| Title | Type | Status | Priority | Agent | Context | Answer | Client | Related Project | Related Task | CW Ticket | Plans | Agent Learnings | Source Computer | Agent Calibration Log | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| April sent sweep: SMARSH Professional Archive allowlist deadline is 2026-09-16 with no team confirmation | On 2026-09-14 Christi forwarded the Professional Archive firewall allowlist notice to help@crimsonit.com, Montira and Anton and asked the team to check it for the SMARSH clients, believed to be EAP and Belay. The vendor deadline in that notice is 2026-09-16. No reply or confirmation has landed in her mailbox. Flagging because the deadline is today. | — | Crimson IT | — | — | — | — | — | — | ||||||
| April sent sweep: Westwood Project Hub has no project record and no known CW ticket | Substantial Westwood Project Hub work was done and emailed on 2026-09-15: migration 005 applied to production, SQL admin group access granted to Evan Reiss, backup retention raised to 30 days, four Azure Monitor alert rules added, a 0.5 GB/day ingestion cap set, projecthub.westfin.com brought live, and the workstation firewall rule removed. There is no project record in OperatingSystem for it and no ConnectWise ticket or project number appears anywhere in the thread, so no CW note was posted. Proposing: create the project record, and confirm the CW ticket or project number so future sweeps can log notes against it. The calendar carries a synced entry named "Westwood Financial - vCIO Consult: Base44 to Azure App Migration and AI Governance (SOW scoping)", which suggests a ticket exists. | — | Westwood Financial | — | — | — | — | — | — | ||||||
| For Bestie #3: rebuild the Chip midday check as a desktop Task Scheduler job (spec: Routines-Planning.md item 5, STATUS.md 2c) | The noon Chip Midday Check email was a cloud routine under Christi other claude.ai login; she paused it 2026-09-15 because cloud routines cannot reach OperatingSystem. Rebuild on CHRISTI-DESKTOP: weekdays 12:00 PM PT, read OperatingSystem tasks + open_loops + Asana, write nothing to tasks, draft nothing to clients, one short HTML email to christi@crimsonit.com via Outlook COM. Also pending Christi go: purge 47 junk "Chip Midday Check <date>" task rows and delete the two 9/15 drafts (Barker/Julius, CareLogic). | Done by Bestie #3 on the desktop 2026-09-15: scheduled task "Chip - Midday Check" (noon, Live) reads OperatingSystem tasks + Asana, reports to the Calibration Log, never writes task rows; stale Barker and CareLogic drafts deleted. The 47 junk task rows were purged from the laptop on Christi go, same day. | Crimson IT | — | — | — | — | — | — | ||||||
| Dewey: 9/14 time posted - bandwidth ticket already existed (962284), no new ticket needed | Aprils queue item asking whether to create a CW ticket for the 9/14 SCHARP bandwidth upgrade approval can be closed - ticket 962284 (SCHARP HQ - Internet Bandwidth Upgrade, 2610 Industry Way) already existed and now has the 9/14 approval-thread time (53 min) logged against it. | — | — | — | — | — | — | — | — | ||||||
| April sent sweep: SCHARP bandwidth upgrade approved 9/14 - create task and CW ticket? | Dr. Barbour approved on 2026-09-14 ("Please proceed") raising SCHARP site circuits from 100 Mbps to at least 500 Mbps (about $200-$500/mo more per active site), HQ and Crenshaw first, then Vermont. Separately, Digital Realty sent the LAX11 200 Mb proposal ($900/mo) for signature on 9/14. No CW ticket number was found for either. Proposal: create a SCHARP task plus a CW ticket for the circuit orders and the LAX11 signature, and consider closing the older Peerless quote loops (57904114, 6819d6bd) since the quote is in. Existing task SCHARP-NET-001 got a dated note. | — | — | — | — | — | — | — | — | ||||||
| April sent sweep: Add Klapach & Klapach, P.C. to the clients table | Klapach & Klapach, P.C. (klapachlaw.com) is an active Crimson client (Claude Team, Copilot Business, CW tickets 973756 and 974346) but is not in the OperatingSystem clients table, so records are linked to Crimson IT for now. Note: some meeting loops spell the domain "klapachlaw.com"; the email domain is klapachlaw.com. | — | — | — | — | — | — | — | — | ||||||
| BAFMA distribution group address — confirm before MFA email send | Christi requested an MFA deadline email for SCHARP and BATHMA staff. Agnes interpreted BATHMA as BAFMA based on the known SCHARP/BAFMA sister-org relationship confirmed in SCHARP CLAUDE.md. Two things need Christi confirmation before send: (1) Is BAFMA correct, or is the org name something else? (2) What is the BAFMA all-staff distribution group email address? The Z_AllStaff group covers SCHARP. There may be a parallel BAFMA group, or BAFMA staff may already be on Z_AllStaff. Draft is at: C:\Users\ChristiBrown\OneDrive - Crimson IT\Documents\2 - Internal Operations\_agent-workspace\mfa-reminder-may15-DRAFT.md | — | SCHARP | — | — | — | — | — | MFA Reminder Email Draft (SCHARP + BAFMA, May 15 deadline) | ||||||
| Time logging 6/3: 3 entries posted, 2 transcripts need your routing call | Autonomous evening run (you were out). Pulled the 3 NEW 06-03 transcripts that landed ~4:30pm. Today's time now stands at 4 entries; 2 transcripts still need your decision. ALREADY LOGGED THIS AFTERNOON (with your approval): 1. Westwood Financial - vCIO consult (Brett Johnston, SVP Ops; Base44->Azure app migration) - tkt 948536, 31 min, NON-BILLABLE pre-sales. Ticket parked at 'Scope Needed' - you owe the SOW + AI readiness survey when back (~6/14-15). 2. Crimson Weekly All-Hands (Wk 23) - tkt 947371, 34 min, DoNotBill. LOGGED TONIGHT (autonomously): 3. Internal billing support - helped a Crimson admin diagnose a no-charge adjustment line on a managed client's invoice (Ms. Raahi onsite-hours commitment). NEW tkt 948543, 13 min, Crimson IT internal/DoNotBill. NOTE: start time was ESTIMATED (early afternoon ~1pm) - correct if you recall the real time. NOT LOGGED - need your routing call: 4. AbilityFirst finance / invoice-allocation & payroll-governance conversation with an AF leader (~18 min, a side-conversation you stepped out of a 2-hr meeting for). I did NOT auto-post: it was largely sensitive personnel/relationship discussion, not IT-deliverable work, and auto-billing AF at the CIO rate would likely be inaccurate. Your call: (a) log ~17 min to AF vCIO (board 80 / agmt 449) BILLABLE, (b) log DoNotBill for visibility only, or (c) don't log. 5. BAFMA AI Community of Practice (~2 hr external CIO peer group; guest speaker Aaron Kotick/Deal IQ on vendor negotiation; you were a participant). Not billable client/Crimson work - professional development. Did NOT log. Want PD time captured anywhere (e.g., Crimson internal DoNotBill) or leave it unlogged? Reply with your calls on 4 & 5 and I'll post them. All transcripts remain in the drop folder (none moved/processed beyond reading). | — | Ability FirstCrimson IT | — | — | — | — | — | — | ||||||
| PROPOSAL 2: Approval gate + idempotency keys + write-lock on ALL billable/PSA writes | Fixes: BAFMA/DTLA near-misbill + 7/16 concurrent-writer race. Change: (a) idempotency key per time entry (member+date+ticket+timeStart) checked against CW before POST - add to Dewey rules + skills; (b) single-writer lock via claiming the Airtable ledger row (status->Processing) before writing (lighter than the n8n Redis-lock template, which is the upgrade path); (c) content-based client verification before any billable write - attendee domains/entities must match the labeled client or the entry routes to an Outlook/Teams approval instead of auto-posting (n8n native HITL, verified in docs, ~May 2026 feature); (d) never two backfill writers on one date range. Effort M. Evidence: docs.n8n.io human-in-the-loop-for-tools; n8n.io/workflows/3976; buildmvpfast idempotency (2026-04). First step: approve and the rules go into Dewey playbook + skills today; n8n HITL flow built by Jerry this week. | APPROVED by Christi 7/16 (blanket). Rules live now: idempotency key + content-based client verification + single-writer ledger claim encoded in log-meeting-time skill and Agent Learnings recjClA4Npp8FsiRP (Approved, Critical, All agents). n8n HITL approval flow delegated to Jerry (Task recQktPBDqWkxxaeV, due 7/22). | — | — | — | — | — | — | — | ||||||
| BrightGauge datasource disconnected - needs reconnection | Alert email from BrightGauge at 5:37 AM: datasource disconnected from Crimson IT. Check which datasource and reconnect. Not urgent but will affect dashboards if left. | — | — | — | — | — | — | — | — | ||||||
| AdaptoSecret M3 kickoff: DECISION — CSP tightening parallel in M3 or defer to M4 | Flagged by Vector + Nigel during M3 kickoff team check (2026-04-22). Finding: next.config.ts line 25 currently has `'unsafe-inline' 'unsafe-eval'` in script-src. This contradicts the Security Controls & Threat Model (SOPs & KBs recPF4sMwvfURg2Aw) which specifies `script-src 'strict-dynamic' nonce-{random}; no unsafe-inline`. Not a blocker for M3 development. IS a launch blocker — CSP must be tightened before adaptosecret.com goes public. RISK OF DEFERRING TO M4: Tailwind 4 + hash-wasm lazy-loaded WASM + Next.js 16 runtime can all fight a strict nonce-based CSP in unexpected ways. Discovering breakage during M4 polish compresses the launch window. RECOMMENDATION (Vector + Nigel aligned): 2-3h parallel workstream during M3 to spike strict-dynamic + nonce CSP and validate hash-wasm loads cleanly. Owner: Nigel. Timing: during M3 downtime while Bruno/Stella iterate. DECISION NEEDED FROM CHRISTI: approve 2-3h M3 parallel CSP spike, or defer to M4 and accept late-discovery risk? Files involved: next.config.ts:25, package.json (hash-wasm 4.11.0 not yet added) | APPROVED 2026-04-22 (Christi): START NOW, front-loaded. 