{"capabilities":[{"id":"m0_heartbeat","title":"Always-on cloud floor (M0 heartbeat)","description":"The scheduled heartbeat proving the cloud execution substrate is alive.","surface":"ria-builder","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"getSystemStatus: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 120s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":120}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"gmail_draft","title":"RIA Chief drafts Gmail messages for you to send","description":"RIA Chief composes a Gmail draft for you to review and send — not yet built.","surface":"ria-builder","ownerAgent":"ria-chief","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"no successful run/receipt found","checkedAtMs":1788293169215},{"kind":"tool_in_bundle","evidenceRole":"existence","result":"fail","evidence":"tool \"propose_email_draft\" absent from deployed bundle","checkedAtMs":1788293169215},{"kind":"feature_flag","evidenceRole":"existence","result":"fail","evidence":"flag \"gmail_draft_enabled\" = off/absent","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"action_sync","title":"RIA Chief records durable action receipts (Action Sync)","description":"Every RIA Chief tool action writes an auditable receipt. Verdict is probe-derived.","surface":"ria-builder","ownerAgent":"ria-chief","lifecycle":"active","status":"not-built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"riaChiefActionReceipts: HTTP 401 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 2754374s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":2754374}],"gaps":[],"knownGaps":[{"id":"action-sync-proven-by-use","ownerAgent":"ria-chief","reason":"Proof for this row is produced only when David actually uses the lane — there is no timer or synthetic exercise behind it. A red here can mean idle, not broken. The durable fix is a scheduled prober whose cadence matches the freshness window.","reviewAfter":"2026-09-25"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"ria_chief_dispatchable_work_requests","title":"RIA Chief creates dispatcher-aware implementation requests","description":"RIA Chief's create_implementation_request tool normalizes repo scope and marks low-risk Claude requests as Command Center dispatcher work instead of passive specs.","surface":"ria-builder","ownerAgent":"ria-chief","lifecycle":"active","status":"not-built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"riaChiefImplementationRequests: HTTP 401 (deployed)","checkedAtMs":1788293169215},{"kind":"tool_in_bundle","evidenceRole":"existence","result":"pass","evidence":"tool \"create_implementation_request\" present in deployed bundle","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 4788113s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":4788113}],"gaps":[],"knownGaps":[{"id":"first-live-dispatch-run-proof","ownerAgent":"cto","reason":"Board row proves the deployed PR #99 request contract; close this gap after the next eligible request is consumed and completed by the scheduled dispatcher.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"cto_board_live","title":"Command-Center capability board is deployed","description":"dvo88.com renders the built/live Infrastructure board served by command-center.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"dvo88-board: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 113s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":113}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"command_center_home_search","title":"Command Center home hydrates operational search","description":"Home loads the current command-center dashboard and indexes operational records into site search.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"home: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 113s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":113}],"gaps":[],"knownGaps":[{"id":"home-search-health-probe","ownerAgent":"cto","reason":"Checker still needs a search-index assertion proving nonempty results and no retired-route hrefs.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"project_inventory_status","title":"Command Center tracks project inventory freshness","description":"Projects and project detail pages expose David's active project inventory with current status and capability rollups.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"projects: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"no successful run/receipt found","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"project-freshness-probe","ownerAgent":"cto","reason":"Checker still needs a project-data assertion against lastUpdated overrides and per-project route resolution.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"cto_operator_workspace","title":"CTO operator workspace is reachable","description":"The CTO surface exposes the cross-project roadmap and operator entry points for David's technical stack.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"cto: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 113s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":113}],"gaps":[],"knownGaps":[{"id":"cto-chat-functional-probe","ownerAgent":"cto","reason":"Checker still needs a CTO thread/chat success probe before this row proves assistant usability.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"cto_reference_page_live","title":"CTO operating-model reference is deployed","description":"dvo88.com publishes the gated CTO reference for canonical GitHub policy, agent roles, safe memory-path guidance, diagrams, live proof, and known gaps.