Mindbridge ยท engineering status

What's next

One ordered queue across every track. Open this when deciding what to pick up; the track pages carry the reasoning for their own work.

Generated by docs/status/next_queue.py from gh issue list. No prose on this page is hand-written โ€” it is regenerated whole, so it cannot drift behind the labels it renders and cannot conflict when two sessions touch it. Generated 2026-08-17 09:22 UTC.

153open issues
3p0
35p1
7not in effect
8unprioritised

Merged, but not in effect

Merged is not landed. A lazy backfill still draining, a flag not yet flipped, a migration whose data has not moved โ€” each reads as done everywhere and is not. Label the issue state:not-in-effect while the PR is open, and it stays here until someone measures the outcome and removes it. Open or closed both appear: an issue that never closes would otherwise carry the label invisibly.
prioritytrackissue
p0ama-discloseTypedItemMaterializer reduces a multi-message node's audience to one arbitrary carrier (stable_min_uuid) โ€” under-gating live on Regina (#3128)
p1ama-trustAMA cannot read re-extracted spreadsheets: 1,433 of 1,588 v2 docs have empty body_text and 22ร— smaller searchable_text (Regina, live) (#3255)
p1wire-truthWhatsApp senders with no usable pushName render as "Unknown WhatsApp user" โ€” 671 people in prod (#3054)
p1wire-truthConversation feed cards render a derived summary tier-gated only โ€” an aggregate has no scope to inherit, but its inputs do (#3194)
p2wire-truthRecover WhatsApp @-mentions from LIDs in message text (mentionedJid never arrives) (#3012)
nonedoc-truthThe published status artifacts (track index, next, board) are stale โ€” republish from docs/status/dist (#3351)
noneno trackMessage-node extractor stamps land on each tenant's next FULL materialization pass, not at merge (#3353)

