Ticket graphs

Every ticket as the root of its provenance graph — goal, patch, approval, runs and (as the ticket-class build lands) mandate, manifestations, guarantees, journey, artifacts and children. Rendered through the <<<TicketGraphList>>> tag.

← all ticket-graphs

REQUESTED#181 jazz-agents

Test: MCP-only enforcement + dispatch least-privilege are airtight

goal

Adversarially prove an agent cannot reach ANY tool outside its MCP allowlist (no shell escape; no file write for dispatch) and that the dispatch agent cannot author/modify work product. Attempt escapes; each MUST be refused. This is the trust boundary the whole 'don't trust Claude' redesign rests on. Gated on B3 + B4.

patch

none

approval

unapproved

runs

no runs recorded

mandate (clauses)

not yet recorded — lands with the ticket-class build

manifestations

not yet recorded — lands with the ticket-class build

guarantees

not yet recorded — lands with the ticket-class build

journey (blunders & successes)

not yet recorded — lands with the ticket-class build

artifacts (forge)

not yet recorded — lands with the ticket-class build

source (forge tree)

browse congruency source (forge-parked tree)

children

not yet recorded — lands with the ticket-class build