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"cto-reference: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 113s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":113}],"gaps":[],"knownGaps":[{"id":"cto-reference-content-probe","ownerAgent":"cto","reason":"The checker proves the deployed endpoint; CI verifies the required reference content, but a browser-level content probe is not yet available.","reviewAfter":"2026-08-17"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"webcto_route_a_web_door","title":"WebCTO reaches the single cloud Hermes CTO","description":"The production WebCTO panel completes a turn through the one cloud Hermes CTO with authority and session proof.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"cto-web-door-health: fresh 564s old with positive proofCount","checkedAtMs":1788293169215},{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"webcto-route-a-cto: HTTP 200 (deployed)","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"webcto_route_a_telegram_door","title":"Telegram has one healthy cloud Hermes CTO listener","description":"The existing CTO Telegram bot is reachable through exactly one conflict-free listener on the same cloud Hermes profile.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"cto-telegram-door-health: fresh 564s old with positive proofCount","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"webcto_route_a_single_memory_authority","title":"Web and Telegram share one CTO memory authority","description":"Cross-channel recall resolves to one writable cloud Hermes CTO memory without a second persona or split authority.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"cto-memory-authority-health: fresh 564s old with positive proofCount","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"webcto_route_a_tool_parity","title":"Cloud Hermes proves its approved WebCTO tools","description":"Cloud Hermes completes a real file create/read canary while the monitor confirms host-terminal access stays reserved for trusted Local Hands.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"cto-tool-parity-health: fresh 564s old with positive proofCount","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"webcto_route_a_backup_restore","title":"CTO core recovery is rehearsed","description":"The latest credential-free five-file core-recovery bundle restored with private modes, initialized fresh empty Hermes stores, proved the approved non-terminal tool policy, and matched immutable CMEK-protected object metadata.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"fail","evidence":"cto-backup-restore-health: JSON artifact not reachable (HTTP 503)","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"cto_local_hands_worker","title":"Portfolio PM hands local work to the CTO","description":"Portfolio PM routes a local-PC/repository work order to the existing trusted Windows Hermes CTO profile, and a recent real dispatch returns a non-synthetic, evidence-bearing, sanitized receipt.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"portfolio-pm-local-hands-status: fresh 0s old with positive laneDispatchable, runFresh, ctoProfileConfirmed, receiptVerified","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"ria_working_hands_specialist","title":"Portfolio PM dispatches RIA Working Hands within five RIA properties","description":"RIA Working Hands is a distinct RIA Technical Specialist. Portfolio PM is its sole dispatcher; a recent policy-bound Windows run must return a non-synthetic receipt from one of exactly five approved RIA repositories.","surface":"ria-builder","ownerAgent":"ria-chief","lifecycle":"active","status":"not-built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"fail","evidence":"portfolio-pm-ria-working-hands-status: coverage.stale=true","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"ria-working-hands-protected-activation","ownerAgent":"cto","reason":"David authorized the bounded activation window. The lane remains fail-closed and unproven until profile, dedicated-worktree, Portfolio PM receipt, and harmless live-pilot checks pass.","reviewAfter":"2026-08-17"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"agent_cockpit_workstreams","title":"Cockpit manages agent messages and the shared Work Desk","description":"Cockpit renders agent communications alongside shared work queues and proof links.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"cockpit: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"no successful run/receipt found","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"cockpit-work-desk-proof-probe","ownerAgent":"cto","reason":"Checker still needs route-specific proof for Cockpit message delivery and shared Work Desk links.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"agent_inbox_read_only","title":"Agent Inbox privately reads allowlisted Buzz channels","description":"Agent Inbox gives David one authenticated, read-only view of allowlisted private Buzz channels without exposing the bridge credential or adding any Buzz mutation capability.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"agent-inbox: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"no successful run/receipt found","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"agent-inbox-private-functional-probe","ownerAgent":"cto","reason":"The private session-gated functional proof is exercised during release; the public checker intentionally receives no Buzz channel or message metadata.","reviewAfter":"2026-09-17"},{"id":"agent-inbox-read-deepening-probe","ownerAgent":"cto","reason":"2026-08-18 read-side deepening (needs-you lane, unread watermarks, loaded-message search, membership audit panel) ships without its own checker probe; a real functional check arrives with the receipted reply path, and this row claims nothing about the new features until then.","reviewAfter":"2026-09-17"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"agent_ownership_directive","title":"Agents publishes the stable ownership directive","description":"Agents exposes the stable surface-agent, outside-coding-agent, and Hermes-reviewer ownership lanes.