Skip to content

feat: account-wide sending trust ladder and daily allowance visibility - #1064

Merged
jiashuoz merged 3 commits into
mainfrom
feat/account-trust-ladder
Sep 30, 2026
Merged

jiashuoz merged 3 commits into
mainfrom
feat/account-trust-ladder

Conversation

@jiashuoz

@jiashuoz jiashuoz commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Adds an opt-in account-wide external-recipient trust ladder, replacing independent domain progression. Accounts start at 20/day and reach 2,000 on the thirtieth clean active day, subject to the plan cap. Shared-identity sends consume that allowance and are additionally capped at 50/day; internal recipients do not consume daily capacity.

Reservations serialize across identities, retain uncertain exposure, and preserve idempotent late settlement. Clean-day credit uses immutable accepted-attempt provenance, including across recipient reclassification and runtime-policy changes. Bounded retention preserves earned progress. Immediate refusals and queued holds explain current usage and reset time; /v1/account, both SDKs, CLI, MCP, and dashboard expose the same optional contract.

Validation (final head d756e2212: 28 CI checks passed, one skipped):

  • Affected Go packages pass; trust admission regressions pass under the race detector.
  • TypeScript SDK 276, CLI 365, MCP 347, dashboard 1,099, Python 644 tests pass (Python coverage 94.33%).
  • Shared contract scenario passes through Go, TypeScript, and Python. OpenAPI compatibility and generated SDK freshness pass.
  • Isolated local HTTP-to-SMTP checks cover external/internal counting, free/paid plan caps, shared/own-domain composition, idempotency, and scheduled hold diagnostics.
  • Full local Go run is not green: clock-sensitive outreach tests also fail on untouched main; the initial run hit integration timeouts. With SMTP available, the e2e suite had an outreach baseline failure and an inbound timing failure that passed on isolated rerun. The corresponding CI Go tests, dedicated e2e suite, and coverage gate all pass.

Independent and adversarial review both have no remaining blockers after fixes for late-attempt attribution, internal-only retries, recipient reclassification, and policy-toggle provenance. The final reviewed build passed the isolated local SMTP checks again.

Both flags default off. This PR does not enable hosted enforcement. Reviewed grandfathering, the policy-source rollout/observation window, and detector automation remain separate rollout work; see docs/design/account-trust-ladder.md.

@jiashuoz
jiashuoz merged commit 7f64c82 into main Sep 30, 2026
29 checks passed
@jiashuoz
jiashuoz deleted the feat/account-trust-ladder branch September 30, 2026 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant