What happened: Guardian gate reported RED.
Who it affects: Unknown — no exposure has been confirmed. on KleinHub AI.
Proven so far: Snapshot records the HUB-RLS gate as RED.
Best guess, not proven: Policy definition drifted from the reviewed baseline (suspected, unverified).
Still unknown: Whether any tenant data was actually reachable across boundaries.
This one cannot move without your approval.
Not flagged escalated. Hub case_escalated evidence appears on Support when observed.
Owner decision required. Pulse displays the gate; only the owner can decide it.
Atlas / Tower return contracts
- PARTIALatlas/api/public/support-snapshot
Read-only Support/Pulse snapshot for Atlas /api/atlas/pulse and /api/atlas/support adapters.
Consumer env: PULSE_SUPPORT_BASE_URL — Payload is code-ready on Pulse. Atlas LIVE-FEEDS-ATLAS-READ-001 wires live fetch when PULSE_SUPPORT_BASE_URL is set; honesty stays PARTIAL until Hub caller + durable store proven. No secrets in snapshot.
- PARTIALtower/support
Tower product handoff into Pulse support watch desk (customer-impact observe).
Consumer env: VITE_SUPPORT_URL — Tower already declares VITE_SUPPORT_URL. Point it at the Pulse origin + /support for watch. Canonical Support is OmniSupport Nexus — Pulse is not a second Support product. Missing URL stays setup-required — not Connected.
Snapshot: GET /api/public/support-snapshot
Outbound handoffs (Pulse → Atlas / Tower)
- MISSINGOpen Atlas
Setup required: set VITE_ATLAS_URL to an https URL.
VITE_ATLAS_URL not set — Atlas return deep-link unavailable.
- MISSINGOpen Tower
Setup required: set VITE_TOWER_URL to an https URL.
VITE_TOWER_URL not set — Tower product return deep-link unavailable. In-Pulse /control-tower still works.
In-Pulse Control Tower observe surface: /control-tower
Build / product repair hop
HMAC client posts to https://builder.kleinhubai.com/api/public/pulse/health-intake with header x-pulse-signature (sha256=). Shared secret PULSE_INTAKE_SIGNING_SECRET must be set on Pulse and App Builder. Pulse also needs APP_BUILDER_HOSPITAL_WORKSPACE_ID. Live hop remains NOT_CONNECTED until a signed intake is accepted. Pulse watch desks are not App Builder Hospital.
Mission Control / OmniSupport Nexus
Canonical Support is OmniSupport Nexus (Lovable 530988ff). Emit safe ops signals to Pulse POST /api/public/hooks/omnisupport-signal (Bearer PULSE_SUPPORT_SERVICE_TOKEN). Pulse /support is watch/impact only — not a second ticket DB. Not CONNECTED until live emit proven.
- Hub support evidence hop · PARTIAL · /api/public/hooks/hub-support-evidence
- OmniSupport operational signal intake · PARTIAL · /api/public/hooks/omnisupport-signal
- Tower support URL · PARTIAL · /support
- OmniSupport Nexus (Lovable) · MISSING
- Detect
- Triage
- Diagnose
- Guardian check
- Assign specialist
- Owner GO
- Repair
- Test
- Audit
- Guardian recheck
- Recovery watch
- Discharge
Pulse snapshot · HUB-RLS gate · Recent · 2026-08-06 17:30 UTC · Known
- • Guardian gate reported RED
- • Release readiness marked conditional
- • Snapshot records the HUB-RLS gate as RED.
- • Production remains at Lovable commit 9da5e27.
- • Policy definition drifted from the reviewed baseline (suspected, unverified).
- • Whether any tenant data was actually reachable across boundaries.
- • Whether the drift originated in a migration or a manual change.
customer Impact
No confirmed customer impact; risk is to data boundaries.
data Risk
Tenant data separation cannot be proven while the gate is RED.
security Risk
Row-level security policy unverified.
revenue Impact
None observed
operational Impact
None observed
release Impact
Blocks further hub releases.
blast Radius
All hub tenants
time Sensitivity
High — gate has been open across two snapshots.
Affected users: Unknown — no exposure has been confirmed.
Affected systems: KleinHub AI hub database, Hub authentication
Rollback baseline: Lovable commit 9da5e27
Audit verdict: Conditional — cannot close while the gate is RED.
Guardian recheck: Required after any policy change.
Recovery watch: Not started
Discharge proof: None recorded
Change row-level security policy on the KleinHub AI hub database
An incorrect policy can expose one tenant's data to another, or lock every user out of the hub.
Protected area: RLS · Owner decision: Waiting
- • Current policy definition for each affected table
- • Proposed policy diff
- • Tenant isolation test results before and after
- • Rollback statement
Pulse displays this gate. Only the owner can decide it, and only Guardian can clear it.
- 1. Export current policy definitions
- 2. Compare against reviewed baseline
- 3. Prepare policy diff for Guardian
- 4. Run tenant isolation tests
- NOT RUNTenant isolation suitenot run
mightyprophets-rgb/kleinhubai-48a0f586 · specialist/hub-rls-review · first command pnpm run policy:export
Start proof: none — assignment only, no proven start
- 2026-08-05T13:05:12ZGate reported RED in health registry.
- 2026-08-06T17:30:00ZStill RED at snapshot refresh.
Read-only view. Pulse never publishes, deploys, migrates or clears a Guardian gate.