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"agents: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 113s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":113}],"gaps":[],"knownGaps":[{"id":"agent-ownership-rendered-content-probe","ownerAgent":"cto","reason":"Checker still needs a rendered-content assertion proving /agents includes the stable ownership directive and Hermes reviewer lane.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"agent_communication_map","title":"Infrastructure shows the live agent communication map","description":"The Infrastructure page renders every fleet identity on both sides of an interactive map and distinguishes messages, reviews, execution runs, and passive handoffs using the route registry plus live capability evidence.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"agent-communication-map: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 113s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":113}],"gaps":[],"knownGaps":[{"id":"agent-communication-map-content-probe","ownerAgent":"cto","reason":"Checker still needs a rendered-content assertion that every fleet identity appears and route cards expose method, work-start semantics, and receipt requirements.","reviewAfter":"2026-08-09"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"hermes_kanban_mirror","title":"Command Center mirrors Hermes Kanban","description":"dvo88.com renders the approved read-only, stale-aware Hermes Kanban snapshot mirror.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"kanban: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"no successful run/receipt found","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"kanban-snapshot-freshness-probe","ownerAgent":"cto","reason":"Checker still needs to read /api/kanban/board or hermes_kanban_snapshots/current and assert a valid fresh snapshot without raw task bodies or local paths.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dv_os_google_full_auth_readiness","title":"DV-OS shows Google full-auth Workspace readiness","description":"DV-OS exposes site-gated Google full-auth target readiness plus read-only Gmail, Drive metadata, and Calendar upcoming-event routes while bodies, descriptions, attendee emails, file contents, and write actions remain off.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"dv-os: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"no successful run/receipt found","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"google-full-auth-status-probe","ownerAgent":"cto","reason":"Checker still needs an authenticated /api/dv-os/google-full-auth/status assertion proving Gmail, Drive, and Calendar are read-only wired, targets are masked, and no credential material is returned.","reviewAfter":"2026-07-15"},{"id":"google-full-auth-gmail-metadata-probe","ownerAgent":"cto","reason":"Checker still needs an authenticated /api/dv-os/gmail/messages assertion proving fail-closed or masked metadata only, no message body fields, no write actions, and no credential material.","reviewAfter":"2026-07-15"},{"id":"google-full-auth-drive-metadata-probe","ownerAgent":"cto","reason":"Checker still needs an authenticated /api/dv-os/drive/files assertion proving fail-closed or masked metadata only, no file body/export fields, no write actions, and no credential material.","reviewAfter":"2026-07-15"},{"id":"google-full-auth-calendar-events-probe","ownerAgent":"cto","reason":"Checker still needs an authenticated /api/dv-os/calendar/events assertion proving fail-closed or masked event metadata only, no descriptions, no attendee emails, no write actions, and no credential material.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"news_pulse_curation","title":"News Pulse serves current curated cards","description":"News Pulse serves source-backed cards, saved cards, run history, and curation feedback workflows.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"news: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 12920s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":12920}],"gaps":[],"knownGaps":[{"id":"news-api-shape-probe","ownerAgent":"cto","reason":"Checker still needs an API assertion for cards, saved cards, and admin run payload shape.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"media_intake_youtube_to_news_pulse","title":"YouTube channels reach News Pulse as cards","description":"Media Intake's YouTube lane ingests the owner-confirmed channels from their public uploads feeds and those videos surface as News Pulse cards. The functional check is the end result — a YouTube-sourced card visible on /news — not a green ingest run, so configuring channels or shipping code cannot turn this row green on its own.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"news-youtube-lane-status: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"news-youtube-lane-status: fresh 0s old with positive channels.ready, cards.youtubeCardsActive","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"youtube-lane-transcript-enrichment","ownerAgent":"cto","reason":"Runtime card content is the promo-stripped video description; transcript enrichment stays out-of-band (yt-dlp + youtube-transcript-api) and is not exercised by this check.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"portfolio_pm_operational","title":"Portfolio PM full autonomous loop is verified end to end","description":"The strict bar for the canonical Portfolio PM web agent. The dvo88 Portfolio workspace — the agent's only David-facing channel — proves its Hermes route is open, its runtime identity and reasoning turns are current, the dispatcher is ticking, no execution dispatch is wedged, every terminal dispatch reconciles to its receipt, and one real bound end-to-end workflow still re-verifies from its own records. The retired Telegram-native /api/portfolio-pm/status endpoint remains diagnostic only and cannot gate this row. David's interactive card intake is tracked separately as portfolio_pm_card_intake — this row red does NOT mean PM is unreachable.