Mindbridge's only push surface β proactive cards delivered to a user who did not ask; today they reach the wrong people, or nobody.
Top to bottom. The blocking product decision first β the index pill is Needs a call, and nothing below can safely move until the owner rules on a per-user consent control, because widening enablement without one is what would turn the latent defects live. Then the two gating preconditions (#3243 silent audience drop, #3116 ungated extraction) β fix before any scope-classified tenant enables nudges; silent loss outranks a disclosure gap. Then stale-premise cleanup (#3147). Then gated future work (#1034β#1038), blocked on #1033's five dependencies.
Deliberately ignored: issue age and filing order (the five granular items are the oldest and sort last); priority labels alone (the two p1s are latent today, and the granular items were re-rated from an inherited p1 to p2/p3 on 2026-08-14); how cheap or well-understood an item looks; and the severity a body asserts before exposure was measured β #3116's body said it "may matter more than #2906", but its follow-up measured live exposure at zero.
Census (prod, 2026-08-07, from #3116's follow-up). Every persisted nudge card was surfaced β 360 cards (229 event, 129 shift, 2 reachout), resolving to 611 cardβmessage pairs. Every pair is scope IS NULL and tier-3-by-default, 0 genuinely scope-classified. Four tenants have proactive_nudges_enabled, two empty; the two active tenants (Ahmed El-Daly, Sudqi) carry one viewer each and zero scope-classified messages. Regina β the only tenant with real restrictive scopes (51,831 scoped messages) β does not have nudges enabled. Hence zero live exposure, structurally, not coincidentally.
Panel provenance (#3147). Found by the VIEWER-TRUTH W2 adversarial panel, which grepped for method names and missed these two files that build the query inline. Recorded as a trap in .ai/choke-points.md β census by access pattern, never by method name. Its 2026-08-08 comment declared the premise stale: the recipient list now reads viewer_bindings.