2-3h timebox held (actual: 2h, Nigel). IMPLEMENTATION COMPLETE 2026-04-22 (Nigel): Nonce-based CSP live on prod (dpl_GqxDMq7sxKjFzovBwbVToX6t8sRq). script-src 'strict-dynamic' + per-request nonce. Middleware-injected via src/middleware.ts. WASM FOLLOW-UP CLOSED 2026-04-23: When Stella wired the M3 passphrase create flow, hash-wasm WebAssembly.compile() was blocked by strict-dynamic — confirming Bruno's flagged risk. Fixed by adding `'wasm-unsafe-eval'` to script-src (commit f2caf72, deploy dpl_aWVWNLTsKo5MXz8CU5fT4uP8fMky). Verified working end-to-end on prod by Christi. Details and tradeoff analysis folded into Vector ack queue item recDyS1IPnC8yK0iP. TRADEOFFS ACCEPTED (awaiting Vector sign-off on SOP update): - style-src 'unsafe-inline' — Tailwind 4 runtime CSS injection - script-src 'wasm-unsafe-eval' — hash-wasm lazy-load for M3 Argon2id Both captured in recDyS1IPnC8yK0iP with alternatives-rejected reasoning. | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| AdaptoSecret: log rotation salt — Phase 2 tracker (NOT a launch blocker) | Hugo M4 Conditional Pass (2026-04-25) flagged this as a watch item, NOT a launch blocker. The static daily-rotation salt placeholder in src/lib/log.ts is currently used for both IP hashing and recordId hashing. Before Phase 2 (paid vault, persistent secrets, audit log), this should be replaced with a real rotating salt mechanism so audit-log entries cannot be cross-correlated by IP across long time windows. Tracking here so it does not get lost between Phase 1 close and Phase 2 kickoff. No action required for Phase 1 launch. | — | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| AdaptoExpenses: confirm positioning — IT-spend wedge + T&E-lite hybrid (vs original pure T&E) | The six-agent research sweep found classic T&E is a losing fight for software-only (Ramp/BILL give it away free via card interchange), while IT/SaaS spend tracking for 50-500-employee companies is an EMPTY price band ($0 lead-gen tools → $30k/yr Zylo/Vertice; they use spreadsheets) — and it sells to the same IT leader who buys AdaptoPolicy/AdaptoSecret. The plan (recSDblgPZ3Jscckf) leads with vendor registry + renewal radar + license waste, keeps expense capture + the mean-streak Auditor fully intact (the Auditor also bites subscriptions: unused seats, duplicate tools, renewal spikes). Your original 'agent with a mean streak' concept is preserved — research confirmed nobody in the market gives the audit AI a personality. Hugo W1: decide during M1 at the latest — landing copy, tier names, and marketing story all flow from this. Code is positioning-neutral through M2. Reply with: approve hybrid / revert to pure T&E / discuss. | ANSWERED by Christi's product vision message, 2026-08-09 (same day): contracts overview w/ 90/60/30 expiration alerts, per-contract contacts + support lines, contract file uploads, monthly costs, Hudu/ScalePad-style inventory (serials, warranties, selectable asset types), and budget forecasting. That IS the IT-ops direction — and goes further than the hybrid proposed here. Hugo delta gate confirmed: 'This is an IT-ops product that happens to include T&E.' Plan updated to v2 (143h, recSDblgPZ3Jscckf); T&E-lite retained as secondary scope and first cut line. | — | AdaptoHub: AdaptoExpenses | — | — | AdaptoExpenses — Product Plan | — | — | ||||||
| Mike Yasuma replied re: Brivo billing - needs your read | Mike Yasuma emailed at 7:05 AM: 'Re: Brivo Quote for SCHARP Industry Way - Billable project or nah?' You have an open draft reply to Mike about Brivo billing from yesterday. Read his response and decide on billing approach. | — | — | — | — | — | — | — | — | ||||||
| AdaptoSecret: root cause of 'Neon unreachable' ghost — DATABASE_URL missing on Vercel | Root cause identified and fixed 2026-04-22 during M3 kickoff check. BACKGROUND: Agent Queue recWkA6fPj8wHwj3e (2026-04-20) logged 'Neon DB unreachable — 5 tests blocked' during Margo's M2 QA. CURRENT-STATUS and Plan rec1mqhk9depLFAN8 recorded the issue as 'Resolved by reboot, verified via @neondatabase/serverless SELECT 1 -> {ok:1}'. That verification ran against LOCALHOST only. Vercel production was never actually fixed. EVIDENCE: Vercel runtime logs showed /api/cron/purge returning 500 every 15 minutes for 24h+ (through 2026-04-22 14:00:39). Production /api/health returned {status:degraded,db:disconnected}. Christi's browser POST today (14:07:47) got the generic 'Something went wrong creating your secret' because POST /api/secrets returned 500 from the generic catch. ACTUAL ROOT CAUSE: DATABASE_URL was missing from Vercel Production, Preview, AND Development env vars. Only DATABASE_URL_UNPOOLED was pushed 2d ago. The code at src/lib/db.ts:17 reads process.env.DATABASE_URL specifically, so getDb() threw 'DATABASE_URL is not configured' on every call. Every DB-touching route 500ed. FIX APPLIED 2026-04-22: - Added DATABASE_URL to Vercel Production (piped from .env.local, value length 150) - Redeployed to production (dpl_Cm8XBwz3gXetQkKpXtxPEgNWUn8Z) - Verified: https://adaptosecret.vercel.app/api/health returns 200 {status:ok,db:connected} STILL OUTSTANDING: 1. Preview and Development envs still missing DATABASE_URL. Vercel CLI `vercel env add DATABASE_URL preview --yes` was blocked by claude-code Vercel plugin requiring explicit user confirmation. Christi to complete via Dashboard or run the command on her own terminal. 2. NEXT_PUBLIC_SITE_URL is also missing across all three envs. Non-critical until M4 custom domain cutover. IMPLICATIONS: - M2 GREEN QA verdict was verified only on localhost + the subset of preview pages that don't hit the DB (landing, /about). The actual secret-sharing flow on Vercel has been broken since provisioning. - Purge cron missed ~96 runs over 24h. Data retention window slightly exceeded spec. No confidentiality impact (ciphertext unreadable without URL-fragment key). Next successful purge catches up. - Runbook (SOP rec8ec9hu8jGKqJ1h) needs update: post-deploy verification should hit /api/health on the target environment, not just localhost. | Fixed by adding DATABASE_URL to Vercel Production env (2026-04-22, piped from .env.local). Redeployed as dpl_Cm8XBwz3gXetQkKpXtxPEgNWUn8Z. Health endpoint verified 200 ok. DECISION 2026-04-22 (Christi): Dev-in-prod until adaptosecret.com custom domain cutover. Preview and Development env vars will NOT be backfilled. Rationale: site sits behind Vercel Deployment Protection with no public DNS, so 'prod' is effectively a protected preview for the team. Tighter feedback loop, no env-var drift between environments. Implication: Dependabot preview deploys will 500 on any DB-touching route (landing + /about still work). Do not use preview URLs for functional QA while dev-in-prod is in effect. Revisit at M4 domain cutover — Nigel will re-backfill Preview/Development env at that point. | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| Absolute: renewal was ~4/13/26, no Tommy follow-up - silent renew or lapse? | From SCHARP mailbox sweep 5/5/26. Tommy Pham at Absolute sent 30-day renewal reminder 3/14/26 saying renewal was 30 days out (so ~4/13/26). NO follow-up emails from Tommy after 3/14 in your mailbox. Discrepancy: Tommy quoted 300 licenses. Priority brief said 450 endpoints. Worth reconciling. Question: Did Absolute renew silently or lapse? Easy ping to Tommy (topham@absolute.com) to confirm. If renewed: capture term + cost for tracker. If lapsed: decide whether to skip (Crimson RMM may cover endpoint tracking). | Christi 2026-05-05: Absolute was NOT renewed - lapsed at ~4/13/26. No further action needed. Endpoint tracking will be covered by Crimson RMM. | SCHARP | — | SCHARP vendor contract investigation - mailbox sweep for [TBD] cells | — | — | — | — | ||||||
| Cotsen: Define cleanup scope boundary or it eats the 36h budget | Hugo's plan validation flagged that 'M365 cleanup' has no scope limit. Audit is defined, but cleanup (stale accounts? MFA? licenses?) is unbounded. Need a ceiling: define what cleanup is in-scope for Quote 7203 and what gets flagged as a separate engagement. Budget is 34-41h estimated against 36h. | Two-phase approach: Phase 1 (Quote 7203) = audit + report with findings and recommendations. Phase 2 (separate engagement/quote) = remediation based on report. Audit is read-only via app registration. Report feeds the May 15 board presentation. Remediation findings in the report naturally set up the follow-on engagement. | — | — | — | 930316 | — | — | — | ||||||
| WordPress MCP connection is broken — needed for AdaptoIT/MIL/Crimson blog posts | Tried to use the WordPress MCP (via n8n) to test pushing drafts — got 'fetch failed' on both Get_many_posts and WordPress_HTTP_Categories. The credential or workflow in n8n is likely expired or disconnected. Stuart (AdaptoIT blog), Bob (My Imperfect Life), Otto (Crimson IT) all need this to push drafts. ChoreSteps and Counted Doors use their own built-in blogs so they are unaffected. Likely fix: reconnect WordPress credential in n8n dashboard and re-activate the MCP trigger workflow. | — | — | — | — | — | — | — | — | ||||||
| Cotsen: Is the May 15 board report in-scope or a freebie? | Board progress report is on the timeline but NOT in the original 5 deliverables of Quote 7203. Hugo estimates 3-4 hours. On a 36h budget, that matters. Decide now: billable deliverable or relationship freebie? | In scope. The audit report IS the board deliverable. Not a separate document — the findings and recommendations report is what goes to the board on May 15. | — | — | — | 930316 | — | — | — | ||||||
| Product idea: Social media agent - draft-as-me with human approval, not auto-post | Christi is thinking about social media outreach strategy and considering building an app that lets her agents post as her on various social platforms. My honest take: auto-posting is the risky version. The AdaptoIT brand is built on her voice being unmistakably hers - an agent that gets one tone miss wrong across LinkedIn, X, Bluesky, Threads kills that brand faster than it builds audience. Safer product shape: agent DRAFTS posts in her voice from recent blog/activity/voice profile, queues them to a review dashboard (same rule as her email Drafts folder - never send without her eyes), one-click approve publishes via platform APIs. Analytics loop teaches the agent what lands. The draft quality is the product, not the scheduling - differentiator vs Buffer/Hootsuite/Typefully. This is AdaptoIT product territory. Could be its own SKU or a feature inside AdaptoInbox/AdaptoHub. Open questions for Warren and Segrid: (1) Standalone product or AdaptoHub feature? (2) Platform priority - LinkedIn and Bluesky are cheapest APIs to start, X is expensive, Threads has no official API yet, Instagram requires business verification (3) Voice profile training - how much content does the model need from Christi to draft convincingly in her voice? (Blog archive + email sample may be enough) (4) Liability model - if an auto-approved draft says something off, is that a brand issue only Christi eats, or a product feature she charges customers for knowing they accept the same risk? (5) Timing - defer until AdaptoInbox Starter/Pro is stable, or parallel track? | — | — | — | — | — | — | — | — | ||||||
| Waiting on Greg Hays (ADT) to send SCHARP access control quotes | 2026-04-22: SCHARP access control decision made — ADT wins over Hi-Tech Resources. Christi sent door counts to Greg Hays (702-289-6263) this morning via Gmail and will sign the quotes when they arrive. Open loop: Greg hasn't sent the quotes yet as of this morning's triage. If this queue item is still Open 3 business days from now (2026-04-27 Monday), nudge Greg — access control needs to move before any more Brivo panels age out. Dr. Barbour approved 4/21. Hi-Tech has been informed they didn't win. No Christi action needed unless Greg goes quiet past 4/27. | 2026-04-22: Greg's quotes arrived and Christi signed them. ADT access control engagement is locked in. No further action on this item. | — | — | — | — | — | — | — | ||||||