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"fail","evidence":"portfolio-pm-web-status: coverage.stale=true","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"portfolio_pm_card_intake","title":"David can tell Portfolio PM to take on work (interactive intake)","description":"Portfolio PM is live on its interactive channels — gateway, Telegram, agent-fabric routing — and records incoming work events, so David's 'create this card' requests reach a running PM. The full autonomous delivery loop is the separate strict row portfolio_pm_operational.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"portfolio-pm-intake-status: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"public_json_artifact","evidenceRole":"functional","result":"fail","evidence":"portfolio-pm-intake-status: gatewayHealthy is not positive","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"portfolio-pm-card-receipt-probe","ownerAgent":"cto","reason":"The checker proves the live intake channels; a per-card completion-receipt probe (proving a specific requested card landed on the board) is not wired yet.","reviewAfter":"2026-08-04"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"steward_pm_intake_door","title":"Surface stewards file David's requests as Portfolio PM cards","description":"CTO, RIA Chief, and ELMer relay David's feature/fix requests through the agent-authenticated intake door (POST /api/portfolio-pm/agent-intake) into real Portfolio PM cards, bylined to the steward, with a receipt back to David. Functional proof is the latest completed steward_pm_intake run record; per-steward wiring is tracked in knownGaps until each runtime PR lands.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 8038s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":8038}],"gaps":[],"knownGaps":[{"id":"steward-intake-self-certified-proof","ownerAgent":"cto","reason":"The intake run record is written by the intake handler itself in the same request — the actor certifies its own success. The freshness bound limits the age of that self-certification; it does not replace recipient-side proof.","reviewAfter":"2026-09-25"},{"id":"ria-chief-pm-intake-wiring","ownerAgent":"ria-chief","reason":"RIA Chief's create_portfolio_pm_intake implementation exists in RIA-builder PR #127 (head cb6170e4), open/mergeable/green, but not yet merged, deployed, or exercised by a live intake -- until then only CTO exercises the door.","reviewAfter":"2026-08-06"},{"id":"elmer-pm-intake-wiring","ownerAgent":"elmer","reason":"ELMer's create_portfolio_pm_intake implementation exists in 672elmstreet PR #105 (head 9ee57970), open/mergeable/green, but not yet merged, deployed, or exercised by a live intake -- until then only CTO exercises the door.","reviewAfter":"2026-08-06"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"cto_email_intake","title":"Emailing cto@agents.dvo88.com reaches CTO","description":"David emails CTO's workspace address and CTO answers from his runtime. The checker continuously proves the mailbox is reachable with a real IMAP read (sanitized mailbox-status artifact — reachability and age only, never message content) and that the gated inbox reader route is deployed. The reply loop itself is CTO-agent behavior, proven in production by real David-to-CTO threads.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"cto-inbox-api: HTTP 401 (deployed)","checkedAtMs":1788293169215},{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"cto-mailbox-status: fresh 0s old with positive inboxReachable","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"cto-email-reply-loop-probe","ownerAgent":"cto","reason":"The checker proves inbox reachability and the deployed reader; an automated probe of the reply loop (CTO answering a synthetic inbound email) is not wired yet.","reviewAfter":"2026-08-04"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"agent_cost_tracking","title":"CTO tracks observed agent dispatch spend","description":"dvo88.com exposes the private Agent Spend report while a sanitized public health signal proves that current provider reporting is working without revealing spend or usage.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"agent-spend: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"protected-agent-spend-status: HTTP 401 (deployed)","checkedAtMs":1788293169215},{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"agent-spend-health: fresh 0s old with positive providerSources, reportWindows, trackedSurfaces","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"scheduled_automation_control","title":"Scheduled shows automation jobs and next runs","description":"Scheduled exposes the automation calendar, gateway state, job health, and next-run inventory.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"scheduled: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 113s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":113}],"gaps":[],"knownGaps":[{"id":"scheduled-api-shape-probe","ownerAgent":"cto","reason":"Checker still needs an API assertion for /api/scheduled/tasks gateway state and jobs array freshness.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"command_library","title":"Commands exposes the current operator command catalog","description":"Commands owns the durable operator command and tooling catalog after toolkit/reference/shortcut routes retire.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"commands: HTTP 200 (deployed)","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 113s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":113}],"gaps":[],"knownGaps":[{"id":"command-manifest-probe","ownerAgent":"cto","reason":"Checker still needs a command-manifest assertion proving nonempty commands and resolvable highlighted ids.