The queue โ€” p0 and p1, in order

prioritytrackissue
p0ama-discloseAMA: facts fail OPEN on missing audience while messages fail CLOSED โ€” conversation-anchored facts skip disclosure (#2905)
p0ama-disclosetraverse_graph renders the RAW canonical_name in a candidate's title at ABSTRACTED/ATTRIBUTED (#3155)
p0securityidx_node_aliases_person_per_source is a cross-tenant UNIQUE index (no tenant_id) (#2968)
p1ama-disclosebusiness_context ships to the client ungated by disclosure level (#2824)
p1ama-discloseFindBridges feeds ungated profile content into the LLM that writes the rendered rationale (#3117)
p1ama-disclose, attachment-truthA document's audience can be decided by an arbitrary carrier message (ADR-145 D4) (#3325)
p1ama-trustAMA: verify arithmetic in the emitted answer, not just in derive() (#2899)
p1ama-trustAMA: coverage as a structured ledger, not a prose caveat (#2900)
p1ama-trustAMA: a renderable attachment scored INVISIBLE would leak if disclosure enforcement is ever rolled back (#3096)
p1attachment-truthmessage_attachments: a message can carry N files (ADR-145 D1/D2) (#3324)
p1attachment-truthThe library caps documents at one per message via a PRIMARY KEY (ADR-145 D5) (#3326)
p1billingWeb Google signup can never complete โ€” the OAuth full-page redirect destroys the form state (#2768)
p1billingMeter enterprise AMA questions for billing โ€” Regina's contract has a 6,000/month fair-use pool with $0.30/question overage that nothing counts (#2915)
p1connector-truthchore: Complete Google OAuth App Verification for Gmail (Restricted) + Calendar (Sensitive) Scopes (#1241)
p1connector-truthchore: CASA Tier 2 Assessment โ€” Preparation & Completion (#1248)
p1edge-truthfix(extraction): relationship typing structurally wrong โ€” sister typed as spouse, PARENT both-directions, no reconciliation (#1465)
p1edge-truthsuggested-questions v2: personalized ranker uses placeholder recency on v2 (provenance-conversation cutover) (#1483)
p1edge-truthnode_viewer_scoped_repository orders entity nodes by nodes_v2.created_at โ€” a rebuild timestamp, not content recency (#2994)
p1edge-truthedges_v2 concurrent upserts deadlock in a 4-way cycle โ€” CI retries and swallows it, production has no such retry (#3307)
p1measurementNothing tells us when a customer's connector dies โ€” the health score can't, and shouldn't (#3060)
p1nightly-nudgeNightly-nudge event extraction has no tier or disclosure gating at all (#3116)
p1nightly-nudge, viewer-truthA linked account that resolves to no person node is silently dropped from the nightly nudge audience โ€” Regina's audience is halved (#3243)
p1retentionADR-138 stage 6: the tenant-wide deleter has no resumability design for a partial failure across 72 FK'd tables (#2941)
p1retentionADR-138: no dead-sweep detection โ€” D6's CI gate catches 'never scheduled', not 'scheduled and silently stopped working' (#2942)
p1securityADR-097: impersonation flag keyed on spoofable From address poisons the legitimate mailbox owner (#2037)
p1securityClient end-user read endpoints run as DB superuser (RLS bypassed) โ€” migrate to run-as-user (#2445)
p1securitySupabase default privileges grant ALL on every new public table to anon/authenticated โ€” close it at the schema, not per object (#2938)
p1test-truthSuggested-questions node-side tenant_id predicate is unproven โ€” no fixture has a second tenant to leak (#3016)
p1viewer-truthfix(compose): proactive nudge + AMA narrative prose must attribute the sender by resolved display_name (#1314)
p1viewer-truthnodes_v2.properties.user_id owner-stamp is never cleared once written, and a stale stamp overrides identity silently (#3080)
p1viewer-truthW3: the client resolves the viewer itself, and now disagrees with the server (#3148)
p1viewer-truth"Which person node is this account?" has 17 independent expressions and no detector (#3162)
p1viewer-truthVIEWER-TRUTH: a suppression filter that filters nothing โ€” 1,316 persons leak into the attribution index (#3172)
p1viewer-truthVIEWER-TRUTH: the viewer's display NAME has 5-6 implementations that disagree, and no detector (#3173)
p1viewer-truthVIEWER-TRUTH: no real-DB test covers list_tenant_users, and the 50-id chunk boundary is untested (#3179)
p1viewer-truthVIEWER-TRUTH: a create with NO person writes a tier the reconciler will later discard (#3265)
p1viewer-truthVULN-05's confirmation is auto-supplied by the client โ€” the tier-0 downgrade guard cannot fire (#3267)
p1viewer-truthdisclose() enforced on a PERSONAL tenant and blanked the surface โ€” an unresolved viewer removes the exemption that would have spared it (#3276)

Below this tier: 82 p2, 25 p3, 8 unprioritised. They are ordered by the same criterion and omitted here to keep the queue readable.

This does not supersede the track pages

The track index and this page WILL disagree, by design. Each track orders its own work by a criterion that suits it โ€” irreversibility, leverage, live exposure โ€” and this page orders everything by one priority label. So a track can name a next item that does not appear in the tier shown here, and that is not a defect in either page. Use this to choose between tracks; use a track page to choose within one. If the two ever need reconciling, the track page is the one with the reasoning.

The ordering criterion, and what it ignores

Order: priority label, then track, then issue number ascending. No weighting, no composite, no ratio โ€” a four-expert panel killed the tenant-health score on 2026-08-06, and the finding that generalises is that a composite nothing branches on is decoration, while ratios of customer input to system output have no natural scale. This is a flat list.
What this order is blind to โ€” stated because an unstated blind spot reads as coverage:
  • What blocks what. GitHub carries no dependency edge we populate, and inferring one from issue prose would be a guess wearing a number's clothes.
  • How long anything takes. A p1 that is a week of work sorts above a p2 that is ten minutes.
  • Which commitment an issue serves. Priority approximates it and is not the same axis: a launch blocker can sit at p2 and hygiene can sit at p1.
  • Anything degrading users right now that nobody has filed. This queue can only order what exists as an issue.