| AdaptoSecret M2 QA: log hygiene FAIL — secret IDs in plaintext logs | FAIL — HIGH severity. Finding: The structured logs include the full secret ID in the `recordId` field: {"level":"warn","recordId":"abc123def456789","ipHash":"52444f91","outcome":"not_found"...} Spec requires: no secret IDs, no ciphertext, no IPs in plaintext logs. IP is correctly hashed via ipHash, but recordId is logged in plaintext. Additionally, Next.js default access logs expose the full URL: `GET /api/secrets/abc123def456789 404 in 14.1s`. Reproduction: Run dev server, hit any secret endpoint, check server stdout. Recommendation: Hash recordId before logging (reuse the ipHash pattern). Consider suppressing or customizing Next.js access logs via middleware or log transport. Files involved: src/lib/log.ts, src/app/api/secrets/[id]/route.ts Must fix before production. Assign Bruno post-reboot. | Fixed by Bruno in commit 82555ce on 2026-04-20. src/lib/log.ts is now async and hashes recordId before emit (verified `recordIdHash:"6dec5490"` in logs where plaintext IDs used to appear). next.config.ts sets `logging.fetches.fullUrl: false` so Next.js access logs show `[id]` pattern instead of the raw ID segment. Margo re-verified with GREEN verdict. | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| Pick a short-term personal vault to bridge until AdaptoSecrets exists | You need a personal vault today to get the n8n API key and AdaptoIT WordPress MCP URL onto the other 3 computers safely. AdaptoSecrets is now a proposed project but won't be ready for months. Options: 1. **Bitwarden Free** - fastest, $0, CLI on every OS, shared personal vault works across all 4 machines. Set up in 10 minutes. Easiest to migrate off later. 2. **1Password Personal** - $3/mo, polished UI, CLI, nice family plan ($5/mo for 5 users). Better if you want to add family members to the vault. 3. **Encrypted file in OneDrive** - no subscription, you already have OneDrive syncing. Use age or gpg to encrypt a secrets file. Works but more fiddly, you manage key rotation manually. Recommend Bitwarden for the bridge - free, fast, CLI-friendly, easy to export when AdaptoSecrets ships. Migrate then. Which path do you want to take? | Let's hold off on this. I think I have an idea that might work but it needs to be a CLI so let me figure that out | — | — | — | — | — | — | — | ||||||
| PROPOSAL 4: Nightly reconciliation/verification agent + Close-Out Checklist table (exception-only oversight) | Fixes: 'Christi as the QA layer' - which research says cannot work (Microsoft Research 2026-02, arXiv 2602.16844: better review UIs made humans faster but NOT more accurate and MORE confident when wrong). Change: new Airtable Close-Out Checklist table with explicit rubric rows (day's time complete? every Plaude ledger row fully checked? every Completed task's alert sources closed? every client-ask captured to CW+Airtable?); ONE new agent (per Anthropic's verification-subagent pattern, 2026-01/2026-04) walks it nightly with mandatory-completion instructions ('you MUST check every row'), hard iteration cap, and reports EXCEPTIONS ONLY into the morning briefing, with drill-down links. Also starts accumulating per-agent error metrics to drive fleet consolidation (Anthropic: fewer, broader agents unless evidence justifies specialists). Effort M-L. First step: approve; checklist table + agent def drafted for Christi's review this week. | APPROVED by Christi 7/16 (blanket). BUILT: Close-Out Checklist table tblTqWg3m2Zc9zstS with 8 mandatory-instruction rubric rows (time integrity x2, meeting ledger x2, capture, alert hygiene, calendar, agent fleet); new agent VERA (vera.md) created - read-only verifier, exceptions-only reporting, hard iteration caps. REMAINING: schedule Vera's nightly run (Task Scheduler or post-sweep chain) + first supervised run for Christi to see the output format. | — | — | — | — | — | — | — | ||||||
| AdaptoExpenses: name the Auditor persona + confirm default intensity | The mean-streak Auditor is the brand differentiator and research says the character IS the marketing (Duolingo's Duo, Cleo's Roast Mode). Needs: (1) a name + character — a literal bulldog mascot fits the AdaptoIT minion-army style; (2) confirm intensity ladder naming: Watchdog (default) / Bulldog / Attack Dog; (3) tone ground rules are already in the plan — bites the expense never the person, questions not verdicts, clean reports fast-tracked silently, human always gets the last word. Tone review against ChoreSteps warmth principles happens pre-launch regardless. No blocker until M2 persona layer; naming earlier makes UI copy and landing page easier. | — | — | AdaptoHub: AdaptoExpenses | — | — | AdaptoExpenses — Product Plan | — | — | ||||||
| Weingart policies need tech stack corrections before sending remaining 21 | Jason Tucker feedback 4/8: 1. Sophos reference is wrong — Weingart migrated to Huntress. All 22 policies reference Sophos and need updating. 2. Sites count is 11 now, not 39. The old data was outdated. 3. Tonja's name was misspelled (corrected by Jason). 4. Jason is sending ONLY the Corporate IT Security Policy to Tonja for now. Remaining 21 policies will be sent after he reviews and confirms all data. Action: Before sending remaining policies, do a bulk find-and-replace across all .md and .docx files: Sophos → Huntress, 39 locations → 11 locations. Have Percy/Gus re-review after corrections. | — | — | — | — | — | — | — | — | ||||||
| AdaptoExpenses: purchase adaptoexpenses.com — $11.25/yr via Vercel | Verified available 2026-08-09 via Vercel domains: adaptoexpenses.com $11.25/yr (adaptoexpense.com singular also available at the same price if you want to defend it). Needed before M4 landing page / M5 DNS cutover — no rush today, but domains do get sniped. Purchase URL: https://vercel.com/domains/search?q=adaptoexpenses.com (Hugo W5). | — | — | AdaptoHub: AdaptoExpenses | — | — | AdaptoExpenses — Product Plan | — | — | ||||||
| Trellix lapses 8/1/26 - need EDR replacement plan (88 days) | From SCHARP mailbox sweep 5/5/26. You gave non-renewal notice 3/5/26. End date confirmed by Carahsoft as 8/1/26. That's 88 days from today. Need EDR replacement deployed and operational on the SCHARP fleet (~400 endpoints) before the lapse. Crimson stack option per M365 migration plan: Huntress. Alternative: Keep CrowdStrike as primary EDR (already deployed, ~450 endpoints per priority brief - Cody Gallizioli is the AM at CrowdStrike). Decision needed: Trellix replacement path + deployment timeline. Want a working session on this? | Christi 2026-05-05: Trellix non-renewal already decided, removal in progress. EDR replacement path established separately. Closing this queue item; tracking actual removal under SCHARP project work. | SCHARP | — | SCHARP vendor contract investigation - mailbox sweep for [TBD] cells | — | — | — | — | ||||||
| CybeReady is STILL ACTIVE through April 2026 - kill or keep? | From SCHARP mailbox sweep 5/5/26. Priority brief said CybeReady expired 10/2025 and asked us to confirm killed. Mailbox shows the OPPOSITE: CybeReady has been sending weekly engagement reports through April 2026 (2/22, 3/1, 3/8, 3/29, 4/5) plus campaign summaries (3/3, 4/6). Service is actively running. No renewal/billing emails in mailbox - billing channel unknown. Decision needed: (a) Keep - find contract terms, transition to Crimson SAT at next renewal (b) Kill - formal cancellation, replace with Crimson phishing platform when capacity allows The assumption that this was already killed has been baked into the transition plan. Want to revisit? | MYSTERY SOLVED via Lorenzo mailbox sweep 5/5/26: Lorenzo actually renewed CybeReady in Dec 2025 / Jan 2026 after months of suspension threats. So the 'expired 10/2025' assumption baked into the priority brief was wrong - the contract was reinstated by Lorenzo before he departed. Service IS active. Vendor contacts: Connor Wilkins, Shai Horstock. Decision still needed: keep + transition to Crimson SAT, or kill + replace. But the mystery of why it's still running is resolved. | SCHARP | — | SCHARP vendor contract investigation - mailbox sweep for [TBD] cells | — | — | — | — | ||||||
| PROPOSAL 5: Email capture that WRITES records (Thread-pattern, built cheaply in our stack) | Fixes: DTLA-style inbox death (flagged but never captured). April's rule 7e is the manual version; this automates it. Pattern proven by Thread (750+ MSPs, writes CW tickets w/ title/category/priority/type/time at claimed 96% - marketing number, capability verified in their implementation docs). Change: Outlook flag or forward-to-address -> n8n -> Claude classifies + drafts fields -> CW ticket/note POST + Airtable Tasks row in the SAME run; 'captured' = record exists, never 'flag set'. Buying Thread is the fallback if the homebuilt version underperforms. NOTE: QuickTix forward-to-ticket pattern was REFUTED in verification - do not adopt; Rewst/Pia/Moovila capture claims did not survive verification. Effort M (after Proposals 1-2 ship). First step: approve sequencing after 1-3; Jerry + April build. | APPROVED by Christi 7/16 (blanket). Sequenced after Proposals 1-3 per plan; delegated to Jerry + April (Task rectbqcDsRSn3avIL, due 7/28). April's manual rule 7e covers the gap until the automated flow ships. | — | — | — | — | — | — | — | ||||||
| Review 92 unclassified email contacts before Airtable import | April scanned 12 months of email and extracted 154 contacts. 62 are classified (45 client, 15 vendor, 1 personal, 1 spam). 92 are unclassified. Key reclassifications needed: Arc Capital (client), Karney karney.net (client), DTLA downtownla.com (client), DC Innovations (pentest vendor), Comdirect (AF vendor), Mobility Pros (prospect), Verizon Wireless (AF vendor). Also ~8 spam entries to remove. Full report at: 2 - Internal Operations/Knowledge Base/email-contact-extraction.md. Review and approve before bulk import to Contacts table. | — | — | — | — | — | — | — | — | ||||||
| AdaptoInbox Phase 2 & 3 need Plans before their start dates | You pre-approved all three AdaptoInbox phases. Beta has a full Plan record with scope, risks, milestones, and 225 budget hours. Phase 2 (starts Sep 1 2026) and Phase 3 (starts Jan 1 2027) are at Approved status but have no linked Plans yet — they will need budget hours, deliverables, risk assessment, and tech stack documentation before their start dates. Not urgent today. Recommend Segrid builds Plan records for each about 30 days before their respective start dates. | — | — | — | — | — | — | — | — | ||||||
