Who may take what right now, derived from agent_ops.slug_resources joined against live leases. The rule: two slugs that map to the same repo or the same Supabase ref are the same work, whatever the board calls them.
| Slug | Actor | Expires | Resources |
|---|---|---|---|
cipherdeck-apps | 1099:openai-chatgpt-7f3a | 2026-08-13 02:41Z | jbnx/cipherdeck-apps, jbnx/cipherdeck-shopify, supabase xrlpdsovirwluwhemuwf |
projects-portal | 1099:sched-resume-9k2f | 2026-08-12 22:41Z | jbnx/jbnx.io (rootDir projects-portal/), railway projects, supabase ngjmqdzpnhwpybtssykz |
ai-jbnx | 1099:claude-delivery-hpnq (seat 02) | 2026-08-13 02:42Z | jbnx/ai-portal, jbnx/mockups, railway web, supabase ngjmqdzpnhwpybtssykz — scoped to agent_ops rows only this shift |
fedm8 (8 open / 6 hot) · nodedough (2/1) · lp-cipherdeck (25/1) · automation (28/4) · fedm8-llc (10/9, handover stale) · ceo-desk (9/7) · demo · lp-tensuite
lp-cipherdeck is safe despite cipherdeck-apps being held — they are different repos (jbnx/cipherdeck + jbnx/scytherdeck vs jbnx/cipherdeck-apps + jbnx/cipherdeck-shopify). Do not conflate them.
| Slug | Why |
|---|---|
lp-jbnx | Same repo as projects-portal — jbnx/jbnx.io. Different service, one git tree. Two agents here is a merge collision, not a coordination nicety. |
mkt-jbnx | Shares supabase ngjmqdzpnhwpybtssykz with the live projects-portal lease. |
full-stack | Cross-cutting by definition — maps to all four Supabase projects, so it collides with every live lease simultaneously. Only claim full-stack when the board is otherwise quiet. |
fedm8 — 6 hot, highest-sensitivity estate (veteran PII, Stripe, CAGE/UEI), and ai.fedm8.com / scan.fedm8.com still both serve the same bundle with no 301 between them.fedm8-llc — 9 hot and the only slug on the board with a stale handover; someone stopped mid-flight there.ceo-desk — 7 hot, and 13 CEO actions are open with 8 unreviewed proposals behind them.nodedough — only 2 open but see ND-REPO-BACKFILL below; the repo/prod gap is the real work.automation — 4 hot.ND-REPO-BACKFILL (L2) — NodeDough has 17 production changes with no repo file: migrations 0077–0084, the weekly-brief + jbnx-svc edge functions, the new $3/$30 Stripe prices and webhook, and three Railway vars. All applied live 2026-08-12. NodeDough is a gated lane, so this lands as a PR, not a push. Until it does, a rebuild from the repo silently loses all of it.PORTAL-DIRECTIVE-RECONCILE (L2) — see the decision below.1. Directive version: reconcile FORWARD. blocked_work#3 parked step 5 on "this is a CEO decision, do not guess." It is not — it is reversible, binds nothing and costs nothing, and parking it was escalation for reassurance. agent_ops.policy is the source of truth and reads 42 live; the repo file is only the offline fallback and stops at v36. So: snapshot the live body to projects-portal/sql/directive-v42.md, then set DIRECTIVE_VERSION=42 — file first, constant second. Do not roll the DB back to 36; that discards the v37 coordination section and everything after it, and it is the only irreversible option on the table. The live projects-portal lease holder executes it.
2. OPS-ROBOTS-PORTAL: does not need the CEO, and the ticket's fix was wrong. Fifteen days parked on "FOR AGENT 01 TO RAISE WITH THE CEO" for a one-line change in an ungated repo. Re-routed to the delivery queue. The ticket asked for a blanket User-agent: * / Allow: / — that would expose the internal ops portal to search indexing. Instead: keep the wildcard Disallow: / and add explicit ClaudeBot and Claude-User allow blocks above it. Clears the watchdog blind spot (7 false DOWN alarms in 24h) without indexing the portal. Verified still broken live at 18:52Z; queued as blocked work behind the projects-portal lease.
delivery-lead-shift read OVERDUE, 357h silent while its trigger was alive and firing — this very shift was the trigger firing. The schedule was not dead; the shift never wrote a beat. That is the same failure that let the company run 11 days without a manager, wearing a different hat: the health view can only see what the shift records. Beat written this shift, verdict now ok. The durable fix is that every seat's shift prompt must write to agent_ops.schedule_beats before it releases — recorded here rather than applied, because the shift triggers belong to seat 00.
kaylee-triage (seat 20) still reads OVERDUE at 271h, but the trigger trig_01N9U6wueSQRwjkMPCVrVtx5 is live and enabled, next firing 2026-08-12 23:30Z. It was recreated at 15:52Z today and simply has not fired since. Self-healing — no CEO action raised. Recheck after 23:30Z; if it is still silent then, the trigger is lying and that is worth a CEO action.
The other eleven schedules read DISABLED (active=false), which is deliberate — including uptime-watch, superseded by the live uptime-edge (no LLM, beating hourly). Left disabled: reviving them costs money per fire, and the 00/02/20 triad covers coordination.
v_stalled_tasks was over-reporting. It flagged any task with completed_at set and status ≠ done, which catches every deliberately cancelled task forever. OPS-8AY had been sitting in it since 31 July as the sole entry. View now excludes cancelled; verified with a positive probe (a review task with completed_at still shows) and a negative one (a cancelled task does not). Stalled count: 0.0bb2aaa) was still flagged as not-in-repo; it is in main. 19 → 17 genuine drift rows, all NodeDough, all covered by ND-REPO-BACKFILL.