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"personal_agents_runtime","title":"dvo and dvo-CFO use isolated deployed identities","description":"The deployed HTTP routes reject legacy credentials, cross-role access, and body overrides; a separate confirmed pinned-Telegram reply proves the dvo runtime path is actually operating.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"partial","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 1378309s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":1378309},{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 350486s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":350486}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_telegram_request_reply","title":"dvo answers pinned Telegram requests","description":"A pinned Telegram request produces a server-owned proof only after the bounded reply delivery is confirmed sent.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 350486s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":350486}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_personal_context","title":"dvo reads source-backed personal context","description":"A nonempty, source-backed personal-context read records a sanitized server-owned round-trip proof. The authenticated /personal home is the profile and memory surface for that same governed context.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 361378s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":361378}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_telegram_files","title":"dvo receives retained Telegram file context","description":"The deterministic proof verifies pinned Telegram ingress, retained nonempty attachment context, the exact backend-claimed Drive source, and confirmed reply delivery. It does not claim the model used the file semantically; V1 acceptance separately challenges a known fact from the file.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 3733115s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":3733115}],"gaps":[],"knownGaps":[{"id":"telegram-files-proven-by-use","ownerAgent":"dvo","reason":"Proof for this row is produced only when David actually uses the lane — there is no timer or synthetic exercise behind it. A red here can mean idle, not broken. The durable fix is a scheduled prober whose cadence matches the freshness window.","reviewAfter":"2026-09-25"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_google_read","title":"dvo automatically loads personal Gmail and both Calendar windows","description":"One sanitized aggregate receipt proves a pinned Telegram turn automatically loaded personal Gmail plus personal and work Calendar past/future windows, with every required section available or empty.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 3654838s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":3654838}],"gaps":[],"knownGaps":[{"id":"google-read-proven-by-use","ownerAgent":"dvo","reason":"Proof for this row is produced only when David actually uses the lane — there is no timer or synthetic exercise behind it. A red here can mean idle, not broken. The durable fix is a scheduled prober whose cadence matches the freshness window.","reviewAfter":"2026-09-25"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_google_draft","title":"dvo creates personal and work Google drafts","description":"Separate sanitized receipts prove successful real-adapter draft creation in both the personal and work Google accounts without treating a draft as a send.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 605579s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":605579},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 1366193s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":1366193}],"gaps":[],"knownGaps":[{"id":"google-draft-proven-by-use","ownerAgent":"dvo","reason":"Proof for this row is produced only when David actually uses the lane — there is no timer or synthetic exercise behind it. A red here can mean idle, not broken. The durable fix is a scheduled prober whose cadence matches the freshness window.","reviewAfter":"2026-09-25"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_google_send","title":"dvo sends through its bounded Workspace mailbox","description":"A sanitized proof is recorded only after the dedicated dvo Workspace sender persists a terminal sent job.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 614276s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":614276}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_reminders","title":"dvo delivers Calendar-backed reminders","description":"The reminder ledger proves a Calendar-backed reminder reached the pinned Telegram channel with deliveryState sent.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"pass","evidence":"last success 533092s ago","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":533092}],"gaps":[],"knownGaps":[{"id":"reminders-idle-not-broken","ownerAgent":"dvo","reason":"The check asserts a DELIVERED reminder, which only exists when one was due — a quiet week is healthy. The honest re-shape is a heartbeat on the every-minute scan loop; until that writer exists, red here means no delivery in 7 days, not a broken loop.","reviewAfter":"2026-09-25"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"cto_fleet_status_check","title":"CTO can answer fleet-status requests","description":"The Command Center agent lane records a completed cto_fleet_status_check run when the CTO worker answers a fleet-status query, proving the live worker loop.