| Mike Yasuma joined DTLA tabletop late, missed Crimson-voice intro — post-mortem worth doing | Mike Yasuma was the assigned Crimson 'voice' role in the 4/29 tabletop simulation (acting as the MSP responding to the client's incident calls) but joined after Christi's intro. He missed the framing. Worth a 5-minute walkthrough before the next tabletop so he's ready to play the role. Not blocking anything, just polish. | — | — | — | — | — | — | — | — | ||||||
| Revisit: n8n WordPress-to-LinkedIn automation when blog volume grows | Currently using WP LinkedIn Auto Publish plugin. When blog volume grows, build n8n workflow: WP publish webhook -> Claude caption generation -> LinkedIn personal + company page. FS Poster ($47 one-time) is backup option. Power Automate won't work (no personal profile support). Jerry would build the n8n flow. | — | — | — | — | — | — | — | — | ||||||
| Entrotech mobility audit needed - SCHARP (~700 lines) and AF (~200 lines) | From 04-21 mobility meeting. Entrotech needs 3 months invoices + device report from Verizon portals to complete no-cost audit. SCHARP presentation to leadership in ~2 weeks. Christi waiting on Verizon rep (on paternity leave, back next week) for portal access. AF on month-to-month with Verizon since Jan 2026. Entrotech rep will follow up in 1 week if no files received. | — | — | — | — | — | — | — | — | ||||||
| AdaptoInbox Chat Spec gate (recZTyCQQWMA4B8hA) — 2026-05-10 deadline LAPSED, decision needed | The Chat Spec Approved gate (task recZTyCQQWMA4B8hA in Plan recsyCdbfvBGy1pEn) is the Hugo-mandated Week 4 exit gate for the AdaptoInbox /api/chat backend build (P2-1 — the entire conversational onboarding differentiator). Hard deadline was 2026-05-10. That date passed today with no decision made and no spec written. Until this gate moves off Not Started, P2-1 work is blocked, which compounds against the Aug 15 beta onboarding target. Decision needed (one of): (a) Approve a Chat Spec — Christi writes or delegates the conversational onboarding spec, links it to the gate task, marks gate Approved. Unblocks /api/chat build in Week 5+. (b) Formally downscope the beta to default-categories-only (no chatbot training flow), update marketing/positioning, mark this gate as no-longer-applicable. Ships sooner but is not the product as currently marketed. Cascading dependencies if neither is decided this week: Stripe integration is fine to keep moving in parallel, but the differentiator ships late or not at all. Buffer in the plan (Aug 16-31) gets consumed. Context source: AdaptoInbox status briefing 2026-05-10. See Plan record Notes for full session handoff. | — | — | — | — | — | AdaptoInbox Beta Completion - Restart | — | — | ||||||
| AdaptoSecret M2 QA: Neon DB unreachable — 5 tests blocked | BLOCKED — HIGH severity (infrastructure). Finding: Neon Postgres endpoint ep-old-butterfly-akm9ptet-pooler.c-3.us-west-2.aws.neon.tech is unreachable from Christi's machine. Ping shows 100% packet loss. Stella also encountered this during M2 Frontend local testing. Tests blocked (all require DB): - MaxViews exhaustion (create with maxViews=2, consume twice, third should 404) - Expiry behavior (short expiry, wait, verify 404) - Purge correctness (consumed/expired >24h deleted, fresh preserved) - 404 indistinguishability (never-existed vs consumed vs expired = byte-identical) - Rate limit enforcement (inconclusive — Upstash round-trip latency prevented hitting 60/min threshold; rate limiter IS being called per response latency) Diagnosis options: 1. Neon free-tier auto-suspend (most likely — wakes on first real DB query, but Margo was testing health checks that may not touch the pooler) 2. Local network/DNS issue (planned reboot may resolve) 3. Neon outage (check status.neon.tech) Next steps post-reboot: 1. Wake Neon via simple query: `psql $DATABASE_URL -c 'SELECT 1'` 2. Re-launch Margo against running dev server to complete blocked tests 3. Hit Vercel preview deploy as alternative — preview environment connects to same DB but may surface different network path | Resolved by reboot on 2026-04-20. Post-reboot verification via @neondatabase/serverless: `SELECT 1` returned `{ok:1}`. Root cause was likely Neon free-tier auto-suspend combined with a local network path that only recovered after reboot (ping to the pooler host still 100% loss, which is expected — Neon poolers don't respond to ICMP, but TCP/TLS to 5432 works fine). Margo completed all 5 previously-blocked tests successfully. | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| AdaptoInbox Beta: end-of-session handoff 2026-04-13 | END-OF-SESSION HANDOFF. Pick up at start of next session. === WHERE WE ARE === Plan recsyCdbfvBGy1pEn Active (Hugo Conditional Pass). Project recHnJCYqKfc2qNRk. Repo C:\Users\Christi\OneDrive\Documents\adaptoinbox (not moved to 03_Projects yet). === WEEK 1 DONE === - Migration 003 run on prod Neon. last_polled_at column exists. Commit 8b35e20. - Cross-machine env pattern: Vercel env pull. .env.example updated, docs/ENV_SETUP.md new, CURRENT-STATUS.md updated. Commits fd51ff8, 2071b9f, 94a59f6, f56b6e8. === ONE ACTION FROM CHRISTI === Add ANTHROPIC_API_KEY to Vercel once: `cd adaptoinbox && vercel env add ANTHROPIC_API_KEY production`. Then every machine can `vercel env pull` to get .env.local. === NEXT (Week 2, Apr 20-26) === 1. Dashboard Accuracy metric (task recwkLEcoe3AyTi3E). Hugo watch item: define measurement window + sample size FIRST, then implement. 2. Account deletion (task recbh8e9tQCN73uai). OAuth revoke, GDPR cascade delete, confirm dialog, sign-out. === GATES === - Week 4 by 2026-05-10: Chat Spec Approved required before /api/chat build. Task recZTyCQQWMA4B8hA. - Before Week 3 Stripe: env pattern verified across 4 machines. === SESSION ALSO COMPLETED === - 10 AdaptoIT blog drafts regenerated and pushed to WordPress (WP 2591-2601) with meta descriptions and image prompts. - Dev discipline learning recgGWFrvd0u6dafP (Critical, All agents, Approved) enforces commit-per-milestone. - Stuart world-domination joke variation feedback saved. - AdaptoIT project folder audit: 5 products missing folders (AdaptoHub, AdaptoSecrets, AdaptoBriefing, AdaptoMeetings, Pipeline Dashboard). === KEY IDs === Plan recsyCdbfvBGy1pEn | Project recHnJCYqKfc2qNRk | Learning recgGWFrvd0u6dafP | — | — | AdaptoInbox: Beta Phase | — | — | — | — | — | ||||||
| Thu/Fri Cotsen schedule conflicts need resolution | Thursday 8AM-12PM Cotsen block overlaps Hudu work (8-9:30) and Chris 1:1 (9:30-10:30). Friday 1-4PM Cotsen overlaps Claire (1PM, personal - protected) and Quotes/ITG (2-4PM). Per schedule rules: Chris 1:1 is from someone else (don't move). Claire is personal (protect). Recommend: Thu Cotsen starts 10:30AM, Fri Cotsen starts 1:30PM around Claire. | — | — | — | — | — | — | — | — | ||||||
| AdaptoSecret M4: third-party security audit firm — decision needed before M4 close | Hugo's M4 Conditional Pass (2026-04-25) carries the third-party security audit firm question as a watch item. Decision must land before M4 closes, even if the call is 'not now.' ============================================= SEGRID AUDIT FIRM SHORTLIST — 2026-04-26 ============================================= NOTE: Segrid's web search was blocked this run. Shortlist is built from her existing knowledge of the security audit market. Christi should verify current pricing/availability before committing. 1. CURE53 (https://cure53.de) - Track: A (Phase 1 specialist) - Phase 1 cost: $8,000-12,000 - Phase 1 timeline: 3-4 weeks total (1 week prep, 1-2 weeks audit, 1 week report) - Relevance: Browser security and crypto audit specialists. Audited KeePassXC, ProtonMail, Bitwarden, numerous password managers and zero-knowledge tools. Perfect match for client-side crypto + CSP review. - Concern: Berlin-based, timezone coordination needed. No SOC 2 attestation capability — strictly code review shop. 2. TRAIL OF BITS (https://trailofbits.com) - Track: B (multi-phase relationship) - Phase 1 cost: $15,000-25,000 - Phase 1 timeline: 4-6 weeks - Relevance: Elite crypto and security engineering firm. Audited 1Password, Signal components, major DeFi protocols. Deep expertise in Argon2, AES-GCM, key derivation patterns. Can grow into SOC 2 advisory and formal verification work. - Concern: Expensive. May be overqualified for Phase 1 scope. 4-6 week lead time could push past launch window. 3. DOYENSEC (https://doyensec.com) - Track: A and B (hybrid fit) - Phase 1 cost: $10,000-15,000 - Phase 1 timeline: 4 weeks total - Relevance: Web application security specialists with strong Next.js/React experience. Founded by former WhiteHat Security researchers. Good balance of depth and accessibility. Can grow with you through Phase 2. - Concern: Less crypto-specific depth than Cure53 or Trail of Bits. May need supplemental crypto-focused review. 4. 7ASECURITY (https://7asecurity.com) - Track: A (budget-conscious Phase 1) - Phase 1 cost: $6,000-10,000 - Phase 1 timeline: 3-4 weeks - Relevance: Mobile and web app pentest specialists. Good track record with startups and smaller SaaS products. Published audits for multiple open-source security tools. - Concern: Less brand recognition than Cure53 or Trail of Bits. Finding letter may carry less weight with enterprise customers in Phase 4. 5. NCC GROUP (https://nccgroup.com) - Track: B (enterprise relationship) - Phase 1 cost: $18,000-30,000 - Phase 1 timeline: 6-8 weeks - Relevance: Full-service security consultancy with SOC 2, ISO 27001, and HIPAA attestation capabilities. Can serve as single vendor from code review through Type 2 attestation. Acquired iSEC Partners and Matasano — deep technical roots. - Concern: Enterprise sales cycle and pricing. Likely overkill and slow for Phase 1. Better entry point at Phase 2 or 4. ============================================= TRACK A RECOMMENDATION: Cure53 ============================================= Cure53 is the clear choice for Phase 1. Their specialization in browser security, client-side crypto, and zero-knowledge tooling directly matches AdaptoSecret's architecture. They've audited the exact category of product you're building (KeePassXC, Bitwarden, ProtonMail). Their finding letters carry significant weight in the security community. At $8-12K and 3-4 week turnaround, they fit the budget and timeline. The tradeoff is explicit: no SOC 2 capability, so Phase 2+ needs a different partner. ============================================= TRACK B RECOMMENDATION: Trail of Bits ============================================= If Christi wants one firm for the long haul, Trail of Bits is the premium choice. Their crypto expertise is unmatched, their reports are industry-standard references, and they can advise on the SOC 2 journey even if they don't perform attestation directly. The $15-25K Phase 1 cost buys context retention and relationship building. Use Phase 1 as the paid introduction, then expand scope in Phase 2. The concern is timeline — their lead time may not fit the 7-day M4 close