What happened: Work orders show assignment but no run or start proof.
Who it affects: Internal specialists on BuildCommand.
Proven so far: No BuildCommand feed is attached to Pulse.
Best guess, not proven: Feed was never authorized (known).
Still unknown: Real worker, run id and start timestamps.
This one cannot move without your approval.
Not flagged escalated. Hub case_escalated evidence appears on Support when observed.
Owner decision required. Pulse displays the gate; only the owner can decide it.
Atlas / Tower return contracts
- PARTIALatlas/api/public/support-snapshot
Read-only Support/Pulse snapshot for Atlas /api/atlas/pulse and /api/atlas/support adapters.
Consumer env: PULSE_SUPPORT_BASE_URL — Payload is code-ready on Pulse. Atlas LIVE-FEEDS-ATLAS-READ-001 wires live fetch when PULSE_SUPPORT_BASE_URL is set; honesty stays PARTIAL until Hub caller + durable store proven. No secrets in snapshot.
- PARTIALtower/support
Tower product handoff into Pulse support watch desk (customer-impact observe).
Consumer env: VITE_SUPPORT_URL — Tower already declares VITE_SUPPORT_URL. Point it at the Pulse origin + /support for watch. Canonical Support is OmniSupport Nexus — Pulse is not a second Support product. Missing URL stays setup-required — not Connected.
Snapshot: GET /api/public/support-snapshot
Outbound handoffs (Pulse → Atlas / Tower)
- MISSINGOpen Atlas
Setup required: set VITE_ATLAS_URL to an https URL.
VITE_ATLAS_URL not set — Atlas return deep-link unavailable.
- MISSINGOpen Tower
Setup required: set VITE_TOWER_URL to an https URL.
VITE_TOWER_URL not set — Tower product return deep-link unavailable. In-Pulse /control-tower still works.
In-Pulse Control Tower observe surface: /control-tower
Build / product repair hop
HMAC client posts to https://builder.kleinhubai.com/api/public/pulse/health-intake with header x-pulse-signature (sha256=). Shared secret PULSE_INTAKE_SIGNING_SECRET must be set on Pulse and App Builder. Pulse also needs APP_BUILDER_HOSPITAL_WORKSPACE_ID. Live hop remains NOT_CONNECTED until a signed intake is accepted. Pulse watch desks are not App Builder Hospital.
Mission Control / OmniSupport Nexus
Canonical Support is OmniSupport Nexus (Lovable 530988ff). Emit safe ops signals to Pulse POST /api/public/hooks/omnisupport-signal (Bearer PULSE_SUPPORT_SERVICE_TOKEN). Pulse /support is watch/impact only — not a second ticket DB. Not CONNECTED until live emit proven.
- Hub support evidence hop · PARTIAL · /api/public/hooks/hub-support-evidence
- OmniSupport operational signal intake · PARTIAL · /api/public/hooks/omnisupport-signal
- Tower support URL · PARTIAL · /support
- OmniSupport Nexus (Lovable) · MISSING
- Detect
- Triage
- Diagnose
- Guardian check
- Assign specialist
- Owner GO
- Repair
- Test
- Audit
- Guardian recheck
- Recovery watch
- Discharge
BuildCommand · Not connected · no timestamp · Unknown — Feed not attached.
- • Work orders show assignment but no run or start proof
- • No BuildCommand feed is attached to Pulse.
- • Feed was never authorized (known).
- • Real worker, run id and start timestamps.
customer Impact
None observed
data Risk
None observed
security Risk
None observed
revenue Impact
None observed
operational Impact
Dispatch cannot prove that assigned work actually started.
release Impact
None observed
blast Radius
Every work order
time Sensitivity
Normal
Affected users: Internal specialists
Affected systems: Response Dispatch
Rollback baseline: Not applicable
Audit verdict: Not applicable
Guardian recheck: Not required for a read-only feed.
Recovery watch: Not started
Discharge proof: None recorded
Authorize a read-only BuildCommand feed
Feed authorization exposes run and worker metadata to Pulse.
Protected area: provider authorization · Owner decision: Waiting
- • Owner authorization
- • Read-only scope confirmation
Pulse displays this gate. Only the owner can decide it, and only Guardian can clear it.
- 1. Owner authorizes read-only BuildCommand feed
No tests defined yet.
No work order has been written for this case.
- 2026-08-07T00:00:00ZCapability gap raised as a case.
Read-only view. Pulse never publishes, deploys, migrates or clears a Guardian gate.