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 4753075s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":4753075}],"gaps":[],"knownGaps":[{"id":"fleet-status-proven-by-use","ownerAgent":"cto","reason":"The fleet-status run is written by an external runner with no in-repo schedule; its newest record is 53 days old. Red here is honest — the durable fix is a scheduled prober or retiring the row.","reviewAfter":"2026-09-25"},{"id":"cto-fleet-status-checker-deploy","ownerAgent":"cto","reason":"Not built until the Cloud Function checker deploys with command_center_agent_runs allowlisted and a real completed run exists.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"cia_strategic_advisory","title":"CIA Strategic Advisory","description":"David-facing high-level technology strategy and architecture advisory for the AI stack, agent fleet, model/provider choices, governance design, reliability, cost/risk tradeoffs, and best-practice recommendations, with narrowly scoped handoff channels to CTO and Parliamentarian. Excludes execution/deployment, secret management, arbitrary agent dispatch, broad agent-to-agent chat, raw RIA/client/private content access, proactive changelog spam, and live model-router behavior.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 3713225s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":3713225},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 5183175s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":5183175}],"gaps":[],"knownGaps":[{"id":"cia-self-certified-proof","ownerAgent":"cto","reason":"Both proof records are written by the SENDER inside the same request that posts the message, before any recipient could have read it. A freshness bound shortens that self-certification from 'forever' to the window; it does not end it. Fix: record the proof on the recipient-side read of agent_messages.","reviewAfter":"2026-09-25"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"parliamentarian_publication_verifier","title":"Parliamentarian publication verifier runs on schedule","description":"A deterministic, read-only verifier checks the publication manifest on a schedule and publishes only current execution health. Findings prove the audit ran; they do not grant Parliamentarian remediation, approval, publishing, model, or network authority.","surface":"command-center","ownerAgent":"cto","lifecycle":"active","status":"built","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"parliamentarian-publication-verifier-health: fresh 474s old with positive proofCount, workerEnabled, timerEnabled","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_sensitive_fill_request","title":"dvo requests task-specific sensitive fills","description":"dvo can request a single-purpose approval for high-risk identifiers without exposing raw secret values to chat, UI, prompts, or logs.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 5264540s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":5264540},{"kind":"tool_in_bundle","evidenceRole":"existence","result":"pass","evidence":"tool \"request_sensitive_fill\" present in deployed bundle","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"sensitive-fill-idle-not-broken","ownerAgent":"dvo","reason":"This capability is rare and safety-gated by design; a quiet month is correct behaviour. Red on this row means unproven-lately, not broken. A safe synthetic exercise in a test namespace (the check already asserts rawValueReturned=false and irreversibleActionApproved=false) is the durable fix.","reviewAfter":"2026-09-25"},{"id":"sensitive-fill-atomic-consume","ownerAgent":"cto","reason":"Capability remains not built until approvals atomically transition pending to consumed before any Secret Manager read.","reviewAfter":"2026-07-15"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_cfo_plaid_production_derived_sync","title":"dvo-CFO syncs Plaid production data into derived summaries","description":"dvo-CFO can create production Plaid Link sessions, exchange public tokens server-side, store Plaid access only in Secret Manager, verify production webhooks, and persist only derived finance snapshots for v1.","surface":"command-center","ownerAgent":"dvo-cfo","lifecycle":"active","status":"not-built","checks":[{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 4687016s ago — older than the 172800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":4687016},{"kind":"endpoint_live","evidenceRole":"existence","result":"pass","evidence":"plaid-prod-connections: HTTP 401 (deployed)","checkedAtMs":1788293169215}],"gaps":[],"knownGaps":[{"id":"plaid-derive-self-certified-proof","ownerAgent":"dvo-cfo","reason":"The derive pipeline records its own completion run. Bounded to two daily cycles, but still actor-written proof.","reviewAfter":"2026-09-25"}],"checkHealth":"ok","checkedAtMs":1788293169215},{"id":"dvo_cross_agent_finance_request","title":"dvo asks dvo-CFO for derived finance summaries","description":"A fresh dedicated deterministic dvo-CFO worker processes derived-only requests, and a pinned Telegram request received a confirmed reply after its correlated real derived-summary run completed. Acceptance separately challenges whether the answer is useful.","surface":"command-center","ownerAgent":"dvo","lifecycle":"active","status":"partial","checks":[{"kind":"public_json_artifact","evidenceRole":"functional","result":"pass","evidence":"dvo-cfo-derived-worker-health: fresh 55s old with positive workerRunning, workerEnabled, timerEnabled, pollHealthy, credentialIsolated, reportFresh","checkedAtMs":1788293169215},{"kind":"last_success_run","evidenceRole":"functional","result":"fail","evidence":"last success 1391788s ago — older than the 604800s freshness window","checkedAtMs":1788293169215,"lastSuccessAgeSeconds":1391788}],"gaps":[],"knownGaps":[],"checkHealth":"ok","checkedAtMs":1788293169215}],"generatedAtMs":1788293169215,"checkerVersion":"m2.5-personal-agent-proof-fields","registryVersion":"32bfb748b96fe96f","registryHealth":"ok","ageSeconds":1674,"stale":false,"thresholdSeconds":5400}