target. ============================================= SEQUENCING RECOMMENDATION: Outreach starts NOW, parallel with M4 close ============================================= Do not wait for launch. Security audit firms book 2-4 weeks out. Send scoping emails to Cure53 and Trail of Bits this week with a target audit start of mid-May. This positions the audit to complete before Q3 launch marketing ramps. If Cure53 can start sooner, take Track A for Phase 1 speed. If Trail of Bits can match timing, consider Track B for relationship value. ============================================= DECISION PATH FOR CHRISTI ============================================= A. Cure53 (Track A): fast, cheaper, Phase 1 only. Different partner needed for SOC 2. B. Trail of Bits (Track B): premium, multi-phase relationship, possibly slower start. C. Run parallel intros to both, pick after first scoping calls. D. Defer entirely to Phase 1.5 (post-launch, pre-Phase-2) — explicitly chosen, not drift. E. Override: pick a firm not on the shortlist. | RESOLVED 2026-04-26 by Christi: third-party audit DEFERRED to Phase 1.5. Rationale: Phase 1 budget cannot absorb $8-25K audit cost. Hugo's M4 Conditional Pass explicitly allowed 'the decision must land before M4 closes, even if the call is not now' — this is a deliberate, documented 'not now' call, not drift. What this means: - Phase 1 launches WITHOUT a third-party audit finding letter. - /about page already frames third-party audit as a roadmap item, not a current state. No copy change needed. - Threat Model SOP recPF4sMwvfURg2Aw Section 12 (Audit Recommendation) and Compliance Mapping SOP recspej4D9C662db8 stay as the documented intent. - Decision revisits at Phase 1.5 entry (post-Phase-1 launch, pre-Phase-2 build). At that point: revenue picture should be clearer; audit cost may be amortizable across Phase 2 SOC 2 prep. What to track for Phase 1.5 entry: - Cure53 stays the Track A pick if Phase 1.5 audit goes ahead. - Trail of Bits stays the Track B pick if multi-phase relationship value justifies the premium. - Re-run pricing/availability check at Phase 1.5 entry (Segrid web search was blocked this round; pricing is rough estimate). Launch communication implication: do NOT claim or imply 'third-party audited' anywhere. Public copy stays accurate (zero-knowledge architecture documented and self-described, audit on the roadmap not the present). | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| AppRiver: overpaying 78% on CipherPost prepay base - right-size opportunity | From SCHARP mailbox sweep 5/5/26. Unilan invoices show: 2026 prepaid baseline is 255 CipherPost + 255 Archive users. March 2026 actual was 453 CipherPost (78% overage) + 325 Archive (27% overage). SCHARP is paying overage true-ups every month on top of an undersized prepay base. Right-size at next renewal to capture savings. Also: AppRiver is M2M with 60-day cancellation notice (per Stan Wong 2/25/26). Real annual cost lives in Invoice 129303.pdf (msg 19c783efea1e26b0) - download to capture the dollar amount. Replaced-by-M365 path: Exchange Online archiving + Defender for O365 replace AppRiver entirely. If migration timing aligns, give 60-day notice to terminate rather than right-size. | Christi 2026-05-05: Confirmed M2M status. Right-sizing vs. M365 termination path TBD - tied to migration timing. Keep visible until decision is paired with M365 migration plan. | SCHARP | — | SCHARP vendor contract investigation - mailbox sweep for [TBD] cells | — | — | — | — | ||||||
| DTLA Alliance — IR Plan + IT Policy is project-scope work, should be quoted not absorbed | On the 4/29 DTLA tabletop debrief Christi committed to (1) full rewrite of the Cybersecurity Incident Response Plan and (2) drafting a comprehensive IT policy. That is real project work, not tabletop wrap-up. The tabletop itself was scoped — these two deliverables were not. Decision needed: - Quote both as a project (sales gate, Hugo review) and route through Anzor/sales? OR - Absorb as part of relationship investment given Anzor said 'Awesome. This is a project. Thank you.' on 3/30 re: the broader Claude/SSO direction? Recommendation: quote it. Anzor's prior 'this is a project' comment was about a different work stream (Claude rollout). IR plan + IT policy is a separate scope. Hugo gate before Christi pushes draft. | For the Tabletop Debrief I don't think this is going to be a project. This just needs to be work. We need to take the information from the meeting that we had with them last week, build out the report, and update the incident response plan. Also he did send us information by email for the rest of the stuff we need | — | — | — | — | — | — | — | ||||||
| ACTION NEEDED: Import patched CalendarMirror workflow + run AF calendar cleanup | Jerry diagnosed CalendarMirror duplicates (2026-05-20). Root cause: Fetch Existing AF Mirror Events node used /me/events with extended property filter - Graph returns 0 results for this in delegated OAuth2 context, so every 20-min run creates fresh duplicates instead of recognizing existing ones. Fix applied to: n8n-calendar-mirror-workflow.json (line 71 - calendarView URL) Cleanup script: Cleanup-AF-CalendarMirror-Duplicates.ps1 (write-only, NOT run yet) Actions needed: 1. Import patched workflow JSON to adaptoit.app.n8n.cloud (replace existing CalendarMirror workflow) 2. Review Cleanup-AF-CalendarMirror-Duplicates.ps1 - confirm $TargetUserUPN is correct 3. Run cleanup script with -WhatIf first, review output, then re-run with -WhatIf:$false 4. Verify AF calendar looks clean after Both files in: 2 - Internal Operations/_agent-workspace/ | — | — | — | — | — | — | — | — | ||||||
| AdaptoSecret M2 QA: rate limit prefix mismatch on POST endpoint | CONCERN — MEDIUM severity. Finding: POST /api/secrets rate limiter uses prefix `adaptosecret:ratelimit` instead of the spec'd `rl:secret:write`. GET endpoint correctly uses `rl:secret:read`. Location: src/lib/ratelimit.ts line 33-37. Impact: Minor deviation from spec but could cause confusion during debugging or if rate limits need to be inspected/reset in Upstash. Functional behavior is unaffected. Recommendation: Change prefix to `rl:secret:write` for consistency with GET endpoint naming convention. One-line fix. Assign Bruno post-reboot. | Fixed by Bruno in commit 82555ce on 2026-04-20. src/lib/ratelimit.ts POST prefix changed from `adaptosecret:ratelimit` to `rl:secret:write`. GET prefix `rl:secret:read` was already correct. Margo confirmed Upstash key scan shows only `rl:secret:read:*` and `rl:secret:write:*` — old prefix is gone. | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| AdaptoPolicy: confirm document voice split (prose policies vs structured operational docs) | V1 had two contradictory prompt philosophies living side by side: a law-firm system prompt that BANS bullet points ('the output must look like it came from a law firm or Big 4 consulting engagement') and 3,164 lines of enhanced policy prompts built entirely from bullets and ✅/❌ emoji. Working default I've adopted for the rebuild (matches the 'reads like a law firm' marketing line and your Gus/Percy policy-writing conventions): • POLICIES → formal numbered prose, no bullets, no emoji, anti-AI-slop validator enforced (V1's orphaned validator, now actually wired in) • CHECKLISTS / GUIDES / RUNBOOKS / TABLETOPS → structured operational formatting (checkboxes, steps, warnings, facilitator scripts) — these are working documents, not governance prose • The enhanced prompts' CONTENT (MFA hierarchies, the ai_usage 3-tier AI approval model, tech-stack specificity) is kept and recast into the prose voice for policies. If you want bullets in policies too, or prose everywhere, flag it here before M2 closes — changing the voice after the smoke matrix runs means regenerating the golden files. | — | — | AdaptoHub: AdaptoPolicy | — | — | — | — | — | ||||||
| AdaptoIT blog batch: 10 drafts lost at context compaction | Before context compaction, Stuart had written ~10 AdaptoIT blog drafts in-session. 6 pushed to WordPress as drafts (IDs 2584-2589). 2 pushes hit fetch-failed errors (rec34nsmjiiEP56ry Power Automate Hidden Costs, recjft1ZX1rgiJzaA Claude Code Daily). 8 more were never pushed. Problem: Stuart's draft HTML was never saved to the Airtable Body HTML field. All 12 remaining Blog Pipeline records still show Status=Idea with empty Body HTML. Drafts lived in the prior conversation context and are now gone. Records affected (all AdaptoIT / Stuart): - rec34nsmjiiEP56ry Power Automate Premium Hidden Costs (WP push failed) - recjft1ZX1rgiJzaA Claude Code as Daily Work Partner (WP push failed) - rec0s1LwgpYeW0SX4 Meeting Transcript to CRM Pipeline (WP 2588, no Airtable body) - recEfaGjlvHW5LHjg One Line That Changed How My AI Thinks (WP 2589, no Airtable body) - recAzs02BhWTbYTqG GDPR Plugin Adoption - recMV3DZ8oMydCyQY ScalePad LMX - recn8l13DXuNsH1gO Token Economics 101 - recTwzyKdYpLHWa66 Workflows to Agentic AI - reco0cuS6J60e5Xme Plan First - recgdfS1YmEC5RC7p Automation Tool Costs Comparison - rec1OuR66hEnSbNoh Power Automate Licensing Changes - reczNK3MUsAfvOhx7 Nonprofit AI Plateau Already in WordPress (fine, but source text isn't in Airtable): 2584 Risk Labeling, 2585 Glasswing, 2586 Claude Cowork vs Copilot, 2587 n8n vs Power Automate, 2588 Meeting Transcript, 2589 One Line AI Thinks Options when you revisit: 1. Have Stuart regenerate all 10 drafts fresh, save Body HTML to Airtable first, then push to WP 2. Pull the 6 already-in-WP drafts back into Airtable Body HTML, only regenerate the 8 truly missing ones 3. Drop the backlog, keep only what's already live in WP, remove ideas from pipeline Recommendation: Option 2 is the least-waste path. Learning already saved: drafts must go in Airtable Body HTML before any WP push. | — | — | — | — | — | — | — | — | ||||||
| OperatingSystem: Migrate AdaptoHub/AdaptoInbox in same pass? | PROJECT: NEST App - Airtable Replacement Should AdaptoHub and AdaptoInbox migrate to the new NEST backend in the same project, or as separate follow-on projects? CONTEXT: - Both currently use Vercel + Airtable - They could share the new Postgres backend - Bundling them adds scope but creates a unified system - Separating them keeps this project focused but means more migration work later OPTIONS: 1. Same pass - migrate them during Phase 5 (Decommission) 2. Separate projects - NEST first, then Hub/Inbox after stabilization 3. Hybrid - migrate backend connections now, leave UI untouched RECOMMENDATION: Separate projects. NEST core should stabilize before adding Hub/Inbox complexity. Hub/Inbox are working fine on Airtable today. NOT BLOCKING: This decision can wait until Phase 4. | Not applicable, neither product uses Airtable | Crimson IT | — | — | — | OperatingSystem - Airtable Replacement (all bases) | — | — | ||||||
