Skip to content

Epic: Basic supervised Slack ingress for v1.5.0 #903

Description

@jeffhuber

Canonical completion state — 2026-09-17

This section supersedes the older checklist and sequencing text below where they conflict.

#921/#978 and optional #951 are deferred to v1.5.1. #922 does not depend on telemetry or Board/cloud views.

Part of roadmap #900.

Supervised Slack ingress for v1.5.0

Outcome

An authorized Slack user can start, inspect, answer and cancel bounded Code Mower work for an administrator-allowlisted repository. Slack is ingress and conversation transport. A separately qualified configured Codex/Claude supervisor owns orchestration, hosted-builder dispatch, clarification, review, cancellation and recovery. Selecting Devin never promotes it beyond bounded builder work.

Current status

#918, #977 and #983 can proceed in parallel where repositories and source ownership are independent. #919 consumes #918/#977; #920 follows #919; #921 freezes the cross-repository telemetry contract before #978 implements it; #922 follows both telemetry sides; #923 converges the release.

Safety and privacy

Authorize immutable Slack enterprise/team/app/user identities rather than display names or email. Persist a durable receipt before acknowledging. Deduplicate commands, modals, events, provider creates, answers and outbound messages. Reconcile uncertain paid creates without blind retries. Keep task prose, answers, Slack identities, response URLs, provider references, tokens and raw records out of public evidence, Board projections and cloud aggregates.

Every implementation PR uses one named writer, independent exact-head review, zero unresolved P0/P1/P2 findings, relevant tests, privacy/package checks, normal CI and authoritative gate. Hosted and OSS changes remain separately reviewable.


Owner-approved v1.5.0 boundary (2026-09-17)

An authorized user in one private Slack workspace can start, inspect, answer, and cancel bounded Code Mower work for an administrator-allowlisted repository. A separately qualified configured Codex or Claude supervisor owns scope, dispatch, clarification, recovery, review, cancellation, and completion. Hosted Devin remains a bounded builder.

v1.5.0 supports one workspace; immutable user, channel, and repository bindings; private start/status/answer/completion/cancel interactions; one qualified supervisor/provider route; and fail-closed authorization. Slack Connect, public posting, rich status UX, arbitrary provider selection, Slack-specific cloud telemetry, and hosted analytics move to v1.5.1.

Required remaining children are #1022, #918's private administration exercise, #920's completion and cancellation canaries, minimal #922, and #923 release convergence. #921 and #978 remain open as v1.5.1 work and no longer block #922 or #923. Optional #951 Board observation is also deferred to v1.5.1.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestepicEpic tracking issueserial-releaseSerialize because it changes release, gate, or final adoption posture

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions