
Project MCP→Domain identity
verify namespace
- 03implemented
Domain identity→Swift, Python and web
generate projections
- 04implemented
Swift, Python and web→Pinned local release
bind candidate
- 05observed
Pinned local release→Field Notebook pilot
historical hosted proof
- 06implemented
Field Notebook pilot→Deployment console
manage lifecycle
- 07planned
Current runtime acceptance→Pinned local release
next accepted release
- 08implemented
Deployment MCP (bounded changes)→Deployment console
same server contracts
Connections and evidence
8 directed, source-backed relationships
Numbers set an explanatory reading order. They do not measure runtime timing.
- 01implemented
Customer repository→Project MCP
author locally
- 02implemented
Project MCP→Domain identity
verify namespace
- 03implemented
Domain identity→Swift, Python and web
generate projections
- 04implemented
Swift, Python and web→Pinned local release
bind candidate
- 05observed
Pinned local release→Field Notebook pilot
historical hosted proof
- 06implemented
Field Notebook pilot→Deployment console
manage lifecycle
- 07planned
Current runtime acceptance→Pinned local release
next accepted release
- 08implemented
Deployment MCP (bounded changes)→Deployment console
same server contracts
What this view establishes
The architectural commitments
- A customer owns its domain and application; release pins identify the platform artifacts it consumes.
- Project and deployment MCPs are implemented. Customer-data MCP admits delegated reads and bounded writes with local installed HTTPS/source-denied proof. Human MCP access ended. Tenant-admin MCP remains planned.
- The hosted pilot is evidence for its pinned runtime, not a current production service.
Follow the live system
Move from explanation to inspection
The Atlas is static and source-backed. The Observatory shows authenticated environment state.
19 repository sources behind this view
distribution/project-tools/src/neostory_project_tools/grant.pydistribution/project-tools/src/neostory_project_tools/mcp.pydocs/delegation/customer-data-mcp-assessment-2026-09-11.mddocs/delegation/customer-data-mcp-phase4-results-2026-09-11.mddocs/delegation/platform-groundwork-landing-2026-09-11.mddocs/delegation/platform-release-wave-0-results-2026-09-08.mddocs/platform-business-cases.mddocs/releases/evidence/customer-data-mcp-phase4/runtime.jsondocs/releases/evidence/deployment-mcp-bounded-changes/receipt.jsondocs/releases/evidence/deployment-mcp-inspect-plan/receipt.jsondocs/releases/evidence/deployment-mcp-session-mode/receipt.jsondocs/releases/evidence/records-v2-provider-readiness/hosted-three-client-receipt.jsongateway/src/neostory_gateway/delegated_mutation.pyplatform/control-plane/control_plane.pyplatform/control-plane/release_validation_preflight.pyplatform/customer-runtime/customer_runtime.pyplatform/deployment-console/README.mdplatform/deployment-mcp/README.mdplatform/deployment-mcp/src/neostory_deployment_mcp/server.py