| NEST App: Keep the name NEST or rename? | PROJECT: NEST App - Airtable Replacement Is the app name "NEST" or should it be renamed? CONTEXT: - NEST is the Airtable base name (Christis acronym) - The new app could keep the same name or get a fresh identity - Repository will be created under TheOtherChrisBrown OPTIONS: 1. Keep NEST - continuity, agents already know the name 2. Rename - fresh start, avoid confusion with Airtable base during dual-write 3. Something like "NEST2" during transition, then back to NEST after decommission NOT BLOCKING: Just need to know before creating the GitHub repo. | OperatingSystem. Christi created the GitHub repo and is provisioning the Vercel project herself on 2026-09-02. Repository URL to be confirmed. | Crimson IT | — | — | — | OperatingSystem - Airtable Replacement (all bases) | — | — | ||||||
| TPx: Tracey Aziz waiting 5+ weeks for disconnect decisions + Account Summary xlsx ready to pull | From SCHARP mailbox sweep 5/5/26. GOLDMINE finding: Tracey Aziz at TPx sent a complete Account Summary 3/30/26 with ALL TPx contract end dates pre-summarized. Attachments to download (msg 19d402c505384a13): - Southern California Health & Rehabilitation Account Summary.xlsx - CSR.pdf (DIDs and virtual fax numbers) - Southern California Health & Rehabilitation Programs Proposal.xlsx (analog line conversion) Tracey has chased 3 times (3/30 -> 4/17 -> 4/20) for disconnect decisions. Crickets from our side for 5+ weeks. Action items: 1. Download the Account Summary xlsx 2. Drop dates into the vendor tracker [TBD] cells 3. Reply to Tracey with disconnect decisions (or 'still working through it' acknowledgment) Disconnect form for when ready: https://www.tpx.com/terms/notice-of-termination-form/ Want me to draft the reply to Tracey? | — | SCHARP | — | SCHARP vendor contract investigation - mailbox sweep for [TBD] cells | — | — | — | — | ||||||
| AdaptoSecret M4: Vercel deployment-protection removal sequencing — Nigel to investigate | Hugo flagged a watch item: the M4 PROPOSED scope does not specify when Vercel Deployment Protection comes off relative to DNS bind. Recommended sequencing: domain bind first, smoke test on the live domain WHILE deployment protection is still on, THEN remove protection. Need Nigel to confirm Vercel's actual behavior on custom-domain bind — does protection drop automatically when the domain attaches, or does it stay until manually removed in Project Settings? This affects when Margo can safely run the production smoke matrix without exposing the site publicly. Folded into Nigel's pre-DNS investigation scope (M4 kickoff 2026-04-26). | RESOLVED 2026-04-26 by Nigel investigation during M4 pre-DNS work. Finding: Vercel Deployment Protection does NOT automatically disable when a custom domain is bound. Protection persists across the domain bind and DNS cutover. It must be manually toggled in Project Settings > Deployment Protection. Sequencing for the smoke test: 1. Bind adaptosecret.com in Vercel dashboard (Domains > Add) 2. Add DNS records at registrar (A 76.76.21.21, CNAME www to cname.vercel-dns.com) 3. Wait for DNS propagation (verify with dig adaptosecret.com or browser) 4. Smoke test on adaptosecret.com WHILE deployment protection is still ON (Christi authenticates through Vercel SSO; site loads, Margo runs matrix) 5. Confirm production smoke green 6. Vercel > Project Settings > Deployment Protection > set Production to 'No protection' (or 'Standard Protection' which allows public access) 7. Confirm public-anonymous load works (incognito, no Vercel auth prompt) 8. THEN HSTS preload submission gate (48h domain stability after step 7, not after step 1) Confidence: high but not 100%. Nigel could not verify from Vercel rendered docs (heavy client-side JS). Christi can confirm in dashboard before flipping. If Vercel's behavior has changed since Nigel's knowledge cut-off, the only risk is that protection drops earlier than expected, which is recoverable (re-enable protection, finish smoke test). M4 plan updated to lock this sequencing as the authoritative deploy order. | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| Cotsen: Log pre-work hours or write them off? | December meeting (~1.5h), email correspondence (~1h), survey creation (~1h) are real hours not captured. Project shows 0.5h but significant pre-work was done. Log retroactively to know real remaining budget, or write off as pre-sales? | — | — | — | — | 930316 | — | — | — | ||||||
| PROPOSAL 1: Convert Plaude Meetings into the transcript processing LEDGER (status fields + ledger-driven sweep) | Fixes: routed-folder blindness + slept-scheduler misses (7/9-7/15 time gaps). Change: add Client link, Time Logged (CW#), CW Note (#), File Path, Status (Pending/Processing/Completed/Failed) to Plaude Meetings tblXvY6gHVF0cIbPl; rewrite log-meeting-time skill Step 1 to iterate ledger rows (last 14 days, Time Logged empty), folder glob demoted to safety net that only creates missing rows. Idempotent re-runs. Single-writer discipline (Airtable has no transactional locking). Effort S (half-day incl. backfilling July's 45 rows). Evidence: dqops.com file-ingest ledger pattern (2025-07); Airtable when-webhook-received trigger doc (2026-03). First step: Christi says GO and it ships before tonight's 8:30 sweep. | APPROVED by Christi 7/16 (blanket). BUILT same night: Meeting Type / Client / Time Logged / CW Note / File Path fields added to Plaude Meetings; all 45 July rows backfilled (typed + Processed + CW entry refs); log-meeting-time skill Step 1 rewritten ledger-first with folder glob demoted to safety net. Live for tonight's 8:30 PM sweep. | — | — | — | — | — | — | — | ||||||
| AdaptoExpenses HUGO COND 2: sequencing vs AdaptoPolicy — approve default or re-prioritize | Hugo's gate (Conditional Pass, 2026-08-09) requires an explicit capacity answer before AdaptoExpenses M1 starts: the 115h build runs ~13 weeks alongside AdaptoPolicy M1-M5 (80h, M1 active now), AdaptoSecret M4, and other open work. RECOMMENDED DEFAULT: AdaptoPolicy stays the primary build. AdaptoExpenses M0 scaffold (6h, positioning-neutral, Hugo says GO) may run on any credit-burn day. AdaptoExpenses M1+ starts only after AdaptoPolicy M2 closes — unless you re-prioritize. Reply with: approve default / AdaptoExpenses first / interleave both / other. | ANSWERED by Christi 2026-08-09: 'Start building it.' AdaptoExpenses builds now, alongside AdaptoPolicy beta. Hugo Cond 2 satisfied by owner directive. M0 closed green + M1 schema applied same session; M1 code is next. Capacity note stands: track actuals from M1 close (Hugo v2 watch), and AdaptoPolicy M4 + AdaptoExpenses M6 still share the Clerk provisioning dependency (rec05xr5qTkOop9S0). | — | AdaptoHub: AdaptoExpenses | — | — | AdaptoExpenses — Product Plan | — | — | ||||||
| AdaptoPolicy HUGO COND 1: rotate exposed V1 policygenerator keys + provide fresh ANTHROPIC_API_KEY | The old policygenerator working tree (OneDrive - AdapToIT\03_Projects\policygenerator) has .env.local and .env.vercel sitting on disk with LIVE Anthropic and Stripe keys, plus a deploy.zip. Hugo made rotation a hard condition: it must be DONE before AdaptoPolicy M1 makes its first live Anthropic/Stripe API call. What you need to do: 1. Anthropic console (console.anthropic.com → API Keys): revoke the key found in policygenerator/.env.local, create a fresh one named 'adaptopolicy', and drop it in the new repo's .env.local as ANTHROPIC_API_KEY (I'll have .env.example ready with the slot). 2. Stripe dashboard → Developers → API keys: roll the secret key that appears in those files. 3. Optional cleanup: delete .env.local/.env.vercel/deploy.zip from the policygenerator folder afterward. Build impact while this is open: M1 generation engine is being built fully env-gated — no V1 key is copied or referenced anywhere in the new repo — but live generation testing (the smoke matrix) is BLOCKED until the fresh key lands. Everything else proceeds. | — | — | AdaptoHub: AdaptoPolicy | — | — | — | — | — | ||||||
| AdaptoSecret CSP: Vector ack needed for 2 divergences (style-src 'unsafe-inline' + script-src 'wasm-unsafe-eval') | TWO accepted CSP divergences from Vector's published threat model (SOP recPF4sMwvfURg2Aw Section 7). Filed as one Vector review to avoid fragmentation. === DIVERGENCE 1: style-src 'unsafe-inline' === Shipped: `style-src 'self' 'unsafe-inline' https://fonts.googleapis.com` Spec: `style-src 'self'` (no unsafe-inline) ROOT CAUSE: Tailwind 4.2.2 uses `@theme inline` which injects CSS at runtime. Nonce-based style injection is not supported by Tailwind 4's architecture. TRADEOFF: CSS injection is meaningfully less exploitable than script injection. Script-src remains strict (strict-dynamic + nonce). Revisit at Tailwind 5 or migration to PostCSS-only static extraction. === DIVERGENCE 2: script-src 'wasm-unsafe-eval' (added 2026-04-23) === Shipped: `script-src 'strict-dynamic' 'nonce-{random}' 'wasm-unsafe-eval'` Spec: `script-src 'strict-dynamic' 'nonce-{random}'` (no wasm-unsafe-eval) ROOT CAUSE: Under strict-dynamic, browsers block `WebAssembly.compile()` / `WebAssembly.instantiate()` without explicit `'wasm-unsafe-eval'`. hash-wasm 4.11.0 lazy-loaded for M3 Argon2id passphrase KDF triggers this block. Symptom: M3 passphrase submit failed silently with generic UI error (confirmed 2026-04-23, fixed in commit f2caf72 + deploy dpl_aWVWNLTsKo5MXz8CU5fT4uP8fMky). TRADEOFF: 'wasm-unsafe-eval' permits WASM compile/instantiate but does NOT re-enable JS eval(). Browser support universal (Chrome 97+, Firefox 102+, Safari 15.4+). This is the least-permissive directive that allows hash-wasm to function under strict-dynamic. Alternatives rejected: - Falling back to 'unsafe-eval' would re-enable JS eval (major regression) - Moving Argon2id to server-side would break the zero-knowledge property (catastrophic) - Using a non-WASM pure-JS Argon2id library would balloon bundle size ~10x and run 50-100x slower === REQUEST FOR VECTOR === Review both tradeoffs and EITHER: (a) Sign off and update SOP recPF4sMwvfURg2Aw Section 7 to reflect the two accepted divergences with reasoning, so the threat model matches shipped reality. (b) Push back with an alternative implementation path within timebox. === LINKED === - Parent CSP resolution: recx0xjiV6r3afp6F (original nonce CSP work by Nigel) - Code locations: src/middleware.ts:29 (CSP header), src/lib/crypto.ts:58-64 (hash-wasm lazy import) - Live production deploy: dpl_aWVWNLTsKo5MXz8CU5fT4uP8fMky - Live CSP header verified via curl at 2026-04-23 14:24 | RESOLVED 2026-04-26 by Threat Model SOP recPF4sMwvfURg2Aw revision (M4 docs work). Section 7 of the Security Controls and Threat Model SOP now contains: - Updated 'Deployed Content-Security-Policy' block reflecting actual deployed shape (style-src 'self' 'unsafe-inline' https://fonts.googleapis.com + script-src 'strict-dynamic' 'wasm-unsafe-eval' 'nonce-{per-request}') - Section 7.1 Accepted CSP Divergence — style-src 'unsafe-inline' (Tailwind 4 root cause, risk-accepted under SOC 2 CC6, annual review trigger Tailwind 5 release) - Section 7.2 Accepted CSP Divergence — script-src 'wasm-unsafe-eval' (hash-wasm Argon2id root cause, risk-accepted under SOC 2 CC6, mitigations enumerated) - Section 7.3 Annual Review (next review 2027-04-26, owner Vector + Christi) Closure rationale: both divergences were accepted-in-practice during M3 but not formally documented. The threat model now reflects deployment reality and explicitly accepts each divergence with rationale, mitigations, and review triggers. | — | AdaptoHub: AdaptoSecret | — | — | AdaptoSecret — Product Plan | — | — | ||||||
