ContriveAtlas
neostory-schema-set/22snapshot a59c206cec9d
Open Observatory

Platform boundaries · Customer delivery

From a customer-owned domain to a pinned application release

M1 groundwork connects an external customer repository, local distribution candidates and an inspectable deployment journey; the deployment MCP inspects and plans over the same control-plane contract. Hosted pilot evidence is historical; publication and current-runtime acceptance remain explicit milestones.

Business · Partners · Engineering · Operations
DeclaredImplementedObservedPlanned
neostory-schema-set/22snapshot a59c206cec9d

Platform boundaries · Customer delivery

From a customer-owned domain to a pinned application release

M1 groundwork connects an external customer repository, local distribution candidates and an inspectable deployment journey; the deployment MCP inspects and plans over the same control-plane contract. Hosted pilot evidence is historical; publication and current-runtime acceptance remain explicit milestones.

Business · Partners · Engineering · Operations11 nodes · 8 directed relationships

What this view establishes

The architectural commitments

  1. A customer owns its domain and application; release pins identify the platform artifacts it consumes.
  2. Project and deployment MCPs are implemented. Customer-data MCP admits delegated reads and bounded writes with local installed HTTPS/source-denied proof. Human MCP access ended. Tenant-admin MCP remains planned.
  3. The hosted pilot is evidence for its pinned runtime, not a current production service.

Layered platform stack

01
03

Customer owns the product

projectimplemented

Customer repository

Domain schema and application stay outside the product monorepo.

authorimplemented

Project MCP

Initialize, validate, edit, generate and package a local project.

domainimplemented

Domain identity

Namespace grant and exact schema closure constrain generation.

02
04

Platform supplies the boundary

clientsimplemented

Swift, Python and web

Local distribution candidates support customer-owned applications.

releaseimplemented

Pinned local release

Manifest, compatibility and installed validation bind the candidate.

runtime-gapplanned

Current runtime acceptance

Rebuild the customer artifact with the latest access-gate migrations.

customer-data-mcpimplemented

Customer data MCP (scoped writes)

Delegation-only: five read tools plus submit_mutation for write capability. Scoped endpoints, member ownership and agent attribution. Local installed HTTPS/source-denied write and revoke proof.

03
04

Evidence and operations

pilotobserved

Field Notebook pilot

Python create, Swift update and signed-in browser update over HTTPS.

consoleimplemented

Deployment console

Inspect permitted environments and server-admitted actions.

deployment-mcpimplemented

Deployment MCP (bounded changes)

Seven tools cover inspect, plan and confirmed create/trim through existing control-plane APIs. Local and real staging session evidence passed; freshness, scoped authority and sibling retention are proven. Recovery remains unavailable.

customer-tenant-admin-mcpplanned

Customer tenant admin MCP

Future separate delegated-admin surface for tenant membership and roles; not customer data or deployment administration.

Connections and evidence

Open the 8-relationship source key

Numbers set an explanatory reading order. They do not measure runtime timing.

  1. 01

    Customer repositoryProject MCP

    author locally

    implemented
  2. 02

    Project MCPDomain identity

    verify namespace

    implemented
  3. 03

    Domain identitySwift, Python and web

    generate projections

    implemented
  4. 04

    Swift, Python and webPinned local release

    bind candidate

    implemented
  5. 05

    Pinned local releaseField Notebook pilot

    historical hosted proof

    observed
  6. 06

    Field Notebook pilotDeployment console

    manage lifecycle

    implemented
  7. 07

    Current runtime acceptancePinned local release

    next accepted release

    planned
  8. 08

    Deployment MCP (bounded changes)Deployment console

    same server contracts

    implemented

Connections and evidence

8 directed, source-backed relationships

Numbers set an explanatory reading order. They do not measure runtime timing.

  1. 01

    Customer repositoryProject MCP

    author locally

    implemented
  2. 02

    Project MCPDomain identity

    verify namespace

    implemented
  3. 03

    Domain identitySwift, Python and web

    generate projections

    implemented
  4. 04

    Swift, Python and webPinned local release

    bind candidate

    implemented
  5. 05

    Pinned local releaseField Notebook pilot

    historical hosted proof

    observed
  6. 06

    Field Notebook pilotDeployment console

    manage lifecycle

    implemented
  7. 07

    Current runtime acceptancePinned local release

    next accepted release

    planned
  8. 08

    Deployment MCP (bounded changes)Deployment console

    same server contracts

    implemented

What this view establishes

The architectural commitments

  1. A customer owns its domain and application; release pins identify the platform artifacts it consumes.
  2. Project and deployment MCPs are implemented. Customer-data MCP admits delegated reads and bounded writes with local installed HTTPS/source-denied proof. Human MCP access ended. Tenant-admin MCP remains planned.
  3. The hosted pilot is evidence for its pinned runtime, not a current production service.
19 repository sources behind this view
  • distribution/project-tools/src/neostory_project_tools/grant.py
  • distribution/project-tools/src/neostory_project_tools/mcp.py
  • docs/delegation/customer-data-mcp-assessment-2026-09-11.md
  • docs/delegation/customer-data-mcp-phase4-results-2026-09-11.md
  • docs/delegation/platform-groundwork-landing-2026-09-11.md
  • docs/delegation/platform-release-wave-0-results-2026-09-08.md
  • docs/platform-business-cases.md
  • docs/releases/evidence/customer-data-mcp-phase4/runtime.json
  • docs/releases/evidence/deployment-mcp-bounded-changes/receipt.json
  • docs/releases/evidence/deployment-mcp-inspect-plan/receipt.json
  • docs/releases/evidence/deployment-mcp-session-mode/receipt.json
  • docs/releases/evidence/records-v2-provider-readiness/hosted-three-client-receipt.json
  • gateway/src/neostory_gateway/delegated_mutation.py
  • platform/control-plane/control_plane.py
  • platform/control-plane/release_validation_preflight.py
  • platform/customer-runtime/customer_runtime.py
  • platform/deployment-console/README.md
  • platform/deployment-mcp/README.md
  • platform/deployment-mcp/src/neostory_deployment_mcp/server.py