| AF: 70.1h logged on wrong agreement (313 instead of 449) | Billing prep found 70.1h of Christi's time logged on Agreement 313 (Managed IT Premier) instead of 449 (vCIO Support). Mostly February (52.1h). This inflates helpdesk numbers and understates CIO hours. UPDATE 4/8: Michuan conversation no longer urgent but stays high priority. The 2025 discount is gone and Microsoft license costs increased. Budget was built on the old pricing. Bekker is pulling AF tenant licensing data to quantify the impact. | Old tickets prior to the agreeement being create4d. | — | — | — | 931598 | — | — | — | ||||||
| OperatingSystem: Auth method for UI login? | PROJECT: NEST App - Airtable Replacement What authentication mechanism should the NEST app use for Christi UI login? OPTIONS: 1. Vercel Auth with Google SSO - tight integration, matches your existing Google account 2. Simple password - lowest complexity, but less secure 3. Magic link (email) - secure, no password to remember 4. Other RECOMMENDATION: Google SSO via Vercel Auth. You already use Google, and this is Christi-only so no multi-user complexity. BLOCKING: Phase 2 (UI Build) needs this decision by Week 6. | Clerk | Crimson IT | — | — | — | OperatingSystem - Airtable Replacement (all bases) | — | — | ||||||
| SonicWall: support expired 3/17/26, no vendor reply - confirm disposition | From SCHARP mailbox sweep 5/5/26. You sent 'Support Renewal Quote Request - 6 Appliances, SCHARP' to hello@sonicwall.com on 3/10/26 (msg 19cda824d9915a33). Zero response from SonicWall in mailbox. Support contract expired 3/17/26 - that's 7 weeks ago today. Devices in scope: - 5x SonicWall TZ350 - 1x SonicWall TZ500 Either renewal happened off-platform (LT Tech / Armen / someone at Crimson) or 6 SCHARP firewalls are running unsupported. This is a HIPAA exposure if unrenewed. Decision needed: confirm renewal status. Options: (a) Renewed off-platform - track down the channel and document (b) Lapsed - decide to renew now, replace, or accept risk with mitigation SMA 410 VPN was NOT mentioned in your 3/10 email - separate verification needed. | Christi 2026-05-05: Approved Crimson replacement strategy. Created Task SCHARP-NET-008 to track the replacement initiative (6 SonicWall appliances, plus SMA 410 verification). Closing this queue item; tracking ongoing under SCHARP project work. Reminder: Vector's same-day security sweep flagged active CISA KEV exploitation against SMA 410 — emergency mitigation (disable SSL VPN) may be the highest-priority sub-step before the replacement project completes. | SCHARP | — | SCHARP vendor contract investigation - mailbox sweep for [TBD] cells | — | — | — | — | ||||||
| OperatingSystem: Which Postgres provider for dedicated database? | PROJECT: NEST App - Airtable Replacement Which Postgres provider for the dedicated NEST database? OPTIONS: 1. Vercel Postgres - tightest Vercel integration, native in dashboard, managed backups 2. Neon - generous free tier, serverless scaling, branching for dev environments 3. Supabase - includes auth/storage extras, open source, good docs 4. Railway - simple, pay-as-you-go, no cold starts 5. Other (PlanetScale moved away from MySQL, Turso is SQLite) RECOMMENDATION: Vercel Postgres or Neon. Vercel Postgres is simpler if you want everything in one place. Neon has better free tier and branching. COST CONTEXT: - Vercel Postgres Pro: ~/mo for basic usage - Neon: Free tier covers most hobby projects, then ~/mo BLOCKING: Phase 0 (Week 1) needs this to provision the database. | Neon. Database created 2026-09-02, DATABASE_URL already set in Vercel project. | Crimson IT | — | — | — | OperatingSystem - Airtable Replacement (all bases) | — | — | ||||||
| AdaptoHub: next module build order — recommend AdaptoKnowledge, need your scope sign-off | AdaptoPolicy is built through M3 (deploy live behind protection; M4 held on your two key items). You said today to work through the rest of the Adapto projects — but per your own NEST records, every remaining module is scope-TBD: AdaptoMeetings ('needs fresh scope review after AdaptoPolicy ships'), AdaptoExpenses (TBD, domain not purchased), AdaptoTraining (TBD, domain not purchased), AdaptoKnowledge (positioned but unscoped in detail). RECOMMENDATION: AdaptoKnowledge next. It's the only one with real positioning already decided (in-house IT knowledge base — runbooks, SOPs, institutional knowledge, NOT an MSP tool), the domain is owned (adaptoknowledge.com), it has a planning doc on the AdaptoHub Miro board, and it composes naturally with AdaptoPolicy (generated runbooks/SOPs need a place to live — cross-linking is already in AdaptoPolicy's Phase 2 list). What I need from you: (a) confirm AdaptoKnowledge is next (or pick another), and (b) 3-4 sentences on MVP scope — e.g. is it primarily storage/organization of docs (spaces, search, versioning) with AdaptoPolicy import, or does it also generate content? With that, I'll run the same pipeline as today: salvage/reference audit → Plan record → Hugo gate → build on the shared stack conventions. Also worth stating: same-day follow-through on your two AdaptoPolicy items (key rotation recF9vt3Evrb5u01N, Clerk rec05xr5qTkOop9S0) is what unblocks finishing AdaptoPolicy end-to-end — the 53-template smoke matrix is the only exit criterion I couldn't run. | — | — | AdaptoHub | — | — | — | — | — | ||||||
| Expand AdaptoIT Voice SOP from 2 modes to 6 - Stuart catalogued the full set | SOP recDyZdTlZqK105y8 currently documents 2 voice modes (incident satire, tutorial framework). Stuart's 4/13 catalog of 8 published adaptoit.com posts surfaced 6 distinct modes: 1. Personal narrative / day-in-the-life 2. Opinion / cautionary tale 3. Procedural playbook 4. Tutorial / how-to 5. Advisory / time-sensitive alert 6. Product field test / review Bestie #1 flagged this as the most important artifact of tonight's debate - every writing agent is currently working with incomplete info. When Christi has 20 min tomorrow, expand the SOP with all 6 modes + example post per mode + when to use each. Not a blocker for tonight's social media buildout. Tomorrow-Christi work. | — | — | — | — | — | — | — | — | ||||||
| STRATEGIC FLAG: AF Board moving to true cost model - ripples through every IT service line | Christi flagged on 2026-04-30: 'AF's board wants to go to true cost. You will read more in my meeting note, but this needs to be flagged.' CONTEXT: 'True cost' has been an AF operational push since at least 3/12/2026 (Cost Allocation Dashboard work was tied to it; Susanna/Kathy/Carl have been pushing). The BOARD now driving it = escalation from operational to governance level. That's the change. IMPLICATIONS for IT (preliminary, pending Christi's meeting note): - IT services likely need to be charged to programs at full loaded cost rather than subsidized from admin/grant - Cost Allocation Dashboard (currently in progress per AF-XX tasks) becomes mission-critical, not nice-to-have - Crimson IT billing structure with AF may need restructuring (per-program vs flat rate) - Program-level IT consumption reporting needs to exist - Agreement 449 (CIO) vs 313 (Managed IT) split may need program-level allocation logic added - Carl/CFO needs better cost visibility tooling, urgently WAITING ON: Christi's meeting note for the specific board decisions, timeline, and what she committed to. Once received, file as Knowledge Base entry and update AF roadmap accordingly. AGENTS TO LOOP IN: - Bekker: AF director, owns the IT health rollup - Rex: vCIO strategy and roadmap framing - Warren: business strategy implications for Crimson agreement structure - Tim: cost allocation data model in Airtable if we need to build reporting DO NOT touch the existing Cost Allocation Dashboard task without checking with Christi first - context may have shifted. | We don't have anything other than a statement that was in a meeting last week about it. We just need to be in the mindset of keeping this as a top-of-the-mind thing but we also need to work on the automation that I'm still working through | — | — | — | — | — | — | — | ||||||
| Design agent usage tracking system | Need a way to track when agents are used. Key questions for Tim/Segrid to plan: 1. What to track: agent name, task description, client/project, start/end time, token usage, duration 2. Where: new Airtable table? Log file? Both? 3. Billing tie-in: which agent runs are billable (client work) vs internal? 4. Credit tracking: monitor burn rate against the $200 expiring 4/15 5. ROI analysis: which agents produce the most value vs cost? 6. Should agents self-report (log their own usage) or should we instrument it centrally? 7. How does this connect to CW time entries? Agent time ≠ human time per Dewey's rules. Today's session alone has had 20+ agent invocations across 15+ different agents. That's data we're losing. | — | — | — | — | — | — | — | — | ||||||
| DTLA Alliance / Downtown Center BID missing from Clients table | Active client engagement (CW company 'Downtown Center BID', tickets visible in Outlook back to mid-2025) but no record in Airtable Clients table. Active 4/29 tabletop, ongoing IR plan + IT policy work, Mike Yasuma as account manager, Kevin Thomas + Michael Ashkenasi + Suzanne as stakeholders. Should be created. Action items just landed in Tasks table without client link as a result. | — | — | — | — | — | — | — | — | ||||||
| SENSITIVE: Edward ex-employee harassment escalating - needs decision on cease and desist | From 04-09 call between Christi and Pete. Edward (ex-employee on disability/workers comp) sending harassment emails, BCC-ing staff including Christi. His own lawyer dropped him for harassment. Anzor keeps delaying cease and desist action. Pete strongly urging legal action. Risk: potential client communications damage if Edward contacts clients. Pete suggested blocking his emails to everyone except Pete and Anzor. Christi ready to pursue legal action if given authority. | We can ignore this one and mark it as completed. There's nothing left to do in this. I just need to keep an eye out in case he sends me another email | — | — | — | — | — | — | — | ||||||
| CGM ELVI MFA enrollment not working on Christi's account | 2026-04-22: Christi has her CGM ELVI authorized-contact account working enough to operate (has the info she needs). However, MFA enrollment on her account is not completing successfully. Unclear whether this is a browser/TOTP app issue, a CGM-side config issue, or something in the ELVI portal that needs CGM Support intervention. Short-term: not a blocker. She has what she needs to authorize adds/removes. Follow-up path when Christi has a moment: 1. Try a second browser / clear cache to rule out a local issue 2. If still broken, open a ticket to support@ais-us.cgm.com subject 'MFA enrollment failing' with screenshot of the error 3. CC Holly Kitson <holly.kitson@cgm.com> for account-rep awareness Don't let this fester — any CGM policy change that requires MFA will lock her out if it's not working. Revisit by EOD Friday 2026-04-25 if not resolved. | — | — | — | — | — | — | — | — | ||||||
| Enable MCP access on 2 n8n workflows to restore WordPress MCP (1-min click) | Jerry diagnosed, Bestie2 executed. Root cause found. === WHAT WAS BROKEN === The WordPress MCP tools that dropped mid-session correspond to n8n workflows with MCP access disabled in their workflow settings. API calls to publish them fail with 'Workflow is not available in MCP. Enable MCP access in workflow settings.' === WORKFLOW STATE === 1. [MCP] AdaptoIT Wordpress (id: LvwSimuuo3Uxp47s) — active: true, availableInMCP: FALSE ← Stuart's tool, needs toggle ON 2. [Blog] SharePoint to WordPress (My Imperfect Life) - v1 (id: SCAPGJatPlBDpTvO) — active: false, availableInMCP: FALSE ← Bob's tool, needs activate + MCP toggle 3. [Blog] SharePoint to WordPress - v1 (id: eM0HKCfKGtUGG0vt) — active: true, availableInMCP: TRUE — this one is fine === CHRISTI 1-MINUTE ACTION === 1. Open https://adaptoit.app.n8n.cloud (or wherever the n8n is hosted) 2. Workflow: [MCP] AdaptoIT Wordpress → Settings → toggle 'MCP access' ON → Save 3. Workflow: [Blog] SharePoint to WordPress (My Imperfect Life) - v1 → Activate (it's currently inactive) + Settings → toggle 'MCP access' ON → Save 4. Ping back — I'll test immediately and confirm Stuart and Bob can push drafts === WHY API COULDN'T DO IT === n8n MCP access is a per-workflow security setting. It must be enabled in the n8n UI before the API will expose the workflow to MCP consumers. Bestie2 cannot toggle it from the MCP side — the MCP server itself doesn't see the workflow until the setting is on. Jerry's App Password diagnostics are a good fallback if the toggle alone doesn't fix it, but try the toggle first. | For the blog SharePoint to WordPress for My Imperfect Life, it has invalid credentials. It's also set up for Supabase even though we moved to a different type of database so this one is going to need to be rewritten | — | — | — | — | — | — | — | ||||||
| Draft OneCause technical analysis that trains Darnell and builds Jeremy's trust | Jeremy Sidell (CDO) asked Christi to get involved in OneCause-Salesforce integration. Michuan signed off. This is NOT about the technical work itself — it's about: 1. Building relationship capital with Jeremy (he thinks SMB, Christi is training him to think enterprise) 2. Building up Darnell as the internal Salesforce owner 3. Providing a technical analysis that demonstrates CIO value while positioning Darnell as the long-term owner Don't bill these hours (eat into budget as relationship investment). Frame the analysis as: here's what needs to happen, here's who should own each piece, here's how Darnell can grow into this. Make Jeremy feel heard while steering him toward enterprise thinking. Commitment: analysis by EOD 4/8. Use the OneCause transcript and Bekker's assessment as source material. | I sent an email to Jeremy two or three weeks ago and he has not gotten back to me on it | — | — | — | 918757 | — | — | — | ||||||
| PROPOSAL 3: Event-driven completion propagation via ConnectWise callbacks -> n8n (kill stale alerts at the source) | Fixes: Meraki-style stale alerts (work done, alerts kept firing). Change: install @adamhancock/n8n-nodes-msp-ai (real CW /system/callbacks webhooks - verified in source, no polling; pin v0.1.18); on ticket->Completed, n8n auto-closes the matching Airtable Task, deletes calendar reminder blocks, marks Asana. Segrid's scheduled reconciliation pass STAYS as the safety net (community 0.1.x package, single maintainer). Effort M (Jerry: one n8n workflow + callback registration). Evidence: github.com/adamhancock/n8n-nodes-msp-ai (2025-11). First step: approve; Jerry installs on adaptoit n8n cloud and wires ticket-status->Task-close first. | APPROVED by Christi 7/16 (blanket). Delegated to Jerry: install @adamhancock/n8n-nodes-msp-ai pinned v0.1.18, wire ticket-Completed callback to Airtable Task close + calendar cleanup (Task recBHnjDwF2ZaRnHu, due 7/23). Segrid scheduled reconciliation stays as safety net. | — | — | — | — | — | — | — | ||||||
| Clean up unused Source Computer options on Agent Queue field | The Source Computer singleSelect field on the Agent Queue table (field ID fld3Wsd1Cz0TCqAGh) has six leftover options from the initial build: Home, Pasadena, DTLA, Laptop, Mobile, Unknown. None of them are in use anymore — all queue records have been migrated to the new canonical names. The API cannot delete singleSelect options, so this needs to be done manually in the Airtable UI. To clean up: 1. Open NEST base 2. Open Agent Queue table 3. Click the Source Computer field header 4. Choose 'Customize field type' 5. Delete these six options: Home, Pasadena, DTLA, Laptop, Mobile, Unknown 6. Leave only: Work - Desktop, Work - Laptop, Home - Desktop, Home - Laptop Low priority — the extras do not break anything, they just clutter the dropdown. | — | — | — | — | — | — | — | — | ||||||
| Build Airtable Agent Operations Dashboard — Omni was buggy 5/5, retry | Christi tried 3 different ways to get Omni to build the dashboard on 5/5/26 — Omni kept erroring out (likely Airtable-side outage). The Omni prompt is ready and the Calibration Log already has 28 entries from today plus ongoing entries. When ready, two paths: (a) Retry Omni in NEST base (appYVXneddw1eKZEu) with the prompt parent saved to chat history (b) Manual Interface build — parent has the click-by-click walkthrough ready (c) Quick fallback: 4-5 saved Views in Calibration Log table (Today, Pending Review, By Agent, By Client) gets 80% of the value in 5 min No deadline, but Christi wants visibility into agent outputs going forward. | — | — | — | — | — | — | — | — | ||||||
| Tim's 11 remaining computed fields need to be added to Projects table manually | The Airtable API cannot create formula, rollup, or count field types — only basic types. I created PendingDecisionFrom (singleSelect) via API. The other 11 fields Tim recommended (BudgetPercent, BudgetStatus, HoursRemaining, DaysUntilDeadline, DeadlineStatus, DeadlineConflict, DaysSinceLastActivity, LastTaskUpdate rollup, TaskCount, OpenTaskCount, CompletedTaskCount) must be created manually in the Airtable UI. Formulas were provided earlier and are saved in the ChoreSteps Code Review Fixes project notes. These power the views Tim recommended (Budget Watch, Stalled Projects, Red/Yellow Watch). Low urgency — pipeline works without them, they just enable richer dashboarding. | — | — | — | — | — | — | — | — | ||||||
| AdaptoInbox chat training backend is the main beta gap | AdaptoInbox codebase is ~70% built — database layer, auth (Google + Microsoft), email pipeline, cron endpoint, OAuth flows, dashboard/followups/settings all wired to real data. The main remaining gap for beta launch is the chat training backend. UI at /chat exists but no API endpoint. Need: /api/chat route that sends messages to Claude, extracts structured rules from conversation, saves to user_rules table, stores chat history in chat_sessions table. Want me to spin up Mark (AdaptoInbox dev agent) to start on this, or do you want to tackle it yourself? | — | — | AdaptoInbox: Beta Phase | — | — | — | — | — | ||||||
| Set Clerk admin role on your user for ChoreSteps/Counted Doors | The /admin routes on ChoreSteps and Counted Doors are gated on Clerk publicMetadata.role === 'admin'. Your user (christibrown252@gmail.com or outlook) needs this set before you can access /admin/blog to preview and publish the 12 scheduled posts. Go to clerk.com → select the app → Users → find your user → Public metadata → add {"role": "admin"} → Save. Once that is set, /admin/blog will show all drafts. Same process on both ChoreSteps and Counted Doors Clerk instances if they are separate. | Done | — | Counted Doors Code Review FixesChoreSteps Code Review Fixes | — | — | — | — | — | ||||||
| AdaptoPolicy HUGO COND 2: Clerk instance — create AdaptoHub shared app or approve deferral | The AdaptoHub platform design calls for a single shared Clerk instance across all module domains. For AdaptoPolicy M2 (UI milestone, 28h), Hugo requires an answer before M2 starts: (a) the Clerk instance exists and keys are available, or (b) Clerk UI wiring is deferred to M3/M4 with rebalanced hours. Since you're not in the loop mid-build, I've taken option (b) as the working default: M2 builds against an env-gated auth abstraction (src/lib/auth.ts) with a dev-mode bypass, so every screen works locally; real Clerk components get wired the moment keys exist. What you need to do (whenever convenient, before launch): clerk.com → Create application 'AdaptoHub' → enable email + Google → copy NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY and CLERK_SECRET_KEY into adaptopolicy/.env.local and the Vercel project env. If you'd rather AdaptoPolicy get its own Clerk app instead of the shared AdaptoHub one, say so here — that's a platform architecture call I don't want to make unilaterally. | DECIDED 2026-08-09: Christi purchased a Clerk monthly subscription — Hugo Condition 2 resolved as option (a). Full Clerk integration is now wired and deployed (env-gated): middleware protection, sign-in/sign-up pages, UserButton, CSP updates, auth seam. The ONLY remaining step is Christi's: dashboard.clerk.com → Create application 'AdaptoHub' (shared instance per platform architecture — AdaptoInbox stays on its own NextAuth, it's a sibling product not a module) → enable email + Google → copy NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY and CLERK_SECRET_KEY into adaptopolicy/.env.local AND the Vercel adaptopolicy project env (Production), then redeploy. The app switches from dev bypass to real auth automatically when both keys are present. Reminder for that moment: REMOVE AUTH_DEV_BYPASS from Vercel Production (M4 checklist item), and reassign any dev-created documents from 'dev_local_user' to the real Clerk user id in adaptopolicy.documents if worth keeping. | — | AdaptoHub: AdaptoPolicy | — | — | — | — | — |
1 to 75 of 75